Certificate revocation list updating method and related apparatus
By obtaining the pending records and user configuration information of the certificate revocation list, CRL updates are triggered dynamically, solving the problem of insufficient periodic updates in the prior art, and improving communication security and flexibility.
Patent Information
- Application Number
- PCT/CN2023/143240
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-03
AI Technical Summary
In the prior art, the update of the certificate revocation list (CRL) is mostly periodic update, which cannot meet the update requirements in diverse scenarios, resulting in insufficient communication security.
By obtaining reference information, including pending revocation records, certificate types, number of CRL accesses, update cycles and user-configured update timelines, CRL updates are triggered dynamically to ensure that the update time is earlier than the preset cycle, and improve flexibility and timeliness.
It realizes flexible and timely updates of the certificate revocation list, improves communication security between terminals, and avoids the abuse of revoked certificates.
Smart Images

Figure CN2023143240_03072025_PF_FP_ABST
Abstract
Description
A certificate revocation list updating method and related device Technical Field
[0001] The present application relates to the field of information security, and in particular to a certificate revocation list updating method and related devices. Background Art
[0002] Certificate revocation list (CRL) query is a critical operation in the public key infrastructure based on digital certificates. A certificate revocation list (CRL), also known as a certificate revocation list, is a list of revoked certificates that helps systems or applications verify the status of certificates to ensure that untrusted certificates are not abused.
[0003] Currently, most CRLs are updated by the issuing authority of the certificate periodically, and the recipient needs to wait until the next update time to obtain the latest CRL, which cannot meet the CRL update needs in diverse scenarios.
[0004] Summary of the Invention
[0005] The present application discloses a certificate revocation list updating method and related devices, which improve the flexibility and timeliness of certificate revocation list updating and are conducive to improving communication security between terminals.
[0006] In a first aspect, the present application provides a certificate revocation list updating method, the method comprising: obtaining reference information, the reference information including a pending revocation record of a first certificate revocation list CRL, the certificate type of the revoked certificate, the number of times the first CRL has been accessed, the preset update cycle of the first CRL, and at least one of the update timeliness level of the first CRL configured by the user, each revocation record including a certificate revoked after the first CRL was issued; if the reference information meets the update condition, updating the first CRL to obtain a second CRL, wherein the interval between the issuance time of the first CRL and the issuance time of the second CRL is less than the preset update cycle of the first CRL.
[0007] It can be understood that the revocation record to be processed is a revocation record newly generated after the first CRL is issued.
[0008] Exemplarily, the certificate types may be divided into device certificates and pseudonym certificates.
[0009] Accessing the first CRL includes but is not limited to at least one of a user requesting to query whether a certain certificate is included in the first CRL, a user requesting to download the first CRL, and a user requesting to query the release time of the first CRL.
[0010] For example, the user-configured first CRL update timeliness level reflects the user's requirement for the first CRL update timeliness. The user may be, for example, a user of the first CRL, a holder or user of a terminal device (e.g., a vehicle, a mobile phone, etc.), etc., without specific limitation herein. It is understood that the user-configured first CRL update timeliness level may not be configured specifically for the first CRL, but may apply not only to the first CRL but also to other CRLs.
[0011] For example, the first CRL update timeliness level can be divided into at least two levels, for example, level 1 and level 2. Compared to the first CRL update timeliness level configured by the user as level 2, the first CRL update timeliness level configured by the user as level 1 indicates that the user has higher requirements for communication security, meaning that the user expects the first CRL to be updated more promptly.
[0012] Exemplarily, updating the first CRL may include updating the first CRL based on the revocation records to be processed. Here, the first CRL may be updated based on some or all of the revocation records to be processed, where "partial revocation records" include, for example, revocation records in the revocation records to be processed that meet the update condition.
[0013] In the above method, an update of the first CRL is triggered when the reference information satisfies an update condition, and the update occurs before the next preset update time of the first CRL, unlike existing solutions that periodically update the first CRL at a fixed time. In addition, the reference information includes at least one of the following: new revocation records, the number of times the first CRL has been accessed, a user-configured update timeliness level for the first CRL, the type of revoked certificate, and a preset update period for the first CRL. This fully considers the impact of various factors on the update time of the first CRL, provides a personalized solution for CRL updates, improves the flexibility and timeliness of certificate revocation list updates, and facilitates increased communication security.
[0014] Optionally, the method further includes: publishing the second CRL.
[0015] Exemplarily, the method is applied to a certificate revocation device (i.e., for updating a certificate revocation list). When the certificate revocation device is integrated with a certificate management device (e.g., for issuing and revoking certificates), the certificate revocation device may issue the second CRL to the user. If the certificate revocation device and the certificate management device are separately provided, the certificate revocation device may issue the second CRL to the certificate management device, which then issues the second CRL to the user. Alternatively, the certificate revocation device may directly issue the second CRL to the user.
[0016] By implementing the above implementation method, the latest CRL (ie, the second CRL) is published in time, so that the receiver of the CRL can obtain the latest certificate revocation list in time, thus preventing the revoked certificates from being abused.
[0017] Optionally, the reference information includes the revocation record to be processed and the certificate type of the revoked certificate, and the update condition includes: there is a revocation record of the first certificate, the certificate type of the first certificate is a device certificate and the device type corresponding to the first certificate is a critical device.
[0018] Here, device types can be categorized as critical devices and non-critical devices. For example, in a vehicle, critical devices refer to devices that are essential for the safe communication of the entire vehicle. The vehicle's in-vehicle communication box (TBox), which serves as a wireless gateway, can be considered a critical device, while the remaining components in the vehicle can be considered non-critical devices.
[0019] By implementing the above implementation, when there is a revocation record of a key device having its device certificate revoked in the revocation record to be processed, the first CRL can be updated in a timely manner, which is beneficial to improving communication security.
[0020] Optionally, the reference information includes the revocation record to be processed and the certificate type of the revoked certificate, and the update condition includes: there is a revocation record of the revoked certificate of the first terminal, and the certificate type of the revoked certificate of the first terminal is a pseudonymous certificate.
[0021] Here, the revocation of the certificate of the first terminal may be: all pseudonym certificates of the first terminal are revoked. That is, when there is a revocation record in the revocation records to be processed indicating that all pseudonym certificates of the first terminal are revoked, the update of the first CRL may be triggered.
[0022] Optionally, the update condition includes at least one of the following conditions:
[0023] The number of the revocation records to be processed reaches a first threshold;
[0024] The number of times the first CRL is accessed reaches a second threshold; and
[0025] The current time interval from the issuance of the first CRL exceeds the first duration but does not reach the preset update period of the first CRL.
[0026] For example, the update condition in the aforementioned "update condition includes at least one of the following conditions" may be determined to satisfy the premise that "all certificates included in the pending revocation record are certificates of non-critical devices." Alternatively, the update condition may be determined to satisfy the premise that "all certificates included in the pending revocation record are certificates of non-critical devices and the reference information includes a user-configured update validity level of the first CRL as level 1."
[0027] The implementation of the above-mentioned method also considers the impact on the update time of the first CRL from at least one dimension of the number of revocation records to be processed, the number of times the first CRL is accessed, and the current time from the release of the first CRL, thereby increasing the flexibility of the certificate revocation list update.
[0028] Exemplarily, publishing the second CRL includes publishing the second CRL to users who have configured, in the reference information, an update validity level of the first CRL as level 1. In this way, a dedicated service is provided to users who have configured an update validity level of the first CRL as level 1, enabling these users to obtain the latest certificate revocation list in a timely manner, thereby preventing revoked certificates from being misused.
[0029] Optionally, the update condition includes: the current time from the publication of the first CRL exceeds a second time period but has not reached the preset update period of the first CRL. Exemplarily, the judgment of the update condition can meet the premise that "the certificates included in the revocation record to be processed are all certificates of non-critical devices." Alternatively, the judgment of the update condition can meet the premise that "the certificates included in the revocation record to be processed are all certificates of non-critical devices and the update validity level of the first CRL configured by the user in the reference information is all level two."
[0030] Exemplarily, the second duration is greater than or equal to the first duration.
[0031] Optionally, the update condition includes: a comprehensive score corresponding to the reference information reaches a target threshold, where the comprehensive score corresponding to the reference information is obtained by weighted summation based on the number of revocation records to be processed, the number of times the first CRL has been accessed, and the current time since the first CRL was published. Here, the target threshold may be preset.
[0032] Exemplarily, when the reference information further includes the update timeliness level of the first CRL configured by the user, the target threshold may be set to different values depending on whether the update timeliness level of the first CRL configured by the user in the reference information is the first level.
[0033] By implementing the above implementation, a comprehensive score may be obtained by weighted summing of factors affecting the update time of the first CRL. When it is determined that the comprehensive score reaches a target threshold, updating of the first CRL is triggered.
[0034] Optionally, if the first terminal is compromised or the amount of private data leakage of the first terminal reaches a third threshold, the revocation record to be processed includes a revocation record of the first terminal's pseudonym certificate being revoked. Here, the revocation of the first terminal's pseudonym certificate means that all pseudonym certificates of the first terminal are revoked.
[0035] Optionally, obtaining reference information includes: receiving the reference information sent by the certificate management device; or obtaining at least part of the reference information from at least one of a terminal, a roadside device, and a network side device.
