Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

150 results about "Root certificate" patented technology

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed and form the basis of an X.509-based public key infrastructure (PKI). Either it has matched Authority Key Identifier with Subject Key Identifier, in some cases there is no Authority Key identifier, then Issuer string should match with Subject string (RFC5280). For instance, the PKIs supporting HTTPS for secure web browsing and electronic signature schemes depend on a set of root certificates.

Bidirectional authentication security mobile communication method and system based on public key digital fingerprint

The invention discloses a bidirectional authentication secure mobile communication method and system based on a public key digital fingerprint, and belongs to the technical field of communication security. The method specifically comprises the following steps: S1, digital certificate application and issuing: a mobile terminal and a service server respectively use an encryption algorithm to generate an asymmetric key pair which comprises a public key and a private key, an entity submits a CSR file which comprises a public key, entity identity information and an extension field to a CA, and the CA strictly audits the entity identity and issues a digital certificate; and performing digital signature on the public key and the entity information by using a CA private key after the auditing is passed. Two-way identity authentication is achieved, communication safety is improved, a traditional scheme only supports one-way authentication of a client to a server and is prone to phishing attack and identity false use, digital certificates are exchanged before communication between a mobile terminal and a service server, the legality of the certificates is verified through a public key of a CA root certificate, and the authenticity of the identities of the two parties is ensured. A bidirectional authentication mechanism effectively prevents man-in-the-middle attack and identity counterfeiting problems, and the security risk is greatly reduced.
Owner:HAINAN SOFTWARE VOCATIONAL & TECH COLLEGE

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Industrial Internet of Things equipment data encryption transmission method based on edge computing

The invention discloses an edge computing-based industrial Internet of Things equipment data encryption transmission method, which comprises the following steps of: constructing an edge node alliance comprising at least two cross-regional edge gateways, completing bidirectional identity authentication through an alliance root certificate, and establishing an encrypted communication link; industrial equipment collects original data and then transmits the original data to an edge gateway which the industrial equipment belongs to, and the gateway extracts data features and divides the data features into a core control level, a process parameter level, a common monitoring level and a security level; differential encryption strategies are adopted for different levels of data; each edge gateway uploads the encrypted data to a distributed key management node, and obtains and synchronizes a periodically updated key chain; during cross-region transmission, performing secondary packaging and encryption to generate a data packet containing identifications such as a security level and the like; and the receiving end verifies the legality of the node, decrypts and verifies the integrity of the data, distributes the data if the decryption is passed, and blocks the alarm if the decryption The method is suitable for scenes such as single-area monitoring and multi-area manufacturing, data security and transmission efficiency balance are achieved, and all-weather stable transmission is guaranteed.
Owner:HEFEI UNIV OF ECONOMICS

Virtual microcontroller for device authentication in a confidential computing environment

Embodiments are directed to a virtual microcontroller for device authentication in a confidential computing environment. An embodiment includes a processor to implement a service trust domain (TD) as a virtual microcontroller (VMC) trust domain (VMC-TD) for a device, where the VMC-TD is to support protocols for device authentication, device measurement, and device management; and receive a VMC certificate chain that is endorsed by a startup service component comprising at least one of a trusted module of the confidential computing environment, the VMC certificate chain comprising a root certificate of the startup service component, a startup services module signing certificate, and a full VMC certificate comprising the initial VMC certificate and a TD report comprising a measurement of the device.
Owner:INTEL CORP

Data processing method and related equipment

The data processing method comprises the following steps: a second client extracts a public key of a second user from an identity certificate of the second user, performs hierarchical encryption on data by using the public key of the second user to obtain a ciphertext, and stores the ciphertext and the identity certificate of the second user in a block chain network; and the first client obtains the ciphertext and the identity certificate of the second user from the block chain network, and verifies the legality of the identity certificate of the second user by using the root certificate. And when the verification is passed, the first client extracts the first derived information from the identity certificate of the first user and extracts the second derived information from the identity certificate of the second user. Wherein the derivation information indicates a derivation path of the identity certificate. And the first client determines a private key of the second user according to the derived information and the private key of the first user, and decrypts the ciphertext according to the private key of the second user to obtain data. According to the method, an authentication mechanism of an identity certificate is used for carrying out identity authentication on a public key, the identity trust problem is solved, and the visibility of data divided according to levels is realized.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Cluster self-discovery method suitable for cloud server cipher machine

