Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

112 results about "Root certificate" patented technology

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed and form the basis of an X.509-based public key infrastructure (PKI). Either it has matched Authority Key Identifier with Subject Key Identifier, in some cases there is no Authority Key identifier, then Issuer string should match with Subject string (RFC5280). For instance, the PKIs supporting HTTPS for secure web browsing and electronic signature schemes depend on a set of root certificates.

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Industrial Internet of Things equipment data encryption transmission method based on edge computing

The invention discloses an edge computing-based industrial Internet of Things equipment data encryption transmission method, which comprises the following steps of: constructing an edge node alliance comprising at least two cross-regional edge gateways, completing bidirectional identity authentication through an alliance root certificate, and establishing an encrypted communication link; industrial equipment collects original data and then transmits the original data to an edge gateway which the industrial equipment belongs to, and the gateway extracts data features and divides the data features into a core control level, a process parameter level, a common monitoring level and a security level; differential encryption strategies are adopted for different levels of data; each edge gateway uploads the encrypted data to a distributed key management node, and obtains and synchronizes a periodically updated key chain; during cross-region transmission, performing secondary packaging and encryption to generate a data packet containing identifications such as a security level and the like; and the receiving end verifies the legality of the node, decrypts and verifies the integrity of the data, distributes the data if the decryption is passed, and blocks the alarm if the decryption The method is suitable for scenes such as single-area monitoring and multi-area manufacturing, data security and transmission efficiency balance are achieved, and all-weather stable transmission is guaranteed.
Owner:HEFEI UNIV OF ECONOMICS

Data processing method and related equipment

The data processing method comprises the following steps: a second client extracts a public key of a second user from an identity certificate of the second user, performs hierarchical encryption on data by using the public key of the second user to obtain a ciphertext, and stores the ciphertext and the identity certificate of the second user in a block chain network; and the first client obtains the ciphertext and the identity certificate of the second user from the block chain network, and verifies the legality of the identity certificate of the second user by using the root certificate. And when the verification is passed, the first client extracts the first derived information from the identity certificate of the first user and extracts the second derived information from the identity certificate of the second user. Wherein the derivation information indicates a derivation path of the identity certificate. And the first client determines a private key of the second user according to the derived information and the private key of the first user, and decrypts the ciphertext according to the private key of the second user to obtain data. According to the method, an authentication mechanism of an identity certificate is used for carrying out identity authentication on a public key, the identity trust problem is solved, and the visibility of data divided according to levels is realized.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Cluster self-discovery method suitable for cloud server cipher machine

The invention relates to the technical field of information security, in particular to a cluster self-discovery method suitable for a cloud server cipher machine, which comprises the following steps: when physical equipment of the cloud server cipher machine leaves a factory, a certificate management module generates an equipment certificate and a root CA certificate in combination with an enterprise CA system, and stores the equipment certificate and the root CA certificate; after the virtual cipher machine is created and started, the key management service module combines with the certificate management module to generate a virtual machine certificate, and stores the virtual machine certificate, the storage device certificate and the root CA certificate together; the cluster management service module enables the master node of the virtual cipher machine to discover the slave node of the virtual cipher machine in the same network domain through UDP broadcast, and executes three-level verification on the slave node of the virtual cipher machine from three aspects of an equipment certificate, a virtual machine certificate and an authentication signature; and the virtual cipher machine master node synchronizes the cluster master key to the virtual cipher machine slave node passing verification. According to the invention, hierarchical identity isolation and verification of the cloud server cipher machine host and the virtual cipher machine can be realized, and the security of cluster self-discovery and authentication stages is ensured.
Owner:山东三未信安信息科技有限公司

