Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

83 results about "Public key certificate" patented technology

In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the ownership of a public key. The certificate includes information about the key, information about the identity of its owner (called the subject), and the digital signature of an entity that has verified the certificate's contents (called the issuer). If the signature is valid, and the software examining the certificate trusts the issuer, then it can use that key to communicate securely with the certificate's subject. In email encryption, code signing, and e-signature systems, a certificate's subject is typically a person or organization. However, in Transport Layer Security (TLS) a certificate's subject is typically a computer or other device, though TLS certificates may identify organizations or individuals in addition to their core role in identifying devices. TLS, sometimes called by its older name Secure Sockets Layer (SSL), is notable for being a part of HTTPS, a protocol for securely browsing the web.

Data sharing method, device and system

The present application relates to the technical field of computers, and provides a data sharing method, a device, and a system. Shared data and a data protocol set by a data owner are bound for encryption protection, ciphertext structured data and retrieval metadata are integrally digitally signed, an encapsulation signature and a signature public key certificate are bound on the ciphertext structured data and the retrieval metadata, so that the data authenticity can be verified during circulation and sharing of encapsulated data, and confidentiality and integrity protection of the shared data and the data protocol during circulation and sharing are realized. In addition, the encapsulated data is generated by a trusted device trusted by the data owner, a shared agent is trusted by a plurality of participants participating in data sharing, and data is transmitted between the trusted device and the shared agent through a secure transmission channel, so that the security, confidentiality and integrity protection of the shared data and the data protocol during exporting are realized.
Owner:HUAWEI TECH CO LTD

Internet of Things authentication method and electronic equipment

The embodiment of the invention provides an Internet of Things authentication method and electronic equipment, and relates to the technical field of communication security, and the Internet of Things authentication method comprises the steps: obtaining a dynamic key element of terminal equipment; generating a dynamic key of the terminal equipment according to the dynamic key element, the static identity public key of the terminal equipment and the identity identification information; the static identity public key is obtained through calculation based on hardware fingerprint information and identity identification information of the terminal equipment and pre-configured bilinear pair parameters; sending an authentication request to an access point accessed by the terminal equipment; the authentication request carries identity identification information and a dynamic key; and the access point is used for acquiring the static identity public key from the block chain system according to the identity information, and authenticating the dynamic key based on the static identity public key. According to the method and the device, the security of the dynamic key can be ensured from multiple aspects, the authentication process can be accurately and efficiently completed without pre-storing a public key certificate, and the communication security between the terminal equipment and the access point is improved.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Linear homomorphic digital signature method based on identity on lattice and related equipment

The invention discloses an on-lattice identity-based linear homomorphic digital signature method and related equipment, and belongs to the technical field of information security and passwords, and the method comprises the following steps: S1, generating a public parameter based on a preset security level; s2, calculating a main public key and a main private key based on the public parameters and an NTRU equation; s3, calculating an identity private key based on the main public key, the main private key, the public parameter and the identity id; s4, calculating a signature of the to-be-signed message based on the to-be-signed message, the identity private key and the identity id; s5, performing linear homomorphic operation on the signature of the to-be-signed message based on the public parameter to obtain a homomorphic signature; and S6, verifying whether the signature is passed based on the to-be-signed message, the homomorphic signature, the identity id, the main public key and the public parameter. According to the method, the problem of dependence on a public key certificate management system is solved while the efficient homomorphic operation capability is kept, and more times of linear homomorphic operation are supported, so that the security and practicability of a signature scheme in a quantum computing environment are improved.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Tamper protection for the clock of a field tool

Method (100) for operating a field device (1) comprising an adjustable clock (2), at least one non-volatile CA memory (3) containing a public key certificate (3a) of a trusted certification authority, CA, at least one non-volatile time memory (4) for recording a date and / or time (4a) and at least one interface (5), comprising the steps: • A current date and / or time (7a) is received via the interface (5) (170); • this current date or time (7a) is compared with the date or time (4a) in the time memory (4) (180); and • In response to the fact that the current date or time (7a) is later (190) than the date or time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set to the current date or time (7a) (200).
Owner:VEGA GRIESHABER GMBH & CO

