CN121619102A - Certificate issuing method and related device - Google Patents

Certificate issuing method and related device

Info

Publication number
CN121619102A
CN121619102A CN202411186320.0A CN202411186320A CN121619102A CN 121619102 A CN121619102 A CN 121619102A CN 202411186320 A CN202411186320 A CN 202411186320A CN 121619102 A CN121619102 A CN 121619102A
Authority
CN
China
Prior art keywords
network device
challenge
result
certificate
remote
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202411186320.0A
Other languages
Chinese (zh)
Inventor
刘春池
潘伟
王海光
耿峰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN202411186320.0A priority Critical patent/CN121619102A/en
Priority to PCT/CN2025/071975 priority patent/WO2026045076A1/en
Publication of CN121619102A publication Critical patent/CN121619102A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

A certificate issuing method is used for improving the security of a certificate issuing process. In the certificate issuing method, when the certificate applying apparatus applies for issuing a certificate, the certificate issuing apparatus returns a challenge of which the challenge type is remote certification to the certificate applying apparatus to instruct the certificate applying apparatus to complete the challenge by performing the remote certification. And under the condition that the certificate issuing equipment verifies that the certificate applying equipment successfully completes the challenge, the certificate issuing equipment issues the certificate. When the certificate application device executes the remote certification, the remote certification server can verify the credibility of the certificate application device, and the remote certification process can be completed only after the credibility of the certificate application device passes the verification. Therefore, under the condition that the certificate applying equipment completes the challenge, the certificate issuing equipment can determine that the credibility of the certificate applying equipment is verified, so that the certificate issuing equipment is ensured to issue a certificate for the credible equipment, and the safety of the certificate issuing process is further ensured.

Description

Certificate issuing method and related device
Technical Field
The application relates to the technical field of computer security, in particular to a certificate issuing method and a related device.
Background
An Automated CERTIFICATE MANAGEMENT Environment (ACME) is a protocol for automating the processing of digital certificate issuing requests. Based on ACME, a certificate authority (CERTIFICATE AUTHORITY, CA) automatically verifies the domain name ownership of the certificate applicant, thereby issuing the corresponding certificate to the certificate applicant, so that the certificate issuing process does not require manual intervention.
In the process of realizing certificate issuing based on ACME, an ACME server device serving as a verifier can send challenges to an ACME client device serving as a certificate applicant, and issues a certificate for the ACME client device after the ACME client device successfully completes challenge. Wherein the challenge sent by the ACME server device is actually to verify ownership of a certain identifier (such as a domain name or company name) by the ACME client device. Thus, the condition for the ACME server device to issue a certificate is to verify that the ACME client device has ownership of a certain identifier.
Currently, certificate issuing is realized based on ACME, only the ACME client device can be proved to have ownership of a certain identifier, and the ACME client device itself cannot be proved to be safe and reliable, so that the security of the certificate issuing process is low.
Disclosure of Invention
The application provides a certificate issuing method and a related device, which can improve the safety of a certificate issuing process.
In a first aspect, a certificate issuing method is provided, applied to a first network device as a certificate issuing device. The certificate issuing method comprises the steps that a first network device receives a certificate application message sent by a second network device, wherein the certificate application message is used for applying for issuing a certificate.
In response to receiving the credential application message, the first network device sends a challenge message to the second network device, the challenge message for instructing the second network device to complete the challenge by performing the remote attestation. That is, the first network device instructs the second network device to complete the first network device specified challenge by sending a challenge message, and the first network device specified challenge is to perform remote attestation.
After the second network device completes the challenge, the first network device obtains a challenge result. Wherein the challenge result comprises a remote attestation result for indicating a result of the second network device performing the remote attestation process. Typically, the remote attestation result is generated by the remote attestation server after verifying the trustworthiness of the second network device for attesting to the trustworthiness of the second network device.
In this way, the first network device can further verify the obtained challenge result, and in the case where the challenge result passes the verification, the first network device issues a certificate to the second network device.
