Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

61 results about "Certificate signing request" patented technology

In public key infrastructure (PKI) systems, a certificate signing request (also CSR or certification request) is a message sent from an applicant to a certificate authority in order to apply for a digital identity certificate. It usually contains the public key for which the certificate should be issued, identifying information (such as a domain name) and integrity protection (e.g., a digital signature). The most common format for CSRs is the PKCS #10 specification and another is the Signed Public Key and Challenge SPKAC format generated by some web browsers.

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Systems, methods, and protocols for zero knowledge proof user authentication

Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and / or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.
Owner:T STAMP INC

System And Method For Managing Secure Shell Protocol Access In Cloud Infrastructure Environments

Techniques for creating, managing, and using SSH certificates with one or more target-specific principals are disclosed. A certificate authority receives a certificate signing request that includes both a user identifier and a resource identifier. The user identifier identifies a user, and the resource identifier represents one or more target hosts. The certificate authority forms a target-specific principal for use in creating the certificate. The target-specific principal indicates both the user and the resource identifier representing the resource(s) for which access is requested. The resource identifier may represent a host class associated with more than one host. Once the certificate authority verifies that the user is entitled to access the requested resource(s), it generates the certificate, signs it, and returns it to the requesting device.
Owner:ORACLE INT CORP

Systems and methods for handling supply chain certificates

PendingUS20260017672A1User identity/authority verificationCommerceProgram instructionOriginal equipment manufacturer
Systems and methods for handling supply chain certificates are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor. The memory may store program instructions that, upon execution, cause the IHS to receive a message from a supplier identifying a device. The IHS may verify the device against a Purchase Order (PO) database of an Original Equipment Manufacturer (OEM) and may send encrypted material to the supplier. The supplier may generate a Certificate Signing Request (CSR) for the device comprising the encrypted material. The supplier may receive a digital certificate in response to the CSR and stores the certificate in the device. The system may ensure the authenticity and quality of components throughout the supply chain using cryptographic techniques.
Owner:DELL PROD LP

Client-Rooted Decryption Public Key Infrastructure (PKI) for Secure Cloud-Based Inspection of Encrypted Traffic

PendingUS20260005873A1User identity/authority verificationDigital data authenticationIntermediate certificate authoritiesInternet privacy
Techniques for implementing a client-rooted decryption Public Key Infrastructure (PKI) to securely inspect encrypted traffic in cloud-based proxy environments are disclosed. A proxy node generates an intermediate Certificate Authority (CA) certificate signing request (CSR) and sends it to a client device equipped with a locally-managed root CA. The client device cross-signs the CSR, creating a client-specific intermediate CA certificate, which it returns to the proxy node. This client-specific intermediate CA certificate is scoped uniquely to the individual client device, significantly reducing the potential blast radius in case of CA key compromise. The proxy node uses the client-specific CA certificate to dynamically generate short-lived, scoped decryption certificates for inspecting encrypted traffic. This architecture provides client-level control of trust boundaries, enhanced traceability, reduced complexity, and improved scalability of encrypted traffic inspection, minimizing the operational risks associated with conventional centralized certificate management.
Owner:ZSCALER INC

Information processing apparatus, method for controlling information processing apparatus, and storage medium

To provide a mechanism capable of preventing an expiration date exceeding a compromise period of an algorithm used for issuance processing of an electronic certificate from being set as the expiration date of the electronic certificate.SOLUTION: The multifunction peripheral 101 generates a public key pair. Further, the multifunction peripheral 101 generates, in accordance with an instruction by the user, an issuance request for an electronic certificate for certifying the validity of the multifunction peripheral 101, which is an issuance request including a certificate signing request generated based on the public key in the public key pair. The multifunction peripheral 101 performs control for preventing an expiration date exceeding the compromise time of the algorithm used for the issuance processing of the electronic certificate from being included in the issuance request for the electronic certificate as the expiration date of the electronic certificate.SELECTED DRAWING: Figure 3
Owner:CANON KK

Method for verifying the origin of an electronic unit for a control device using a verification system, computer program product and verification system