Document printing and traceability tracking system based on block chain

The invention relates to the technical field of block chain data storage and traceability tracking, in particular to a document printing and traceability tracking system based on a block chain. Comprising an off-line certificate generation unit used for generating an off-line cryptographic certificate based on technical parameters analyzed from an external printing request; the dynamic anchoring control unit is used for monitoring system state parameters and carrying out dynamic anchoring strategy calculation based on the system state parameters so as to generate an anchoring triggering decision; the aggregation anchoring unit is used for responding to the anchoring triggering decision, aggregating a plurality of offline cryptographic certificates to generate an aggregation root certificate, and broadcasting a block chain transaction containing the aggregation root certificate; and the verification traceability unit is used for acquiring the aggregation root certification on the block chain and executing cryptographic verification in combination with the offline data to obtain a final verification result. According to the invention, the core pain point that the system is unavailable due to the performance bottleneck of the block chain in a high-concurrency scene in the prior art is solved, and the continuity and reliability of services are ensured.
Owner:北京微点科学技术有限公司

SIP (Session Initiation Protocol) authentication method based on post-quantum and national secret hybrid signature algorithm

The invention provides an SIP (Session Initiation Protocol) authentication method based on a post quantum and national secret mixed signature algorithm, which is applied to an SIP client, and comprises the following steps: sending a first registration message to an SIP server, the first registration message comprising a target authentication control parameter, so that the SIP server generates a first reply message according to the target authentication control parameter; receiving a first reply message; obtaining a first mixed signature certificate of the SIP client according to the first reply message, generating a first random number, and performing mixed signature on the first random number to generate a first signature value; sending a second registration message to the SIP server, so that the SIP server verifies the first mixed signature certificate by adopting a pre-stored root certificate of the SIP client, and verifies the first signature value; and receiving second reply information, and indicating whether the SIP client is successfully verified or not. By integrating a post-quantum algorithm, SIP authentication has the characteristic of quantum attack resistance.
Owner:中电信量子信息科技集团有限公司

Systems and methods for streamlined platform component attestation

Systems and methods for streamlined platform attestation are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor. The memory may have program instructions stored thereon that, upon execution, cause the IHS to: read root certificates for a plurality of components of the IHS; and embed the root certificates for the plurality of components into a platform certificate.
Owner:DELL PROD LP

Equipment verification method and electronic equipment

The invention discloses a device verification method and an electronic device, and relates to the technical field of device verification, and the device verification method comprises the steps: responding to a condition that an authentication structure file signature accords with a protocol specification requirement of an authentication platform, carrying out the analysis of an authentication structure, and obtaining a terminal entity certificate, an encrypted device private key and a target verification code; verifying the encrypted device private key based on the unique identifier of the target device; in response to verification passing, decrypting the encrypted device private key to obtain a plaintext device private key; verifying the digital signature of the terminal entity certificate by using the authentication platform root certificate public key; in response to verification passing, generating a random number; obtaining a signature result of the response data packet; and if the authentication platform root certificate public key of the terminal entity certificate verifies the signature result successfully, determining that the target equipment passes the verification. The technical problem that an attacker simulates legal verification response and forges verification pass in the related technology is solved, and the technical effect of improving the equipment verification reliability is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Authentication method and apparatus, and communication device and storage medium

Provided in the embodiments of the present disclosure is an authentication method. The method is executed by a first root certificate authority (CA), and comprises: generating a first type of certificate on the basis of a transport layer security (TLS) protocol, wherein the first type of certificate is a certificate of an entity in a first security domain where the first root CA is located.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Network access control method, apparatus and device, and storage medium

Embodiments of the present disclosure relate to a network access control method, apparatus and device, and a storage medium. The network access control method includes: receiving a certificate verification request sent by a terminal, and returning a certificate verification response to the terminal, wherein the certificate verification response carries a preset server certificate, the certificate verification response is used for instructing the terminal to verify the preset server certificate based on a root certificate installed in the terminal, and identity verification information of the root certificate is partially or fully different from identity verification information of the preset server certificate; and receiving a verification result returned by the terminal for the preset server certificate, and in a case where the verification result indicates that certificate verification succeeds, determining that the terminal has a security risk and interrupting a network access communication link of the terminal. In the embodiments of the present disclosure, when the terminal successfully verifies the preset server certificate, the terminal may be prevented from accessing a network by interrupting the network access communication link with the terminal, thereby improving the security of the network.
Owner:DOUYIN VISION CO LTD