[0036] Exemplarily, obtaining at least part of the reference information from at least one of a terminal, a roadside device, and a network-side device includes: receiving monitoring information of a first terminal from a roadside device; detecting, based on the monitoring information, that the first terminal has been compromised or that the amount of leakage of the first terminal's private data has reached a third threshold, revoking the pseudonym certificate of the first terminal and generating a corresponding revocation record. Here, revoking the pseudonym certificate of the first terminal may be revoking all pseudonym certificates of the first terminal. When the certificate revocation device used in this method is provided separately from the certificate management device, the above-mentioned revocation of the certificate and generation of the corresponding revocation record may be performed by the certificate management device.
[0037] By implementing the above implementation, the methods of obtaining reference information are diversified and can be applied to different application scenarios, making the method more generalizable.
[0038] Exemplarily, after obtaining the reference information, update indication information may also be received; in response to the update indication information, the first CRL is updated according to the reference information to obtain the second CRL.
[0039] By implementing the above implementation, the first CRL can also be updated immediately based on the received update indication information, thereby improving the timeliness of certificate revocation list updates and facilitating improved communication security between terminals.
[0040] In second aspect, the present application provides a certificate revocation list updating method, the method comprising: obtaining reference information, the reference information including the pending revocation records of a first certificate revocation list CRL, the certificate type of the revoked certificate, the number of times the first CRL has been accessed, the preset update cycle of the first CRL and at least one of the update timeliness level of the first CRL configured by the user, each revocation record including a certificate revoked after the first CRL was issued; sending the reference information to a certificate revocation device, the reference information being used to update the first CRL to obtain a second CRL if the reference information meets the update condition, wherein the interval between the publication time of the first CRL and the publication time of the second CRL is less than the preset update cycle of the first CRL.
[0041] Here, terms such as certificate type, renewal validity level, etc. can refer to the description of the corresponding content in the first aspect above.
[0042] This method can be applied to a certificate management device, which can be responsible for issuing certificates, revoking corresponding certificates based on real-time monitored information, and generating corresponding revocation records. The certificate management device can be, for example, a server of a certificate authority, or a component within the server, such as a chip or integrated circuit.
[0043] In the above method, reference information is collected, and the reference information includes at least one of the following: new revocation records, the number of times the first CRL is accessed, the user-configured update timeliness level of the first CRL, the type of revoked certificate, the preset update period of the first CRL, etc., and fully considers the impact of various factors on the update time of the first CRL. The reference information is reported to the certificate revocation device in a timely manner, which is conducive to improving the flexibility and timeliness of the certificate revocation list update and also helps to increase the security of communication.
[0044] Optionally, the method further includes: receiving the second CRL issued by the certificate revocation device.
[0045] Illustratively, the second CRL includes part or all of the certificates recorded in the revocation record to be processed.
[0046] By implementing the above implementation, the certificate management device can obtain the latest CRL, ie, the second CRL, from the certificate revocation device.
[0047] Optionally, before receiving the second CRL issued by the certificate revocation device, the method further includes: receiving query information sent by the terminal, the query information being used to request querying the latest CRL; sending the query information to the certificate revocation device; and after receiving the second CRL, issuing the second CRL to the terminal.
[0048] By implementing the above implementation method, the terminal can query the certificate revocation device for the latest CRL through the certificate management device, so that the certificate management device can forward the second CRL obtained from the certificate revocation device to the corresponding terminal, so that the terminal can obtain the latest CRL in time, avoiding the abuse of revoked certificates.
[0049] Optionally, the acquiring of reference information includes: obtaining at least part of the reference information from at least one of a terminal, a roadside device, and a network side device.
[0050] In implementing the above-mentioned implementation method, the terminal, roadside equipment and network-side equipment can all serve as data source devices for providing reference information. The certificate management device obtains reference information in ways that include but are not limited to: directly obtaining from the data source device (for example, the first CRL update validity level configured by the user); obtaining based on information provided by the data source device (for example, revocation records, the number of times the first CRL has been accessed, etc.), etc. At least one of the following.
[0051] Optionally, obtaining at least part of the reference information from at least one of the terminal, roadside equipment and network side equipment includes: receiving monitoring information of the first terminal by the roadside equipment; detecting based on the monitoring information that the first terminal has been hacked or the amount of leakage of the privacy data of the first terminal reaches a first threshold, revoking the pseudonym certificate of the first terminal and generating a corresponding revocation record.
[0052] Here, revoking the pseudonym certificate of the first terminal means revoking all pseudonym certificates of the first terminal.
[0053] By implementing the above implementation, when the certificate management device detects that the terminal has been compromised or the amount of leakage of the terminal's private data reaches a privacy leakage threshold, it can promptly revoke all pseudonym certificates of the terminal and generate corresponding revocation records.
[0054] In a third aspect, the present application provides a device for updating a certificate revocation list, the device comprising: an acquisition unit for acquiring reference information, the reference information including a pending revocation record of a first certificate revocation list CRL, the certificate type of the revoked certificate, the number of times the first CRL has been accessed, the preset update cycle of the first CRL, and at least one of the update timeliness level of the first CRL configured by the user, each revocation record including a certificate revoked after the first CRL was issued; a processing unit for updating the first CRL to obtain a second CRL when the reference information meets the update condition, wherein the interval between the issuance time of the first CRL and the issuance time of the second CRL is less than the preset update cycle of the first CRL.
[0055] Optionally, the device further includes a sending unit, configured to: publish the second CRL.
[0056] Optionally, the reference information includes the revocation record to be processed and the certificate type of the revoked certificate, and the update condition includes: there is a revocation record of the first certificate, the certificate type of the first certificate is a device certificate and the device type corresponding to the first certificate is a critical device.
[0057] Optionally, the reference information includes the revocation record to be processed and the certificate type of the revoked certificate, and the update condition includes: there is a revocation record of the revoked certificate of the first terminal, and the certificate type of the revoked certificate of the first terminal is a pseudonymous certificate.
[0058] Optionally, the update condition includes at least one of the following conditions:
[0059] The number of the revocation records to be processed reaches a first threshold;
[0060] The number of times the first CRL is accessed reaches a second threshold; and
[0061] The current time interval from the issuance of the first CRL exceeds the first duration but does not reach the preset update period of the first CRL.
[0062] For example, the update condition in the aforementioned "update condition includes at least one of the following conditions" may be determined to satisfy the premise that "all certificates included in the pending revocation record are certificates of non-critical devices." Alternatively, the update condition may be determined to satisfy the premise that "all certificates included in the pending revocation record are certificates of non-critical devices and the reference information includes a user-configured update validity level of the first CRL as level 1."
[0063] Exemplarily, the sending unit is specifically configured to: publish the second CRL to a user whose update timeliness level of the first CRL is configured as the first level in the reference information.
[0064] Optionally, the update condition includes: the current time from the publication of the first CRL exceeds a second time period but has not reached the preset update period of the first CRL. Exemplarily, the judgment of the update condition can meet the premise that "the certificates included in the revocation record to be processed are all certificates of non-critical devices." Alternatively, the judgment of the update condition can meet the premise that "the certificates included in the revocation record to be processed are all certificates of non-critical devices and the update validity level of the first CRL configured by the user in the reference information is all level two."
[0065] Optionally, the update condition includes: the comprehensive score corresponding to the reference information reaches a target threshold, and the comprehensive score corresponding to the reference information is obtained by weighted summation based on the number of revocation records to be processed, the number of times the first CRL is accessed, and the current time from the release of the first CRL.
[0066] Optionally, the first terminal is hacked or the amount of leakage of the privacy data of the first terminal reaches a third threshold, and the revocation record to be processed includes a revocation record of the pseudonym certificate of the first terminal being revoked.
[0067] Optionally, the acquisition unit is specifically used to: receive the reference information sent by the certificate management device; or obtain at least part of the reference information from at least one of a terminal, a roadside device and a network side device.
[0068] Optionally, the acquisition unit is further configured to receive update indication information; and the processing unit is configured to: in response to the update indication information, update the first CRL according to the reference information to obtain the second CRL.
[0069] In a fourth aspect, the present application provides a device for updating a certificate revocation list, the device comprising: an acquisition unit for acquiring reference information, the reference information including a pending revocation record of a first certificate revocation list CRL, the certificate type of the revoked certificate, the number of times the first CRL has been accessed, the preset update cycle of the first CRL, and at least one of the update timeliness level of the first CRL configured by the user, each revocation record including a certificate revoked after the first CRL was issued; a sending unit for sending the reference information to a certificate revocation device, the reference information being used to update the first CRL to obtain a second CRL when the reference information meets an update condition, wherein the interval between the issuance time of the first CRL and the issuance time of the second CRL is less than the preset update cycle of the first CRL.
[0070] Optionally, the acquiring unit is further configured to: receive the second CRL issued by the certificate revocation device.
[0071] Optionally, the acquisition unit is further used to receive query information sent by the terminal, the query information being used to request querying the latest CRL; the sending unit is further used to send the query information to the certificate revocation device; and after the acquisition unit receives the second CRL, publish the second CRL to the terminal.
[0072] Optionally, the acquisition unit is specifically configured to obtain at least part of the reference information from at least one of a terminal, a roadside device, and a network side device.
[0073] Optionally, the acquisition unit is specifically used to: receive monitoring information of the first terminal by the roadside equipment; the device also includes a processing unit, which is used to detect based on the monitoring information that the first terminal has been hacked or the amount of leakage of the privacy data of the first terminal has reached a first threshold, revoke the pseudonym certificate of the first terminal and generate a corresponding revocation record.
[0074] In a fifth aspect, the present application provides a device for updating a certificate revocation list, the device comprising a processor and a memory, wherein the memory is used to store program instructions; the processor calls the program instructions in the memory so that the device executes the method in the first aspect or any possible implementation of the first aspect, or executes the method in the second aspect or any possible implementation of the second aspect.