In the scheme, when the certificate applying device applies for issuing the certificate, the certificate issuing device returns a challenge with a challenge type of remote certification to the certificate applying device so as to instruct the certificate applying device to complete the challenge by executing the remote certification. And under the condition that the certificate issuing equipment verifies that the certificate applying equipment successfully completes the challenge, the certificate issuing equipment issues the certificate. When the certificate application device executes the remote certification, the remote certification server can verify the credibility of the certificate application device, and the remote certification process can be completed only after the credibility of the certificate application device passes the verification. Therefore, under the condition that the certificate applying equipment completes the challenge, the certificate issuing equipment can determine that the credibility of the certificate applying equipment is verified, so that the certificate issuing equipment is ensured to issue a certificate for the credible equipment, and the safety of the certificate issuing process is further ensured.
In one possible implementation, the remote attestation result includes attributes of the second network device. In the process of verifying the challenge result, the first network device verifies the authenticity of the remote proof result. For example, the first network device verifies the digital signature in the remote proof result through a digital signature verification manner, so as to verify the authenticity of the remote proof result.
When the remote certification result passes the verification, the first network device verifies whether the attribute of the second network device meets the certificate issuing condition based on the remote certification result. And, in the event that the attribute of the second network device meets the certificate issuance condition, the first network device determines that the challenge result is validated.
In the scheme, the certificate issuing equipment further verifies whether the attribute of the certificate application equipment included in the remote proof result accords with the certificate issuing condition or not besides verifying the authenticity of the remote proof result, so that the verification range is expanded to a series of attributes of the certificate application equipment, the certificate issuing equipment can conveniently reject to issue certificates to the certificate application equipment with the attribute which does not accord with the condition, and the safety of the certificate issuing process is further improved. In addition, the certificate issuing equipment acquires the attribute of the certificate application equipment from the remote verification result of the authenticity passing verification, so that the certificate issuing equipment can ensure the authenticity of the acquired attribute of the certificate application equipment, the certificate issuing equipment is prevented from acquiring the forged attribute of the certificate application equipment, and the reliability of the attribute verification process of the certificate application equipment is ensured.
In one possible implementation, the attribute of the second network device includes a plurality of attribute identifications indicating different attributes of the second network device. For example, one of the plurality of attribute identifications is information indicating a certain hardware of the second network device, and another one of the plurality of attribute identifications is a version number indicating a certain software of the second network device. The certificate issuance condition includes at least one attribute condition for indicating that the attribute identification of the second network device is to satisfy the condition.
In the process of verifying whether the attribute of the second network device meets the certificate issuing condition, the first network device firstly determines at least one attribute identifier which needs to meet the attribute condition in a plurality of attribute identifiers based on the at least one attribute condition. The first network device then determines whether the at least one attribute identification satisfies a corresponding attribute condition, respectively, to determine whether the attribute of the second network device meets a certificate issuance condition.
In one possible implementation, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number.
Therefore, the first network device determines the version number of the target software in the second network device in the plurality of attribute identifiers, and judges whether the version number of the target software is not lower than a preset version number. And if the version number of the target software is lower than the preset version number, the attribute of the second network device is not in accordance with the certificate issuing condition.
For example, in the case that the certificate issuing condition includes that the version number of the target software is not lower than the preset version number, if the version number of the target software in the second network device is lower than the preset version number, the target software in the second network device is not updated in time and is at risk of being easily attacked, so that the first network device determines that the challenge result of the first network device is not verified, and then refuses to issue a certificate to the second network device, so as to avoid the security risk brought after issuing the certificate to the second network device.
In one possible implementation, the challenge message sent by the first network device to the second network device includes a challenge type and a challenge identifier, where the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote attestation, and the challenge identifier is used to identify a current challenge task to be completed by the second network device.
The challenge result obtained by the first network device comprises a remote proving result, a challenge identifier and signature information, wherein the signature information is obtained by signing the remote proving result and the challenge identifier by the second network device. That is, the second network device, after obtaining the remote attestation result, simultaneously feeds back the remote attestation result and the challenge identification to the first network device to declare that the second network device completes the challenge specified by the first network device.