DDS Security certificate secure creation and deployment method

The invention discloses a DDS Security certificate secure creation and deployment method, which comprises the following steps of: initializing a certificate management service (CMS), establishing a secure channel with a trusted execution environment (TEE), and loading a preset DDS identity CA root certificate from the TEE; an application package manager APM analyzes the application configuration information, carries an application identity ID, and initiates a certificate creation request to a CMS; the CMS constructs certificate information, and sends a certificate creation request carrying the certificate information and an application identity (ID) to the trusted execution environment; public and private keys are generated in the TEE, a certificate is created and signed, and the created application identity certificate is returned to the CMS; the certificate management service verifies and stores the certificate, and returns an identity certificate and a CA root certificate to the APM; and the APM installs the identity certificate to a specified folder of the application installation directory. According to the invention, the establishment and deployment of the identity certificate are realized based on the CMS and the TEE, the certificate management process is simplified, and the deployment efficiency is improved.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Ca consensus method, apparatus, and node

Provided are a CA consensus method, an apparatus, and a node. The method comprises: obtaining a final voting result for a voting event on the basis of voting results of a plurality of first CAs; and when the final voting result indicates that the voting event passes, executing a first operation, wherein the first operation comprises registration of a CA, revocation of a CA, or update of a root certificate. In this way, a decision can be jointly made by a plurality of CAs without relying on a central CA, thereby improving the degree of decentralization of DPKI systems, and thus improving the overall security of the DPKI systems.
Owner:HUAWEI TECH CO LTD

Data processing method and device, electronic equipment and storage medium

The embodiment of the invention discloses a data processing method and device, electronic equipment and a storage medium. According to the embodiment of the invention, a code package pulling request can be sent; obtaining a returned code packet and a digital signature, wherein the digital signature is obtained by encrypting a message digest of the code packet by a private key of the root certificate; generating a new message abstract of the code package, and decrypting the digital signature by adopting a public key of the root certificate to obtain decrypted data; and if the new message digest of the code package is the same as the decrypted data, loading the code package. In the embodiment of the invention, the public key of the root certificate is set at the client, and the private key of the root certificate is set at the server, so that the authenticity and integrity of the code packet can be verified before loading according to the digital signature encrypted based on the private key and returned by the server when the client requests the code packet from the server. Therefore, according to the scheme, the security of the data processing method can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Trusted computing remote attestation method and device, computer device and storage medium

The application relates to a trusted computing remote attestation method and device, computer equipment and a storage medium. The method comprises the following steps: obtaining random verification information, generating a remote attestation request according to the random verification information; outputting the remote attestation request to a party to be checked, receiving signature random information and a signature digital certificate fed back by the party to be checked, the party to be checked being a trusted computing execution party, the signature digital certificate being generated by signing a trusted digital certificate by the party to be checked, and the trusted digital certificate being issued to the party to be checked by a trusted agency; obtaining trusted attestation information of the party to be checked and a root certificate of the trusted agency from a preset block chain; when the signature digital certificate is verified to be correct according to the root certificate and the trusted attestation information, the signature random information is verified according to the signature digital certificate and the random verification information; and when the signature random information is verified to be correct, it is determined that the remote attestation is passed. The method can improve verification security and realize accurate verification.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Hierarchical certificate issuing system, method, device and equipment

