Digital certificate processing method and device

A technology of digital certificates and processing methods, applied in digital transmission systems, secure communication devices, user identity/authority verification, etc., can solve problems such as non-unique trust anchors of certificates

Active Publication Date: 2018-11-02
CHINA INTERNET NETWORK INFORMATION CENTER
View PDF6 Cites 2 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

In order to obtain and verify digital certificates, the current common method is to pre-install trusted root certificates on terminals. However, there are currently many CA institutions, so that the number of pre-installed root certificates on terminals is large. For example, the number of pre-installed root certificates can reach hundreds. Causes certificate trust anchors to be non-unique
[0003] And at present, CA organizations have too much power to issue digital certificates. Any CA organization can issue digital certificates to any domain name. Once any CA organization issues a digital certificate by mistake due to being attacked or cheated, it can use the wrongly issued digital certificate to pretend to be a domain name. Become the owner of a specific domain name and implement a man-in-the-middle attack

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Digital certificate processing method and device
  • Digital certificate processing method and device
  • Digital certificate processing method and device

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0066] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments It is a part of embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0067] see figure 1 , which shows the system architecture diagram of the digital certificate management system corresponding to the digital certificate processing method provided by the embodiment of the present invention, the digital certificate management system includes: a root domain name server, a first-level domain name server to an M-l...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a digital certificate processing method and device. After a domain name application request carrying a to-be-applied domain name is acquired, the to-be-applied domain name carried in the domain name application request is authorized if the to-be-applied domain name carried in the domain name application request is allowed to be registered, a digital certificate correspondingto the authorized to-be-applied domain name is singed and issued, and therefore an N-stage domain name server can be not only be a domain name administrator but also be a novel CA mechanism for signing and issuing the digital certificate corresponding to the domain name. That is to say, for any stage of domain name server, the domain name server only can sign and issue the digital certificate corresponding to the next-stage domain name administrated by the domain name server, therefore, the power that various stages of domain name servers sign and issue the digital certificates is limited, and the problem that the domain name serves are prone to be attacked due to the fact that the power is too large is solved; and in addition, the digital certificate corresponding to the domain name under each stage of domain name server is related to the root domain name server, trust anchors corresponding to the various stages of domain name servers are all root domain name digital certificates ofthe root domain name servers, and then the uniqueness of the trust anchors is achieved.

Description

technical field [0001] The invention belongs to the technical field of network and information security, and in particular relates to a digital certificate processing method and device. Background technique [0002] At present, the digital certificate is in charge of an authoritative and trusted third party, such as a CA (Certificate Authority, certificate authority), and establishes a secure TLS (Transport Layer Security, secure transport layer protocol) connection or SSL (Secure Sockets Layer) connection between the terminal and the server. , Secure Sockets Layer) connection, the terminal needs to obtain the digital certificate sent by the server and verify the digital certificate. In order to obtain and verify digital certificates, the current common method is to pre-install trusted root certificates on terminals. However, there are currently many CA institutions, so that the number of pre-installed root certificates on terminals is large. For example, the number of pre-i...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/32H04L29/06H04L29/12
CPCH04L9/3268H04L63/0823H04L63/166H04L61/4511
Inventor 柏宗超姚健康孔宁
Owner CHINA INTERNET NETWORK INFORMATION CENTER
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products