Communication method and communication device
The BBU proxies the AAU to manage digital certificates from the CA server, addressing the lack of direct communication, ensuring secure AAU-BBU communication by using an asynchronous remote signature method.
Patent Information
- Application Number
- JP2024539862
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-12-29
- Filing Date
- 2022-12-23
- Publication Date
- 2025-11-12
- Estimated Expiration
- 2042-12-23
AI Technical Summary
In a new radio (NR) system, active antenna units (AAUs) cannot update or manage their digital certificates due to the absence of a direct channel with the certificate authority (CA) server, compromising secure communication with baseband units (BBUs).
A communication method where a baseband unit (BBU) acts as a proxy for the AAU to apply for and manage digital certificates from the CA server, using an asynchronous remote signature method to ensure security without transferring the AAU's private key over the network.
Enables secure and efficient management of digital certificates for AAUs, maintaining network security without exposing the AAU's private key, thus ensuring uninterrupted and secure communication with BBUs.
Smart Images

Figure 0007769128000001 
Figure 0007769128000002 
Figure 0007769128000003
Abstract
Description
[Technical Field]
[0001] This application claims priority to Chinese Patent Application No. 202111639208.4, entitled "Communication Method and Communication Apparatus," filed with the State Intellectual Property Office of the People's Republic of China on December 29, 2021, which is incorporated herein by reference in its entirety.
[0002] The present application relates to the field of communications technology, and in particular to a communication method and a communication device. [Background technology]
[0003] A digital certificate is a file digitally signed by a certificate authority (CA) server and contains information about the owner and the public key. The CA server is a trusted and impartial third party. Therefore, devices in a communication system are provided with digital certificates, allowing them to establish secure transmission channels and perform identity authentication based on the certificates issued by the CA server. In a new radio (NR) system, a base station includes a first device and a second device. For example, the first device is an active antenna unit (AAU), and the second device is a baseband unit (BBU). The AAU and BBU communicate with each other through the enhanced common public radio interface (eCPRI). Therefore, the AAU and BBU must use digital certificates to implement secure eCPRI communication. However, because there is no direct channel between the AAU and the CA server, the AAU cannot update or manage its digital certificates. Summary of the Invention [Means for solving the problem]
[0004] The present application provides a communication method and device for updating or managing digital certificates.
[0005] According to a first aspect, the present application provides a communication method, which is applicable to a second device, the method comprising: receiving a first message from a first device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; sending a second message to a certificate authority CA server based on the first message, the second message including a certificate request file; receiving a digital certificate from a CA server; sending a digital certificate to the first device; Includes.
[0006] In this application, the AAU does not need to establish a transmission network with the CA server, but applies for a digital certificate from the CA server through a first device (e.g., a BBU) on behalf of a second device (e.g., an AAU), so that the digital certificate can be updated or managed.
[0007] In one possible implementation, the step of sending a second message to the CA server based on the first message includes: sending a third message to the first device, the third message including a certificate request file; receiving first signature data corresponding to the third message from the first device; sending a second message to the CA server, the second message including the first signature data and the third message; Includes.
[0008] In this application, an asynchronous remote signature method, specifically, a method in which a second device sends data to be signed (e.g., a third message) to a first device and receives signature data (e.g., first signature data) fed back by the first device, can ensure the security of the proxy process and ensure that the AAU's private key is not transferred over the network and is not leaked.
[0009] In one possible implementation, the step of receiving a digital certificate from a CA server includes: receiving a first response from the CA server for the second message, the first response including the digital certificate; Includes:
[0010] In one possible implementation, the first response carries first response signature data, and the step of sending the digital certificate to the first device includes: a step of checking the first response based on the signature data of the first response and transmitting first confirmation response information to the CA server based on the check result; receiving second acknowledgment information from the CA server for the first acknowledgment information; sending a digital certificate to the first device in response to the second acknowledgment information; Includes:
[0011] In one possible implementation, the step of sending first confirmation response information to the CA server based on a check result of checking the first response based on the signature data of the first response includes: sending first acknowledgement information to the first device if the check result is that the check is successful; receiving second signature data corresponding to the first acknowledgment information from the first device; sending the first confirmation response information and the second signature data to the CA server; Includes:
[0012] In this application, an asynchronous remote signature method, specifically, a method in which a second device sends data to be signed (e.g., first acknowledgment information) to a first device and receives signature data (e.g., second signature data) fed back by the first device, can ensure the security of the proxy process and ensure that the AAU's private key is not transferred over the network and is not leaked.
[0013] According to a second aspect, the present application provides a communication method, applicable to a first device, the method comprising: sending a first message to a second device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; receiving a digital certificate from a second device; Includes:
[0014] In one possible implementation, the method comprises: receiving a third message from the second device, the third message including a certificate request file; sending the first signature data corresponding to the third message to the second device; Further includes:
[0015] In one possible implementation, the method comprises: receiving first acknowledgment information from the second device; sending second signature data corresponding to the first acknowledgment information to the second device; Further includes:
[0016] According to a third aspect, the present application provides a communication method, which is applicable to a CA server, the method comprising: receiving a second message from a second device, the second message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; sending the digital certificate to the second device; Includes:
[0017] In one possible implementation, the second message includes the first signature data corresponding to the third message and the third message, and the third message includes the certificate request file.
[0018] In one possible implementation, the step of sending the digital certificate to the second device includes: sending a first response to the second message to the second device, the first response including the digital certificate; Includes:
[0019] In one possible implementation, the first response carries first response signature data, and the method comprises: receiving first acknowledgment information from a second device, the first acknowledgment information being generated based on a check result of checking the first response by the second device based on signature data of the first response; transmitting second acknowledgment information to the second device in response to the first acknowledgment information; Further includes:
[0020] In one possible implementation, the first acknowledgment information further carries second signature data corresponding to the first acknowledgment information.
[0021] According to a fourth aspect, the present application provides a communication apparatus, which may be a second device. The apparatus comprises: a transceiver unit configured to receive a first message from a first device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; a processing unit configured to send a second message to a certificate authority CA server through the transceiver unit based on the first message, the second message including a certificate request file; Including, the transceiver unit is configured to receive a digital certificate from a CA server; The transceiver unit is configured to transmit the digital certificate to the first device.