The invention relates to a method for verifying the origin of an electronic unit (1) for a control device (2) using a verification system (3), comprising the steps of: receiving a certificate signing request (7) for digitally certifying the control device (2) with the electronic unit (1) from a requesting instance using a receiving device (4) of the verification system (3), wherein the certificate signing request (7) is signed with a wrapper signature (8) of the electronic unit (1); generating a verification request (9) with a manufacturer of the electronic unit (1) based on the received wrapper signature (8) using an electronic computing device (6) of the verification system (3); transmitting the verification request (9) to the manufacturer using a sending device (5) of the verification system (3);Receiving a verification message (11) for verifying the electronic unit (1) from the manufacturer using the receiving device (4); and verifying the origin of the electronic unit (1) depending on the verification message (11) using the electronic computing device (6). The invention further relates to a computer program product and a verification system (3).
Owner:AUDI AG +1

Secure programming system, operating method thereof and computer readable recording medium using such operating method

A method for operating a secure programming system is provided. Firstly, a first verification code is calculated according to a payload extracted from a job control package. Then, a second verification code is calculated according to the payload burnt into a programmable device. If the first verification code and the second verification code are verified successfully, a burning task is performed. Then, an OEM certificate signing request is generated according to an identifiable information and a programmable device public key. If the OEM certificate signing request is verified successfully, an OEM device certificate is generated and signed with an OEM private key. A third verification code is calculated according to the OEM device certificate. Then, a fourth verification code is calculated according to the OEM device certificate burnt into the programmable device.
Owner:DEDIPROG TECH

Hierarchical certificate issuing system, method, device and equipment

The invention provides a hierarchical certificate issuing system, method, device and equipment, and the system comprises root CA equipment, strategy CA equipment and certificate issuing CA equipment: the root CA equipment is used for generating a self-signature root CA certificate based on a root CA key pair, and carrying out the signature of a strategy CA certificate signature request of the strategy CA equipment through employing a root CA private key, and obtaining the strategy CA certificate; the policy CA equipment is used for acquiring a policy CA certificate from the root CA equipment and signing a certificate issuing CA certificate signature request of the certificate issuing CA equipment by adopting a policy CA private key to obtain the certificate issuing CA certificate; the certificate issuing CA equipment is used for acquiring a certificate issuing CA certificate from the policy CA equipment and signing a terminal certificate signature request of the terminal equipment by adopting a certificate issuing CA private key to obtain a terminal entity certificate; and the certificate issuing CA equipment is also used for sending a certificate chain to the terminal equipment, and the certificate chain comprises a self-signature root CA certificate, a policy CA certificate, a certificate issuing CA certificate and a terminal entity certificate.
Owner:BEIJING CHUANGRUI HONGKE TECHNOLOGY CO LTD

Cryptographic algorithm identity (CAI) certificate selection system and method

Systems and methods for cryptographic algorithm identity certificate selection in an Information Handling System (IHS) are described. In one embodiment, an IHS includes a processor, and a memory coupled to the processor. The memory stores program instructions that, upon execution, cause the processor to receive a Certificate Signing Request (CSR) from a server, sign the CSR with a first Cryptographic Algorithm Identity (CAI) key stored in the memory, and send the signed CSR to the server. The server is configured to identify a geographical region that is associated with the first CAI key, identify an approved cryptographic algorithm that is approved for use in the identified region, and send a second CAI key associated with the identified approved cryptographic algorithm. When the IHS receives the second CAI key from the server, it may perform a cryptographic operation using a cryptographic algorithm associated with the second CAI key.
Owner:DELL PROD LP

Security authentication method and system for edge device

The invention provides an edge device security authentication method and system, and the method comprises the steps: a production stage: generating a certificate signature request based on a security element of an edge device, so that a cloud server signs and issues a device certificate according to the certificate signature request; in the cloud server, establishing a binding relationship between the device identifier of the edge device and the element identifier of the secure element; in the deployment stage, the edge device executes bidirectional authentication with the cloud server so as to complete registration of the edge device after the cloud server verifies the binding relationship between the device identifier and the element identifier; in the use stage, the cloud server responds to a binding request which is initiated by the user terminal and carries the device identifier, and binding of the user terminal and the edge device is completed. According to the invention, security protection based on a deep hardware level and full-life-cycle security management from production to user use are provided, a security authentication process is guaranteed through high automation, and the authentication efficiency and security risk are greatly improved.
Owner:SHENZHEN SNOWBALL TECHNOLOGY CO LTD