[0075] In the sixth aspect, the present application provides a certificate revocation list update system, which includes a first device, or includes a first device and a second device, wherein the first device is used to execute the method in the first aspect or any possible implementation of the first aspect, and the second device is used to execute the method in the second aspect or any possible implementation of the second aspect.
[0076] Illustratively, the first device may be the device described in the third aspect or any possible implementation of the third aspect, or the device described in the fifth aspect for performing the method of the first aspect. The second device may be the device described in the fourth aspect or any possible implementation of the fourth aspect, or the device described in the fifth aspect for performing the method of the second aspect.
[0077] In the seventh aspect, the present application provides a computer-readable storage medium comprising computer instructions, which, when executed by a processor, implement the method of the above-mentioned first aspect or any possible implementation of the first aspect, or implement the method of the above-mentioned second aspect or any possible implementation of the second aspect.
[0078] In an eighth aspect, the present application provides a computer program product, which, when executed by a processor, implements the method of the above-mentioned first aspect or any possible implementation of the first aspect, or implements the method of the above-mentioned second aspect or any possible implementation of the second aspect.
[0079] Illustratively, the computer program product may include a software product, such as a software installation package, or a hardware product, such as a computer-readable storage medium. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] FIG1A is a schematic diagram of the architecture of a certificate revocation list updating system provided in an embodiment of the present application;
[0081] FIG1B is a schematic diagram of the architecture of another certificate revocation list updating system provided in an embodiment of the present application;
[0082] FIG2 is a flow chart of a method for updating a certificate revocation list provided in an embodiment of the present application;
[0083] FIG3 is a schematic diagram of some certificate revocation list update scenarios provided in an embodiment of the present application;
[0084] FIG4 is a flowchart of another method for updating a certificate revocation list provided in an embodiment of the present application;
[0085] FIG5 is a schematic structural diagram of an apparatus for updating a CRL according to an embodiment of the present application;
[0086] FIG6 is a schematic structural diagram of an apparatus for CRL updating provided in an embodiment of the present application;
[0087] FIG7 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0088] It should be noted that the prefixes such as "first" and "second" used in this application are only for distinguishing different description objects, and do not have any limiting effect on the position, order, priority, quantity or content of the described objects. For example, if the described object is a "field", then the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the described object is a "level", then the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of described objects is not limited by the prefix and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," then the "first device" and the "second device" can be the same device, the same type of device, or different types of devices. For another example, if the described object is "information," then the "first information" and the "second information" can be information of the same content or information of different contents. In short, the use of prefixes to distinguish the described objects in the embodiments of this application does not constitute a limitation on the described objects. For the description of the described objects, please refer to the description in the context of the claims or embodiments, and the use of such prefixes should not constitute an unnecessary limitation.
[0089] It should be noted that the descriptions used in the embodiments of the present application, such as "at least one of a1, a2, ..., and an" include any one of a1, a2, ..., and an existing alone, and any combination of any multiple of a1, a2, ..., and an, each of which can exist alone. For example, the description "at least one of a, b, and c" includes a alone, b alone, c alone, a combination of a and b, a combination of a and c, a combination of b and c, or a combination of ab and c.
[0090] To facilitate understanding, the following first introduces relevant terms that may be involved in the embodiments of this application.
[0091] (1) Pseudo-name certificate
[0092] A pseudonymous certificate, also known as an anonymous certificate, is a digital certificate used for authentication and encrypted communications without publicly revealing the true identity of the certificate holder. It uses a pseudonym or pseudonym in place of real personal identification information, thereby protecting personal privacy.
[0093] For example, a pseudonymous certificate includes a public key and related identity information, but this information is replaced with a pseudonym or pseudonym. When communicating with other parties, the certificate holder can use the pseudonym for authentication without having to reveal their true identity.
[0094] (2) Equipment Certificate
[0095] A device certificate is a digital certificate. Each device has a unique device certificate that verifies and identifies the identity of a specific physical or virtual device, ensuring that the device is legitimate, trusted, and authorized to perform specific operations. These devices include but are not limited to computers, servers, smartphones, routers, and more.
[0096] These certificates use asymmetric cryptography, typically based on a public key infrastructure (PKI), to ensure that only devices with a valid certificate can communicate securely. For example, the issuer of a certificate signs the certificate using its private key, and the verifier verifies the signature using the issuer's public key to ensure the certificate's authenticity.
[0097] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.
[0098] The certificate revocation list updating system provided in the embodiment of the present application can be used to implement the update of the certificate revocation list CRL.
[0099] Before introducing the certificate revocation list update system, we first introduce the three functional modules required for implementing the update process of the certificate revocation list (CRL). Here, the three functional modules include: a certificate revocation module, a CRL update module, and a CRL storage module. The certificate revocation module can be used to revoke corresponding certificates based on real-time monitored information to generate reference information. The CRL update module is used to update the CRL for pending revocation records in the reference information when the reference information meets the update conditions. The CRL storage module is used to store the updated CRL. Here, the reference information and update conditions can be referred to the relevant description of the following method embodiment. For the sake of brevity, they are not repeated here.
[0100] Based on the different locations where these three functional modules are deployed, the corresponding certificate revocation list update system is also different. In the embodiment of the present application, the certificate revocation list update system can be, for example, any of the following forms:
[0101] The first one:
[0102] The CRL update module and CRL storage module are deployed on the same device, and the certificate revocation module is deployed on another device.
[0103] See Figure 1A, which is a schematic diagram of the architecture of a certificate revocation list update system provided in an embodiment of the present application. As shown in Figure 1A, the system includes Device 1 and Device 2, wherein Device 1 is deployed with a certificate revocation module, and Device 2 is deployed with a CRL update module and a CRL storage module. Device 1 and Device 2 can communicate wirelessly or wired.
[0104] In FIG1A , after updating the CRL, device 2 may store the updated CRL locally.
[0105] The second type:
[0106] The certificate revocation module, CRL update module, and CRL storage module are deployed on different devices respectively.
[0107] See Figure 1B, which is a schematic diagram of the architecture of another certificate revocation list update system provided in an embodiment of the present application. As shown in Figure 1B, the system includes Device 3, Device 4, and Device 5. Device 3 is deployed with a certificate revocation module, Device 4 is deployed with a CRL update module, and Device 5 is deployed with a CRL storage module. Any two of Device 3, Device 4, and Device 5 can communicate with each other via wireless or wired means.
[0108] In Figure 1B, after updating the CRL, device 4 needs to send the updated CRL to device 5 for storage. In addition, device 5 can provide device 3 with a query service for the latest CRL.
[0109] In some possible embodiments, the certificate revocation module, CRL update module, and CRL storage module may also be deployed on the same device. In this case, the device has all the functions of the three functional modules described above. Alternatively, the certificate revocation module and CRL update module may be deployed on the same device, and the CRL storage module may be deployed on another device, which is not limited here.
[0110] The certificate revocation list update system shown in FIG1B can be applied to a variety of application scenarios, such as the following application scenarios: mobile internet (MI), industrial control (industrial control), self-driving, transportation safety (transportation safety), Internet of Things (IoT), smart city (smart city), or smart home (smart home).
[0111] The certificate revocation list update system shown in Figure 1B can be applied to a variety of network types, for example, one or more of the following network types: SparkLink, long term evolution (LTE) network, 5th generation mobile communication technology (5G), wireless local area network (for example, Wi-Fi), Bluetooth (BT), Zigbee, or in-vehicle short-range wireless communication network, etc.
[0112] It should be noted that Figures 1A and 1B are merely exemplary architecture diagrams, and do not limit the number of network elements included in any of the certificate revocation list update systems shown in Figures 1A and 1B , which may also be in other forms. Furthermore, the method provided in the embodiments of the present application can be applied to the certificate revocation list update system shown in any of Figures 1A and 1B . Of course, the method provided in the embodiments of the present application can also be applied to other certificate revocation list update systems, and the embodiments of the present application are not limited thereto.
[0113] See Figure 2, which is a flow chart of a certificate revocation list updating method provided in an embodiment of the present application. This method can be applied to a certificate revocation device. The certificate revocation device can be, for example, device 2 in Figure 1A, device 4 in Figure 1B, or a device that integrates at least the certificate revocation module and CRL update module, without specific limitation herein. The method includes but is not limited to the following steps:
[0114] S201: Obtain reference information, the reference information including at least one of the pending revocation record of the first CRL, the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update period of the first CRL, and the user-configured update timeliness level of the first CRL.
[0115] Wherein, each revocation record includes a certificate revoked after the first CRL is issued. It can be understood that the revocation record to be processed is a revocation record newly generated after the first CRL is issued.
[0116] Here, the reasons for certificate revocation include but are not limited to at least one of the following: certificate expiration, certificate holder requesting revocation (for example, no longer needed, private key lost or certificate leaked, etc.), certificate holder violating certificate policy, certificate authority discovering problems with the certificate, certificate private key leaked, and certificate holder's identity authentication problems.
[0117] For example, if a first vehicle is compromised or the amount of private data leaked from the first vehicle reaches a privacy leakage threshold, the pending revocation record includes a revocation record for the first vehicle's pseudonym certificate. Here, revocation of the first vehicle's pseudonym certificate refers to the revocation of all pseudonym certificates for the first vehicle. The privacy leakage threshold can be a custom setting or a factory default setting.
[0118] Exemplarily, the certificate type of the second certificate of the second vehicle is a pseudonymous certificate. When the second certificate expires or the private key of the second certificate is leaked, the revocation record to be processed includes a revocation record of the second certificate being revoked.