In one possible implementation, to facilitate the first network device determining the challenge type supported by the second network device, the credential application message sent by the second network device to the first network device is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message sent by the first network device to the second network device includes a challenge type and a challenge identifier, where the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote attestation, and the challenge identifier is used to identify a current challenge task to be completed by the second network device. The challenge message is used to instruct the second network device to perform remote attestation with the challenge identification as part of the attribute proof.
The verification of the challenge result specifically comprises that the authenticity of the remote proving result is verified, and the remote proving result comprises a challenge identifier.
That is, the second network device, when performing the remote attestation process, needs to submit the challenge identifier provided by the first network device to the remote attestation server as proof of the attribute, thereby obtaining a remote attestation result including the challenge identifier.
In one possible implementation, the challenge message includes a remote attestation server (Verifier) list that indicates remote attestation servers that the second network device is able to select when performing remote attestation. The remote proving server list comprises one or more remote proving servers, and the remote proving servers in the remote proving server list are all remote proving servers trusted by the first network device.
In one possible implementation, the first network device may obtain the challenge result in a variety of ways. For example, the first network device receives the challenge result sent by the second network device. Or the first network device receives a challenge completion notification sent by the second network device, and obtains a challenge result based on the challenge completion notification, wherein the challenge completion notification is used for indicating a position where the challenge result is stored. That is, after generating the challenge result based on the remote attestation result, the second network device does not directly transmit the challenge result to the first network device, but stores the challenge result in a specific location, and notifies the first network device to acquire the challenge result from the specific location.
In one possible implementation, the first network device can act as a proxy device to assist the second network device in performing the remote attestation process to obtain the challenge result from the remote attestation server. Specifically, the first network device receives attribute evidence sent by the second network device. The first network device then sends the attribute proof to a remote attestation server that verifies the attribute proof and generates a remote attestation result. After the remote certification server generates the remote certification result, the first network device receives a challenge result from the remote certification server, wherein the challenge result is the remote certification result generated by the remote certification server.
In a second aspect, a certificate issuing method is provided, which is applied to a second network device as a certificate applying device. The certificate issuing method comprises the steps that a second network device sends a certificate application message to a first network device, the certificate application message is used for applying for issuing certificates, the second network device receives a challenge message sent by the first network device, the challenge message is used for indicating the second network device to finish challenges through executing remote certification, and the second network device receives the certificates issued by the first network device under the condition that the second network device finishes the challenges and the challenge result of the second network device passes verification, wherein the challenge result comprises a remote certification result, and the remote certification result is used for indicating the second network device to execute the result of the remote certification process.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by signing the remote attestation result and the challenge content by the second network device.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used to identify a current challenge task to be completed by the second network device, and the challenge message is used to indicate that the second network device performs remote attestation using the challenge identifier as part of the attribute evidence.
The challenge result is verified, including that the authenticity of the remote proof result is verified and the remote proof result includes the challenge identification.
In a possible implementation, the challenge message includes a remote attestation server list, where the remote attestation server list is used to instruct the second network device to select a remote attestation server that can be selected when performing remote attestation, and the certificate issuing method further includes the second network device selecting one remote attestation server from the remote attestation server list to perform a remote attestation process, and obtaining a remote attestation result.
In one possible implementation, after the second network device completes the challenge, the certificate issuing method further comprises the step that the second network device sends a challenge result to the first network device, or the second network device sends a challenge completion notification to the first network device, wherein the challenge completion notification is used for indicating a position where the challenge result is stored.
In one possible implementation, the certificate issuing method further comprises the second network device sending the attribute evidence to the first network device, wherein the first network device is configured to forward the attribute evidence to a remote attestation server, and the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result.