Data sharing method, device and system

The invention provides a data sharing method, device and system, and belongs to the technical field of computers. Encryption protection is performed by binding shared data with a data protocol set by a data owner, digital signature is performed on ciphertext structure data and retrieval metadata as a whole, and a packaging signature and a signature public key certificate are bound on the ciphertext structure data and the retrieval metadata, so that the packaging data can be distributed in a circulation and sharing process, and the service life of the data is prolonged. The data authenticity can be verified, and confidentiality and integrity protection of shared data and data protocols in the circulation and sharing process is achieved. Besides, since the encapsulated data is generated by the trusted equipment trusted by the data owner, the sharing agent is trusted by a plurality of participants participating in data sharing, and the data is transmitted between the trusted equipment and the sharing agent through the secure transmission channel. And the security, confidentiality and integrity protection of the shared data and the data protocol in the export process is realized.
Owner:HUAWEI TECH CO LTD

Method and device for post-quantum secure shared secret generation from zero trust

A method and system for generating a secure shared secret between a first device and a second device. The first / second device sends a public key and a public key certificate of the first / second device to the second / first device and receives a public key and a public key certificate of the second / first device from the second / first device, respectively. The first and second devices verify the public key certificate of the other device, respectively, and if the verification is successful, generate a ciphertext by encrypting its own secret with the public key of the other device, and send the ciphertext to the other device, respectively. The first and second devices decrypt the received ciphertext using its own private key and retrieve the secret of the other device. The first and second devices then generate a shared secret by combining its own secret with a secret of the other device.
Owner:INTEL CORP

Security authentication method, system and device for distributed network and medium

The invention discloses a security authentication method, system, device and medium for a distributed network, and the method comprises the steps: obtaining authentication communication data, and generating a device public key and a device private key in a trusted execution environment through employing a random number generator; performing certificate generation processing on the authentication communication data according to the equipment public key and the equipment private key to obtain a public key certificate; performing ciphertext generation processing on the authentication communication data according to the device private key to obtain an authentication ciphertext; and sending the public key certificate and the authentication ciphertext to at least one distributed connection device through a bus of a distributed network, so that the at least one distributed connection device performs device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result returned by the distributed connection device. According to the method, the security authentication efficiency of the distributed equipment can be effectively improved. The invention relates to the technical field of security authentication.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Vehicle charging method and device, computer device and storage medium

This application discloses a vehicle charging method, apparatus, computer equipment, and storage medium, relating to the field of vehicle technology, to address the security risks associated with the transmission of vehicle identification codes in plug-and-charge technology. The method is applicable to the target vehicle and includes: in response to receiving an authentication request from a charging pile, obtaining the original data required for authentication; if a public key certificate is stored locally, signing the original data using a private key to obtain a digital signature; generating first authentication data based on the public key certificate, digital signature, and original data; and transmitting the first authentication data transparently to the cloud via the charging pile, so that the cloud sends a charging start command to the charging pile after successful authentication.
Owner:CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD

Method of operating a public key certificate validation system for facilitating a secure communication between an aircraft and a ground entity

A method of operating a public key certificate validation system for facilitating a secure communication between an aircraft and a ground entity includes: sending a public key certificate of the ground entity from the ground entity to a trusted responder; at the trusted responder, validating the public key certificate of the ground entity and storing a trust indication regarding the public key certificate of the ground entity in a pre-cached validation database; and at the trusted responder, maintaining the pre-cached validation database for providing a validation response regarding the public key certificate of the ground entity, when a validation request, associated with the secure communication between the aircraft and the ground entity, reaches the trusted responder, wherein the validation response is based on the trust indication regarding the public key certificate of the ground entity from the pre-cached validation database.
Owner:ARINC INC