[0119] Here, the first CRL is issued by the certificate revocation device and is the CRL most recently issued by the certificate revocation device.
[0120] For example, the certificate types can be divided into device certificates and pseudonym certificates. Here, the device certificates and pseudonym certificates can refer to the description of the corresponding terms above and will not be repeated here.
[0121] Illustratively, the first CRL being accessed includes, but is not limited to, at least one of the following situations: a user requests to query whether a certain certificate is included in the first CRL, a user requests to download the first CRL, a user requests to query the release time of the first CRL, etc. It will be understood that the number of times the first CRL is accessed is also counted starting from the time the first CRL is released.
[0122] Here, when the certificate revocation device and the certificate management device are separately provided, the preset update period of the first CRL may be configured by the certificate management device. In this case, the reference information includes the preset update period of the first CRL. When the certificate management device is integrated into the certificate revocation device, the preset update period of the first CRL may be obtained locally by the certificate revocation device. It will be understood that the preset update period of the first CRL is not limited to the first CRL but may also apply to other CRLs and is not specifically limited here.
[0123] Here, the user-configured first CRL update timeliness level reflects the user's requirement for the first CRL update timeliness. The user may be, for example, a user of the first CRL, a holder or user of a terminal device (e.g., a vehicle, a mobile phone, etc.), etc., without specific limitation herein. It will be understood that the user-configured first CRL update timeliness level is not specifically configured for the first CRL and may also be applicable to other CRLs.
[0124] Exemplarily, the first CRL update timeliness level can be divided into at least two levels, such as the first level and the second level. Specifically, compared to the user-configured first CRL update timeliness level of the second level, the user-configured first CRL update timeliness level of the first level indicates that the user has higher requirements for communication security, meaning that the user expects the first CRL to be updated more promptly. As an example, a first CRL update timeliness level of the first level means that the user is sensitive to the update timeliness of the first CRL; a first CRL update timeliness level of the second level means that the user is not sensitive to the update timeliness of the first CRL.
[0125] Furthermore, the first CRL update timeliness level may be represented, for example, by bit mapping, binary value, or threshold comparison, which is not specifically limited here.
[0126] In one implementation, obtaining the reference information includes: receiving the reference information sent by the certificate management device. In this case, the certificate revocation device and the certificate management device are provided separately.
[0127] In one implementation, obtaining the reference information includes: obtaining at least part of the reference information from at least one of a terminal, a roadside device, and a network-side device. For example, when the certificate management device is integrated into the certificate revocation device, the terminal, the roadside device, and the network-side device can all serve as data source devices for providing the reference information. Obtaining the reference information includes, but is not limited to, at least one of the following methods: directly obtaining the reference information from the data source device (e.g., the user-configured first CRL update validity level); obtaining the reference information based on information provided by the data source device (e.g., revocation records, the number of times the first CRL has been accessed, etc.).
[0128] Here, the roadside equipment can be, for example, a road side unit (RSU), multi-access edge computing (MEC) or sensor, or a component or chip inside these devices, or a system-level device composed of RSU and MEC, or a system-level device composed of RSU and sensors, or a system-level device composed of RSU, MEC and sensors.
[0129] The terminal can be, for example, intelligent transportation equipment (such as vehicles, ships, drones, trains, vans, trucks, etc.), intelligent terminals (mobile phones, computers, tablets, PDAs, desktops, headphones, speakers, wearable devices, vehicle-mounted equipment, virtual reality equipment, augmented reality equipment, etc.), smart home equipment (such as televisions, sweeping robots, smart desk lamps, audio systems, smart lighting systems, electrical control systems, home background music, home theater systems, intercom systems, video surveillance, etc.), intelligent manufacturing equipment (such as robots, industrial equipment, intelligent logistics, smart factories, etc.), or components within the terminal (such as chips or integrated circuits).
[0130] The network-side device can be a server deployed in the cloud (e.g., a server for intelligent driving, a traffic monitoring server, etc.), or a component within the server (e.g., a chip, integrated circuit, etc.), or a system-level device composed of multiple servers. The network-side device can be deployed in a cloud environment or an edge environment, and is not specifically limited here.
[0131] As an example, obtaining at least part of the reference information from at least one of a terminal, a roadside device, and a network-side device includes: receiving monitoring information of a first terminal from a roadside device; detecting based on the monitoring information that the first terminal has been compromised or the amount of leakage of the first terminal's private data has reached a privacy leakage threshold, revoking the pseudonym certificate of the first terminal and generating a corresponding revocation record. Here, revoking the pseudonym certificate of the first terminal may be revoking all pseudonym certificates of the first terminal. In addition, the privacy leakage threshold may be a custom setting or a factory default setting. Exemplarily, the first terminal is a vehicle.
[0132] Exemplarily, the monitoring information of the first terminal by the roadside device includes at least one of the amount of leakage of the first terminal's private data, whether the first terminal is attacked, the frequency of communication between the first terminal and other terminals, etc.
[0133] In this way, when it is detected that the first terminal has been compromised or the privacy data of the first terminal has reached a preset value, all pseudonym certificates of the first terminal can be proactively revoked to prevent the abuse of the pseudonym certificates of the first terminal. This is particularly helpful in improving the security of vehicle network communication when applied to the field of intelligent vehicles.
[0134] As an example, the certificate revocation device may also determine that the target certificate of the second terminal has expired or the private key of the target certificate has been leaked based on the monitoring information of the terminal by the roadside equipment. In this case, the certificate revocation device revokes the target certificate and generates a corresponding revocation record, where the certificate type of the target certificate is a pseudonym certificate.
[0135] In this way, for any pseudonym certificate of a terminal (such as a vehicle), when it is detected that the pseudonym certificate has expired or the private key of the pseudonym certificate has been leaked, the pseudonym certificate can be revoked in time to avoid the pseudonym certificate from being abused, which is conducive to improving the security of vehicle network communications.
[0136] As an example, obtaining at least part of the reference information from at least one of a terminal, a roadside device, and a network side device includes: receiving revocation request information sent by a roadside device, the revocation request information including an identifier of a first terminal, wherein the first terminal is hacked or the amount of leakage of the first terminal's privacy data reaches the above-mentioned privacy leakage threshold; revoking the pseudonym certificate of the first terminal based on the revocation request information and generating a corresponding revocation record.
[0137] That is to say, the roadside device can monitor whether the first terminal has been hacked or whether the amount of leakage of the first terminal's privacy data has reached the privacy leakage threshold. When the roadside device determines that the first terminal has been hacked or the amount of leakage of the first terminal's privacy data has reached the privacy leakage threshold, the roadside device can report to the certificate revocation device, so that the certificate revocation device can revoke the pseudonym certificate of the first terminal in a timely manner.
[0138] In some possible embodiments, the certificate revocation device may also receive update indication information from the certificate management device, or the certificate revocation device may receive update indication information from a roadside device, a network side device or a terminal, and the update indication information is used to instruct the certificate revocation device to update the first CRL.
[0139] S202: When the reference information meets the update condition, the first CRL is updated to obtain a second CRL.
[0140] The interval between the release time of the first CRL and the release time of the second CRL is less than the preset update period of the first CRL.
[0141] That is to say, by applying the method provided in the embodiment of the present application, the update time of the first CRL will be advanced, rather than strictly updating the first CRL according to the update time determined by the preset update cycle of the first CRL. For example, assuming that the release time of the first CRL is June 1, the preset update cycle of the first CRL is 7 days, and the update date of the first CRL is determined to be June 8 based on the preset update cycle of the first CRL, by applying the method provided in the embodiment of the present application, it is possible that on June 3, the certificate revocation device determines that the reference information meets the update conditions based on the obtained reference information, so on June 3, the first CRL is updated to obtain the second CRL, and the second CRL is also released. In this way, the revocation records newly generated between the release of the first CRL and June 3 will be added to the second CRL due to the update of the first CRL on June 3, without having to wait until June 8 to be updated to the second CRL, thereby improving the flexibility and timeliness of the certificate revocation list update, and also helping to improve the communication security between terminals.
[0142] In one implementation, the reference information includes a pending revocation record for the first CRL and the type of the certificate being revoked, which is an integer. The update conditions include: the existence of a revocation record for the first certificate; the certificate type of the first certificate is a device certificate; and the device type corresponding to the first certificate is a critical device. In other words, an update to the first CRL is triggered when a revocation record for a device certificate of a critical device is found among the pending revocation records.
[0143] Here, device types can be categorized as critical devices and non-critical devices. For example, in a vehicle, critical devices refer to devices that are essential for the safe communication of the entire vehicle. The vehicle's in-vehicle communication box (TBox), which serves as a wireless gateway, can be considered a critical device, while the remaining components in the vehicle can be considered non-critical devices.
[0144] In one implementation, the reference information includes a pending revocation record of the first CRL and an integer certificate type that was revoked. The update condition includes: the existence of a revocation record indicating that the certificate of the first terminal was revoked, and the certificate type of the revoked certificate of the first terminal is a pseudonymous certificate. Here, the revocation of the certificate of the first terminal refers to the revocation of all pseudonymous certificates of the first terminal. In other words, when a revocation record indicating that all pseudonymous certificates of the first terminal are revoked exists in the pending revocation record, an update of the first CRL can be triggered.
[0145] In one implementation, the update condition includes at least one of the following conditions:
[0146] Condition 1: The number of pending revocation records reaches a first threshold;
[0147] Condition 2: The number of times the first CRL is accessed reaches a second threshold; and
[0148] Condition 3: The first time period has passed since the first CRL was issued, but the preset update period of the first CRL has not yet been reached.