[0022] In one possible implementation, the processing unit specifically: sending a third message to the first device through the transceiver unit, the third message including the certificate request file; receiving first signature data corresponding to the third message from the first device through the transceiver unit; sending a second message to the CA server through the transceiver unit, the second message including the first signature data and the third message; It is configured as follows.
[0023] In one possible implementation, the transceiver unit specifically comprises: receiving a first response from the CA server for the second message, the first response including the digital certificate; It is configured as follows.
[0024] In one possible implementation, the first response carries signature data of the first response, and the transceiver unit specifically: checking the first response based on the signature data of the first response, and transmitting first confirmation response information to the CA server based on the check result; receiving second acknowledgment information from the CA server regarding the first acknowledgment information; transmitting a digital certificate to the first device in response to the second acknowledgment information; It is configured as follows.
[0025] In one possible implementation, the transceiver unit specifically comprises: If the check result is that the check is successful, sending first acknowledgment information to the first device; receiving second signature data corresponding to the first acknowledgment information from the first device; sending the first acknowledgment information and the second signature data to the CA server; It is configured as follows.
[0026] According to a fifth aspect, the present application provides a communication apparatus. The apparatus may be a first device. The apparatus includes: a transceiver unit configured to transmit a first message to a second device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; Including, The transceiver unit is configured to receive a digital certificate from a second device.
[0027] In one possible implementation, the transceiver unit is configured to receive a third message from the second device, the third message including a certificate request file; This device is a processing unit configured to transmit first signature data corresponding to the third message to the second device through the transceiver unit; Further includes:
[0028] In one possible implementation, the transceiver unit specifically comprises: receiving first acknowledgment information from the second device; sending second signature data corresponding to the first acknowledgment information to the second device; It is configured as follows.
[0029] According to a sixth aspect, the present application provides a communication device, the device being a CA server. The device comprises: a transceiver unit configured to receive a second message from a second device, the second message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; Including, The transceiver unit is further configured to transmit the digital certificate to the second device.
[0030] In one possible implementation, the second message includes the first signature data corresponding to the third message and the third message, and the third message includes the certificate request file.
[0031] In one possible implementation, the transceiver unit comprises: sending a first response to the second message to the second device, the first response including the digital certificate; It is further configured as follows.
[0032] In one possible implementation, the first response carries signature data of the first response, and the transceiver unit: receiving first acknowledgment information from a second device, the first acknowledgment information being generated based on a check result of checking the first response by the second device based on signature data of the first response; transmitting second acknowledgment information to the second device in response to the first acknowledgment information; It is further configured as follows.
[0033] In one possible implementation, the first acknowledgment information further carries second signature data corresponding to the first acknowledgment information.
[0034] According to a seventh aspect, the present application provides a communication device. The device may be a second device, a device within a second device, or a device that can be used with a second device. Alternatively, the communication device may be a chip system. The communication device can perform the method according to the first aspect. The functions of the communication device may be realized by hardware, or by hardware executing corresponding software. The hardware or software may include one or more units or modules corresponding to the aforementioned functions. The units or modules may be software and / or hardware. For operations performed by the communication device and their beneficial effects, please refer to the method according to the first aspect and their beneficial effects. Repeated parts will not be described again.
[0035] According to an eighth aspect, the present application provides a communication device. The device may be a first device, a device within the first device, or a device that can be used with the first device. Alternatively, the communication device may be a chip system. The communication device can perform the method according to the second aspect. The functions of the communication device may be realized by hardware, or by hardware executing corresponding software. The hardware or software may include one or more units or modules corresponding to the aforementioned functions. The units or modules may be software and / or hardware. For operations performed by the communication device and their beneficial effects, please refer to the method according to the second aspect and their beneficial effects. Repeated parts will not be described again.
[0036] According to a ninth aspect, the present application provides a communication device. The device may be a CA server, a device within a CA server, or a device that can be used with a CA server. Alternatively, the communication device may be a chip system. The communication device can perform the method according to the third aspect. The functions of the communication device may be realized by hardware, or by hardware executing corresponding software. The hardware or software may include one or more units or modules corresponding to the aforementioned functions. The units or modules may be software and / or hardware. For operations performed by the communication device and their beneficial effects, please refer to the method according to the third aspect and their beneficial effects. Repeated parts will not be described again.
[0037] According to a tenth aspect, the present application provides a communications apparatus, which may be a second device, including a processor and a transceiver, the processor and the transceiver being configured to execute computer programs or instructions stored in at least one memory to enable the apparatus to perform a method according to any one of the possible implementations of the first aspect.
[0038] According to an eleventh aspect, the present application provides a communication device, which may be a second device, including a processor, a transceiver, and a memory. The processor, the transceiver, and the memory are coupled together. The processor and the transceiver are configured to perform a method according to any one of the possible implementations of the first aspect.
[0039] According to a twelfth aspect, the present application provides a communications apparatus, which may be a first device, including a processor and a transceiver, the processor and the transceiver configured to execute computer programs or instructions stored in at least one memory to enable the apparatus to perform a method according to any one of the possible implementations of the second aspect.
[0040] According to a thirteenth aspect, the present application provides a communication device. The device may be a first device, and the communication device includes a processor, a transceiver, and a memory. The processor, the transceiver, and the memory are coupled together. The processor and the transceiver are configured to perform a method according to any one of the possible implementations of the second aspect.
[0041] According to a fourteenth aspect, the present application provides a communications device, which may be a CA server, including a processor and a transceiver, the processor and the transceiver being configured to execute a computer program or instructions stored in at least one memory to enable the device to perform a method according to any one of the possible implementations of the third aspect.
[0042] According to a fifteenth aspect, the present application provides a communication device. The device may be a CA server, and the communication device includes the processor, transceiver, and memory of FIG. 8. The processor, transceiver, and memory are coupled together. The processor and transceiver are configured to perform a method according to any one of the possible implementations of the third aspect.
[0043] According to a sixteenth aspect, the present application provides a computer-readable storage medium storing a computer program or instructions that, when executed by a computer, performs a method according to any one of the first to third aspects.
