Communication method and communication device
By sending requests to process information for traditional and post-quantum cryptographic algorithm certificates in the certificate authentication device, and utilizing combined signature or associated certificate mechanisms, the problem of certificate management incompatibility is solved, achieving compatibility and security of certificates during quantum migration and improving the efficiency of identity authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-10-24
- Publication Date
- 2026-04-24
AI Technical Summary
In the current technology, the certificate management of traditional cryptographic algorithms and post-quantum cryptographic algorithms has not been effectively adapted, which makes it impossible for certificates to be successfully migrated in a quantum computing environment, affecting the security and compatibility of identity authentication.
By sending a request to the certificate authentication device to process information of traditional cryptographic algorithms and post-quantum cryptographic algorithms, and using combined signature or associated certificate mechanisms for joint authentication, the compatibility and security of certificates are ensured during quantum migration.
It achieves joint authentication of certificates using traditional cryptographic algorithms and post-quantum cryptographic algorithms, ensuring smooth migration and compatibility of certificates in a quantum computing environment, reducing message sending overhead, and improving the security and efficiency of identity authentication.
Smart Images

Figure CN121923799A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, specifically to a communication method and a communication device. Background Technology
[0002] With the development of quantum computing technology, many algorithms in traditional cryptography may be threatened by quantum computers. To address this threat, post-quantum cryptographic algorithms need to be introduced.
[0003] Currently, post-quantum cryptography algorithms are not widely used. Therefore, when using cryptographic algorithms for key exchange and authentication in cryptographic security protocols, a hybrid mechanism is employed, employing both traditional and post-quantum cryptography algorithms. For example, certificates signed using both traditional and post-quantum cryptography algorithms can be used to jointly authenticate the identity of the same entity.
[0004] How to manage these two types of certificates so that they can be adapted for quantum migration is a problem that needs to be addressed. Summary of the Invention
[0005] This application provides a communication method and a communication device, which enables quantum migration of two certificates encrypted with different algorithms after adaptation.
[0006] In a first aspect, a communication method is provided, the method comprising: when a first certificate of a first entity is pending processing, determining a second certificate of the first entity based on the first certificate, wherein the first certificate and the second certificate are used for joint authentication of the first entity; and sending first information requesting processing of the first certificate and second information requesting processing of the second certificate to a certificate authentication device.
[0007] For example, the communication method can be implemented by a first entity, or by modules, units, processors, circuits, chips or chip systems included in the first entity.
[0008] The method provided in this application, when a first certificate and a second certificate of a first entity can jointly authenticate the first entity, firstly determines the second certificate based on the first certificate, and when the first certificate needs to be processed, the first entity sends first information requesting processing of the first certificate and second information requesting processing of the second certificate to the certificate authentication device, so that the certificate authentication device can process the first certificate and process the second certificate jointly authenticated with the first certificate, thereby enabling the processed first certificate and second certificate to be adapted for quantum migration.
[0009] In some possible implementations, the first certificate can refer to a certificate that does not contain information about the second certificate; that is, the first certificate can refer to a certificate signed based on a traditional cryptographic signature algorithm, or the first certificate can refer to an incremental certificate. The second certificate can refer to a certificate that contains information about the first certificate; that is, the second certificate can refer to a certificate signed based on a post-quantum signature algorithm, or the second certificate can refer to a basic certificate.
[0010] For example, an entity already holds a digital certificate / incremental certificate (first certificate) based on a traditional cryptographic algorithm, and then applies for a certificate / basic certificate (second certificate) based on a post-quantum algorithm. To adapt to hybrid authentication scenarios, the newly applied certificate needs to carry information from the first certificate, associating or pairing it with the previously held first certificate. This allows both certificates to support hybrid authentication mechanisms without affecting the independent use of the digital certificate based on the traditional cryptographic algorithm. This implementation ensures good backward compatibility and adapts to current post-quantum migration scenarios. Optionally, the joint authentication of the first entity using the first and second certificates can refer to authentication based on a combined signature, which includes sub-signature 1 and sub-signature 2. The first certificate verifies sub-signature 1, and the second certificate verifies sub-signature 2. Authentication of the first entity is successful when both sub-signature 1 and sub-signature 2 are verified.
[0011] Of course, the first entity can also be jointly authenticated using the first certificate and the second certificate in other ways. This application does not specifically limit the method of joint authentication.
[0012] In some possible implementations, the joint authentication of the first entity by the first certificate and the second certificate may include: a first signature algorithm corresponding to the first certificate and a second signature algorithm corresponding to the second certificate being used to authenticate the signature of the first entity.
[0013] For example, the first signature algorithm can be a traditional cryptographic signature algorithm, and the second signature algorithm can be a post-quantum signature algorithm.
[0014] Alternatively, both the first and second signature algorithms can be traditional cryptographic signature algorithms, or they can be post-quantum signature algorithms.
[0015] For example, traditional cryptographic signature algorithms include at least one of the following: RSA, DSA, SM2, or ECDSA. The second signature algorithm can be a post-quantum signature algorithm, which includes at least one of the following: CRYSTALS-Dilithium, Falcon, SPHINCS+, XMSS, Lamport, SQISign, etc.
[0016] It should be noted that traditional cryptographic signature algorithms may also include other algorithms, and post-quantum signature algorithms may also include other algorithms. This application does not specifically limit these algorithms.
[0017] It should be noted that the processing mentioned in the embodiments of this application may refer to the updating of the first certificate and the second certificate, or the revocation of the first certificate and the second certificate, etc. Of course, the request processing may also include other processing methods, and this application does not specifically limit them.
[0018] In some possible implementations, sending a request to the certificate authentication device to process the first information of the first certificate includes: sending a first request message to the certificate authentication device, the first request message carrying the first information; sending a request to the certificate authentication device to process the second information of the second certificate includes: after determining the second certificate of the first entity, sending a second request message to the certificate authentication device, the second request message carrying the second information.
[0019] In this implementation, two request messages can be used to request the processing of the first certificate and the second certificate respectively.
[0020] For example, the two messages can be a first certificate update request message and a second certificate update request message, or the two messages can be a first certificate revocation request message and a second certificate revocation request message, respectively.
[0021] It should be understood that the first certificate update request message, the second certificate update request message, the first certificate revocation request message, and the second certificate revocation request message can be in existing message formats.
[0022] It should be noted that the first request message may be sent before or after the second certificate of the first entity is determined. This application embodiment does not specifically limit the timing of sending the first request message.
[0023] For example, the first request message may be a first certificate update request message, which is used to request the update of a first certificate and carries first information; the second request message may be a second certificate update request message, which is used to request the update of a second certificate and carries second information.
[0024] For example, the first request message may be a first certificate revocation request message, which is used to request the revocation of the first certificate and carries first information; the second request message may be a second certificate revocation request message, which is used to request the revocation of the second certificate and carries second information.
[0025] In some possible implementations, the processing is an update, and the first information includes at least one of the following: the public key of the third certificate, the first certificate, the serial number of the first certificate, and the signature of the first certificate update request message by the private key of the first certificate.
[0026] The third certificate is an updated version of the first certificate. The first information is used to request an update to the first certificate from the certificate authentication device.
[0027] Specifically, the public key of the third certificate is used to instruct the certificate authentication device to update the first certificate for the first entity so that the public key corresponding to the obtained certificate (i.e., the third certificate) is the public key of the third certificate; the signature of the first request message by the first certificate / first certificate serial number and the first certificate private key is used to prove to the certificate authentication device that the requester of the first request message is indeed the first entity holding the first certificate.
[0028] It should be noted that the first information may not include the first certificate, but rather its serial number. This allows the certificate authentication device to find the corresponding first certificate based on its serial number.
[0029] Optionally, the certificate authentication device can prove that the requester of the first request message is indeed the first entity holding the first certificate by verifying the signature of the first certificate update request message by using the public key of the first certificate.
[0030] In some possible implementations, the processing is as an update, and the second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0031] The fourth certificate is an updated version of the second certificate. The second information can be used by the certificate authentication device to obtain information about the updated first certificate (third certificate), so that it can be bound to the third certificate during the subsequent issuance of the fourth certificate, thereby enabling the two certificates to be used for joint authentication of the first entity.
[0032] The serial number and location information of the third certificate can be used by the certificate authentication device to obtain the third certificate; the serial number, public key, signature value, and signature algorithm of the third certificate can be used to determine the certificate domain information that is different between the third certificate and the updated second certificate (i.e., the fourth certificate); the signature of the private key of the third certificate on at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate, can be used to determine to the certificate authentication device that the sender of the second request message has a certificate (i.e., the third certificate) corresponding to the above information. If the third certificate is possessed, the certificate authentication device will bind the third certificate to the fourth certificate.
[0033] It should be understood that when the first certificate and the second certificate are bound together, the first certificate and the second certificate can be used to perform joint authentication of the first entity.
[0034] Optionally, the binding of the first certificate and the second certificate can be achieved by associating the first certificate and the second certificate (that is, the first certificate and the second certificate are associated certificates) or by pairing the first certificate and the second certificate (that is, the first certificate and the second certificate are paired certificates). Of course, the binding of the first certificate and the second certificate can also be achieved in other ways. This application embodiment does not limit the binding method of the first certificate and the second certificate.
[0035] For example, the first certificate and the second certificate are associated certificates, and the second certificate contains the hash value of the first certificate to bind the first certificate. In this case, the second information may include: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate and / or the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0036] It should be noted that after obtaining the third certificate through its serial number and / or location information, the public key of the third certificate can be extracted.
[0037] The serial number and location information of the third certificate can be used to determine how the certificate authentication device obtains the third certificate. The private key of the third certificate is used to sign at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate. This can be used to determine to the certificate authentication device that the sender of the second request message has a certificate (i.e., the third certificate) corresponding to the above information. If the third certificate is possessed, the certificate authentication device will bind the third certificate to the fourth certificate.
[0038] For example, the first certificate and the second certificate are paired certificates. The second certificate contains information that is different from the first certificate (i.e., the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate, etc.). In this case, the second information may include: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate.
[0039] The serial number, public key, signature value, and / or signature algorithm of the third certificate are key differences between the third and fourth certificates. These details can be used to reconstruct the third certificate, allowing certificate authentication devices to verify its signature value using the reconstructed certificate and the third certificate's public key, thus validating the third certificate. Once verified, this information can be included in the fourth certificate.
[0040] It should be understood that when processing is an update, the first request message can be a first certificate update request message, and the second request message can be a second certificate update request message. Of course, the first and second certificates can be updated through other request messages. In this application embodiment, the message name of the request message is not specifically limited.
[0041] When the first request message is a first certificate update request message and the second request message is a second certificate update request message, the first entity requests to update both the first and second certificates. The second information mainly includes information about the updated first certificate (third certificate). The certificate authentication device can update the second certificate based on the information from the third certificate, thereby ensuring that the updated second certificate (fourth certificate) can be used normally.
[0042] In some possible implementations, the process is revocation, and the first message includes at least one of the following: the serial number of the first certificate, the first certificate, and a signature of the first request message using the private key of the first certificate. The second message includes at least one of the following: the serial number of the second certificate, the second certificate, and a signature of the second request message using the private key of the second certificate.
[0043] The first certificate / second certificate, or the serial number of the first certificate / second certificate, is used by the certificate authentication device to obtain the certificate to be revoked. The signature of the first request message with the private key of the first certificate is used by the certificate authentication device to determine that the request message comes from the first entity that owns the first certificate, and the signature of the second request message with the private key of the second certificate is used by the certificate authentication device to determine that the request message comes from the first entity that owns the second certificate.
[0044] It should be understood that the first information may not include the first certificate, but rather its serial number, so that the certificate authentication device can find the corresponding first certificate based on the serial number.
[0045] For example, a certificate authentication device can look up the first certificate in a certificate issuance list that stores certificates based on the serial number of the first certificate.
[0046] It should also be understood that the first information may not include the second certificate, but rather its serial number, so that the certificate authentication device can find the corresponding second certificate based on the serial number.
[0047] For example, a certificate authentication device can look up a second certificate in a certificate issuance list that stores certificates based on the second certificate's serial number.
[0048] It should be understood that when the processing is revocation, the first request message can be a first certificate revocation request message, and the second request message can be a second certificate revocation request message. Of course, the first certificate and the second certificate can be revoked through other request messages. This application embodiment does not specifically limit the message name of the request message.
[0049] In this implementation, when the first request message is a first certificate revocation request message and the second request message is a second certificate revocation request message, after the first entity requests the revocation of the first certificate, it requests the synchronous revocation of the second certificate.
[0050] In some possible implementations, sending first information requesting the processing of a first certificate and second information requesting the processing of a second certificate to the certificate authentication device includes sending a third request message, which carries the first and second information.
[0051] In this implementation, the first and second certificates are processed using a single message request, reducing the overhead of sending messages. For example, the third request message can be a multi-certificate synchronization update message or a multi-certificate synchronization revocation message.
[0052] For example, if the processing is for an update, the third request message can be a multi-certificate synchronization update message, which requests the update of the first and second certificates. This multi-certificate synchronization update message carries the first and second information. Of course, when the processing is for an update, the third request message can also have other message names; this application embodiment does not specifically limit the name of the third request message.
[0053] For example, if the processing is revocation, the third request message can be a multi-certificate synchronous revocation message, which is used to request the revocation of the first certificate and the second certificate. This multi-certificate synchronous revocation message includes first information and second information. Of course, when the processing is revocation, the third request message can also have other message names; this application embodiment does not specifically limit the name of the third request message.
[0054] In this implementation, when the process is to update, the certificate authentication device can update the first certificate and the second certificate based on the third request message. The updated first certificate and the updated second certificate can be used to perform joint authentication on the first entity, thereby ensuring that the updated first certificate and the updated second certificate can be used normally.
[0055] In some possible implementations, when processing is an update, the first information and the second information include at least one of the following: a first certificate, a serial number of the first certificate, a second certificate, a serial number of the second certificate, a public key of a third certificate, a public key of a fourth certificate, a signature of the third request message by the private key of the first certificate and / or the private key of the second certificate, wherein the third certificate is a certificate updated from the first certificate, and the fourth certificate is a certificate updated from the second certificate.
[0056] The first certificate / serial number of the first certificate and the second certificate / serial number of the second certificate are used to obtain the first certificate and the second certificate. The public key of the third certificate and the public key of the fourth certificate are used by the certificate authentication device to obtain the public key information corresponding to the updated first certificate and the updated second certificate. The signature of the third request message by the private key of the first certificate and / or the private key of the second certificate is used by the certificate authentication device to determine that the sender of the message does indeed possess the first certificate and the second certificate.
[0057] It should be understood that the first and second information may not include the first and second certificates, but may include the serial numbers of the first and second certificates. Thus, the certificate authentication device can find the serial number of the first certificate in the certificate issuance list that stores the certificates to obtain the first certificate, and find the serial number of the second certificate to obtain the second certificate.
[0058] In this embodiment, the third request message can be signed using the private key of the first certificate, the private key of the second certificate, or both the private keys of the first and second certificates can be used to sign the third request message, or the private keys of the first and second certificates can be used to jointly sign the third request message. This embodiment does not specifically limit the signing method of the third request message.
[0059] For example, the first information may be a first certificate, the serial number of the first certificate, the public key of the third certificate, and a signature of the third request message using the private key of the first certificate. The second information may be a second certificate, the serial number of the second certificate, the public key of the fourth certificate, and a signature of the third request message using the private key of the second certificate.
[0060] The signature of the third request message using the private keys of the first and second certificates can be either the first information or the second information. This application does not specifically limit this.
[0061] In some possible implementations, the third request message may further include: a first federated certificate instruction, which instructs a first certificate and a second certificate to be used for federated authentication of the first entity.
[0062] In this implementation, the third request message uses the first federated certificate to indicate the association between the first certificate and the second certificate. The certificate authentication device synchronously updates the first certificate and the second certificate based on the first federated certificate instruction, thereby ensuring that the updated first certificate and the updated second certificate retain their association, or the certificate authentication device synchronously revokes the first certificate and the second certificate based on the first federated certificate instruction.
[0063] In some possible implementations, the process is an update, and the method further includes: receiving a first response message, the first response message including a third certificate; and receiving a second response message, the second response message including a fourth certificate. The third and fourth certificates are used for federated authentication of the first entity.
[0064] In this implementation, the first entity receives the updated first certificate (third certificate) sent by the certificate authentication device, and then receives the updated second certificate (fourth certificate).
[0065] In some possible implementations, the method further includes receiving a third response message, the third response message including a third certificate and a fourth certificate, the third certificate and the fourth certificate being used for federated authentication of the first entity.
[0066] In this implementation, when the third request message is a request to synchronize and update the first certificate and a request to update the second certificate, the first entity receives the updated first certificate (third certificate) and the updated second certificate (fourth certificate) sent by the certificate authentication device.
[0067] In some possible implementations, the third response message may also include a second federated certificate instruction, which instructs the third and fourth certificates to be used for federated authentication of the first entity.
[0068] In this implementation, the certificate authentication device indicates to the first entity that the updated first certificate (third certificate) and the updated second certificate (fourth certificate) are associated, that is, the third certificate and the fourth certificate are used to jointly authenticate the first entity.
[0069] In some possible implementations, the method also includes: verifying the association between the third and fourth certificates based on the indications of the second joint authentication certificate.
[0070] In this implementation, the first entity verifies the association between the third and fourth certificates based on the second federated authentication certificate, and verifies whether the third and fourth certificates can be used to perform federated authentication on the first entity.
[0071] In some possible implementations, determining the second certificate of the first entity based on the first certificate includes: determining the second certificate based on the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0072] For example, the first certificate and the second certificate are associated certificates. The second certificate contains the hash value of the first certificate. The first entity can determine the second certificate based on the hash value of the first certificate contained in the second certificate.
[0073] For example, the first certificate and the second certificate are paired certificates. The second certificate contains information that is different from the first certificate (such as the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate, etc.). The first entity can determine the second certificate based on the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate contained in the second certificate.
[0074] In some possible implementations, determining the second certificate of the first entity based on the first certificate includes: determining the second certificate based on the correspondence between the first certificate and the storage.
[0075] Optionally, the method further includes: the first entity can store the correspondence between the first certificate and the second certificate;
[0076] For example, the stored correspondence may refer to a list of associations between the first certificate and the second certificate. Alternatively, the list of stored correspondences may refer to a list of pairings between the first certificate and the second certificate. Alternatively, the correspondence between the first certificate and the second certificate may be represented in other ways, which are not specifically limited in this embodiment.
[0077] This application does not specifically limit the correspondence between the first certificate and the second certificate.
[0078] It should be noted that the correspondence between the first certificate and the second certificate may be stored before the first certificate determines the second certificate of the first entity. Alternatively, the correspondence between the first certificate and the second certificate may be determined before the first entity determines that the first certificate is the certificate to be processed. This application embodiment does not specifically limit the storage time of the correspondence between the first certificate and the second certificate.
[0079] In a second aspect, a communication method is provided, the method comprising: a certificate authentication device receiving first information of a first certificate of a first entity requesting processing and second information of a second certificate of a first entity requesting processing, the first certificate and the second certificate being used for joint authentication of the first entity; and the certificate authentication device processing the first certificate and the second certificate.
[0080] For example, the communication method can be implemented by a certificate authentication device, or by modules, units, processors, circuits, chips or chip systems included in the certificate authentication device.
[0081] It should be noted that the certificate authentication device may also be referred to as a certificate authentication authority, certificate issuing authority, certificate issuing entity, certificate issuing network element, etc., and such naming should not constitute any limitation on the embodiments of this application.
[0082] The method provided in this application uses a first certificate and a second certificate of a first entity to perform joint authentication of the first entity. When the first certificate needs to be processed, the certificate authentication device receives first information requesting the processing of the first certificate and second information requesting the processing of the second certificate, and can process the first certificate and process the second certificate that performs joint authentication with the first certificate, thereby better adapting to post-quantum migration.
[0083] In some possible implementations, processing the first certificate and the second certificate includes: updating the first certificate to obtain a third certificate, updating the second certificate to obtain a fourth certificate, and using the fourth certificate and the third certificate to perform federated authentication of the first entity.
[0084] In this implementation, the process is an update. The certificate authentication device updates the first certificate and the second certificate. Since the second certificate references the first certificate, the second certificate needs to be updated synchronously when the first certificate is changed, so that the updated second certificate (fourth certificate) and the updated first certificate (third certificate) can jointly authenticate the first entity.
[0085] In some possible implementations, updating the second certificate to obtain the fourth certificate includes updating the second certificate based on information from the third certificate to issue the fourth certificate.
[0086] Specifically, the information of the certificate used in the fourth certificate for joint authentication of the first entity includes: information of the third certificate;
[0087] It should be noted that the updated first certificate (third certificate) has the same values for the certificate subject, certificate issuer, key purpose, and / or signature algorithm as the first certificate. Similarly, the updated second certificate (fourth certificate) has the same values for the certificate subject, certificate issuer, key purpose, and / or signature algorithm as the second certificate.
[0088] Optionally, the first certificate and the second certificate are associated certificates, with the second certificate containing the hash value of the first certificate to bind the first certificate. In this case, the information of the third certificate can be the hash value of the third certificate.
[0089] Optionally, the first certificate and the second certificate are paired certificates. The second certificate contains information that is different from the first certificate (i.e., the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate, etc.). In this case, the information of the third certificate may be the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate, etc.
[0090] In some possible implementations, receiving first information of the first certificate of the request processing first entity includes: receiving a first request message, the first request message carrying the first information; receiving second information of the second certificate of the request processing first entity includes: receiving a second request message, the second request message carrying the second information.