In a third aspect, a certificate issuing apparatus is provided, the certificate issuing apparatus is deployed on a first network device, and the certificate issuing apparatus includes a receiving module configured to receive a certificate application message sent by a second network device, where the certificate application message is used to apply for issuing a certificate, a sending module configured to send a challenge message to the second network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, the receiving module is further configured to obtain a challenge result after the second network device completes the challenge, where the challenge result includes a remote attestation result, where the remote attestation result is used to instruct the second network device to perform a result of the remote attestation process, and the sending module is further configured to issue a certificate to the second network device if the challenge result passes verification.
In one possible implementation, the remote attestation result comprises an attribute of the second network device, and the certificate issuing apparatus further comprises a processing module, wherein the processing module is used for verifying the authenticity of the remote attestation result, verifying whether the attribute of the second network device meets the certificate issuing condition based on the remote attestation result when the remote attestation result is verified, and determining that the challenge result is verified when the attribute of the second network device meets the certificate issuing condition.
In one possible implementation, the attribute of the second network device comprises a plurality of attribute identifiers, the plurality of attribute identifiers are used for indicating different attributes of the second network device, the certificate issuing condition comprises at least one attribute condition, the at least one attribute condition is used for indicating a condition to be met by the attribute identifier of the second network device, the processing module is specifically used for determining at least one attribute identifier which needs to meet the attribute condition in the plurality of attribute identifiers by the first network device based on the at least one attribute condition, and the first network device is used for determining whether the at least one attribute identifier meets the corresponding attribute condition or not respectively so as to determine whether the attribute of the second network device meets the certificate issuing condition or not.
In one possible implementation, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by the second network device by signing the remote attestation result and the challenge identifier.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list for indicating remote attestation servers that the second network device is able to select when performing remote attestation.
In one possible implementation, the receiving module is further configured to receive a challenge result sent by the second network device, or receive a challenge completion notification sent by the second network device, and obtain the challenge result based on the challenge completion notification, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the receiving module is further configured to receive the attribute evidence sent by the second network device, the sending module is further configured to send the attribute evidence to a remote attestation server, the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result, and the receiving module is further configured to receive the challenge result from the remote attestation server.
In a fourth aspect, a certificate applying apparatus is provided, where the certificate applying apparatus is disposed on a second network device, and the certificate applying apparatus includes a sending module configured to send a certificate applying message to a first network device, where the certificate applying message is used to apply for issuing a certificate, a receiving module configured to receive a challenge message sent by the first network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, and receive, when the second network device completes the challenge and a challenge result of the second network device passes verification, a certificate issued by the first network device, where the challenge result includes a remote attestation result, and where the remote attestation result is used to instruct the second network device to perform a result of a remote attestation process.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by signing the remote attestation result and the challenge content by the second network device.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list, where the remote attestation server list is used to instruct the second network device to select a remote attestation server that can be selected when performing remote attestation, and the sending module is further used to select, by the second network device, one remote attestation server from the remote attestation server list to perform a remote attestation process, and obtain a remote attestation result.
In one possible implementation, the sending module is further configured to send a challenge result to the first network device, or send a challenge completion notification to the first network device, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the sending module is further configured to send the attribute evidence to a first network device, where the first network device is configured to forward the attribute evidence to a remote attestation server, and the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result.
A fifth aspect of the application provides a network device comprising a processor and a memory, wherein the memory is for storing program code, the processor being for invoking the program code in the memory to cause the network device to perform the method as in any of the implementations of the first to second aspects.
A sixth aspect of the present application provides a certificate issuing system comprising a first network device with apparatus as in any of the implementations of the third aspect deployed, and a second network device with apparatus as in any of the implementations of the fourth aspect deployed.
A seventh aspect of the application provides a computer readable storage medium storing instructions that when run on a computer cause the computer to perform a method as any one of the embodiments of the first to second aspects.
An eighth aspect of the application provides a computer program product which, when run on a computer, causes the computer to perform the method as any one of the embodiments of the first to second aspects.