The invention relates to the technical field of information security, in particular to a cluster self-discovery method suitable for a cloud server cipher machine, which comprises the following steps: when physical equipment of the cloud server cipher machine leaves a factory, a certificate management module generates an equipment certificate and a root CA certificate in combination with an enterprise CA system, and stores the equipment certificate and the root CA certificate; after the virtual cipher machine is created and started, the key management service module combines with the certificate management module to generate a virtual machine certificate, and stores the virtual machine certificate, the storage device certificate and the root CA certificate together; the cluster management service module enables the master node of the virtual cipher machine to discover the slave node of the virtual cipher machine in the same network domain through UDP broadcast, and executes three-level verification on the slave node of the virtual cipher machine from three aspects of an equipment certificate, a virtual machine certificate and an authentication signature; and the virtual cipher machine master node synchronizes the cluster master key to the virtual cipher machine slave node passing verification. According to the invention, hierarchical identity isolation and verification of the cloud server cipher machine host and the virtual cipher machine can be realized, and the security of cluster self-discovery and authentication stages is ensured.
Owner:山东三未信安信息科技有限公司

Document printing and traceability tracking system based on block chain

The invention relates to the technical field of block chain data storage and traceability tracking, in particular to a document printing and traceability tracking system based on a block chain. Comprising an off-line certificate generation unit used for generating an off-line cryptographic certificate based on technical parameters analyzed from an external printing request; the dynamic anchoring control unit is used for monitoring system state parameters and carrying out dynamic anchoring strategy calculation based on the system state parameters so as to generate an anchoring triggering decision; the aggregation anchoring unit is used for responding to the anchoring triggering decision, aggregating a plurality of offline cryptographic certificates to generate an aggregation root certificate, and broadcasting a block chain transaction containing the aggregation root certificate; and the verification traceability unit is used for acquiring the aggregation root certification on the block chain and executing cryptographic verification in combination with the offline data to obtain a final verification result. According to the invention, the core pain point that the system is unavailable due to the performance bottleneck of the block chain in a high-concurrency scene in the prior art is solved, and the continuity and reliability of services are ensured.
Owner:北京微点科学技术有限公司

Secure Onboarding of a Component in a Network

A method for providing a secure onboarding of a component from at least one first host device into a second host device includes verifying the integrity, authenticity and / or execution environment of the first host device by an orchestrator; providing a trusted root certificate to the second host device by the orchestrator; providing an onboarding identity by the orchestrator to the first host device, when the integrity, the authenticity and / or the execution environment of the first host device has been verified; receiving the onboarding identity from the orchestrator by the first host device and assigning the onboarding identity to the component; providing the assigned onboarding identity to the second host device; and securely onboarding the component from the first host device into the second host device based on the assigned onboarding identity and the provided trusted root certificate.
Owner:ABB (SCHWEIZ) AG

SIP (Session Initiation Protocol) authentication method based on post-quantum and national secret hybrid signature algorithm

The invention provides an SIP (Session Initiation Protocol) authentication method based on a post quantum and national secret mixed signature algorithm, which is applied to an SIP client, and comprises the following steps: sending a first registration message to an SIP server, the first registration message comprising a target authentication control parameter, so that the SIP server generates a first reply message according to the target authentication control parameter; receiving a first reply message; obtaining a first mixed signature certificate of the SIP client according to the first reply message, generating a first random number, and performing mixed signature on the first random number to generate a first signature value; sending a second registration message to the SIP server, so that the SIP server verifies the first mixed signature certificate by adopting a pre-stored root certificate of the SIP client, and verifies the first signature value; and receiving second reply information, and indicating whether the SIP client is successfully verified or not. By integrating a post-quantum algorithm, SIP authentication has the characteristic of quantum attack resistance.
Owner:中电信量子信息科技集团有限公司