[0149] Here, the first threshold and the second threshold are both preset, for example, they can be custom settings by relevant developers or default settings.
[0150] Here, in this implementation, satisfying any one of the above conditions 1, 2, and 3 can trigger the update of the first CRL. Alternatively, multiple conditions (e.g., 2 or 3) among conditions 1, 2, and 3 can be arbitrarily combined to generate an update condition, and when the update condition is satisfied, the update of the first CRL can also be triggered.
[0151] Taking the combination of conditions 1 and 3 as an example, assuming the preset CRL update cycle is 7 days, the update condition can be, for example, that the current time since the first CRL was published has exceeded a first duration (e.g., 1 day) and the number of pending revocation records has reached a first threshold. In this way, the impact of the time since the first CRL was published and the number of newly generated revocation records on the update time of the first CRL is taken into account. Taking the combination of conditions 2 and 3 as an example, assuming the preset CRL update cycle is 7 days, the update condition can be, for example, that the current time since the first CRL was published has exceeded a first duration (e.g., 1 day) and the number of times the first CRL has been accessed has reached a second threshold. In this way, the impact of the time since the first CRL was published and the number of times the first CRL has been accessed has reached a second threshold on the update time of the first CRL is taken into account. Taking the combination of conditions 1 and 2 as an example, the update condition can be, for example, that the current number of pending revocation records has reached a first threshold and the number of times the first CRL has been accessed has reached a second threshold. In this way, the impact of the number of newly generated revocation records and the number of times the first CRL has been accessed on the update time of the first CRL is taken into account.
[0152] In another implementation, when the certificates included in the revocation records to be processed are all certificates of non-critical devices, the update condition includes at least one of the above-mentioned conditions 1, 2, and 3. Furthermore, when the reference information also includes the update validity level of the first CRL configured by the user, it may also be: when the certificates included in the revocation records to be processed are all certificates of non-critical devices and the update validity level of the first CRL configured by the user in the reference information is the above-mentioned first level, the update condition includes at least one of the above-mentioned conditions 1, 2, and 3.
[0153] In another implementation, at least one of the above conditions 1, 2 and 3 can also be combined with at least one of the above update conditions "there is a revocation record of the first certificate, the certificate type of the first certificate is a device certificate and the device type corresponding to the first certificate is a key device", "there is a revocation record of the certificate of the first terminal being revoked, and the certificate type of the revoked certificate of the first terminal is a pseudonym certificate" to generate an update condition. When the update condition is met, the update of the first CRL can also be triggered.
[0154] In one implementation, the update condition includes: the current time from the issuance of the first CRL has exceeded the second time period but has not reached the preset update period of the first CRL. In some possible embodiments, the condition in this implementation can also be combined with at least one of the above-mentioned update conditions "there is a revocation record of the first certificate, the certificate type of the first certificate is a device certificate, and the device type corresponding to the first certificate is a critical device" and "there is a revocation record of the revoked certificate of the first terminal, and the certificate type of the revoked certificate of the first terminal is a pseudonymous certificate" to generate an update condition. It can also be combined with at least one of the above-mentioned conditions 1, 2, and 3 to generate an update condition, which is not specifically limited here.
[0155] Here, the second duration is greater than or equal to the first duration, and the second duration is less than a preset update period of the first CRL.
[0156] Exemplarily, the second duration is 90% of the preset update period of the first CRL. It is understood that 90% is just an example, and in some possible embodiments, it may also be 80%, 85%, 87% or other proportions, which are not specifically limited here.
[0157] In another implementation, when the certificates included in the revocation records to be processed are all certificates of non-critical devices, the update condition includes: the current time period from the issuance of the first CRL has exceeded the second time period but has not reached the preset update period of the first CRL. Furthermore, when the reference information also includes the update validity level of the first CRL configured by the user, it can also be: when the certificates included in the revocation records to be processed are all certificates of non-critical devices and the update validity level of the first CRL configured by the user in the reference information is the second level, the update condition includes: the current time period from the issuance of the first CRL has exceeded the second time period but has not reached the preset update period of the first CRL.
[0158] In one implementation, the update condition includes: the comprehensive score corresponding to the reference information reaches a target threshold, wherein the comprehensive score corresponding to the reference information is obtained by weighted summation based on the number of revocation records to be processed, the number of times the first CRL is accessed, and the current time from the release of the first CRL.
[0159] For example, the calculation formula of the comprehensive score corresponding to the reference information can refer to formula (1): Soc i =RRN*W RRN +VT*W VT +RD*W RD Formula (1)
[0160] Among them, Soc i represents the comprehensive score of the reference information, RRN represents the number of revocation records to be processed after the first CRL is issued, VT represents the number of times the most recently issued CRL (i.e., the first CRL) has been accessed, RD represents the time from the current CRL to the first CRL, and W RRN is the weight of RRN, W VT is the weight of VT, W RD is the weight of RD.
[0161] In formula (1), W RRN 、W VT and W RD It is preset, for example, it can be obtained by calculation using a multiple linear regression model.
[0162] Exemplarily, when the reference information further includes the update timeliness level of the first CRL configured by the user, the target threshold may be set to different values depending on whether the update timeliness level of the first CRL configured by the user in the reference information is the first level.
[0163] The update of the first CRL can be triggered by the aforementioned reference information satisfying an update condition. In some possible embodiments, the update of the first CRL can also be directly triggered by the certificate revocation device receiving update indication information. For example, the certificate revocation device receives update indication information from a roadside device, a terminal, or a network-side device; in response to the update indication information, the device updates the first CRL based on the aforementioned reference information to obtain a second CRL.
[0164] As an example, updating the first CRL may include updating the first CRL according to the to-be-processed revocation record of the first CRL in the reference information (ie, the revocation record newly generated after the first CRL is issued).
[0165] Here, updating the first CRL based on the pending revocation records can be understood as updating the first CRL based on some or all of the revocation records in the pending revocation records. Accordingly, the second CRL obtained after the first CRL is updated includes some or all of the revoked certificates recorded in the pending revocation records. For example, the second CRL is the updated first CRL.
[0166] For example, the revocation records to be processed include 20 revocation records. Assuming that it is detected that the 10th revocation record meets the update condition "there is a revocation record in which the device certificate of a key device is revoked", the first CRL is updated based on the revocation records to be processed: the first CRL can be updated based on the first 10 revocation records in the revocation records to be processed, or based on these 20 revocation records, or based on the revocation record in which the device certificate of a key device is revoked in the revocation records to be processed.
[0167] For another example, the revocation records to be processed include 30 revocation records, and these 30 revocation records do not include the revocation record of the device certificate of the key equipment being revoked. Assuming that the first 20 revocation records in the revocation records to be processed include the revocation record of all the pseudonym certificates of vehicle 1 being revoked, when the 20th revocation record is detected, the update condition "there is a revocation record of the pseudonym certificate of the first terminal being revoked" is met, then updating the first CRL based on the revocation records to be processed can be to update the first CRL based on the first 20 revocation records in the revocation records to be processed, or to update the first CRL based on these 30 revocation records, or to update the first CRL based on the revocation record of all the pseudonym certificates of vehicle 1 in the revocation records to be processed.
[0168] In one implementation, after obtaining the second CRL, the certificate revocation device also publishes the second CRL. In this way, the certificate revocation device can promptly publish the latest CRL (i.e., the second CRL), so that the recipient of the CRL can promptly obtain the latest certificate revocation list, thereby preventing the revoked certificate from being abused.
[0169] Exemplarily, before issuing the second CRL, the certificate revocation device signs the second CRL using a local private key to obtain a signed second CRL. Accordingly, the certificate revocation device issues the second CRL, including: the revocation device issues the signed second CRL, so that a recipient of the second CRL can decrypt the second CRL using the public key to determine whether the second CRL has been tampered with during transmission.
[0170] As an example, publishing the second CRL may include sending the second CRL in a broadcast, multicast, or unicast manner.
[0171] Exemplarily, when the certificate revocation device and the certificate management device are separately provided, the certificate revocation device issues the second CRL, which may be: the certificate revocation device issues the second CRL to the certificate management device, and the certificate management device then issues the second CRL to the user.
[0172] Exemplarily, the certificate management apparatus receives query information sent by the terminal, the query information being used to request querying the latest CRL, and sends the query information to the certificate revocation apparatus; in response to the query information, the certificate revocation apparatus issues a second CRL to the certificate management apparatus.
[0173] As an example, in a case where the reference information includes the update timeliness level of the first CRL configured by the user, if there is a user-configured first CRL with an update timeliness level of the above-mentioned first level, publishing the second CRL can be: publishing the second CRL to the user who configured the update timeliness level of the first CRL as the above-mentioned first level in the reference information.
[0174] In some possible embodiments, after obtaining the second CRL, the certificate revocation device may further store the second CRL.
[0175] Exemplarily, when the certificate revocation device is integrated with a CRL storage module, the certificate revocation device stores the second CRL locally. When the certificate revocation device is not integrated with a CRL storage module, the certificate revocation device pushes the second CRL to the device where the CRL storage module is located for storage.
[0176] As can be seen, the embodiments of the present application are no longer limited to periodically updating the CRL at a fixed time. Instead, before the next preset update time of the CRL, when it is determined that the reference information obtained after the last CRL release meets the update conditions, the update of the CRL can be triggered. Here, the reference information includes at least one of the following: new revocation records, the number of times the CRL has been accessed, the user-configured CRL update timeliness level, the type of revoked certificate, the preset update period of the CRL, etc. This fully considers the impact of multiple factors on CRL updates, provides a personalized solution for CRL updates, improves the flexibility and timeliness of certificate revocation list updates, and helps to increase the security of communications.