Verification method and device

The invention provides a verification method and device, and relates to the technical field of security, and the method comprises the steps: verifying a target object based on CMS data corresponding to the target object before the target object runs, and allowing the target object to run only when the verification is passed. The CMS data can comprise post-quantum digital signature information of the target object and corresponding post-quantum public key certificate information, and the post-quantum digital signature information comprises information obtained after the target object is signed by adopting a post-quantum public key algorithm and a post-quantum private key, related to the post-quantum public key algorithm, of the target object. And then, the quantum public key algorithm can resist quantum attacks, and a quantum computer cannot recover a post quantum private key through post quantum public key certificate information in the CMS data, so that post quantum digital signature information in the CMS data cannot be tampered, and tampering of a target object and a post quantum digital signature thereof is avoided. Therefore, unauthorized program codes or software can be prevented from being executed in the safe starting process.
Owner:HUAWEI TECH CO LTD

An industrial mainboard security booting method based on hardware root of trust

PendingCN122640112APathPingRandom seed
The application relates to the technical field of mainboards, in particular to an industrial mainboard security starting method based on a hardware root of trust, which comprises the following steps: after the industrial mainboard is powered on and reset, a security control domain runs prior to a business processing domain, and a main processor is kept waiting for starting; the security control domain reads hardware root anchor credentials and an initial boot program, and sequentially performs integrity measurement and signature verification on the initial boot program and a later-stage boot program; after the verification passes, running key materials are derived based on a random seed, device private credentials and a later-stage boot program digest, a running private key is written into a restricted key area, and a running public key is written into a public storage area; when a boot update package exists, a firmware public key certificate, a boot image signature and a replacement identifier are verified, a boot image is loaded after the certificate is valid and the signature passes, starting proof information is generated, an access path is closed and the main processor is released; any verification failure enters a fault processing flow.
Owner:深圳市兴研科技有限公司

Data security docking method and system, electronic equipment and storage medium

The invention relates to the technical field of computers, and discloses a data security docking method and system, electronic equipment and a storage medium, and the method comprises the following steps: generating an asymmetric key pair based on a national cryptographic algorithm, securely storing a private key in a trusted execution environment, submitting registration information, obtaining a digital certificate, chaining certificate metadata, and establishing a trusted digital identity; obtaining an authentication request identifier and a random number, and generating a composite report; performing equipment registration state verification, hardware trust chain verification and public key certificate consistency verification on the composite report, generating a structured authentication result after the verification is passed, and uploading the structured authentication result for evidence storage; querying an on-chain authentication state, encrypting data by using a data key, encrypting the data key by using a public key obtained from an authentication result, and transmitting the encrypted data; and using the private key to decrypt the data key in the trusted execution environment, and using the data key to decrypt and process the encrypted data. According to the method, the operation process can be simplified, the data leakage risk is eliminated, and a globally audible trust system is established.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Digital key management method and device

The invention provides a digital key management method and device, and the method comprises the steps: receiving a digital key activation request initiated by friend equipment after a target vehicle deletes a public key of vehicle owner equipment; obtaining a first public key certificate of the friend equipment according to the digital key activation request, and sending the first public key certificate to a cloud server; and receiving a signature verification result of the first public key certificate sent by the cloud server, and authorizing the friend equipment to be activated under the condition that the signature verification result has the activation permission. Under the situation that the public key of the vehicle owner equipment is deleted from the target vehicle, the cloud server uses the second public key certificate corresponding to the vehicle owner digital key to verify the first public key certificate of the friend equipment, so that only the legal and trusted friend equipment can initiate an activation request; and illegal equipment is effectively prevented from pretending friend equipment to obtain the digital key permission. And whether to authorize to activate the friend equipment is determined based on the signature verification result, so that refined authority management is realized.
Owner:XIAOMI EV TECH CO LTD

Digital key creation method, device, equipment and medium

This application proposes a method, device, equipment and medium for creating a digital key, which relates to the field of communication technology, wherein the method includes: receiving a terminal public key certificate sent by a target terminal; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet pairing private key; verifying the terminal public key certificate using the fleet pairing public key; when the signature verification is successful and the terminal public key is obtained, sending the vehicle public key certificate of the target vehicle to the target terminal; in response to receiving the signature verification success notification sent by the target terminal, determining that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created. As a result, there is no need to be constrained by the requirement that "the user needs to have other keys for the target vehicle", so that the user can apply for the use of the fleet vehicle conveniently and flexibly, thereby improving the user's vehicle pick-up efficiency and the user's vehicle experience.
Owner:XIAOMI EV TECH CO LTD