A ninth aspect of the application provides a chip comprising one or more processors. Some or all of the processor is configured to read and execute computer instructions stored in the memory to perform the method of any of the possible implementations of any of the aspects described above. Optionally, the chip further comprises a memory. Optionally, the chip further comprises a communication interface, and the processor is connected with the communication interface. The communication interface is used for receiving data and/or information to be processed, and the processor acquires the data and/or information from the communication interface, processes the data and/or information and outputs a processing result through the communication interface. Optionally, the communication interface is an input-output interface or a bus interface. The method provided by the application is realized by one chip or a plurality of chips in a cooperative manner.
The solutions provided in the third aspect to the ninth aspect are used to implement or cooperatively implement the methods provided in the first aspect to the second aspect, so that the same or corresponding beneficial effects as those in the first aspect to the second aspect can be achieved, and are not described herein.
Drawings
FIG. 1A is a schematic diagram of a remote attestation model provided by the present application;
FIG. 1B is a schematic diagram of challenge types and identifiers of ACME existing in the related art;
FIG. 2 is a schematic flow chart of a method for issuing certificates;
fig. 3 is a schematic flow chart of verifying a challenge result by a first network device according to the present application;
fig. 4 is a schematic flow chart of applying a certificate by a second network device based on a remote certification result obtained in advance;
fig. 5 is a schematic flow chart of a second network device according to the present application, after obtaining an instruction, performing a remote attestation process to apply for a certificate;
FIG. 6 is a flowchart of a second network device according to another embodiment of the present application, after obtaining an instruction, performing a remote attestation process to apply for a certificate;
fig. 7 is a schematic flow chart of a first network device as a proxy device for assisting a second network device in completing a remote certification process according to the present application;
FIG. 8 is a schematic diagram of a certificate issuing apparatus according to the present application;
Fig. 9 is a schematic structural diagram of a certificate applying apparatus provided by the present application;
fig. 10 is a schematic structural diagram of a network device according to the present application.
Detailed Description
In order to make the objects, technical solutions and advantages of the present application more apparent, embodiments of the present application will be described below with reference to the accompanying drawings, and it is apparent that the described embodiments are only some embodiments of the present application, not all embodiments. As a person skilled in the art can know, with the appearance of a new application scenario, the technical scheme provided by the embodiment of the application is also applicable to similar technical problems.
The terms first, second and the like in the description and in the claims and in the above-described figures, are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order.
In order to facilitate understanding, some technical terms related to the present application are described below.
(1) Digital certificate
A digital certificate (hereinafter referred to as a certificate) refers to a digital certificate that marks the identity information of each party in communication in internet communication. A digital certificate is essentially a file issued by a CA that contains public key owner information and a public key. The simplest certificate typically contains a public key, certificate name, and the digital signature of the CA.
(2) Remote attestation
The network equipment (such as a switch, a server, a gateway or terminal equipment and other equipment) sends the security attribute (such as a measurement value of software and hardware, configuration information and node state) of the network equipment to the remote proving equipment through a certain format and an interaction flow, and the remote proving equipment verifies according to a certain strategy to finally prove whether the network equipment is credible or not. In addition, in order to ensure the security of devices and communications throughout the remote attestation protocol interaction process, a certificate mechanism (e.g., a certificate application) must be pre-deployed to support the necessary operations such as checksum viewing of the certificates during the protocol interaction process.
Referring to fig. 1A, fig. 1A is a schematic diagram of a remote certification model according to the present application. As shown in fig. 1A, for a server, a gateway, a terminal device, or other devices that need remote attestation, all may be abstracted to be an attestation Platform (Attest Platform). During the process of the attach Platform, the calculation and recording of the metric values are performed from the TPM trusted Platform module (Trusted Platform Module, TPM) to the basic input output system (Basic Input Output System, BIOS), operating system (Kernel), application (APP). In addition, the Attest Platform interacts with an external certificate authority (Certification Authority, CA) to perform certificate applications and the like. Remote attestation may be performed between the Attest Platform and the remote attestation server (ATTEST SERVER) using a challenge-response approach. That is, the remote attestation device actively initiates a challenge request for attributes of the Attest Platform, and in response to the challenge request, encrypts and signs the attributes such as the metrics and the like recorded by the Attest Platform and information (e.g., device log) for attesting the trustworthiness of the attributes using the certificate applied from the CA, and returns the encrypted and signed security attributes to the remote attestation server. That is, attest Platform is to submit attribute evidence to a remote attestation server for verification. In this way, the remote attestation device and the CA interact to verify that the certificate of Attest Platform is legitimate and to decrypt and verify the security attributes received from Attest Platform. In the case that the security attribute sent by the Attest Platform is verified, the remote attestation server sends a remote attestation result to the Attest Platform.