[0177] The following are some specific scenarios to illustrate the application of the embodiment of FIG2 .
[0178] See Figure 3, which is a schematic diagram of some certificate revocation list update scenarios provided in an embodiment of the present application. As can be seen from Figure 3, the preset update period of the first CRL is 7 days. Here, 7 days is just an example and should not be limited to the preset update period of the first CRL.
[0179] In (1) of FIG. 3 , after the first CRL is issued, if the device certificate of a key device is revoked or the pseudonym certificate of a terminal is revoked, the first CRL can be immediately updated and the updated first CRL can be issued.
[0180] In (2) of FIG3 , after the first CRL is published, if more than one day has passed since the last CRL (ie, the first CRL) was published and there is a new revocation record, the first CRL may be updated immediately and the updated first CRL may be published.
[0181] In (3) of FIG. 3 , after the first CRL is published, if the first CRL is frequently accessed (ie, the number of times the first CRL is accessed reaches a second threshold), the first CRL may be updated immediately and the updated first CRL may be published.
[0182] In (4) of FIG3 , after the first CRL is published, if the second time period has passed since the last CRL publication (ie, the first CRL), the first CRL may be updated immediately and the updated first CRL may be published.
[0183] It can be understood that Figure 3 is only some examples of certificate revocation list update scenarios, and does not limit the certificate revocation list update scenarios to only those shown in Figure 3. The specific update conditions of the certificate revocation list can refer to the description of the "Update Conditions" in the embodiment of Figure 2, which will not be repeated here.
[0184] 4 is a flow chart of another method for updating a certificate revocation list provided in an embodiment of the present application. The method can be applied to a certificate revocation list updating system, which includes a certificate revocation device and a certificate management device.
[0185] As an example, the certificate management device may be device 1 in FIG. 1A , and the certificate revocation device may be device 2 in FIG. 1A .
[0186] As an example, the certificate management device may be device three in FIG. 1B , and the certificate revocation device may be device four in FIG. 1B .
[0187] The method includes but is not limited to the following steps:
[0188] S401: The certificate management device obtains reference information, which includes at least one of the pending revocation record of the first CRL, the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update period of the first CRL, and the update timeliness level of the first CRL configured by the user.
[0189] Here, the content in the reference information can be specifically referred to the description of the corresponding content in embodiment S201 of Figure 2, and will not be repeated here.
[0190] In one implementation, the certificate management device obtains the reference information, including: the certificate management device obtains at least a portion of the reference information from at least one of a terminal, a roadside device, and a network device. The terminal, roadside device, and network device can be described with reference to the corresponding contents in the embodiment of FIG. 2 .
[0191] In this case, the terminal, roadside equipment, and network-side equipment can all serve as data source devices for providing reference information. The reference information is obtained in at least one of the following ways: the certificate management device directly obtains the reference information from the data source device (e.g., the user-configured CRL update validity level); the certificate management device obtains the reference information based on information provided by the data source device (e.g., revocation records, the number of times the first CRL has been accessed, etc.). In this case, the certificate management device is integrated into the certificate revocation device.
[0192] As an example, the certificate management device obtains at least part of the reference information from at least one of the terminal, the roadside device, and the network side device, including: the certificate management device receives monitoring information of the first terminal by the roadside device; the certificate management device detects based on the monitoring information that the first terminal has been hacked or the amount of leakage of the first terminal's private data reaches a privacy leakage threshold, and the certificate management device revokes the pseudonym certificate of the first terminal and generates a corresponding revocation record. Here, the certificate management device revoking the pseudonym certificate of the first terminal means that the certificate management device revokes all pseudonym certificates of the first terminal. In addition, the privacy leakage threshold can be a custom setting or a factory default setting.
[0193] In some possible embodiments, the certificate management device determines that the target certificate of the first terminal has expired or the private key of the target certificate has been leaked based on the monitoring information of the first terminal by the roadside equipment. In this case, the certificate revocation device revokes the target certificate and generates a corresponding revocation record, wherein the certificate type of the target certificate is a pseudonym certificate.
[0194] As another example, the certificate management device obtains at least part of the reference information from at least one of the terminal, the roadside device and the network side device, including: the certificate management device receives revocation request information sent by the roadside device or the second terminal, the revocation request information includes the identification of the second terminal, wherein the second terminal is hacked or the amount of leakage of the second terminal's privacy data reaches the above-mentioned privacy leakage threshold; in response to the revocation request information, the certificate management device revokes the pseudonym certificate of the second terminal and generates a corresponding revocation record.
[0195] S402: The certificate management apparatus sends the reference information to the certificate revocation apparatus.
[0196] Correspondingly, the certificate revocation apparatus receives the reference information sent by the certificate management apparatus.
[0197] S403: The certificate revocation device determines whether all pseudonym certificates of terminals have been revoked or device certificates of key devices have been revoked based on the reference information.
[0198] For example, if it is determined based on the reference information that all pseudonym certificates of a terminal are revoked or the device certificate of a key device is revoked, S408 is executed. If it is determined based on the reference information that none of the revoked certificates are device certificates of key devices and all pseudonym certificates of a terminal are revoked, S404 is executed.
[0199] S404: The certificate revocation apparatus determines, based on the reference information, whether there is a first CRL configured by the user whose update validity level is the first level.
[0200] Here, the first level can refer to the description of the corresponding content in the embodiment of FIG. 2 above, which will not be repeated here.
[0201] For example, if the update validity level of the first CRL configured by the user in the reference information is determined to be level 1, any of steps S405-S407 is executed. If the update validity level of the first CRL not configured by the user in the reference information is determined to be level 1, S407 is executed.
[0202] S405: The certificate revocation apparatus determines, based on the reference information, that the number of the revocation records to be processed reaches a first threshold.
[0203] In this case, the certificate revocation device may execute S408.
[0204] S406: The certificate revocation apparatus determines, based on the reference information, that the number of times the first CRL has been accessed reaches a second threshold.
[0205] In this case, the certificate revocation device may execute S408.
[0206] S407: The certificate revocation apparatus determines based on the reference information that the current time from the issuance of the first CRL has exceeded the target time but has not reached the preset update period of the first CRL.
[0207] In this case, the certificate revocation device may execute S408.
[0208] Here, the target duration may be the second duration in the embodiment of FIG. 2 .
[0209] As can be seen from FIG4 , when the conditions in any of steps S405-S407 are met, the certificate revocation device can be triggered to execute S408 to update the first CRL. In some possible embodiments, the conditions in at least two of steps S405-S407 can be combined as a condition for triggering the certificate revocation device to execute S408. For example, the combination of S405 and S406 is used as a condition for triggering the certificate revocation device to execute S408. That is, when the certificate revocation device determines that the number of revocation records to be processed has reached a first threshold and the number of times the first CRL has been accessed has reached a second threshold, the certificate revocation device executes S408.
[0210] In some possible embodiments, the certificate revocation device may also score the reference information. When it is determined that the comprehensive score corresponding to the reference information reaches a target threshold, the certificate revocation device executes S408.
[0211] For example, a score can be assigned to each condition to be judged, and when the reference information meets the corresponding condition, the comprehensive score corresponding to the reference information can be added with the score corresponding to the condition. Refer to Table 1, which shows the correspondence between the conditions and the assigned scores. As can be seen from Table 1, taking the correspondence of "the device certificate of a key device is revoked-2" as an example, it means that when the reference information meets the condition "the device certificate of a key device is revoked", the comprehensive score corresponding to the reference information is added by 2. The other correspondences in Table 1 can refer to the example description of this correspondence, which will not be repeated here. Among them, the initial value of the comprehensive score corresponding to the reference information is 0. In this case, exemplarily, the target threshold can be set to 2, then when the reference information meets any of the conditions shown in Table 1, the comprehensive score corresponding to the reference information can reach the target threshold, thereby triggering the certificate revocation device to execute S408.
[0212] Table 1
[0213] It is understood that Table 1 is only an example to reflect the correspondence between conditions and scores, but the conditions and assigned scores are not limited to those shown in Table 1. For example, they may also be as shown in Table 2 below.
[0214] See Table 2, which also shows the correspondence between conditions and assigned scores. The description of the correspondence in Table 2 can refer to the description of the correspondence in Table 1 for "Device Certificate with Revoked Certificate for Key Device - 2," and will not be repeated here.
[0215] In one implementation, when scoring the reference information, the target threshold may be set to different values for different conditions.
[0216] For example, for the first five conditions in Table 2, the target threshold can be set to 2. That is, when the reference information satisfies the condition that "a device certificate for a critical device has been revoked," the corresponding comprehensive score for the reference information reaches the target threshold of "2." Alternatively, when the reference information satisfies the condition that "all pseudonymous certificates for a certain terminal have been revoked," the corresponding comprehensive score for the reference information reaches the target threshold of "2." Alternatively, when the reference information satisfies the condition that "all revoked certificates are certificates for non-critical devices, a user-configured first CRL exists with an update validity level of the first level, and the number of pending revocation records reaches the first threshold," "all revoked certificates are certificates for non-critical devices, a user-configured first CRL exists with an update validity level of the first level, and the number of times the first CRL has been accessed reaches the second threshold," and "all revoked certificates are certificates for non-critical devices, a user-configured first CRL exists with an update validity level of the first level, and the current time since the first CRL was issued has exceeded the target duration but has not yet reached the preset update period for the first CRL," the corresponding comprehensive score for the reference information reaches the target threshold of "2."