Authentication method, authentication system and communication method

The invention discloses an authentication method, an authentication system and a communication method, a complex three-level architecture under a PKI (Public Key Infrastructure) framework is abandoned, a two-layer architecture of a main controller and nodes is adopted, hierarchical interaction overhead is reduced, a certificate signature request is firstly sent through the nodes, a trust chain between the two layers is established by adopting a signature verification mode, and a certificate signature request is sent through the nodes. And then, within a preset time, based on encryption, decryption, signature and signature verification of the secret key, strict identity authentication of a request-response-confirmation mechanism is completed, so that the security of data interaction during communication can be ensured.
Owner:JIANGSU XCMG STATE KEY LAB TECH CO LTD

Method of updating device certificate and device for driving the method

A device may include processing circuitry configured to, generate a device identifier associated with the device, and generate a unique endorsement identity (ID) associated with the device identifier, a first layer sub-circuit configured to, receive the device identifier, and generate a first certificate and a second certificate based on the device identifier and the unique endorsement ID, the first certificate and the second certificate including information to authenticate the device, and the processing circuitry is further configured to, receive the first certificate and the second certificate, and verify whether the device has been modified based on the first certificate and the second certificate, wherein, in response to the first layer sub-circuit being modified, the first layer sub-circuit is further configured to, generate an endorsement key based on a new unique endorsement ID, and generate a certificate signing request for the new unique endorsement ID based on the endorsement key.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for verifying the origin of an electronic unit for a control device using a verification system, computer program product, and verification system

The invention relates to a method for verifying the origin of an electronic unit (1) for a control device (2) using a verification system (3), having the steps of: receiving a certificate signing request (7) for digitally certifying the control device (2) with the electronic unit (1) from a query entity by means of a receiving device (4) of the verification system (3), wherein the certificate signing request (7) is signed with a wrapper signature (8) of the electronic unit (1); generating a verification query (9) for a manufacturer of the electronic unit (1) on the basis of the received wrapper signature (8) by means of an electronic computing device (6) of the verification system (3); transmitting the verification query (9) to the manufacturer by means of a transmitting device (5) of the verification system (3); receiving a verification message (11) for verifying the electronic unit (1) from the manufacturer by means of the receiving device (4); and verifying the origin of the electronic unit (1) on the basis of the verification message (11) by means of the electronic computing device (6). The invention also relates to a computer program product and to a verification system (3).
Owner:VOLKSWAGEN AG +1

Trusted digital identity management method and device, equipment, medium and product

The invention discloses a trusted digital identity management method, device, equipment, medium and product, a super SIM card receives a key generation instruction sent by a user terminal, generates a key comprising a public key and a private key, generates a certificate signature request file according to the public key and an identity identification code of the user terminal, and sends the certificate signature request file to the user terminal; the user terminal carries a certificate signature request file and user identity information and initiates a digital identity creation request to the trusted identity platform; and when the SIM card receives encrypted data returned after the trusted identity platform adopts the public key to encrypt, the SIM card adopts the private key to decrypt to obtain the digital identity certificate, the user identity information and the biological characteristic identification information signed by adopting the digital identity certificate in the encrypted data, and returns a digital identity creation result to the user terminal. According to the invention, the management processes such as creation and authentication of the digital identity certificate are realized through the super SIM card, and the security of the digital identity certificate in the storage and authentication process is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

xApp instance registration in cloud-native networks

Provided are a method, system, and device for registering an xApp instance in a cloud-native network. The method may be implemented by a Near Real-Time (RT) Radio Access Network (RAN) Intelligent Controller (RIC), and the method may include: receiving a registration message including details of an xApp instance and an xApp identifier (ID) from Service Management and Orchestration (SMO); generating a certificate signing request (CSR) based on the registration message, wherein the CSR includes the xApp ID registered in the Near RT-RIC; receiving an identification request message from the xApp instance; verifying the xApp instance based on the identification request message; and sending an identification response message to the xApp instance.
Owner:RAKUTEN SYMPHONY INC

