Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

41 results about "Public key certificate" patented technology

In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the ownership of a public key. The certificate includes information about the key, information about the identity of its owner (called the subject), and the digital signature of an entity that has verified the certificate's contents (called the issuer). If the signature is valid, and the software examining the certificate trusts the issuer, then it can use that key to communicate securely with the certificate's subject. In email encryption, code signing, and e-signature systems, a certificate's subject is typically a person or organization. However, in Transport Layer Security (TLS) a certificate's subject is typically a computer or other device, though TLS certificates may identify organizations or individuals in addition to their core role in identifying devices. TLS, sometimes called by its older name Secure Sockets Layer (SSL), is notable for being a part of HTTPS, a protocol for securely browsing the web.

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Tamper protection for the clock of a field tool

PendingDE102024122454A1Programme controlTime-division multiplexTamper resistancePublic key certificate
Method (100) for operating a field device (1) comprising an adjustable clock (2), at least one non-volatile CA memory (3) containing a public key certificate (3a) of a trusted certification authority, CA, at least one non-volatile time memory (4) for recording a date and / or time (4a) and at least one interface (5), comprising the steps: • A current date and / or time (7a) is received via the interface (5) (170); • this current date or time (7a) is compared with the date or time (4a) in the time memory (4) (180); and • In response to the fact that the current date or time (7a) is later (190) than the date or time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set to the current date or time (7a) (200).
Owner:VEGA GRIESHABER GMBH & CO

Vehicle charging method and device, computer device and storage medium

This application discloses a vehicle charging method, apparatus, computer equipment, and storage medium, relating to the field of vehicle technology, to address the security risks associated with the transmission of vehicle identification codes in plug-and-charge technology. The method is applicable to the target vehicle and includes: in response to receiving an authentication request from a charging pile, obtaining the original data required for authentication; if a public key certificate is stored locally, signing the original data using a private key to obtain a digital signature; generating first authentication data based on the public key certificate, digital signature, and original data; and transmitting the first authentication data transparently to the cloud via the charging pile, so that the cloud sends a charging start command to the charging pile after successful authentication.
Owner:CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD

Verification method and device

The invention provides a verification method and device, and relates to the technical field of security, and the method comprises the steps: verifying a target object based on CMS data corresponding to the target object before the target object runs, and allowing the target object to run only when the verification is passed. The CMS data can comprise post-quantum digital signature information of the target object and corresponding post-quantum public key certificate information, and the post-quantum digital signature information comprises information obtained after the target object is signed by adopting a post-quantum public key algorithm and a post-quantum private key, related to the post-quantum public key algorithm, of the target object. And then, the quantum public key algorithm can resist quantum attacks, and a quantum computer cannot recover a post quantum private key through post quantum public key certificate information in the CMS data, so that post quantum digital signature information in the CMS data cannot be tampered, and tampering of a target object and a post quantum digital signature thereof is avoided. Therefore, unauthorized program codes or software can be prevented from being executed in the safe starting process.
Owner:HUAWEI TECH CO LTD

An industrial mainboard security booting method based on hardware root of trust

PendingCN122640112APathPingRandom seed
The application relates to the technical field of mainboards, in particular to an industrial mainboard security starting method based on a hardware root of trust, which comprises the following steps: after the industrial mainboard is powered on and reset, a security control domain runs prior to a business processing domain, and a main processor is kept waiting for starting; the security control domain reads hardware root anchor credentials and an initial boot program, and sequentially performs integrity measurement and signature verification on the initial boot program and a later-stage boot program; after the verification passes, running key materials are derived based on a random seed, device private credentials and a later-stage boot program digest, a running private key is written into a restricted key area, and a running public key is written into a public storage area; when a boot update package exists, a firmware public key certificate, a boot image signature and a replacement identifier are verified, a boot image is loaded after the certificate is valid and the signature passes, starting proof information is generated, an access path is closed and the main processor is released; any verification failure enters a fault processing flow.
Owner:深圳市兴研科技有限公司

Data security docking method and system, electronic equipment and storage medium

The invention relates to the technical field of computers, and discloses a data security docking method and system, electronic equipment and a storage medium, and the method comprises the following steps: generating an asymmetric key pair based on a national cryptographic algorithm, securely storing a private key in a trusted execution environment, submitting registration information, obtaining a digital certificate, chaining certificate metadata, and establishing a trusted digital identity; obtaining an authentication request identifier and a random number, and generating a composite report; performing equipment registration state verification, hardware trust chain verification and public key certificate consistency verification on the composite report, generating a structured authentication result after the verification is passed, and uploading the structured authentication result for evidence storage; querying an on-chain authentication state, encrypting data by using a data key, encrypting the data key by using a public key obtained from an authentication result, and transmitting the encrypted data; and using the private key to decrypt the data key in the trusted execution environment, and using the data key to decrypt and process the encrypted data. According to the method, the operation process can be simplified, the data leakage risk is eliminated, and a globally audible trust system is established.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Distributed gateway identity cross-trust methods, systems, and related devices

ActiveCN121262018BUser identity/authority verificationEngineeringPublic key certificate
The application relates to a distributed gateway identity mutual trust method, system and related equipment. The method comprises the following steps: a first gateway node sends a registration request containing a digital certificate and an agency code to a second gateway node; the second gateway node generates and returns a registration response containing a public key certificate and a security policy template in response to the registration request; the first gateway node verifies the validity of the public key certificate and audits whether the security policy template meets a preset security policy; if the audit is passed, the first gateway node signs a mutual trust protocol and sends the signed mutual trust protocol to the second gateway node; after verifying the validity of the signature, the second gateway node establishes and stores a trust record with the first gateway node, completes the trust establishment between the gateways, solves the technical problem that the cross-domain identity authentication scheme in the prior art generally depends on a unified identity authentication center and has a single-point failure risk, and achieves the technical effect of realizing safe and reliable cross-domain identity mutual trust.
Owner:BEIJING EETRUST TECH CO LTD

Two-way authentication key negotiation method and electricity consumption information collection system using the method

This invention belongs to the field of smart grid technology, specifically relating to a two-way authentication key negotiation method and an electricity consumption information collection system using this method. During the two-way authentication key negotiation process, both parties generate their own digital signatures, and include the digital signatures and timestamps in the generated authentication key negotiation request message, authentication key negotiation response message, or authentication key negotiation confirmation message. After each signature is successfully authenticated, both parties are considered to have authenticated each other's identities. This method applies a certificate-free authentication key negotiation protocol based on the elliptic curve discrete logarithm problem (without bilinear pairings) to a high-speed dual-mode communication system for electricity consumption information collection. This eliminates the necessity of traditional public key certificates in authentication key negotiation, avoiding the problems of high computational overhead, communication latency, storage space, and high power consumption caused by certificate management in the high-speed dual-mode communication system for electricity consumption information collection. Furthermore, the addition of timestamps to the messages helps resist replay attacks.
Owner:HENAN XJ INSTR +1

Browser authentication of server public key certificate (bas-pkc)

The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for determining, by a browser, data cipher by encrypting data using a first encryption key, the first encryption key is generated using a first random number, a second random number, and a third random number. The browser sends to a server, the data cipher. The browser determines a key cipher by encrypting the third random number using a certificate of the server. The browser sends to the server the key cipher.
Owner:WELLS FARGO BANK NA

Seamless authentication methods and systems for distributed devices

The present invention provides a method and system for seamless authentication of distributed devices. A first device and a second device establish a distributed connection via a distributed soft bus. The first device obtains a matching public key and private key, and based on the public and private key pairs, obtains corresponding public key certificates and authentication ciphertext. The second device performs authentication based on the public key certificate and authentication ciphertext, and returns the corresponding authentication result, thus completing the authentication. This ensures the security of the distributed device connection and improves data security. Furthermore, during the authentication process between the first and second devices, the first and second devices autonomously send and return authentication information via the distributed soft bus, without user intervention or input, simplifying the device authentication process, achieving seamless authentication of distributed devices, optimizing user experience, and improving device authentication efficiency.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Serial number generation for stateless cloud certificate authority

A system associated with a public key infrastructure certificate framework in a cloud computing environment may include a certificate authority data store that contains information about a plurality of certificate authority instances (with each certificate authority instance being associated with an instance index and an instance deployment time). A certificate authority server, coupled to the certificate authority data store, may retrieve an instance index and instance deployment time from the certificate authority data store. The certificate authority server may then determine a current certificate identifier generation timestamp. A unique certificate identifier for a public key certificate is generated by the certificate authority server based on a deterministic creation algorithm, the instance index, the instance deployment time, and the certificate identifier generation timestamp. The public key certificate can then be issued using the unique certificate identifier.
Owner:SAP SE

Blockchain-based dynamic updating of user credentials cross-domain authentication system and method

ActiveCN120498778BUser identity/authority verificationPoint registrationTransaction data
The application discloses a kind of user credential dynamic updating cross-domain authentication system and method based on blockchain, system includes user and terminal, and blockchain module, the blockchain module includes: block storage module, set multiple blocks, each block stores blockchain transaction data and version data;Intelligent contract registration verification module, according to user and terminal and registration node carry out single-point registration, while user and terminal and registration node and each blockchain node carry out multi-point authentication between each other.This scheme solves the problem that public key certificate is static and easy to be analyzed by enemy when traditional public key signature verification method is used for cross-domain authentication, the problem that public key certificate exposure surface is difficult to control caused by cross-domain authentication certificate circulation, the problem that certificate update process is complex, and the problem that single sign-on fails and single-point data is lost.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Computer-implemented method for creating signed certificates

The invention relates to a computer-implemented method for creating signed certificates (Zert2), the method comprising the steps of: - generating a first private key (Priv1), a first public key (Pub1) and a first certificate (Zert1), wherein the first certificate (Zert1) comprises the first public key (Pub1), information regarding the certificate owner (Inh) and a first validity period (T1, T2), - generating a second private key (Priv2), a second public key (Pub2) and a second certificate (Zert2), wherein the second certificate (Zert2) comprises the second public key (Pub2), the information regarding said certificate holder (Inh) and a second validity period (T3, T4), wherein the second validity period (T3, T4) starts after the first validity period (T1, T2) has started, wherein the validity periods of the first certificate (Zert1) and of the second certificate (Zert2) preferably overlap, - signing the second certificate (Zert2) with the first private key (Zert1).
Owner:RES IND SYST ENG RISE FORSCHUNGS ENTWICKLUNGS UND GROSSPROJEKTBERATUNG

Communication systems, servers, and devices

We provide communication systems, servers, and devices that can suppress increases in processing load and communication data volume. [Solution] The communication system comprises a device and a server. The device comprises an authentication data generation unit that generates authentication data, and a first communication unit that transmits the authentication data to the server, receives an authentication result indicating that the authentication of the device was successful, transmits the public key of the device to the server if the authentication result is received, and receives a public key certificate. The server comprises a second communication unit that receives the authentication data and the public key, and transmits the authentication result and the public key certificate, an authentication processing unit that executes the authentication process based on the authentication data and generates the authentication result if the authentication of the device is successful, and a certificate generation unit that generates the public key certificate including the public key.
Owner:TOPPAN HOLDINGS INC

Near-field secure transmission method and system based on android environment

The invention discloses a near-field secure transmission method based on an android environment, and the method comprises the steps: a cloud end generates an equipment formal key pair and an equipment public key certificate according to equipment information transmitted by an equipment end, and transmits the equipment formal key pair and the equipment public key certificate to the equipment end; the cloud correspondingly generates a controller ID according to controller information and an equipment invitation code sent by the control end, finds an equipment official public key and an equipment public key certificate of corresponding equipment, sends the controller ID to the equipment end, and sends the controller ID, the equipment official public key and the equipment public key certificate to the control end; finally, the control end and the equipment end are bound at the cloud end and the equipment end in the mode that the controller ID is inserted into an equipment official public key permission sequence; the equipment end performs permission matching according to the controller ID sent by the control end, generates a corresponding random symmetric key after successful matching, and sends the random symmetric key to the control end; and the control end and the equipment end carry out near field communication interaction in a manner of encrypting and decrypting interaction data through the symmetric key. According to the invention, secure data transmission between near-field devices is realized.
Owner:SHENZHEN LANYOU TECHNOLOGY CO LTD

Product management system

To provide a product management system, a product device, a product management method, and a non-transitory computer readable medium capable of verifying authenticity of the product device in a supply chain.SOLUTION: The product management system includes an issuing unit, an authentication unit, a data registration unit, and an output unit. When receiving a certificate issuance request from the product device, the issuance unit generates a public key certificate including a public key, a U (Unique) ID of the product device, and a signature of a certificate authority, and stores a secret key in a hardware security module (HSM) of the product device. When receiving an authentication request from the product equipment, the authentication unit verifies the public key certificate, and verifies whether or not the authentication data is signed with the private key by using the public key in the public key certificate. When a use start request is received from the successfully authenticated product device, the output part reads the product history data registered in association with the UID included in the public key certificate of the product device from the storage, and outputs output information related to the product history data.SELECTED DRAWING: Figure 1
Owner:NEC CORP

System upgrading method, encryption method of upgrading package, electronic device and storage medium

PendingCN122293351ANot easy to tamper withcomplete structureCiphertextPublic key certificate
This application provides a system upgrade method, an upgrade package encryption method, an electronic device, and a storage medium. The system upgrade method includes: decrypting an encrypted upgrade package using an upgrade package key to obtain a signed upgrade package; splitting the signed upgrade package to obtain a plaintext upgrade package and descriptive information of the plaintext upgrade package, the descriptive information including a digest signature and a public key certificate; calculating a second digest value of the plaintext upgrade package; verifying the legitimacy of the plaintext upgrade package based on the second digest value, the digest signature, and the public key certificate; and, in response to the legitimacy of the plaintext upgrade package, performing a system upgrade based on the plaintext upgrade package.
Owner:SHANGHAI PATEO ELECTRONIC EQUIPMENT MANUFACTURING CO LTD

Distributed gateway identity mutual trust method and system and related equipment

ActiveCN121262018AUser identity/authority verificationEngineeringPublic key certificate
The invention relates to a distributed gateway identity mutual trust method, a distributed gateway identity mutual trust system and related equipment. The method comprises the following steps: sending a registration request containing a digital certificate and an institution code to a second gateway node through a first gateway node; the second gateway node generates and returns a registration response containing the public key certificate and the security policy template in response to the registration request; the first gateway node verifies the validity of the public key certificate and checks whether the security policy template conforms to a preset security policy; if the verification is passed, the first gateway node signs the mutual trust protocol and sends the signed mutual trust protocol to the second gateway node; after the second gateway node verifies the validity of the signature, a trust record with the first gateway node is established and stored, and trust establishment between gateways is completed, so that the technical problem that a cross-domain identity authentication scheme generally depends on a unified identity authentication center and has a single-point fault risk in the prior art is solved; the technical effect of safe and reliable cross-domain identity mutual trust is achieved.
Owner:BEIJING EETRUST TECH CO LTD

Data processing method and related device

The invention provides a data processing method and a related device. The embodiment of the invention can be applied to various scenes such as the technical field of network security. According to the embodiment of the invention, a front end receives a behavior request instruction of a user, obtains a public key voucher stored in the front end, generates a target request instruction with signature information according to the public key voucher and behavior information, and sends the target request instruction with the signature information to a server; and after receiving a target request instruction with the signature information, the server verifies the signature information according to a private key voucher of the server, and the server makes a response and sends feedback information generated by the response to the front end under the condition that the signature information is valid. According to the data processing method provided by the embodiment of the invention, the legality and security of the request are ensured, and the risk that user information is stolen is effectively reduced; a third party can be prevented from using pirated websites to carry out hostile attacks, and normal operation and reputation of genuine websites are guaranteed.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

A client information system and intelligent meter secure interaction method, medium and terminal

The application is suitable for the field of information security technology, and relates to a customer information system and a smart meter security interaction method, medium and terminal. The application has simple process and convenient operation. Through end-to-end technical security measures, encryption and decryption and signature verification are performed on the data transmitted between the customer information system of the source endpoint and the smart meter of the destination endpoint. The intermediate systems cannot decrypt, and do not need to decrypt and verify the signature without the key and the public key certificate. The uppermost layers of the two are application layer end-to-end APDU (application layer protocol data unit). The security of the information is not affected by the number and reliability of the intermediate systems. The application solves the problems that the privacy is easily leaked and the anti-attack strength is insufficient due to multiple encryption and decryption and signature verification in the communication process of the customer information system and the smart meter, and effectively improves the data security and the anti-attack property.
Owner:WASION GROUP HLDG

Method and device for upgrading in-vehicle equipment

ActiveCN119968616BSoftware deploymentIn vehiclePublic key certificate
The application discloses an upgrading method and device of a vehicle-mounted device, and relates to the field of information and communication technologies. The method comprises the following steps: receiving first signature information and first public key information from an electronic device, and sending an upgrading package to the electronic device in the case that the first signature information and the first public key information are verified successfully. The first signature information is obtained by signing a first upgrading request with a private key of the electronic device, the first upgrading request is used for requesting an upgrading package of at least one vehicle-mounted device, the first public key information is used for verifying the identity of the electronic device, and the first public key information comprises a public key certificate of a public key of the electronic device or the first public key information comprises the public key of the electronic device. In this way, the received information can be verified whether it is tampered with through the first signature information, the identity of the electronic device can be verified through the first public key information, and the security of the upgrading of the vehicle-mounted device is ensured.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Distributed identity opening method and device

The embodiment of the invention discloses a distributed identity opening method and device, electronic equipment and a computer readable medium, and the method comprises the steps: responding to the completion of the installation of a distributed identity application program in a security chip, and transmitting an installation result of the distributed identity application program to a wallet application, sending a verifiable certificate acquisition request to the issuing mechanism by the wallet application; acquiring a distributed identity opening instruction containing a verifiable certificate sent by the wallet application, and generating a user distributed identity private key, a user distributed identity public key and a user distributed identity public key certificate; and obtaining a user distributed identity identifier from the verifiable certificate, and sending the user distributed identity identifier and a user distributed identity public key certificate to the wallet application, so that the wallet application sends a user distributed identity identifier document and the verifiable certificate to a distributed identity chain for associative storage. The operation that the user submits the identity information for the second time is reduced, the user experience is improved, and the identity opening efficiency is high.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Key migration method, cryptographic module and live migration method thereof, and related equipment

The embodiment of the invention provides a key migration method, a cryptographic module and a live migration method thereof, and related equipment, the key migration method is applied to a target cryptographic module coupled to a key mirror image import interface, and the key mirror image import interface is an interface which is preset by a target physical host and is only used for transmitting a key mirror image ciphertext. Comprising the following steps: sending a public key certificate and first cryptographic protocol information when a cryptographic module is thermally migrated; receiving a key mirror image ciphertext and second cryptographic protocol information based on the key mirror image import interface, the second cryptographic protocol information being generated by the source cryptographic module; and generating a decryption key for decrypting the key mirror image ciphertext according to the second cryptographic protocol information to obtain a key mirror image, and after the integrity of the key mirror image is verified, outputting an import result, thereby realizing the thermal migration of the cryptographic module.
Owner:HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD

Tamper protection for the clock of a field device

PCT designated stageWO2026032895A1Programme controlUser identity/authority verificationTrust certificatePublic key certificate
The invention relates to a method (100) for operating a field device (1), which has an adjustable clock (2), at least one non-volatile CA memory (3) having a public key certificate (3a) from a trusted certificate authority, CA, at least one non-volatile time memory (4) for storing a date and / or a time (4a), and at least one interface (5), the method comprising the following steps: - a current date and / or a current time (7a) is received (170) via the interface (5); - said current date or said current time (7a) is compared (180) with the date or the time (4a) in the time memory (4); and - in response to the current date or the current time (7a) being later (190) than the date or the time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set (200) to the current date or to the current time (7a).
Owner:VEGA GRIESHABER GMBH & CO

Construction method of tight reduction password scheme based on identity equality test

The equality test is a special technology in a public key cryptographic mechanism, and can judge whether two ciphertexts encrypt the same plaintext or not under the condition of not decrypting. The technology is widely applied to a cloud computing environment after being put forward, such as spam filtering, encrypted database retrieval and the like. Wherein the identity-based equality test further reduces the burden of public key certificate management. The invention provides a specific compact-reduction structure based on an identity equality test scheme and a standard determinative bilinear Diffie-Hellman (short for DBDH) problem, and realizes the purpose that the method can be applied to different identities, specific ciphertexts, specific ciphertexts and identities under the condition that plaintexts are not revealed. And a fine-grained ciphertext equality test between a particular ciphertext and a particular comparator.
Owner:QUFU NORMAL UNIV

