Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

181 results about "Certificate verification" patented technology

The online certificate verification process can be used to verify that a certificate of filing or a certificate of fact has, in fact, been issued by the Corporations Section of the Texas Secretary of State. Enter the document number that appears at the bottom of the document you wish to verify,...

Power system source network interaction data security encryption verification method, system, device and medium

The invention discloses a power system source network interaction data security encryption verification method, system, device and medium, and belongs to the technical field of power system communication encryption, and the method comprises the following steps: a source side device and a network side device complete identity authentication through a bidirectional digital certificate verification mechanism; and an identity binding label is generated in combination with the device identifier, the timestamp and the position information. And after the authentication is passed, the two parties perform key negotiation based on an elliptic curve algorithm, and generate a temporary encryption key in combination with an authentication result. A source side device carries out structural packaging on original interaction data, adds a random number, a timestamp and a hash abstract, then encrypts the original interaction data in an AES-GCM mode, and carries out signature binding on key fields through digital signatures to form a complete data packet. And a receiving end performs compliance judgment on the timestamp and the random number in the data packet, and after the timestamp and the random number are confirmed to be in an effective time window and are not replayed, signature verification, decryption processing and Hash consistency verification are sequentially completed, so that closed-loop processing of a data flow is ensured.
Owner:GUANGDONG YTD TECH DEV CO LTD

Network range-based iframe bidirectional encryption communication method and system

The invention discloses an iframe two-way encryption communication method and system based on a network target range, and belongs to the technical field of network security. In the aspect of data communication of iframes of a front-end platform and a third-party platform, security is enhanced, a digital certificate is generated through an ECDH key pair, and a foundation is laid for identity verification; then TCP handshake is simulated to establish a reliable channel, and two-way identity authentication resisting replay attack is achieved through two-way certificate verification and random number exchange; then negotiating a shared key by using ECDH, deriving a dynamic session key through an HKDF algorithm, and ensuring forward confidentiality; and finally, real-time data encryption and integrity verification are carried out by adopting AES-GCM, and the anti-leakage capability is continuously improved through a timing key rotation mechanism. The whole process fuses the characteristics of quantum computing resistance, low resource consumption, efficient transmission and the like, an end-to-end secure communication normal form is provided for Web application, and cross-session key confusion is prevented.
Owner:SAINING WANGAN

SD card-based power distribution terminal upgrading method, system, equipment and medium

The invention discloses a power distribution terminal upgrading method, system and device based on an SD card and a medium. The method specifically comprises the steps of generating an incremental package of a Linux kernel and / or a root file system, calculating a hash value file of the incremental package, and generating a block chain certificate with a timestamp; encrypting and packaging the incremental package, the hash value file and the block chain certificate into a container mirror image, performing digital signature to form an upgrade package, and writing the upgrade package into an SD card; after it is detected that the SD card is inserted, mounting a boot partition, analyzing metadata of an upgrade package, and setting an upgrade flag bit and an upgrade operation type of Boot; and performing digital signature verification, hash value file verification and block chain certificate verification on the upgrade package in the SD card, if the verification is passed, backing up user parameters to the encrypted storage area, and restarting to enter the Recovery OS to complete replacement upgrade of the Linux kernel and / or the root file system. According to the method, safe, efficient and flexible upgrading of the operating system of the power distribution automation terminal is achieved, the rollback function is achieved, and the upgrading risk and cost are effectively reduced.
Owner:ZHUHAI COPOWER ELECTRIC

Certificate verification method, computer program, and certificate verification system

To provide a novel technique for streamlining a verification operation of a certificate possessed by a user by utilizing a video call.SOLUTION: A certificate verification method executed by a computer device includes: a video call step of executing a video call between a user terminal and a supporter; a target certificate information acquisition step of acquiring target certificate information on the basis of imaging at the user terminal during the video call; a certificate verification step of verifying a certificate on the basis of the target certificate information acquired in the target certificate information acquisition step; and a registration step of registering a verification result for the target certificate information in association with user information of a user who executed the video call, the steps being performed by at least one processing unit.SELECTED DRAWING: Figure 5
Owner:HUBBIT CO LTD

Asynchronous verification and batch storage system and method for high-concurrency voucher data