Distributed gateway identity cross-trust methods, systems, and related devices

The application relates to a distributed gateway identity mutual trust method, system and related equipment. The method comprises the following steps: a first gateway node sends a registration request containing a digital certificate and an agency code to a second gateway node; the second gateway node generates and returns a registration response containing a public key certificate and a security policy template in response to the registration request; the first gateway node verifies the validity of the public key certificate and audits whether the security policy template meets a preset security policy; if the audit is passed, the first gateway node signs a mutual trust protocol and sends the signed mutual trust protocol to the second gateway node; after verifying the validity of the signature, the second gateway node establishes and stores a trust record with the first gateway node, completes the trust establishment between the gateways, solves the technical problem that the cross-domain identity authentication scheme in the prior art generally depends on a unified identity authentication center and has a single-point failure risk, and achieves the technical effect of realizing safe and reliable cross-domain identity mutual trust.
Owner:BEIJING EETRUST TECH CO LTD

Two-way authentication key negotiation method and electricity consumption information collection system using the method

This invention belongs to the field of smart grid technology, specifically relating to a two-way authentication key negotiation method and an electricity consumption information collection system using this method. During the two-way authentication key negotiation process, both parties generate their own digital signatures, and include the digital signatures and timestamps in the generated authentication key negotiation request message, authentication key negotiation response message, or authentication key negotiation confirmation message. After each signature is successfully authenticated, both parties are considered to have authenticated each other's identities. This method applies a certificate-free authentication key negotiation protocol based on the elliptic curve discrete logarithm problem (without bilinear pairings) to a high-speed dual-mode communication system for electricity consumption information collection. This eliminates the necessity of traditional public key certificates in authentication key negotiation, avoiding the problems of high computational overhead, communication latency, storage space, and high power consumption caused by certificate management in the high-speed dual-mode communication system for electricity consumption information collection. Furthermore, the addition of timestamps to the messages helps resist replay attacks.
Owner:HENAN XJ INSTR +1

Energy storage wireless BMS data transmission method, device, equipment and storage medium

The present invention discloses a method, apparatus, device, and storage medium for transmitting data in an energy storage wireless BMS. The method comprises: receiving a transmission request initiated by a decryption party; verifying the public key certificate of the decryption party using a pre-set certificate; and, after verification, compressing and encrypting the original data to be transmitted using a chaotic mapping rule to obtain an encrypted data stream; inputting the encrypted data stream into a wireless signal encryption model, generating a carrier image in the wireless signal encryption model through adversarial training optimization of an encoder, embedding the carrier image into an environmental image, and generating a transmission image; and sending the transmission image to the decryption party. The present invention utilizes a dual security mechanism of chaotic mapping rules and wireless signal encryption models to achieve secure data transmission from battery cells to a monitoring system, thereby eliminating the risk of data interception in the energy storage wireless BMS communication system.
Owner:SHENZHEN SHENGLU IOT COMM TECH CO LTD +1

Methods and apparatus for a sixth generation (6G) roaming solution using protocol for n32 interconnect security (PRINS) with roaming intermediaries

Session management for a Fifth Generation (5G) roaming solution using PRotocol for N32 INterconnect Security (PRINS) with roaming intermediaries is described herein. A first network node establishes a transport layer security (TLS) connection with a second network node, wherein the TLS connection is established using hypertext transfer protocol secure (HTTPS) as a uniform resource identifier (URI). The first network node creates a security negotiation request message, including a fully qualified domain name (FQDN) of the second network node. The first network node protects information elements (IEs) in the security negotiation request message with a Javascript Object Notation (JSON) Web Signature (JWS) token, wherein the JWS token uses a digital signature and includes a public key certificate of the first network node. The first network node sends over TLS, to the second network node, an HTTPS request, including the security negotiation request message and the JWS token.
Owner:CABLE TELEVISION LAB INC

Browser authentication of server public key certificate (bas-pkc)

