WO2013159723A1 - 一种数字证书自动申请方法和装置及系统 - Google Patents

一种数字证书自动申请方法和装置及系统 Download PDF

Info

Publication number
WO2013159723A1
WO2013159723A1 PCT/CN2013/074735 CN2013074735W WO2013159723A1 WO 2013159723 A1 WO2013159723 A1 WO 2013159723A1 CN 2013074735 W CN2013074735 W CN 2013074735W WO 2013159723 A1 WO2013159723 A1 WO 2013159723A1
Authority
WO
WIPO (PCT)
Prior art keywords
digital certificate
applicant
issuer
certificate
digital
Prior art date
Application number
PCT/CN2013/074735
Other languages
English (en)
French (fr)
Inventor
胡亚楠
铁满霞
童伟刚
张变玲
黄振海
简练
袁鹏
Original Assignee
西安西电捷通无线网络通信股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 西安西电捷通无线网络通信股份有限公司 filed Critical 西安西电捷通无线网络通信股份有限公司
Priority to KR1020147033074A priority Critical patent/KR101617753B1/ko
Priority to US14/396,973 priority patent/US9397840B2/en
Priority to EP13780700.4A priority patent/EP2843873B1/en
Priority to JP2015507357A priority patent/JP5856352B2/ja
Publication of WO2013159723A1 publication Critical patent/WO2013159723A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority

Definitions

  • the present application relates to the field of network security technologies, and in particular, to a digital certificate automatic application method, apparatus, and system.
  • BACKGROUND In the current network environment, various technologies and devices need to use digital certificates, and digital certificates can be used for identity authentication and data encryption, but how to automatically apply for, update, and issue digital certificates requires a special way. stand by.
  • wireless local area network technology includes two types of security solutions: The first category, Wireless LAN Authentication and Privacy Infrastructure (WAPI), is the national standard for wireless local area networks (GB15629).
  • RSN Robust Security Network
  • IEEE Institute of Electrical and Electronics Engineers
  • the station (STA) and the access point ( Access Point, AP) as a digital certificate applicant must apply to the Certificate Authority (CA), which is the issuer of the digital certificate, to apply for a digital certificate that can identify itself, and then install the digital certificate to the device. among.
  • CA Certificate Authority
  • digital certificate applicants need to provide information to the digital certificate issuer during the digital certificate application and update process, or digital certificate issuers in the digital certificate issuance process What information needs to be provided to the digital certificate applicant will directly affect whether the wireless LAN technology security mechanism can be effectively implemented.
  • the present application provides a method, device, and system for automatically applying a digital certificate to implement automatic application of a digital certificate. Please, update and issue.
  • the application provides a method for automatically applying a digital certificate, including:
  • the digital certificate applicant notifies the digital certificate issuer of the digital certificate generation method supported by itself, and if the digital certificate applicant determines that the digital certificate issued by the digital certificate issuer is already included, the digital certificate applicant will also have the digital certificate applicant
  • the digital certificate information informs the digital certificate issuer that if it is determined that there is no digital certificate issued by the digital certificate issuer, the digital certificate applicant will also need to notify the digital certificate to be issued in the certificate information included in the applied new digital certificate.
  • the digital certificate issuer selects a digital certificate generation method from the digital certificate generation method supported by the digital certificate applicant and notifies the digital certificate applicant, and the digital certificate issuer determines that the digital certificate applicant needs to apply for a new digital certificate, according to the selected digital certificate.
  • the method and the certificate information notified by the digital certificate applicant generate new digital certificate information and notify the digital certificate applicant to determine that the digital certificate applicant does not need to apply for a new digital certificate, and notifies the digital certificate applicant of the invalid digital certificate information;
  • the digital certificate applicant determines the digital certificate to be used based on the notification from the digital certificate issuer.
  • the application also provides a digital certificate application device, including:
  • a first notification unit configured to notify a digital certificate issuer of a digital certificate generation method supported by the digital certificate application device
  • a second notification unit configured to determine that the digital certificate application device already contains the digital certificate issued by the digital certificate issuer, and notify the digital certificate issuer of the digital certificate information existing by the digital certificate applicant, if it is determined that the digital certificate application device does not have The digital certificate issued by the digital certificate issuer will notify the digital certificate issuer of the certificate information contained in the new digital certificate of the application;
  • a certificate determining unit configured to determine a digital certificate to be used according to the notification of the digital certificate issuer.
  • the application also provides a digital certificate issuing device, including:
  • a first notification unit configured to select a digital certificate generation method from the digital certificate generation method supported by the digital certificate applicant and notify the digital certificate applicant according to the digital certificate generation method supported by the digital certificate applicant notified by the digital certificate applicant;
  • a second notification unit configured to: when the digital certificate applicant needs to apply for a new digital certificate, generate new digital certificate information according to the selected digital certificate generation method and the certificate information notified by the digital certificate applicant, and notify the digital certificate applicant to determine the digital certificate.
  • the applicant will notify the digital certificate applicant of the invalid digital certificate information.
  • the application also provides a digital certificate automatic application system, including:
  • the digital certificate applicant is configured to notify the digital certificate issuer of the digital certificate generation method supported by itself, and if it is determined that the digital certificate issued by the digital certificate issuer is already included, the digital certificate applicant has the digital certificate information already notified to the digital certificate information
  • the certificate issuer if it is determined that there is no digital certificate issued by the digital certificate issuer, Notifying the digital certificate issuer of the certificate information contained in the applied new digital certificate, and determining the digital certificate to be used according to the notification of the digital certificate issuer;
  • the digital certificate issuer is configured to select a digital certificate generation method from the digital certificate generation method supported by the digital certificate applicant and notify the digital certificate applicant to determine, when the digital certificate applicant needs to apply for a new digital certificate, according to the selected digital certificate generation method. And the certificate information notified by the digital certificate applicant generates new digital certificate information and notifies the digital certificate applicant to determine that the digital certificate applicant does not need to apply for a new digital certificate, and notifies the digital certificate applicant of the invalid digital certificate information.
  • FIG. 1 is a flowchart of a method for automatically applying a digital certificate according to Embodiment 1 of the present application;
  • FIG. 2 is a schematic diagram of message contents in a method for automatically applying a digital certificate according to Embodiment 1 of the present application;
  • Embodiment 3 is a flowchart of a method for automatically applying a digital certificate in Embodiment 2 of the present application;
  • FIG. 4 is a schematic diagram of message contents in a method for automatically applying a digital certificate according to Embodiment 2 of the present application.
  • DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The digital certificate automatic application method, apparatus and system provided by the present application will be described in more detail below with reference to the accompanying drawings and embodiments.
  • the embodiment of the present application provides a method, device, and system for automatically applying a digital certificate, which can automatically and automatically apply for, update, and issue digital certificates.
  • the method includes:
  • the digital certificate applicant notifies the digital certificate issuer of the digital certificate generation method supported by itself, and if the digital certificate applicant determines that the digital certificate issued by the digital certificate issuer is already included, the digital certificate applicant will also have the digital certificate applicant
  • the digital certificate information informs the digital certificate issuer that if it is determined that there is no digital certificate issued by the digital certificate issuer, the digital certificate applicant will also need to notify the digital certificate to be issued in the certificate information included in the applied new digital certificate.
  • the digital certificate issuer selects a digital certificate generation method from the digital certificate generation method supported by the digital certificate applicant and notifies the digital certificate applicant, and the digital certificate issuer determines that the digital certificate applicant needs to apply for a new digital certificate, according to the selected digital certificate.
  • the method and the certificate information notified by the digital certificate applicant generate new digital certificate information and notify the digital certificate applicant to determine that the digital certificate applicant does not need to apply for a new digital certificate, and the invalid digital certificate information will be invalid. Notifying the digital certificate applicant;
  • the digital certificate applicant determines the digital certificate to be used based on the notification from the digital certificate issuer.
  • the automatic application, update and issuance of the digital certificate can be realized by using the digital certificate automatic application method provided in the embodiment of the present application.
  • the wireless local area network number of different types can be automatically applied.
  • Certificate when the digital certificate applicant does not have a digital certificate or the issued digital certificate is invalid, the digital certificate issuer automatically determines the certificate status of the digital certificate applicant when the local certificate issuance policy allows the digital certificate applicant to issue a certificate.
  • the certificate applicant issues a valid digital certificate, otherwise it sends invalid digital certificate information, thereby realizing the automatic application, update and issuance of the digital certificate, thereby ensuring whether the wireless LAN technical security mechanism can be effectively carried out.
  • the embodiments of the present application are not limited to the message and the interaction mode of the digital certificate applicant and the digital certificate issuer.
  • the automatic application, update, and issuance of the digital certificate can be implemented as described in the present application.
  • the preferred message interaction mode of the present application is given.
  • the digital certificate automatic application method includes the following steps:
  • Step 101 The digital certificate applicant first sends a digital certificate generation capability message to the digital certificate issuer, where the digital certificate generation capability message includes a digital certificate generation method supported by the digital certificate applicant;
  • Step 102 The digital certificate issuer selects a digital certificate generation method from a digital certificate generation method supported by the digital certificate applicant, and notifies the digital certificate applicant through the digital certificate generation type message;
  • Step 103 The digital certificate applicant sends a digital certificate application message to the digital certificate issuer, wherein if the digital certificate applicant determines that the digital certificate issued by the digital certificate issuer is already included, the digital certificate application message carries the digital certificate application The existing digital certificate information, if the digital certificate applicant determines that there is no digital certificate issued by the digital certificate issuer, the digital certificate application message carries the certificate information that needs to be included in the applied new digital certificate;
  • Step 104 The digital certificate issuer sends a digital certificate confirmation message to the digital certificate applicant, where the digital certificate issuer determines that the digital certificate applicant needs to apply for a new digital certificate, and the digital certificate confirmation message includes the digital certificate issuer according to the selected The digital certificate generation method and the new digital certificate information generated by the certificate information included in the digital certificate application message, and the digital certificate issuer determines that the digital certificate confirmation message carries the invalid digital certificate information when the digital certificate applicant does not need to apply for the new digital certificate;
  • Step 105 The digital certificate applicant receives the digital certificate confirmation message sent by the digital certificate issuer, and determines the used digital certificate according to the digital certificate confirmation message.
  • This embodiment implements automatic application, update, and issuance of digital certificates by interacting with four messages.
  • step 103 the digital certificate applicant determines that the digital certificate issued by the digital certificate issuer is already present.
  • the signature of the existing digital certificate information by using the private key of the existing digital certificate is also sent;
  • the digital certificate issuer determines the certificate information that the applicant who receives the digital certificate needs to include in the new digital certificate of the application, or determines the digital certificate information and signature that the digital certificate applicant has received, and determines the digital certificate when the verification signature is invalid.
  • the applicant needs to apply for a new digital certificate; the digital certificate issuer determines the digital certificate information and signature already received by the applicant who has received the digital certificate, and when the verification signature is valid, it is determined that the digital certificate applicant does not need to apply for a new digital certificate.
  • the digital certificate applicant does not have a digital certificate issued by the digital certificate issuer to implement the digital certificate application; 2) the digital certificate applicant has a digital certificate issued by the digital certificate issuer, but the digital certificate is an invalid digital certificate, thereby realizing Digital certificate update.
  • the specific information included in the message exchanged by the digital certificate applicant and the digital certificate issuer is not limited herein, as long as the purpose of the foregoing interaction can be achieved, preferably, the following application is implemented.
  • the digital certificate automatic application method in this embodiment includes:
  • Step 201 The digital certificate applicant sends a digital certificate generating capability message to the digital certificate issuer, where the digital certificate generating capability message includes: a digital certificate applicant identity field and a digital certificate generating capability identifier field.
  • the digital certificate generation capability message further includes a digital certificate applicant random number.
  • the digital certificate applicant identity field identifies the identity of the digital certificate applicant, and the digital certificate generation capability identification field is used to identify the digital certificate generation method supported by the digital certificate applicant.
  • the digital certificate generation capability identification field lists the digital certificate application. The method of generating all digital certificates supported by the person.
  • the digital certificate generating capability identification field identifies the manner in which the digital certificate is generated, but is not limited to the manner shown in Table 1:
  • the value of the lowest 1-bit bitO is 1.
  • the low-digit bitl value of 1 indicates that the single-certificate mode P12 delivery capability digital certificate generation method is supported.
  • the value of the lower 3 bits of bit 2 is 1, it indicates that the multi-certificate mode public-private key pair local generation capability digital certificate generation method is supported.
  • the lower 4-bit bit3 value is 1, it indicates that the multi-certificate mode P12 delivery capability digital certificate generation method is supported.
  • the corresponding capability identifier bit is 1 at the same time.
  • the value is 0x03, that is, 00000011, which indicates that the single certificate mode public-private key pair local generation capability and the single-certificate mode P12 delivery capability digital certificate generation method are simultaneously supported.
  • the digital certificate applicant uses the digital certificate generation capability identification field to indicate the supported digital certificate generation method, and the digital certificate generation method selected by the digital certificate issuer.
  • Step 202 The digital certificate issuer sends a digital certificate generation capability message and sends a digital certificate generation type message to the digital certificate applicant.
  • the digital certificate generation type message includes: a digital certificate issuer identity identifier field, and a digital certificate generation type field. .
  • the digital certificate generation type message further includes a digital certificate issuer random number.
  • the Digital Certificate Issuer Identity field identifies the identity of the digital certificate issuer and the Digital Certificate Generation Type field is used for the digital certificate generation method selected by the digital certificate issuer. Specifically, after receiving the digital certificate generating capability message sent by the digital certificate applicant, the digital certificate issuer confirms the digital certificate issuing method according to the digital certificate applicant and the digital certificate generating method jointly supported by the digital certificate applicant or the local policy. The digital certificate generation method is identified in the Digital Certificate Generation Type field.
  • the digital certificate generation type field identifies the selected digital certificate generation method in a manner that is not limited to the manner shown in Table 2:
  • the value of the lowest bit 1 When the value of the lowest bit 1 is 0, it indicates that the single-certificate mode public-private key pair local generation capability digital certificate is generated.
  • the low-bit bit 1 When the low-bit bit 1 is 1, the single-certificate mode P12 delivery capability digital certificate generation method is selected.
  • bit 2 When bit 2 is set to 1, it indicates that the multi-certificate mode public-private key pair local generation capability digital certificate generation method is selected.
  • the lower 4-bit bit3 value When the lower 4-bit bit3 value is 1, it indicates that the multi-certificate mode P12 delivery capability digital certificate generation method is selected. Number of digital certificate issuers
  • the value of the word certificate generation type field indicates that the selected digital certificate generation method, that is, the digital certificate generation type, notifies the digital certificate applicant to select the same digital certificate generation type.
  • Step 203 After receiving the digital certificate generation type message, the digital certificate applicant sends a digital certificate application message to the digital certificate issuer, where the digital certificate application message specifically includes a new digital certificate application identifier field and a digital certificate applicant request field.
  • the digital certificate generation type message further carries a digital certificate application message integrity check value
  • the digital certificate application message integrity check value is a key pair digital certificate generated by the digital certificate applicant random number and the digital certificate issuer random number.
  • the content of the application message is calculated in addition to the application message integrity check value.
  • the digital certificate applicant determines the digital certificate generation method used for the issuance of the certificate according to the digital certificate generation type field value in the digital certificate generation type message, and determines whether it is necessary to apply for a new one.
  • the digital certificate, identified in the new digital certificate application identification field, is determined as follows:
  • the new digital certificate Determining, according to the digital certificate issuer identity field in the digital certificate generation type message, whether the digital certificate issued by the digital certificate issuer is already included, and if the digital certificate applicant already contains the digital certificate issued by the digital certificate issuer, the new digital certificate
  • the application identification field identifier does not need to apply for a new digital certificate. If the digital certificate applicant does not have a certificate issued by the digital certificate issuer, the new digital certificate application identification field identifier needs to apply for a new digital certificate.
  • the new digital certificate application identification field identifier is used but is not limited to the form shown in Table 3a.
  • the digital certificate applicant determines the content of the digital certificate applicant request field according to the identifier in the new digital certificate application identification field, and the determination manner is as follows:
  • the digital certificate applicant request field specifically carries the certificate information included in the newly applied digital certificate for the digital certificate applicant; if the new digital certificate application identification field The medium identifier does not need to apply for a new digital certificate, indicating that the certificate issued by the digital certificate issuer is already included, and the digital certificate applicant request field specifically carries the digital certificate information existing by the digital certificate applicant and the private key using the existing digital certificate.
  • the signature of the existing digital certificate information is such that the digital certificate issuer determines whether the digital certificate applicant's existing digital certificate is valid according to the digital certificate information and signature already existing by the digital certificate applicant.
  • the digital certificate applicant request field includes a certificate information field and a signature value field; when the digital certificate applicant determines that there is no digital certificate issued by the digital certificate issuer, the digital certificate issuer needs to be Apply for a digital certificate.
  • the certificate information field carries the digital certificate.
  • the certificate information that the applicant needs to include in the new digital certificate applied for, the signature value field is invalid.
  • the digital certificate issuer When the digital certificate applicant determines that the digital certificate issued by the digital certificate issuer has been issued, the digital certificate issuer does not need to apply for a digital certificate, and the certificate information field specifically carries the digital certificate information existing by the digital certificate applicant, and the signature value.
  • the field carries the signature of the existing digital certificate information using the private key of the existing digital certificate.
  • the digital certificate applicant constructs a digital certificate request message to the digital certificate issuer, the digital certificate application message including: a new digital certificate application identifier (see Table 3a) and a digital certificate applicant request field (see Table 4).
  • I certificate information I signature value I step 204 after the digital certificate issuer receives the digital certificate application message, if the digital certificate application message carries the digital certificate application message integrity check value, first determine the digital certificate application message integrity check value If it is correct, discard the message if it is incorrect. If the digital certificate confirmation message is sent correctly to the digital certificate applicant, if the digital certificate application message does not carry the digital certificate application message integrity check value, send a digital certificate confirmation to the digital certificate applicant.
  • the digital certificate confirmation message specifically includes a new digital certificate issuance identification field and a digital certificate applicant certificate field.
  • the digital certificate confirmation message further includes a digital certificate confirmation message integrity check value, and the digital certificate confirmation message integrity check value is confirmed by the digital certificate applicant random number and the digital certificate issuer random number key pair digital certificate verification The content is encrypted and calculated in addition to the digital certificate confirmation message integrity check value.
  • the digital certificate issuer in the certificate local issuance policy allows the digital certificate applicant to issue a certificate and determines that the digital certificate applicant needs to apply for a new digital certificate, the new digital certificate issuance identification field identifier is issued a new digital certificate, the digital certificate applicant certificate field Specifically carrying new digital certificate information;
  • the digital certificate issuer grants a certificate to the digital certificate applicant and determines that the digital certificate applicant does not need to apply for a new digital certificate, or the digital certificate issuer does not allow the certificate to be issued to the digital certificate applicant.
  • the new digital certificate issuance identification field identifies that a new digital certificate has not been issued, and the digital certificate applicant certificate field ID is invalid.
  • the digital certificate issuer's certificate local issuance policy allows the digital certificate applicant to be issued a new digital certificate when issuing a certificate to the digital certificate applicant as follows:
  • the new digital certificate application identification field in the digital certificate application message it is judged whether the digital certificate applicant already contains the certificate issued by the digital certificate issuer, and if the digital certificate applicant does not have the certificate issued by the digital certificate issuer, the new digital certificate is issued.
  • the identity field is set to require the issuance of a new digital certificate, if the digital certificate applicant The certificate issued by the digital certificate issuer is already included, and the digital certificate issuer determines whether the digital certificate applicant's existing digital certificate is valid according to the digital certificate information and signature already existing by the digital certificate applicant in the digital certificate applicant request field; If the digital certificate applicant's existing digital certificate information in the digital certificate applicant request field is valid, indicating that the digital certificate applicant has a valid digital certificate, the new digital certificate issuance identification field is set to not require the issuance of a new digital certificate, if If the digital certificate applicant's existing digital certificate information in the digital certificate applicant request field is invalid, indicating that the digital certificate applicant does not have a valid digital certificate, the new digital certificate issuance identification field is set to require the issuance of a new digital certificate.
  • the new digital certificate issuance identification field is used but is not limited to the identification method shown in Table 3b.
  • the digital certificate applicant certificate field contains the newly issued digital certificate, the digital certificate applicant certificate field value is valid, and the field value is the number according to the digital certificate request message.
  • the digital certificate applicant certificate field When the digital certificate applicant certificate field value is valid, the digital certificate applicant certificate field includes a certificate number field and a digital certificate field, as shown in Table 5.
  • Number of Certificates Digital Certificates Part 1 The number of certificates, indicating the number of certificates issued in total, related to the method of generating the digital certificate.
  • Part II A digital certificate indicating the format of the digital certificate issued, which is related to the method of generating the digital certificate.
  • the digital certificate field specifically includes an identifier certificate type, a certificate identifier, a length, and a value word.
  • Certificate type certificate identification length value Subfield 1 The certificate type, as shown in Table 7, lists the certificate type of the new digital certificate issued.
  • Subfield 2 The certificate identifier, as shown in Table 8, lists the encoding of the new digital certificate.
  • Subfield 3 Length, which represents the length of the "Value” subfield, which is the length of the new digital certificate content.
  • Subfield 4 Value, which represents the complete certificate content that identifies the new digital certificate.
  • Step 205 If the digital certificate confirmation message carries the digital certificate confirmation message integrity check value, the digital certificate applicant first determines whether the digital certificate confirmation message integrity check value is correct after the digital certificate confirmation message is sent, if not, The message is discarded. If the digital certificate is used for correct processing, if the digital certificate confirmation message does not carry the digital certificate confirmation message integrity check value, the digital certificate applicant determines the digital certificate to be used according to the digital certificate confirmation message.
  • the digital certificate applicant determines, according to the new digital certificate issuance identification field, whether the digital certificate applicant certificate field contains a new digital certificate issued by the digital certificate issuer, and if the new digital certificate issuance identification field identifier issues a new digital certificate, The digital certificate applicant installs the new digital certificate contained in the Digital Certificate Applicant Certificate field. If the new digital certificate issuance identification field identifies that a new digital certificate does not need to be issued, the digital certificate applicant continues to use the certificate issued by the issuer who already contains the digital certificate. Digital certificate.
  • the embodiment of the present invention does not limit the field specifically included in the message exchanged by the digital certificate applicant and the digital certificate issuer, as long as the purpose of the interaction can be achieved. Therefore, when the digital certificate request message specifically includes the new digital certificate application identifier field and the digital certificate applicant request field, the fields of the other three messages may also be other fields than the above enumerated fields; when the digital certificate confirmation message specifically includes The new digital certificate issuance identification field and the digital certificate applicant certificate field, and the fields of the other three messages may also be other fields than the above enumerated fields; the digital certificate generating capability message includes a digital certificate applicant identity field and a digital certificate generation When the capability identifies the field, the fields of the other three messages may also be other fields than the above enumerated fields; when the digital certificate generation type message includes the digital certificate issuer identity field and the digital certificate generation type field, the other three messages The fields may also be other fields than the above enumerated fields.
  • the digital certificate automatic application method includes the following steps:
  • Step 301 The digital certificate applicant first sends a digital certificate application message to the digital certificate issuer.
  • the digital certificate application message includes a digital certificate generation method supported by the digital certificate applicant, if the digital certificate applicant determines that the number is already included. a digital certificate issued by the certificate issuer, wherein the digital certificate application message further carries digital certificate information existing by the digital certificate applicant; if the digital certificate applicant determines that there is no digital certificate issued by the digital certificate issuer, The digital certificate application message also carries the certificate information that needs to be included in the new digital certificate of the application;
  • Step 302 The digital certificate issuer sends a digital certificate confirmation message to the digital certificate applicant.
  • the digital certificate confirmation message includes a digital certificate generation method selected by a digital certificate issuer from a digital certificate generation method supported by a digital certificate applicant, and the digital certificate issuer determines that the digital certificate applicant needs to apply for a new digital certificate, the digital certificate
  • the confirmation message further includes new digital certificate information generated by the digital certificate issuer according to the selected digital certificate generation method and the certificate information included in the digital certificate application message, and the digital certificate issuer determines that the digital certificate applicant does not need to apply for a new digital certificate,
  • the digital certificate confirmation message also carries invalid digital certificate information;
  • Step 303 The digital certificate applicant receives the digital certificate confirmation message sent by the digital certificate issuer, and determines the used digital certificate according to the digital certificate confirmation message.
  • This embodiment implements automatic application, update, and issuance of digital certificates by interacting with two messages.
  • the embodiment Compared with the first embodiment, the embodiment combines the step 201 and the step 203 of the embodiment 1 to perform the step 301, and the digital certificate applicant sends the message only to the digital certificate issuer, and the step 202 of the embodiment 1 is Step 204 merges to proceed to step 302 where the digital certificate issuer only sends the message to the digital certificate applicant.
  • step 301 the digital certificate applicant sends a digital certificate application message to the digital certificate issuer, where the digital certificate application message specifically includes a digital certificate applicant identity field, a digital certificate generation capability identification field, a new digital certificate application identification field, and a number.
  • the certificate applicant request field may also include a digital certificate applicant random number. Does not include the digital certificate request message integrity check value.
  • step 302 of the embodiment when the digital certificate issuer receives the digital certificate application message, the digital certificate issuer sends the number to the number.
  • the certificate applicant sends a digital certificate confirmation message, where the digital certificate confirmation message specifically includes a digital certificate issuer identity field, a digital certificate generation type field, a new digital certificate issuance identification field, and a digital certificate applicant certificate field, and may also include a digital certificate.
  • the issuer random number and digital certificate confirm the message integrity check value.
  • the digital certificate confirms that the message integrity check value is generated by the digital certificate applicant random number and the digital certificate issuer random number.
  • the digital certificate confirmation message is encrypted in addition to the digital certificate confirmation message integrity check value.
  • the digital certificate applicant determines that the digital certificate confirmation message integrity check value is correct, and then determines the used digital certificate according to the digital certificate confirmation message.
  • the digital certificate applicant determines that the digital certificate issued by the digital certificate issuer has already been sent, it also sends the existing digital certificate information and also sends the signature of the existing digital certificate information by using the private key of the existing digital certificate. ;
  • the digital certificate issuer determines the certificate information that the applicant who receives the digital certificate needs to include in the new digital certificate of the application, or determines the digital certificate information and signature that the digital certificate applicant has received, and determines the digital certificate when the verification signature is invalid. Applicants are required to apply for a new digital certificate;
  • the digital certificate issuer determines that the digital certificate information and signature already existing by the digital certificate applicant are received, and when the verification signature is valid, it is determined that the digital certificate applicant does not need to apply for a new digital certificate.
  • the embodiment of the present application further provides a digital certificate automatic application device, a digital certificate issuing device, and a digital certificate automatic application system, and the principle of solving the problem is similar to a digital certificate automatic application method. Therefore, the implementation of these systems can be referred to the implementation of the method, and the repetition will not be repeated.
  • a first notification unit configured to notify a digital certificate issuer of a digital certificate generation method supported by the digital certificate application device
  • a second notification unit configured to determine that the digital certificate application device already contains the digital certificate issued by the digital certificate issuer, and notify the digital certificate issuer of the digital certificate information existing by the digital certificate applicant, if it is determined that the digital certificate application device does not have The digital certificate issued by the digital certificate issuer will notify the digital certificate issuer of the certificate information contained in the new digital certificate of the application;
  • a certificate determining unit configured to determine a digital certificate to be used according to the notification of the digital certificate issuer.
  • a first notification unit configured to select a digital certificate generation method from the digital certificate generation method supported by the digital certificate applicant and notify the digital certificate applicant according to the digital certificate generation method supported by the digital certificate applicant notified by the digital certificate applicant;
  • a second notification unit configured to: when the digital certificate applicant needs to apply for a new digital certificate, generate new digital certificate information according to the selected digital certificate generation method and the certificate information notified by the digital certificate applicant, and notify the digital certificate applicant to determine the digital certificate.
  • the applicant will notify the digital certificate applicant of the invalid digital certificate information.
  • the digital certificate applicant is configured to notify the digital certificate issuer of the digital certificate generation method supported by itself, and if it is determined that the digital certificate issued by the digital certificate issuer is already included, the digital certificate applicant has the digital certificate information already notified to the digital certificate information
  • the certificate issuer if it is determined that there is no digital certificate issued by the digital certificate issuer, will also need to notify the digital certificate issuer of the certificate information contained in the new digital certificate of the application, and determine the use according to the notification of the digital certificate issuer.
  • the digital certificate issuer is configured to select a digital certificate generation method from the digital certificate generation method supported by the digital certificate applicant and notify the digital certificate applicant to determine, when the digital certificate applicant needs to apply for a new digital certificate, according to the selected digital certificate generation method. And the certificate information notified by the digital certificate applicant generates new digital certificate information and notifies the digital certificate applicant to determine that the digital certificate applicant does not need to apply for a new digital certificate, and notifies the digital certificate applicant of the invalid digital certificate information.
  • the digital certificate applicant is an end station STA, an access point AP or other device, and the digital certificate issuer is a certificate authority center CA.
  • the present application provides a digital certificate application method and system for realizing digital certificate automatic application, update and issuance based on a digital certificate security mechanism in a network environment, which is realized by the same group of information exchange:
  • the digital certificate issuer automatically judges the certificate status of the digital certificate applicant and issues a valid digital certificate to the digital certificate applicant.
  • the digital certificate applicant of the present application may be the digital certificate application device, or may be any entity including the digital certificate application device, such as a network access point, a terminal device, etc.; the digital certificate issuer may be The digital certificate issuing device may also be any entity including the digital certificate issuing device, such as a digital certificate server.
  • embodiments of the present application can be provided as a method, system, or computer program Product.
  • the application can be in the form of an entirely hardware embodiment, an entirely software embodiment, or a combination of software and hardware.
  • the application can be in the form of a computer program product embodied on one or more computer-usable storage interfaces (including but not limited to disk storage, CD-ROM, optical storage, etc.) in which computer usable program code is embodied.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Abstract