The invention relates to the technical field of data processing and storage, in particular to an asynchronous verification and batch storage system and method for high-concurrency voucher data. Certificate verification is executed based on the memory snapshot, and verification time consumption is improved from the millisecond level of database IO to the microsecond level of memory calculation; a batch persistence mechanism enables the throughput of the system to be improved by dozens of times, and a concurrent storage scene of ten thousand-level TPS can be easily supported; the voucher storage response time is reduced from a hundred millisecond level to a millisecond level; the response is immediately returned to the user after the verification is passed, the user almost does not need to wait, and the operation experience is smooth; the introduction of the message queue enables the system to have peak clipping and valley filling capabilities, and can deal with burst traffic leisurely; the multi-node cluster deployment supports horizontal capacity expansion, the fault of a single node does not influence the overall service availability, and the system reliability is improved.
Owner:PANSOFT

Backup and recovery method and system for iOS device data

The invention relates to the technical field of data backup, and discloses an iOS device data backup and recovery method and system, and the method comprises the steps: carrying out the SSL certificate verification and EscrowBag key authentication of an iOS device, and obtaining a data path list; according to the data path list, parallel scanning of APFS file system B-Tree traversal, NAND flash memory page reading and SQLite WAL log analysis is carried out on the iOS device storage partition, and an original data set is obtained; performing integrity evaluation based on the original data set to obtain an effective data set and constructing a virtual file index; the data selection list of the user is confirmed based on the virtual file index, safety recovery is executed, and a data recovery result is returned. The SQLite page Cell reconstruction and fragment file signature matching technology is combined, intelligent repair and quality prediction can be conducted on damaged data, the user experience and operation efficiency are improved, and the user experience is improved. And the security and the reliability in the data recovery process are ensured.
Owner:深圳市乐数科技有限责任公司

Power distribution authorization method and device based on certificate file, equipment and medium

The invention provides a power distribution authorization method and device based on a certificate file, equipment and a medium, and relates to the technical field of cross of power distribution automation and information security. A certificate generation end formats authorization information such as equipment unique identification, validity period and operation authority into an XML plaintext, randomly generates a one-time RSA key pair, and sends the one-time RSA key pair to a server; encrypting the segmented plaintext by using a public key to obtain a ciphertext, and carrying out BASE64 coding; and meanwhile, coding the private key through BASE64, performing equal-length segmentation and cross mixing on the private key and the ciphertext to form a mixed character string, adding a private key coding length identifier at the tail part, and finally outputting. And text certificates. And the verification end can perform reverse splitting only according to the length identifier, restore the ciphertext and the private key, complete BASE64 decoding and RSA decryption, analyze the XML, compare the SN and determine whether to open the configuration permission after the validity period.
Owner:XIAMEN FOUR-FAITH SMART POWER TECH CO LTD

Customized network interface card oriented to intranet security access and design method thereof

The invention discloses a network interface card with autonomous access authentication, and provides an integrated hardware authentication mechanism. The EAP-TLS client protocol stack is integrated on the bottom layer of the network card, so that the defect that an authentication module depends on a host system, manual intervention and the like in the existing scheme is overcome, TLS handshake and certificate verification are independently completed on the network card side, and authentication interaction is automatically initiated. The network interface card serves as a unique identity certificate of an access network, a client certificate and a corresponding private key are embedded in the network interface card and are stored in a protected nonvolatile area, and data confidentiality is effectively enhanced. The network card is used as an identity certificate and network access equipment at the same time, and the integrated design reduces the dependence on the service capability of management personnel. A traditional physical network card and an automatic authentication protocol are fused, and the method is suitable for application environments with high requirements for access control and authentication safety, such as an enterprise intranet and a government affair private network.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Anti-quantum computing IPSEC key exchange method

The invention relates to an IPSEC (Internet Protocol Security) key exchange method resistant to quantum computing. According to the invention, based on a lattice cryptographic algorithm and improved SM4-256 symmetric encryption, secure communication between a master mode and a fast mode is realized; in the main mode, an initiator sends an IKE first message through a UDP (User Datagram Protocol), negotiates SA parameters with a responder and exchanges a lattice password certificate; the two parties encapsulate a temporary 32-byte secret key by using the public key of the opposite party, generate a 512-bit random number through SM4-256 encryption, and sign and transmit the 512-bit random number to realize secure random number exchange and certificate verification; and the two parties calculate a first session key based on a PRF (Pseudo Random Function), and encrypt an exchange data HASH value to complete main mode key consistency confirmation. And after entering the fast mode, taking the main mode session key as an SM4-256 symmetric key to continue communication, sending an SA message carrying a 512-bit random number by the two parties, calculating to obtain a second session key, and establishing an ESP tunnel. According to the method, the security of IPSEC under the threat of quantum computing is improved through the lattice password.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Exit and entry certificate verification method based on dynamic weight and multi-modal fusion