Certificate signature request file synchronization method and device, electronic equipment and storage medium

The invention relates to a certificate signature request file synchronization method and device, electronic equipment and a storage medium, and the method comprises the steps: automatically sending a generated CSR file to a first server located in the same local area network as the electronic equipment in response to the availability of network connection, forwarding the received CSR file by the first server, and sending the CSR file to the electronic equipment; and the CSR file sent by the electronic equipment can be uniformly forwarded to the second server only by configuring the first server which can be connected with the same local area network as the electronic equipment and also can be connected with the external network without configuring a special network which can be connected with the external network for writing on the electronic equipment. In this way, additional manual sites can be omitted, network and after-sales costs are saved, the data reliability is further improved, and the risk of file leakage is avoided; and meanwhile, the automation and intellectualization of the automatic generation, sending and forwarding processes of the whole CSR file are realized, the production efficiency is remarkably improved, and the electronic equipment of which the CSR file is not successfully forwarded is prevented from flowing into the market.
Owner:SHENZHEN SKYWORTH RGB ELECTRONICS CO LTD

Interim root-of-trust enrolment and device-bound public key registration

Methods, apparatuses, devices and computer readable media are provided in relation to enrolment. In one example, an electronic device is provided. The electronic device comprises a security module having a physical unclonable function (PUF). The security module is configured to establish an enrolment key pair (EPK,ESK) based on a first challenge and response to the PUF, the enrolment key pair comprising an enrolment public key (EPK) and an enrolment secret key (ESK). The electronic device further comprises one or more memories. The electronic device further comprises one or more processors configured to, over a secure connection, transmit a certificate signing request (CSR) comprising a device identifier and the EPK to a server for a certificate certifying that the EPK is associated with the device identifier, wherein the CSR is signed using the ESK, and wherein the device identifier is based on a function of the EPK. The one or more processors are further configured to, over the secure connection, receive a temporary enrolment device certificate certifying that the EPK is associated with the device identifier and including a validity period. The one or more processors are further configured to install the temporary enrolment device certificate in memory.
Owner:CRYPTO QUANTIQUE LTD

Digital certificate full life cycle management method and system based on PKI system

The invention provides a digital certificate full life cycle management method and system based on a PKI system, and relates to the technical field of information security, and the method comprises the steps: receiving a certificate signature request sent by an unmanned platform end through a user datagram protocol UDP; if the validity verification of the certificate signature request is passed, signing and issuing an unmanned platform end certificate by using a private key of the intermediate CA; a complete certificate chain containing an unmanned platform end certificate is assembled, and the complete certificate chain is issued to the unmanned platform end at a time through a UDP; monitoring the state information of the certificate managed by the intermediate CA through a certificate life cycle management engine integrated in the intermediate CA; and when the residual validity period of the certificate is determined to be insufficient based on the state information, a certificate updating process is automatically triggered, and the unmanned platform end is notified to send a new certificate signature request through a UDP (User Datagram Protocol). According to the method, security risks are isolated through hierarchical CA design, automatic processing of certificate application, signing and issuing, updating and revoking is realized, and the security of a PKI system is improved.
Owner:天津(滨海)人工智能创新中心

Certificate registration system and method for non-virtual machine-based network element

To provide a certificate registration system and a method for a non-virtual machine-based network element performing fully automated certificate registration in a mobile communication network.SOLUTION: A system is composed with a network element (NE) that requests a certificate and a central data center that includes a DHCP server that authenticates the NE and provides them with information about a Certificate Authority (CA) server, and a Certificate Manager (CM) that acquires a pre-configured policy for a requested certificate, acquires the certificate on the basis of the pre-configured policy, and issues the certificates to the NE. The NE transmits a request to the CM to acquire information about the CM, acquires the information about the CM from the CM, transmits, on the basis of the acquired information about the CM, a certificate signing request to the CM to request a certificate, and receives from the CM the requested certificate generated by the CA server possessed by the CM.SELECTED DRAWING: Figure 2
Owner:RAKUTEN MOBILE INC