[0091] In this implementation, two messages can be used to process the first certificate and the second certificate. For example, these two messages can be a first certificate update request message and a second certificate update request message, respectively, or they can be a first certificate revocation request message and a second certificate revocation request message, respectively.
[0092] It should be understood that the first certificate update request message, the second certificate update request message, the first certificate revocation request message, and the second certificate revocation request message can be in existing message formats.
[0093] In some possible implementations, the processing is as an update, and the second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0094] For example, the first certificate and the second certificate are associated certificates. The second certificate contains the hash value of the first certificate to bind the first certificate. The second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, or the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0095] For example, the first certificate and the second certificate are paired certificates. The second certificate contains information that is different from the first certificate (i.e., the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate, etc.). In this case, the second information includes at least one of the following: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
[0096] For example, the first certificate and the second certificate are associated certificates, and the second information includes at least one of the following: the public key of the third certificate, the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate. The method further includes: using the public key of the third certificate to verify the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; if the verification is successful, issuing the fourth certificate according to the information of the third certificate, wherein the information of the third certificate includes the hash value of the third certificate.
[0097] Optionally, in this example, the second information also includes a third certificate and a signature of the second request message using the third certificate's private key. The signature of the second request message using the third certificate's private key is verified using the third certificate's public key. If the verification passes, the hash value of the third certificate is calculated, and this hash value is included in the fourth certificate issued to the first entity.
[0098] It should be understood that in this implementation, if the verification passes, the hash value of the third certificate is calculated by the certificate authentication device.
[0099] Furthermore, the second information also includes the serial number of the third certificate and / or the location information of the third certificate. The method further includes: obtaining the third certificate based on the serial number of the third certificate and / or the location information of the third certificate in the second information.
[0100] It should be understood that if the public key of the third certificate is included in the second information, the signature of the private key of the third certificate against at least one of the following can be verified using the public key of the third certificate in the second information: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; if the public key of the third certificate is not included in the second information, the public key of the third certificate may be obtained after obtaining the third certificate using the serial number / location information of the third certificate.
[0101] Optionally, before obtaining the third certificate, the certificate authentication device can also use the public key of the second certificate to verify the signature of the second request message using the private key of the second certificate. If the verification is successful, the third certificate is obtained. That is, the verification of the signature of the second request message by the certificate authentication device can ensure that the message source is reliable, that is, the second request message was indeed sent by the first entity holding the second certificate and has not been tampered with.
[0102] It should be noted that the embodiments of this application do not specifically limit the order of the above verifications.
[0103] In some possible implementations, the first certificate and the second certificate are paired certificates. The second certificate contains information that differs from the first certificate (i.e., the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate, etc.). In this case, the second information includes at least one of the following: the public key of the third certificate, the signature value of the third certificate, the serial number of the third certificate, and the signature algorithm of the third certificate. Before issuing the fourth certificate based on the third information, the method further includes: verifying the signature value of the third certificate using the public key of the third certificate; and, if the verification is successful, issuing the fourth certificate based on the information of the third certificate, which includes: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate.
[0104] It should be understood that the first certificate and the second certificate are paired certificates. The certificate authentication device first updates the incremental certificate (the first certificate) and issues the updated first certificate, i.e., the third certificate, to the first entity. Then, the certificate authentication device issues the fourth certificate based on the information in the third certificate.
[0105] In some possible implementations, the method further includes: sending a first response message, the first response message including a third certificate; sending a second response message, the second response message including a fourth certificate; wherein the third certificate and the fourth certificate are used for federated authentication of the first entity.
[0106] In this implementation, when there are two messages requesting to update the first certificate and requesting to update the second certificate, the certificate authentication device sends the updated first certificate (third certificate) to the first entity, and then sends the updated second certificate (fourth certificate) to the first entity.
[0107] In some possible implementations, receiving first information of a first certificate of a first entity requesting processing and second information of a second certificate of a first entity requesting processing includes receiving a third request message, the third request message carrying the first and second information.
[0108] In this implementation, the first and second certificates are processed using a single message request, reducing the overhead of sending messages.
[0109] For example, when the processing is for updating, the third request message may be a multi-certificate synchronization update message; or, when the processing is for revocation, the third request message may be a multi-certificate synchronization revocation message.
[0110] Furthermore, the processing is to update, and the first information and the second information include at least one of the following: a first certificate, the serial number of the first certificate, a second certificate, the serial number of the second certificate, the public key of the third certificate, the public key of the fourth certificate, the private key of the first certificate and / or the private key of the second certificate for signing the third request message;
[0111] The third certificate is obtained by updating the first certificate, and the fourth certificate is obtained by updating the second certificate. The third and fourth certificates are used to jointly authenticate the first entity.
[0112] It should be noted that the updated first certificate (third certificate) has the same values for the certificate subject, certificate issuer, key purpose, and / or signature algorithm as the first certificate. Similarly, the updated second certificate (fourth certificate) has the same values for the certificate subject, certificate issuer, key purpose, and / or signature algorithm as the second certificate.
[0113] It should be understood that the first and second information may not include the first and second certificates, but may include the serial numbers of the first and second certificates. Thus, the certificate authentication device can find the serial number of the first certificate in the certificate issuance list that stores the certificates to obtain the first certificate, and find the serial number of the second certificate to obtain the second certificate.
[0114] For example, the first information may include at least one of the following: a first certificate, a serial number of the first certificate, a public key of a third certificate, or a signature of the third request message using the private key of the first certificate. The second information may include at least one of the following: a second certificate, a serial number of the second certificate, a public key of a fourth certificate, or a signature of the third request message using the private key of the second certificate.
[0115] It should be understood that the first information may not include the first certificate, but may include the serial number of the first certificate, so that the certificate authentication device can find the serial number of the first certificate in the certificate issuance list that stores the certificates and obtain the first certificate.
[0116] The second information may not include the second certificate, but may include the serial number of the second certificate so that the certificate authentication device can look up the serial number of the second certificate in the certificate issuance list that stores the certificates to obtain the first certificate.
[0117] The signature of the third request message using the private keys of the first and second certificates can be either the first information or the second information. This application does not specifically limit this.
[0118] In some possible implementations, the method further includes: using the public key of the first certificate and / or the public key of the second certificate to verify the signature of the third request message by the private key of the first certificate and / or the private key of the second certificate; if the verification is successful, issuing a third certificate based on the public key of the third certificate; and issuing a fourth certificate based on the information of the third certificate and the public key of the fourth certificate.
[0119] In this embodiment, when signing the third request message using the private key of the first certificate, the signature of the third request message using the private key of the first certificate can be verified using the public key of the first certificate. When signing the third request message using the private key of the second certificate, the signature of the third request message using the private key of the first certificate can be verified using the public key of the first certificate. When signing the third request message using the private keys of the first and second certificates respectively, the signatures of the third request message using the private keys of the first and second certificates can be verified using the public keys of the first and second certificates respectively. When jointly signing the third request message using the private keys of the first and second certificates, the joint signature of the third request message can be verified using the public keys of the first and second certificates. This embodiment does not specifically limit the verification method for the signature of the third request message.
[0120] Optionally, when the first and second certificates are associated certificates, the information of the third certificate is the hash value of the third certificate.
[0121] In some possible implementations, when the first certificate and the second certificate are paired certificates, the first information and the second information may also include: a signature of the third request message by the private key of the third certificate.
[0122] The signature of the third request message by the private key of the third certificate can be the first information, or it can be the second information. This application embodiment does not specifically limit the division of the signature of the third request message by the private key of the third certificate.
[0123] In some possible implementations, the method further includes, before issuing the fourth certificate, verifying the signature of the third request message by using the public key of the third certificate to verify the signature of the third request message by the private key of the third certificate.
[0124] In this implementation, the certificate authentication device uses the public key of the third certificate to verify the signature of the third request message by the private key of the third certificate. If the verification is successful, a fourth certificate is issued.
[0125] In some other possible implementations, the first and second information may also include: a signature of the third certificate’s private key on information that is different from the fourth certificate, wherein the information that is different from the fourth certificate may include, but is not limited to, the third certificate’s serial number, the third certificate’s public key, the third certificate’s signature value, the third certificate’s signature algorithm, etc.
[0126] In this implementation, the certificate authentication device can also use the public key of the third certificate to verify the signature of the third certificate's private key on information that is different from the fourth certificate. If the verification is successful, the fourth certificate is issued.
[0127] In some possible implementations, the method further includes sending a third response message, which includes a third certificate and a fourth certificate used for federated authentication of the first entity.
[0128] In this implementation, when the third request message is a message requesting the update of the first certificate and the second certificate, the certificate authentication device sends the updated first certificate (third certificate) and the updated second certificate (fourth certificate) to the first entity.
[0129] Thirdly, a communication method is provided, the method comprising: receiving a fourth request message for requesting processing a first certificate of a first entity; determining a second certificate of the first entity based on the first certificate; the first certificate and the second certificate being used for joint authentication of the first entity; and processing the first certificate and the second certificate.
[0130] For example, the communication method can be implemented by a certificate authentication device, or by modules, units, processors, circuits, chips or chip systems included in the certificate authentication device.
[0131] The method provided in this application, when a first certificate is pending processing, after the certificate authentication device receives a message from a first entity requesting processing of the first certificate, the certificate authentication device determines a second certificate that is jointly authenticated with the first certificate based on the first certificate, thereby processing the first certificate and processing the second certificate that is jointly authenticated with the first certificate, ensuring that the processed first certificate and second certificate are better adapted for quantum migration.
[0132] For example, when the request is processed as a request for update, the fourth request message could be a certificate update request message. Or, when the request is processed as a request for revocation, the fourth request message could be a certificate revocation request message.
[0133] For example, when the fourth request message is a certificate update request message, the certificate authentication device updates the first and second certificates. When the fourth request message is a certificate revocation request message, the certificate authentication device revokes the first and second certificates.
[0134] It should be understood that the joint authentication of the first entity by the first certificate and the second certificate may include: the first signature algorithm corresponding to the first certificate and the second signature algorithm corresponding to the second certificate being used to authenticate the signature of the first entity.
[0135] For example, the first signature algorithm can be a conventional cryptographic signature algorithm, which includes, but is not limited to, at least one of the following: RSA algorithm, DSA, SM2, or ECDSA algorithm. The second signature algorithm can be a post-quantum signature algorithm, which includes, but is not limited to, at least one of the following: CRYSTALS-Dilithium, Falcon, SPHINCS+, XMSS, Lamport, or SQISign.
[0136] In some possible implementations, the processing is an update, and processing the first certificate and the second certificate includes: updating the first certificate to obtain a third certificate; updating the second certificate to obtain a fourth certificate, the fourth certificate and the third certificate being used for federated authentication of the first entity.
[0137] In some possible implementations, the second certificate is updated based on the information of the third certificate to issue a fourth certificate. The information of the certificate used for joint authentication of the first entity with the fourth certificate in the fourth certificate includes: the information of the third certificate; wherein the information of the third certificate includes at least one of the following: the hash value of the third certificate, the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
[0138] For example, the first certificate and the second certificate are associated certificates, and the information of the third certificate is the hash value of the third certificate. The hash value of the third certificate is calculated by the certificate authentication device after issuing the third certificate.
[0139] The first and second certificates are paired certificates. The information in the third certificate includes its serial number, public key, signature value, and / or signature algorithm. This information is extracted from the third certificate itself.
[0140] It should be understood that the reference in this application to updating the second certificate based on the information of the third certificate in order to issue the fourth certificate specifically refers to including the information of the third certificate in the fourth certificate.
[0141] In some possible implementations, updating the first certificate to obtain the third certificate includes: issuing the third certificate based on the public key of the third certificate; updating the second certificate based on the information of the third certificate to issue the fourth certificate includes: issuing the fourth certificate based on the information of the third certificate and the public key of the fourth certificate.
[0142] In some possible implementations, determining the second certificate of the first entity based on the first certificate includes: determining the second certificate according to the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0143] For example, the first certificate and the second certificate are associated certificates. The second certificate contains the hash value of the first certificate to bind to the first certificate. The information in the second certificate includes the hash value of the first certificate. The first entity can determine the second certificate based on the hash value of the first certificate contained in the second certificate.
[0144] For example, the first certificate and the second certificate are paired certificates. The second certificate contains information that differs from the first certificate (i.e., the serial number, public key, signature value, and / or signature algorithm of the first certificate, etc.). The information in the second certificate includes, but is not limited to, at least one of the following: the serial number, public key, signature value, and / or signature algorithm of the first certificate. The first entity can determine the second certificate based on the serial number, public key, signature value, and / or signature algorithm of the first certificate contained in the second certificate.
[0145] In some possible implementations, determining the second certificate of the first entity based on the first certificate includes: determining the second certificate based on the correspondence between the first certificate and the storage.
[0146] Optionally, the method further includes: the first entity can store the correspondence between the first certificate and the second certificate;
[0147] For example, the stored correspondence may refer to a list of associations between the first certificate and the second certificate. Alternatively, the list of stored correspondences may refer to a list of pairings between the first certificate and the second certificate. Alternatively, the correspondence between the first certificate and the second certificate may be represented in other ways, which are not specifically limited in this embodiment.
[0148] This application does not specifically limit the correspondence between the first certificate and the second certificate.
[0149] It should be noted that the correspondence between the first certificate and the second certificate may be stored before the first certificate determines the second certificate of the first entity. Alternatively, the correspondence between the first certificate and the second certificate may be determined before the first entity determines that the first certificate is the certificate to be processed. This application embodiment does not specifically limit the storage time of the correspondence between the first certificate and the second certificate.
[0150] In some possible implementations, the method further includes sending a third response message, which includes a third certificate and a fourth certificate used for federated authentication of the first entity.
[0151] In this implementation, after the certificate authentication device updates the first certificate and the second certificate, it sends the updated first certificate (third certificate) and the updated second certificate (fourth certificate) to the first entity.
[0152] In some possible implementations, the third response message may also include: a second federated certificate instruction, which instructs the third and fourth certificates to be used for federated authentication of the first entity.
[0153] In this implementation, the certificate authentication device indicates to the first entity that the updated first certificate (third certificate) and the updated second certificate (fourth certificate) are associated, that is, the third certificate and the fourth certificate are used to jointly authenticate the first entity.
[0154] In some possible implementations, the third certificate and the fourth certificate are used to perform joint authentication of the first entity, including: a first signature algorithm corresponding to the third certificate and a second signature algorithm corresponding to the fourth certificate are used to authenticate the signature of the first entity.
[0155] In some possible implementations, the method further includes: receiving a third federated certificate indication, the third federated certificate indication being used to indicate the existence of a second certificate that federates the first certificate to the first entity.
[0156] In this implementation, the certificate authentication device receives a third joint authentication certificate instruction from the first entity, and determines a second certificate to be jointly authenticated with the first certificate based on the third joint authentication certificate instruction.
[0157] Fourthly, a communication method is provided, the method comprising: when a first certificate of a first entity is pending processing, determining a second certificate of the first entity based on the first certificate, the first certificate and the second certificate being used for joint authentication of the first entity; sending a fifth request message to a certificate authentication device, the fifth request message being used to request an update of the first certificate to obtain a third certificate, the fifth request message including first information of the second certificate, the second certificate being a certificate used for joint authentication of the first entity with the third certificate.
[0158] For example, the communication method can be implemented by a first entity, or by modules, units, processors, circuits, chips or chip systems included in the first entity.
[0159] The method provided in this application, when the first certificate needs to be processed, determines whether there is a second certificate jointly authenticated with the first certificate. If there is a second certificate jointly authenticated with the first certificate, the first entity requests the certificate authentication device to process the first certificate and carry the first information of the second certificate, so that the updated first certificate (third certificate) includes the certificate information used to jointly authenticate the first entity with the third certificate. That is, the method can bind the updated first certificate to the second certificate, so that it can adapt to the post-quantum migration without triggering the synchronous update or revocation of the two certificates.
[0160] In some possible implementations, determining the second certificate of the first entity based on the first certificate includes: determining the second certificate according to the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0161] For example, the first certificate and the second certificate are associated certificates, and the information in the second certificate includes the hash value of the first certificate. The first entity can determine the second certificate based on the hash value of the first certificate contained in the second certificate.
[0162] For example, the first certificate and the second certificate are paired certificates. The information in the second certificate includes: the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate. The first entity can determine the second certificate based on the serial number, public key, signature value, and / or signature algorithm of the first certificate contained in the second certificate.
[0163] In some possible implementations, determining the second certificate of the first entity based on the first certificate includes: determining the second certificate based on the correspondence between the first certificate and the storage.
[0164] Optionally, the method further includes: the first entity can store the correspondence between the first certificate and the second certificate;
[0165] For example, the stored correspondence may refer to a list of associations between the first certificate and the second certificate. Alternatively, the list of stored correspondences may refer to a list of pairings between the first certificate and the second certificate. Alternatively, the correspondence between the first certificate and the second certificate may be represented in other ways, which are not specifically limited in this embodiment.
[0166] This application does not specifically limit the correspondence between the first certificate and the second certificate.
[0167] It should be noted that the correspondence between the first certificate and the second certificate may be stored before the first certificate determines the second certificate of the first entity. Alternatively, the correspondence between the first certificate and the second certificate may be determined before the first entity determines that the first certificate is the certificate to be processed. This application embodiment does not specifically limit the storage time of the correspondence between the first certificate and the second certificate.
[0168] In some possible implementations, the first information of the second certificate includes at least one of the following: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, the signature value of the second certificate, the signature algorithm of the second certificate, or the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0169] For example, the first certificate and the second certificate are associated certificates. The first information of the second certificate is: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, or the signature of the private key of the second certificate against at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate, etc.
[0170] It should be noted that the first information of the second certificate may not include the public key of the second certificate. After obtaining the second certificate through its serial number and location information, the public key of the second certificate can be extracted.
[0171] The serial number and location information of the second certificate can be used by the authentication device to obtain the second certificate; the private key of the second certificate is signed with at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate, which can be used by the certificate authentication device to determine that the sender of the fifth request message has a certificate (i.e., the second certificate) corresponding to the above information. If the second certificate is indeed possessed, the certificate authentication device will bind the second certificate to the third certificate.
[0172] For example, the first certificate and the second certificate are paired certificates. The first information of the second certificate is: the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, the signature algorithm of the second certificate, etc.
[0173] The serial number, public key, signature value, and / or signature algorithm of the second certificate are information that distinguishes the second certificate from the third certificate. These information can be used to reconstruct the second certificate, allowing the certificate authentication device to verify its signature value using the reconstructed certificate and the public key of the second certificate, thus validating the second certificate's legitimacy. After successful verification, this information, distinguishing the second certificate from the third certificate, can be included in the third certificate.
[0174] In some possible implementations, the method further includes: receiving a fourth response message, the fourth response including a third certificate, wherein the information in the third certificate used for federated authentication of the first entity with the third certificate is second information of the second certificate.
[0175] In some possible implementations, the second information of the second certificate is at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0176] For example, the first certificate and the second certificate are associated certificates, and the second information of the second certificate is the hash value of the second certificate.
[0177] For example, the first certificate and the second certificate are paired certificates, and the second information of the second certificate is: the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, and / or the signature algorithm of the second certificate, etc.
[0178] Fifthly, a communication method is provided, the method comprising: receiving a fifth request message, the fifth request message being used to request the update of a first certificate of a first entity, the fifth request message including first information of a second certificate, the first certificate and the second certificate being used for joint authentication of the first entity; updating the first certificate according to the first information of the second certificate to obtain a third certificate of the first entity, the second certificate being a certificate used for joint authentication of the first entity with the third certificate.
[0179] For example, the communication method can be implemented by a certificate authentication device, or by modules, units, processors, circuits, chips or chip systems included in the certificate authentication device.
[0180] The method provided in this application involves a certificate authentication device updating the first certificate based on the first information of the second certificate carried by the first entity when requesting the processing of the first certificate. This update results in the first certificate (third certificate) including information of the certificate used for joint authentication of the first entity with the third certificate. In other words, this method allows the updated first certificate to be associated with the second certificate, thus enabling adaptation to post-quantum migration without triggering the synchronous update or revocation of the two certificates.
[0181] In some possible implementations, the third certificate contains information about the certificate used for joint authentication of the first entity with the third certificate, and the information about the certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0182] In some possible implementations, the method further includes: receiving an authentication request message carrying a third certificate of a first entity and a second certificate of the first entity; verifying the second certificate of the first entity based on information in the third certificate of the first entity, wherein the information in the third certificate is information about a certificate used for joint authentication of the first entity with the third certificate; and, if the verification is successful, using the third certificate and the second certificate for joint authentication of the first entity, wherein the second certificate contains information about a certificate used for joint authentication of the first entity with the second certificate, and the certificate used for joint authentication of the first entity with the second certificate is the first certificate.
[0183] In this implementation, the updated first certificate (third certificate) is bound to the second certificate. If the second certificate of the first entity is verified to be valid based on the information in the third certificate of the first entity, the third certificate and the second certificate can jointly authenticate the first entity without verifying the second certificate again. Even if the second certificate is verified and the verification fails, the third certificate can still jointly authenticate the first entity with the second certificate.
[0184] In some possible implementations, the method further includes: verifying the first entity's first certificate based on information in the second certificate, and, if verification fails, verifying the first entity's second certificate based on information in the first entity's third certificate.
[0185] In this implementation, the certificate authentication device can perform multiple verifications. That is, the certificate authentication device can verify the first certificate of the first entity based on the information of the first certificate in the second certificate. If the verification fails, it can verify the second certificate of the first entity based on the information of the third certificate of the first entity. If the verification is successful, the third certificate and the second certificate are used to jointly authenticate the first entity. In other words, one-way verification is sufficient.