Systems and methods for streamlined platform component attestation

Systems and methods for streamlined platform attestation are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor. The memory may have program instructions stored thereon that, upon execution, cause the IHS to: read root certificates for a plurality of components of the IHS; and embed the root certificates for the plurality of components into a platform certificate.
Owner:DELL PROD LP

Equipment verification method and electronic equipment

The invention discloses a device verification method and an electronic device, and relates to the technical field of device verification, and the device verification method comprises the steps: responding to a condition that an authentication structure file signature accords with a protocol specification requirement of an authentication platform, carrying out the analysis of an authentication structure, and obtaining a terminal entity certificate, an encrypted device private key and a target verification code; verifying the encrypted device private key based on the unique identifier of the target device; in response to verification passing, decrypting the encrypted device private key to obtain a plaintext device private key; verifying the digital signature of the terminal entity certificate by using the authentication platform root certificate public key; in response to verification passing, generating a random number; obtaining a signature result of the response data packet; and if the authentication platform root certificate public key of the terminal entity certificate verifies the signature result successfully, determining that the target equipment passes the verification. The technical problem that an attacker simulates legal verification response and forges verification pass in the related technology is solved, and the technical effect of improving the equipment verification reliability is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Authentication method and apparatus, and communication device and storage medium

Provided in the embodiments of the present disclosure is an authentication method. The method is executed by a first root certificate authority (CA), and comprises: generating a first type of certificate on the basis of a transport layer security (TLS) protocol, wherein the first type of certificate is a certificate of an entity in a first security domain where the first root CA is located.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Network access control method, apparatus and device, and storage medium

Embodiments of the present disclosure relate to a network access control method, apparatus and device, and a storage medium. The network access control method includes: receiving a certificate verification request sent by a terminal, and returning a certificate verification response to the terminal, wherein the certificate verification response carries a preset server certificate, the certificate verification response is used for instructing the terminal to verify the preset server certificate based on a root certificate installed in the terminal, and identity verification information of the root certificate is partially or fully different from identity verification information of the preset server certificate; and receiving a verification result returned by the terminal for the preset server certificate, and in a case where the verification result indicates that certificate verification succeeds, determining that the terminal has a security risk and interrupting a network access communication link of the terminal. In the embodiments of the present disclosure, when the terminal successfully verifies the preset server certificate, the terminal may be prevented from accessing a network by interrupting the network access communication link with the terminal, thereby improving the security of the network.
Owner:DOUYIN VISION CO LTD

DDS Security certificate secure creation and deployment method

The invention discloses a DDS Security certificate secure creation and deployment method, which comprises the following steps of: initializing a certificate management service (CMS), establishing a secure channel with a trusted execution environment (TEE), and loading a preset DDS identity CA root certificate from the TEE; an application package manager APM analyzes the application configuration information, carries an application identity ID, and initiates a certificate creation request to a CMS; the CMS constructs certificate information, and sends a certificate creation request carrying the certificate information and an application identity (ID) to the trusted execution environment; public and private keys are generated in the TEE, a certificate is created and signed, and the created application identity certificate is returned to the CMS; the certificate management service verifies and stores the certificate, and returns an identity certificate and a CA root certificate to the APM; and the APM installs the identity certificate to a specified folder of the application installation directory. According to the invention, the establishment and deployment of the identity certificate are realized based on the CMS and the TEE, the certificate management process is simplified, and the deployment efficiency is improved.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Cloud service authentication method and cloud service system

The invention provides a cloud service authentication method and a cloud service system, the method is applied to the cloud service system, and the cloud service system comprises at least one trust anchor and a plurality of application configurations; the method comprises the steps that a request of a first user for obtaining a temporary certificate is received, the request comprises a client certificate of the first user and information of a first role requested by the first user, and the client certificate of the first user comprises a subject identifier of the first user; determining that the first user accesses the cloud service system according to the client certificate of the first user and the root certificate in the first trust anchor; according to the main body identifier of the first user, determining the permission of the first user to obtain the first application configuration; acquiring the permission of the first user to use the first role in the first application configuration; acquiring a temporary voucher; and sending the temporary credential to the first user. According to the embodiment of the invention, the risk that illegal applications invade cloud resources can be reduced.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Ca consensus method, apparatus, and node

Provided are a CA consensus method, an apparatus, and a node. The method comprises: obtaining a final voting result for a voting event on the basis of voting results of a plurality of first CAs; and when the final voting result indicates that the voting event passes, executing a first operation, wherein the first operation comprises registration of a CA, revocation of a CA, or update of a root certificate. In this way, a decision can be jointly made by a plurality of CAs without relying on a central CA, thereby improving the degree of decentralization of DPKI systems, and thus improving the overall security of the DPKI systems.
Owner:HUAWEI TECH CO LTD

Data processing method and device, electronic equipment and storage medium

The embodiment of the invention discloses a data processing method and device, electronic equipment and a storage medium. According to the embodiment of the invention, a code package pulling request can be sent; obtaining a returned code packet and a digital signature, wherein the digital signature is obtained by encrypting a message digest of the code packet by a private key of the root certificate; generating a new message abstract of the code package, and decrypting the digital signature by adopting a public key of the root certificate to obtain decrypted data; and if the new message digest of the code package is the same as the decrypted data, loading the code package. In the embodiment of the invention, the public key of the root certificate is set at the client, and the private key of the root certificate is set at the server, so that the authenticity and integrity of the code packet can be verified before loading according to the digital signature encrypted based on the private key and returned by the server when the client requests the code packet from the server. Therefore, according to the scheme, the security of the data processing method can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

K8s root certificate change method and device, electronic equipment and storage medium

The invention provides a k8s root certificate change method and device, electronic equipment and a storage medium, and the method comprises the steps: combining an original root certificate with a target root certificate to obtain a combined root certificate, and gradually replacing the root certificate of each component with the combined root certificate according to a first preset replacement sequence and a second preset replacement sequence, according to the method, each component has the original root certificate and the target root certificate at the same time, so that each component can be normally accessed by using the request of the original root certificate and the request of the updated target root certificate, the normal operation of the service in the updating process is ensured, then the original root certificate in the root certificates of each component is removed, and the component is restarted; and automatic updating of the root certificate of each component in k8s is realized.
Owner:DUXIAOMAN TECH (BEIJING) CO LTD

Trusted computing remote attestation method and device, computer device and storage medium

The application relates to a trusted computing remote attestation method and device, computer equipment and a storage medium. The method comprises the following steps: obtaining random verification information, generating a remote attestation request according to the random verification information; outputting the remote attestation request to a party to be checked, receiving signature random information and a signature digital certificate fed back by the party to be checked, the party to be checked being a trusted computing execution party, the signature digital certificate being generated by signing a trusted digital certificate by the party to be checked, and the trusted digital certificate being issued to the party to be checked by a trusted agency; obtaining trusted attestation information of the party to be checked and a root certificate of the trusted agency from a preset block chain; when the signature digital certificate is verified to be correct according to the root certificate and the trusted attestation information, the signature random information is verified according to the signature digital certificate and the random verification information; and when the signature random information is verified to be correct, it is determined that the remote attestation is passed. The method can improve verification security and realize accurate verification.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Hierarchical certificate issuing system, method, device and equipment

The invention provides a hierarchical certificate issuing system, method, device and equipment, and the system comprises root CA equipment, strategy CA equipment and certificate issuing CA equipment: the root CA equipment is used for generating a self-signature root CA certificate based on a root CA key pair, and carrying out the signature of a strategy CA certificate signature request of the strategy CA equipment through employing a root CA private key, and obtaining the strategy CA certificate; the policy CA equipment is used for acquiring a policy CA certificate from the root CA equipment and signing a certificate issuing CA certificate signature request of the certificate issuing CA equipment by adopting a policy CA private key to obtain the certificate issuing CA certificate; the certificate issuing CA equipment is used for acquiring a certificate issuing CA certificate from the policy CA equipment and signing a terminal certificate signature request of the terminal equipment by adopting a certificate issuing CA private key to obtain a terminal entity certificate; and the certificate issuing CA equipment is also used for sending a certificate chain to the terminal equipment, and the certificate chain comprises a self-signature root CA certificate, a policy CA certificate, a certificate issuing CA certificate and a terminal entity certificate.
Owner:BEIJING CHUANGRUI HONGKE TECHNOLOGY CO LTD

Managing startup of a data processing system using trust stores

Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, an entity may obtain, using a security protocol and data model (SDPM) security standard, at least a first device certificate of a certificate chain for a device. Using the at least the first device certificate and a store of trusted device certificates, the entity may perform a first analysis process to determine a level of trust in the device. If the level of trust is indeterminate, the entity may use the certificate chain and a store of trusted root certificates to perform a second analysis process to determine the level of trust in the device. Operation of the data processing system may be managed based on the level of trust in the device.
Owner:DELL PROD LP

Transaction data verification method and device, computer readable medium and electronic equipment

The embodiment of the invention provides a transaction data verification method and device, a computer readable medium and electronic equipment, the method is executed by a target alliance chain node in an alliance chain network, the alliance chain network comprises a plurality of authorized alliance chain nodes, and the alliance chain nodes are used for verifying and executing a transaction. The method comprises: receiving a transaction request carrying transaction data from a client, the transaction data comprising a certificate index corresponding to a digital certificate of a requester of the transaction request, and the certificate index being used for uniquely identifying the digital certificate; obtaining a digital certificate corresponding to a certificate index in the transaction data from a certificate management center, wherein the certificate management center is used for correspondingly storing the certificate index and the digital certificate; and performing validity check on the digital certificate at least according to a pre-acquired root certificate so as to verify the transaction data. According to the embodiment of the invention, the utilization rate of the on-chain storage space can be improved, and the waste of the on-chain storage space is reduced.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Digital certificate verification methods, devices, equipment, systems, and readable storage media

This application discloses a method, apparatus, device, system, and readable storage medium for verifying digital certificates, belonging to the field of information and communication technology. The method includes: a second device sending a first certificate set to a first device, wherein the first certificate set is at least one of the certificate sets corresponding to each of at least two root certificates stored by the second device. The dormancy period of the target root certificate whose validity period is not the latest is covered by the working period of a backup secondary CA certificate signed by the target root certificate and the working periods of other secondary CA certificates. The first device verifies the legitimacy of at least one digital certificate of the second device based on the root certificates stored and trusted by the first device and the received first certificate set. In this application, the first device can verify the legitimacy of the digital certificate of the second device using the root certificates trusted by the first device. The first device does not need to upload other certificates, increase the number of certificate verification levels, or support new cryptographic algorithms, thus having a wide range of applications.
Owner:HUAWEI TECH CO LTD

Real estate registration method and system based on block chain

The invention relates to the technical field of real estate registration, and discloses a real estate registration method and system based on a blockchain, and the system comprises a data collection module, a data encryption module, a blockchain storage module, and an information verification module.In the aspect of data security, public key encryption and private key decryption mechanisms effectively guarantee data privacy and security, and the data security is improved. Stealing and tampering are prevented; in terms of data integrity, block hash values are compared through an information verification module, whether transmission data are changed or not is accurately judged, and completeness and reliability of the transmission data are ensured; the identity verification checks the signature validity by means of a digital certificate and a root certificate, constructs a security trust system, and prevents illegal operation; the multi-node alliance reduces the single-point fault risk, and the data change history can be checked to facilitate audit supervision; on the whole, the transparency, the fairness and the credibility of real estate registration are improved, the registration process is optimized, the processing capacity and the response speed are improved, the pain point of a traditional mode is solved, and efficient and healthy development of real estate registration business is promoted.
Owner:临沂润恒信息科技有限公司

Satellite access network enhancements for store and forward operation

Systems and methods are disclosed for enhancing satellite access networks with Store and Forward (S&F) operation. The user equipment (UE) sends an Initial Attach Request message to a Mobility Management Entity on a satellite (MME-SAT) indicating S&F operation support. The UE receives an Attach Reject message with a cause value and timer value, both protected by a digital signature, and validates the signature using preconfigured root certificates or a public certificate of the operator. For Mobile Originated Short Message Service (MO SMS), the UE establishes a connection with the MME-SAT, sends the MO SMS, and receives an immediate delivery report from the MME-SAT. The MME-SAT forwards the MO SMS to the SMS-Gateway Mobile Switching Center (SMS-GMSC).
Owner:INTEL CORP

WAPI identification method and device for multiple root certificates, computer equipment, readable storage medium and program product

The invention relates to a WAPI identification method and device for multiple root certificates, computer equipment, a readable storage medium and a program product. The method comprises the following steps: receiving a certificate authentication request message; carrying out certificate authentication on the digital certificate of each WAPI wireless network device to generate a certificate authentication result; under the condition that the AS root certificates corresponding to the digital certificates of the WAPI wireless network devices are different, private keys corresponding to the AS root certificates corresponding to the digital certificates of the WAPI wireless network devices are obtained, and according to the private keys corresponding to the WAPI wireless network devices, double signature is carried out on the certificate identification result, and double signature information of the certificate identification result is generated; and sending an identification response message to the WAPI wireless network equipment. By adopting the method, wireless access authentication can be successfully completed under the condition that different AS root certificates are installed on different WAPI wireless network devices, so that the WAPI wireless network can be successfully accessed.
Owner:SHENZHEN ZHIKAI TECH CO LTD

Intelligent household electrical appliance, control method of intelligent household electrical appliance, computer equipment and storage medium

The invention relates to an intelligent household electrical appliance, a control method of the intelligent household electrical appliance, computer equipment and a storage medium. The intelligent household electrical appliance comprises a communicator; the controller is in communication connection with the firmware upgrading server and the operation support system server through the communicator; the controller is configured to respond to a firmware upgrading instruction of the intelligent household electrical appliance, send a first firmware upgrading request to the firmware upgrading server, and receive a first certificate chain returned by the firmware upgrading server in response to the first firmware upgrading request; sending a target fault instruction to an operation support system server under the condition that the verification of the first certificate chain by adopting the pre-installed root certificate is not passed; receiving a target root certificate returned by the operation support system server in response to the target fault instruction, and updating the pre-installed root certificate into the target root certificate; the target root certificate is used for firmware upgrading of the intelligent household electrical appliance, so that the controller can update the root certificate in time, and the reliability of firmware updating of the intelligent household electrical appliance is improved.
Owner:HISENSE (GUANGDONG) AIR CONDITIONER

System, machine, method for configuring a system, and method for operating a machine

A system, a machine, a method for configuring such a system, and a method for operating such a machine are provided. The system comprises at least one machine having at least one device for exchanging data with another device of the machine, with another machine for jointly solving a task, or with a superordinate device, and the system comprises a certificate device configured to identify the at least one machine with a root certificate and to distribute a sub-certificate to at least one device of the machine, wherein the certificate device is configured to sign the sub-certificate with the root certificate of the machine in order to identify the device as belonging to the machine, and wherein the sub-certificate is issued uniquely for the device.
Owner:ROBERT BOSCH GMBH

CA root certificate issuing method or device based on block chain

The invention discloses a block chain-based CA root certificate issuing method or device, and the method comprises the steps: carrying out the registration or maintenance of a CA mechanism with an electronic authentication permission through a registration ECP method; then, certificate data are written in batches through a certificate writing method, certificate content and an electronic authentication license number ECP to which the certificate content belongs are stored by taking a CA root certificate serial number SN as a unique index, and the global certificate number, the certificate number under the ECP and an SN list are synchronously maintained when the certificate is written for the first time; the CA root certificate revocation state is independently managed through a revocation management method, revocation information is only recorded in state mapping, certificate main body data is not affected, and therefore efficient state change is achieved. In the query stage, the certificate content, the affiliated ECP and the CA name can be obtained based on the SN, the CA root certificate serial number set, the certificate number and the global ECP number corresponding to the ECP can also be queried based on the ECP, and the whole process does not need to traverse data on the chain.
Owner:CHENGDU BITWELL TECH CO LTD