Communication certificate secure canning method, device and equipment of vehicle-mounted terminal and medium

The invention provides a communication certificate security canning method, device and equipment of a vehicle-mounted terminal and a medium, and effectively solves the problem that a large number of security risks and uncontrollable factors occur due to the fact that a communication certificate does not exist between an existing vehicle-mounted terminal and a vehicle factory. The method comprises the following steps: a production line module sends a certificate generation instruction to a vehicle-mounted terminal, and a vehicle-mounted host receives the certificate generation instruction through a vehicle body bus and forwards the certificate generation instruction to a key generation module of the vehicle-mounted terminal; the key generation module calls the vehicle factory encryption module, locally generates an asymmetric key pair at the vehicle-mounted terminal through the vehicle factory encryption module, and generates a certificate signature request based on the asymmetric key pair; the vehicle factory encryption module binds the certificate signature request with a vehicle-mounted terminal identifier pre-acquired by the key generation module to generate a communication certificate; and the key generation module generates a processing result and feeds back the processing result to the production line module through the vehicle body bus so as to complete safe canning.
Owner:JIANGSU BDSTAR AUTOMOTIVE ELECTRONICS CO LTD

Signature request verification method and system, certificate generation method and system and electronic equipment

The invention discloses a signature request verification method and system, a certificate generation method and system and electronic equipment, which are applied to a verification terminal, the verification terminal is respectively connected with a terminal to be verified and a registration terminal, and the method comprises the following steps: establishing a connection with an operator UKEY through dual verification; obtaining verification information from the operator UKEY, and establishing a secure channel with the registration terminal through the verification information; a first device serial number is obtained, a generation instruction and the first device serial number are sent to the to-be-verified terminal, and the generation instruction is used for driving the to-be-verified terminal to generate a certificate signature request; a certificate signature request is received, the first device serial number, the certificate signature request and a verification instruction are sent to the registration terminal through the secure channel, and the verification instruction is used for driving the registration terminal to verify the first device serial number and the certificate signature request to obtain a verification result; and receiving a verification result. The registration terminal can identify the certificate signature request of a legal source, and the authentication efficiency and security are improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Dynamic generation of digital certificate requests

A method in a server, the method comprising: storing, in a memory of the server, a certificate signing request (CSR) input template comprising: (i) a dynamic first field definition including an attribute name, and (ii) a second field definition including a second field value; transmitting respective CSR instructions to a plurality of client devices, each instruction including the CSR input template; in response to transmitting the instructions, receiving, from each client device, a CSR comprising: (i) a first field value including an attribute value inserted by the client device in place of the attribute name, and (ii) the second field value; installing respective digital certificates at each of the client devices in response to receiving the CSRs.
Owner:ZEBRA TECHNOLOGIES CORP

Vehicle network security authentication device, vehicle network equipment and vehicle network security authentication method

An embodiment of the present invention provides an in-vehicle network security authentication device, an in-vehicle network device, and an in-vehicle network security authentication method. The device includes: a first TLS communication module for establishing a TLS communication connection with the in-vehicle network device; an initialization module for sending a temporary login password to the in-vehicle network device that initially establishes a TLS communication connection with the first TLS communication module and receiving a device address code fed back by the in-vehicle network device and binding and storing the temporary login password and device address code; a login management module for comparing the temporary login password and device address code sent by the in-vehicle network device with a pre-bound temporary login password and device address code, and issuing a disconnection instruction when it is determined that they do not match; and a certificate management module for generating a temporary digital certificate in response to a certificate signing request and returning the temporary digital certificate to the in-vehicle network device. This embodiment can effectively improve the security of data transmission between in-vehicle network devices.
Owner:CHENGDU BOYN TIANFU SOFTWARE TECH CO LTD

Multi-algorithm PKI certificate issuing and verifying method and system

The invention provides a multi-algorithm PKI certificate issuing and verifying method and system. The multi-algorithm PKI certificate issuing method comprises the following steps: receiving a certificate signature request; determining a cryptographic algorithm of a target algorithm family based on the content of the certificate signature request or an externally input algorithm selection parameter; routing the certificate signature request to a signature engine corresponding to the target algorithm family to execute digital signature operation so as to obtain a certificate signature value; assembling an extension field of the certificate according to a predefined certificate template; and generating and outputting the digital certificate containing the certificate signature value. The method and the device are suitable for diversified encryption scene requirements.
Owner:DONGFENG MOTOR GRP