(3) Digital signature
A digital signature (also called public key digital signature) is a digital string that cannot be forged by others only the signer of the information, and is also a valid proof of the authenticity of the information sent by the signer of the information. Digital signatures are a common physical signature written on paper-like, essentially implemented using techniques in the field of public key cryptography, and are used to authenticate digital information.
When generating a digital signature, a signer processes text by using a hash function to generate a text digest, then encrypts the text digest by using a private key of the signer, and the encrypted digest is used as the digital signature of the text.
In general, digital signatures have two functions, namely, determining that text is indeed signed and sent out by a signer, because others cannot impersonate the signer's signature, and determining the integrity of the text. Because the digital signature is characterized in that it represents a feature of text, if the text changes, the value of the digital signature will also change. That is, different text will get different digital signatures.
(4) Digital signature verification mode
The digital signature verification method is a method for determining the integrity of a text by verifying a digital signature of the text.
Specifically, when verifying the digital signature of the text, the signer first calculates a text digest from the acquired text using the same hash function as the signer, and then decrypts the digital signature transmitted by the signer using the public key to obtain the text digest. If the text abstract calculated by the signer through the hash function is the same as the text abstract obtained by decryption, the signer can confirm that the obtained text is truly complete.
Currently, in automatically issuing a certificate for an ACME client device by an ACME server device, the condition for the ACME server device to issue a certificate is to verify that the ACME client device has ownership of a certain identifier. Thus, implementing certificate issuance based on ACME can only prove that an ACME client device has ownership of a certain identifier, and cannot prove that the ACME client device itself is safe and trusted, resulting in lower security of the certificate issuance process.
Specifically, referring to fig. 1B, fig. 1B is a schematic diagram of challenge types and identifiers of ACME existing in the related art. As shown in fig. 1B, a plurality of AMCE challenge types have been defined in the prior art, and each ACME challenge type typically has a corresponding identifier. In the prior art, however, the type of challenge returned by the ACME server device to the ACME client device is typically to verify whether the ACME client device has ownership of a certain identifier. For example, in the case where the challenge type is hypertext transfer protocol (Hypertext Transfer Protocol, HTTP) -01, the ACME server device is to verify whether the ACME client has ownership of a certain web page. For another example, in the case where the challenge type is Domain name system (Domain NAME SYSTEM, DNS) -01, the ACME server device is to verify whether the ACME client has ownership of DNS.
In view of this, upon the certificate applying apparatus applying for issuing a certificate, the certificate applying apparatus returns a challenge whose challenge type is a remote certification (and whose challenge type is newly defined) to the certificate applying apparatus to instruct the certificate applying apparatus to complete the challenge by performing the remote certification. And under the condition that the certificate issuing equipment verifies that the certificate applying equipment successfully completes the challenge, the certificate issuing equipment issues the certificate. When the certificate application device executes the remote certification, the remote certification server can verify the credibility of the certificate application device, and the remote certification process can be completed only after the credibility of the certificate application device passes the verification. Therefore, under the condition that the certificate applying equipment completes the challenge, the certificate issuing equipment can determine that the credibility of the certificate applying equipment is verified, so that the certificate issuing equipment is ensured to issue a certificate for the credible equipment, and the safety of the certificate issuing process is further ensured.
Specifically, the certificate issuing method provided by the application can be applied to the certificate application scene of various network devices (such as switches, gateways, routers, hubs, servers, personal computers or smart phones and other devices with certificate application requirements), so that only network devices meeting security requirements can obtain certificates.