Authentication service and certificate exchange protocol in wireless ad hoc networks

ActiveUS12719849B2Data setIp address
A method for protecting data transmission in an ad hoc network including nodes, each node including a private key, a public key and a certificate of the public key signed by a certification authority, the method including transmitting by the first node to the second node: a first message signed with the private key of the first node; a third message containing a first set of initialization data including: a first certificate including the public key of the first node, signed by the certification authority; a second data set including the IP address of the first node; and the first certificate associated with the IP address of the first node, wherein the second data set is signed with the private key of the first node.
Owner:AIRBUS DEFENCE & SPACE SAS

Method and system for implementing a privacy preserving, face-based protected public key infrastructure

A computer-implemented method of issuing a public key certificate in a public key infrastructure is provided. The public key infrastructure comprises a user device, a trusted server comprising a public key registry, and a third-party device operated by a third party. The method includes the steps: the user device obtaining biometric data comprising a facial image of the user; the user device or the trusted server generating a privacy preserving data structure using the biometric data; the user device receiving a purpose ID from the third-party device; the user device obtaining subsequently acquired biometric data comprising the facial image of the user; the user device or the trusted server generating a public key from the privacy preserving data structure using the subsequently acquired biometric data and the purpose ID, wherein a private key corresponding to the public key can be generated from the privacy preserving data structure using the purpose ID and further subsequently acquired biometric data comprising the facial image of the user; and the trusted server obtaining a public key certificate from an issuer, the public key certificate comprising the public key and a digital signature of the issuer, and the trusted server storing the public key certificate in the public key registry.
Owner:SEVENTH SENSE ARTIFICIAL INTELLIGENCE PTE LTD +1

Data access method and related equipment

The invention provides a data access method and related equipment, which are applied to the technical field of information security, and the method comprises the following steps: when an encryption application is in an unlocked state, sending a link application to a server based on a first application; when the server verifies the first certificate chain and the first protocol parameter and the verification is passed, receiving a server public key certificate sent by the server; verifying the server public key certificate based on the encryption application, and sending a first ciphertext to the server after the verification is passed; receiving a second session key sent by the server; and performing data access on the server based on the second session key and the first application. In the method, under the condition of realizing data isolation between the dual systems, the risk of remote management in the prior art can also be avoided, so that the security risk of data access of the dual-system terminal can be reduced.
Owner:CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1

A device public key certificate acquisition method and a communication apparatus

The application provides a device public key certificate acquisition method and a communication device. In the method, a device receives a first message from a first access device, the first message being used for requesting a public key certificate of the first access device; a second message is sent to a wireless network, the second message being used for notifying the wireless network that a service set identifier serves the first access device; a third message is received from the first access device, the third message being used for indicating the public key certificate of the first access device; and the public key certificate of the first access device is acquired according to the third message. In this way, the public key certificate of the access device can be acquired online, which can reduce security risks and improve the acquisition efficiency of the public key certificate compared with the code scanning method.
Owner:RUIJIE NETWORKS CO LTD

A terminal device management and control method based on a public key certificate

The present application relates to the technical field of terminal equipment management and control, in particular to a terminal equipment management and control method based on public key certificate, the present application unifies a security model, is based on domestic and foreign general technical standards of security industry, is irrelevant with business rules, and the system is more efficient, unauthorized terminal equipment is rejected in the network protocol kernel level service, in addition, the safety factor is higher, and terminal management and control platform equipment certificate acquisition needs to pass the only path of self-research trusted authentication SDK of the office, and trusted authentication SDK acquisition needs to go through the relevant authorization approval process. The security protection of the kernel level can effectively prevent system infection risk, and finally supports domestic signal creation, which is based on large number decomposition inverse module operation or elliptic curve encryption algorithm, and the present application is not limited, and the signal creation environment can be flexibly selected and customized according to actual business requirements.
Owner:FUJIAN STRAIT CORNERSTONE TECH GRP CO LTD