[0044] According to a seventeenth aspect, the present application provides a computer program product comprising instructions, the computer program product comprising computer program code, which when executed on a computer performs a method according to any one of the first to third aspects. [Brief explanation of the drawings]
[0045] [Figure 1]1 is a schematic diagram of the network architecture of a 5G system. [Figure 2] 1 is a schematic diagram of a network architecture between a base station and a CA server. [Figure 3] 1 is a diagram of an application scenario of a communication method according to an embodiment of the present application; [Figure 4] 1 is a schematic flowchart of a communication method according to an embodiment of the present application; [Figure 5] FIG. 1 is a diagram of an integrity protection scenario according to an embodiment of the present application. [Figure 6] 4 is another schematic flowchart of a communication method according to an embodiment of the present application; [Figure 7] 4 is another schematic flowchart of a communication method according to an embodiment of the present application; [Figure 8] 1 is a diagram of the structure of a communication device according to an embodiment of the present application; [Figure 9] FIG. 10 is a diagram of the structure of another communication device according to an embodiment of the present application; [Figure 10] FIG. 10 is a diagram of the structure of another communication device according to an embodiment of the present application; [Figure 11] FIG. 10 is a diagram of the structure of another communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION
[0046] The following clearly and completely describes the technical solutions of the embodiments of the present application with reference to the accompanying drawings of the embodiments of the present application.
[0047] In the description of this application, unless otherwise specified, " / " means "or." For example, A / B can represent A or B. The term "and / or" in this specification describes only a relational relationship between related objects and indicates that three relationships may exist. For example, A and / or B can represent the following three cases: when only A exists, when both A and B exist, and when only B exists. In addition, "at least one" means one or more, and "multiple" means two or more. Terms such as "first" and "second" do not limit the quantity or execution order, and terms such as "first" and "second" do not indicate a clear distinction.
[0048] In this application, terms such as "example" or "for example" are used to denote providing an example, illustration, or explanation. Any embodiment or design manner described in this application as an "example" or "for example" should not be described as preferred or having more advantages than another embodiment or design manner. Strictly speaking, the use of terms such as "example" or "for example" is intended to present the relevant concept in a concrete manner.
[0049] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as an enhanced-long-term evolution (eLTE) system, a fifth-generation (5G) system, and a new radio (NR) system. The 5G mobile communication system in the present application includes a non-standalone (NSA) 5G mobile communication system or a standalone (SA) 5G mobile communication system. The technical solutions provided in the present application can also be applied to future communication systems, such as a sixth-generation mobile communication system. Alternatively, the communication system may be a public land mobile network (PLMN), a device-to-device (D2D) communication system, a machine-to-machine (M2M) communication system, an Internet of Things (IoT) communication system, or another communication system, which is not limited herein.
[0050] For ease of understanding, a 5G system is used as an example for explanation. Figure 1 is a schematic diagram of a network architecture of a 5G system. As shown in Figure 1, the network architecture may include a terminal device, a (radio) access network ((R)AN), a core network (CN), and a data network (DN). The (R)AN (hereinafter referred to as RAN) is configured to connect the terminal device to the radio network, and the CN is configured to manage the terminal device and provide a gateway for communication with the DN.
[0051] A terminal device may be a device with wireless transceiver capabilities. A terminal device may have different names, such as a terminal, user equipment (UE), access terminal, terminal unit, terminal station, mobile station, remote station, remote terminal, mobile device, wireless communication device, terminal agent, or terminal equipment. A terminal device includes an indoor device, an outdoor device, a handheld device, or an in-vehicle device, and may be deployed on land, on water (e.g., a ship), or in the air (e.g., on an airplane, balloon, or satellite). A terminal device includes a handheld device, an in-vehicle device, a wearable device, or a computing device with wireless communication capabilities. For example, a terminal device may be a mobile phone, a tablet computer, or a computer with wireless transceiver capabilities. Alternatively, the terminal device may be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, an industrial control wireless terminal, an autonomous driving wireless terminal, a telemedicine wireless terminal, a smart grid wireless terminal, a smart city wireless terminal, a smart home wireless terminal, etc. In embodiments of the present application, an apparatus configured to realize the functions of the terminal device may be a terminal device, or may be a device that can assist the terminal device in realizing the functions, such as a chip system. In embodiments of the present application, the chip system may include a chip, or may include a chip and another discrete device. In embodiments of the present application, the technical solutions provided in embodiments of the present application are described using an example in which the apparatus configured to realize the functions of the terminal device is a terminal device.
[0052] An access network device may also be referred to as a base station. Base stations may include various types of base stations, such as a macro base station, a micro base station (sometimes referred to as a small cell), a relay station, and an access point. In particular, a base station may be an access point (AP) of a wireless local area network (WLAN), a base transceiver station (BTS) of a global system for mobile communications (GSM) or code division multiple access (CDMA), a Node B (NB) of a wideband code division multiple access (WCDMA), an evolved Node B (eNB or eNodeB) of LTE, a relay station, an access point, an in-vehicle device, a wearable device, the next generation Node B (gNB) of a future 5G network, a base station of a future evolved public land mobile network (PLMN), etc.
[0053] A base station typically includes a baseband unit (BBU), a remote radio unit (RRU), an antenna, and a feeder used to connect the RRU and the antenna. The BBU is configured to perform signal modulation. The RRU is configured to perform radio frequency processing. The antenna is configured to convert between guided waves on the cable and space waves in the air. On the one hand, a distributed base station significantly shortens the length of the feeder between the RRU and the antenna, thereby reducing signal loss and feeder costs. On the other hand, the RRU and antenna are small and can be installed anywhere, making network planning more flexible. The RRU may be remotely located. In addition, all BBUs may be centralized and located in a central office (CO). This centralization method significantly reduces the number of base station equipment rooms, reduces the energy consumption of auxiliary devices, especially air conditioning, and significantly reduces carbon emissions. In addition, distributed BBUs can be centrally managed and scheduled after forming a BBU baseband pool through centralization, making resource allocation more flexible. In this mode, all physical base stations evolve into virtual base stations. All virtual base stations share information such as user data transmission and reception and channel quality in the BBU baseband pool, and cooperate with each other to perform joint scheduling.