Method for securely equipping control units manufactured by a supplier with crypto material

The invention relates to a method for securely equipping electronic control units (ECUs) manufactured by a supplier (SUP) for vehicles of a vehicle manufacturer (OEM) with an individual key pair (KeyPairECU) and a certificate (ZertECU), for which In a first step, a key pair (KeyPairSUP) is securely negotiated between the vehicle manufacturer (OEM) and the suppliers (SUP), whereby in a second step, during production at the supplier (SUP), each of the control units (ECU) generates a unique random key pair (KeyPairECU) and stores it within the control unit (ECU), after which In a third step, the control unit (ECU) generates a certificate signing request (CSR) and signs it with the public key from the generated key pair (KeyPairECU), after which In a fourth step, the supplier (SUP) delivers the control unit (ECU) and the certificate signing request (CSR) to the vehicle manufacturer (OEM), after which In a fifth step, the vehicle manufacturer (OEM) verifies the certificate signing request (CSR) in its public key infrastructure (PKI). and, in the event of a positive inspection, issues a certificate (ZertECU) for the control unit (ECU), according to which In a sixth step in the production process of the vehicle manufacturer (OEM), the certificate (ZertECU) belonging to the control unit (ECU) is installed in the control unit (ECU).
Owner:MERCEDES BENZ GROUP AG

Information processing apparatus using electronic certificate, control method therefor, and storage medium storing control program therefor

An apparatus capable of preventing from setting an expiration date of an electronic certificate exceeding an imperilment time of an algorithm used for an electronic certificate issuing process. The apparatus including a memory device that stores a set of instructions, and at least one processor that executes the set of instructions to generate a key pair, generate an issue request for an electronic certificate that certifies legitimacy of the apparatus according to an instruction by a user, the issue request including a certificate signing request generated based on a public key included in the key pair, perform control to prevent a date exceeding an imperilment time of an algorithm used for an issue process for an electronic certificate from being included in the issue request as an expiration date of the electronic certificate, and obtain an electronic certificate generated according to the issue request.
Owner:CANON KK

Managing hygiene of key pairs between certificate authorities using FHE

A method of issuing a digital certificate includes receiving a certificate signing request (CSR) from an entity; determining a public key of the entity from the CSR; applying encryption to the public key; checking whether a result of the encryption is in a database to determine whether the public key has been previously used; and responsive to the public key not having been previously used, issuing a certificate to the entity based on the public key and the CSR. The method can further include, responsive to the public key having been previously used, alerting the entity to resubmit the CSR with a public key that has not been previously used or inquiring from the entity whether to proceed to issuing the certificate despite previous use. The encryption can be fully homomorphic encryption (FHE).
Owner:DIGICERT INC

Digital certificate issuing method based on double certificate system and related device

Embodiments of the application disclose a digital certificate issuing method and related device based on a double-certificate system, a user terminal generates a first and a second public-private key pair according to an asymmetric encryption algorithm and a post-quantum key signature algorithm respectively; the first and the second public key are taken as a hybrid public key to generate a certificate signature request together with user identification information, and the certificate signature request is sent to a certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key and an encrypted symmetric key according to the certificate signature request; the user terminal decrypts the encrypted hybrid key encapsulation private key and the symmetric key according to the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed and bound with the corresponding private key, so that the hybrid key signature certificate and the hybrid key encapsulation certificate are issued, the legal use of the certificate in a quantum algorithm resistant scenario is ensured, and the information security is improved.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Secure token distribution

A method for facilitating certificate signing requests with a registration authority is disclosed. In at least one embodiment, a registration authority computer can receive a certificate signing request associated with a token requester. The registration authority can authenticate the identity of the token requester and forward the certificate signing request to a certificate authority computer. A token requester ID and a signing certificate can be provided by the certificate authority computer and forwarded to the token requester. The token requester can utilize the token requester ID to generate a digital signature for subsequent token-based transactions.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION