Cloud Sub-Certificate Generation for Terminal Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current certificate management systems in terminal devices lack efficient methods for generating and managing sub-certificates, leading to challenges in secure communication and synchronization between cloud and terminal devices.
Innovation Solution
A method and apparatus for sending and receiving sub-certificates, where the cloud acquires a root certificate, generates a target sub-certificate including a sub-certificate of a functional module, and sends it to the terminal device, enabling improved management and synchronization of sub-certificates for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate management is performed locally in terminal devices, then communication security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the certificate issuance function from the terminal device and relocates it to the cloud server. The terminal device no longer needs to locally generate certificates, but instead receives pre-generated sub-certificates from the cloud, thereby reducing device complexity while maintaining communication security through cloud-managed certificates.
Solution Approach 2:
The patent introduces a cloud server as an intermediary between certificate authorities and terminal devices. The cloud server acts as a mediator that receives root certificates, generates sub-certificates, and distributes them to terminal devices, simplifying the certificate management process for terminal devices while ensuring security through centralized control.
2Adaptability or versatility
If sub-certificates are generated locally in terminal devices, then communication flexibility is improved, but management capability deteriorates
Solution Approach 1:
The patent implements preliminary action by having the cloud server pre-generate and distribute sub-certificates to terminal devices before they are needed for communication. This allows terminal devices to have ready-to-use certificates without needing complex local generation capabilities, improving ease of management while maintaining communication flexibility through pre-configured sub-certificates for different functional modules.
3Adaptability or versatility
If multiple sub-certificates are managed locally, then functional module communication is improved, but synchronization difficulty increases
Solution Approach 1:
The cloud server serves as an intermediary that manages and synchronizes multiple sub-certificates for different functional modules. Instead of terminal devices managing multiple certificates locally with complex synchronization requirements, the cloud server centrally manages all sub-certificates and distributes them as needed, reducing synchronization complexity while enabling functional module communication.
Data Source
AI summary
A method includes acquiring a root certificate of a first node; generating a target sub-certificate based on the root certificate, where the target sub-certificate includes a first sub-certificate of a first functional module of a first application associated with the first node; and sending the target sub-certificate to a terminal device. The target sub-certificate is used for the first functional module of the first application in the terminal device communicating through the target sub-certificate. In such a manner, a capability of managing the first sub-certificate of the first functional module in the terminal device can be improved.