[0186] In some possible implementations, the first information of the second certificate includes at least one of the following: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, the signature value of the second certificate, the signature algorithm of the second certificate, or the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0187] Optionally, if the first certificate and the second certificate are associated certificates, the first information of the second certificate may be: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, and / or the signature of the private key of the second certificate against at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0188] It should be understood that the first information of the second certificate includes information used to obtain the second certificate and information used to verify the second certificate.
[0189] The information used to obtain the second certificate in the first information of the second certificate may be the serial number and / or the location information of the second certificate. The information used to verify the second certificate in the first information of the second certificate may be the public key of the second certificate, the signature of the private key of the second certificate against at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0190] Optionally, the first information of the second certificate may not include the public key of the second certificate. After obtaining the second certificate through its serial number and location information, the public key of the second certificate can be extracted. This public key can then be used to verify the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate. If the verification is successful, the second and third certificates can be used for joint authentication of the first entity.
[0191] Optionally, when the first information of the second certificate includes the public key of the second certificate, the signature of the private key of the second certificate against at least one of the following is verified using the public key included in the first information of the second certificate: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate. If the verification is successful, the second certificate and the third certificate can be used to perform joint authentication of the first entity.
[0192] When the first certificate and the second certificate are paired certificates, the first information of the second certificate may be: the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, and / or the signature algorithm of the second certificate.
[0193] Optionally, the first information of the second certificate includes information indicating that the second certificate and the third certificate are different. For example, this different information may be the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate. Of course, the first information of the second certificate may also include other information that distinguishes the second certificate from the third certificate; this embodiment of the application does not specifically limit this.
[0194] For example, the serial number, public key, signature value, and / or signature algorithm of the second certificate are information that distinguishes the second certificate from the third certificate. This information can be used to reconstruct the second certificate, allowing the certificate authentication device to verify its signature value using the reconstructed certificate and the public key of the second certificate, thereby verifying the legitimacy of the second certificate. After successful verification, this information, which distinguishes the second certificate from the third certificate, can be included in the third certificate.
[0195] In some possible implementations, the method further includes sending a fourth response message, the fourth response including a third certificate, wherein the information in the third certificate used for federated authentication of the first entity with the third certificate is the second information of the second certificate.
[0196] In some possible implementations, the second information of the second certificate includes at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0197] For example, the first certificate and the second certificate are associated certificates, and the second information of the second certificate is the hash value of the second certificate.
[0198] For example, the first certificate and the second certificate are paired certificates. The second information of the second certificate is: the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, and / or the signature algorithm of the second certificate, etc.
[0199] In some possible implementations, the third certificate contains information about a certificate used for joint authentication of the first entity with the third certificate, wherein the information about the certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0200] It should be understood that the certificate information in the third certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0201] A sixth aspect provides a communication method, the method comprising: receiving an authentication request message, the authentication request message carrying a third certificate of a first entity and a second certificate of the first entity; verifying the second certificate of the first entity based on information in the third certificate of the first entity, the information in the third certificate being information of a certificate used for joint authentication of the first entity with the third certificate; and, if the verification is successful, performing joint authentication of the first entity based on the third certificate and the second certificate.
[0202] For example, the communication method can be implemented by a second entity, or by modules, units, processors, circuits, chips or chip systems included in the second entity.
[0203] The method provided in this application allows the second entity to receive a second certificate and a third certificate sent by the first entity when the first entity and the second entity perform identity authentication based on certificates. When the information in the third certificate of the first entity verifies the second certificate of the first entity and the verification is successful, the second entity can perform joint authentication of the first entity based on the second certificate and the third certificate. Even if the information in the first certificate in the second certificate verifies the first certificate of the first entity and the verification fails, the second entity can still perform joint authentication of the first entity based on the second certificate and the third certificate.
[0204] In some possible implementations, the second certificate contains information about a certificate used for joint authentication of the first entity with the second certificate, wherein the certificate used for joint authentication of the first entity with the second certificate is the first certificate.
[0205] In some possible implementations, the method further includes: verifying the first certificate of the first entity based on the information of the first certificate in the second certificate, and, if the verification fails, verifying the second certificate of the first entity based on the information of the third certificate of the first entity.
[0206] In this implementation, the certificate authentication device can perform multiple authentications. That is, the certificate authentication device can verify the first certificate of the first entity based on the information of the first certificate in the second certificate. If the verification fails, it can verify the second certificate of the first entity based on the information of the third certificate of the first entity. If the verification is successful, the third certificate and the second certificate are used to jointly authenticate the first entity. In other words, one-way verification is sufficient.
[0207] In some possible implementations, the information in the third certificate used for joint authentication of the first entity with the third certificate includes at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0208] For example, the first certificate and the second certificate are associated certificates, and the information in the third certificate used to perform federated authentication of the first entity with the third certificate is the hash value of the second certificate.
[0209] For example, the first certificate and the second certificate are paired certificates. The information in the third certificate used to perform joint authentication of the first entity with the third certificate includes: the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, and / or the signature algorithm of the second certificate, etc.
[0210] A seventh aspect provides a communication apparatus comprising: a module (e.g., including a processing module and a communication module) for performing the steps of the first aspect or any possible implementation thereof; or a module for performing the steps of the second aspect or any possible implementation thereof; or a module for performing the steps of the third aspect or any possible implementation thereof; or a module for performing the steps of the fourth aspect or any possible implementation thereof; or a module for performing the steps of the fifth aspect or any possible implementation thereof; or a module for performing the steps of the sixth aspect or any possible implementation thereof.
[0211] Eighthly, a communication apparatus is provided, the apparatus comprising at least one processor, the at least one processor being configured to execute: the method of the first aspect or any possible implementation thereof, or the method of the second aspect or any possible implementation thereof, or to execute the method of the second aspect or any possible implementation thereof, or to execute the method of the third aspect or any possible implementation thereof, or to execute the method of the fourth aspect or any possible implementation thereof, or to execute the method of the fifth aspect or any possible implementation thereof, or to execute the method of the sixth aspect or any possible implementation thereof.
[0212] In one possible implementation, the communication device may further include a memory storing a computer program. At least one processor executes the method of the first aspect or any possible implementation thereof by executing the computer program stored in the memory, or executes the method of the second aspect or any possible implementation thereof, or executes the method of the third aspect or any possible implementation thereof, or executes the method of the fourth aspect or any possible implementation thereof, or executes the method of the fifth aspect or any possible implementation thereof. Optionally, the processor and the memory may be integrated together, or the processor may be used to execute the method of the sixth aspect or any possible implementation thereof.
[0213] In one possible implementation, at least one processor executes the method of the first aspect or any possible implementation of the first aspect through logic circuits or processing circuits, or executes the method of the second aspect or any possible implementation of the second aspect, or executes the method of the third aspect or any possible implementation of the third aspect, or executes the method of the fourth aspect or any possible implementation of the fourth aspect, or executes the method of the fifth aspect or any possible implementation of the fifth aspect, or executes the method of the sixth aspect or any possible implementation of the sixth aspect.
[0214] In one possible implementation, the communication device may further include an interface circuit for performing specific signal transmission and reception. For example, the communication device may be a first entity, a component within the first entity (a chip, chip system, or processor), or a logic module or software capable of implementing all or part of the terminal functions.
[0215] For example, the communication device can be a certificate authentication device, a component (chip, chip system, or processor) in the certificate authentication device, or a logical node, logical module, or software that can realize all or part of the functions of a network device.
[0216] Ninthly, a computer program product is provided, comprising a computer program that, when executed by a processor, performs the method of the first aspect or any possible implementation thereof; or performs the method of the second aspect or any possible implementation thereof; or performs the method of the third aspect or any possible implementation thereof; or performs the method of the fourth aspect or any possible implementation thereof; or performs the method of the fifth aspect or any possible implementation thereof; or performs the method of the sixth aspect or any possible implementation thereof.
[0217] In a tenth aspect, a computer-readable storage medium is provided, which stores a computer program that, when executed, performs the method of the first aspect or any possible implementation thereof; or performs the method of the second aspect or any possible implementation thereof; or performs the method of the third aspect or any possible implementation thereof; or performs the method of the fourth aspect or any possible implementation thereof; or performs the method of the fifth aspect or any possible implementation thereof; or performs the method of the sixth aspect or any possible implementation thereof.
[0218] Eleventhly, a chip is provided, comprising: a processor for calling and running a computer program from a memory, causing a communication device on which the chip is installed to execute a method for performing the first aspect or any possible implementation of the first aspect; or for performing the second aspect or any possible implementation of the second aspect; or for performing the third aspect or any possible implementation of the third aspect; or for performing the fourth aspect or any possible implementation of the fourth aspect; or for performing the fifth aspect or any possible implementation of the fifth aspect; or for performing the sixth aspect or any possible implementation of the sixth aspect.
[0219] In a twelfth aspect, a communication system is provided, comprising the first entity, the second entity, and / or a certificate authentication device described above. The first entity is configured to perform the methods described in the first aspect or any possible implementation thereof, or to perform the methods described in the fourth aspect or any possible implementation thereof. The second entity is configured to perform the methods described in the sixth aspect or any possible implementation thereof. The certificate authentication device is configured to perform the methods described in the second aspect or any possible implementation thereof, or to perform the methods described in the third aspect or any possible implementation thereof, or to perform the methods described in the fifth aspect or any possible implementation thereof. Attached Figure Description
[0220] Figure 1 This diagram illustrates the certificate issuance process applied by the IETF to network elements in 3GPP.
[0221] Figure 2 A schematic interactive diagram of an example communication method provided in an embodiment of this application is shown.
[0222] Figure 3A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0223] Figure 4 A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0224] Figure 5 A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0225] Figure 6 A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0226] Figure 7 A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0227] Figure 8 A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0228] Figure 9 A schematic interactive diagram of another communication method provided in an embodiment of this application is shown.
[0229] Figure 10 A schematic block diagram of a communication device provided in an embodiment of this application is shown.
[0230] Figure 11 A schematic block diagram of another communication device provided in an embodiment of this application is shown. Detailed Implementation
[0231] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0232] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long-term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, and other future communication systems. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems. The technical solutions provided in this application are also applicable to networks that facilitate communication between entities, such as the Internet, the World Wide Web, and other similar networks.
[0233] A public land mobile network (PLMN) is a network established and operated by a government or its approved operators for the purpose of providing land mobile communication services to the public. It is primarily a public network used by mobile network operators (MNOs) to provide mobile broadband access services to users. The PLMN described in this application embodiment can specifically be a network conforming to the 3GPP (3rd Generation Partnership Project) standard, or simply a 3GPP network. 3GPP networks typically include, but are not limited to, 5G networks, fourth-generation (4G) mobile communication networks, and other future communication systems, such as (6th-generation, 6G) networks. Of course, it can also be other communication networks; this application embodiment does not specifically limit this.
[0234] Before introducing the communication method provided in this application, the relevant background technology will be explained in detail.
[0235] 1. PKI Public Key Infrastructure
[0236] Asymmetric cryptography, also known as public-key cryptography, is a type of cryptography that uses the trapdoor one-way function principle to design cryptographic algorithms where the encryption key is public and the decryption key is kept secret. The encryption key is called the public key, and the decryption key is called the private key. Asymmetric cryptography can be used to achieve various functions such as asymmetric encryption, digital signatures, and key negotiation.
[0237] Digital signature algorithms are frequently used for authentication and integrity protection. A digital signature algorithm consists of a signing algorithm and a verification algorithm. Given a public-private key pair (pk, sk), the signing algorithm uses the private key sk and the message m to calculate the digital signature value sig corresponding to message m. The verification algorithm uses the public key pk and the digital signature value sig to calculate the result, indicating whether the verification passes (usually returning 1) or fails (usually returning 0).
[0238] Public Key Infrastructure (PKI) is an infrastructure that provides security services using asymmetric cryptography theory and techniques. The main function of PKI is to bind the identity of the certificate holder to the associated key pair (by issuing digital certificates for users' public keys and related user identity information), providing users with convenient means for certificate application, renewal, revocation, acquisition, and status inquiry. It also utilizes digital certificates and various related services (certificate issuance, blacklist issuance, timestamp services, etc.) to achieve authentication, integrity, non-repudiation, and confidentiality for entities in communication.
[0239] In a PKI system, a Certificate Authority (CA) issues digital certificates, binding the PKI user's identity information and public key. A PKI relying party pre-stores self-signed certificates (i.e., the root certificates of the root CA) of its trusted root CA to verify the certificate chain of the PKI user it communicates with, thereby reliably obtaining the user's public key for various security services. A complete PKI system consists of digital certificates, a Certificate Authority (CA), a certificate repository, a certificate revocation system, a key backup and recovery system, and a PKI application interface system.
[0240] Specifically, a digital certificate is an electronic credential containing a public key used for signing and encrypting data, and is a core element of PKI. A Certificate Authority (CA) is the authority that applies for and issues digital certificates. CAs possess authority, and can also include registration authorities (RAs). RAs are used to obtain and authenticate user identities before submitting certificate issuance requests to the CA. An RA can be integrated into a CA function or deployed independently; this embodiment assumes the CA integrates RA functionality. A certificate repository stores issued digital certificates and public keys, as well as related certificate directories, allowing access to other users' certificates and public keys. A certificate revocation list is a list of certificates revoked within their validity period; the Online Certificate Status Protocol (OCSP) is an international protocol for obtaining certificate status. Key backup and recovery refers to the mechanism provided by PKI to back up and recover keys to prevent users from being unable to decode legitimate data due to lost decryption keys. This is performed by a trusted authority. Furthermore, key backup and recovery can only be performed on decryption keys; signing private keys cannot be backed up. The PKI application interface provides a secure, consistent, and traceable way for various applications to interact with PKI, ensuring the security and reliability of the established network environment and reducing management costs.
[0241] 2.X.509 Certificate
[0242] The X.509 certificate standard specifies what information a certificate can contain and describes the methods for recording that information. Existing technical documents (e.g., RFC 5280) define the relevant certificate profiles. An X.509 certificate includes the following information: certificate information (tbsCertificate), signature algorithm (signatureAlgorithm), and signature value (signatureValue). The certificate information primarily includes one or more of the following: certificate version (version), certificate serial number (serialNumber), signature algorithm identifier (signature), certificate issuer (issuer), certificate validity (validity), certificate subject (subject), certificate subject's public key (subjectPublicKeyInfo), certificate issuer unique ID (issuerUniqueID), certificate subject unique ID (subjectUniqueID), and certificate extensions.
[0243] The certificate version identifies the version of the X.509 standard used for the certificate, which can affect the information specified in the certificate. To date, three versions have been defined. The serial number is assigned by the issuing entity to distinguish the certificate from other certificates issued by that entity. This information has many uses; for example, if a Certificate Revocation List (CRL) mechanism is used for revocation, if a certificate is revoked, its serial number will be added to the CRL. Note that if other revocation or certificate status mechanisms are provided, a compliant CA-issued CRL is not required. The signature algorithm identifier identifies the algorithm used by the CA when signing the certificate. The issuer name is the X.500 name of the entity that issued the certificate. It is usually a CA. Using this certificate means trusting the entity that issued it (note: in some cases (e.g., root or top-level CA certificates), the issuer will sign their own certificates). The subject name is the entity name that identifies the certificate's public key. The subject public key information is the public key of the certificate subject, including the algorithm identifier specifying the public key cryptosystem to which the key belongs and all relevant key parameters. The certificate validity period is the time period during which the certificate is valid; after this period, the certificate expires. A certificate signature refers to the digital signature information of the certificate issued by the CA using its private key. Certificate extension options refer to optional extension options for the certificate used to enhance its functionality or identity.
[0244] Issuing a digital certificate by a certificate authority refers to the certificate authority using the private key corresponding to its root certificate and the corresponding signature algorithm (the identifier of the signature algorithm is signatureAlgorithm) to digitally sign the certificate information (tbsCertificate), obtain the signature value (signatureValue), and combine the certificate information, the corresponding signature algorithm identifier, and the signature value into the corresponding certificate file.
[0245] 3. Post-quantum cryptography transfer
[0246] With the continuous development of quantum computing technology, traditional cryptographic algorithms may face threats from quantum computers. For example, asymmetric cryptographic algorithms may be cracked, and the bit strength of symmetric cryptographic algorithms may be halved. To address the threat of quantum computers, a post-quantum cryptography migration is necessary. NIST solicited post-quantum cryptographic algorithms in 2016, conducted multiple rounds of selection, and officially released three post-quantum cryptographic algorithm standards in August 2024, including one encryption algorithm and two signature algorithms.
[0247] Cryptographic security protocols use cryptographic algorithms to protect the security of two or more interacting parties. To address the threat of quantum computers, post-quantum migration is necessary, incorporating corresponding post-quantum cryptographic algorithms into the cryptographic protocols. However, because post-quantum algorithms have not yet undergone large-scale commercial testing, there is a lack of confidence in them. Therefore, the industry currently tends to use a hybrid mechanism, employing both traditional and post-quantum cryptographic algorithms.
[0248] As an example: When using a hybrid mechanism, hybrid authentication scenarios require the use of two algorithms for digital signatures. For instance, a combined signature can be achieved using two algorithms, such as digital signature algorithm 1 and digital signature algorithm 2. Specifically, digital signature algorithm 1 and private key 1 are used to sign the message m to obtain sub-signature 1, and digital signature algorithm 2 and private key 2 are used to sign the message m to obtain sub-signature 2. Sub-signature 1 and sub-signature 2 are concatenated to obtain the combined signature. Here, private key 1 is the private key in the public-private key pair corresponding to digital signature algorithm 1, and private key 2 is the private key in the public-private key pair corresponding to digital signature algorithm 2.
[0249] Optionally, the signature message m includes identifiers of two signature algorithms. Of course, the two signature algorithms can also be other combinations, and this application embodiment does not specifically limit this.
[0250] Therefore, in hybrid authentication scenarios, the form of the corresponding digital certificate may change. For example, two digital certificates with different algorithms can be used, or a single digital certificate can carry public key information for multiple different algorithms.
[0251] It should be understood that federated authentication of an entity can be performed using at least two bound certificates. These two bound certificates can be associated certificates or paired certificates. Of course, two certificates can also be bound in other ways, and this application embodiment does not limit this.
[0252] An example of the application and issuance scheme for associated and paired certificates in a hybrid authentication scenario is as follows:
[0253] 1. Application and issuance of related certificates
[0254] When a network element already possesses a certificate, and a request for another certificate is made, the IETF draft defines a new CSR request attribute: Related Cert Request, and a new X.509 certificate extension: Related Certificate. The new CSR request is used to request a certificate that includes the new extension; the requested certificate and the certificate in the extension belong to the same entity.
[0255] The newly defined attributes and extended items are as follows:
[0256] (1) Related Cert Request attribute
[0257] This attribute is carried in the Certificate Request Message (CSR) and is therefore included in the CSR sent to the Certificate Authority. The specific syntax is requesterCertificate, which includes four items: certID (representing the serial number of the certificate already owned by the requester), requestTime (the time of the current request, to ensure freshness), locationInfo (pointing to the location of the certificate already owned by the requester, such as a URL), and signature (a signature value obtained by signing the certificate serial number and request time using the private key of the already owned certificate).
[0258] (2) RelatedCertificate extension option for X.509 certificates
[0259] If a certificate contains this extended option, it means that the certificate is associated with another certificate, and the hash value of the associated certificate is included in the extended option.
[0260] Therefore, when applying for a certificate, the following verification is required: If a node expresses its intention to use a non-hybrid authentication mode via the protocol (e.g., during the negotiation phase) and receives the corresponding authentication data, it should verify the entity certificate to check for the Related Certificate extension. If a certificate has the RelatedCertificate extension option, the hash value of the other certificate is calculated, and this hash value is verified to be the same as the value in the RelatedCertificate extension option. The hash algorithm used is the same as the hash algorithm used in the signature algorithm of this extension option.
[0261] Figure 1 This diagram illustrates the certificate issuance process applied by the IETF to network elements in 3GPP, such as... Figure 1 As shown, the process for the network element (NF) to apply for a second certificate (cert2) from the operator's CA is as follows:
[0262] Step 1: NF generates a new public-private key pair (sk2, pk2) and generates a Certificate Request Message (CSR), which carries the public key pk2 and related certificate request attributes. Specifically, it carries the cert1 ID, requestTime, cert1's locationInfo, and a signature (signature1) using the private key pair cert1ID and requestTime.
[0263] Step 2: After receiving the corresponding certificate application message, the CA finds that it carries relevant certificate application attributes, extracts the cert1ID and locationInfo carried in the attributes, obtains the corresponding certificate cert1 based on the locationInfo, and compares its certificate serial number with the cert1ID carried in the attributes. If they are the same, the public key of the certificate is used to verify the signature value signature1. If the verification passes, a certificate with public key pk2 is issued to the NF, and a RelatedCertificate extension option is added to the extension options of the certificate. The RelatedCertificate extension option carries the hash value of the cert1 certificate.
[0264] Step 3: The CA sends a certificate request response message to the NF.
[0265] Step 4: When NF receives the certificate response message, NF requests a second certificate, cert2, and associates cert2 with cert1.
[0266] In the specific communication process, the above-mentioned hybrid signature and associated certificate are used as follows: Entity 1 and Entity 2 communicate with each other. The entities may need to perform identity authentication. When Entity 1 uses certificates and hybrid signatures for identity authentication, Entity 1 sends two associated certificates, Certificate 1 and Certificate 2, and a combined signature issued using the private keys of the two certificates to Entity 2. After receiving the two associated certificates, Entity 2 first verifies the correlation between the two certificates, that is, verifies that Certificate 2 contains the hash value of Certificate 1. Then, it uses the two certificates and the corresponding signature algorithm to verify the corresponding part of the signature. If the verification is successful, it means that the identity authentication is successful.