[0217] For example, for the last condition in Table 2, the target threshold can be set to 1. That is, when the reference information satisfies the following conditions: "all revoked certificates are certificates of non-critical devices and none of the user-configured first CRLs have an update validity level of level 1, and the current time since the first CRL was issued has exceeded the target time but has not reached the preset update period of the first CRL", the comprehensive score corresponding to the reference information can reach the target threshold of "1", thereby triggering the certificate revocation device to execute S408.
[0218] Table 2
[0219] It is understood that Table 2 is merely an example to illustrate the correspondence between conditions and scores, but does not limit the conditions and assigned scores to only those shown in Table 2.
[0220] S408: The certificate revocation device updates the first CRL according to the revocation record to be processed to obtain a second CRL.
[0221] S409: The certificate revocation device sends the second CRL to the certificate management device.
[0222] Correspondingly, the certificate management apparatus receives the second CRL sent by the certificate revocation apparatus.
[0223] In some possible embodiments, the terminal may also request the certificate revocation device to query the latest CRL through the certificate management device. For example, the certificate management device receives query information sent by the terminal, the query information being used to request the latest CRL; the certificate management device sends the query information to the certificate revocation device; and in response to the query information, the certificate revocation device sends a second CRL to the certificate management device.
[0224] It can be seen that when it is determined based on the reference information that a device certificate for a critical device with a high security level has been revoked, the CRL can be updated immediately to improve security. When it is determined based on the reference information that all pseudonym certificates of a terminal have been revoked, the update of the CRL is triggered. In addition, it is also possible to combine multiple factors such as new revocation records in the reference information, the number of times the CRL has been accessed, the user-configured CRL update timeliness level, the type of revoked certificate, and the preset update cycle of the CRL to determine whether the update conditions are met. This provides a personalized solution for the update of the CRL, which is no longer limited to periodic updates of the CRL at a fixed time. This improves the flexibility and timeliness of the certificate revocation list update, which is conducive to increasing the security of communications.
[0225] 5 is a schematic diagram of a structure of a device for updating a CRL according to an embodiment of the present application. The device 30 for updating a CRL includes an acquisition unit 310 and a processing unit 312. The device 30 for updating a CRL can be implemented by hardware, software, or a combination of hardware and software.
[0226] Among them, the acquisition unit 310 is used to obtain reference information, the reference information includes the revocation record to be processed of the first CRL, the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update cycle of the first CRL and at least one of the update timeliness level of the first CRL configured by the user, and each revocation record includes a certificate revoked after the first CRL is issued; the processing unit 312 is used to update the first CRL and obtain the second CRL when the reference information meets the update condition, wherein the interval between the issuance time of the first CRL and the issuance time of the second CRL is less than the preset update cycle of the first CRL.
[0227] The apparatus 30 for CRL updating may be used to implement the method described in the embodiment of Figure 2. In the embodiment of Figure 2, the acquiring unit 310 may be used to execute S201, and the processing unit 312 may be used to execute S202.
[0228] In some possible embodiments, the apparatus 30 for updating a CRL further includes a sending unit (not shown) configured to publish a second CRL. The apparatus 30 for updating a CRL may also be used to implement the certificate revocation device-side method described in the embodiment of FIG. 4 . In the embodiment of FIG. 4 , the acquiring unit 310 may be configured to execute S402 , the processing unit 312 may be configured to execute S403 - S408 , and the sending unit may be configured to execute S409 .
[0229] 6 is a schematic diagram of a structure of a device for updating a CRL according to an embodiment of the present application. The device 40 for updating a CRL includes an acquiring unit 410 and a sending unit 412. The device 40 can be implemented by hardware, software, or a combination of hardware and software.
[0230] Among them, the acquisition unit 410 is used to obtain reference information, which includes the revocation record to be processed of the first CRL, the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update cycle of the first CRL and at least one of the update timeliness level of the first CRL configured by the user, and each revocation record includes a certificate revoked after the first CRL is issued; the sending unit 412 is used to send the reference information to the certificate revocation device, and the reference information is used to update the first CRL to obtain the second CRL when the reference information meets the update condition, and the interval between the issuance time of the first CRL and the issuance time of the second CRL is less than the preset update cycle of the first CRL.
[0231] The apparatus 40 for updating a CRL may be used to implement the method on the certificate management apparatus side described in the embodiment of Figure 4. In the embodiment of Figure 4, the acquiring unit 410 may be used to execute S401, and the sending unit 412 may be used to execute S402.
[0232] It should be understood that the division of the various units in the above devices (e.g., device 30 for CRL updating or device 40 for CRL updating) is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a single physical entity, or they may be physically separated. In addition, the units in the device may be implemented in the form of a processor calling software; for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units can be realized by designing the hardware circuits. The hardware circuit can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units by designing the logical relationship of the components in the circuit. For another example, in another implementation, the hardware circuit can be implemented by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units. All units of the above devices can be implemented in the form of software called by the processor, or in the form of hardware circuits, or in part by software called by the processor, and the rest by hardware circuits.
[0233] In an embodiment of the present application, a processor is a circuit with a signal processing capability. In one implementation, the processor can be a circuit with instruction reading and execution capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the processor loads a configuration document to implement the process of hardware circuit configuration, which can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0234] It can be seen that each unit in the above device can be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.
[0235] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor can be different, for example, including a CPU and FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.
[0236] Referring to Figure 7 , Figure 7 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. As shown in Figure 7 , computing device 50 includes a processor 501, a communication interface 502, a memory 503, and a bus 504. Processor 501, memory 503, and communication interface 502 communicate with each other via bus 504. It should be understood that this application does not limit the number of processors and memories in computing device 50.
[0237] In one implementation, the computing device 50 may be a network-side device. The network-side device may be, for example, a server deployed in the cloud (e.g., a server for updating CRLs, a server for uploading reference information, etc.), or a component within the server (e.g., a chip, an integrated circuit, etc.), or a system-level device composed of multiple servers. The network-side device may be deployed in a cloud environment or an edge environment, and is not specifically limited here.
[0238] As an example, the computing device 50 may be the certificate revocation device or the certificate management device.
[0239] Bus 504 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG7 illustrates a single bus line, but this does not imply a single bus or type of bus. Bus 504 may include a path for transmitting information between various components of computing device 50 (e.g., memory 503, processor 501, and communication interface 502).
[0240] The processor 501 can refer to the relevant description of the processor in the above embodiment, which will not be repeated here.
[0241] Memory 503 is used to provide storage space for storing data such as the operating system and computer programs. Memory 503 can be one or a combination of random access memory (RAM), erasable programmable read-only memory (EPROM), read-only memory (ROM), or compact disc read-only memory (CD-ROM). Memory 503 can exist independently or be integrated into processor 501.
[0242] The communication interface 502 can be used to provide information input or output for the processor 501. Alternatively, the communication interface 502 can be used to receive data transmitted externally and / or transmit data externally. It can be a wired link interface such as an Ethernet cable, or a wireless link interface (such as Wi-Fi, Bluetooth, general wireless transmission, etc.). Alternatively, the communication interface 502 can also include a transmitter (such as a radio frequency transmitter, antenna, etc.) or a receiver coupled to the interface.
[0243] In some possible embodiments, the computing device 50 further includes a display 505. The display 505 is connected or coupled to the processor 501 via a bus 504. The display 505 can be used to indicate the properties of multiple audio streams to the user. The display 505 can be a display screen, which can be a liquid crystal display (LCD), an organic or inorganic light-emitting diode (OLED), an active matrix organic light-emitting diode (AMOLED), etc. The display 505 can also be a vehicle-mounted tablet, an in-vehicle display, or a head-up display (HUD) system.
[0244] The processor 501 in the computing device 50 is used to read the computer program stored in the memory 503 to execute the aforementioned method, such as the method described in FIG. 2 or FIG. 4 .
[0245] In one possible design, the computing device 50 may be one or more modules in an execution entity that executes the method shown in FIG. 2 , and the processor 501 may be configured to read one or more computer programs stored in a memory to perform the following operations:
[0246] Acquiring reference information through the acquisition unit 310, the reference information including at least one of a pending revocation record of the first CRL, a certificate type of the revoked certificate, a number of times the first CRL has been accessed, a preset update period of the first CRL, and a user-configured update validity level of the first CRL, each revocation record including a certificate revoked after the first CRL was issued;
[0247] When the reference information meets the update condition, the first CRL is updated to obtain the second CRL, and the interval between the release time of the first CRL and the release time of the second CRL is less than the preset update period of the first CRL.
[0248] In one possible design, the computing device 50 may be one or more modules in an execution entity (e.g., a certificate management device) that executes the method shown in FIG. 4 . The processor 501 may be configured to read one or more computer programs stored in a memory to perform the following operations:
[0249] Acquiring reference information through an acquisition unit 410, the reference information including at least one of a pending revocation record of the first CRL, a certificate type of the revoked certificate, a number of times the first CRL has been accessed, a preset update period of the first CRL, and a user-configured update validity level of the first CRL, each revocation record including a certificate revoked after the first CRL was issued;
[0250] The reference information is sent to the certificate revocation device through the sending unit 412. The reference information is used to update the first CRL to obtain the second CRL when the reference information meets the update condition. The interval between the publication time of the first CRL and the publication time of the second CRL is less than the preset update period of the first CRL.
[0251] In the embodiments described above, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant descriptions of other embodiments. In addition, in the various embodiments of this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0252] It should be noted that, those skilled in the art can see that all or part of the steps in the various methods of the above embodiments can be completed by a program to instruct relevant hardware. The program can be stored in a computer-readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.
