Certificate replacement method and system

By pre-determining the scope and mode of certificate replacement for each type of business, member institutions are allowed to choose independently, which solves the problem of time-consuming and labor-intensive certificate renewal in existing technologies and realizes an efficient, low-cost and low-risk certificate replacement process.

CN122137560APending Publication Date: 2026-06-02NETSUNION CLEARING CORP

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NETSUNION CLEARING CORP
Filing Date
2024-11-25
Publication Date
2026-06-02

Smart Images

  • Figure CN122137560A_ABST
    Figure CN122137560A_ABST
Patent Text Reader

Abstract

A certificate replacement method and system are disclosed, which displays a range of selectable certificate replacement modes pre-determined for each business involved by a member organization; obtains the target certificate replacement mode selected by the target member organization for the target business within the corresponding range of selectable certificate replacement modes; and performs certificate replacement for the target business of the target member organization according to the target certificate replacement mode. This disclosure allows member organizations to decide the timing of certificate replacement and flexibly select a certificate switching mode more suitable for their own business situation from the corresponding range of selectable certificate replacement modes. Therefore, it avoids communication between member organizations applying the business and business maintenance personnel regarding certificate replacement time and method, thereby saving significant manpower and time costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of business processing, and in particular to a certificate replacement method and system. Background Technology

[0002] Digital certificates serve as identity verification for various entities (cardholders / individuals, merchants / enterprises, gateways / banks, etc.) during online information exchange and business activities. At each stage of an electronic transaction, all parties involved must verify the validity of each other's certificates to resolve trust issues. However, since digital certificates have a limited validity period, they need to be updated promptly after the expiration date to continue verifying the validity of online information.

[0003] In related technologies, the method for updating digital certificates is as follows: member organizations of the application business and the maintenance personnel of the business need to communicate about the certificate replacement time and certificate replacement method, which is very time-consuming and energy-intensive. Summary of the Invention

[0004] This disclosure provides a certificate replacement method and system that can avoid communication between member organizations of the application business and the maintenance personnel of the business regarding the certificate replacement time and method, thereby saving a lot of manpower and time costs.

[0005] On one hand, this disclosure provides a certificate replacement method, including: displaying a range of selectable certificate replacement modes pre-determined for each business involved by a member institution;

[0006] Obtain the target certificate replacement mode selected by the target member institution from the available range of certificate replacement modes for the target business.

[0007] The target member organization's target business is replaced according to the target certificate replacement mode.

[0008] On the other hand, this disclosure also provides a certificate replacement system, including: an information display module, an information acquisition module, and an information processing module;

[0009] The information display module is used to display the range of selectable certificate replacement modes pre-determined for each type of business involved by the member institution;

[0010] The information acquisition module is used to acquire the target certificate replacement mode selected by the target member institution within the range of selectable certificate replacement modes for the target business.

[0011] The information processing module is used to replace the certificate for the target business of the target member institution according to the target certificate replacement mode.

[0012] Compared with related technologies, the certificate replacement method provided in this disclosure predetermines the range of certificate replacement options for each service. Member organizations can decide the timing of certificate replacement and flexibly choose the certificate switching mode that is more suitable for their own business situation from the corresponding certificate replacement mode selection range. Therefore, it avoids communication between member organizations of the application service and the service maintenance personnel regarding the certificate replacement time and certificate replacement method, thereby saving a lot of manpower and time costs.

[0013] Other features and advantages of this disclosure will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the disclosure. Other advantages of this disclosure may be realized and obtained by means of the methods described in the description and the accompanying drawings. Attached Figure Description

[0014] The accompanying drawings are used to provide an understanding of the technical solutions of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the technical solutions of this disclosure and do not constitute a limitation on the technical solutions of this disclosure.

[0015] Figure 1 This is a flowchart illustrating a certificate replacement method according to an embodiment of the present disclosure;

[0016] Figure 2 This is a schematic diagram illustrating the correspondence between the selectable range of services and certificate replacement modes in an embodiment of this disclosure;

[0017] Figure 3 This is a flowchart illustrating another certificate replacement method according to an embodiment of this disclosure;

[0018] Figure 4 This is a flowchart illustrating another certificate replacement method according to an embodiment of the present disclosure;

[0019] Figure 5 This is a flowchart illustrating another certificate replacement method according to an embodiment of the present disclosure;

[0020] Figure 6 This is a flowchart illustrating another certificate replacement method according to an embodiment of the present disclosure;

[0021] Figure 7 This is a flowchart illustrating another certificate replacement method according to an embodiment of the present disclosure;

[0022] Figure 8 This is a schematic diagram of the structure of a certificate replacement system according to an embodiment of the present disclosure. Detailed Implementation

[0023] This disclosure describes several embodiments, but these descriptions are exemplary and not limiting, and it will be apparent to those skilled in the art that many more embodiments and implementations are possible within the scope of the embodiments described herein. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with, or may replace, any feature or element of any other embodiment.

[0024] This disclosure includes and contemplates combinations of features and elements known to those skilled in the art. The embodiments, features, and elements disclosed in this disclosure may also be combined with any conventional features or elements to form a unique solution as defined by the claims. Any feature or element of any embodiment may also be combined with features or elements from other solutions to form another unique solution as defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this disclosure may be implemented individually or in any suitable combination. Therefore, the embodiments are not limited except by the limitations imposed by the appended claims and their equivalents. Furthermore, various modifications and changes may be made within the scope of the appended claims.

[0025] Furthermore, in describing representative embodiments, the specification may have presented methods and / or processes as a specific sequence of steps. However, the method or process should not be limited to the specific order of steps described herein, to the extent that the method or process does not depend on the specific order of steps described herein. As will be understood by those skilled in the art, other sequences of steps are also possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation of the claims. Moreover, the claims relating to the method and / or process should not be limited to the steps performed in the order written, and those skilled in the art will readily understand that these orders can be varied and still remain within the spirit and scope of the embodiments disclosed herein.