For example, in a campus scenario, each worker holds a terminal device for checking products, and the terminal device is a network device attributed to a company. To ensure the security of the terminal device, companies will generally continuously update the verification software in the terminal device. But since the terminal device is actually operated by a worker, there may be some workers who do not update the verification software in the terminal device as required (i.e., do not upgrade the verification software to the latest version). In this case, based on the certificate issuing method provided by the application, the certificate issuing device can require the terminal device to execute remote certification and obtain the remote certification result of the terminal device in the process that the worker applies for the certificate by using the terminal device. Then, based on the remote certification result of the terminal device, the certificate issuing device can obtain the version number of the verification software in the terminal device, thereby determining whether to issue a certificate to the terminal device. For example, if the version number of the verification software in the terminal device is lower than the version number set by the company, the issuing of the certificate for the terminal device is refused, so that the terminal device cannot use the certificate for network communication.
As another example, in an operator scenario, firmware or configuration information on a network device (e.g., a router or gateway, etc.) operating in a communication network often has a manufacturer recommended security update channel and a minimum security baseline configuration. Therefore, an operator can perform security baseline management on network equipment in a communication network by adopting the certificate issuing method provided by the application. That is, when the network device applies for a certificate, the certificate issuing device acquires and verifies firmware or configuration information in the network device through the certificate issuing method provided by the application. And when the firmware or the configuration information in the network equipment does not accord with the security baseline configuration, the certificate issuing equipment refuses to issue the certificate for the network equipment, thereby ensuring the security of the network equipment.
Referring to fig. 2, fig. 2 is a schematic flow chart of a certificate issuing method provided by the present application. As shown in fig. 2, the execution flow of the certificate issuing method provided by the present application includes the following steps 201 to 204.
In step 201, the first network device receives a certificate application message sent by the second network device, where the certificate application message is used to apply for issuing a certificate.
In the application, the first network device is a certificate issuing device, for example, an ACME server (i.e. ACME server), and can automatically issue a certificate for the certificate applying device. The second network device is a certificate applying device and needs to request to issue a certificate from a certificate issuing device. The second network device is illustratively a device such as a switch, gateway, router, hub, server, personal computer or smart phone.
When the second network device needs to apply for the certificate, the second network device sends a certificate application message to the first network device so as to apply for the first network device to issue the certificate for the second network device.
Optionally, to facilitate the first network device determining the challenge type supported by the second network device, the credential application message is further used to instruct the second network device to support performing remote attestation. In this way, based on the certificate application message, the first network device confirms that the second network device currently applying the certificate is capable of performing remote attestation, and thus the first network device can instruct the second network device to complete the challenge in the certificate issuing process by performing remote attestation.
Step 202, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
In order to ensure the security of the certificate issuing process, the first network device sends a challenge message to the second network device after receiving the certificate application message, so as to instruct the second network device to complete the challenge specified by the first network device. Wherein the challenge message sent by the first network device specifically indicates that the second network device needs to complete the challenge by performing a remote attestation.
Optionally, since remote attestation is not included in the existing challenge types, a challenge type can be newly defined based on the existing challenge types, and the newly defined challenge type is remote attestation. Based on this, the challenge message sent by the first network device to the second network device includes a challenge type, which is a type for indicating that the second network device needs to complete a challenge task, including remote attestation. For example, the challenge message includes a newly defined challenge type identifier, which can indicate that the challenge task is of a remote attestation type.
In step 203, after the second network device completes the challenge, the first network device obtains a challenge result, where the challenge result includes a remote proof result, and the remote proof result is used to instruct the second network device to execute a result of the remote proof process.
Since the challenge message indicates that the second network device completes the challenge by performing the remote attestation, after the second network device completes the remote attestation and obtains the remote attestation result, the second network device completes the challenge specified by the second network device, thereby obtaining the challenge result.
Wherein the first network device obtains the challenge result from the second network device or other device. Since the challenge performed by the first network device is specifically a process of performing remote attestation, the challenge result may include a remote attestation result to instruct the second network device to perform the result of the remote attestation process.