The invention provides a hierarchical certificate issuing system, method, device and equipment, and the system comprises root CA equipment, strategy CA equipment and certificate issuing CA equipment: the root CA equipment is used for generating a self-signature root CA certificate based on a root CA key pair, and carrying out the signature of a strategy CA certificate signature request of the strategy CA equipment through employing a root CA private key, and obtaining the strategy CA certificate; the policy CA equipment is used for acquiring a policy CA certificate from the root CA equipment and signing a certificate issuing CA certificate signature request of the certificate issuing CA equipment by adopting a policy CA private key to obtain the certificate issuing CA certificate; the certificate issuing CA equipment is used for acquiring a certificate issuing CA certificate from the policy CA equipment and signing a terminal certificate signature request of the terminal equipment by adopting a certificate issuing CA private key to obtain a terminal entity certificate; and the certificate issuing CA equipment is also used for sending a certificate chain to the terminal equipment, and the certificate chain comprises a self-signature root CA certificate, a policy CA certificate, a certificate issuing CA certificate and a terminal entity certificate.
Owner:BEIJING CHUANGRUI HONGKE TECHNOLOGY CO LTD

Managing startup of a data processing system using trust stores

Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, an entity may obtain, using a security protocol and data model (SDPM) security standard, at least a first device certificate of a certificate chain for a device. Using the at least the first device certificate and a store of trusted device certificates, the entity may perform a first analysis process to determine a level of trust in the device. If the level of trust is indeterminate, the entity may use the certificate chain and a store of trusted root certificates to perform a second analysis process to determine the level of trust in the device. Operation of the data processing system may be managed based on the level of trust in the device.
Owner:DELL PROD LP

Digital certificate verification methods, devices, equipment, systems, and readable storage media

This application discloses a method, apparatus, device, system, and readable storage medium for verifying digital certificates, belonging to the field of information and communication technology. The method includes: a second device sending a first certificate set to a first device, wherein the first certificate set is at least one of the certificate sets corresponding to each of at least two root certificates stored by the second device. The dormancy period of the target root certificate whose validity period is not the latest is covered by the working period of a backup secondary CA certificate signed by the target root certificate and the working periods of other secondary CA certificates. The first device verifies the legitimacy of at least one digital certificate of the second device based on the root certificates stored and trusted by the first device and the received first certificate set. In this application, the first device can verify the legitimacy of the digital certificate of the second device using the root certificates trusted by the first device. The first device does not need to upload other certificates, increase the number of certificate verification levels, or support new cryptographic algorithms, thus having a wide range of applications.
Owner:HUAWEI TECH CO LTD

Real estate registration method and system based on block chain

The invention relates to the technical field of real estate registration, and discloses a real estate registration method and system based on a blockchain, and the system comprises a data collection module, a data encryption module, a blockchain storage module, and an information verification module.In the aspect of data security, public key encryption and private key decryption mechanisms effectively guarantee data privacy and security, and the data security is improved. Stealing and tampering are prevented; in terms of data integrity, block hash values are compared through an information verification module, whether transmission data are changed or not is accurately judged, and completeness and reliability of the transmission data are ensured; the identity verification checks the signature validity by means of a digital certificate and a root certificate, constructs a security trust system, and prevents illegal operation; the multi-node alliance reduces the single-point fault risk, and the data change history can be checked to facilitate audit supervision; on the whole, the transparency, the fairness and the credibility of real estate registration are improved, the registration process is optimized, the processing capacity and the response speed are improved, the pain point of a traditional mode is solved, and efficient and healthy development of real estate registration business is promoted.
Owner:临沂润恒信息科技有限公司

WAPI identification method and device for multiple root certificates, computer equipment, readable storage medium and program product

The invention relates to a WAPI identification method and device for multiple root certificates, computer equipment, a readable storage medium and a program product. The method comprises the following steps: receiving a certificate authentication request message; carrying out certificate authentication on the digital certificate of each WAPI wireless network device to generate a certificate authentication result; under the condition that the AS root certificates corresponding to the digital certificates of the WAPI wireless network devices are different, private keys corresponding to the AS root certificates corresponding to the digital certificates of the WAPI wireless network devices are obtained, and according to the private keys corresponding to the WAPI wireless network devices, double signature is carried out on the certificate identification result, and double signature information of the certificate identification result is generated; and sending an identification response message to the WAPI wireless network equipment. By adopting the method, wireless access authentication can be successfully completed under the condition that different AS root certificates are installed on different WAPI wireless network devices, so that the WAPI wireless network can be successfully accessed.
Owner:SHENZHEN ZHIKAI TECH CO LTD