本申请公开了一种数字证书自动申请方法和装置及系统,该方法包括:数字证书申请者将支持的数字证书产生方法通知数字证书颁发者,如果含有数字证书颁发者颁发的数字证书,还将已有的数字证书信息通知数字证书颁发者,否则,还将需要在申请的新数字证书中包含的证书信息通知数字证书颁发者;数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择数字证书产生方法并通知数字证书申请者,确定数字证书申请者需申请新数字证书时,产生新数字证书信息并通知数字证书申请者,否则,将无效的数字证书信息通知数字证书申请者;数字证书申请者根据数字证书颁发者的通知确定使用的数字证书。本申请可以实现数字证书的自动申请、更新和颁发。

Description

一种数字证书自动申请方法和装置及系统 本申请要求在 2012年 4月 25日提交中国专利局、 申请号为 201210124061.X、 发明名称为
"一种数字证书自动申请方法和装置及系统"的中国专利申请的优先权,其全部内容通过引用结 合在本申请中。 技术领域 本申请涉及网络安全技术领域, 尤其涉及一种数字证书自动申请方法和装置及系统。 背景技术 当前的网络环境中, 多种技术和设备都需要使用到数字证书, 利用数字证书可以实现 身份的鉴别和数据加密等功能, 但是如何对数字证书自动申请、 更新和颁发需要特别的方 式来支持。
以无线局域网技术为例, 无线局域网技术包含两大类的安全方案: 第一类, 无线局域 网筌别与保密基础结构 ( Wireless LAN Authentication and Privacy Infrastructure, WAPI ), 是中国无线局域网国家标准 GB15629. il 中提出的无线局域网安全解决方案; 第二类, 健 壮安全网络 ( Robust Security Network, RSN ), 是电气和电子工程师协会 ( Institute of Electrical and Electronics Engineers, IEEE )无线局域网标准 ΙΕΕΕ802.1Π中包含的安全解决 方案。 它们共同的特点是可以釆用基于公钥密码体系的数字证书方案实施鉴别过程, 在釆 用基于公钥密码体系的数字证书方案实施鉴别过程之前, 端站 (Station, STA ) 与接入点 ( Access Point, AP )作为数字证书申请者必须提前向作为数字证书颁发者的证书授证中心 ( Certificate Authority, 缩写为 CA ) 申请可以标识自己身份的数字证书, 然后将申请到的 数字证书安装到设备当中。
为了利用信息交换实现自动申请、 更新和颁发不同类型的数字证书, 数字证书申请者 在数字证书申请和更新过程中需要向数字证书颁发者提供哪些信息, 或者数字证书颁发者 在数字证书颁发过程中需要向数字证书申请者提供哪些信息, 将直接影响到无线局域网技 术安全机制能否有效进行。
但是如何利用信息交换自动申请、 更新和颁发数字证书方法不在无线局域网技术标准 的设计范围之内, 目前缺乏一种有效的自动申请、 更新和颁发数字证书方法。 发明内容 本申请提供一种数字证书自动申请方法和装置及系统, 用以实现数字证书的自动申 请、 更新和颁发。
本申请提供一种数字证书自动申请方法, 包括:
数字证书申请者将自身支持的数字证书产生方法通知数字证书颁发者, 如果数字证书 申请者确定已经含有所述数字证书颁发者颁发的数字证书, 所述数字证书申请者还将数字 证书申请者已有的数字证书信息通知数字证书颁发者, 如果确定没有所述数字证书颁发者 所颁发的数字证书, 所述数字证书申请者还将需要在申请的新数字证书中包含的证书信息 通知数字证书颁发者;
数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择数字证书产生方 法并通知数字证书申请者, 数字证书颁发者确定数字证书申请者需申请新数字证书时, 根 据选择的数字证书产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通 知数字证书申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息 通知数字证书申请者;
数字证书申请者根据数字证书颁发者的通知确定使用的数字证书。
本申请还提供一种数字证书申请装置, 包括:
第一通知单元, 用于将数字证书申请装置支持的数字证书产生方法通知数字证书颁发 者;
第二通知单元, 用于确定数字证书申请装置已经含有所述数字证书颁发者颁发的数字 证书, 将数字证书申请者已有的数字证书信息通知数字证书颁发者, 如果确定数字证书申 请装置没有所述数字证书颁发者所颁发的数字证书, 将需要在申请的新数字证书中包含的 证书信息通知数字证书颁发者;
证书确定单元, 用于根据数字证书颁发者的通知确定使用的数字证书。
本申请还提供一种数字证书颁发装置, 包括:
第一通知单元, 用于根据数字证书申请者通知的数字证书申请者支持的数字证书产生 方法, 从数字证书申请者支持的数字证书产生方法中选择数字证书产生方法并通知数字证 书申请者;
第二通知单元, 用于确定数字证书申请者需申请新数字证书时, 根据选择的数字证书 产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通知数字证书申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息通知数字证书申请 者。
本申请还提供一种数字证书自动申请系统, 包括:
数字证书申请者, 用于将自身支持的数字证书产生方法通知数字证书颁发者, 如果确 定已经含有所述数字证书颁发者颁发的数字证书, 还将数字证书申请者已有的数字证书信 息通知数字证书颁发者, 如果确定没有所述数字证书颁发者所颁发的数字证书, 还将需要 在申请的新数字证书中包含的证书信息通知数字证书颁发者, 并根据数字证书颁发者的通 知确定使用的数字证书;
数字证书颁发者, 用于从数字证书申请者支持的数字证书产生方法中选择数字证书产 生方法并通知数字证书申请者, 确定数字证书申请者需申请新数字证书时, 根据选择的数 字证书产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通知数字证书 申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息通知数字证 书申请者。
利用本申请提供的数字证书自动申请方法和装置系统具有以下有益效果: 通过信息交 换可以实现数字证书申请者自动申请不同类型的无线局域网数字证书; 数字证书申请者自 动更新不同类型的无线局域网数字证书; 数字证书颁发者自动判断数字证书申请者的证书 状态, 为数字证书申请者颁发有效的数字证书。 附图说明 图 1为本申请实施例 1中数字证书自动申请方法流程图;
图 2为本申请实施例 1中数字证书自动申请方法中消息内容示意图;
图 3为本申请实施例 2中数字证书自动申请方法流程图;
图 4为本申请实施例 2中数字证书自动申请方法中消息内容示意图。 具体实施方式 下面结合附图和实施例对本申请提供的数字证书自动申请方法和装置及系统进行更 详细地说明。
本申请实施例提供了一种数字证书自动申请方法和装置及系统, 能够安全有效实现数 字证书自动申请、 更新和颁发。 该方法包括:
数字证书申请者将自身支持的数字证书产生方法通知数字证书颁发者, 如果数字证书 申请者确定已经含有所述数字证书颁发者颁发的数字证书, 所述数字证书申请者还将数字 证书申请者已有的数字证书信息通知数字证书颁发者, 如果确定没有所述数字证书颁发者 所颁发的数字证书, 所述数字证书申请者还将需要在申请的新数字证书中包含的证书信息 通知数字证书颁发者;
数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择数字证书产生方 法并通知数字证书申请者, 数字证书颁发者确定数字证书申请者需申请新数字证书时, 根 据选择的数字证书产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通 知数字证书申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息 通知数字证书申请者;
数字证书申请者根据数字证书颁发者的通知确定使用的数字证书。
利用本申请实施例提供的数字证书自动申请方法, 可以实现数字证书的自动申请、 更 新和颁发, 在数字证书申请者没有数字证书颁发者颁发的数字证书时, 可以自动申请不同 类型的无线局域网数字证书, 在数字证书申请者没有数字证书或颁发的数字证书无效时, 数字证书颁发者在证书本地颁发策略允许向这个数字证书申请者颁发证书时, 自动判断数 字证书申请者的证书状态, 为数字证书申请者颁发有效的数字证书, 否则发送无效的数字 证书信息, 从而实现数字证书的自动申请、 更新和颁发, 从而保证无线局域网技术安全机 制能否有效进行。
本申请实施例对数字证书申请者和数字证书颁发者交互釆用的消息及交互方式不作 限定, 只要能够实现上述信息交互实现数字证书的自动申请、 更新和颁发, 都属于本申请 实施方式, 下面给出本申请优选的消息交互方式。
实施例 1
本实施例提供一种优选的消息交互方式, 如图 1所示, 数字证书自动申请方法, 具体 包括如下步骤:
步骤 101 , 数字证书申请者首先向数字证书颁发者发送数字证书产生能力消息, 所述 数字证书产生能力消息包括所述数字证书申请者支持的数字证书产生方法;
步骤 102, 数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择数字证 书产生方法, 并通过数字证书产生类型消息通知数字证书申请者;
步骤 103 , 数字证书申请者向数字证书颁发者发送数字证书申请消息, 其中, 如果数 字证书申请者确定已经含有所述数字证书颁发者颁发的数字证书, 所述数字证书申请消息 中携带数字证书申请者已有的数字证书信息, 如果数字证书申请者确定没有所述数字证书 颁发者所颁发的数字证书时, 所述数字证书申请消息中携带需要在申请的新数字证书中包 含的证书信息;
步骤 104, 数字证书颁发者向数字证书申请者发送数字证书确认消息, 其中, 数字证 书颁发者确定数字证书申请者需申请新数字证书时, 所述数字证书确认消息包含数字证书 颁发者根据选择的数字证书产生方法和数字证书申请消息包含的证书信息产生的新数字 证书信息, 数字证书颁发者确定数字证书申请者不需申请新数字证书时, 所述数字证书确 认消息携带无效的数字证书信息;
步骤 105 , 数字证书申请者接收数字证书颁发者发送的数字证书确认消息, 根据数字 证书确认消息确定使用的数字证书。
本实施例通过四个消息进行交互, 实现数字证书的自动申请、 更新和颁发。
优选地, 步骤 103中, 数字证书申请者确定已有所述数字证书颁发者所颁发的数字证 书时, 在利用数字证书申请消息发送已有的数字证书信息的同时, 还发送利用已有数字证 书的私钥对已有的数字证书信息的签名;
数字证书颁发者确定接收到数字证书申请者需要在申请的新数字证书中包含的证书 信息, 或确定接收到数字证书申请者已有的数字证书信息及签名, 且验证签名无效时, 确 定数字证书申请者需申请新数字证书; 数字证书颁发者确定接收到数字证书申请者已有的 数字证书信息及签名, 且验证签名有效时, 确定数字证书申请者不需申请新数字证书。
即数字证书颁发者在证书本地颁发策略允许向这个数字证书申请者颁发证书时, 为数 字证书申请者颁发新数字证书有两种情况:
1 )数字证书申请者没有数字证书颁发者颁发的数字证书, 从而实现数字证书申请; 2 )数字证书申请者有数字证书颁发者颁发的数字证书, 但该数字证书为无效的数字 证书, 从而实现数字证书更新。
为了实现本申请实施例提供的方式, 上述数字证书申请者和数字证书颁发者交互的消 息具体包括的字段这里不作限定, 只要能实现上述交互的目的即可, 优选地, 釆用本申请 下面实施例提供的方式。
如图 2所示, 本实施例中数字证书自动申请方法包括:
步骤 201 , 数字证书申请者向数字证书颁发者发送数字证书产生能力消息, 所述数字 证书产生能力消息包括: 数字证书申请者身份标识字段、 数字证书产生能力标识字段。
优选地, 数字证书产生能力消息还包括数字证书申请者随机数。
数字证书申请者身份标识字段标识数字证书申请者的身份, 数字证书产生能力标识字 段用于标识数字证书申请者支持的数字证书产生方法, 优选地, 数字证书产生能力标识字 段列出了数字证书申请者支持的所有数字证书产生的方法。
本实施例中数字证书产生能力标识字段标识数字证书产生方法的方式釆用但不限于 表 1所示方式:
表 1 数字证书产生能力标识字段
Figure imgf000007_0001
其中, 最低 1位 bitO取值为 1时表示支持单证书模式公私钥对本地生成能力数字证书 产生方法, 低 2位 bitl取值为 1时表示支持单证书模式 P12下发能力数字证书产生方法, 低 3位 bit2取值为 1时表示支持多证书模式公私钥对本地生成能力数字证书产生方法, 低 4位 bit3取值为 1时表示支持多证书模式 P12下发能力数字证书产生方法。 当多种能力同 时支持, 则对应能力标识位同时取值为 1 , 例如取值为 0x03即 00000011表示同时支持上 述单证书模式公私钥对本地生成能力和单证书模式 P12下发能力数字证书产生方法。 数字 证书申请者通过数字证书产生能力标识字段的取值表明支持的数字证书产生方法, 供数字 证书颁发者选择使用的数字证书产生方法。
步骤 202, 数字证书颁发者收到数字证书产生能力消息后构建数字证书产生类型消息 发送给数字证书申请者,所述数字证书产生类型消息包括:数字证书颁发者身份标识字段、 数字证书产生类型字段。
优选地, 数字证书产生类型消息还包括数字证书颁发者随机数。
数字证书颁发者身份标识字段标识数字证书颁发者的身份, 数字证书产生类型字段用 于数字证书颁发者选择的数字证书产生方法。 具体地, 数字证书颁发者收到数字证书申请 者发送的数字证书产生能力消息后, 根据数字证书申请者和自己共同支持的数字证书产生 方法, 或者本地策略来确认本次数字证书颁发所使用的数字证书产生方法, 并在数字证书 产生类型字段中标识。
本实施例中数字证书产生类型字段标识选择的数字证书产生方法的方式釆用但不限 于表 2所示的方式:
表 2 数字证书产生类型字段
Figure imgf000008_0001
最低 1位 bitO取值为 1时表示选择单证书模式公私钥对本地生成能力数字证书产生方 法, 低 2位 bitl取值为 1时表示选择单证书模式 P12下发能力数字证书产生方法, 低 3位 bit2取值为 1时表示选择多证书模式公私钥对本地生成能力数字证书产生方法,低 4位 bit3 取值为 1时表示选择多证书模式 P12下发能力数字证书产生方法。 数字证书颁发者通过数 字证书产生类型字段的取值表明选择的数字证书产生方法即数字证书产生类型, 以通知数 字证书申请者选择使用相同的数字证书产生类型。
步骤 203 , 数字证书申请者收到数字证书产生类型消息后, 向数字证书颁发者发送数 字证书申请消息, 所述数字证书申请消息具体包括新数字证书申请标识字段、 数字证书申 请者请求字段。
优选地, 数字证书产生类型消息还携带数字证书申请消息完整性校验值 , 数字证书申 请消息完整性校验值由数字证书申请者随机数和数字证书颁发者随机数产生的密钥对数 字证书申请消息中除申请消息完整性校验值外其它内容加密计算得到。
具体地, 数字证书申请者收到数字证书产生类型消息后, 根据数字证书产生类型消息 中的数字证书产生类型字段取值确认本次证书颁发所使用的数字证书产生方法, 并判断是 否需要申请新的数字证书, 在新数字证书申请标识字段中标识, 判断方式如下:
根据数字证书产生类型消息中的数字证书颁发者身份标识字段判断是否已经含有这 个数字证书颁发者颁发的数字证书, 如果数字证书申请者已经含有这个数字证书颁发者颁 发的数字证书, 则新数字证书申请标识字段标识不需要申请新的数字证书, 如果数字证书 申请者没有这个数字证书颁发者颁发的证书, 则新数字证书申请标识字段标识需要申请新 的数字证书。
新数字证书申请标识字段标识釆用但不限于表 3a所示形式。
表 3a新数字证书申请标识字段格式(布尔型)
Figure imgf000009_0001
数字证书申请者根据新数字证书申请标识字段中的标识, 确定数字证书申请者请求字 段的内容, 确定方式如下:
如果新数字证书申请标识字段中标识需要申请新的数字证书, 则数字证书申请者请求 字段中具体携带数字证书申请者需要在新申请的数字证书中包含的证书信息; 如果新数字 证书申请标识字段中标识不需要申请新的数字证书, 表示已经含有这个数字证书颁发者颁 发的证书, 则数字证书申请者请求字段具体携带数字证书申请者已有的数字证书信息和利 用已有数字证书的私钥对已有的数字证书信息的签名, 以使数字证书颁发者根据数字证书 申请者已有的数字证书信息和签名来判断数字证书申请者已有的数字证书是否有效。 优选地, 如表 4所示, 数字证书申请者请求字段包括证书信息字段和签名值字段; 数字证书申请者确定没有所述数字证书颁发者所颁发的数字证书时, 即需要向数字证 书颁发者申请数字证书, 证书信息字段具体携带数字证书申请者需要在申请的新数字证书 中包含的证书信息, 签名值字段无效;
数字证书申请者确定已有所述数字证书颁发者所颁发的数字证书时, 即不需要向数字 证书颁发者申请数字证书, 证书信息字段具体携带数字证书申请者已有的数字证书信息, 签名值字段携带利用已有数字证书的私钥对已有的数字证书信息的签名。
数字证书申请者构建数字证书申请消息发送给数字证书颁发者, 所述数字证书申请消 息包括: 新数字证书申请标识(参见表 3a )和数字证书申请者请求字段(参见表 4 )。
表 4: 数字证书申请者请求字段格式
I证书信息 I签名值 I 步骤 204 , 当数字证书颁发者收到数字证书申请消息后, 如果数字证书申请消息携带 数字证书申请消息完整性校验值, 首先判断数字证书申请消息完整性校验值是否正确, 如 果不正确则丢弃该消息, 如果正确向数字证书申请者发送数字证书确认消息, 如果数字证 书申请消息未携带数字证书申请消息完整性校验值 , 向数字证书申请者发送数字证书确认 消息, 所述数字证书确认消息具体包括新数字证书颁发标识字段、 数字证书申请者证书字 段。
优选地, 数字证书确认消息还包括数字证书确认消息完整性校验值, 数字证书确认消 息完整性校验值由数字证书申请者随机数和数字证书颁发者随机数产生的密钥对数字证 书确认消息中除数字证书确认消息完整性校验值外内容加密计算得到。
数字证书颁发者在证书本地颁发策略允许向这个数字证书申请者颁发证书且确定数 字证书申请者需申请新数字证书时, 新数字证书颁发标识字段标识颁发新的数字证书, 数 字证书申请者证书字段具体携带新数字证书信息;
数字证书颁发者在证书本地颁发策略允许向这个数字证书申请者颁发证书且确定数 字证书申请者不需申请新数字证书时, 或数字证书颁发者在证书本地颁发策略不允许向这 个数字证书申请者颁发证书时, 新数字证书颁发标识字段标识未颁发新的数字证书, 数字 证书申请者证书字段标识为无效。
优选地,数字证书颁发者的证书本地颁发策略允许向这个数字证书申请者颁发证书时, 判断是否需要为数字证书申请者颁发新的数字证书方法如下:
根据数字证书申请消息中的新数字证书申请标识字段判断数字证书申请者是否已经 含有这个数字证书颁发者颁发的证书, 如果数字证书申请者没有这个数字证书颁发者颁发 的证书, 则新数字证书颁发标识字段设置为需要颁发新的数字证书, 如果数字证书申请者 已经含有这个数字证书颁发者颁发的证书, 则数字证书颁发者根据数字证书申请者请求字 段中数字证书申请者已有的数字证书信息和签名来判断数字证书申请者已有的数字证书 是否有效; 如果数字证书申请者请求字段中数字证书申请者已有的数字证书信息有效, 表 示数字证书申请者已有有效的数字证书, 则新数字证书颁发标识字段设置为不需要颁发新 的数字证书, 如果数字证书申请者请求字段中数字证书申请者已有的数字证书信息无效, 表示数字证书申请者没有有效的数字证书, 则新数字证书颁发标识字段设置为需要颁发新 的数字证书。
新数字证书颁发标识字段釆用但不限于表 3b所示的标识方式。
表 3b 新数字证书颁发标识字段格式(布尔型)
Figure imgf000011_0001
根据新数字证书颁发标识字段中标识确定数字证书申请者证书字段的内容, 数字证书 申请者证书字段确定方法如下:
如果新数字证书颁发标识字段中标识需要颁发新的数字证书, 则数字证书申请者证书 字段中包含新颁发的数字证书, 数字证书申请者证书字段值有效, 字段值为根据数字证书 申请消息的数字证书申请者请求字段中包含的证书信息和选择的数字证书生成方法生成 的数字证书申请者证书; 如果新数字证书颁发标识字段中标识不需要申请新的数字证书, 表示数字证书申请者已经含有这个数字证书颁发者颁发的有效的数字证书, 则数字证书申 请者证书字段值标识为无效。
数字证书申请者证书字段值有效时, 数字证书申请者证书字段包括证书个数字段和数 字证书字段, 如表 5所示。
表 5 数字证书申请者证书字段格式
证书个数 数字证书 第一部分: 证书个数,表示一共颁发的证书的个数, 与选择的数字证书产生方法有关。 第二部分: 数字证书,表示颁发的数字证书的格式, 与选择的数字证书产生方法有关。 优选地, 如表 6所示, 数字证书字段具体包括标识证书类型、 证书标识、 长度和值字 表 6数字证书字段格式
证书类型 证书标识 长度 值 子字段一: 证书类型, 如表 7所示, 列举了颁发的新数字证书的证书类型。
表 7证书类型子字段格式
Figure imgf000012_0001
子字段二: 证书标识, 如表 8所示, 列举了新数字证书的编码方式。
表 8 证书标识子字段格式
Figure imgf000012_0002
子字段三: 长度, 表示 "值" 子字段的长度, 即新数字证书内容长度。
子字段四: 值, 表示完整的标识新数字证书的证书内容。
步骤 205 , 如果数字证书确认消息携带数字证书确认消息完整性校验值, 数字证书申 请者首先对发来的数字证书确认消息后判断数字证书确认消息完整性校验值是否正确, 如 果不正确则丢弃该消息, 如果正确进行处理获得使用的数字证书, 如果数字证书确认消息 未携带数字证书确认消息完整性校验值 , 数字证书申请者根据数字证书确认消息确定使用 的数字证书。
优选地, 数字证书申请者根据新数字证书颁发标识字段判断数字证书申请者证书字段 中是否含有数字证书颁发者颁发的新的数字证书, 如果新数字证书颁发标识字段标识颁发 新的数字证书, 则数字证书申请者安装数字证书申请者证书字段中含有的新的数字证书, 如果新数字证书颁发标识字段标识不需要颁发新的数字证书, 则数字证书申请者继续使用 已经含有这个数字证书颁发者颁发的数字证书。
需说明的是, 表 1和 2中示出的值、 标识位、 含义的对应关系, 表 3a和 3b中示出的 消息、 值、 含义的对应关系, 以及表 7和 8中示出的值、 含义的对应关系仅是举例, 在实 际实施时可根据实际需要进行调整, 例如, 表 7中的值 "0x00" 可改为对应含义 "AP证 书" 而值 "0x00" 可改为对应含义 "AS 证书"; 表 4-6 中字段的顺序是可以根据实际需 要进行调整的, 例如, 可将表 5中的 "证书个数" 及 "数字证书" 进行对调。 应当指出的是, 上述图 2对应的处理流程只是一种优选的实施方式。 如上所述, 本发 明实施例对上述数字证书申请者和数字证书颁发者交互的消息具体包括的字段不作限定, 只要能实现上述交互的目的即可。 因此, 当数字证书申请消息具体包括新数字证书申请标 识字段和数字证书申请者请求字段时, 其他三个消息的字段也可以是上述例举字段之外的 其他字段; 当数字证书确认消息具体包括新数字证书颁发标识字段和数字证书申请者证书 字段, 其他三个消息的字段也可以是上述例举字段之外的其他字段; 数字证书产生能力消 息包括数字证书申请者身份标识字段和数字证书产生能力标识字段时, 其他三个消息的字 段也可以是上述例举字段之外的其他字段; 数字证书产生类型消息包括数字证书颁发者身 份标识字段和数字证书产生类型字段时, , 其他三个消息的字段也可以是上述例举字段之 外的其他字段。
实施例 2
本实施例提供一种优选的消息交互方式, 如图 3所示, 数字证书自动申请方法, 具体 包括如下步骤:
步骤 301 , 数字证书申请者首先向数字证书颁发者发送数字证书申请消息; 所述数字证书申请消息包括所述数字证书申请者支持的数字证书产生方法, 如果数字 证书申请者确定已经含有所述数字证书颁发者颁发的数字证书, 所述数字证书申请消息中 还携带数字证书申请者已有的数字证书信息; 如果数字证书申请者确定没有所述数字证书 颁发者所颁发的数字证书时, 所述数字证书申请消息中还携带需要在申请的新数字证书中 包含的证书信息;
步骤 302, 数字证书颁发者向数字证书申请者发送数字证书确认消息;
所述数字证书确认消息包括数字证书颁发者从数字证书申请者支持的数字证书产生 方法中选择的数字证书产生方法, 数字证书颁发者确定数字证书申请者需申请新数字证书 时, 所述数字证书确认消息还包含数字证书颁发者根据选择的数字证书产生方法和数字证 书申请消息包含的证书信息产生的新数字证书信息, 数字证书颁发者确定数字证书申请者 不需申请新数字证书时, 所述数字证书确认消息还携带无效的数字证书信息;
步骤 303 , 数字证书申请者接收数字证书颁发者发送的数字证书确认消息, 根据数字 证书确认消息确定使用的数字证书。
本实施例通过两个消息进行交互, 实现数字证书的自动申请、 更新和颁发。
本实施例与实施例 1相比, 具体是将实施例 1的步骤 201与步骤 203合并进行进行步 骤 301 , 数字证书申请者仅向数字证书颁发者发送一次消息, 将实施例 1的步骤 202与步 骤 204合并进行步骤 302, 数字证书颁发者仅向数字证书申请者发送一次消息。
将实施例 1的步骤 201与步骤 203合并进行步骤 301时, 如图 4所示, 本实施例的步 骤 301中, 数字证书申请者向数字证书颁发者发送数字证书申请消息, 所述数字证书申请 消息具体包括数字证书申请者身份标识字段、 数字证书产生能力标识字段、 新数字证书申 请标识字段、 数字证书申请者请求字段, 还可以包括数字证书申请者随机数。 不包括数字 证书申请消息完整性校验值。上述各字段的具体内容详见实施例 1的描述,这里不再详述。
将实施例 1中的步骤 202并入步骤 204进行步骤 302时, 如图 4所示, 本实施例的步 骤 302中, 当数字证书颁发者收到数字证书申请消息后, 数字证书颁发者向数字证书申请 者发送数字证书确认消息, 所述数字证书确认消息具体包括数字证书颁发者身份标识字 段、 数字证书产生类型字段、 新数字证书颁发标识字段和数字证书申请者证书字段, 还可 以包括数字证书颁发者随机数和数字证书确认消息完整性校验值。 上述各字段的具体内容 详见实施例 1的描述, 这里不再详述。 所述数字证书确认消息完整性校验值由数字证书申 请者随机数和数字证书颁发者随机数产生的密钥对数字证书确认消息中除数字证书确认 消息完整性校验值外内容加密计算得到; 数字证书申请者接收到数字证书确认消息后, 确 定数字证书确认消息完整性校验值正确时, 再根据数字证书确认消息确定使用的数字证 书。
实施例 2中还存在其他与实施例 1侧相同或相似的技术特征, 例举如下。 应当指出的 是, 每个技术特征的详细描述可以参见实施例 1 , 这里不再赘述。
数字证书申请者确定已有所述数字证书颁发者所颁发的数字证书时, 在发送已有的数 字证书信息的同时, 还发送利用已有数字证书的私钥对已有的数字证书信息的签名;
数字证书颁发者确定接收到数字证书申请者需要在申请的新数字证书中包含的证书 信息, 或确定接收到数字证书申请者已有的数字证书信息及签名, 且验证签名无效时, 确 定数字证书申请者需申请新数字证书;
数字证书颁发者确定接收到数字证书申请者已有的数字证书信息及签名, 且验证签名 有效时, 确定数字证书申请者不需申请新数字证书。
基于同一发明构思, 本申请实施例中还提供了一种数字证书自动申请装置、 数字证书 颁发装置和数字证书自动申请系统, 由于该装置和系统解决问题的原理与一种数字证书自 动申请方法相似, 因此这些系统的实施可以参见方法的实施, 重复之处不再赘述。
本申请实施例的数字证书申请装置, 包括:
第一通知单元, 用于将数字证书申请装置支持的数字证书产生方法通知数字证书颁发 者;
第二通知单元, 用于确定数字证书申请装置已经含有所述数字证书颁发者颁发的数字 证书, 将数字证书申请者已有的数字证书信息通知数字证书颁发者, 如果确定数字证书申 请装置没有所述数字证书颁发者所颁发的数字证书, 将需要在申请的新数字证书中包含的 证书信息通知数字证书颁发者; 证书确定单元, 用于根据数字证书颁发者的通知确定使用的数字证书。
本申请实施例提供的数字证书颁发装置, 包括:
第一通知单元, 用于根据数字证书申请者通知的数字证书申请者支持的数字证书产生 方法, 从数字证书申请者支持的数字证书产生方法中选择数字证书产生方法并通知数字证 书申请者;
第二通知单元, 用于确定数字证书申请者需申请新数字证书时, 根据选择的数字证书 产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通知数字证书申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息通知数字证书申请 者。
本申请实施例提供的一种数字证书自动申请系统, 包括:
数字证书申请者, 用于将自身支持的数字证书产生方法通知数字证书颁发者, 如果确 定已经含有所述数字证书颁发者颁发的数字证书, 还将数字证书申请者已有的数字证书信 息通知数字证书颁发者, 如果确定没有所述数字证书颁发者所颁发的数字证书, 还将需要 在申请的新数字证书中包含的证书信息通知数字证书颁发者, 并根据数字证书颁发者的通 知确定使用的数字证书;
数字证书颁发者, 用于从数字证书申请者支持的数字证书产生方法中选择数字证书产 生方法并通知数字证书申请者, 确定数字证书申请者需申请新数字证书时, 根据选择的数 字证书产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通知数字证书 申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息通知数字证 书申请者。
优选地, 数字证书申请者为端站 STA、 接入点 AP或者其他设备, 数字证书颁发者为 证书授证中心 CA。
本申请提供了一种网络环境中基于数字证书安全机制的实现数字证书自动申请、 更新 和颁发的数字证书申请方法和系统, 利用同一组信息交换实现:
1 )数字证书申请者自动申请不同类型的无线局域网数字证书;
2 )数字证书申请者自动更新不同类型的无线局域网数字证书;
3 )数字证书颁发者自动判断数字证书申请者的证书状态, 为数字证书申请者颁发有 效的数字证书。
本申请所述数字证书申请者可以是所述数字证书申请装置, 也可以是包含了所述数字 证书申请装置的任一实体如网络接入点、 终端设备等; 所述数字证书颁发者可以是所述数 字证书颁发装置, 也可以是包含了所述数字证书颁发装置的任一实体, 如数字证书服务器 等。
本领域内的技术人员应明白, 本申请的实施例可提供为方法、 系统、 或计算机程序产 品。 因此, 本申请可釆用完全硬件实施例、 完全软件实施例、 或结合软件和硬件方面的实 施例的形式。 而且, 本申请可釆用在一个或多个其中包含有计算机可用程序代码的计算机 可用存储介盾 (包括但不限于磁盘存储器、 CD-ROM、 光学存储器等)上实施的计算机程 序产品的形式。
本申请是参照根据本申请实施例的方法、 设备 (系统)、 和计算机程序产品的流程图 和 /或方框图来描述的。 应理解可由计算机程序指令实现流程图和 /或方框图中的每一流 程和 /或方框、 以及流程图和 /或方框图中的流程和 /或方框的结合。 可提供这些计算机 程序指令到通用计算机、 专用计算机、 嵌入式处理机或其他可编程数据处理设备的处理器 以产生一个机器, 使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用 于实现在流程图一个流程或多个流程和 /或方框图一个方框或多个方框中指定的功能的 装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方 式工作的计算机可读存储器中, 使得存储在该计算机可读存储器中的指令产生包括指令装 置的制造品, 该指令装置实现在流程图一个流程或多个流程和 /或方框图一个方框或多个 方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上, 使得在计算机 或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理, 从而在计算机或其他 可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和 /或方框图一个 方框或多个方框中指定的功能的步骤。
尽管已描述了本申请的优选实施例, 但本领域内的技术人员一旦得知了基本创造性概 念, 则可对这些实施例作出另外的变更和修改。 所以, 所附权利要求意欲解释为包括优选 实施例以及落入本申请范围的所有变更和修改。
显然, 本领域的技术人员可以对本申请实施例进行各种改动和变型而不脱离本申请实 施例的精神和范围。 这样, 倘若本申请实施例的这些修改和变型属于本申请权利要求及其 等同技术的范围之内, 则本申请也意图包含这些改动和变型在内。