The invention relates to an entry and exit certificate verification method based on dynamic weight and multi-modal fusion, and belongs to the technical field of entry and exit certificate information processing and verification. The method comprises the following steps: collecting multi-source heterogeneous data of a certificate in three modes of visual reading, machine reading and chip reading; constructing a verification data graph taking the unique identification of the certificate as a core, and carrying out data association and alignment; based on a dynamic weight distribution model, performing weighted voting fusion on the homologous key fields, and performing semantic fusion on the heterologous complementary fields; and constructing a traceable verification decision factor matrix, judging a verification conclusion according to the content of the matrix, positioning a source when the verification conclusion is abnormal, and generating a structured verification record containing a complete decision path and a disposal scheme. Through the dynamic weight fusion and the decision factor matrix, the problem of splitting of the existing verification mode is effectively solved, and the accuracy and reliability of the verification result and the process traceability are remarkably improved.
Owner:中华人民共和国上海出入境边防检查总站

Intelligent contract management method and system for cargo receipt circulation

The invention provides an intelligent contract management method and system for cargo receipt circulation, and the method comprises the steps: carrying out the certificate verification of a cargo receipt circulation request of a certificate initiation node through an intelligent contract system, generating a first receipt certificate, and transmitting the first receipt certificate to a certificate confirmation node for signing; receiving signing information of the voucher confirmation node, generating a second document voucher, sending the second document voucher to a first execution node, and monitoring cargo state information; according to the cargo state information, generating a third document voucher, sending the third document voucher to a second execution node, and obtaining transfer state information; and carrying out delivery voucher identification based on the transfer state information, generating a fourth document voucher, sending the fourth document voucher to a voucher receiving node for confirmation, and completing document circulation. According to the method, automatic receipt generation and circulation of multi-node collaboration and state driving can be realized, and trust cost and communication delay across subjects are greatly reduced.
Owner:SHENZHEN QIANHAIZEJIN IND & FINANCE TECH CO LTD

TLS1.3 protocol security enhancement method and system based on homologous cryptographic algorithm

The invention discloses a TLS1.3 protocol security enhancement method and system based on a homologous cryptographic algorithm, and the method comprises the steps: 1), certificate generation: signing and issuing a certificate through an SQISign signature algorithm, and guaranteeing the verification and use of a post-quantum security signature algorithm through the certificate; and 2) protocol design: the client and the server complete identity verification through certificate verification based on an SQISign signature algorithm in a handshake stage of a TLS 1.3 protocol. And the server uses a FleS public key encryption algorithm to carry out key encapsulation and send the key encapsulation to the client, completes key exchange and establishes secure encryption connection with the client. The step 1) and the step 2) comprise compatibility design, and a homology-based post-quantum algorithm and a traditional cryptographic algorithm are allowed to coexist, so that the compatibility of an existing system is ensured. Through the method provided by the invention, the TLS 1.3 protocol can effectively resist security threats brought by quantum computing, the security of network communication in the quantum era is ensured, and meanwhile, the smooth transition of the existing system is ensured.
Owner:WUHAN UNIV

Network access control method, apparatus and device, and storage medium

Embodiments of the present disclosure relate to a network access control method, apparatus and device, and a storage medium. The network access control method includes: receiving a certificate verification request sent by a terminal, and returning a certificate verification response to the terminal, wherein the certificate verification response carries a preset server certificate, the certificate verification response is used for instructing the terminal to verify the preset server certificate based on a root certificate installed in the terminal, and identity verification information of the root certificate is partially or fully different from identity verification information of the preset server certificate; and receiving a verification result returned by the terminal for the preset server certificate, and in a case where the verification result indicates that certificate verification succeeds, determining that the terminal has a security risk and interrupting a network access communication link of the terminal. In the embodiments of the present disclosure, when the terminal successfully verifies the preset server certificate, the terminal may be prevented from accessing a network by interrupting the network access communication link with the terminal, thereby improving the security of the network.
Owner:DOUYIN VISION CO LTD