Intelligent household electrical appliance, control method of intelligent household electrical appliance, computer equipment and storage medium

The invention relates to an intelligent household electrical appliance, a control method of the intelligent household electrical appliance, computer equipment and a storage medium. The intelligent household electrical appliance comprises a communicator; the controller is in communication connection with the firmware upgrading server and the operation support system server through the communicator; the controller is configured to respond to a firmware upgrading instruction of the intelligent household electrical appliance, send a first firmware upgrading request to the firmware upgrading server, and receive a first certificate chain returned by the firmware upgrading server in response to the first firmware upgrading request; sending a target fault instruction to an operation support system server under the condition that the verification of the first certificate chain by adopting the pre-installed root certificate is not passed; receiving a target root certificate returned by the operation support system server in response to the target fault instruction, and updating the pre-installed root certificate into the target root certificate; the target root certificate is used for firmware upgrading of the intelligent household electrical appliance, so that the controller can update the root certificate in time, and the reliability of firmware updating of the intelligent household electrical appliance is improved.
Owner:HISENSE (GUANGDONG) AIR CONDITIONER

CA root certificate issuing method or device based on block chain

The invention discloses a block chain-based CA root certificate issuing method or device, and the method comprises the steps: carrying out the registration or maintenance of a CA mechanism with an electronic authentication permission through a registration ECP method; then, certificate data are written in batches through a certificate writing method, certificate content and an electronic authentication license number ECP to which the certificate content belongs are stored by taking a CA root certificate serial number SN as a unique index, and the global certificate number, the certificate number under the ECP and an SN list are synchronously maintained when the certificate is written for the first time; the CA root certificate revocation state is independently managed through a revocation management method, revocation information is only recorded in state mapping, certificate main body data is not affected, and therefore efficient state change is achieved. In the query stage, the certificate content, the affiliated ECP and the CA name can be obtained based on the SN, the CA root certificate serial number set, the certificate number and the global ECP number corresponding to the ECP can also be queried based on the ECP, and the whole process does not need to traverse data on the chain.
Owner:CHENGDU BITWELL TECH CO LTD

Session establishment method and system, storage medium and electronic device

The present application discloses a session establishment method and system, a storage medium and an electronic device, and relates to the field of smart home technology. The session establishment method includes: when it is determined that the session established between the edge gateway and the target application has expired, receiving the signature certificate and encrypted identification information sent by the target application, wherein the identification information is used to identify the target object; verifying the signature certificate through the saved root certificate, and decrypting the encrypted identification information using the saved private key; when the verification of the signature certificate passes and the decryption of the encrypted identification information is successful, re-establishing the session between the edge gateway and the target application based on the identification information. The above technical solution solves the problem in the prior art that the edge computing engine cannot normally establish a session with the application after being disconnected from the external network for a long time or restarted after a power outage, resulting in the inability of the edge scenario to operate normally.
Owner:QINGDAO HAIER TECH +2

Certificate query method and device based on edge node, equipment, medium and product

The invention relates to the field of block chains, and provides a certificate query method and device based on edge nodes, equipment, a medium and a product. The method comprises the following steps: receiving registration transaction information initiated by an authoritative certification authority; under the condition that the pre-verification of the registration transaction information is passed, sending the root certificate to the distributed public key infrastructure block chain, and receiving a registration completion response fed back by the distributed public key infrastructure block chain; under the condition that the registration completion response passes verification, after the registration completion response is fed back to the authority authentication mechanism, the authority authentication mechanism issues an entity certificate and feeds the entity certificate back to the network element; receiving a certificate verification request sent by the network element; and carrying out certificate query according to the certificate verification request, and determining a certificate query result. According to the certificate query method based on the edge node, a bridge is built through the edge node, and during certificate query, the network element securely accesses the distributed public key infrastructure through the edge node, so that the query efficiency is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

CA consensus method, device and node

The invention provides a CA consensus method, a CA consensus device and a node. Wherein the final voting result of the voting event is obtained based on the voting results of the plurality of first CAs; under the condition that the final voting result indicates that the voting event passes, executing a first operation; wherein the first operation comprises CA registration, CA logout or root certificate updating. Thus, the decentralization degree of the DPKI system can be improved through co-determination of a plurality of CAs without relying on a central CA, and the overall safety of the DPKI system is further improved.
Owner:HUAWEI TECH CO LTD

Methods and systems for ensuring trust between entities

This technology simplifies the management of information used to authenticate communication partners. [Solution] The first entity possesses a first identity certificate, and the second entity possesses a second identity certificate. The root certificate authority generates a first relationship certificate between the first entity and the first group. The first entity stores the first relationship certificate. The first entity sends the first identity certificate and the first relationship certificate to the second entity as a first communication. The second entity verifies that the first identity certificate and the first relationship certificate were legitimately created by the root certificate authority. Based on the verification of the first identity certificate and the first relationship certificate by the second entity, the second entity or the first entity activates a predetermined function.
Owner:DENSO CORP

Data processing method and related device

A data processing method, comprising: a second client extracts a public key of a second user from an identity certificate of the second user, uses the public key of the second user to hierarchically encrypt data to obtain a ciphertext, and stores the ciphertext and the identity certificate of the second user to a blockchain network; and a first client acquires the ciphertext and the identity certificate of the second user from the blockchain network, and uses a root certificate to verify the legitimacy of the identity certificate of the second user. When the verification is passed, the first client extracts first derived information from an identity certificate of a first user and extracts second derived information from the identity certificate of the second user. The derived information indicates a derivation path of an identity certificate. The first client determines a private key of the second user on the basis of the derived information and a private key of the first user, and on the basis of the private key of the second user, decrypts the ciphertext to obtain the data. In the method, an authentication mechanism of the identity certificate is used for authenticating the public key, thereby resolving an identity trust issue and achieving hierarchical visibility of data.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Method for processing reliability of site within intranet on virtual machine outside intranet

An information processing apparatus that provides a rendering result of a web page based on a request from a communication terminal connected to an intranet includes receiving a root certificate for a website on the intranet from the communication terminal and a performing, when the web page of the website on the intranet is rendered, verification of reliability of the website on the intranet with the root certificate.
Owner:CANON KK

User authentication method, system, medium and equipment

The invention provides a user authentication method and system, a medium and equipment, and the method comprises the steps: a service portal and a private network authentication agent pre-install a root certificate based on a standard public key infrastructure, and establish a safety message channel through the mutual verification of digital certificates; a user sends an authentication request to a service portal through a client, the service portal forwards authentication information to an authentication agent through a secure channel, and the authentication agent submits the authentication information to a private network LDAP server after protocol conversion; the LDAP server verifies the identity and returns a result, the result is transmitted back to the service portal through the authentication agent and the secure channel, and the service portal generates a short-term token or a black hole cache and feeds back the short-term token or the black hole cache to the client; and the client accesses the service site by the token. According to the invention, the deployment process is simplified, the existing network architecture and security rules of an enterprise are prevented from being changed, the pressure of a private network LDAP server is reduced, and the security, efficiency and system stability of cross-domain authentication are improved.
Owner:CHINA TOWER CO LTD

ACCESS TO A TERMINAL

When access to a terminal is requested, a mobile computer receives a communication certificate chain from a terminal computer contained within the terminal. The mobile computer establishes a communication session with the terminal computer based on whether an issuer ID associated with a root certificate in the communication certificate chain matches a stored issuer ID. Once the communication session is established, the mobile computer determines, for each of a plurality of access certificate chains, a corresponding issuer ID associated with a root certificate in that access certificate chain. If a corresponding issuer ID in an access certificate chain matches the stored issuer ID, the mobile computer selects that access certificate chain.The mobile computer transmits the selected access certificate chain to the terminal computer.
Owner:FORD GLOBAL TECH LLC