The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for determining, by a browser, data cipher by encrypting data using a first encryption key, the first encryption key is generated using a first random number, a second random number, and a third random number. The browser sends to a server, the data cipher. The browser determines a key cipher by encrypting the third random number using a certificate of the server. The browser sends to the server the key cipher.
Owner:WELLS FARGO BANK NA

Seamless authentication methods and systems for distributed devices

The present invention provides a method and system for seamless authentication of distributed devices. A first device and a second device establish a distributed connection via a distributed soft bus. The first device obtains a matching public key and private key, and based on the public and private key pairs, obtains corresponding public key certificates and authentication ciphertext. The second device performs authentication based on the public key certificate and authentication ciphertext, and returns the corresponding authentication result, thus completing the authentication. This ensures the security of the distributed device connection and improves data security. Furthermore, during the authentication process between the first and second devices, the first and second devices autonomously send and return authentication information via the distributed soft bus, without user intervention or input, simplifying the device authentication process, achieving seamless authentication of distributed devices, optimizing user experience, and improving device authentication efficiency.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Authentication interaction method, coding network card and virtual machine

The invention provides an authentication interaction method, a coding network card and a virtual machine. The method comprises the following steps: acquiring a handshake request sent by a target virtual machine, and responding to the handshake request; sending a digital certificate to the target virtual machine, wherein the digital certificate comprises at least one of a public key, a certificate issuer and a validity period; instructing the target virtual machine to verify the signature of the digital certificate according to the public key of the certificate issuer; and negotiating a temporary session key with the target virtual machine, and sending a handshake message to the target virtual machine through the session key so as to establish a connection with the target virtual machine through the handshake message. According to the authentication interaction method disclosed by the invention, the security authentication of the virtual machine on the coding network card can be realized, so that the security of outward transmission of the data of the virtual machine is ensured, and the full-process security protection of the data is further realized.
Owner:XIAN WANXIANG ELECTRONICS TECH CO LTD

Serial number generation for stateless cloud certificate authority

A system associated with a public key infrastructure certificate framework in a cloud computing environment may include a certificate authority data store that contains information about a plurality of certificate authority instances (with each certificate authority instance being associated with an instance index and an instance deployment time). A certificate authority server, coupled to the certificate authority data store, may retrieve an instance index and instance deployment time from the certificate authority data store. The certificate authority server may then determine a current certificate identifier generation timestamp. A unique certificate identifier for a public key certificate is generated by the certificate authority server based on a deterministic creation algorithm, the instance index, the instance deployment time, and the certificate identifier generation timestamp. The public key certificate can then be issued using the unique certificate identifier.
Owner:SAP SE

Blockchain-based dynamic updating of user credentials cross-domain authentication system and method

ActiveCN120498778BUser identity/authority verificationPoint registrationTransaction data
The application discloses a kind of user credential dynamic updating cross-domain authentication system and method based on blockchain, system includes user and terminal, and blockchain module, the blockchain module includes: block storage module, set multiple blocks, each block stores blockchain transaction data and version data;Intelligent contract registration verification module, according to user and terminal and registration node carry out single-point registration, while user and terminal and registration node and each blockchain node carry out multi-point authentication between each other.This scheme solves the problem that public key certificate is static and easy to be analyzed by enemy when traditional public key signature verification method is used for cross-domain authentication, the problem that public key certificate exposure surface is difficult to control caused by cross-domain authentication certificate circulation, the problem that certificate update process is complex, and the problem that single sign-on fails and single-point data is lost.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Computer target object verification method and device, storage medium and related apparatus

Embodiments of the present application provide a computer target object verification method, device, storage medium and related device. The computer target object verification method comprises: obtaining a public key signature, wherein the public key signature comprises a signature of a processor private key on a public key certificate, and the public key certificate comprises at least a computer public key; using a processor public key pre-configured in the processor to verify the public key signature; when the processor public key verifies the public key signature successfully, using the computer public key to verify a target signature, wherein the target signature is a signature of a computer private key on a target object; and when the computer public key verifies the target signature successfully, the target object is verified successfully. It can be seen that the computer target object verification method provided by the embodiments of the present application can be implemented by a computer while verifying the trusted root verification program or data in the processor.
Owner:HYGON INFORMATION TECH CO LTD