[0267] Based on the above introduction, it can be considered that digital certificate one and digital certificate two are associated certificates, meaning that digital certificate one and digital certificate two belong to the same entity (same subject), and digital certificate two contains the hash value of digital certificate one to establish the association relationship between digital certificate one and digital certificate two. Furthermore, digital certificate one and digital certificate two can be used to perform joint authentication on the entity.
[0268] For example, using digital certificate one and digital certificate two to perform joint authentication of the first entity can refer to authenticating the entity's signature using the first signature algorithm corresponding to digital certificate one and the second signature algorithm corresponding to digital certificate two.
[0269] For example, the entity's signature includes sub-signature 1 and sub-signature 2. Sub-signature 1 of the entity's signature is verified using the public key corresponding to digital certificate 1 and the corresponding first signature algorithm. Sub-signature 2 of the entity's signature is verified using the public key corresponding to digital certificate 2 and the second signature algorithm. If both verifications pass, the entity is considered to be authenticated.
[0270] Sub-signature 1 is the private key signature corresponding to digital certificate 1, and sub-signature 2 is the private key signature corresponding to digital certificate 2.
[0271] 2. Application and issuance of paired certificate
[0272] The two paired certificates are a base certificate and a delta certificate. The base certificate contains its own fields and extensions, and additionally includes a DeltaCertificateDiscriptor extension. This extension contains information that differs from the base certificate in the paired delta certificate. For example, this extension may include: the serial number, public key information, and signature value of the delta certificate. Optionally, it may also include the signature algorithm, issuer, validity period, and subject name.
[0273] Basic certificates and incremental certificates can be applied for separately or together. If the basic certificate and incremental certificate are applied for separately, you need to apply for the incremental certificate first, and then apply for the basic certificate. When applying for the basic certificate, you need to include information about the delta certificate request in the Certificate Request Message (CSR), which contains information that distinguishes the delta certificate from the basic certificate.
[0274] If a basic certificate and an incremental certificate are requested simultaneously, a PKCS#10 certificate request message can be sent. The main request content is information about the basic certificate, along with two new certificate request attributes: the deltacertificate request attribute and the delta certificate request signature attribute. The delta certificate request attribute contains information such as the incremental certificate's public key (subjectPublicKeyInfo), signature algorithm (signature), subject name (subject), and extensions. The delta certificate request signature attribute contains the signature value used to sign the certificate request message using the incremental certificate's private key. Upon receiving the request message, the CA uses the incremental certificate's public key to verify the signature value used to sign the certificate request message. Based on these two attributes and other information in the request message, it constructs the X.509 certificate content for the delta certificate, thereby issuing the corresponding incremental and basic certificates. In practical use, receiving a basic certificate allows for the reconstruction of the corresponding incremental certificate, reducing communication load during operation.
[0275] The common feature of associated certificates and paired certificates is that one certificate contains information about the other, thus establishing a binding relationship between the two certificates. This allows for joint authentication of the entity using the two bound certificates. Before joint authentication, the binding relationship needs to be verified or the corresponding certificates need to be reconstructed. In other words, joint authentication of the entity can be performed using two bound certificates. These two bound certificates can be called associated certificates or paired certificates. Of course, two certificates can be bound in other ways, and this application embodiment does not limit this.
[0276] Certificate renewal and revocation are involved in all current IETF certificate management protocols. In related technologies, certificate renewal generally adopts the following method: Before the certificate is about to expire, the entity sends a certificate renewal request to the CA. Specifically, the message format of the certificate renewal request is the same as that of the certificate application message, and the content of the certificate renewal request message is signed with the private key of the old certificate that is about to expire. After signing with the private key, it is sent to the CA. The CA verifies the signature. If the verification is successful, the CA issues a new certificate to the entity.
[0277] Certificate updates are divided into key updates and expiration updates. Key updates are more common, generating a new public-private key pair while updating the certificate, and using the new public key as the public key of the updated certificate. Expiration updates are less common and have slightly weaker security; they only update the certificate's expiration date without updating the corresponding public key.
[0278] Certificate revocation generally involves different methods such as CRL and OSCP:
[0279] Various circumstances may cause a certificate to expire before its validity period, such as name change, change of association between the subject and the CA (e.g., employee termination of employment with the organization), and leakage or suspected leakage of the corresponding private key. In these cases, the CA needs to revoke the certificate.
[0280] X.509 defines a certificate revocation method whereby each CA periodically publishes signed data called a Certificate Revocation List (CRL). A CRL is a timestamped list identifying revoked certificates signed by the CA or CRL issuer and freely available in a public repository. Each revoked certificate is identified in the CRL by its certificate serial number. When a system using a certificate uses the certificate (e.g., to verify the digital signature of a remote user), the system not only checks the certificate signature and validity but also retrieves the appropriate, up-to-date CRL and checks if the certificate serial number is not on that CRL. The meaning of "appropriately up-to-date" may vary depending on the policy, but it generally refers to the most recently published CRL. New CRLs are published periodically (e.g., hourly, daily, or weekly). After a revocation notice, an entry is added to the CRL as part of the next update. An entry may not be removed from the CRL until it appears on a periodically scheduled CRL after the revoked certificate's expiration date.
[0281] The CRL method has several drawbacks. First, CRLs cannot be updated in real time. Since CAs only issue CRLs periodically, they cannot reflect the certificate status promptly, limiting security. Second, even regular CRL updates are problematic. When the number of revoked certificates is large and the user base is extensive, the CRL often grows very large. Each CRL distribution consumes significant network bandwidth and server processing power. For many cluster customers (such as a bank and its numerous customers, or a large enterprise and its subsidiaries and distributors), to improve certificate validity verification efficiency, they often download the CRL to their own servers first to reduce online CRL queries. However, frequent CRL downloads are also a headache for users. Sometimes, this CRL processing method also requires users to configure client PCs to handle CRLs from multiple certificate authorities.
[0282] Therefore, another method for managing and querying certificate validity, namely the online query mechanism, emerged. The protocol it uses is called the Online Certificate Status Protocol (OCSP).
[0283] The Online Certificate Status Protocol (OCSP) is an IETF standard for verifying the validity of digital certificates at a given time during a transaction, described in RFC 2560. It provides online businesses with a way to verify the validity of digital certificates, offering a faster, more convenient, and more independent approach than the traditional method of downloading and processing Certificate Revocation Lists (CRLs). OCSP provides users with certificate status in real-time online, resulting in significantly faster processing than CRLs and avoiding headaches from logical problems and processing overhead.
[0284] When performing a post-quantum migration using the IETF's current associated or paired certificates, if Certificate 2 references Certificate 1, and Certificate 1 is updated or revoked, the use of Certificate 2 will be affected. For example, if Certificate 2 is valid but Certificate 1 has been updated, Certificate 2 will attempt to verify the hash value of Certificate 1. Because Certificate 1 has been updated (i.e., its hash value has changed), Certificate 2 will fail to verify the hash, and thus Certificate 2 will be unusable. Similarly, if Certificate 2 is valid but Certificate 1 has expired or been revoked, Certificate 1's verification will fail, and Certificate 2 will also be unusable.
[0285] In summary, when Certificate 1 and Certificate 2 are associated or paired certificates, and Certificate 2 references Certificate 1, how to ensure that Certificate 2 can still be used normally when Certificate 1 is updated or revoked, so as to adapt to quantum migration, is a problem that needs to be solved.
[0286] In view of this, this application provides a communication method, which includes: when a first certificate of a first entity is pending processing, determining a second certificate of the first entity based on the first certificate, wherein the first certificate and the second certificate are used for joint authentication of the first entity; and sending first information requesting processing of the first certificate and second information requesting processing of the second certificate to a certificate authentication device. The method provided by this application, when the first certificate needs processing, allows the first entity to send first information requesting processing of the first certificate and second information requesting processing of the second certificate to the certificate authentication device, enabling the certificate authentication device to process the first certificate and the second certificate used for joint authentication with the first certificate, thereby ensuring that the processed first certificate and second certificate can be adapted for post-quantum migration.
[0287] The communication method provided in the embodiments of this application will be described in detail below.
[0288] The following is combined Figure 2 This application provides a detailed description of an example communication method. Figure 2 A schematic interactive diagram of an example communication method provided in an embodiment of this application is shown.
[0289] like Figure 2 As shown, Figure 2 The method 200 shown may include S210 to S230. The following is in conjunction with... Figure 2 The steps in method 200 are explained in detail.
[0290] S210, if the first certificate of the first entity is pending processing, determine the second certificate of the first entity based on the first certificate, and the first certificate and the second certificate are used to perform joint authentication of the first entity.
[0291] In the application scenario of this application embodiment, the first entity stores multiple digital certificates, wherein the first certificate and the second certificate among the multiple certificates are used to perform joint authentication on the first entity.
[0292] For example, the first entity in this application embodiment may be a network element, application, server, client or other entity that performs identity authentication. This application embodiment does not specifically limit the form of the first entity.
[0293] In some possible implementations, the first certificate can refer to a certificate that does not contain information about the second certificate; that is, the first certificate can refer to a certificate signed based on a traditional cryptographic signature algorithm, or the first certificate can refer to an incremental certificate. The second certificate can refer to a certificate that contains information about the first certificate; that is, the second certificate can refer to a certificate signed based on a post-quantum signature algorithm, or the second certificate can refer to a basic certificate.
[0294] For example, an entity already holds a digital certificate / incremental certificate (first certificate) based on a traditional cryptographic algorithm, and then applies for a certificate / basic certificate (second certificate) based on a post-quantum algorithm. To adapt to hybrid authentication scenarios, the newly applied certificate needs to carry information from the first certificate, associating or pairing it with the previously held first certificate. This allows both certificates to support hybrid authentication mechanisms without affecting the independent use of the digital certificate based on the traditional cryptographic algorithm. This implementation ensures good backward compatibility and adapts to current post-quantum migration scenarios.
[0295] Optionally, the joint authentication of the first entity using the first certificate and the second certificate can be based on a combined signature of the first and second certificates. This combined signature includes sub-signature 1 and sub-signature 2. The first certificate verifies sub-signature 1, and the first certificate verifies sub-signature 2. If both verifications pass, the authentication of the first entity is successful. Of course, other methods can also be used to jointly authenticate the first entity using the first certificate and the second certificate. This application embodiment does not specifically limit the method of joint authentication.
[0296] For example, the joint authentication of the first entity by the first certificate and the second certificate can refer to authenticating the signature of the first entity by using the first signature algorithm corresponding to the first certificate and the second signature algorithm corresponding to the second certificate.
[0297] For example, the signature of the first entity includes sub-signature 1 and sub-signature 2. Sub-signature 1 of the first entity's signature is verified using the public key corresponding to the first certificate and the corresponding first signature algorithm. Sub-signature 2 of the first entity's signature is verified using the public key corresponding to the second certificate and the second signature algorithm. If both verifications pass, the first entity is considered to be authenticated.
[0298] Sub-signature 1 is the private key signature corresponding to the first certificate, and sub-signature 2 is the private key signature corresponding to the second certificate.
[0299] It should be understood that the signature of the first entity can also be in other forms, and the embodiments of this application do not specifically limit the signature form of the first entity.
[0300] For example, the first signature algorithm can be a traditional cryptographic signature algorithm, and the second signature algorithm can be a post-quantum signature algorithm.
[0301] Alternatively, both the first and second signature algorithms can be traditional cryptographic signature algorithms, or they can be post-quantum signature algorithms.
[0302] For example, the first signature algorithm includes a traditional cryptographic signature algorithm, which includes at least one of the following: RSA algorithm, DSA, SM2, or ECDSA algorithm; the second signature algorithm includes a post-quantum signature algorithm, which includes at least one of the following: CRYSTALS-Dilithium, Falcon, SPHINCS+, XMSS, Lamport, SQISign, etc.
[0303] It should be noted that traditional cryptographic signature algorithms may also include other algorithms, and post-quantum signature algorithms may also include other algorithms. This application does not specifically limit these algorithms.
[0304] In some possible implementations, "to be processed" in this application embodiment can refer to "to be updated" or "to be revoked," "request to process the first certificate" can refer to "request to update the first certificate" or "request to revoke the first certificate," and "request to process the second certificate" can refer to "request to update the second certificate" or "request to revoke the second certificate." Of course, the processing of the first and second certificates can also include other methods, which are not specifically limited in this application embodiment.
[0305] When the first entity detects locally that the first certificate is about to expire or needs to be revoked, the first entity checks its local certificates to determine if there is a second certificate that is jointly certified with the first certificate.
[0306] In some possible implementations, the first entity determines the second certificate based on information in the first and second certificates, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the public key of the first certificate, and the signature of the first certificate.
[0307] It should be understood that when the first certificate and the second certificate are bound together, the first certificate and the second certificate can be used to perform joint authentication of the first entity.
[0308] Optionally, the binding of the first certificate and the second certificate can be achieved by associating the first certificate and the second certificate (that is, the first certificate and the second certificate are associated certificates) or by pairing the first certificate and the second certificate (that is, the first certificate and the second certificate are paired certificates). Of course, the binding of the first certificate and the second certificate can also be achieved in other ways. This application embodiment does not limit the binding method of the first certificate and the second certificate.
[0309] For example, the first certificate and the second certificate are associated certificates. The second certificate contains the hash value of the first certificate to bind the first certificate. The first entity can determine the second certificate based on the hash value of the first certificate contained in the second certificate.
[0310] Specifically, the first entity calculates or obtains the hash value of the first certificate based on the first certificate. The first entity checks whether other certificates have the RelatedCertificate extension option, and further checks whether the RelatedCertificate extension option contains the hash value of the first certificate. If a second certificate among multiple certificates includes the RelatedCertificate extension option, and the RelatedCertificate extension option contains the hash value of the first certificate, then it indicates that the second certificate is used to perform federated authentication of the first entity with the first certificate.
[0311] For example, the first certificate and the second certificate are paired certificates. The second certificate contains information that is different from the first certificate (such as the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate). The first entity can determine the second certificate based on the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate contained in the second certificate.
[0312] Specifically, the first entity checks whether other certificates have the DeltaCertificateDiscriptor incremental certificate description extension option, and further checks whether the DeltaCertificateDiscriptor incremental certificate description extension option contains the first certificate's serial number, public key, signature value, etc. If the second certificate among multiple certificates includes the DeltaCertificateDiscriptor extension option, and the DeltaCertificateDiscriptor extension option contains the first certificate's serial number, public key, signature value, etc., then it indicates that the second certificate is used to perform federated authentication of the first entity with the first certificate.
[0313] In some other possible implementations, the first entity stores a list of correspondences between the first certificate and the second certificate, and the first entity can determine the second certificate based on the first certificate and the stored list of correspondences.
[0314] For example, the first certificate and the second certificate are associated certificates. The first entity stores a list of associations between the first certificate and the second certificate. The first entity can determine the second certificate based on the stored list of associations.
[0315] For example, the first certificate and the second certificate are paired certificates. The first entity stores a list of pairing relationships between the first certificate and the second certificate. The first entity can determine the second certificate based on the stored list of pairing relationships.
[0316] It should be noted that the correspondence between the first certificate and the second certificate may be stored before the first certificate determines the second certificate of the first entity. Alternatively, the correspondence between the first certificate and the second certificate may be determined before the first entity determines that the first certificate is the certificate to be processed. This application embodiment does not specifically limit the storage time of the correspondence between the first certificate and the second certificate.
[0317] S220. The first entity sends the first information requesting the processing of the first certificate and the second information requesting the processing of the second certificate to the certificate authentication device.
[0318] In some possible implementations, the processing of the first and second certificates includes updating and revoking. Of course, the processing of the first and second certificates may also include other methods, which are not specifically limited in this embodiment.
[0319] In some possible implementations, the first entity sending a request to the certificate authentication device for processing first information of the first certificate and a request to process second information of the second certificate may refer to the first entity sending a first request message to the certificate authentication device, which carries the first information, and after determining the second certificate of the first entity, the first entity sending a second request message to the certificate authentication device, which carries the second information.
[0320] In this implementation, the first entity can send two messages: a first message requesting the processing of the first certificate and a second message requesting the processing of the second certificate.
[0321] For example, when the request processing is a request to update a first certificate and a request to update a second certificate, the first request message can be a first certificate update request message, and the second request message can be a second certificate update request message. When the request processing is a request to revoke a first certificate and a request to revoke a second certificate, the first request message can be a first certificate revocation request message, and the second request message can be a second certificate revocation request message.
[0322] It should be understood that the first certificate update request message and the second certificate update request message, or the first certificate revocation request message and the second certificate revocation request message sent by the first entity, can be in existing message formats.
[0323] In some other possible implementations, the first entity sending a request to the certificate authentication device for processing the first information of the first certificate and the request for processing the second information of the second certificate may refer to the first entity sending a third request message to the certificate authentication device, the third request message carrying the first and second information.
[0324] In this implementation, the first entity can send a message requesting the processing of the first certificate's first information and the processing of the second certificate's second information.
[0325] For example, when the request is processed as a request to update the first certificate and a request to update the second certificate, the third request message can be a multi-certificate synchronous update request message; when the request is processed as a request to revoke the first certificate and a request to revoke the second certificate, the third request message can be a multi-certificate synchronous revocation request message.
[0326] It should be understood that the specific content of the first and second information in this application can be found in subsequent embodiments, and will not be repeated here.
[0327] S230, Certificate Authentication Equipment processes the first and second certificates.
[0328] Certificate authentication equipment is used to sign certificates. This equipment may also be referred to as a certificate authority, certificate issuing entity, certificate issuing network element, etc., and such naming does not constitute any limitation on the embodiments of this application.
[0329] In this embodiment of the application, the first entity sends first information requesting the processing of the first certificate and second information requesting the processing of the second certificate to the certificate authentication device. The corresponding certificate authentication device processes the first certificate and the second certificate after receiving the first information requesting the processing of the first certificate and the second information requesting the processing of the second certificate.
[0330] For example, after receiving a request to update the first information of a first certificate and a request to update the second information of a second certificate, the certificate authentication device updates the first and second certificates. As another example, after receiving a request to revoke the first certificate and a request to revoke the second certificate, the certificate authentication device revokes both the first and second certificates.
[0331] The method provided in this application embodiment uses a first certificate and a second certificate of a first entity to perform joint authentication of the first entity. The second certificate is determined based on the first certificate. When the first certificate needs to be processed, the first entity sends first information requesting processing of the first certificate and second information requesting processing of the second certificate to the certificate authentication device, so that the certificate authentication device can process the first certificate and process the second certificate that performs joint authentication with the first certificate, thereby enabling the quantum migration after the processed first certificate and second certificate are adapted.
[0332] The following is combined Figure 3 , Figure 4 , Figure 5 The communication method provided in the embodiments of this application is specifically described in response to the first request message, the second request message and the third request message sent by the first entity.
[0333] Figure 3 A schematic interaction diagram illustrating another communication method provided in an embodiment of this application is shown. For example... Figure 3 As shown, Figure 3 The method 300 shown may include S310 to S370. The following is in conjunction with… Figure 3 Detail each step in method 300.
[0334] S310. If the first certificate of the first entity is pending processing, determine the second certificate of the first entity based on the first certificate. The first certificate and the second certificate are used to perform joint authentication of the first entity.
[0335] Step S310 can be referred to step S210, and will not be repeated here.
[0336] S320, The first entity sends a first request message, which carries first information.
[0337] In this embodiment of the application, the first entity sends a first request message to the certificate authentication device, requesting the certificate authentication device to process the first certificate.
[0338] In some possible implementations, when the first certificate needs to be updated, i.e., when the above processing is for updating, the first request message sent by the first entity to the certificate authentication device can be a first certificate update request message. The first information may include at least one of the following: the public key of the third certificate, the first certificate, the serial number of the first certificate, and a signature of the first certificate's private key on the first certificate update request message. The third certificate is obtained by updating the first certificate. The first information is used to request the certificate authentication device to update the first certificate.
[0339] It should be understood that before the first entity sends the public key of the third certificate to the first certificate, the first entity generates a public-private key pair for the third certificate and then sends the public key of the third certificate to the certificate authentication device.
[0340] The first entity generating the public-private key pair of the third certificate can be replaced by the first entity selecting the public-private key pair of the third certificate, or by the first entity determining the public-private key pair of the third certificate.
[0341] Optionally, the signature of the first certificate update request message can be verified using the public key of the first certificate. If the verification is successful, it can prove to the certificate authentication device that the requester of the first request message is indeed the first entity holding the first certificate.
[0342] The public key of the first certificate can be obtained from the first certificate carried in the first information, or it can be obtained from the first certificate after obtaining the corresponding first certificate based on the serial number of the first certificate carried in the first information.
[0343] In some other possible implementations, when the first certificate needs to be revoked, i.e., when the above-described process is revocation, the first entity sends a first request message to the certificate authentication device, which can be a first certificate revocation request message. The first information may include at least one of the following: the serial number of the first certificate, the first certificate, the signature of the first certificate's private key on the first certificate revocation request message.
[0344] The first certificate, or the serial number of the first certificate, is used by the certificate authentication device to obtain the certificate to be revoked. The signature of the first request message by the private key of the first certificate is used by the certificate authentication device to determine that the request message comes from the first entity that owns the first certificate.
[0345] It should be understood that the first information may not include the first certificate itself, but instead include the serial number of the first certificate. This allows the certificate authentication device to locate the corresponding first certificate based on the serial number. For example, the certificate authentication device can search for the first certificate in a stored certificate issuance list based on the serial number. Alternatively, the first information may also omit the serial number of the first certificate and instead include the first certificate itself.
[0346] S330, the certificate authentication device processes the first certificate based on the first request message.
[0347] Accordingly, the certificate authentication device receives the first request message sent by the first entity and processes the first certificate based on the first request message.
[0348] In some possible implementations, when the first certificate needs to be updated, that is, when the above process is an update, the certificate authentication device receives the first request message sent by the first entity as the first certificate update request message. The first information can be referred to the examples and descriptions of the first information in step S320 above, and will not be repeated here.
[0349] The certificate authentication device updates the first certificate based on the first request message, and the updated first certificate becomes the third certificate.
[0350] For example, the certificate authentication device uses the public key in the first certificate to verify the signature of the first certificate update request message using the private key of the first certificate. If the verification is successful, a certificate is signed for the first entity using the public key carried in the first certificate update request message (the public key of the third certificate), i.e., the third certificate. It should be understood that the certificate authentication device obtains the first certificate before verification.
[0351] In this context, the certificate authentication device can obtain the first certificate either by directly extracting it from the first request message or by obtaining the first certificate's serial number. It should be understood that "obtain" here can also be interpreted as "extract," and these two terms can be used interchangeably in this application.
[0352] In one possible implementation, retrieving the first certificate by its serial number means that the certificate authentication device locally stores all the digital certificates it has issued, and the corresponding first certificate can be found by searching based on its serial number.
[0353] In another possible implementation, retrieving the first certificate by its serial number means that all issued digital certificates are uniformly stored in a public certificate list in a fixed location. The certificate authentication device accesses this location and finds the first certificate by its serial number.
[0354] In some other possible implementations, when the first certificate needs to be revoked, that is, when the above process is revocation, the certificate authentication device may receive a first request message from the first entity as a first certificate revocation request message. The first information can be referred to in the examples and descriptions of the first information in step S320 above, and will not be repeated here.
[0355] The certificate authentication device revokes the first certificate based on the first certificate revocation request message.
[0356] For example, the certificate authentication device uses the public key in the first certificate to verify the signature of the first certificate revocation request message. If the verification is successful, the certificate serial number to be revoked (i.e. the serial number of the first certificate) is added to the CRL list, or the status of the corresponding certificate (the first certificate) in the OCSP server is updated to revoked.
[0357] In one possible implementation, the certificate authentication device obtains the first certificate before verifying the signature of the first certificate revocation request message using the public key in the first certificate. For the specific method of obtaining the first certificate, please refer to the method of obtaining the first certificate when the first request message is a first certificate update request message, which will not be repeated here.
[0358] S340, the certificate authentication device sends a first response message, which includes a third certificate, which is an updated version of the first certificate.
[0359] After the certificate authentication device updates the first certificate to the third certificate, it sends a first response message to the first entity, which carries the third certificate.
[0360] It should be noted that step S440 is an optional step, that is, when the first certificate needs to be revoked, the certificate authentication device revokes the first certificate without sending the first response message to the first entity.
[0361] S350, the first entity sends a second request message, which carries second information.
[0362] Based on step S310, the first entity determines that it has a second certificate that is jointly authenticated with the first certificate. Therefore, when the first entity receives the third certificate sent by the certificate authentication device, it sends a second request message to the certificate authentication device. The second request message is used to request the processing of the second certificate and carries second information.
[0363] In some possible implementations, when the second certificate needs to be updated, the second request message sent by the first entity to the certificate authentication device can be a second certificate update request message. The second information may include at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or a signature of the private key of the third certificate on at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; wherein the third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate.
[0364] It should be understood that the second information is used by the certificate authentication device to obtain and jointly authenticate the certificate (i.e., the third certificate) with the updated second certificate, so that it can be bound to the third certificate in the subsequent process of issuing the fourth certificate, thereby enabling the two certificates to be used for joint authentication of the first entity.
[0365] The serial number and location information of the third certificate can be used by the certificate authentication device to obtain the third certificate.
[0366] The serial number, public key, signature value, and signature algorithm of the third certificate can be used by certificate authentication devices to obtain certificate domain information that differs between the third certificate and the updated second certificate (i.e., the fourth certificate).
[0367] The private key of the third certificate is signed with at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate. This can be used to prove to the certificate authentication device that the sender of the second request message does indeed possess the certificate (i.e., the third certificate) corresponding to the above information. If the third certificate is indeed possessed, the certificate authentication device will bind the third certificate to the fourth certificate.
[0368] For example, the first certificate and the second certificate are associated certificates, and the second certificate contains the hash value of the first certificate to bind the first certificate. In this case, the second information may be: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate and / or the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0369] It should be noted that after obtaining the third certificate through its serial number and / or location information, the public key of the third certificate can be extracted.
[0370] In some implementations, the second certificate update request message can use the CSR format. In this case, the second information can be carried in the RelatedCertRequest attribute of the CSR.
[0371] For example, the first certificate and the second certificate are paired certificates. The second certificate contains information that is different from the first certificate (i.e., the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate, etc.). In this case, the second information can be: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate, etc.
[0372] The serial number, public key, signature value, and / or signature algorithm of the third certificate are key differences between the third and fourth certificates. These details can be used to reconstruct the third certificate, allowing certificate authentication devices to verify its signature value using the reconstructed certificate and the third certificate's public key, thus validating the third certificate. Once verified, this information can be included in the fourth certificate.
[0373] In some implementations, the second certificate update request message can use the CSR format. In this case, the second information can be carried in the delta certificate request and delta certificate request signature attributes of the second certificate request message CSR.
[0374] In some other possible implementations, when the second certificate needs to be revoked, the second request message sent by the first entity to the certificate authentication device can be a second certificate revocation request message. Specifically, the second information may include at least one of the following: the second certificate, the serial number of the second certificate, and the signature of the second certificate revocation request message using the private key of the second certificate.
[0375] The second certificate / second certificate serial number is used by the certificate authentication device to obtain the certificate to be revoked. The signature of the second certificate revocation request message using the private key of the second certificate is used by the certificate authentication device to determine that the request message indeed comes from the first entity that owns the second certificate.
[0376] It should be understood that the first information may not include the second certificate, but rather its serial number, so that the certificate authentication device can find the corresponding second certificate based on the serial number.
[0377] For example, a certificate authentication device can look up a second certificate in a certificate issuance list that stores certificates based on the second certificate's serial number.
[0378] S360, the certificate authentication device processes the second certificate based on the second request message.
[0379] The certificate authentication device receives a second request message sent by the first entity and processes the second certificate based on the second request message.
[0380] In some possible implementations, when the second certificate needs to be updated, the certificate authentication device receives a second request message sent by the first entity as a second certificate update request message. The first information includes: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, and / or the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0381] The certificate authentication device updates the second certificate based on the second certificate update request message, and the updated second certificate becomes the fourth certificate.
[0382] Optionally, the certificate authentication device can update the second certificate based on the information from the third certificate to issue a fourth certificate.
[0383] Specifically, the information in the fourth certificate used for joint authentication of the first entity with the fourth certificate includes: information from the third certificate, i.e., the certificate authentication device writes the information from the third certificate into the fourth certificate.
[0384] For example, the information of the third certificate may include: the hash value of the third certificate, the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
[0385] It should be noted that the fourth certificate and the second certificate share the same certificate subject, certificate issuer, key purpose, and / or signature algorithm. Therefore, the issuance of a fourth certificate based on the information in the third certificate can also be understood as updating the second certificate based on the information in the third certificate to issue the fourth certificate.
[0386] For example, when the first and second certificates are associated certificates, the information of the third certificate can be the hash value of the third certificate.
[0387] For example, when the first certificate and the second certificate are paired certificates, the information of the third certificate can be the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
[0388] Optionally, when the first certificate and the second certificate are associated certificates, the second certificate contains the hash value of the first certificate to bind the first certificate. The second information carried in the second certificate update request message may include the public key of the third certificate, the private key of the third certificate, and a signature of at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0389] Furthermore, the certificate authentication device can use the public key of the third certificate to verify the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate. If the verification is successful, the fourth certificate is issued based on the information of the third certificate. That is, the extension of the fourth certificate includes the hash value of the third certificate.
[0390] It should be noted that when the first and second certificates are associated certificates, the second information carried in the second certificate update request message may also include the serial number and / or location information of the third certificate. The certificate authentication device can obtain the third certificate based on its serial number and / or location information, and thus obtain its public key. In this case, the second information may not carry the public key of the third certificate.
[0391] Optionally, in this example, the second information also includes a third certificate and a signature of the second request message using the third certificate's private key. The signature of the second request message using the third certificate's private key is verified using the third certificate's public key. If the verification passes, the hash value of the third certificate is calculated, and this hash value is included in the fourth certificate issued to the first entity.
[0392] It should be noted that the hash algorithm used to calculate the hash value can be consistent with the hash algorithm used in the signature algorithm of the third certificate, so that it is not necessary to specify the hash algorithm used separately in the fourth certificate; the hash algorithm used to calculate the hash value can also be included in the fourth certificate along with the hash value of the third certificate, so that the hash value is calculated according to the indicated hash algorithm.
[0393] Optionally, the serial number of the third certificate can be carried in the fourth certificate. Before performing joint authentication using the third and fourth certificates, the serial number of the third certificate can be checked to see if it is the same as the serial number of the third certificate carried in the fourth certificate before verifying the hash value.
[0394] Furthermore, when the first certificate and the second certificate are associated certificates, the second information carried in the second certificate update request message may also include: the serial number of the third certificate and / or the location information of the third certificate. The certificate authentication device may also verify the signature of the second certificate update request message, and if the verification is successful, obtain the third certificate based on the serial number and / or location information of the third certificate in the second information.
[0395] It should be noted that when the first certificate and the second certificate are associated certificates, the order of the above verification is not specifically limited in the embodiments of this application.
[0396] Optionally, when the first certificate and the second certificate are paired certificates, the second information carried in the second certificate update request message may be the public key of the third certificate, the signature value of the third certificate, the serial number of the third certificate, and / or the signature algorithm of the third certificate.
[0397] Furthermore, the certificate authentication device uses information from the third certificate that differs from the fourth certificate (e.g., the third certificate's public key, signature value, serial number, and / or signature algorithm) to reconstruct the third certificate. Using the reconstructed third certificate and its public key, the device verifies the signature value to validate the third certificate's legitimacy. If verification is successful, a fourth certificate is issued based on the information in the third certificate. Specifically, the extensions of the fourth certificate include the third certificate's serial number, public key, signature value, and / or signature algorithm.
[0398] Furthermore, the certificate authentication device can also verify the signature of the second certificate update request message. That is, the verification of the signature of the second certificate update request message by the certificate authentication device can ensure that the message source is reliable, meaning that the second certificate update request message was indeed sent by the first entity holding the second certificate and has not been tampered with.
[0399] Optionally, the certificate authentication device can also use the public key of the third certificate to verify the signature value of the third certificate; if the verification is successful, a fourth certificate is issued based on the information of the third certificate, which includes: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate and / or the signature algorithm of the third certificate.
[0400] It should be noted that when the first certificate and the second certificate are paired certificates, the order of the above verification is not specifically limited in the embodiments of this application.
[0401] In some other implementations of this application, when a second certificate is associated with multiple certificates (including the first certificate among the multiple certificates), after the first certificate is updated to a third certificate, the extension of the updated second certificate (fourth certificate) includes the hash value of the third certificate and the hash values of the other certificates among the multiple certificates.
[0402] Alternatively, in the case of a second certificate paired with multiple certificates (including the first certificate among the multiple certificates), after the first certificate is updated to the third certificate, the extended options of the updated second certificate (fourth certificate) include information that the third certificate differs from the fourth certificate, and information that the other certificates among the multiple certificates differ from the fourth certificate.
[0403] In some other possible implementations, when the second certificate needs to be revoked, the certificate authentication device receives a second request message sent by the first entity as a second certificate revocation request message, and the second certificate revocation request message carries at least one of the following: the second certificate, the serial number of the second certificate, and the signature of the private key of the second certificate on the second certificate revocation request message.
[0404] The certificate authentication device revokes the second certificate based on the second certificate revocation request message.
[0405] For example, the certificate authentication device uses the public key of the second certificate to verify the signature of the second certificate revocation request message. If the verification is successful, the certificate serial number to be revoked (i.e. the serial number of the second certificate) is added to the CRL list, or the status of the corresponding certificate (second certificate) in the OCSP server is updated to revoked.
[0406] In one possible implementation, the certificate authentication device obtains the second certificate and retrieves the public key of the second certificate before verifying the signature of the second certificate revocation request message using the public key in the second certificate.
[0407] For example, the certificate authentication device can extract the second certificate either directly from the second certificate revocation request message or by obtaining the first certificate through the serial number of the second certificate. It should be understood that "obtain" here can also be interpreted as "extract," and these two terms can be used interchangeably in this application.
[0408] It should be understood that retrieving the second certificate by the serial number of the first certificate means that the certificate authentication device locally stores all the digital certificates it has issued, and the corresponding second certificate can be found by searching based on the serial number of the second certificate.
[0409] Alternatively, retrieving the second certificate by its serial number means that all issued digital certificates are stored in a public certificate list in a fixed location. The certificate authentication device accesses this location and finds the second certificate by its serial number.
[0410] In some possible implementations, when the first certificate and the second certificate are used to jointly authenticate the first entity, if the first certificate is revoked, the second certificate may still exist and be used to jointly authenticate the first entity with other certificates. In this case, the second certificate may not be revoked.
[0411] S370, the certificate authentication device sends a second response message, which includes a fourth certificate, which is the updated version of the second certificate.
[0412] After the certificate authentication device updates the second certificate to the fourth certificate, it sends a second response message to the first entity, which carries the fourth certificate.
[0413] It should be noted that step S370 is an optional step, that is, when the second certificate needs to be revoked, the certificate authentication device revokes the second certificate without sending a second response message to the first entity.
[0414] The communication method provided in method 300 involves a first entity sending two existing messages to a certificate authentication device: a first message requesting the processing of a first certificate and a second message requesting the processing of a second certificate. This enables the certificate authentication device to process the first certificate and the second certificate that is jointly authenticated with the first certificate, thereby allowing the processed first and second certificates to be adapted for quantum migration.
[0415] The following is combined Figure 4 The third request message sent by the first entity is described in detail. Figure 4 A schematic diagram of another communication method provided in an embodiment of this application is shown. For example... Figure 4 As shown, Figure 4 The method 400 shown may include S410 to S440. The following is in conjunction with… Figure 4 Detail each step in method 400.
[0416] S410. If the first certificate of the first entity is pending processing, determine the second certificate of the first entity based on the first certificate. The first certificate and the second certificate are used to perform joint authentication of the first entity.
[0417] Step S410 can be referred to step S210, and will not be repeated here.
[0418] S420, the first entity sends a third request message, which carries the first information and the second information.
[0419] In this embodiment of the application, the first entity sends a third request message to the certificate authentication device. The third request message is used to request the processing of the first certificate and the second certificate. The third request message carries the first information and the second information.
[0420] In some possible implementations, when the first certificate and the second certificate need to be updated, the third request message sent by the first entity can be a multi-certificate synchronization update request message, or other request messages. This application embodiment does not specifically limit the name of the request message.
[0421] The following section uses the third request message, which is a multi-certificate synchronization update request message, as an example to illustrate this application.
[0422] Optionally, the first and second information carried in the multi-certificate synchronization update request message includes at least one of the following: a signature of the third request message using the first certificate, the serial number of the first certificate, the second certificate, the serial number of the second certificate, the public key of the third certificate, the public key of the fourth certificate, the private key of the first certificate, and / or the private key of the second certificate. The third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate.
[0423] The first certificate, its serial number, the second certificate, and its serial number are used to obtain the first and second certificates. The public key of the third certificate and the public key of the fourth certificate are used by the certificate authentication device to obtain the public key information corresponding to the updated first and second certificates. The signature of the third request message by the private key of the first certificate and / or the private key of the second certificate is used by the certificate authentication device to determine that the sender of the message possesses the first and second certificates.
[0424] It should be understood that before the first entity sends the public key of the fourth certificate to the first certificate, the first entity generates a public-private key pair for the fourth certificate and then sends the public key of the fourth certificate to the certificate authentication device.
[0425] The first entity generating the public-private key pair of the fourth certificate can be replaced by the first entity selecting the public-private key pair of the fourth certificate, or by the first entity determining the public-private key pair of the fourth certificate.
[0426] It should be understood that when the first and second information include the serial numbers of the first and second certificates, the certificate authentication device searches for the serial number of the first certificate in the certificate issuance list storing the certificates to obtain the first certificate, and searches for the serial number of the second certificate to obtain the second certificate. In this case, the first and second information may not include the first and second certificates.
[0427] For example, the first information may be a signature of the multi-certificate synchronization update request message made up of the first certificate, the serial number of the first certificate, the public key of the third certificate, and the private key of the first certificate. The second information may be a signature of the multi-certificate synchronization update request message made up of the second certificate, the serial number of the second certificate, the public key of the fourth certificate, and the private key of the second certificate.
[0428] In this application, the signature of the multi-certificate synchronization update request message using the private keys of the first and second certificates can be either the first information or the second information. This embodiment does not impose specific limitations on this.
[0429] In this embodiment, the private key of the first certificate can be used to sign the multi-certificate synchronization update message, or the private key of the second certificate can be used to sign the multi-certificate synchronization update message, or the private keys of the first certificate and the second certificate can be used to sign the multi-certificate synchronization update message respectively, or the private keys of the first certificate and the second certificate can be used to jointly sign the multi-certificate synchronization update message. This embodiment does not specifically limit the signing method of the multi-certificate synchronization update message.
[0430] In some other possible implementations, when the first certificate and the second certificate need to be revoked, the third request message sent by the first entity can be a multi-certificate synchronous revocation request message, or of course, other request messages. This application embodiment does not specifically limit the name of the request message.
[0431] The following section uses the third request message, which is a multi-certificate synchronization revocation request message, as an example to illustrate this application.
[0432] Optionally, the first and second information carried in the multi-certificate synchronization revocation request message includes at least one of the following: a first certificate, the serial number of the first certificate, a second certificate, the serial number of the second certificate, and a signature of the multi-certificate synchronization revocation request message using the private key of the first certificate and / or the private key of the second certificate.
[0433] Among them, the first certificate, the serial number of the first certificate, the second certificate, and the serial number of the second certificate are used to obtain the first certificate and the second certificate. The signature of the multi-certificate synchronization revocation request message by the private key of the first certificate and / or the private key of the second certificate is used to prove to the certificate authentication device that the sender of the message does indeed possess the first certificate and the second certificate.
[0434] For example, the first information may be a first certificate, the serial number of the first certificate, and the signature of the private key of the first certificate to the multi-certificate synchronization revocation request message; the second information may be a second certificate, the serial number of the second certificate, and the signature of the private key of the second certificate to the multi-certificate synchronization revocation request message.
[0435] In this context, the signature of the multi-certificate synchronization revocation request message using the private keys of the first and second certificates can be either the first information or the second information. This application does not impose specific limitations on this.
[0436] Similarly, in this embodiment, the private key of the first certificate can be used to sign the multi-certificate synchronous revocation request message, or the private key of the second certificate can be used to sign the multi-certificate synchronous revocation request message, or the private keys of the first certificate and the second certificate can be used to sign the multi-certificate synchronous revocation request message respectively, or the private keys of the first certificate and the second certificate can be used to jointly sign the multi-certificate synchronous revocation message. This embodiment does not specifically limit the signing method of the multi-certificate synchronous revocation request message.
[0437] S430, the certificate authentication device processes the first and second certificates based on the third request message.
[0438] Accordingly, the certificate authentication device receives the third request message sent by the first entity and processes the first certificate and the second certificate based on the third request message.
[0439] In some possible implementations, when the first certificate and the second certificate need to be updated, the third request message sent by the first entity to the certificate authentication device may be a multi-certificate synchronization update request message, or other request messages. This application embodiment does not specifically limit the name of the request message.
[0440] The following section uses the third request message, which is a multi-certificate synchronization update request message, as an example to illustrate this application.
[0441] Optionally, the first and second information carried in the multi-certificate synchronization update request message include at least one of the following: the first certificate / serial number of the first certificate, the second certificate / serial number of the second certificate, the public key of the third certificate, the public key of the fourth certificate, the private key of the first certificate, and / or the private key of the second certificate in the multi-certificate synchronization update request message.
[0442] The certificate authentication device updates the first and second certificates based on the multi-certificate synchronous update request message, including updating the first certificate to obtain a third certificate and updating the second certificate to obtain a fourth certificate. The fourth and third certificates are used to perform joint authentication of the first entity.
[0443] It should be noted that the updated first certificate (third certificate) has the same values for the certificate subject, certificate issuer, key purpose, and / or signature algorithm as the first certificate. Similarly, the updated second certificate (fourth certificate) has the same values for the certificate subject, certificate issuer, key purpose, and / or signature algorithm as the second certificate.
[0444] In some possible implementations, when the first certificate and the second certificate are associated certificates, the signature of the multi-certificate synchronization request message is verified using the public key of the first certificate and / or the public key of the second certificate. If the verification is successful, a third certificate is issued based on the public key of the third certificate, and a fourth certificate is issued based on the information of the third certificate and the public key of the fourth certificate.
[0445] In this embodiment, when signing a multi-certificate synchronization update request message using the private key of the first certificate, the signature of the multi-certificate synchronization update request message using the public key of the first certificate can be verified using the public key of the first certificate. When signing a multi-certificate synchronization update request message using the private key of the second certificate, the signature of the multi-certificate synchronization update request message using the public key of the first certificate can be verified using the public key of the first certificate. When signing a multi-certificate synchronization update request message using the private keys of the first and second certificates respectively, the signatures of the first and second certificates can be verified using the public keys of the first and second certificates respectively. When jointly signing a multi-certificate synchronization update request message using the private keys of the first and second certificates, the joint signature of the multi-certificate synchronization update request message can be verified using the public keys of the first and second certificates. This embodiment does not specifically limit the verification method for the signature of the multi-certificate synchronization update request message.
[0446] Furthermore, if the signature verification of the multi-certificate synchronization update request message passes, the certificate authentication device signs a certificate for the first entity whose public key is the public key of the third certificate (i.e., the third certificate).
[0447] Furthermore, the certificate authentication device signs a certificate for the first entity with the public key of the fourth certificate (i.e., the fourth certificate), and the extension of the fourth certificate contains the hash value of the third certificate, which is calculated by the certificate authentication device.
[0448] It should be noted that the hash algorithm used to calculate the hash value can be consistent with the hash algorithm used in the signature algorithm of the third certificate, so that it is not necessary to specify the hash algorithm used separately in the fourth certificate; the hash algorithm used to calculate the hash value can also be included in the fourth certificate along with the hash value of the third certificate, so that the hash value is calculated according to the indicated hash algorithm.
[0449] Optionally, the serial number of the third certificate can be carried in the fourth certificate. Before performing joint authentication using the third and fourth certificates, the serial number of the third certificate can be checked to see if it is the same as the serial number of the third certificate carried in the fourth certificate before verifying the hash value.
[0450] It should be noted that, if the verification is successful, the public key of the third certificate signed by the first entity is extracted from the second information carried in the multi-certificate synchronization update request message, and the public key of the fourth certificate signed by the first entity is also extracted from the second information carried in the multi-certificate synchronization update request message.
[0451] In some other possible implementations, when the first and second certificates are paired, the certificate authentication device uses the public key of the first certificate and / or the public key of the second certificate to verify the signature of the multi-certificate synchronization update request message using the private key of the first certificate and / or the private key of the second certificate. If the verification is successful, it signs a certificate for the first entity with the public key of the third certificate (an incremental certificate, also called the third certificate), and then signs a certificate for the first entity with the public key of the fourth certificate (the basic certificate, also known as the fourth certificate). That is, the incremental certificate description extension options of the fourth certificate include the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the certificate of the signature algorithm of the third certificate.
[0452] It should be understood that, if the verification is successful, the public key of the third certificate signed by the first entity is extracted from the second information carried in the multi-certificate synchronization update request message, and the public key of the fourth certificate signed by the first entity is also extracted from the second information carried in the multi-certificate synchronization update request message.
[0453] Optionally, when the first and second certificates are paired certificates, the first and second information carried in the multi-certificate synchronization update request message may further include: a signature of the multi-certificate synchronization update request message using the private key of the third certificate. The certificate authentication device may also use the public key of the third certificate to verify the signature of the multi-certificate synchronization update request message using the private key of the third certificate, and issue a fourth certificate if the verification is successful.
[0454] In some other possible implementations, the first and second information of the multi-certificate synchronization update request message may also include: a signature of the third certificate’s private key on information that is different from that of the fourth certificate, wherein the information that is different from that of the fourth certificate may include, but is not limited to, the third certificate’s serial number, the third certificate’s public key, the third certificate’s signature value, the third certificate’s signature algorithm, etc.
[0455] In this implementation, the certificate authentication device can also use the public key of the third certificate to verify the signature of the third certificate's private key on information that is different from the fourth certificate. If the verification is successful, the fourth certificate is issued.
[0456] In some other possible implementations, when the first certificate and the second certificate need to be revoked, the third request message sent by the certificate authentication device to the first entity may be a multi-certificate synchronous revocation request message, or of course other request messages. This application embodiment does not specifically limit the name of the request message.
[0457] The following section uses the third request message, which is a multi-certificate synchronization revocation request message, as an example to illustrate this application.
[0458] Optionally, the first and second information carried in the multi-certificate synchronization revocation request message include at least one of the following: the first certificate, the serial number of the first certificate, the second certificate, the serial number of the second certificate, the private key of the first certificate, and / or the private key of the second certificate for signing the multi-certificate synchronization revocation request message.
[0459] The certificate authentication device revokes the first and second certificates based on a multi-certificate synchronous revocation request message.
[0460] For example, when the first information and the second information include a first certificate and a second certificate, the public key of the first certificate and the public key of the second certificate are used to verify the signature of the multi-certificate synchronization revocation request message by the private key of the first certificate and / or the private key of the second certificate.
[0461] It should be understood that before verification, the certificate authentication device obtains a first certificate and a second certificate, and obtains the public key of the first certificate based on the first certificate and the public key of the second certificate based on the second certificate.
[0462] When the first information and the second information include the serial number of the first certificate and the serial number of the second certificate, the certificate authentication device can extract the first certificate and the second certificate based on the serial number of the first certificate and the serial number of the second certificate, thereby obtaining the public key of the first certificate and the public key of the second certificate.
[0463] In one possible implementation, obtaining the first certificate via its serial number means that the certificate authentication device locally stores all the digital certificates it has issued, and the corresponding first certificate can be found by searching for its serial number. Similarly, obtaining the second certificate via its serial number means that the certificate authentication device locally stores all the digital certificates it has issued, and the corresponding second certificate can be found by searching for its serial number.
[0464] In another possible implementation, obtaining the first certificate via its serial number means that all issued digital certificates are uniformly stored in a public certificate list in a fixed location. The certificate authentication device accesses this location and finds the first certificate using its serial number. Similarly, obtaining the second certificate via its serial number means that all issued digital certificates are uniformly stored in a public certificate list in a fixed location. The certificate authentication device accesses this location and finds the second certificate using its serial number.
[0465] In this embodiment, when signing a multi-certificate synchronous revocation request message using the private key of the first certificate, the signature of the multi-certificate synchronous revocation request message using the public key of the first certificate can be verified. When signing a multi-certificate synchronous revocation request message using the private key of the second certificate, the signature of the multi-certificate synchronous revocation request message using the public key of the first certificate can be verified. When signing a multi-certificate synchronous revocation request message using the private keys of the first and second certificates respectively, the signatures of the first and second certificates can be verified using the public keys of the first and second certificates respectively. When jointly signing a multi-certificate synchronous revocation request message using the private keys of the first and second certificates, the signatures of the multi-certificate synchronous revocation request message can be jointly verified using the public keys of the first and second certificates. This embodiment does not specifically limit the verification method for the signature of the multi-certificate synchronous revocation request message.
[0466] If the verification is successful, the certificate serial numbers requested for revocation (i.e., the serial numbers of the first certificate and the second certificate) will be added to the CRL list, or the status of the corresponding certificates (the first certificate and the second certificate) in the OCSP server will be updated to revoked.
[0467] S440, the certificate authentication device sends a third response message, which includes a third certificate and a fourth certificate, used for joint authentication of the first entity.
[0468] After the certificate authentication device updates the first certificate to the third certificate and the second certificate to the fourth certificate, it sends a third response message to the first entity, which carries the third certificate and the fourth certificate.
[0469] It should be noted that step S440 is an optional step, that is, when the first certificate and the second certificate need to be revoked, the certificate authentication device revokes the first certificate and the second certificate without sending a third response message to the first entity.
[0470] The communication method provided in method 400 involves a first entity sending a message to a certificate authentication device, requesting the processing of a first certificate and requesting the processing of a second certificate, so that the certificate authentication device processes the first certificate and processes the second certificate that is jointly authenticated with the first certificate, thereby enabling the quantum migration after the processed first certificate and second certificate are adapted.
[0471] Figure 5 A schematic diagram of another communication method provided in an embodiment of this application is shown. For example... Figure 5 As shown, Figure 5 The method 500 shown may include S510 to S550. The following is in conjunction with… Figure 5 Detail each step in Method 500.
[0472] S510, if the first certificate of the first entity is pending processing, determine the second certificate of the first entity based on the first certificate, and the first certificate and the second certificate are used to perform joint authentication of the first entity.
[0473] Step S510 can be referred to step S210, and will not be repeated here.
[0474] S520. The first entity sends a third request message, which carries first information, second information and a first joint authentication certificate instruction. The first joint authentication certificate instruction is used to instruct the first certificate and the second certificate to perform joint authentication on the first entity.
[0475] Step S520 can be referred to step S420, and will not be repeated here.
[0476] The difference between step S520 and step S420 is that the third request message may carry a first joint authentication certificate instruction, which is used to instruct the first certificate and the second certificate to perform joint authentication on the first entity.
[0477] For example, the first joint authentication certificate instruction may be a first associated certificate instruction or a first paired certificate instruction.
[0478] For example, when the first joint certification certificate indication is the first associated certificate indication, the certificate authentication device can determine that the first certificate and the second certificate are associated certificates based on the first associated certificate indication.
[0479] For example, when the first joint certification certificate indication is the first paired certificate indication, the certificate authentication device can determine that the first certificate and the second certificate are paired certificates based on the first paired certificate indication.
[0480] The S530 certificate authentication device processes the first and second certificates based on a third request message.
[0481] Step S530 can be referred to step S430, and will not be repeated here.
[0482] S540, the certificate authentication device sends a third response message, which includes a third certificate, a fourth certificate, and a second joint authentication certificate instruction. The second joint authentication certificate instruction is used to instruct the third certificate and the fourth certificate to perform joint authentication on the first entity.
[0483] Step S540 can be referred to step S440, and will not be repeated here.
[0484] The difference between step S540 and step S440 is that the third response message may carry a second federated authentication certificate instruction, which is used to instruct the third certificate and the fourth certificate to perform federated authentication on the first entity.
[0485] For example, the second joint certificate instruction may be a second associated certificate instruction or a second paired certificate instruction.
[0486] In one possible implementation, the certificate authentication device updates the first certificate to a third certificate and the second certificate to a fourth certificate, with the fourth certificate's extended options including the hash value of the third certificate, meaning the third and fourth certificates retain their association. The certificate authentication device then instructs the first entity via a third response message that the third and fourth certificates are used for federated authentication of the first entity.
[0487] In another possible implementation, the certificate authentication device updates the first certificate to a third certificate and the second certificate to a fourth certificate. The extended options of the fourth certificate include information related to the third certificate (e.g., the serial number, public key, signature value, or signature algorithm of the third certificate), meaning the third and fourth certificates remain paired certificates. The certificate authentication device then instructs the first entity via a third response message that the third and fourth certificates are used for federated authentication of the first entity.
[0488] S550. Verify the association or pairing relationship between the third and fourth certificates according to the instructions of the second joint certification certificate.
[0489] Accordingly, the first entity receives the third response message and verifies the association between the third certificate and the fourth certificate based on the second federated certificate instruction in the third response message.
[0490] For example, when the second joint certification certificate indication is the second associated certificate indication, the certificate authentication device can determine that the third and fourth certificates are associated certificates based on the second associated certificate indication.
[0491] For example, when the second joint certification certificate indication is the second paired certificate indication, the certificate authentication device can determine that the third and fourth certificates are paired certificates based on the second paired certificate indication.
[0492] When the third and fourth certificates are associated certificates, the first entity verifies whether the fourth certificate contains the RelatedCertificate extension option. If the fourth certificate contains the RelatedCertificate extension option, the hash value of the third certificate is calculated, and it is verified whether this hash value is the same as the hash value in the RelatedCertificate extension option. If the hash value in the RelatedCertificate extension option is the same as the hash value calculated by the third certificate, it means that the third and fourth certificates can be used to jointly authenticate the signature of the first entity.
[0493] When the third and fourth certificates are paired, the first entity verifies whether the fourth certificate contains the DeltaCertificateDiscriptor incremental certificate description extension option. If the fourth certificate contains the DeltaCertificateDiscriptor incremental certificate description extension option, then it verifies whether the DeltaCertificateDiscriptor incremental certificate description extension option in the fourth certificate contains information related to the third certificate (such as the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate). If the DeltaCertificateDiscriptor incremental certificate description extension option contains information related to the third certificate, it means that the third and fourth certificates can be used to jointly authenticate the signature of the first entity.
[0494] The communication method provided in Method 500 involves a first entity sending a message to a certificate authentication device requesting the processing of first certificate information and second certificate information, and indicating the association between the first and second certificates in a third request message, so that the third certificate obtained by the certificate authentication device from processing the first certificate and the fourth certificate obtained from processing the second certificate are also associated, thereby better adapting to the post-quantum migration.
[0495] The methods 200, 300, 400 and 500 described above involve a first entity determining a second certificate based on a first certificate. This application also provides another communication method in which a certificate authentication device can determine a second certificate that is jointly authenticated with the first certificate based on a request from a first entity to process the first certificate, process the first certificate, and process the second certificate that is jointly authenticated with the first certificate. As a result, the processed first certificate and second certificate can be better adapted to post-quantum migration.
[0496] The following is combined Figure 6 A schematic interaction diagram illustrating another communication method provided in this application is shown in detail. Figure 6 A schematic interactive diagram of an example communication method provided in an embodiment of this application is shown.
[0497] S610, if the first certificate of the first entity is pending processing, a fourth request message is sent to request processing of the first certificate of the first entity.
[0498] If the first entity detects locally that the first certificate needs to be processed, the first entity sends a fourth request message to request the processing of the first entity's first certificate.
[0499] It should be understood that the request processing may refer to a request to update the first certificate, a request to revoke the first certificate, or a request for other processing methods for the first certificate. This application embodiment does not specifically limit this.
[0500] In one possible implementation, when the first certificate needs to be updated, the fourth request message can be the first certificate update request message.
[0501] The second information carried in the fourth request message includes: the public key of the third certificate, the first certificate, and a signature of the fourth request message using the private key of the first certificate. Optionally, the fourth request message carries the public key of the fourth certificate.
[0502] In another possible implementation, when the first certificate needs to be revoked, the fourth request message can be a first certificate revocation request message.
[0503] The second information carried by the fourth request message includes: the serial number of the first certificate and the signature of the fourth request message by the private key of the first certificate.
[0504] S620, the certificate authentication device determines a second certificate for a first entity based on a first certificate, and the first and second certificates are used to jointly authenticate the first entity.
[0505] Accordingly, the certificate authentication device receives the fourth request message and determines the second certificate to be jointly authenticated with the first certificate based on the first certificate.
[0506] In some possible implementations, the certificate authentication device can determine the second certificate based on information from the first and second certificates.
[0507] The information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0508] For example, the first certificate and the second certificate are associated certificates. The information in the second certificate refers to the hash value of the first certificate. The certificate authentication device can determine the second certificate based on the hash value of the first certificate contained in the second certificate.
[0509] Specifically, the certificate authentication device checks whether other certificates have the RelatedCertificate extension option, and further checks whether the RelatedCertificate extension option contains the hash value of the first certificate. If a second certificate among multiple certificates includes the RelatedCertificate extension option, and the RelatedCertificate extension option contains the hash value of the first certificate, then it means that the second certificate is used to perform federated authentication of the first entity with the first certificate.
[0510] For example, the first certificate and the second certificate are paired certificates. The information in the second certificate refers to the serial number, signature value, and / or signature algorithm of the first certificate. The certificate authentication device can determine the second certificate based on the serial number, signature value, and / or signature algorithm of the first certificate contained in the second certificate.
[0511] Specifically, the certificate authentication device checks whether other certificates have the DeltaCertificateDiscriptor incremental certificate description extension option, and further checks whether the DeltaCertificateDiscriptor incremental certificate description extension option contains the serial number, public key, and signature value of the first certificate. If the second certificate among multiple certificates includes the DeltaCertificateDiscriptor incremental certificate description extension option, and the DeltaCertificateDiscriptor incremental certificate description extension option contains the serial number, public key, and / or signature value of the first certificate, then it indicates that the second certificate is used to perform federated authentication of the first entity with the first certificate.
[0512] In some other possible implementations, the certificate authentication device stores the correspondence between the first certificate and the second certificate, and the certificate authentication device can determine the second certificate based on the first certificate and the stored correspondence.
[0513] It should be understood that the stored correspondence can refer to a list of associations between the first certificate and the second certificate. Alternatively, the list of stored correspondences can refer to a list of pairings between the first certificate and the second certificate. Alternatively, the correspondence between the first certificate and the second certificate can be represented in other ways, which are not specifically limited in this embodiment.
[0514] For example, the first certificate and the second certificate are associated certificates. The certificate authentication device stores a list of associations between the first certificate and the second certificate, and the certificate authentication device can determine the second certificate based on the stored list of associations.
[0515] For example, the first certificate and the second certificate are paired certificates. The certificate authentication device stores a list of pairing relationships between the first certificate and the second certificate. The certificate authentication device can determine the second certificate based on the stored list of pairing relationships.
[0516] It should be noted that the correspondence between the first certificate and the second certificate may be stored before the second certificate of the first entity is determined. Alternatively, the correspondence between the first certificate and the second certificate may be determined before the certificate authentication device determines that the first certificate is the certificate to be processed. This application embodiment does not specifically limit the storage time of the correspondence between the first certificate and the second certificate.
[0517] S630, Certificate Authentication Equipment processes first and second certificates.
[0518] In one possible implementation, the certificate authentication device updates the first certificate and the second certificate, and ensures that the updated first certificate (third certificate) and the updated second certificate (fourth certificate) can be used to jointly authenticate the first entity.
[0519] In some possible implementations, processing the first and second certificates includes: updating the first certificate to obtain a third certificate, updating the second certificate to obtain a fourth certificate, and using the fourth and third certificates to perform joint authentication of the first entity.
[0520] Optionally, updating the first certificate to obtain the fourth certificate includes: updating the second certificate based on information from the third certificate to issue the fourth certificate.
[0521] Specifically, the information in the fourth certificate that is jointly authenticated with the first entity includes the information from the third certificate.
[0522] For example, the information of the third certificate includes: the hash value of the third certificate, the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate.
[0523] Furthermore, the certificate authentication device updates the first certificate, that is, it signs a certificate for the first entity whose public key is the public key of the third certificate (i.e., the third certificate), and issues a fourth certificate based on the information of the third certificate and the public key of the fourth certificate, that is, the fourth certificate includes the information of the third certificate.
[0524] It should be noted that the public key of the fourth certificate can be carried in the fourth request message or determined by the certificate authentication device for the first entity.
[0525] For example, the certificate authentication device determines the public and private key pair of the fourth certificate for the first entity and sends it to the first entity in the third response message in step S740.
[0526] For example, when the first certificate and the second certificate are associated certificates, the certificate authentication device first updates the first certificate, that is, it signs a certificate for the first entity with the public key of the third certificate (i.e., the third certificate). Then, the certificate authentication device signs a certificate for the first entity with the hash value of the third certificate in the RelatedCertificate extension and the public key of the fourth certificate (i.e., the fourth certificate).
[0527] For example, when the first certificate and the second certificate are paired certificates, the certificate authentication device first updates the incremental certificate (i.e., the first certificate), that is, it signs a certificate for the first entity whose public key is the public key of the third certificate (i.e., the third certificate). Then, it signs a certificate for the first entity whose DeltaCertificateDiscripto incremental certificate description extension includes the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate, and whose public key is the public key of the fourth certificate (i.e., the fourth certificate).
[0528] In another possible implementation, the certificate authentication device revokes the first and second certificates.
[0529] For example, the certificate authentication device may add the certificate serial number to the CRL list (i.e., the serial number of the first certificate and the serial number of the second certificate) to the request for revocation, or update the status of the corresponding certificate (the first certificate and the second certificate) in the OCSP server to be revoked.
[0530] S640, the certificate authentication device sends a third response message, which includes a third certificate and a fourth certificate, and the third certificate and the fourth certificate are used to perform joint authentication of the first entity.
[0531] After the certificate authentication device updates the first certificate to the third certificate and the second certificate to the fourth certificate, it sends a third response message to the first entity, which carries the third certificate and the fourth certificate.
[0532] It should be noted that step S640 is an optional step. That is, when the first certificate and the second certificate need to be revoked, the certificate authentication device revokes the first certificate and the second certificate without sending a third response message to the first entity.
[0533] In the communication method provided in method 600, after the first entity sends a message to the certificate authentication device requesting the processing of the first certificate, the certificate authentication device determines the second certificate that is jointly authenticated with the first certificate, processes the first certificate, and processes the second certificate that is jointly authenticated with the first certificate, thereby enabling the processed first certificate and second certificate to be better adapted to the post-quantum migration.
[0534] The following is combined Figure 7 The fourth request message sent by the first entity is described in detail. Figure 7 A schematic interaction diagram illustrating another communication method provided in an embodiment of this application is shown. For example... Figure 7 As shown, Figure 7 The method 700 shown may include S710 to S770. The following is in conjunction with… Figure 7 Detail each step in method 700.
[0535] S710, if the first certificate of the first entity is pending processing, the first entity sends a fourth request message and a third federated certificate instruction. The fourth request message is used to request processing of the first certificate of the first entity, and the third federated certificate instruction is used to indicate that there is a certificate that federated with the first certificate to authenticate the first entity.
[0536] In this embodiment of the application, when the first entity determines that there is a first certificate to be processed, the first entity can also detect locally whether there is a certificate that performs joint authentication with the first certificate on the first entity.
[0537] The specific description of determining whether the first entity has a certificate that performs joint authentication with the first certificate in step S710 can be found in step S210, and will not be repeated here.
[0538] When the certificate exists, when the first entity sends the fourth request message to the certificate authentication device, it also sends a third joint authentication certificate indication to the certificate authentication device, indicating that a certificate exists that is jointly authenticated with the first certificate for the first entity.
[0539] For example, the third joint certificate instruction can be a third certificate instruction or a third paired certificate instruction.
[0540] S720, the certificate authentication device determines a second certificate for a first entity based on a first certificate, and the first and second certificates are used to jointly authenticate the first entity.
[0541] The certificate authentication device retrieves or determines the second certificate of the first entity based on the third joint authentication certificate instruction in step S710.
[0542] Step S720 can be referred to in step S720, and will not be repeated here.
[0543] S730, certificate authentication equipment processes first and second certificates.
[0544] Step S730 can be referred to step S630, and will not be repeated here.
[0545] S740, the certificate authentication device sends a third response message, which includes a third certificate, a fourth certificate, and a second joint authentication certificate instruction. The second joint authentication certificate instruction is used to instruct the third certificate and the fourth certificate to perform joint authentication on the first entity.
[0546] S750. Verify the association / pairing relationship between the third and fourth certificates according to the instructions of the second joint certification certificate.
[0547] Steps S740-S750 can be referred to as steps S540-S550, and will not be repeated here.
[0548] The communication method provided in method 700 involves a first entity sending a fourth request message to a certificate authentication device to request processing of a first certificate. The fourth request message indicates the existence of a certificate that can be jointly authenticated with the first certificate, so that the certificate authentication device can determine a second certificate that can be jointly authenticated with the first certificate, process the first certificate, process the second certificate, and finally obtain a third and fourth certificate that can also be jointly authenticated, so that the third and fourth certificates can be better adapted to post-quantum migration.
[0549] The above embodiments are based on the processing of the first certificate and the second certificate, thereby better adapting to post-quantum migration. This application also provides another communication method in which the first certificate is bound to the second certificate during updating, so that when the updated first certificate is successfully verified, the updated first certificate and the second certificate can jointly authenticate the first entity.
[0550] The following is combined Figure 8 Another communication method provided in the embodiments of this application will be described in detail. Figure 8 A schematic diagram of another communication method provided in an embodiment of this application is shown. For example... Figure 8 As shown, Figure 8 The method 800 shown may include S810 to S840. The following is in conjunction with… Figure 8 Detail each step in method 800.
[0551] S810, if the first certificate of the first entity is pending processing, determine the second certificate of the first entity based on the first certificate, and the first certificate and the second certificate are used to perform joint authentication of the first entity.
[0552] When the first entity detects locally that the first certificate is about to expire or needs to be revoked, the first entity checks its local certificates to determine if there is a second certificate that is jointly certified with the first certificate.
[0553] The specific description of determining whether the first entity has a certificate that performs joint authentication with the first certificate in step S810 can be found in step S210, and will not be repeated here.
[0554] S820. The first entity sends a fifth request message, which is used to request the update of the first certificate in order to obtain the third certificate. The fifth request message includes the first information of the second certificate, which is a certificate jointly authenticated by the first entity with the third certificate.
[0555] When the first entity determines that the first certificate and the second certificate are used for joint authentication of the first entity, the first entity sends a fifth request message to the certificate authentication device. The fifth request message is used to request the renewal of the first certificate and includes the first information of the second certificate.
[0556] In some possible implementations, the first information of the second certificate includes at least one of the following: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, the signature value of the second certificate, the signature algorithm of the second certificate, or the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0557] For example, the first certificate and the second certificate are associated certificates. The first information of the second certificate is: the serial number of the second certificate, the location information of the second certificate, the signature algorithm of the second certificate, or the private key of the second certificate to the serial number of the second certificate and the signature of the request time of the third certificate.
[0558] Optionally, the first information of the second certificate includes information used to obtain the second certificate and information used to verify the second certificate.
[0559] For example, the information used to obtain the second certificate in the first information of the second certificate may be the serial number of the second certificate and / or the location information of the second certificate. Of course, the first information of the second certificate may also include other information used to obtain the second certificate, such as directly including the second certificate. This application embodiment does not specifically limit this.
[0560] For example, the information used to verify the second certificate in the first information of the second certificate may be the public key of the second certificate, the signature of the private key of the second certificate against at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate. Of course, the first information of the second certificate may also include other information used to verify the second certificate, and this application embodiment does not specifically limit this.
[0561] It should be noted that the first information of the second certificate may not include the public key of the second certificate, meaning that the public key of the second certificate can be obtained using the second certificate.
[0562] Optionally, the first information of the second certificate may not include the public key of the second certificate. After obtaining the second certificate through its serial number and location information, the public key of the second certificate can be extracted. This public key can then be used to verify the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate. If the verification is successful, the second and third certificates can be used for joint authentication of the first entity.
[0563] Optionally, when the first information of the second certificate includes the public key of the second certificate, the signature of the private key of the second certificate against at least one of the following is verified using the public key included in the first information of the second certificate: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate. If the verification is successful, the second certificate and the third certificate can be used to perform joint authentication of the first entity.
[0564] For example, the first certificate and the second certificate are paired certificates. The first information of the second certificate is: the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate, etc.
[0565] Optionally, the first information of the second certificate includes information indicating that the second certificate and the third certificate are different. For example, this different information may be the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate. Of course, the first information of the second certificate may also include other information that distinguishes the second certificate from the third certificate; this embodiment of the application does not specifically limit this.
[0566] For example, the serial number, public key, signature value, and / or signature algorithm of the second certificate are information that distinguishes the second certificate from the third certificate. The certificate authentication device can reconstruct the second certificate using the first information, and can then use the reconstructed certificate and the public key of the second certificate to verify the signature value of the second certificate, thereby verifying the legitimacy of the second certificate. After successful verification, the aforementioned information distinguishing the second certificate from the third certificate can be included in the third certificate.
[0567] S830, the certificate authentication device updates the first certificate according to the first information of the second certificate to obtain the third certificate of the first entity. The third certificate contains information about the certificate used for joint authentication of the first entity with the third certificate. The information about the certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0568] Accordingly, the certificate authentication device receives a fifth request message, which includes the first information of the second certificate.
[0569] The certificate authentication device verifies the signature information based on the first information of the second certificate. If the verification is successful, the first certificate is updated to the third certificate.
[0570] In one possible implementation, where the first and second certificates are associated certificates, the certificate authentication device uses the public key in the second certificate to verify the signature of the fifth request message using the private key of the second certificate. If the verification passes, the certificate authentication device signs a third certificate for the first entity, wherein the RelatedCertificate extension option of the third certificate carries the hash value of the second certificate.
[0571] Optionally, if the first certificate and the second certificate are associated certificates, the certificate authentication device can also use the public key of the second certificate to verify the signature of the private key of the second certificate against the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, and / or the signature algorithm of the second certificate. If the verification is successful, the second certificate can be obtained.
[0572] In another possible implementation, where the first and second certificates are paired certificates, the certificate authentication device uses the public key in the second certificate to verify the signature of the fifth request message by the private key of the second certificate. If the verification is successful, the certificate authentication device signs a third certificate (incremental certificate) for the first entity, wherein the DeltaCertificateDiscriptor extension option of the third certificate carries the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, and / or the signature algorithm of the second certificate, etc.
[0573] Optionally, if the first and second certificates are paired certificates, the certificate authentication device can also use the public key of the second certificate to verify the signature value of the second certificate.
[0574] S840, the certificate authentication device sends a fourth response message, which includes a third certificate. The information in the third certificate used for joint authentication of the first entity with the third certificate is at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0575] The certificate authentication device sends a fourth response message to the first entity. This fourth response message includes a third certificate, which is an updated version of the first certificate. The third certificate and the second certificate are used for joint authentication of the first entity.
[0576] It should be understood that using a third certificate and a second certificate for joint authentication of a first entity can refer to authenticating the signature of the first entity using the third signature algorithm corresponding to the third certificate and the second signature algorithm corresponding to the second certificate.
[0577] For example, the signature of the first entity includes sub-signature 1 and sub-signature 2. Sub-signature 1 of the first entity's signature is verified using the public key corresponding to the third certificate and the corresponding third signature algorithm. Sub-signature 2 of the first entity's signature is verified using the public key corresponding to the second certificate and the second signature algorithm. If both verifications pass, the first entity is considered to be authenticated.
[0578] Sub-signature 1 is the private key signature corresponding to the third certificate, and sub-signature 2 is the private key signature corresponding to the second certificate.
[0579] It should be understood that the signature of the first entity can also be in other forms, and the embodiments of this application do not specifically limit the signature form of the first entity.
[0580] In some possible implementations, the method further includes: a certificate authentication device receiving an authentication request message carrying a third certificate of a first entity and a second certificate of the first entity; verifying the second certificate of the first entity based on information in the third certificate of the first entity, the information in the third certificate being used to perform joint authentication of the first entity with the third certificate; and, if the verification is successful, using the third certificate and the second certificate to perform joint authentication of the first entity.
[0581] It should be understood that the second certificate contains information about the certificate used for joint authentication of the first entity with the second certificate, and the certificate used for joint authentication of the first entity with the first certificate is the first certificate.
[0582] It should also be understood that the information in the third certificate is the information of the certificate used to jointly authenticate the first entity with the third certificate.
[0583] Optionally, when the third certificate and the second certificate are associated certificates, the certificate authentication device verifies the second certificate of the first entity based on the information in the third certificate. This means the certificate authentication device determines whether the RelatedCertificate extension option of the third certificate contains the hash value of the second certificate. If the RelatedCertificate extension option of the third certificate contains the hash value of the second certificate, the verification is successful. Then, the certificate used for federated authentication of the first entity with the third certificate is the second certificate.
[0584] Optionally, when the third certificate and the second certificate are paired certificates, the certificate authentication device verifies the second certificate of the first entity based on the information in the third certificate of the first entity. This means that the certificate authentication device determines whether the DeltaCertificateDiscriptor incremental certificate description extension option of the third certificate contains the serial number, public key, signature value, and / or signature algorithm of the second certificate. If the DeltaCertificateDiscriptor incremental certificate description extension option of the third certificate contains the serial number, public key, signature value, and / or signature algorithm of the second certificate, then the verification is successful. The certificate used for federated authentication of the first entity with the third certificate is then the second certificate.
[0585] In this implementation, the updated first certificate (third certificate) is associated with the second certificate. If the information in the third certificate of the first entity verifies the second certificate of the first entity, the third certificate and the second certificate can jointly verify the first entity. It is no longer necessary to verify the information of the certificate contained in the second certificate that is jointly authenticated with the second certificate for the first entity. Even if the second certificate is checked and the verification fails, the third certificate can still jointly authenticate the first entity with the second certificate.
[0586] In some other possible implementations, the method further includes: verifying the first certificate of the first entity based on the information of the first certificate in the second certificate, and, if the verification fails, verifying the second certificate of the first entity based on the information of the third certificate of the first entity.
[0587] In this implementation, the certificate authentication device can perform multiple authentications. That is, the certificate authentication device can verify the first certificate of the first entity based on the information of the first certificate in the second certificate. If the verification fails, it can verify the second certificate of the first entity based on the information of the third certificate of the first entity. If the verification is successful, the third certificate and the second certificate are used to jointly authenticate the first entity. In other words, one-way verification is sufficient.
[0588] This one-way verification can be understood as follows: if the certificate authentication device verifies the second certificate based on the information in the third certificate and the certificate authentication device verifies the first certificate based on the information in the second certificate and the first certificate and the first certificate and the second ... second certificate and the first certificate and the second certificate and the first certificate and the second certificate and the first certificate can still be used to jointly authenticate the first entity.
[0589] Based on method 800, when the first certificate and the second certificate are used to jointly authenticate the first entity, when the first certificate is updated, the relevant information of the second certificate can be referenced in the first certificate, and when jointly authenticating the first entity, the existing logic can be changed, that is, when the updated first certificate is successfully authenticated, the post-quantum migration can be adapted.
[0590] For ease of understanding, this application uses the authentication of the first entity and the second entity as an example to specifically illustrate the application of the above method 800. Figure 9 A schematic diagram of another communication method is shown, such as... Figure 9 As shown, Figure 9 The method 900 shown may include S910 to S930. The following is in conjunction with… Figure 9 Detail each step in Method 900.
[0591] S910. The first entity sends an authentication request message to the second entity. The authentication request message carries the third certificate of the first entity and the second certificate of the first entity.
[0592] When the first entity and the second entity authenticate each other, the first entity can send a second certificate and a third certificate to the second entity. The third certificate is an updated version of the first certificate.
[0593] S920. Verify the second certificate of the first entity based on the information in the third certificate of the first entity. The information in the third certificate is the certificate information used to perform joint authentication of the first entity with the third certificate. If the verification is successful, the third certificate and the second certificate are used to perform joint authentication of the first entity. The second certificate contains the certificate information used to perform joint authentication of the first entity with the second certificate. The certificate used to perform joint authentication of the first entity with the second certificate is the first certificate.
[0594] Correspondingly, the second entity receives the authentication request message sent by the first entity.
[0595] For example, the second entity in this application embodiment may be a network element, application, server, client or other entity that performs identity authentication. This application embodiment does not specifically limit the form of the second entity.
[0596] The second entity verifies the first entity's second certificate based on the information in the first entity's third certificate carried in the authentication request message.
[0597] It should be understood that the information in the third certificate is information about the certificate used to jointly authenticate the first entity with the third certificate.
[0598] In this embodiment of the application, the information of the certificate used for joint authentication of the first entity with the third certificate in the third certificate is at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0599] Optionally, when the third certificate and the second certificate are associated certificates, the second entity verifies the first entity's second certificate based on the information in the third certificate. This means the second entity determines whether the RelatedCertificate extension option of the third certificate contains the hash value of the second certificate. If the RelatedCertificate extension option of the third certificate contains the hash value of the second certificate, the verification is successful. The certificate used for federated authentication of the first entity with the third certificate is then the second certificate.
[0600] Optionally, when the third certificate and the second certificate are paired certificates, the second entity verifies the first entity's second certificate based on the information in the third certificate. This means the second entity determines whether the DeltaCertificateDiscriptor extension option of the third certificate contains the second certificate's serial number, public key, signature value, and / or signature algorithm. If the DeltaCertificateDiscriptor extension option of the third certificate contains the second certificate's serial number, public key, signature value, and / or signature algorithm, the verification is successful. The certificate used for federated authentication of the first entity with the third certificate is then the second certificate.
[0601] In this implementation, the updated first certificate (third certificate) is associated with the second certificate. If the information in the third certificate of the first entity verifies the second certificate of the first entity, the third certificate and the second certificate can jointly verify the first entity. It is no longer necessary to verify the information of the certificate contained in the second certificate that is jointly authenticated with the second certificate for the first entity. Even if the second certificate is checked and the verification fails, the third certificate can still jointly authenticate the first entity with the second certificate.
[0602] It should be noted that the second certificate contains information about the certificate used for joint authentication of the first entity with the second certificate, and the certificate used for joint authentication of the first entity with the second certificate is the first certificate.
[0603] For example, if the second certificate contains the hash value of the first certificate, and the first certificate has been changed, the second certificate will fail to be verified. However, the failure of the second certificate verification does not affect the joint authentication of the first entity by the second and third certificates.
[0604] For example, the second certificate contains the serial number of the first certificate, the public key of the first certificate, the signature value of the first certificate, and / or the signature algorithm of the first certificate. Since the first certificate has been changed, the verification of the second certificate will fail. However, the failure of the second certificate verification will not affect the joint authentication of the first entity by the second certificate and the third certificate.
[0605] In some possible implementations, the method further includes: verifying the first certificate of the first entity based on the information of the first certificate in the second certificate, and, if the verification fails, verifying the second certificate of the first entity based on the information of the third certificate of the first entity.
[0606] In this implementation, the certificate authentication device can perform multiple authentications. That is, the certificate authentication device can verify the first certificate of the first entity based on the information of the first certificate in the second certificate. If the verification fails, it can verify the second certificate of the first entity based on the information of the third certificate of the first entity. If the verification is successful, the third certificate and the second certificate are used to jointly authenticate the first entity. In other words, one-way verification is sufficient.
[0607] Based on methods 800 and 900, when the first certificate is updated, there is no need to update the second certificate simultaneously, and it can also be adapted to post-quantum migration.
[0608] The method embodiments provided in this application have been described above. The apparatus embodiments provided in this application will be described below. It should be understood that the description of the apparatus embodiments corresponds to the description of the method embodiments. Therefore, any content not described in detail can be referred to the method embodiments above. For the sake of brevity, it will not be repeated here.
[0609] Figure 10 This is a schematic block diagram of a communication device provided in an embodiment of this application. Figure 10 As shown, the communication device 1000 may include a transceiver unit 1010 and / or a processing unit 1020. The transceiver unit 1010 can implement corresponding communication functions, and the processing unit 1020 is used for data processing. The transceiver unit 1010 may also be referred to as a communication interface or communication unit. Optionally, the device 1000 may further include a storage unit, which can be used to store instructions and / or data. The processing unit 1020 can read the instructions and / or data in the storage unit to enable the device to implement the aforementioned method embodiments.
[0610] In one possible design, the device 1000 can be any entity from the method embodiments described above. For example, the device can be a first entity or a second entity, or it can be a chip, processor, or chip system that implements the functions of the first entity or the second entity, or it can be a logic node, logic module, or software that can implement all or part of the functions of the first entity or the second entity. The device 1000 can be used to execute the steps or processes performed by the first entity or the second entity in any of the method embodiments described above.
[0611] Specifically, the processing unit 1020 is used to determine a second certificate for the first entity based on the first certificate when the first certificate of the first entity is pending processing. The first certificate and the second certificate are used for joint authentication of the first entity. The transceiver unit 1010 can be used to send first information requesting processing of the first certificate and second information requesting processing of the second certificate to the certificate authentication device.
[0612] Optionally, the request processing includes: requesting an update or requesting a revocation.
[0613] Optionally, the transceiver unit 1010 can also be used to send a first request message, the first request message carrying the first information;
[0614] Optionally, the transceiver unit 1010 can also be used to send a second request message after determining the second certificate of the first entity, the second request message carrying the second information.
[0615] Optionally, the process is an update, and the first information includes at least one of the following: the public key of the third certificate, the first certificate, the serial number of the first certificate, or the signature of the first request message by the private key of the first certificate;
[0616] The second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or the signature of the private key of the third certificate on at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; wherein, the third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate.
[0617] Optionally, the processing is revocation, and the first message includes at least one of the following: a first certificate, the serial number of the first certificate, or a signature of the first certificate revocation request message using the private key of the first certificate; the second information includes at least one of the following: a second certificate, the serial number of the second certificate, and a signature of the first request message using the private key of the second certificate.
[0618] Optionally, the transceiver unit 1010 can also be used to send a third request message, which carries the first information and the second information.
[0619] Optionally, the process is an update, and the first information and the second information include at least one of the following: the first certificate, the second certificate, the serial number of the first certificate, the public key of the third certificate, the public key of the fourth certificate, the private key of the first certificate and / or the private key of the second certificate, and a signature of the third request message; wherein the third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate.
[0620] Optionally, the third request message further includes: a first federated certificate instruction, which instructs the first certificate and the second certificate to perform federated authentication on the first entity.
[0621] Optionally, the transceiver unit 1010 can also be used to receive a first response message, the first response message including a third certificate; the transceiver unit 1010 can also be used to receive a second response message, the second response message including a fourth certificate; wherein, the third certificate and the fourth certificate are used to perform joint authentication on the first entity.
[0622] Optionally, the transceiver unit 1010 can also be used to receive a third response message, the third response message including: the third certificate and the fourth certificate, the third certificate and the fourth certificate being used for joint authentication of the first entity.
[0623] Optionally, the third response message may further include: a second federated certificate instruction, which instructs the third certificate and the fourth certificate to be used for federated authentication of the first entity.
[0624] Optionally, the processing unit 1020 can also be used to verify the association between the third certificate and the fourth certificate according to the second joint authentication certificate indication.
[0625] Optionally, the processing unit 1020 can also be used to determine the second certificate based on the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0626] Optionally, the processing unit 1020 can also be used to store the correspondence between the first certificate and the second certificate;
[0627] Optionally, the processing unit 1020 can also be used to determine the second certificate based on the correspondence between the first certificate and the storage.
[0628] In some other implementations, the processing unit 1020 in the device can be used to determine a second certificate for the first entity based on the first certificate when the first certificate of the first entity is pending processing. The first certificate and the second certificate are used for joint authentication of the first entity. The transceiver unit 1010 can also be used to send a fifth request message to the certificate authentication device. The fifth request message is used to request the update of the first certificate to obtain a third certificate. The fifth request message includes first information of the second certificate. The second certificate is a certificate used for joint authentication of the first entity with the third certificate.
[0629] Optionally, the processing unit 1020 can also be used to determine the second certificate based on the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0630] Optionally, the processing unit 1020 can also be used to determine the second certificate based on the correspondence between the first certificate and the storage, wherein the correspondence is the correspondence between the first certificate and the second certificate.
[0631] Optionally, the first information of the second certificate includes at least one of the following: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, the signature value of the second certificate, the signature algorithm of the second certificate, or the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0632] Optionally, the transceiver unit 1010 can also be used to receive a fourth response message, the fourth response including a third certificate, wherein the information of the certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0633] Optionally, the second information of the second certificate is at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0634] In some other implementations, the transceiver unit 1010 in the device is used to receive an authentication request message, the authentication request message carrying a third certificate of the first entity and a second certificate of the first entity; the processing unit 1020 is used to verify the second certificate of the first entity based on the information in the third certificate of the first entity, the information in the third certificate being information of a certificate used for joint authentication of the first entity with the third certificate; the processing unit 1020 is also used to perform joint authentication of the first entity based on the third certificate and the second certificate.
[0635] Optionally, the second certificate contains information about a certificate used for joint authentication of the first entity with the second certificate, wherein the certificate used for joint authentication of the first entity with the second certificate is the first certificate.
[0636] Optionally, the processing unit 1020 is further configured to verify the first certificate of the first entity based on the information in the second certificate regarding the certificate used for joint authentication of the first entity with the second certificate, and, in the event of verification failure, to verify the second certificate of the first entity based on the information in the third certificate of the first entity.
[0637] Optionally, the information of the certificate used for joint authentication of the first entity with the third certificate in the third certificate is at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0638] In one possible design, the device 1000 can be the certificate authentication device in the above method embodiments, or it can be a chip, processor, or chip system that implements the functions of a certificate authentication device, or it can be a logic node, logic module, or software that can implement all or part of the functions of a certificate authentication device. The device 1000 can be used to execute the steps or processes performed by the certificate authentication device in any of the above method embodiments.
[0639] Specifically, the transceiver unit 1010 can be used to receive first information of a first certificate of a request to process a first entity and second information of a second certificate of a request to process a first entity, wherein the first certificate and the second certificate are used to perform joint authentication on the first entity; the processing unit 1020 can be used to process the first certificate and the second certificate.
[0640] Optionally, the process includes updating or reversing.
[0641] Optionally, the processing unit 1020 can also be used to update the first certificate to obtain a third certificate; update the second certificate to obtain a fourth certificate, wherein the fourth certificate and the third certificate are used to perform joint authentication of the first entity.
[0642] Optionally, the processing unit 1020 can also be used to update the second certificate according to the information of the third certificate to issue the fourth certificate, wherein the information of the certificate used for joint authentication of the first entity with the fourth certificate in the fourth certificate includes: the information of the third certificate;
[0643] The information of the third certificate includes at least one of the following: the hash value of the third certificate, the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
[0644] Optionally, the transceiver unit 1010 can also be used to receive a first request message, the first request message carrying first information;
[0645] Optionally, the transceiver unit 1010 can also be used to receive a second request message, the second request message carrying second information.
[0646] Optionally, the processing is an update, and the second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or the signature of the private key of the third certificate on at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
[0647] Optionally, the second information includes at least one of the following: the public key of the third certificate, the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate. The processing unit 1020 can also be used to: use the public key of the third certificate to verify the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; if the verification is successful, issue the fourth certificate according to the information of the third certificate, wherein the information of the third certificate includes the hash value of the third certificate.
[0648] Optionally, the second information further includes: the serial number of the third certificate and / or the location information of the third certificate. The processing unit 1020 can also be used to: obtain the third certificate according to the serial number of the third certificate and / or the location information of the third certificate in the second information.
[0649] Optionally, the second information includes at least one of the following: the public key of the third certificate, the signature value of the third certificate, the serial number of the third certificate, and the signature algorithm of the third certificate. The processing unit 1020 can also be used to: verify the signature value of the third certificate using the public key of the third certificate; and, if the verification is successful, issue the fourth certificate according to the information of the third certificate, wherein the information of the third certificate includes: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate.
[0650] Optionally, the transceiver unit 1010 can also be used to send a first response message, the first response message including: a third certificate;
[0651] Optionally, the transceiver unit 1010 can also be used to send a second response message, the second response message including: a fourth certificate; wherein the third certificate and the fourth certificate are used for joint authentication of the first entity.
[0652] Optionally, the transceiver unit 1010 can also be used to receive a third request message, the third request message carrying the first information and the second information.
[0653] Optionally, the process is an update, and the first information and the second information include at least one of the following: a signature of the third request message by the first certificate, the second certificate, the public key of the third certificate, the public key of the fourth certificate, the private key of the first certificate and / or the private key of the second certificate;
[0654] The third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate. The third certificate and the fourth certificate are used to perform joint authentication on the first entity.
[0655] Optionally, the processing unit 1020 may also be used to: verify the signature of the third request message by the private key of the first certificate and / or the private key of the second certificate using the public key of the first certificate and / or the public key of the second certificate; if the verification is successful, issue the third certificate according to the public key of the third certificate; and issue the fourth certificate according to the information of the third certificate and the public key of the fourth certificate.
[0656] Optionally, the information of the third certificate includes the hash value of the third certificate.
[0657] Optionally, the first and second information may also include a signature of the third request message using the private key of the third certificate.
[0658] Optionally, the processing unit 1020 can also be used to: verify the signature of the third request message using the public key of the third certificate.
[0659] Optionally, the transceiver unit 1010 can also be used to send a third response message, the third response message including: the third certificate and the fourth certificate, the third certificate and the fourth certificate being used for joint authentication of the first entity.
[0660] Optionally, the first certificate and the second certificate are used to perform joint authentication of the first entity, including: a first signature algorithm corresponding to the first certificate and a second signature algorithm corresponding to the second certificate are used to authenticate the signature of the first entity.
[0661] Optionally, the first signature algorithm includes: a traditional cryptographic signature algorithm, which includes at least one of the following: RSA algorithm, DSA, SM2, or ECDSA algorithm; the second signature algorithm includes a post-quantum signature algorithm, which includes at least one of the following: CRYSTALS-Dilithium, Falcon, XMSS, Lamport, SQISign, or SPHINCS+.
[0662] In other implementations, the transceiver unit 1010 in the device may be used to receive a fourth request message, the fourth request message being used to request processing of a first certificate of a first entity; the processing unit 1020 may be used to determine a second certificate of the first entity based on the first certificate, the first certificate and the second certificate being used to perform joint authentication of the first entity; the processing unit 1020 may be used to process the first certificate and the second certificate.
[0663] Optionally, the process includes updating or reversing.
[0664] Optionally, the processing unit 1020 can also be used to update the first certificate to obtain a third certificate; update the second certificate to obtain a fourth certificate, wherein the fourth certificate and the third certificate are used to perform joint authentication of the first entity.
[0665] Optionally, the processing unit 1020 can also be used to update the second certificate according to the information of the third certificate in order to issue the fourth certificate, wherein the information of the certificate used for joint authentication of the first entity with the fourth certificate in the fourth certificate includes: the information of the third certificate;
[0666] The information of the third certificate includes at least one of the following: the hash value of the third certificate, the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
[0667] Optionally, the processing unit 1020 can also be used to issue the third certificate based on the public key of the third certificate;
[0668] Optionally, the processing unit 1020 can also be used to issue the fourth certificate based on the information of the third certificate and the public key of the fourth certificate.
[0669] Optionally, the processing unit 1020 can also be used to determine the second certificate based on the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
[0670] Optionally, the processing unit 1020 can also be used to determine the second certificate based on the first certificate and the stored correspondence.
[0671] Optionally, the transceiver unit 1010 can also be used to send a third response message, the third response message including: the third certificate and the fourth certificate, the third certificate and the fourth certificate being used for joint authentication of the first entity; wherein, the third certificate is the updated certificate of the first certificate, and the fourth certificate is the updated certificate of the second certificate.
[0672] Optionally, the third response message may further include: a second federated certificate instruction, which instructs the third certificate and the fourth certificate to be used for federated authentication of the first entity.
[0673] Optionally, the third certificate and the fourth certificate are used to perform joint authentication of the first entity, including: a first signature algorithm corresponding to the third certificate and a second signature algorithm corresponding to the fourth certificate are used to authenticate the signature of the first entity.
[0674] Optionally, the transceiver unit 1010 can also be used to receive a third joint authentication certificate indication, which indicates the existence of a second certificate that performs joint authentication of the first entity with the first certificate.
[0675] In some other implementations, the transceiver unit 1010 in the device is used to receive a fifth request message, which requests the update of a first certificate of a first entity. The fifth request message includes first information of a second certificate. The first certificate and the second certificate are used for joint authentication of the first entity. The processing unit 1020 can be used to update the first certificate according to the first information of the second certificate to obtain a third certificate of the first entity. The second certificate is a certificate used for joint authentication of the first entity with the third certificate.
[0676] Optionally, the transceiver unit 1010 can also be used to receive an authentication request message, the authentication request message carrying the third certificate of the first entity and the second certificate of the first entity;
[0677] Optionally, the processing unit 1020 can also be used to verify the second certificate of the first entity based on the information in the third certificate of the first entity, wherein the information in the third certificate is information of a certificate used for joint authentication of the first entity with the third certificate; if the verification is successful, joint authentication of the first entity is performed based on the third certificate and the second certificate.
[0678] Optionally, the second certificate contains information about a certificate used for joint authentication of the first entity with the second certificate, wherein the certificate used for joint authentication of the first entity with the second certificate is the first certificate.
[0679] Optionally, the processing unit 1020 may also be used to verify the first certificate of the first entity based on the information in the second certificate regarding the certificate used for joint authentication of the first entity with the second certificate, and in the event of verification failure, to verify the second certificate of the first entity based on the information in the third certificate of the first entity.
[0680] Optionally, the first information of the second certificate includes at least one of the following: the serial number of the second certificate, the location information of the second certificate, the public key of the second certificate, the signature value of the second certificate, the signature algorithm of the second certificate, or the signature of the private key of the second certificate on at least one of the following: the serial number of the second certificate, the request time of the third certificate, or the location information of the second certificate.
[0681] Optionally, the transceiver unit 1010 can also be used to send a fourth response message, the fourth response including a third certificate, wherein the information of the certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0682] Optionally, the second information of the second certificate is at least one of the following: the hash value of the second certificate, the serial number of the second certificate, the public key of the second certificate, the signature value of the second certificate, or the signature algorithm of the second certificate.
[0683] Optionally, the third certificate includes information about a certificate used for joint authentication of the first entity with the third certificate, wherein the information about the certificate used for joint authentication of the first entity with the third certificate is the second information of the second certificate.
[0684] It should be understood that the "unit" in device 1000 can be implemented in hardware, software, or by hardware executing corresponding software. For example, the "unit" can refer to an application-specific integrated circuit (ASIC), electronic circuitry, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, combined logic circuitry, and / or other suitable components supporting the described functions. As another example, transceiver unit 1010 can be replaced by transceiver circuitry (e.g., may include receiving and transmitting circuitry), and processing unit 1020 can be replaced by a processor or processing circuitry.
[0685] Figure 11 A schematic block diagram of another communication device provided in an embodiment of this application is shown. The communication device 1100 can be any of the above-mentioned entities or devices. For example, the communication device can be a first entity, a second entity, or a certificate authentication device, or it can be a chip, chip system, or processor implementing the above-described methods in the first entity, second entity, or certificate authentication device. This device can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0686] The communication device 1100 may include one or more processors 1110, which may also be referred to as processing units, and can implement certain control functions. The processor 1110 may be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, while the central processing unit can be used to control the communication device, execute software programs, and process data from the software programs.
[0687] In an alternative design, processor 1110 may also store instructions and / or data that can be executed by processor 1610 to cause communication device 1100 to perform the methods described in the above method embodiments.
[0688] In another alternative design, the communication device 1100 may include a communication interface 1120 for implementing receiving and transmitting functions. For example, the communication interface 1120 may be a transceiver circuit, interface, interface circuit, or transceiver. The transceiver circuit, interface, interface circuit, or transceiver for implementing receiving and transmitting functions may be separate or integrated. The aforementioned transceiver circuit, interface, interface circuit, or transceiver may be used for reading and writing code / data, or it may be used for transmitting or relaying signals.
[0689] Optionally, the communication device 1100 may include one or more memories 1130, which may store instructions that can be executed on the processor 1110, causing the communication device 1100 to perform the methods described in the above method embodiments. Optionally, the memories 1130 may also store data. Optionally, the processor 1110 may also store instructions and / or data. The processor 1110 and the memories 1130 may be provided separately or integrated together.
[0690] It should be understood that, in one possible design, the steps in the method embodiments provided in this application can be implemented by integrated logic circuits in the processor's hardware or by instructions in software form. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are not provided here.
[0691] It should be noted that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory; the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0692] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0693] This application also provides a computer program product, which includes computer program code that, when run on a computer, causes the computer to perform the various steps or processes performed by the entity / device in any of the above method embodiments.
[0694] This application also provides a computer-readable storage medium storing program code that, when run on a computer, causes the computer to perform the various steps or processes performed by the entity / device in any of the above method embodiments.
[0695] This application also provides a communication device, including a processor and an interface, the interface being used to send and / or receive signals, causing the processor to execute the various steps or processes performed by the entity / device in any of the above method embodiments.
[0696] The above-described device embodiments and method embodiments are completely corresponding, with corresponding modules or units performing corresponding steps. For example, a communication unit or communication interface performs the receiving or sending steps in the method embodiments, while other steps besides sending and receiving can be performed by a processing unit or processor.
[0697] In the embodiments of this application, the terms and English abbreviations are exemplary examples given for ease of description and should not be construed as limiting the application in any way. The embodiments of this application do not preclude the possibility of defining other terms that can achieve the same or similar functions in existing or future agreements.
[0698] As used in this specification, the terms "component," "module," "system," etc., are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. As illustrated, applications running on computing devices and computing devices can both be components. One or more components may reside in a process and / or an execution thread, and components may be located on a single computer and / or distributed among two or more computers. Furthermore, these components can be executed from various computer-readable storage media on which various data structures are stored. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component between a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).
[0699] Those skilled in the art will recognize that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0700] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be based on the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0701] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0702] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0703] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0704] In the above embodiments, the functions of each functional unit can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs), etc.
[0705] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially or in other words, the parts that contribute to the prior art, or parts of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0706] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method, characterized in that, The method includes: If the first certificate of the first entity is pending processing, a second certificate of the first entity is determined based on the first certificate, and the first certificate and the second certificate are used to perform joint authentication of the first entity. Send a request to the certificate authentication device for processing the first certificate's first information and a request to process the second certificate's second information.
2. The method according to claim 1, characterized in that, The processing includes updating or reversing.
3. The method according to claim 1 or 2, characterized in that, The step of sending a request to the certificate authentication device to process the first information of the first certificate includes: Send a first request message, the first request message carrying the first information; The step of sending the second information to the certificate authentication device to request processing of the second certificate includes: After determining the second certificate of the first entity, a second request message is sent, which carries the second information.
4. The method according to claim 3, characterized in that, The process is an update, and the first information includes at least one of the following: the public key of the third certificate, the first certificate, the serial number of the first certificate, or the signature of the first request message by the private key of the first certificate; The second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or the signature of the private key of the third certificate on at least one of the following: The serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; The third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate. The third certificate and the fourth certificate are used to perform joint authentication on the first entity.
5. The method according to claim 3, characterized in that, The processing is revocation, and the first information includes at least one of the following: a first certificate, the serial number of the first certificate, or a signature of the first request message by the private key of the first certificate; The second information includes at least one of the following: the serial number of the second certificate, and the signature of the second request message by the private key of the second certificate.
6. The method according to claim 1 or 2, characterized in that, The step of sending first information requesting processing of the first certificate and second information requesting processing of the second certificate to the certificate authentication device includes: A third request message is sent, which carries the first information and the second information.
7. The method according to claim 6, characterized in that, The process is an update, and the first information and the second information include at least one of the following: the first certificate, the second certificate, the serial number of the first certificate, the public key of the third certificate, the public key of the fourth certificate, or the signature of the third request message by the private key of the first certificate and / or the private key of the second certificate; The third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate. The third certificate and the fourth certificate are used to perform joint authentication on the first entity.
8. The method according to claim 6 or 7, characterized in that, The third request message further includes: a first federated certificate instruction, which instructs the first certificate and the second certificate to perform federated authentication on the first entity.
9. The method according to any one of claims 6-8, characterized in that, The method further includes: Receive a second joint authentication certificate instruction, which instructs the third certificate and the fourth certificate to perform joint authentication on the first entity.
10. The method according to claim 9, characterized in that, The method further includes: Verify the correspondence between the third certificate and the fourth certificate according to the instructions of the second joint certification certificate.
11. The method according to any one of claims 1-10, characterized in that, The step of determining the second certificate of the first entity based on the first certificate includes: The second certificate is determined based on the information in the first certificate and the second certificate, wherein the information in the second certificate includes at least one of the following: the hash value of the first certificate, the serial number of the first certificate, the signature value of the first certificate, or the signature algorithm of the first certificate.
12. A communication method, characterized in that, The method includes: The system receives first information of a first certificate of a first entity requesting processing and second information of a second certificate of a first entity requesting processing, wherein the first certificate and the second certificate are used to perform joint authentication on the first entity. Process the first certificate and the second certificate.
13. The method according to claim 12, characterized in that, The processing includes updating or reversing.
14. The method according to claim 12 or 13, characterized in that, The process is an update, and the processing of the first certificate and the second certificate includes: Update the first certificate to obtain the third certificate; The second certificate is updated to obtain a fourth certificate, which, together with the third certificate, is used to perform joint authentication of the first entity.
15. The method according to claim 14, characterized in that, The process of updating the second certificate to obtain the fourth certificate includes: The second certificate is updated based on the information of the third certificate to issue the fourth certificate, wherein the information of the certificate used for joint authentication of the first entity with the fourth certificate in the fourth certificate includes: the information of the third certificate; The information of the third certificate includes at least one of the following: the hash value of the third certificate, the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, or the signature algorithm of the third certificate.
16. The method according to any one of claims 12-15, characterized in that, The processing is an update, and the receiving request to process the first information of the first certificate of the first entity includes: Receive a first request message, the first request message carrying first information; The second information of the second certificate of the first entity receiving the request to process includes: Receive a second request message, which carries the second information.
17. The method according to claim 16, characterized in that, The processing is an update, and the second information includes at least one of the following: the serial number of the third certificate, the location information of the third certificate, the public key of the third certificate, the signature value of the third certificate, the signature algorithm of the third certificate, or the signature of the private key of the third certificate on at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate.
18. The method according to claim 17, characterized in that, The second information includes at least one of the following: the public key of the third certificate, the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate. The method further includes: Using the public key of the third certificate, verify the signature of the private key of the third certificate against at least one of the following: the serial number of the third certificate, the request time of the fourth certificate, or the location information of the third certificate; If the verification is successful, the fourth certificate is issued based on the information in the third certificate, which includes the hash value of the third certificate.
19. The method according to claim 18, characterized in that, The second information further includes: the serial number of the third certificate and / or the location information of the third certificate; the method further includes: The third certificate is obtained based on the serial number of the third certificate and / or the location information of the third certificate in the second information.
20. The method according to claim 17, characterized in that, The second information includes at least one of the following: the public key of the third certificate, the signature value of the third certificate, the serial number of the third certificate, and the signature algorithm of the third certificate. The method further includes: Using the public key of the third certificate, verify the signature value of the third certificate; If the verification is successful, the fourth certificate is issued based on the information of the third certificate, which includes: the serial number of the third certificate, the public key of the third certificate, the signature value of the third certificate, and / or the signature algorithm of the third certificate.
21. The method according to any one of claims 12-15, characterized in that, The first information of the first certificate of the first entity requesting processing and the second information of the second certificate of the first entity requesting processing include: A third request message is received, the third request message carrying the first information and the second information.
22. The method according to claim 21, characterized in that, The process is an update, and the first information and the second information include at least one of the following: the signature of the third request message by the first certificate, the second certificate, the public key of the third certificate, the public key of the fourth certificate, the private key of the first certificate and / or the private key of the second certificate; The third certificate is an updated version of the first certificate, and the fourth certificate is an updated version of the second certificate. The third certificate and the fourth certificate are used to perform joint authentication on the first entity.
23. The method according to claim 22, characterized in that, The method further includes: Using the public key of the first certificate and / or the public key of the second certificate, verify the signature of the third request message by the private key of the first certificate and / or the private key of the second certificate; If the verification is successful, the third certificate is issued based on the public key of the third certificate; The fourth certificate is issued based on the information in the third certificate and the public key of the fourth certificate.
24. The method according to claim 23, characterized in that, The information in the third certificate includes the hash value of the third certificate.
25. The method according to claim 22, characterized in that, The first and second information also include the signature of the third request message by the private key of the third certificate.
26. The method according to claim 25, characterized in that, Before issuing the fourth certificate, the method further includes: The signature of the third request message is verified using the public key of the third certificate.
27. The method according to any one of claims 1-26, characterized in that, The first certificate and the second certificate are used to perform joint authentication of the first entity, including: a first signature algorithm corresponding to the first certificate and a second signature algorithm corresponding to the second certificate are used to authenticate the signature of the first entity.
28. The method according to claim 27, characterized in that, The first signature algorithm is a traditional cryptographic signature algorithm, which includes at least one of the following: RSA algorithm, DSA, SM2, or ECDSA algorithm. The second signature algorithm is a post-quantum signature algorithm, which includes at least one of the following: CRYSTALS-Dilithium, Falcon, XMSS, Lamport, SQISign, or SPHINCS+.
29. A communication device, characterized in that, include: A module or unit for performing the method as described in any one of claims 1 to 11, or a module or unit for performing the method as described in any one of claims 12 to 28.
30. A communication device, characterized in that, include: A processor and a memory, the processor being coupled to the memory, the memory being used to store a computer program, the computer program being executed by the processor causing the apparatus to perform the method as claimed in any one of claims 1 to 11, or to perform the method as claimed in any one of claims 12 to 28.
31. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when run on a computer, causes the computer to perform the method as described in any one of claims 1 to 11, or the method as described in any one of claims 12 to 28.
32. A computer program product, characterized in that, include: A computer program, when run on a computer, causes the computer to perform the method as described in any one of claims 1 to 11, or to perform the method as described in any one of claims 12 to 28.
33. A communication system, characterized in that, It includes a first entity and a certificate authentication device, wherein the first entity is used to perform the method as described in any one of claims 1 to 11, and the certificate authentication device is used to perform the method as described in any one of claims 12 to 28.