Trusted time transfer apparatus and method

The application discloses a kind of trusted time transfer device and method, it is related to trusted time transfer technical field, including network management system and trusted time transfer equipment;Network management system is used for equipment identity solidification and authentication and equipment operating state real-time monitoring;Trusted time transfer equipment is based on trusted time signal reception relay module, equipment identity authentication pre-solidification mechanism, two-way certificate verification and transmission encryption mechanism, equipment failure stop signal transmission mechanism and the traceability and proof mechanism of time signal, real-time measurement is carried out to trusted time signal, time delay compensation, signal amplification processing is transferred out;The application ensures that itself is not replaced by strict control mechanism;On signal processing, the controllability of time real-time detection and time delay compensation is realized;In addition, it also provides a feasible path for the traceability verification and credibility proof of time signal with time relay function.
Owner:SICHUAN TAIFU GROUND BEIDOU TECH CO LTD

Cloud distributed node identity authentication method based on identity identification certificate

The invention discloses a cloud distributed node identity authentication method based on an identity label certificate, and aims to solve the problems of single-point failure, difficulty in cross-domain mutual recognition, efficiency and privacy imbalance and the like of a traditional authentication scheme. The system is composed of an identity identification certificate generator, a distributed certificate verification network and a block chain certificate account book, a master key is split through threshold secret sharing, the overhead is optimized through BLS signature aggregation, state consistency is guaranteed in combination with DHT and gossip protocols, and certificate full-life-cycle management is achieved through block chain certificate storage and an intelligent contract. The process includes system initialization, identity registration and certificate issuing, identity authentication and certificate updating and revocation, technologies such as elliptic curve cryptography and zero-knowledge proof are adopted, and security, efficiency and privacy protection are considered. The method is suitable for multiple scenes such as a power grid and the Internet of Things, supports cross-domain mutual recognition and dynamic capacity expansion, can effectively prevent illegal access and data tampering, and is suitable for large-scale cloud distributed node identity authentication.
Owner:GUANGXI POWER GRID CORP

Trusted time transfer device and method

The invention discloses a trusted time transmission device and method, and relates to the technical field of trusted time transmission, and the device comprises a network management system and trusted time transmission equipment; the network management system is used for equipment identity solidification and authentication and equipment operation state real-time monitoring; the trusted time transmission device performs real-time measurement, time delay compensation and signal amplification processing on a trusted time signal based on a trusted time signal receiving relay module, a device identity authentication pre-curing mechanism, a bidirectional certificate verification and transmission encryption mechanism, a device fault stop signal transmission mechanism and a time signal traceability and proving mechanism, and then transmits the trusted time signal; it is ensured that the device is not replaced through a strict control mechanism; in the aspect of signal processing, the controllability of time real-time detection and time delay compensation is realized; in addition, the time relay function is achieved, and a feasible path is provided for traceability verification and credibility proof of time signals.
Owner:SICHUAN TAIFU GROUND BEIDOU TECH CO LTD

An agent system automatically identifies and downloads and installs a self-controllable peripheral

The present application relates to the technical field of computer data processing, and especially relates to an intelligent agent system for automatically identifying, downloading and installing self-controllable peripherals, which comprises a device information acquisition module for collecting data to generate hardware identification data; a driver compatibility determination module for comparing a pre-stored self-controllable peripheral list to match a driver resource to generate a resource identification; a secure downloading module for establishing an encrypted connection to download a driver file, storing the driver file in an isolated sandbox after hash verification and digital certificate verification; a driver migration module for simulating a system call environment through an operating system compatibility layer in the driver migration module, and converting a driver instruction into a host system instruction by using a user-level binary translator in the driver migration module; and an automatic installation module for calling a system interface to deploy the driver and verifying an installation state. The present application realizes closed-loop automatic processing from identification to installation of a peripheral driver, and solves the problem of compatibility between a Linux system and a Windows driver.
Owner:BEIJING TAIJI INFORMATION SYST TECH CO LTD +1

Systems and methods for phone number certification and verification

Methods, systems, apparatuses, and computer-readable storage mediums are described for issuing digital certificates to phone numbers and verifying phone numbers based on the digital certificates. For instance, a client may request from a certificate authority a digital certificate to be associated with the client's phone number. The certificate authority issues a phone number challenge to the client to verify that the request did in fact come from the client. The certificate authority signs and issues the digital certificate to the client responsive to a successful challenge. The digital certificates are utilized to exchange messages between a caller and call recipient to determine whether a phone number provided via CLI is accurate or inaccurate. Embodiments described herein determine whether the phone number is accurate using a process referred herein as positive CLI verification and determines whether the phone number is inaccurate using a process referred herein as negative CLI verification.
Owner:JUST ONE TECH LLC