Method for establishing a secure communication between an aircraft and a ground entity

A method for establishing a secure communication between an aircraft and a ground entity includes: sending a communication initialization message from the aircraft to the ground entity, wherein the communication initialization message is included in an IP datagram structure and wherein the IP datagram structure comprises an IP address of the aircraft; at the ground entity, obtaining a public key certificate of the aircraft via the IP address of the aircraft; and sending a public key certificate of the ground entity from the ground entity to the aircraft as part of a response message to the communication initialization message.
Owner:ARINC INC

Processing device, method, and program

To provide a processing device, method, and program capable of improving the authenticity of information regarding the validity of a public key certificate.SOLUTION: A processing device having a normal environment and a secure environment includes a validity confirmation processing unit operating in the normal environment that accepts a request for revocation confirmation of a public key certificate, a validity management unit operating in the normal environment that outputs information regarding the validity of the public key certificate corresponding to the accepted revocation confirmation request, and an inspection unit operating in the secure environment that inspects the normality of the validity management unit.SELECTED DRAWING: Figure 1
Owner:NEC CORP

Method for establishing trust relationship of entity identity of alliance chain based on hierarchical identity-based cryptography

The application discloses a method for establishing an identity trust relationship of an alliance chain entity based on a hierarchical identity-based password, and comprises the following steps: S10, constructing public identity information of each entity in an alliance chain system according to a construction requirement of a hierarchical identity-based password on a hierarchical entity identity; S20, creating a private key generation mechanism of the hierarchical identity-based password system based on hierarchical relationships of all entities in the alliance chain system, extracting private keys of all mechanisms in the system, and delegating the private keys of all nodes, business terminals and users belonging to each mechanism according to the private keys of the mechanisms; S30, using the public identity information of each entity in the alliance chain system and the corresponding private keys to realize identity trust relationship establishment of each entity in the system, and providing required password services for business transactions based on the alliance chain. The application solves the management of the entity identity and the trust relationship in the alliance chain system based on the hierarchical identity-based password, avoids the use of public key certificates, and does not need to maintain a certificate chain to manage the identity trust relationship.
Owner:SHIJIAZHUANG TIEDAO UNIV

Computer-implemented method for creating signed certificates

The invention relates to a computer-implemented method for creating signed certificates (Zert2), the method comprising the steps of: - generating a first private key (Priv1), a first public key (Pub1) and a first certificate (Zert1), wherein the first certificate (Zert1) comprises the first public key (Pub1), information regarding the certificate owner (Inh) and a first validity period (T1, T2), - generating a second private key (Priv2), a second public key (Pub2) and a second certificate (Zert2), wherein the second certificate (Zert2) comprises the second public key (Pub2), the information regarding said certificate holder (Inh) and a second validity period (T3, T4), wherein the second validity period (T3, T4) starts after the first validity period (T1, T2) has started, wherein the validity periods of the first certificate (Zert1) and of the second certificate (Zert2) preferably overlap, - signing the second certificate (Zert2) with the first private key (Zert1).
Owner:RES IND SYST ENG RISE FORSCHUNGS ENTWICKLUNGS UND GROSSPROJEKTBERATUNG

Log auditing method and device based on identity key and service logic collaborative configuration, equipment and medium

The invention discloses a log auditing method and device based on identity key and business logic collaborative configuration, equipment and a medium. The method comprises the following steps: configuring an auditing strategy associated with a specific business operation node in business logic; in response to service logic execution to the specific service operation node, extracting and structuring a key service data field set from a current service execution context according to the auditing strategy, and generating a to-be-signed data packet; obtaining an identity private key of a current operation main body to perform digital signature operation on the to-be-signed data packet to generate a digital signature value; performing association packaging on the digital signature value, the to-be-signed data packet and a corresponding public key to generate a structured log record; and outputting the structured log record to a log stream, and providing a signature verification interface based on the public key certificate for auditing. The auditing efficiency and accuracy can be effectively improved, and the defect that log auditing lacks business context is overcome.
Owner:HENAN INFORMATIZATION GRP CO LTD