[0054] In some deployments, a base station may include a centralized unit (CU) and distributed units (DUs). The base station may further include an active antenna unit (AAU). The CU performs some base station functions, and the DU performs some base station functions. For example, the CU processes non-real-time protocols and services to perform functions of the radio resource control (RRC) layer and packet data convergence protocol (PDCP) layer. The DU processes physical layer protocols and real-time services to perform functions of the radio link control (RLC) layer, media access control (MAC), and physical (PHY) layer. The AAU performs some physical layer processing functions, radio frequency processing, and active antenna-related functions. RRC layer information ultimately becomes or is converted from PHY layer information. Therefore, in this architecture, higher layer signaling, such as RRC layer signaling or PDCP layer signaling, can also be considered to be transmitted by the DU, or by the DU and AAU. It should be understood that in the embodiments of the present application, an access network device can be a device including any one or more of a CU node, a DU node, and an AAU node. In addition, a CU can be classified as a network device in a RAN, or a network device in a core network (CN). This is not limited herein.
[0055] Core network devices are configured to implement functions such as mobility management, data processing, session management, policy, and charging. The names of devices implementing core network functions in different access technology systems may differ. This is not limited in this application. Taking the 5G network as an example, logical network elements of the 5G network include an access and mobility management function (AMF) network element, a session management function (SMF) network element, a user plane function (UPF) network element, a policy control function (PCF) network element, a unified data management (UDM) network element, and an application function (AF) network element.
[0056] A DN, sometimes called a packet data network (PDN), is a network located outside an operator network. An operator network can access multiple DNs. To provide multiple possible services for terminal devices, a DN may be equipped with application servers supporting multiple services.
[0057] In Figure 1, Npcf, Nudm, Naf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface sequence numbers. For the meaning of these interface sequence numbers, please refer to the meaning defined in the relevant standard protocol, which is not limited in this document.
[0058] It should be noted that in the following embodiments of the present application, the first device may be understood as a network element having the function of an active antenna unit (AAU) or a radio unit (RU), and the second device may be understood as a network element having the function of a baseband unit (BBU). Alternatively, these network elements may be called by other names, which is not limited in this document. For ease of understanding, an example in which the first device is an AAU and the second device is a BBU is used to describe the following embodiments of the present application.
[0059] The following describes and explains the relevant technical features in the embodiments of the present application, and it should be noted that these descriptions are intended to facilitate the understanding of the embodiments of the present application, and should not be considered as limitations on the scope of protection claimed in the present application.
[0060] 1. Digital Certificates A digital certificate is a data structure signed by a certificate authority (CA) server and includes information about the public key owner, the public key, information about the issuer, a validity period, and extended information. Digital certificates are widely used to ensure the confidentiality of data transmission, the integrity of data exchange, non-repudiation of information transmission, and the authenticity of the identities of data exchange targets. The digital certificate of an AAU in the embodiment of this application is a digital certificate in an AAU used to establish a secure channel between the AAU and a BBU.
[0061] 2. Public and Private Keys Asymmetric encryption technology involves two types of keys: private keys and public keys. The private key is kept by the key pair owner and cannot be made public. The public key is made public by the key pair owner to another person. Typically, the public key is used to encrypt data, and the private key is used to decrypt data encrypted by the public key.
[0062] 3. Digest A hash (HASH) calculation is performed on the text that needs to be sent to obtain a digest corresponding to that text.
[0063] 4. Signature A signature is sometimes called signed data or a digital signature. Usually, a private key is used to encrypt a digest of the text that needs to be transmitted, and the resulting ciphertext is called the signature of the current transmission process.
[0064] 5. Integrity protection / checking Integrity protection / checking is used to determine whether the contents of a message have been altered during transmission and can also be used for identity verification to determine the origin of a message. In particular, a data receiver must receive the transmitted text and determine whether the text is the content sent by the data sender, i.e., whether the text has been tampered with during transmission. Therefore, the data receiver must decrypt the signature based on the public key to obtain a digest of the text, then calculate the digest value using the same HASH algorithm used by the sender, and compare the digest value with the digest of the decrypted text. If the digest value and the digest of the decrypted text match exactly, it means that the text has not been tampered with.
[0065] Note that because an Ethernet link is used between the AAU and the BBU, the AAU and the BBU must use certificates to implement secure eCPRI communication. However, because there is no direct channel between the AAU and the CA server, the AAU cannot renew or manage certificates. For example, Figure 2 is a schematic diagram of a network architecture between a base station and a CA server. As shown in Figure 2, in a 5G communication system, a base station includes an AAU and a BBU. The interface between the BBU and the AAU is called a fronthaul interface, which may be, for example, a common public radio interface (CPRI) or an enhanced common public radio interface (eCPRI). The interface between the BBU and the CA server is called a backhaul interface. Because there is no direct channel between the AAU and the CA server, the AAU cannot apply for or renew the CA server's certificate online.
[0066] In view of this, embodiments of the present application provide a communication method for implementing online renewal / management of digital certificates.
[0067] For example, Figure 3 is a diagram of an application scenario of a communication method according to an embodiment of the present application. As shown in Figure 3, in order to prevent security attacks on the eCRPI channel between the AAU and the BBU, in this embodiment of the present application, transport layer security technology is used to implement transport layer security protection between the BBU and the AAU. In other words, data transmission between the AAU and the BBU can be implemented using TLS technology, or data transmission between the AAU and the BBU is implemented using a TLS channel. The BBU communicates with the CA server using the certificate management protocol version 2 (CMPv2) protocol.
[0068] The communication method and communication device provided in this application are described in detail below.
[0069] 4 is a schematic flowchart of a communication method according to an embodiment of the present application. As shown in FIG. 4, the communication method includes the following steps S401 to S403.
[0070] S401. The BBU receives a first message from the AAU.
[0071] In some possible implementations, the AAU generates a key pair and a certificate request file required to apply for a digital certificate. Typically, the certificate request file is a data file containing information for applying for a certificate from a CA server, such as the AAU's public key information, applicant information, and domain name. The information about the AAU's public key may be the AAU's public key or information for obtaining the AAU's public key. This is not limited in this document. In other words, the certificate request file can be used to apply for a digital certificate for the AAU. The AAU can send a first message to the BBU, and the first message includes the certificate request file. In response, the BBU receives the first message from the AAU. In addition to the certificate request file, the first message may further include some other data related to the certificate request. For details, please refer to the RFC4211 protocol specification. Details will not be described here.
[0072] It should be noted that the AAU sending a first message to the BBU can be understood as sending the first message to the BBU through a transport layer security (TLS) channel. Correspondingly, the BBU receives the first message from the AAU through the TLS channel. Typically, during the manufacturing of the AAU and the BBU, device manufacturers of the AAU and the BBU may incorporate at least one device manufacturer certificate into each of the AAU and the BBU as an identity certificate for each of the AAU and the BBU. In this embodiment of the present application, a certificate incorporated into the AAU by the device manufacturer of the AAU is referred to as an AAU vendor pre-configured certificate or an AAU device certificate. A certificate incorporated into the BBU by the device manufacturer of the BBU is referred to as a BBU vendor pre-configured certificate or a BBU device certificate. For ease of explanation, the AAU vendor pre-configured certificate and the BBU vendor pre-configured certificate may be collectively referred to as a vendor certificate. A secure channel (also referred to as a TLS channel) can be established between the AAU and the BBU based on the vendor pre-configured certificate. In particular, an AAU device certificate is used to establish a secure channel between the AAU and the BBU. A BBU device certificate is used to establish a secure channel between the AAU and the BBU. In addition, a BBU device certificate can be further used to establish a secure channel to a CA. In this embodiment of the present application, the method of establishing a secure channel or a TLS channel between the AAU and the BBU based on a vendor-preconfigured certificate can be based on the method specified in the TLS1.2 and TLS1.3 protocols. Details will not be described here.
[0073] It should be understood that after a secure channel is established between the AAU and the BBU, the AAU can communicate with the BBU through the established secure channel. For example, the AAU sends a first message to the BBU through the established secure channel. The first message includes a certificate request file. It should be noted that the BBU's receipt of the first message from the AAU is equivalent to the AAU allowing the BBU to act on its behalf, complete CMPv2 protocol interaction with a CA server to apply for a digital certificate, and transfer the digital certificate obtained through the application to the AAU. For a detailed process, please refer to the following step description.
[0074] S402. The BBU sends a second message to the certificate authority CA server based on the first message.
[0075] In some possible implementations, the BBU sends a second message to a certificate authority (CA) server based on the first message. The second message includes a certificate request file. Specifically, sending the second message to the CA server based on the first message can be understood as the BBU sending a third message to the AAU, the third message including the certificate request file, the BBU receiving first signature data corresponding to the third message from the AAU, and the BBU sending a second message to the CA server, the second message including the first signature data and the third message. In other words, after the AAU sends the first message including the certificate request file to the BBU, the BBU can generate a third message based on the first message and send the third message to the AAU for signing. Furthermore, the BBU receives the first signature data corresponding to the third message from the AAU, combines the third message with the first signature data to generate a second message, and sends the second message to the CA server. In other words, the BBU can send the third message and the first signature data corresponding to the third message to the CA server.
[0076] Typically, the AAU can sign the third message based on the AAU's private key and send the first signature data obtained by the signature to the BBU. Furthermore, the BBU sends the signed message (i.e., the second message) to the CA server according to the CMPv2 protocol. The third message can also be understood as a certificate request message or a certificate management protocol (CMP) initialization request (IR) message. In addition to the certificate request file, the third message can also include other contents. For details, please refer to the RFC4211 protocol and RFC4210 protocol specifications. Details will not be described here.
[0077] The following describes a process in which the AAU signs the third message based on the private key, and a process in which the CA server performs an integrity check on the third message based on the third message and the first signature data.
[0078] For example, FIG. 5 is a diagram of an integrity protection scenario according to an embodiment of the present application. Typically, after receiving a third message, the AAU performs a hash operation on the third message based on a hash algorithm to obtain a corresponding hash value, and then encrypts the generated hash value using the AAU's private key to obtain first signature data. The AAU then sends the first signature data to the BBU. After receiving the first signature data from the AAU, the BBU can combine the third message and the first signature data and send the combined data (i.e., the second message) to the CA server. Note that the CA server that receives the second message sent by the BBU first analyzes the received second message to obtain the third message and the first signature data obtained by separation. Then, the CA server decrypts the first signature data based on the AAU's public key to obtain a decrypted hash value (hereinafter simply referred to as the first hash value) corresponding to the third message. The CA server then performs a hash calculation on the content of the third message obtained by the separation based on a hash algorithm to obtain a hash value corresponding to the third message (hereinafter simply referred to as the second hash value). Finally, the CA server compares and analyzes the first hash value and the second hash value to obtain the check result for the third message. Typically, if the first hash value is equal to the second hash value, the CA server can determine that the third message was not tampered with during transmission. If the first hash value is not equal to the second hash value, the CA server can determine that the third message was maliciously tampered with during transmission. Typically, if the CA server determines that the second message was tampered with during transmission, it can refuse to issue a digital certificate to the AAU. If the CA server determines that the second message was not tampered with during transmission, it can feed back a digital certificate corresponding to the AAU to the BBU based on the second message.
[0079] S403. The BBU receives a digital certificate from the CA server.
[0080] In some possible implementations, the BBU receives a digital certificate from the CA server. It should be understood that the BBU receiving the digital certificate from the CA server can be understood as the BBU receiving a first response from the CA server for the second message, the first response including the digital certificate. The first response may also be described as a CMP initialization response (IP). In addition to the digital certificate, the first response may further include other content. For specific content included in the first response, please refer to the specifications of the RFC4211 and RFC4210 protocols. Details will not be described here.
[0081] Typically, when the CA server sends the first response to the BBU, it can further send signature data of the first response to the BBU. In other words, the first response can further carry the signature data of the first response, and the CA server sends the first response and the signature data of the first response to the BBU. The signature data of the first response is signature data obtained by the CA server signing a digest of the first response based on the private key of the CA server.
[0082] S404. The BBU sends the digital certificate to the AAU.
[0083] In some possible implementations, after receiving a digital certificate from the CA server, the BBU can send the received digital certificate to the AAU. In particular, after receiving a first response and signature data of the first response from the CA server for the second message, the BBU can check the signature data of the first response based on the CA's public key. If the check result of checking the first response based on the CA's public key and the signature data of the first response is successful, the BBU can send the digital certificate to the AAU. Furthermore, if the check result of checking the first response based on the signature data of the first response is successful, the BBU can send first acknowledgement information to the AAU. The first acknowledgement information can be understood as a Cert Confirm message of the certificate management protocol version 2 (CMPv2) protocol. After receiving the first acknowledgement information, the AAU can sign a digest of the first acknowledgement information based on the AAU's private key to obtain second signature data corresponding to the first acknowledgement information, and send the second signature data to the BBU. Correspondingly, after receiving the second signature data from the AAU, the BBU can send first acknowledgment information and the second signature data to the CA server. After the signature verification performed by the CA server on the first acknowledgment information based on the second signature data is successful, the CA server can feed back the second acknowledgment information to the BBU. The second acknowledgment information may be a public key infrastructure (PKI) Confirm message of the CMPv2 protocol, and can be particularly understood as acknowledgment information fed back by the CA server after the CA server successfully receives the first acknowledgment information. For specific content included in the second acknowledgment information, please refer to the specifications of the RFC4211 protocol and the RFC4210 protocol. Details will not be described here.
[0084] For example, Figure 6 is another schematic flowchart of a communication method according to an embodiment of the present application. The method includes the following steps: S601. The BBU receives a first message from the AAU. The first message includes a certificate request file. S602. The BBU sends a third message to the AAU. Typically, the BBU can generate a third message based on the certificate request file in the first message and send the third message to the AAU for signing. S603. The BBU receives first signature data corresponding to the third message from the AAU. The AAU can sign a digest of the third message based on the AAU's private key to generate first signature data and feed the first signature data back to the BBU. S604. The BBU sends a second message to the CA server. After receiving the first signature data, the BBU can combine the third message with the first signature data and send the combined second message to the CA server. In other words, the second message includes the third message and the first signature data. S605. Receive a first response from the CA server for the second message. The first response includes a digital certificate issued by the CA server to the AAU. Typically, after the CA server receives the second message and the integrity check performed on the third message using the first signature data is successful, the CA server can send the first response to the BBU. The first response includes a digital certificate issued by the CA server to the AAU. Typically, the first response further carries signature data obtained by the CA server signing a digest of the first response based on the CA server's private key. That is, the first response carries signature data corresponding to the first response. S606. The BBU sends the digital certificate to the AAU. After the BBU receives the first response and the integrity check performed on the first response using the signature data of the first response is successful, the BBU can send the digital certificate included in the first response to the AAU. S607: The BBU sends the first acknowledgement information to the AAU. The BBU sends the first acknowledgement information to the AAU, which needs to be signed by the AAU.S608. The BBU receives second signature data for the first acknowledgment information from the AAU. The AAU may sign a digest of the first acknowledgment information based on the AAU's private key and then feed the resulting second signature data back to the BBU. S609. The BBU sends the first acknowledgment information and the second signature data to the CA server. The BBU may combine the first acknowledgment information and the second signature data and then send the combined information to the CA server. S610. The BBU receives second acknowledgment information from the CA server. After an integrity check performed on the first acknowledgment information based on the second signature data is successful, the CA server may return the second acknowledgment information to the BBU. Typically, the second acknowledgment information may carry signature data obtained by the CA server signing a digest of the second acknowledgment information based on the CA server's private key.
[0085] Optionally, in some possible implementations, the BBU sending the digital certificate to the AAU can be further understood as sending the digital certificate to the AAU in response to second acknowledgment information. In other words, after receiving the digital certificate from the CA server, the BBU can further send first acknowledgment information to the AAU if the check result of checking the first response based on the signature data of the first response is successful. The first acknowledgment information can be understood as a Cert Confirm message of the CMPv2 protocol. After receiving the first acknowledgment information, the AAU can sign a digest of the first acknowledgment information based on the private key of the AAU to obtain second signature data corresponding to the first acknowledgment information, and send the second signature data to the BBU. Correspondingly, after receiving the second signature data from the AAU, the BBU can send the first acknowledgment information and the second signature data to the CA server. After the signature verification performed by the CA server on the first acknowledgment information based on the second signature data is successful, the CA server can feed back the second acknowledgment information to the BBU. The second acknowledgment information can be understood as a PKI Confirm message of the CMPv2 protocol. After receiving the second acknowledgment information from the CA server for the first acknowledgment information, the BBU sends a digital certificate to the AAU. Typically, the second acknowledgment information can further carry signature data obtained by the CA server signing a digest of the second acknowledgment information. For ease of explanation, the signature data will be simply referred to as third signature data hereinafter. After the BBU receives the second acknowledgment information and the third signature data from the CA server, if the check result of the integrity check performed on the second acknowledgment information based on the third signature data is successful, the BBU sends a digital certificate to the AAU.
[0086] For example, FIG. 7 is another schematic flowchart of a communication method according to an embodiment of the present application. Details are shown in FIG. 7. S701. The BBU receives a first message from the AAU. The first message includes a certificate request file. S702. The BBU sends a third message to the AAU. Typically, the BBU can generate a third message based on the certificate request file in the first message and send the third message to the AAU for signing. S703. The BBU receives first signature data corresponding to the third message from the AAU. The AAU can sign a digest of the third message based on the AAU's private key to generate first signature data and feed the first signature data back to the BBU. S704. The BBU sends a second message to the CA server. After receiving the first signature data, the BBU can combine the third message with the first signature data and send the combined second message to the CA server. In other words, the second message includes the third message and the first signature data. S705. Receive a first response from the CA server for the second message. The first response includes a digital certificate issued by the CA server to the AAU. Typically, after the CA server receives the second message and the integrity check performed on the third message using the first signature data is successful, the CA server can send the first response to the BBU. The first response includes a digital certificate issued by the CA server to the AAU. Typically, the first response further carries signature data obtained by the CA server signing a digest of the first response based on the CA server's private key. That is, the first response carries signature data corresponding to the first response. S706. The BBU sends first acknowledgment information to the AAU. The BBU sends the first acknowledgment information to the AAU, which needs to be signed by the AAU. S707. The BBU receives second signature data for the first acknowledgment information from the AAU. The AAU may sign the digest of the first acknowledgment information based on the private key of the AAU, and then feed the obtained second signature data back to the BBU. S708. The BBU sends the first acknowledgment information and the second signature data to the CA server.After combining the first acknowledgment information and the second signature data, the BBU can send the combined information to the CA server. S709. The BBU receives the second acknowledgment information from the CA server. After an integrity check performed on the first acknowledgment information based on the second signature data is successful, the CA server can return the second acknowledgment information to the BBU. Typically, the second acknowledgment information can carry signature data obtained by the CA server signing a digest of the second acknowledgment information based on the private key of the CA server. S710. The BBU sends a digital certificate to the AAU. After the BBU receives the second acknowledgment information and after an integrity check performed on the second acknowledgment information based on the signature data of the second acknowledgment information (i.e., the third signature data) is successful, the BBU sends a digital certificate to the AAU.
[0087] It should be noted that the opportunity for the BBU to receive the digital certificate from the CA server and send the digital certificate to the AAU may instead be determined based on an actual scenario, which is not limited in this document. The digital certificate of the AAU may be an operator device certificate, etc., which is not limited in this document.
[0088] It will be appreciated that after the BBU has acted on behalf of the AAU to complete the digital certificate application, the proxy application channel between the AAU and the BBU may be closed, and the AAU can establish a service connection to the BBU using the resulting digital certificate.
[0089] In the following, the communication device provided in the present application will be described in detail with reference to FIGS.
[0090] FIG. 8 is a diagram of the structure of a communication device according to an embodiment of the present application. The communication device shown in FIG. 8 may be configured to perform some or all of the functions of the second device in the method embodiments described in FIGS. 4 to 7. The device may be a second device, a device within the second device, or a device that can be used with the second device. Alternatively, the communication device may be a chip system. The communication device shown in FIG. 8 may include a transceiver unit 801 and a processing unit 802. The processing unit 802 is configured to perform data processing. The transceiver unit 801 is integrated with a receiving unit and a transmitting unit. The transceiver unit 801 may also be referred to as a communication unit. Alternatively, the transceiver unit 801 may be divided into a receiving unit and a transmitting unit. The processing unit 802 below is similar to the transceiver unit 801. Details will not be described again below.
[0091] The transceiver unit 801 is configured to receive a first message from a first device, the first message including a certificate request file, and the certificate request file is used to apply for a digital certificate for the first device.
[0092] The processing unit 802 is configured to send a second message to a certificate authority CA server through the transceiver unit 801 based on the first message, where the second message includes a certificate request file.
[0093] The transceiver unit 801 is configured to receive a digital certificate from a CA server.
[0094] The transceiver unit 801 is configured to transmit a digital certificate to a first device.
[0095] In one possible implementation, the processing unit 802 specifically: sending a third message to the first device through the transceiver unit 801, the third message including the certificate request file; receiving first signature data corresponding to the third message from the first device via the transceiver unit 801; sending a second message to the CA server via the transceiver unit 801, the second message including the first signature data and the third message; It is configured as follows.
[0096] In one possible implementation, the transceiver unit 801 specifically comprises: receiving a first response from the CA server for the second message, the first response including the digital certificate; It is configured as follows.
[0097] In one possible implementation, the first response carries signature data of the first response, and the transceiver unit 801 specifically: checking the first response based on the signature data of the first response, and transmitting first confirmation response information to the CA server based on the check result; receiving second acknowledgment information from the CA server regarding the first acknowledgment information; transmitting a digital certificate to the first device in response to the second acknowledgment information; It is configured as follows.
[0098] In one possible implementation, the transceiver unit 801 specifically comprises: If the check result is that the check is successful, sending first acknowledgment information to the first device; receiving second signature data corresponding to the first acknowledgment information from the first device; sending the first confirmation response information and the second signature data to the CA server; It is configured as follows.
[0099] For other possible implementations of this communication device, please refer to the relevant descriptions of the functions of the access network device in the method embodiments corresponding to Figures 4 to 7. Details will not be described again here.
[0100] 9 is a diagram of the structure of another communication device according to an embodiment of the present application. The communication device shown in FIG. 9 may be configured to perform some or all of the functions of the first device in the method embodiments described in FIGS. 4 to 7. The device may be the first device, a device within the first device, or a device that can be used with the first device. Alternatively, the communication device may be a chip system. The communication device shown in FIG. 9 may include a transceiver unit 901 and a processing unit 902.
[0101] The transceiver unit 901 is configured to send a first message to a second device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device.
[0102] The transceiver unit 901 is configured to receive a digital certificate from a second device.
[0103] In one possible implementation, the transceiver unit 901 is configured to receive a third message from the second device, the third message including a certificate request file.
[0104] This device is a processing unit 902 configured to transmit first signature data corresponding to the third message to the second device through the transceiver unit 901; Further includes:
[0105] In one possible implementation, the transceiver unit 901 specifically includes: receiving first acknowledgment information from the second device; sending second signature data corresponding to the first acknowledgment information to the second device; It is configured as follows.
[0106] For other possible implementations of this communication device, please refer to the relevant descriptions of the functions of the access network device in the method embodiments corresponding to Figures 4 to 7. Details will not be described again here.
[0107] FIG. 10 is a diagram of the structure of another communication device according to an embodiment of the present application. This communication device may be the second device of the embodiment of the present application. As shown in FIG. 10, the second device of this embodiment may include one or more processors 1001, memories 1002, and transceivers 1003. The processor 1001, the memory 1002, and the transceiver 1003 are connected using a bus 1004. The memory 1002 is configured to store a computer program. The computer program includes program instructions. The processor 1001 and the transceiver 1003 are configured to execute the program instructions stored in the memory 1002 to implement the functions of the second device of FIGS. 4 to 7.
[0108] It should be understood that in some possible implementations, the processor 1001 may be a central processing unit (CPU), or the processor may be another general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The memory 1002 may include read-only memory and random access memory and may provide instructions and data for the processor 1001. A portion of the memory 1002 may further include non-volatile random access memory. For example, the memory 1002 may further store information related to the device type.
[0109] FIG. 11 is a diagram of the structure of another communication device according to an embodiment of the present application. This communication device may be the first device of the embodiment of the present application. As shown in FIG. 11, the first device of this embodiment may include one or more processors 1101, memories 1102, and transceivers 1103. The processor 1101, the memory 1102, and the transceiver 1103 are connected using a bus 1104. The memory 1102 is configured to store a computer program. The computer program includes program instructions. The processor 1101 and the transceiver 1103 are configured to execute the program instructions stored in the memory 1102 to implement the functions of the first device of FIGS. 4 to 7.
[0110] It should be understood that in some possible implementations, the processor 1101 may be a central processing unit (CPU), or the processor may be another general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The memory 1102 may include read-only memory and random access memory and may provide instructions and data for the processor 1101. A portion of the memory 1102 may further include non-volatile random access memory. For example, the memory 1102 may further store information related to the device type.
[0111] An embodiment of the present application further provides a computer-readable storage medium, which stores instructions that, when executed on a processor, perform the method steps of the aforementioned method embodiments.
[0112] An embodiment of the present application further provides a computer program product, which, when run on a processor, performs the method steps of the aforementioned method embodiments.
[0113] Those skilled in the art can realize that the example units and steps described with reference to the embodiments disclosed herein can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether a function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can implement the described functions using various methods for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0114] It should be understood that in some embodiments provided in the present application, the disclosed systems, devices, and methods may be implemented in other ways. For example, the described device embodiments are merely examples. For example, the division into units is merely a logical division of function. Units described as separate parts may or may not be physically separate, and parts displayed as units may or may not be physical units, and may be located in one location or distributed over multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments.
[0115] When a function is implemented in the form of a software functional unit and sold or used as an independent product, the function may be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present application, or a portion contributing to the prior art, or a part of the technical solution may be implemented in the form of a software product. This computer software product is stored in a storage medium and includes some instructions that instruct a computer device (which may be a personal computer, a server, a network device, etc.) to perform all or part of the steps of the method described in the embodiments of the present application. The computer-readable storage medium may be any available medium that can be accessed by a computer. By way of example, and not limitation, a computer-readable medium may include random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), universal serial bus flash disk, removable hard disk, another compact disc storage device, a magnetic disk storage medium or another magnetic storage device, or any other medium that can be used to carry or store expected program code in the form of instructions or data structures and that can be accessed by a computer.Additionally, many forms of RAM may be used, such as, by way of example and not limitation, static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (synchlink DRAM, SLDRAM), or direct rambus random access memory (direct rambus RAM, DR RAM).
[0116] The above description is merely a specific implementation of the present application and is not intended to limit the scope of protection of the embodiments of the present application. Any modifications or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the embodiments of the present application shall fall within the scope of protection of the embodiments of the present application. Therefore, the scope of protection of the embodiments of the present application shall be subject to the scope of protection of the claims. [Explanation of symbols]
[0117] 801 Transceiver Unit 802 Processing Unit 901 Transceiver Unit 902 Processing Unit 1001 processor 1002 memory 1003 Transceiver 1004 Bus 1101 processor 1102 memory 1103 Transceiver 1104 Bus
Claims
1. 1. A communication method comprising: receiving a first message from a first device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; sending a second message to a Certificate Authority (CA) server based on the first message, the second message including the certificate request file; receiving a first response from the CA server for the second message, the first response including the digital certificate and carrying signature data of the first response; sending first confirmation response information to the first device when a check result of checking the first response based on the signature data of the first response indicates that the check is successful; receiving second signature data corresponding to the first acknowledgement information from the first device; transmitting the first confirmation response information and the second signature data to the CA server; receiving second acknowledgment information from the CA server for the first acknowledgment information; sending the digital certificate to the first device in response to the second acknowledgment information; A method comprising:
2. The step of sending a second message to a CA server based on the first message comprises: sending a third message to the first device, the third message including the certificate request file; receiving first signature data corresponding to the third message from the first device; sending the second message to the CA server, the second message including the first signature data and the third message; 2. The method of claim 1, comprising:
3. 1. A communication method comprising: sending a first message to a second device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; sending, by the second device, a second message to a certification authority (CA) server based on the first message, and after receiving a first response from the CA server regarding the second message, checking the first response based on signature data of the first response and receiving first confirmation response information from the second device if the check result is that the check is successful, wherein the second message includes the certificate request file, the first response includes the digital certificate, and the first response carries the signature data of the first response; sending second signature data corresponding to the first acknowledgement information to the second device; receiving the digital certificate from the second device in response to second acknowledgment information, the second acknowledgment information being received by the second device from the CA server for the first acknowledgment information after the second device transmits the first acknowledgment information and the second signature data to the CA server; A method comprising:
4. The method comprises: receiving a third message from the second device after sending the first message to the second device, the third message including the certificate request file; sending first signature data corresponding to the third message to the second device; 4. The method of claim 3, further comprising:
5. a communication device, the communication device being a second device; a transceiver unit configured to receive a first message from a first device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; and a processing unit configured to send a second message to a Certificate Authority (CA) server through the transceiver unit based on the first message, the second message including the certificate request file; and Equipped with the transceiver unit is configured to receive a first response from the CA server for the second message, the first response including the digital certificate and carrying signature data of the first response; a transceiver unit configured to: send first acknowledgment information to the first device; receive second signature data corresponding to the first acknowledgment information from the first device; send the first acknowledgment information and the second signature data to the CA server; receive second acknowledgment information from the CA server for the first acknowledgment information; and send the digital certificate to the first device in response to the second acknowledgment information, when a check result of checking the first response based on the signature data of the first response indicates that the check is successful.
6. a communication device, the communication device being a first device; a transceiver unit configured to transmit a first message to a second device, the first message including a certificate request file, the certificate request file being used to apply for a digital certificate for the first device; the transceiver unit is configured to receive first confirmation response information from the second device when, after the second device sends a second message to a certification authority (CA) server based on the first message and receives a first response from the CA server for the second message, the second device checks the first response based on signature data of the first response and the check result is that the check is successful, the second message includes the certificate request file, the first response includes the digital certificate, and the first response carries the signature data of the first response; the transceiver unit is configured to send second signature data corresponding to the first acknowledgment information to the second device and receive the digital certificate from the second device in response to the second acknowledgment information, the second acknowledgment information being received from the CA server by the second device for the first acknowledgment information after the second device has sent the first acknowledgment information and the second signature data to the CA server.
7. A communications device comprising a processor and a transceiver, the processor and the transceiver configured to execute computer programs or instructions stored in at least one memory to enable the communications device to perform a method according to claim 1 or 2.
8. A communications device comprising a processor and a transceiver, the processor and the transceiver configured to execute computer programs or instructions stored in at least one memory to enable the communications device to perform a method according to claim 3 or 4.
9. A computer program comprising computer program code, the computer program code performing the method according to claim 1 or 2 when run on a computer.
10. A computer program comprising computer program code, the computer program code being adapted to perform the method according to claim 3 or 4 when run on a computer.
Citation Information
Patent Citations
JPP7113269B
Methods And Apparatus For Use In Obtaining A Digital Certificate For A Mobile Communication Device
US20090222657A1
Method and system for updating and using digital certificates
US20110302411A1
Method and device for certificate application
WO2021120924A1