Claims

权 利 要 求
1、 一种数字证书自动申请方法, 其特征在于, 包括:
数字证书申请者将自身支持的数字证书产生方法通知数字证书颁发者, 如果数字证书 申请者确定已经含有所述数字证书颁发者颁发的数字证书, 所述数字证书申请者还将数字 证书申请者已有的数字证书信息通知数字证书颁发者, 如果确定没有所述数字证书颁发者 所颁发的数字证书, 所述数字证书申请者还将需要在申请的新数字证书中包含的证书信息 通知数字证书颁发者;
数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择数字证书产生方 法并通知数字证书申请者, 数字证书颁发者确定数字证书申请者需申请新数字证书时, 根 据选择的数字证书产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通 知数字证书申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息 通知数字证书申请者;
数字证书申请者根据数字证书颁发者的通知确定使用的数字证书。
2、 如权利要求 1所述的方法, 其特征在于,
数字证书申请者首先向数字证书颁发者发送数字证书申请消息, 所述数字证书申请消 息包括所述数字证书申请者支持的数字证书产生方法, 如果数字证书申请者确定已经含有 所述数字证书颁发者颁发的数字证书, 所述数字证书申请消息中还携带数字证书申请者已 有的数字证书信息; 如果数字证书申请者确定没有所述数字证书颁发者所颁发的数字证书 时, 所述数字证书申请消息中还携带需要在申请的新数字证书中包含的证书信息;
数字证书颁发者向数字证书申请者发送数字证书确认消息, 所述数字证书确认消息包 括数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择的数字证书产生方 法, 数字证书颁发者确定数字证书申请者需申请新数字证书时, 所述数字证书确认消息还 包含数字证书颁发者根据选择的数字证书产生方法和数字证书申请消息包含的证书信息 产生的新数字证书信息, 数字证书颁发者确定数字证书申请者不需申请新数字证书时, 所 述数字证书确认消息还携带无效的数字证书信息;
数字证书申请者接收数字证书颁发者发送的数字证书确认消息, 根据数字证书确认消 息确定使用的数字证书。
3、 如权利要求 1所述的方法, 其特征在于,
数字证书申请者首先向数字证书颁发者发送数字证书产生能力消息, 所述数字证书产 生能力消息包括所述数字证书申请者支持的数字证书产生方法;
数字证书颁发者从数字证书申请者支持的数字证书产生方法中选择数字证书产生方 法, 并通过数字证书产生类型消息通知数字证书申请者;
数字证书申请者向数字证书颁发者发送数字证书申请消息, 其中, 如果数字证书申请 者确定已经含有所述数字证书颁发者颁发的数字证书, 所述数字证书申请消息中携带数字 证书申请者已有的数字证书信息, 如果数字证书申请者确定没有所述数字证书颁发者所颁 发的数字证书时, 所述数字证书申请消息中携带需要在申请的新数字证书中包含的证书信 息;
数字证书颁发者向数字证书申请者发送数字证书确认消息, 其中, 数字证书颁发者确 定数字证书申请者需申请新数字证书时, 所述数字证书确认消息包含数字证书颁发者根据 选择的数字证书产生方法和数字证书申请消息包含的证书信息产生的新数字证书信息, 数 字证书颁发者确定数字证书申请者不需申请新数字证书时, 所述数字证书确认消息携带无 效的数字证书信息;
数字证书申请者接收数字证书颁发者发送的数字证书确认消息, 根据数字证书确认消 息确定使用的数字证书。
4、 如权利要求 2或 3所述的方法, 其特征在于,
数字证书申请者确定已有所述数字证书颁发者所颁发的数字证书时, 在发送已有的数 字证书信息的同时, 还发送利用已有数字证书的私钥对已有的数字证书信息的签名; 数字证书颁发者确定接收到数字证书申请者需要在申请的新数字证书中包含的证书 信息, 或确定接收到数字证书申请者已有的数字证书信息及签名, 且验证签名无效时, 确 定数字证书申请者需申请新数字证书;
数字证书颁发者确定接收到数字证书申请者已有的数字证书信息及签名, 且验证签名 有效时, 确定数字证书申请者不需申请新数字证书。
5、 如权利要求 4 所述的方法, 其特征在于, 所述数字证书申请消息具体包括新数字 证书申请标识字段和数字证书申请者请求字段;
数字证书申请者确定没有所述数字证书颁发者所颁发的数字证书时, 新数字证书申请 标识字段标识需要新数字证书, 数字证书申请者请求字段具体携带数字证书申请者需要在 申请的新数字证书中包含的证书信息;
数字证书申请者确定已有所述数字证书颁发者所颁发的数字证书时, 新数字证书申请 标识字段标识不需要新数字证书, 数字证书申请者请求字段具体携带数字证书申请者已有 的数字证书信息和利用已有数字证书的私钥对已有的数字证书信息的签名。
6、 如权利要求 5 所述的方法, 其特征在于, 数字证书申请者请求字段包括证书信息 字段和签名值字段;
数字证书申请者确定没有所述数字证书颁发者所颁发的数字证书时, 证书信息字段具 体携带数字证书申请者需要在申请的新数字证书中包含的证书信息, 签名值字段无效; 数字证书申请者确定已有所述数字证书颁发者所颁发的数字证书时, 证书信息字段具 体携带数字证书申请者已有的数字证书信息, 签名值字段携带利用已有数字证书的私钥对 已有的数字证书信息的签名。
7、 如权利要求 2或 3所述的方法, 其特征在于, 所述数字证书确认消息具体包括新 数字证书颁发标识字段和数字证书申请者证书字段;
数字证书颁发者确定数字证书申请者需申请新数字证书时, 新数字证书颁发标识字段 标识颁发新的数字证书, 数字证书申请者证书字段具体携带新数字证书信息;
数字证书颁发者确定数字证书申请者不需申请新数字证书时, 新数字证书颁发标识字 段标识未颁发新的数字证书, 数字证书申请者证书字段标识为无效。
8、 如权利要求 7 所述的方法, 其特征在于, 数字证书申请者证书字段包括证书个数 字段和数字证书字段, 所述数字证书字段具体包括标识新数字证书类型的证书类型字段、 用于标识新数字证书编码方式的证书标识字段、 标识新数字证书内容长度的长度字段和表 示新数字证书内容的值字段。
9、 如权利要求 2或 3所述的方法, 其特征在于, 用于通知数字证书申请者支持的数 字证书产生方法的数字证书产生能力消息或数字证书申请消息, 具体包括数字证书申请者 身份标识字段和数字证书产生能力标识字段, 所述数字证书产生能力标识字段用于标识数 字证书申请者支持的数字证书产生方法。
10、 如权利要求 2或 3所述的方法, 其特征在于, 用于通知数字证书颁发者选择的数 字证书产生方法的数字证书产生类型消息或数字证书确认消息, 具体包括数字证书颁发者 身份标识字段和数字证书产生类型字段;
数字证书产生类型字段用于数字证书颁发者选择的数字证书产生方法;
数字证书申请者具体根据数字证书颁发者身份标识字段, 确定是否已有所述数字证书 颁发者所颁发的数字证书。
11、 如权利要求 3所述的方法, 其特征在于,
数字证书申请者将自身支持的数字证书产生方法通知数字证书颁发者的同时, 还将数 字证书申请者产生的数字证书申请者随机数发送给数字证书颁发者;
数字证书颁发者将选择的数字证书产生方法通知数字证书申请者的同时, 还将数字证 书颁发者产生的数字证书颁发者随机数发送给数字证书申请者;
数字证书申请者向数字证书颁发者发送的数字证书申请消息, 还携带数字证书申请消 息完整性校验值, 所述数字证书申请消息完整性校验值由数字证书申请者随机数和数字证 书颁发者随机数产生的密钥对数字证书申请消息中除申请消息完整性校验值外其它内容 加密计算得到;
数字证书颁发者接收到数字证书申请消息, 确定数字证书申请消息完整性校验值正确 时, 再向数字证书申请者发送数字证书确认消息, 所述数字证书确认消息还包括数字证书 确认消息完整性校验值, 所述数字证书确认消息完整性校验值由数字证书申请者随机数和 数字证书颁发者随机数产生的密钥对数字证书确认消息中除数字证书确认消息完整性校 -验值外内容加密计算得到;
数字证书申请接收到数字证书确认消息后, 确定数字证书确认消息完整性校验值正确 时, 再根据数字证书确认消息确定使用的数字证书。
12、 如权利要求 2所述的方法, 其特征在于,
数字证书申请者向数字证书颁发者发送的数字证书申请消息还包括数字证书申请者 产生的数字证书申请者随机数;
数字证书颁发者接收到数字证书申请消息后, 再向数字证书申请者发送数字证书确认 消息, 所述数字证书确认消息还包括数字证书颁发者产生的数字证书颁发者随机数以及数 字证书确认消息完整性校验值, 所述数字证书确认消息完整性校验值由数字证书申请者随 机数和数字证书颁发者随机数产生的密钥对数字证书确认消息中除数字证书确认消息完 整性校验值外内容加密计算得到;
数字证书申请者接收到数字证书确认消息后, 确定数字证书确认消息完整性校验值正 确时, 再根据数字证书确认消息确定使用的数字证书。
13、 一种数字证书申请装置, 其特征在于, 包括:
第一通知单元, 用于将数字证书申请装置支持的数字证书产生方法通知数字证书颁发 者;
第二通知单元, 用于确定数字证书申请装置已经含有所述数字证书颁发者颁发的数字 证书, 将数字证书申请者已有的数字证书信息通知数字证书颁发者, 如果确定数字证书申 请装置没有所述数字证书颁发者所颁发的数字证书, 将需要在申请的新数字证书中包含的 证书信息通知数字证书颁发者;
证书确定单元, 用于根据数字证书颁发者的通知确定使用的数字证书。
14、 一种数字证书颁发装置, 其特征在于, 包括:
第一通知单元, 用于根据数字证书申请者通知的数字证书申请者支持的数字证书产生 方法, 从数字证书申请者支持的数字证书产生方法中选择数字证书产生方法并通知数字证 书申请者;
第二通知单元, 用于确定数字证书申请者需申请新数字证书时, 根据选择的数字证书 产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通知数字证书申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息通知数字证书申请 者。
15、 一种数字证书自动申请系统, 其特征在于, 包括: 数字证书申请者, 用于将自身支持的数字证书产生方法通知数字证书颁发者, 如果确 定已经含有所述数字证书颁发者颁发的数字证书, 还将数字证书申请者已有的数字证书信 息通知数字证书颁发者, 如果确定没有所述数字证书颁发者所颁发的数字证书, 还将需要 在申请的新数字证书中包含的证书信息通知数字证书颁发者, 并根据数字证书颁发者的通 知确定使用的数字证书;
数字证书颁发者, 用于从数字证书申请者支持的数字证书产生方法中选择数字证书产 生方法并通知数字证书申请者, 确定数字证书申请者需申请新数字证书时, 根据选择的数 字证书产生方法和数字证书申请者通知的证书信息产生新数字证书信息并通知数字证书 申请者, 确定数字证书申请者不需申请新数字证书时, 将无效的数字证书信息通知数字证 书申请者。
PCT/CN2013/074735 2012-04-25 2013-04-25 一种数字证书自动申请方法和装置及系统 WO2013159723A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
KR1020147033074A KR101617753B1 (ko) 2012-04-25 2013-04-25 디지털 인증서 자동 신청의 방법, 장치 및 시스템
US14/396,973 US9397840B2 (en) 2012-04-25 2013-04-25 Digital certificate automatic application method, device and system
EP13780700.4A EP2843873B1 (en) 2012-04-25 2013-04-25 Digital certificate automatic application method, device and system
JP2015507357A JP5856352B2 (ja) 2012-04-25 2013-04-25 デジタル証明書の自動申請方法、装置及びシステム