[0253] The technical solution of the present application may essentially or contribute to the part or all or part of the technical solution in the form of a software product. The computer program product is stored in a storage medium and includes a number of instructions for enabling a device (which may be a personal computer, a server, or a network device, a robot, a single-chip microcomputer, a chip, a robot, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
Claims
1. A method for updating a certificate revocation list, characterized in that, The method includes: Obtaining reference information, where the reference information includes at least one of the revocation records to be processed in the first Certificate Revocation List (CRL), the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update period of the first CRL, and the update timeliness level of the first CRL configured by the user. Each revocation record includes a certificate revoked after the release of the first CRL; When the reference information meets the update condition, updating the first CRL to obtain a second CRL, where the interval between the release time of the first CRL and the release time of the second CRL is less than the preset update period of the first CRL.
2. The method according to claim 1, wherein The method further includes: Publishing the second CRL.
3. The method according to claim 1 or 2, characterized in that, The reference information includes the revocation records to be processed and the certificate type of the revoked certificate, and the update condition includes: There is a revocation record of a first certificate, the certificate type of the first certificate is a device certificate, and the device type corresponding to the first certificate is a critical device.
4. The method according to claim 1 or 2, characterized in that, The reference information includes the revocation records to be processed and the certificate type of the revoked certificate, and the update condition includes: There is a revocation record of a certificate of a first terminal being revoked, and the certificate type of the certificate of the first terminal being revoked is a pseudonym certificate.
5. The method according to claim 1 or 2, characterized in that, The update condition includes at least one of the following conditions: The number of the revocation records to be processed reaches a first threshold; The number of times the first CRL is accessed reaches a second threshold; and The current time since the release of the first CRL has exceeded a first duration but has not reached the preset update period of the first CRL.
6. The method according to claim 5, wherein All the certificates included in the revocation records to be processed are certificates of non-critical devices, and the update timeliness level of the first CRL configured by the user in the reference information is the first level.
7. The method according to claim 1 or 2, characterized in that, The update condition includes: The current time since the release of the first CRL has exceeded a second duration but has not reached the preset update period of the first CRL.
8. The method according to claim 7, characterized in that All the certificates included in the revocation records to be processed are certificates of non-critical devices, and the update timeliness levels of the first CRL configured by the user in the reference information are all the second level.
9. The method according to any one of claims 1-5, 7, characterized in that, The update condition includes: The comprehensive score corresponding to the reference information reaches a target threshold, and the comprehensive score corresponding to the reference information is obtained by weighted summation based on the number of the revocation records to be processed, the number of times the first CRL is accessed, and the current time since the release of the first CRL.
10. The method according to any one of claims 1-9, characterized in that, Obtaining reference information includes: Receiving the reference information sent by the certificate management device; or, Obtaining at least part of the information in the reference information from at least one of a terminal, a roadside device, and a network-side device.
11. A method for updating a certificate revocation list, characterized in that The method includes: Obtaining reference information, where the reference information includes at least one of the revocation records to be processed in the first Certificate Revocation List (CRL), the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update period of the first CRL, and the update timeliness level of the first CRL configured by the user. Each revocation record includes a certificate revoked after the release of the first CRL; Send the reference information to the certificate revocation device, where the reference information is used to update the first CRL to obtain a second CRL when the reference information meets the update condition. The interval between the release time of the first CRL and the release time of the second CRL is less than the preset update period of the first CRL.
12. The method according to claim 11, wherein The method further includes: Receive the second CRL released by the certificate revocation device.
13. The method according to claim 12, wherein Before receiving the second CRL released by the certificate revocation device, the method further includes: Receive query information sent by a terminal, where the query information is used to request a query for the latest CRL; Send the query information to the certificate revocation device; After receiving the second CRL, release the second CRL to the terminal.
14. The method according to any one of claims 11-13, characterized in that, The obtaining the reference information includes: Obtain at least part of the information in the reference information from at least one of a terminal, a roadside device, and a network-side device.
15. The method according to claim 14, wherein The obtaining at least part of the information in the reference information from at least one of a terminal, a roadside device, and a network-side device includes: Receive the monitoring information of a first terminal by the roadside device; Based on the monitoring information, if it is detected that the first terminal is compromised or the leakage amount of the private data of the first terminal reaches a first threshold, revoke the pseudonym certificate of the first terminal and generate a corresponding revocation record.
16. A device for certificate revocation list update, characterized in that, The device includes: An obtaining unit, configured to obtain reference information, where the reference information includes at least one of the revocation records to be processed of a first Certificate Revocation List (CRL), the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update period of the first CRL, and the update timeliness level of the first CRL configured by a user. Each revocation record includes a certificate revoked after the release of the first CRL; A processing unit, configured to update the first CRL to obtain a second CRL when the reference information meets the update condition. The interval between the release time of the first CRL and the release time of the second CRL is less than the preset update period of the first CRL.
17. The device according to claim 16, characterized in that, The device further includes a sending unit, and the sending unit is configured to: release the second CRL.
18. The device according to claim 16 or 17, characterized in that, The reference information includes the revocation records to be processed and the certificate type of the revoked certificate, and the update condition includes: There is a revocation record of a first certificate, the certificate type of the first certificate is a device certificate, and the device type corresponding to the first certificate is a critical device.
19. The device according to claim 16 or 17, characterized in that, The reference information includes the revocation records to be processed and the certificate type of the revoked certificate, and the update condition includes: There is a revocation record of a certificate of a first terminal being revoked, and the certificate type of the certificate of the first terminal being revoked is a pseudonym certificate.
20. The device according to claim 16 or 17, characterized in that The update condition includes at least one of the following conditions: The number of the revocation records to be processed reaches a first threshold; The number of times the first CRL is accessed reaches a second threshold; and The current time since the release of the first CRL has exceeded a first duration but has not reached the preset update period of the first CRL.
21. The device according to claim 20, characterized in that, The certificates included in the revocation records to be processed are all certificates of non-critical devices, and the update timeliness level of the first CRL configured by the user in the reference information is the first level.
22. The device according to claim 16 or 17, characterized in that, The update conditions include: The current time since the release of the first CRL has exceeded the second duration but has not reached the preset update period of the first CRL.
23. The device according to claim 22, characterized in that, The certificates included in the revocation records to be processed are all certificates of non-critical devices, and the update timeliness levels of the first CRL configured by the user in the reference information are all the second level.
24. The device according to any one of claims 16-20, 22, characterized in that, The update conditions include: The comprehensive score corresponding to the reference information reaches the target threshold, and the comprehensive score corresponding to the reference information is obtained by weighted summation based on the number of revocation records to be processed, the number of times the first CRL is accessed, and the current time since the release of the first CRL.
25. The device according to any one of claims 16 - 24, characterized in that, The obtaining unit is specifically configured to: Receive the reference information sent by the certificate management device; or, Obtain at least part of the information in the reference information from at least one of the terminal, roadside device, and network-side device.
26. A device for certificate revocation list update, characterized in that, The device includes: An obtaining unit, configured to obtain reference information, where the reference information includes at least one of the revocation records to be processed of the first Certificate Revocation List (CRL), the certificate type of the revoked certificate, the number of times the first CRL is accessed, the preset update period of the first CRL, and the update timeliness level of the first CRL configured by the user, and each revocation record includes a certificate revoked after the release of the first CRL; A sending unit, configured to send the reference information to the certificate revocation device, where the reference information is used to update the first CRL to obtain a second CRL when the reference information meets the update conditions, and the interval between the release time of the first CRL and the release time of the second CRL is less than the preset update period of the first CRL.
27. The device according to claim 26, wherein The obtaining unit is further configured to: receive the second CRL released by the certificate revocation device.
28. The device according to claim 27, characterized in that, The obtaining unit is further configured to receive the query information sent by the terminal, where the query information is used to request to query the latest CRL; The sending unit is further configured to send the query information to the certificate revocation device; and after the obtaining unit receives the second CRL, release the second CRL to the terminal.
29. The device according to any one of claims 26 - 28, characterized in that, The obtaining unit is specifically configured to: Obtain at least part of the information in the reference information from at least one of the terminal, roadside device, and network-side device.
30. The device according to claim 29, wherein The obtaining unit is specifically configured to: receive the monitoring information of the roadside device on the first terminal; The device further includes a processing unit, and the processing unit is configured to: based on the monitoring information, detect that the first terminal is compromised or the leakage amount of the privacy data of the first terminal reaches the first threshold, revoke the pseudonym certificate of the first terminal and generate a corresponding revocation record.
31. A device for certificate revocation list update, characterized in that, The device includes a memory and a processor, the memory stores computer program instructions, and the processor runs the computer program instructions to cause the device to execute the method according to any one of claims 1-10, or execute the method according to any one of claims 11-15.
32. A certificate revocation list update system, characterized in that, The system includes a first device, or includes a first device and a second device, wherein the first device is configured to execute the method according to any one of claims 1-10, and the second device is configured to execute the method according to any one of claims 11-15.
33. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions for implementing the method according to any one of claims 1-10, or implementing the method according to any one of claims 11-15.
34. A computer program product, characterized in that, When the computer program product runs on a processor, it causes the implementation of the method according to any one of claims 1-10, or the implementation of the method according to any one of claims 11-15.
Citation Information
Patent Citations
Revocation list updating method and storage medium
CN113141257A
Certificate revocation list distribution method and device, storage medium, server and vehicle networking device
CN114374516A
Certificate revocation list management method and device and electronic equipment
CN114866243A
Inspection method, and method of manufacturing elliptically polarizing plate
KR1020230054282A
Method and system for intelligent transportation system certificate revocation list reduction
US20200106624A1