Signing, issuing and verifying method and device of digital certificate

The invention discloses a digital certificate signing and issuing method and device and a digital certificate verification method and device. The method comprises the steps that a certificate application request submitted by a user is received, and the certificate application request comprises a shared key received by the user in the digital certificate application process; determining an issuing CA corresponding to the certificate application request, and determining an encryption key corresponding to the issuing CA from a key relationship library; encrypting the shared key according to the encryption key to obtain an encrypted shared key, and adding the encrypted shared key to a private extension field in the certificate application request to obtain an updated target certificate application request; and signing the target certificate application request through the signing and issuing CA to generate a corresponding digital certificate. According to the method and the device, the technical problem that the certificate private key is easy to be illegally used after being leaked due to the fact that digital certificate verification in related technologies only depends on verification of validity of the certificate private key and an effective certificate holder identity dynamic verification mechanism is lacked is solved.
Owner:CHINA TELECOM CORP LTD

A zero-carbon coal washing and water treatment source network load storage integrated microgrid system based on energy ring

PendingCN122659837AMicrogridData stream
The application discloses a zero-carbon washing and selecting and water treatment source network load storage integrated microgrid system based on an energy ring, wherein distributed photovoltaic units and substation energy storage units of each workshop are connected to a common direct-current bus through bidirectional DC / DC isolation units to eliminate parallel circulating current from a physical layer; a central shared energy storage regulating unit is arranged and is specially used for bus voltage stabilization and transient power suppression; a direct-current charging and changing facility with a single-pile independent DC / DC architecture is used as a flexible adjustable load unit, and is combined with washing and selecting and water treatment rigid loads to form a virtual battery regulating capacity of a factory area. A three-in-one scheduling control platform of the application is combined with blockchain storage and wind power green electricity certificate verification and cancellation technologies, and realizes four-flow closed-loop cooperation of energy flow, data flow, carbon flow and value flow. The application effectively reduces equipment loss, improves photovoltaic power consumption capacity, meets distributed photovoltaic full self-generation and self-use approval requirements, realizes zero-carbon energy supply of a factory area at all time periods, and simultaneously completes carbon footprint compliance verification and carbon asset value conversion.
Owner:ORDOS MUMU TECHNOLOGY CO LTD

Certificate authority verification system, certificate authority verification method, and program

PCT designated stageWO2026176551A1Self-signed certificateInternet privacy
This certificate authority verification system includes: a verification device; a local certificate authority device that operates under an isolated execution environment; a certificate presenter device that serves as a server or a client and uses a server certificate or a client certificate; and a certificate verifier device that serves as a server or a client and verifies a presented certificate. The certificate authority device includes a self-certificate generation unit that generates a self-certificate which is a certificate of the certificate authority device itself, an evidence generation unit that generates evidence of the self-certificate, and a reference value registration request unit that executes a reference value registration request together with a reference value of the self-certificate. The verification device includes a reference value registration unit that registers the reference value of the self-certificate.
Owner:NT T INC

Method and apparatus for providing fod service by using certificate

Provided are a method and apparatus for providing a feature on demand (FoD) service by using a certificate. According to an embodiment of the present disclosure, the method performed by an electronic control unit may comprise the operations of: receiving an FoD certificate from a certificate root server, by using a certificate distribution server and a gateway, and verifying a digital signature of the FoD certificate; when the digital signature of the FoD certificate has been verified, verifying fields of the FoD certificate other than the digital signature; when the fields of the FoD certificate other than the digital signature have been verified, re-verifying the digital signature of the FoD certificate and storing the FoD certificate; and applying a digital signature to a challenge of the FoD certificate, and transmitting the FoD certificate to the certificate root server by using the gateway and the certificate distribution server.
Owner:HYUNDAI MOTOR CO LTD +1

Method and apparatus for automatic digital certificate validation

The public key can be recorded on the blockchain by the certificate authority in such a way that any third party can quickly and easily verify that the public key is certified by the certificate authority and that the certification has not been revoked. The certificate authority can revoke a certification almost instantaneously, and / or can certify a new key for the same entity at the same time as revoking the old key. The verification can be incorporated into a new transaction so that there is no gap between reliance on the certificate and verification of its validity. In some cases, each transaction in which a certificate is used can also serve as a certification transaction that links to update the certificate to enable subsequent use.
Owner:ENCHEN CHARTER CO LTD

System, verification method, and program

This invention provides an information processing device, system, verification method, and program that improve digital certificate verification technology. [Solution] In a system in which an information processing device and a terminal device are connected to a network including a mobile communication network and the Internet, the information processing device 10 includes a control unit 11 that acquires attribute information associated with a digital certificate and identification information related to the digital certificate, verifies the digital certificate based on the attribute information and identification information, and outputs the verification result of the digital certificate.
Owner:EIKEN FOUNDATION OF JAPAN

Anonymous authentication and key negotiation method for communication network

The invention relates to an anonymous authentication and key negotiation method for a communication network, relates to the technical field of mobile communication networks, and aims to solve the problems that user identity tracking and revocation are difficult and privacy protection and effective supervision cannot be effectively balanced in a mobile communication system of the communication network. Comprising the following steps: establishing a system and generating system parameters; generating an HN key; generating a tracker key; generating an SN key; distributing certificates, enabling a user to interact with the HN, and requesting the certificate of the attribute of the user; verifying the certificate; a user interacts with the SN to negotiate a session key; displaying the anonymous voucher; verifying the anonymous credential; tracking and tracing; and performing local revocation. According to the method, the role of the tracker is set, the certificate is used for the mobile communication system, and when some malicious behaviors occur, the identity of the user is tracked by the tracker, so that a verifier can perform local revocation, anonymous authentication, identity tracking and revocation oriented to the communication network are effectively realized, and meanwhile, the privacy of other legal users is ensured.
Owner:XIAN UNIV OF POSTS & TELECOMM

Method and system for processing data based on multi-party cooperative network

The invention discloses a data processing method and system based on a multi-party cooperative network. The method comprises the following steps: deploying a digital steward for an operation main body and participants; generating a main body identifier for each participant, and signing and issuing an identity certificate; each participant stores a subject identifier, an identity certificate and a private key of the participant in a digital steward; the participant of the data request issues an invitation link to the participant of the data owner; the data owner receives the invitation link through the digital steward and verifies the identity of the participant of the data request, and the data request verifies the identity of the participant of the data owner; the identity verification comprises main body identification and identity certificate verification; when the identities of the data request and the participant of the data owner pass verification, the data owner and the participant of the data request establish an encrypted connection channel based on the exclusive secret key determined by negotiation; and transmitting the data of the participant of the data request and the participant of the data owner through the encrypted connection channel.
Owner:AISINO CORPORATION

License verification method and electronic equipment

The invention discloses a license verification method and electronic equipment. The method is applied to payment equipment and comprises the following steps: acquiring an equipment license file; analyzing a working certificate and a digital signature from the equipment license file; verifying the legality of the working certificate by using a first public key of a preset intermediate certificate; and if the working certificate is legal, verifying the digital signature by using the working certificate to obtain a verification result. According to the invention, offline verification is realized through a multi-layer certificate trust chain, so that the license is prevented from being easily forged and tampered; through binding correction of the equipment serial number, uniqueness of authorization is ensured, abuse is effectively prevented, and flexibility and practicability of authorization management are improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Server controller login method and device, storage medium and electronic equipment

The application discloses a server controller login method and device, a storage medium and an electronic device, relates to the technical field of servers, and comprises the following steps: receiving a device login request; verifying the integrity of a reference digital certificate carried in the device login request in response to the device login request; in the case where the integrity verification is passed, verifying the first control property of the device login request according to the reference digital certificate; in the case where the first control property verification is passed, verifying the second control property of a target controller by a target account; and in the case where the second control property verification is passed, logging in the target controller according to the control authority of the target controller by the target account carried in the reference digital certificate, so that the technical problem of low login security of the server controller is solved, and the technical effect of improving the login security of the server controller is achieved.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Digital certificate verification methods, devices, equipment, systems, and readable storage media

This application discloses a method, apparatus, device, system, and readable storage medium for verifying digital certificates, belonging to the field of information and communication technology. The method includes: a second device sending a first certificate set to a first device, wherein the first certificate set is at least one of the certificate sets corresponding to each of at least two root certificates stored by the second device. The dormancy period of the target root certificate whose validity period is not the latest is covered by the working period of a backup secondary CA certificate signed by the target root certificate and the working periods of other secondary CA certificates. The first device verifies the legitimacy of at least one digital certificate of the second device based on the root certificates stored and trusted by the first device and the received first certificate set. In this application, the first device can verify the legitimacy of the digital certificate of the second device using the root certificates trusted by the first device. The first device does not need to upload other certificates, increase the number of certificate verification levels, or support new cryptographic algorithms, thus having a wide range of applications.
Owner:HUAWEI TECH CO LTD