[0026] This disclosure provides a certificate replacement method, such as... Figure 1 As shown, it includes:

[0027] Step 101: Display the range of certificate replacement modes that are pre-determined for each type of business involved by the member institution;

[0028] Step 102: Obtain the target certificate replacement mode selected by the target member institution from the range of available certificate replacement modes for the target business;

[0029] Step 103: Replace the certificate for the target business of the target member institution according to the target certificate replacement mode.

[0030] For example, from the perspective of the user of the certificate, the current types of digital certificates mainly include: personal identity certificates, enterprise or institutional identity certificates, payment gateway certificates, server certificates, secure email certificates, and personal code signing. From the perspective of certificate type, certificates include two types: server certificates (link encryption certificates) and enterprise certificates (signature certificates). The network platform and all participating parties need to configure these two types of certificates. Among them, server certificates are mainly used for encryption during transmission and are stored in systems that provide Hypertext Transfer Protocol Secure (HTTPS) encryption. Common systems include: F5, Secure Socket Layer (SSL) gateway devices, high-performance HTTP and reverse proxy web servers Nginx, and the application system itself. Enterprise certificates are used to verify digital signatures and are stored in systems that provide application-layer encryption and decryption. Common systems include: signature verification devices, encryption devices, and application systems that provide self-developed algorithm processing capabilities. The certificate replacement method provided in this embodiment of the invention specifically refers to enterprise certificates.

[0031] The certificate replacement method provided in this disclosure predetermines the range of certificate replacement options for each type of business. Member organizations can decide the timing of certificate replacement and flexibly choose the certificate switching mode that is more suitable for their own business situation from the corresponding certificate replacement mode selection range. Therefore, it avoids communication between member organizations of the application business and the business maintenance personnel regarding the certificate replacement time and certificate replacement method, thereby saving a lot of manpower and time costs.

[0032] For example, the certificate replacement method provided in this disclosure can be specifically applied to the Nets Union Clearing Corporation (NUCC) platform. NUCC is an operating institution for non-bank payment institution online payment clearing platforms, established with the approval of the People's Bank of China. It provides a nationally unified clearing system for non-bank payment institution online payment clearing platforms. The NUCC platform's enterprise signature and encryption certificates are about to expire, affecting six business lines including the Electronics Payment Clearing of China (EPCC) platform and barcode services.

[0033] In related technologies, the application, issuance, and submission of change materials for certificate updates by member institutions of the NetsUnion platform are all conducted via email. Certificate-related operations are performed manually, and all member institutions connected to the NetsUnion platform must cooperate in changing the public key of the NetsUnion certificate during the replacement process. Therefore, the following problems exist:

[0034] 1. High cost and low efficiency;

[0035] 2. The expiration of member institution certificates requires regular manual review, which can easily lead to omissions.

[0036] 3. During the preparation phase of certificate replacement, multiple business teams need to work with each member institution that needs to replace its certificate to develop the certificate replacement process, which consumes a lot of human resources.

[0037] 4. During the implementation phase of certificate replacement, multiple business teams and member institutions need to work together to verify the correctness of transactions during the certificate replacement process. The certificate replacement process can take anywhere from a few hours to several days, which requires a significant amount of human resources.

[0038] If the certificate replacement method provided in this application is applied to the Netlink platform, member institutions can independently choose the certificate replacement mode for their business from the pre-determined range of certificate replacement modes available on the Netlink platform, thereby solving the aforementioned problems. If a member institution cannot support the use of both updated and non-updated certificates during the certificate replacement period, as the updated and non-updated certificates are mutually exclusive, the member institution generally needs to shut down for the replacement. Although this eliminates the need for member institutions to develop new certificate-based system functions, this certificate replacement mode has a significant impact on transactions, leading to business interruptions and a large number of abnormal transactions. Therefore, according to security specifications, the Netlink platform supports member institutions using two versions of certificates simultaneously (updated certificate and non-updated certificate). Adhering to the principle of ensuring business continuity, member institutions can adopt the "gray release" approach, with the application layer supporting both versions of certificates simultaneously. This allows certificate replacement to be completed without interrupting business operations. The proportion of transactions using updated and non-updated signature certificates can be dynamically adjusted based on a function switch, ensuring that member institutions can support the simultaneous use of both updated and non-updated encryption certificates during the switching process. If the certificate replacement mode for the business includes a phased rollout mode, and the member organization has selected the phased rollout mode, the following advantages can be achieved:

[0039] 1. The impact on transactions is minimal, and member institutions do not need to shut down for replacement. If there are no abnormalities during the replacement period, a seamless switchover can be achieved.

[0040] 2. The rollback is relatively quick because the transaction ratio can be controlled. Once the new certificate is confirmed to be abnormal, the transaction sending of the new certificate can be stopped.

[0041] In one exemplary instance, the range of selectable certificate replacement modes pre-determined for each service includes at least one of the following: a gray-scale replacement mode and a shutdown replacement mode; the gray-scale replacement mode involves using the updated certificate for transactions corresponding to the target service at a preset gray-scale ratio, and gradually increasing the preset gray-scale ratio until all transactions corresponding to the target service are conducted using the updated certificate.

[0042] In one exemplary instance, the grayscale replacement mode includes at least one of the following: a first grayscale replacement mode with a preset grayscale ratio of 1 / M, and a second grayscale replacement mode with a preset grayscale ratio of 1 / N; wherein M and N are both integers, and M is greater than N.

[0043] For example, when the target replacement mode is the first grayscale replacement mode in the grayscale replacement mode, the step of replacing the certificate of the target business of the target member institution according to the target certificate replacement mode includes:

[0044] Starting with one transaction out of every M transactions that uses an updated certificate for the target business, we will gradually transition to using updated certificates for all transactions corresponding to the target business.

[0045] When the target replacement mode is the second grayscale replacement mode in the grayscale replacement mode, the step of replacing the certificate for the target business of the target member institution according to the target certificate replacement mode includes:

[0046] Starting with one transaction from each preset number of transactions that uses the updated certificate for the target business, the process will gradually transition to using the updated certificate for all transactions related to the target business.

[0047] In one exemplary instance, the grayscale replacement mode includes at least one of the following: a grayscale replacement mode with a preset grayscale ratio of 0.01%, a grayscale replacement mode with a preset grayscale ratio of 0.1%, and a grayscale replacement mode with a preset grayscale ratio of 0.1%.

[0048] For example, taking four services in NUCC—EPCC channel front-end replacement service, Bar Code Sorter (BCS) barcode channel replacement service, joint operation and maintenance front-end replacement service, and reconciliation bank name file replacement service—as examples, this disclosure provides a schematic diagram showing the correspondence between services and the selectable range of certificate replacement modes, such as... Figure 2As shown, the certificate replacement modes available for member institutions using the network platform for EPCC channel pre-replacement services include: gray-scale replacement mode and shutdown replacement mode. The gray-scale replacement mode includes: 0.01%, 0.1%, and 0.1% gray-scale replacement modes. For BCS barcode channel replacement services, the certificate replacement modes available are also gray-scale and shutdown replacement modes, with gray-scale modes including 0.01%, 0.1%, and 0.1%. For joint operation and maintenance pre-replacement services, the certificate replacement mode is also shutdown replacement mode. For reconciliation bank name file replacement services, the certificate replacement mode is also shutdown replacement mode. Member institutions can choose either the gray-scale replacement mode or the shutdown replacement mode based on their own business needs. If choosing the gray-scale replacement mode, different gray-scale replacement modes can be selected.

[0049] For example, when the target replacement mode is the 0.01% grayscale replacement mode in the grayscale replacement mode, the step of replacing the certificate of the target business of the target member institution according to the target certificate replacement mode includes:

[0050] The process will gradually transition from using updated certificates for one out of every ten thousand transactions to using updated certificates for all transactions related to the target business.

[0051] When the target replacement mode is the 0.1% grayscale replacement mode in the grayscale replacement mode, the step of replacing the certificate for the target business of the target member institution according to the target certificate replacement mode includes:

[0052] The process will gradually transition from using updated certificates for one out of every thousand transactions to using updated certificates for all transactions related to the target business.

[0053] When the target replacement mode is the 1% grayscale replacement mode in the grayscale replacement mode, the step of replacing the certificate for the target business of the target member institution according to the target certificate replacement mode includes:

[0054] Starting with one out of every hundred transactions using the updated certificate for the target business, we will gradually transition to using the updated certificate for all transactions related to the target business.

[0055] For example, the grayscale ratios included in the 0.01% grayscale replacement mode include: 0.01% grayscale, 100% grayscale, and N1 successively increasing grayscale ratios between 0.01% grayscale and 100% grayscale.

[0056] The grayscale ratios included in the 0.1% grayscale replacement mode are: 0.1% grayscale, 100% grayscale, and N2 successively increasing grayscale ratios between 0.1% and 100% grayscale.

[0057] The grayscale ratios included in the 1% grayscale replacement mode are: 1% grayscale, 100% grayscale, and N3 successively increasing grayscale ratios between 1% grayscale and 100% grayscale; wherein N1, N2, and N3 are all integers greater than or equal to 1.

[0058] For example, the specific grayscale ratios included in different grayscale modes can be shown in Table 1.

[0059]

[0060] Table 1

[0061] As shown in Table 1, the N1 successively increasing grayscale ratios included in the 1 / 10,000 grayscale replacement mode are as follows: The N2 progressively increasing grayscale ratios included in the 1%, 5%, 10%, 30%, 50%, and 100% grayscale replacement modes are as follows: The N3 successively increasing grayscale percentages included in the 1% grayscale replacement mode are 1%, 5%, 10%, 30%, 50%, and 100%.

[0062] In an exemplary instance, when the certificate replacement mode corresponding to the target service is the target grayscale replacement mode in the grayscale replacement mode, wherein the target grayscale replacement mode is the first grayscale replacement mode, or the second grayscale replacement mode, or the 0.01% grayscale replacement mode, or the 0.1% grayscale replacement mode, or the 0.1% grayscale replacement mode, or the 0.1% grayscale replacement mode.

[0063] The step of replacing the certificate for the target business of the target member institution according to the target certificate replacement mode includes:

[0064] Using the preset grayscale ratio of the target grayscale replacement mode as the current grayscale ratio to be verified, perform the following verification operation:

[0065] First, the transaction corresponding to the target business is performed using the updated certificate based on the current grayscale ratio to be verified.

[0066] Secondly, determine whether the transaction result meets the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified;

[0067] If the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified is not met, continue to use the updated certificate to perform the transaction corresponding to the target business with the current grayscale ratio to be verified until it is determined that the transaction result meets the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified.

[0068] If the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified is met, it is determined that the current grayscale ratio to be verified will be used for transactions for the target business. The next grayscale ratio greater than the current grayscale ratio to be verified will be used as the current grayscale ratio to be verified, and the verification operation will continue until it is determined that all transactions for the target business will be conducted using updated certificates.

[0069] In one exemplary instance, the grayscale ratio replacement conditions corresponding to the current grayscale ratio to be verified include: the transaction time exceeds a preset time threshold corresponding to the current grayscale ratio, the total transaction success rate within a specified time period exceeds a preset probability threshold corresponding to the current grayscale ratio, and the success rate of transactions using updated certificates within a specified time period exceeds a preset probability threshold corresponding to the current grayscale ratio.

[0070] In one exemplary instance, during each execution of the verification operation, after determining that the current grayscale ratio to be verified is used for the transaction of the target business, and before setting the next grayscale ratio greater than the current grayscale ratio to be verified as the current grayscale ratio, the method further includes:

[0071] Obtain the verification instruction of the target member organization; wherein the verification instruction is used to instruct the verification of the next grayscale ratio that is greater than the current grayscale ratio to be verified.

[0072] Compared to the above examples, this embodiment fully considers that the organization members themselves also need to verify each grayscale ratio they switch to. Therefore, the verification process for each grayscale ratio requires instructions from the member organization before it can proceed.

[0073] In one exemplary instance, during each execution of the verification operation, after determining that the current grayscale ratio to be verified is used for the transaction of the target business, and before setting the next grayscale ratio greater than the current grayscale ratio to be verified as the current grayscale ratio, the method further includes:

[0074] First, obtain the rollback instruction from the target member organization; wherein, the rollback instruction is used to instruct the rollback of the current grayscale ratio to be verified;

[0075] Secondly, continue to use the updated certificate to conduct transactions corresponding to the target business at the current grayscale ratio to be verified until the verification instruction from the target member institution is obtained.

[0076] For example, if a member institution discovers that a certain grayscale ratio caused a transaction anomaly during the verification process of each grayscale ratio it switched to, it will send a rollback instruction. According to the rollback instruction, it will temporarily not determine whether to use the current grayscale ratio to be verified for the target business, but will continue to verify the current grayscale ratio to be verified.

[0077] In one exemplary instance, the certificate replacement mode corresponding to the target service is the shutdown replacement mode. The step of replacing the certificate for the target service of the target member organization according to the target certificate replacement mode includes:

[0078] First, the transaction corresponding to the target business is performed using an updated certificate;

[0079] Secondly, determine whether the transaction results meet the conditions for certificate replacement;

[0080] If the certificate replacement conditions are not met, the transaction will be conducted with the certificate not updated until the next time the target member institution selects the shutdown replacement mode and it is determined that the transaction result meets the certificate replacement conditions.

[0081] If the certificate replacement conditions are met, the transaction corresponding to the target business will be conducted using the updated certificate.

[0082] In one exemplary instance, the certificate replacement conditions include: the transaction time exceeding a specified time threshold, and the transaction success rate exceeding a specified probability threshold within a specified time period.

[0083] This disclosure also provides a certificate replacement method, which includes... Taking the grayscale switching mode of 1% (1 / 10,000) grayscale ratios of 1%, 5%, 10%, 30%, 50%, and 100% as an example, ... Figure 3 As shown, it includes:

[0084] Step 201: Enable certificate update.

[0085] In this step, the Basedata interface is called to initialize the certificate data. In the initialization state, both the unupdated certificate and the updated certificate are enabled. The weight of the unupdated certificate is 10000, and the weight of the updated certificate is 0.

[0086] Step 202: Determine if the condition has been met. If the grayscale ratio is changed, proceed to step 203.

[0087] The conditions for changing the grayscale ratio include: 1. The transaction time exceeds the first time period; 2. The transaction success rate of all transactions in the most recent first time period is greater than the preset success rate; 3. No transactions were conducted using an outdated encryption certificate in the most recent first time period; 4. Either the number of transactions using an updated encryption certificate in the most recent first time period is 0, or the transaction success rate of transactions using an updated encryption certificate in the most recent preset number of transactions is greater than the preset success rate.

[0088] Where M can be 10 minutes, N can be 1 <= N && N <= 10, and the preset success rate can be 99%.

[0089] Specifically, the certificates include: encryption certificates and signature certificates. Encryption certificates are used by member institutions when sending data to the NetsUnion, but not for every data transmission; they are only used for sensitive data. Signature certificates are used by the NetsUnion when sending data to member institutions. Unlike encryption certificates, signature certificates are used by the NetsUnion every time it transmits data to a member institution.

[0090] Step 203: Modify and update the certificate weight ratio to 1‰.

[0091] Call the Basedata interface to modify and update the certificate weight to 10.

[0092] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 202.

[0093] Step 204: Determine if the grayscale ratio replacement condition of 1‰ has been met. If it has, proceed to step 205.

[0094] The conditions for changing the grayscale ratio to 1‰ include: 1. The transaction time exceeds the first time period; 2. The total transaction success rate of the most recent first time period is greater than the preset success rate; 3. The number of transactions using the updated signature certificate in the most recent second time period is greater than 1, and the success rate of the most recent N transactions using the updated signature certificate is greater than the preset success rate.

[0095] The second time period can specifically be 30 minutes.

[0096] Step 205: Modify and update the certificate weight ratio to 1%.

[0097] Call the Basedata interface to modify and update the certificate weight to 101 (the weight is determined to be 101 because 101 / (101+10000)≈1%).

[0098] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 204.

[0099] Step 206: Determine if the 5% grayscale ratio requirement for replacement has been met. If it has, proceed to step 207.

[0100] The conditions for a 5% grayscale ratio change include: 1. The transaction time exceeds the first time period; 2. The total transaction success rate in the most recent first time period is greater than the preset success rate; 3. The number of transactions using the updated signature certificate in the most recent second time period is greater than 1, and the success rate of the most recent N transactions using the updated signature certificate is greater than the preset success rate.

[0101] Step 207: Modify and update the certificate weight ratio to 5%.

[0102] Call the Basedata interface to modify and update the certificate weight to 526 (the weight is determined to be 526 because 526 / (526+10000)≈5%).

[0103] In this step, member institutions need to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 206.

[0104] Step 208: Determine if the 10% grayscale ratio replacement condition has been met. If it has, proceed to step 209.

[0105] The conditions for a 10% grayscale ratio change include: 1. The transaction time exceeds the first time period; 2. The total transaction success rate in the most recent first time period is greater than the preset success rate; 3. The number of transactions using the updated signature certificate in the most recent second time period is greater than 1, and the success rate of transactions using the updated signature certificate in the most recent preset number of transactions is greater than the preset success rate.

[0106] Step 209: Modify and update the certificate weight ratio to 10%.

[0107] Call the Basedata interface to modify and update the certificate weight to 1111 (the weight is determined to be 1111 because 1111 / (1111+10000)≈10%).

[0108] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 208.

[0109] Step 210: Determine if the 30% grayscale ratio requirement for replacement has been met. If it has, proceed to step 211.

[0110] The conditions for a 30% grayscale ratio change include: 1. The transaction time exceeds the first time period; 2. The total transaction success rate in the most recent first time period is greater than the preset success rate; 3. The number of transactions using the updated signature certificate in the most recent second time period is greater than 1, and the success rate of transactions using the updated signature certificate in the most recent preset number of transactions is greater than the preset success rate.

[0111] Step 211: Modify and update the certificate weight ratio to 30%.

[0112] Call the Basedata interface to modify and update the certificate weight to 4258 (the weight is determined to be 4258 because 4258 / (4258+10000)≈30%).

[0113] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 210.

[0114] Step 212: Determine if the 50% grayscale ratio replacement condition has been met. If it has, proceed to step 213.

[0115] The conditions for a 50% grayscale ratio change include: 1. The transaction time exceeds the first time period; 2. The total transaction success rate in the most recent first time period is greater than the preset success rate; 3. The number of transactions using the updated signature certificate in the most recent second time period is greater than 1, and the success rate of the most recent N transactions using the updated signature certificate is greater than the preset success rate.

[0116] Step 213: Modify and update the certificate weight ratio to 50%.

[0117] Call the Basedata interface to modify and update the certificate weight to 10000 (the weight is determined to be 10000 because 10000 / (10000+10000) = 50%).

[0118] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 212.

[0119] Step 214: Determine if the 100% grayscale ratio replacement condition has been met. If it has, proceed to step 215.

[0120] The conditions for a 100% grayscale replacement include: 1. The transaction time exceeds the first time period; 2. The total transaction success rate in the most recent first time period is greater than the preset success rate; 3. The number of transactions using the updated signature certificate in the most recent second time period is greater than 1, and the success rate of transactions using the updated signature certificate in the most recent preset number of transactions is greater than the preset success rate.

[0121] Step 215: Modify and update the certificate weight ratio to 100%.

[0122] Call the Basedata interface to modify the weight of the unupdated certificate to 0.

[0123] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 214.

[0124] Step 216: Determine if the conditions for disabling the certificate due to not being updated have been met. If so, proceed to step 217.

[0125] The conditions for disabling an outdated certificate include: 1. The transaction time exceeds the first time period; 2. The overall transaction success rate in the most recent first time period is greater than the preset success rate; 3. No transactions were conducted in the most recent first time period using an outdated encryption certificate and an outdated signature certificate.

[0126] Step 217: Unupdated certificate deactivated

[0127] Call the Basedata interface to change the status of the unupdated certificate to disabled.

[0128] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 216.

[0129] This disclosure also provides a certificate replacement method, which takes a shutdown replacement mode as an example. Figure 4 As shown, it includes:

[0130] Step 301: Member institutions begin shutdown.

[0131] Step 302: Enable the updated certificate.

[0132] Call the Basedata interface to initialize certificate data. In the initialization state, both the unupdated certificate and the updated certificate are enabled. The weight of the unupdated certificate is 10000, and the weight of the updated certificate is 0.

[0133] Step 303: Modify and update the certificate weight ratio to 100%.

[0134] Call the Basedata interface to modify the updated certificate weight to 10000, and the unupdated certificate weight to 0.

[0135] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 302.

[0136] Step 304: Member institution shutdown completed.

[0137] Step 305: Determine if the conditions for disabling the certificate due to not being updated have been met. If so, proceed to step 306.

[0138] The conditions for disabling an outdated certificate include: 1. The transaction time exceeds the first time period; 2. The overall transaction success rate in the most recent first time period is greater than the preset success rate; 3. No transactions were conducted in the most recent first time period using an outdated encryption certificate and an outdated signature certificate.

[0139] Step 306: Deactivate the old platform certificate.

[0140] Call the Basedata interface to change the status of the unupdated certificate to disabled.

[0141] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 305.

[0142] This disclosure also provides a certificate replacement method. This embodiment uses a 1% grayscale replacement mode, including grayscale ratios of 1%, 5%, 10%, 30%, 50%, and 100%, as an example. Figure 5 As shown, it includes:

[0143] Step 401: Certificate validity check.

[0144] Step 402: Enable certificate update.

[0145] An unupdated certificate has a weight of 100, while an updated certificate has a weight of 0.

[0146] Step 403: Determine whether the 1% grayscale ratio replacement condition has been met. If it has, proceed to step 404.

[0147] Conditions for changing the grayscale ratio to 1%: 1. The transaction success rate is greater than the preset success rate; 2. The transaction volume of transactions using the updated signature certificate in the most recent time period is greater than the preset ratio.

[0148] The preset ratio can specifically be 99%.

[0149] Step 404: Modify and update the certificate weight ratio to 1%.

[0150] Specifically, you can modify and update the certificate weight to 1.

[0151] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 403.

[0152] Step 405: Determine if the 30% grayscale ratio requirement for replacement has been met. If it has, proceed to step 406.

[0153] The conditions for a 30% grayscale ratio change include: 1. The transaction success rate is greater than the preset success rate; 2. The number of transactions using the updated signature certificate in the second most recent time period is greater than one.

[0154] Step 406: Modify and update the certificate weight ratio to 30%.

[0155] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 405.

[0156] Step 407: Determine if the 50% grayscale ratio replacement condition has been met. If it has, proceed to step 408.

[0157] The conditions for a 50% grayscale ratio change include: 1. The transaction success rate is greater than the preset success rate; 2. The number of transactions using the updated signature certificate in the second most recent time period is greater than one.

[0158] Step 408: Modify and update the certificate weight ratio to 50%.

[0159] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 407.

[0160] Step 409: Determine if the 100% grayscale ratio replacement condition has been met. If it has, proceed to step 410.

[0161] The conditions for a 100% grayscale ratio change include: 1. The transaction success rate is greater than the preset success rate.

[0162] Step 410: Modify and update the certificate weight ratio to 100%.

[0163] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 409.

[0164] Step 411: Determine if the conditions for disabling the certificate due to not being updated have been met. If so, proceed to step 412.

[0165] The conditions for disabling an outdated certificate include: 1. The overall transaction success rate in the most recent first time period is greater than the preset success rate; 2. No transactions were conducted using an outdated encryption certificate and an outdated signature certificate in the most recent first time period.

[0166] Step 412: Disable the unupdated certificate.

[0167] If the unrenewed certificate is successfully deactivated, the reconciliation interface is called to regenerate the reconciliation encryption key; otherwise, proceed to step 413.

[0168] Step 413: Rollback operation.

[0169] The outdated certificate will be rolled back, and an alarm message will be displayed, prompting the maintenance duty officer to call for manual assistance.

[0170] This disclosure also provides a certificate replacement method, which takes a shutdown replacement mode as an example. Figure 6 As shown, it includes:

[0171] Step 501: Certificate validity check.

[0172] Step 502: Enable the certificate update command.

[0173] Step 503: Set the weight of the unupdated certificate to 0.

[0174] In this step, the member institution needs to determine whether the transaction is normal. If it is not normal, the member institution triggers a rollback instruction to roll back to step 502.

[0175] Step 504: Determine if the conditions for disabling the certificate due to not being updated have been met. If so, proceed to step 505.

[0176] The conditions for disabling an outdated certificate include: 1. The overall transaction success rate in the most recent first time period is greater than the preset success rate; 2. No transactions were conducted using an outdated encryption certificate and an outdated signature certificate in the most recent first time period.

[0177] Step 505: Disable the unupdated certificate.

[0178] If the unrenewed certificate is successfully deactivated, the reconciliation interface is called to regenerate the reconciliation encryption key; otherwise, proceed to step 506.

[0179] Step 506: Rollback operation.

[0180] The outdated certificate will be rolled back, and an alarm message will be displayed, prompting the maintenance duty officer to call for manual assistance.

[0181] This disclosure also provides a certificate replacement method, involving the member institution side, the web management platform side (e.g., the network connectivity platform), the certificate data service side, and the engineering platform side, such as... Figure 7 As shown, it includes:

[0182] Step 601: Trigger certificate update and enable.

[0183] This step can be performed by the member organization clicking the "Update Certificate" command.

[0184] Step 602, Interface forwarding.

[0185] Step 603: Certificate data initialization.

[0186] This step enables certificate renewal.

[0187] Step 604: Has the signing certificate update been completed? If the signing certificate update has been completed, proceed to step 605.

[0188] Step 605: Have all signature certificates been switched? If all have been switched, proceed to step 606.

[0189] Step 606: Update certificate weight and increase authority.

[0190] Step 607: Interface forwarding.

[0191] Step 608: Modify and update certificate weight

[0192] Step 609: Check if the percentage of transactions successfully completed using the updated certificate and the overall transaction success rate meet the requirements. If they do, proceed to step 605.

[0193] Step 610: Determine if the transaction using the updated certificate exists and is normal. If it is normal, continue to step 606 until the highest weight is reached; if it is not normal, proceed to step 611.

[0194] Step 611: Certificate replacement rollback.

[0195] This step can be performed by the member organization by clicking the certificate replacement rollback command.

[0196] Step 612, Interface forwarding.

[0197] Step 613: Certificate replacement rollback.

[0198] This step can be performed manually via BMS to perform the certificate replacement rollback operation.

[0199] This disclosure provides an embodiment that offers advantages over current certificate replacement schemes used by member organizations, as shown in Table 2.

[0200]

[0201] Table 2

[0202] The certificate replacement method provided in this disclosure can solve these defects, thereby enabling self-service and smooth certificate replacement.

[0203] This disclosure also provides a certificate replacement system, such as... Figure 8 As shown, it includes: an information display module 71, an information acquisition module 72, and an information processing module 73;

[0204] The information display module 71 is used to display the range of selectable certificate replacement modes pre-determined for each type of business involved by the member institution;

[0205] The information acquisition module 72 is used to acquire the target certificate replacement mode selected by the target member institution for the target business within the range of selectable certificate replacement modes.

[0206] The information processing module 73 is used to replace the certificate for the target business of the target member institution according to the target certificate replacement mode.

[0207] The certificate replacement system provided in this disclosure predetermines the range of certificate replacement options for each type of business. Member organizations can decide the timing of certificate replacement and flexibly choose the certificate switching mode that is more suitable for their own business situation from the corresponding certificate replacement mode selection range. Therefore, it avoids communication between member organizations of the application business and the business maintenance personnel regarding the certificate replacement time and certificate replacement method, thereby saving a lot of manpower and time costs.

[0208] In one exemplary instance, the range of selectable certificate replacement modes pre-determined for each service includes at least one of the following: a gray-scale replacement mode and a shutdown replacement mode; the gray-scale replacement mode involves using the updated certificate for transactions corresponding to the target service at a preset gray-scale ratio, and gradually increasing the preset gray-scale ratio until all transactions corresponding to the target service are conducted using the updated certificate.

[0209] In one exemplary instance, the grayscale replacement mode includes at least one of the following: a first grayscale replacement mode with a preset grayscale ratio of 1 / M, and a second grayscale replacement mode with a preset grayscale ratio of 1 / N; wherein M and N are both integers, and M is greater than N.

[0210] In one exemplary instance, the grayscale replacement mode includes at least one of the following: a grayscale replacement mode with a preset grayscale ratio of 0.01%, a grayscale replacement mode with a preset grayscale ratio of 0.1%, and a grayscale replacement mode with a preset grayscale ratio of 0.1%.

[0211] In an exemplary instance, when the certificate replacement mode corresponding to the target service is the target grayscale replacement mode among the grayscale replacement modes, wherein the target grayscale replacement mode is the first grayscale replacement mode, or the second grayscale replacement mode, or the 0.01% grayscale replacement mode, or the 0.1% grayscale replacement mode, or the 0.1% grayscale replacement mode, or the 0.1% grayscale replacement mode; the information processing module 73 is specifically used for:

[0212] Using the preset grayscale ratio of the target grayscale replacement mode as the current grayscale ratio to be verified, perform the following verification operation:

[0213] First, the transaction corresponding to the target business is performed using the updated certificate based on the current grayscale ratio to be verified.

[0214] Secondly, determine whether the transaction result meets the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified;

[0215] If the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified is not met, continue to use the updated certificate to perform the transaction corresponding to the target business with the current grayscale ratio to be verified until it is determined that the transaction result meets the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified.

[0216] If the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified is met, it is determined that the current grayscale ratio to be verified will be used for transactions for the target business. The next grayscale ratio greater than the current grayscale ratio to be verified will be used as the current grayscale ratio to be verified, and the verification operation will continue until it is determined that all transactions for the target business will be conducted using updated certificates.

[0217] In one exemplary instance, the grayscale ratio replacement conditions corresponding to the current grayscale ratio to be verified include: the transaction time exceeds a preset time threshold corresponding to the current grayscale ratio, the total transaction success rate within a specified time period exceeds a preset probability threshold corresponding to the current grayscale ratio, and the success rate of transactions using updated certificates within a specified time period exceeds a preset probability threshold corresponding to the current grayscale ratio.

[0218] In one exemplary instance, during each execution of the verification operation, after determining that the current grayscale ratio to be verified is used for the transaction for the target business, and before setting the next grayscale ratio greater than the current grayscale ratio to be verified as the current grayscale ratio, the information processing module 73 is specifically used to obtain the verification instruction of the target member institution; wherein, the verification instruction is used to instruct the verification of the next grayscale ratio greater than the current grayscale ratio to be verified.

[0219] In one exemplary instance, during each execution of the verification operation, after determining that the current grayscale ratio to be verified is used for the transaction for the target business, and before setting the next grayscale ratio greater than the current grayscale ratio to be verified as the current grayscale ratio, the information processing module 73 is further configured to:

[0220] Obtain the rollback instruction from the target member organization; wherein the rollback instruction is used to instruct the rollback of the current grayscale ratio to be verified;

[0221] Continue to process the transactions corresponding to the target business using the updated certificate at the current grayscale ratio to be verified until the verification instruction from the target member institution is obtained.

[0222] In one exemplary instance, when the certificate replacement mode corresponding to the target service is the shutdown replacement mode, the information processing module 73 is further configured to:

[0223] First, the transaction corresponding to the target business is performed using an updated certificate;

[0224] Secondly, determine whether the transaction results meet the conditions for certificate replacement;

[0225] If the certificate replacement conditions are not met, the transaction will be conducted with the certificate not updated until the next time the target member institution selects the shutdown replacement mode and it is determined that the transaction result meets the certificate replacement conditions.

[0226] If the certificate replacement conditions are met, the transaction corresponding to the target business will be conducted using the updated certificate.

[0227] In one exemplary instance, the certificate replacement conditions include: the transaction time exceeding a specified time threshold, and the transaction success rate exceeding a specified probability threshold within a specified time period.

[0228] It should be understood that a processor can be a Central Processing Unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor, etc.

[0229] Memory may include read-only memory and random access memory, and provides instructions and data to the processor. A portion of the memory may also include non-volatile random access memory. For example, memory may also store information about the device type.

[0230] In implementation, the processing performed by the terminal device can be accomplished through integrated logic circuits in the processor's hardware or through software instructions. That is, the steps of the method disclosed in this embodiment can be executed by a hardware processor, or by a combination of hardware and software modules within the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other storage media. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.

[0231] This application describes several embodiments, but these descriptions are exemplary and not limiting, and it will be apparent to those skilled in the art that many more embodiments and implementations are possible within the scope of the embodiments described herein. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with, or may replace, any feature or element of any other embodiment.

[0232] This application includes and contemplates combinations of features and elements known to those skilled in the art. The embodiments, features, and elements disclosed in this application may also be combined with any conventional features or elements to form a unique inventive scheme as defined by the claims. Any feature or element of any embodiment may also be combined with features or elements from other inventive schemes to form another unique inventive scheme as defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this application may be implemented individually or in any suitable combination. Therefore, the embodiments are not limited except by the limitations imposed by the appended claims and their equivalents. Furthermore, various modifications and changes may be made within the scope of the appended claims.

[0233] Furthermore, in describing representative embodiments, the specification may have presented methods and / or processes as a specific sequence of steps. However, the method or process should not be limited to the specific order of steps described herein, to the extent that it does not depend on such a specific order. As will be understood by those skilled in the art, other sequences of steps are also possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation of the claims. Moreover, the claims concerning the method and / or process should not be limited to the steps performed in the written order, and those skilled in the art will readily understand that these orders can be varied and still remain within the spirit and scope of the embodiments of this application.

Claims

1. A method for certificate replacement, characterized in that, include: Displays the range of certificate replacement modes available for each business activity involved by the member institution, pre-defined. Obtain the target certificate replacement mode selected by the target member institution from the available range of certificate replacement modes for the target business. The target member organization's target business is replaced according to the target certificate replacement mode.

2. The method according to claim 1, characterized in that, The pre-determined certificate replacement mode for each service can be selected from at least one of the following: gray-scale replacement mode and shutdown replacement mode; The grayscale replacement mode is as follows: transactions corresponding to the target business are performed using updated certificates at a preset grayscale ratio, and the preset grayscale ratio is gradually increased until all transactions corresponding to the target business are performed using updated certificates. The shutdown replacement mode is as follows: the system is shut down to replace the outdated certificate, and the updated certificate is used to conduct the transactions corresponding to the target business after the certificate is updated.

3. The method according to claim 2, wherein the grayscale replacement mode includes at least one of the following: a first grayscale replacement mode with a preset grayscale ratio of 1 / M, and a second grayscale replacement mode with a preset grayscale ratio of 1 / N; wherein, Both M and N are integers, and M is greater than N; Alternatively, the grayscale replacement mode may include at least one of the following: a grayscale replacement mode with a preset grayscale ratio of 0.01%, a grayscale replacement mode with a preset grayscale ratio of 0.1%, and a grayscale replacement mode with a preset grayscale ratio of 0.1%.

4. The method according to claim 3, characterized in that, When the certificate replacement mode corresponding to the target service is the target gray-scale replacement mode in the gray-scale replacement mode, wherein the target gray-scale replacement mode is the first gray-scale replacement mode, or the second gray-scale replacement mode, or the 0.01% gray-scale replacement mode, or the 0.1% gray-scale replacement mode, or the 0.1% gray-scale replacement mode, or the 0.1% gray-scale replacement mode. The step of replacing the certificate for the target business of the target member institution according to the target certificate replacement mode includes: Using the preset grayscale ratio of the target grayscale replacement mode as the current grayscale ratio to be verified, perform the following verification operation: The transaction corresponding to the target business is performed using the updated certificate based on the current grayscale ratio to be verified. Determine whether the transaction result meets the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified; If the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified is not met, continue to use the updated certificate to perform the transaction corresponding to the target business with the current grayscale ratio to be verified until it is determined that the transaction result meets the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified. If the grayscale ratio replacement condition corresponding to the current grayscale ratio to be verified is met, it is determined that the current grayscale ratio to be verified will be used for transactions for the target business. The next grayscale ratio greater than the current grayscale ratio to be verified will be used as the current grayscale ratio to be verified, and the verification operation will continue until it is determined that all transactions for the target business will be conducted using updated certificates.

5. The method according to claim 4, characterized in that, The conditions for changing the grayscale ratio corresponding to the current grayscale ratio to be verified include: the transaction time exceeds the preset time threshold corresponding to the current grayscale ratio, the total transaction success rate within the specified time period exceeds the preset probability threshold corresponding to the current grayscale ratio, and the success rate of transactions using the updated certificate within the specified time period exceeds the preset probability threshold corresponding to the current grayscale ratio.

6. The method according to claim 5, characterized in that, During each execution of the verification operation, after determining that the current grayscale ratio to be verified is used for the transaction of the target business, and before taking the next grayscale ratio greater than the current grayscale ratio to be verified as the current grayscale ratio, the process further includes: Obtain the verification instruction of the target member organization; wherein the verification instruction is used to instruct the verification of the next grayscale ratio that is greater than the current grayscale ratio to be verified.

7. The method according to claim 6, characterized in that, During each execution of the verification operation, after determining that the current grayscale ratio to be verified is used for the transaction of the target business, and before taking the next grayscale ratio greater than the current grayscale ratio to be verified as the current grayscale ratio, the process further includes: Obtain the rollback instruction from the target member organization; wherein the rollback instruction is used to instruct the rollback of the current grayscale ratio to be verified; Continue to process the transactions corresponding to the target business using the updated certificate at the current grayscale ratio to be verified until the verification instruction from the target member institution is obtained.

8. The method according to claim 2, characterized in that, When the certificate replacement mode corresponding to the target service is the shutdown replacement mode, the step of replacing the certificate for the target service of the target member organization according to the target certificate replacement mode includes: The target business transaction is performed using an updated certificate; Determine whether the transaction results meet the requirements for certificate replacement; If the certificate replacement conditions are not met, the transaction will be conducted with the certificate not updated until the next time the target member institution selects the shutdown replacement mode and it is determined that the transaction result meets the certificate replacement conditions. If the certificate replacement conditions are met, the transaction corresponding to the target business will be conducted using the updated certificate.

9. The method according to claim 8, characterized in that, The certificate replacement conditions include: the transaction time exceeds a specified time threshold, and the transaction success rate within a specified time period exceeds a specified probability threshold.

10. A certificate replacement system, characterized in that, include: Information display module, information acquisition module, and information processing module; The information display module is used to display the range of selectable certificate replacement modes pre-determined for each type of business involved by the member institution; The information acquisition module is used to acquire the target certificate replacement mode selected by the target member institution within the range of selectable certificate replacement modes for the target business. The information processing module is used to replace the certificate for the target business of the target member institution according to the target certificate replacement mode.