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210124061.XA CN102624531B (zh) 2012-04-25 2012-04-25 一种数字证书自动申请方法和装置及系统
CN201210124061.X 2012-04-25

Publications (1)

Publication Number Publication Date
WO2013159723A1 true WO2013159723A1 (zh) 2013-10-31

Family

ID=46564223

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/074735 WO2013159723A1 (zh) 2012-04-25 2013-04-25 一种数字证书自动申请方法和装置及系统

Country Status (6)

Country Link
US (1) US9397840B2 (zh)
EP (1) EP2843873B1 (zh)
JP (1) JP5856352B2 (zh)
KR (1) KR101617753B1 (zh)
CN (1) CN102624531B (zh)
WO (1) WO2013159723A1 (zh)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102624531B (zh) * 2012-04-25 2014-12-03 西安西电捷通无线网络通信股份有限公司 一种数字证书自动申请方法和装置及系统
US9843452B2 (en) * 2014-12-15 2017-12-12 Amazon Technologies, Inc. Short-duration digital certificate issuance based on long-duration digital certificate validation
US20160286390A1 (en) * 2015-03-27 2016-09-29 Qualcomm Incorporated Flexible and secure network management
CN108667609B (zh) * 2017-04-01 2021-07-20 西安西电捷通无线网络通信股份有限公司 一种数字证书管理方法及设备
ES2687717A1 (es) * 2017-04-26 2018-10-26 Universidad Carlos Iii De Madrid Método y dispositivo móvil para emitir certificados digitales a dispositivos electrónicos
CN111988291B (zh) * 2020-08-07 2022-06-28 北京江南天安科技有限公司 一种数字证书轻量化传输方法及系统
CN113114699B (zh) * 2021-04-26 2023-04-28 中国第一汽车股份有限公司 一种车辆终端身份证书申请方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101521883A (zh) * 2009-03-23 2009-09-02 中兴通讯股份有限公司 一种数字证书的更新和使用方法及系统
CN101815071A (zh) * 2010-04-01 2010-08-25 北京数码视讯科技股份有限公司 数字证书的申请方法、装置及系统
CN102118374A (zh) * 2009-12-30 2011-07-06 鸿富锦精密工业(深圳)有限公司 数字证书自动更新系统及方法
CN102624531A (zh) * 2012-04-25 2012-08-01 西安西电捷通无线网络通信股份有限公司 一种数字证书自动申请方法和装置及系统

Family Cites Families (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH118619A (ja) * 1997-06-18 1999-01-12 Hitachi Ltd 電子証明書発行方法及びシステム
JP2000041032A (ja) * 1998-07-22 2000-02-08 Hitachi Ltd 複数認証機関のポリシーに対応可能な認証書取得方式
US6675296B1 (en) * 1999-06-28 2004-01-06 Entrust Technologies Limited Information certificate format converter apparatus and method
JP2001305956A (ja) * 2000-04-26 2001-11-02 Nippon Telegr & Teleph Corp <Ntt> 公開鍵証明書発行方法及び認証局、利用者端末並びにプログラムを記録した記録媒体
AU2001287441A1 (en) * 2000-09-01 2002-03-13 724 Solutions International Srl Public key infrastructure systems and methods
US7047405B2 (en) * 2001-04-05 2006-05-16 Qualcomm, Inc. Method and apparatus for providing secure processing and data storage for a wireless communication device
EP1398708A4 (en) * 2001-06-19 2011-02-02 Fuji Xerox Co Ltd FORMAT CONTROL DEVICE AND METHOD FOR ELECTRONIC DOCUMENTS
JP4574957B2 (ja) * 2002-05-30 2010-11-04 株式会社東芝 グループ管理機関装置、利用者装置、サービス提供者装置及びプログラム
JP3928589B2 (ja) * 2003-06-12 2007-06-13 コニカミノルタビジネステクノロジーズ株式会社 通信システムおよび方法
JP2006059288A (ja) * 2004-08-24 2006-03-02 Toshiba Corp 電子申請システム、電子申請処理用のコンピュータ、電子申請処理プログラム
US20060048210A1 (en) * 2004-09-01 2006-03-02 Hildre Eric A System and method for policy enforcement in structured electronic messages
JP2006246272A (ja) * 2005-03-07 2006-09-14 Fuji Xerox Co Ltd 証明書取得システム
JP2007166552A (ja) * 2005-12-16 2007-06-28 Canon Inc 通信装置及び暗号通信方法
JP4055815B1 (ja) * 2006-11-06 2008-03-05 富士ゼロックス株式会社 情報処理装置、制御プログラム、情報処理システム
US20090003603A1 (en) * 2007-06-29 2009-01-01 Metabeam Corporation Platform Independent Networked Communications
JP5042109B2 (ja) * 2008-04-17 2012-10-03 株式会社リコー 電子証明書発行システム、電子証明書発行方法、及び電子証明書発行プログラム
JP4252620B1 (ja) * 2008-08-27 2009-04-08 グローバルサイン株式会社 サーバ証明書発行システム
CN101777978B (zh) * 2008-11-24 2012-05-30 华为终端有限公司 一种基于无线终端的数字证书申请方法、系统及无线终端
CN102045716B (zh) * 2010-12-06 2012-11-28 西安西电捷通无线网络通信股份有限公司 一种无线局域网中端站的安全配置方法和系统
US8856514B2 (en) * 2012-03-12 2014-10-07 International Business Machines Corporation Renewal processing of digital certificates in an asynchronous messaging environment
US20140317401A1 (en) * 2013-04-17 2014-10-23 Unetsystem, Inc. Server, system, and method for issuing mobile certificate
US9961073B2 (en) * 2013-09-30 2018-05-01 Digicert, Inc. Dynamic certificate generation on a certificate authority cloud

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101521883A (zh) * 2009-03-23 2009-09-02 中兴通讯股份有限公司 一种数字证书的更新和使用方法及系统
CN102118374A (zh) * 2009-12-30 2011-07-06 鸿富锦精密工业(深圳)有限公司 数字证书自动更新系统及方法
CN101815071A (zh) * 2010-04-01 2010-08-25 北京数码视讯科技股份有限公司 数字证书的申请方法、装置及系统
CN102624531A (zh) * 2012-04-25 2012-08-01 西安西电捷通无线网络通信股份有限公司 一种数字证书自动申请方法和装置及系统

Also Published As

Publication number Publication date
KR101617753B1 (ko) 2016-05-18
EP2843873A4 (en) 2015-05-27
US9397840B2 (en) 2016-07-19
JP5856352B2 (ja) 2016-02-09
EP2843873A1 (en) 2015-03-04
KR20150011364A (ko) 2015-01-30
JP2015518697A (ja) 2015-07-02
EP2843873B1 (en) 2018-11-28
CN102624531B (zh) 2014-12-03
CN102624531A (zh) 2012-08-01
US20150333916A1 (en) 2015-11-19

Similar Documents

Publication Publication Date Title
WO2013159723A1 (zh) 一种数字证书自动申请方法和装置及系统
JP4712871B2 (ja) サービス提供者、端末機及びユーザー識別モジュールの包括的な認証と管理のための方法及びその方法を用いるシステムと端末装置
US9887838B2 (en) Method and device for secure communications over a network using a hardware security engine
JP4750695B2 (ja) コンテンツ提供システム、情報処理装置及びメモリカード
CN109479049B (zh) 用于密钥供应委托的系统、设备和方法
WO2018177045A1 (zh) 数字证书管理方法及设备
WO2015165325A1 (zh) 终端安全认证方法、装置及系统
WO2016201732A1 (zh) 一种虚拟sim卡参数管理方法、移动终端及服务器
JP5399404B2 (ja) 一方向アクセス認証の方法
TW201205333A (en) Transaction auditing for data security devices
EP1754167A1 (en) Method and apparatus for transmitting rights object information between device and portable storage
JP7292263B2 (ja) デジタル証明書を管理するための方法および装置
CN110198295A (zh) 安全认证方法和装置及存储介质
CN110912920A (zh) 数据处理方法、设备及介质
CN109361681B (zh) 国密证书认证方法、装置及设备
KR20110083886A (ko) 휴대용 단말기에서 다른 휴대용 단말기를 인증하는 장치 및 방법
CN109962777A (zh) 许可区块链系统中的密钥生成、获取密钥的方法及设备
CN110635901A (zh) 用于物联网设备的本地蓝牙动态认证方法和系统
CN111314269B (zh) 一种地址自动分配协议安全认证方法及设备
EP4270857A1 (en) Identity authentication method and apparatus, and storage medium, program and program product
US20160210596A1 (en) Method, device and system for controlling presentation of application
JP2016019233A (ja) 通信システム、通信装置、鍵管理装置、及び通信方法
WO2013075674A1 (zh) 一种数字内容传输的方法、系统及装置
CN115714678A (zh) 终端设备的认证方法及装置
WO2019037422A1 (zh) 密钥及密钥句柄的生成方法、系统及智能密钥安全设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13780700

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2015507357

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 14396973

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2013780700

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20147033074

Country of ref document: KR

Kind code of ref document: A