In general, remote attestation results are generated by a remote attestation server. The second network device submits attribute evidence (evidence) to the remote proving server in the process of executing remote proving, wherein the attribute evidence comprises a plurality of attribute identifiers and information (such as a running log of the second network device) for verifying the credibility of the attribute identifiers, and the attribute identifiers are used for indicating different attributes of the second network device (such as information of hardware in the second network device, version numbers of software in the second network device, configuration information of the second network device and the like). The remote attestation server verifies the proof of the attribute submitted by the second network device (e.g., compares the proof of the attribute submitted by the second network device with a reference value for the device attribute) and generates a remote attestation result based on the verified attribute.
Step 204, in case the challenge result is verified, the first network device issues a certificate to the second network device.
After the challenge result corresponding to the second network device is obtained, the first network device verifies the challenge result. For example, in one alternative implementation, the first network device verifies a remote attestation result of the challenge results to determine the authenticity of the remote attestation result. If the remote proof result is not able to pass the verification, the representative challenge result is not able to pass the verification.
The first network device issues a certificate to the second network device if the challenge result is not capable of verification, and the first network device refuses to issue a certificate to the second network device if the challenge result is not capable of verification.
In the scheme, the certificate issuing process and the remote certification are combined, so that the certificate application equipment can be ensured to verify the credibility of the certificate application equipment by the remote certification server when the certificate is applied, and the remote certification process can be completed only after the credibility of the certificate application equipment passes the verification. Therefore, under the condition that the certificate applying device completes the challenges specified by the certificate issuing device, the certificate issuing device can determine that the credibility of the certificate applying device is verified, so that the certificate issuing device is ensured to issue a certificate for the credible device, and the safety of the certificate issuing process is ensured.
For ease of understanding, the process by which the first network device verifies the challenge results will be described in detail below.
Referring to fig. 3, fig. 3 is a flow chart illustrating a verification of a challenge result by a first network device according to the present application. As shown in fig. 3, the above-described step 204 specifically includes the following steps 2401-2403.
Step 2401, the first network device verifies the authenticity of the remote attestation result.
Since the challenge result includes the remote attestation result, the first network device needs to verify the authenticity of the remote attestation result itself first to determine that the second network device has indeed performed the remote attestation process.
Specifically, the remote attestation result typically includes an attribute of the second network device (i.e., an attribute identifier submitted to the remote attestation device when the second network device performs the remote attestation) and a digital signature derived based on the attribute of the second network device. Therefore, the first network device adopts a digital signature verification mode to verify the digital signature in the remote proof result, so that the authenticity of the remote proof result can be determined, and the authenticity of the remote proof result is verified. The description of the digital signature verification method can be explained with reference to the above technical terms, and will not be repeated here.
Step 2402, when the remote attestation result passes the verification, the first network device verifies whether the attribute of the second network device meets the certificate issuing condition based on the remote attestation result.
The remote proof result includes attributes of the second network device, such as information of hardware in the second network device, version number of software in the second network device, configuration information of the second network device, and the like. And, the first network device is preset with a certificate issuing condition for further verifying whether the second network device applying for the certificate meets the certificate issuing condition.
Specifically, if the authenticity of the remote attestation result is verified, the first network device obtains the attribute of the second network device from the remote attestation result and further verifies whether the attribute of the second network device meets the certificate issuing condition.
Optionally, in the remote attestation result, the attribute of the second network device specifically includes a plurality of attribute identifiers, where the plurality of attribute identifiers are used to indicate different attributes of the second network device. For example, one of the plurality of attribute identifications is information indicating a certain hardware of the second network device, and another one of the plurality of attribute identifications is a version number indicating a certain software of the second network device. The preset certificate issuing conditions in the first network device comprise at least one attribute condition, wherein the at least one attribute condition is used for indicating conditions to be met by the attribute identification of the second network device. For example, each attribute condition in the at least one attribute condition corresponds to one attribute identifier, and each attribute condition is a condition for indicating that the corresponding attribute identifier needs to be satisfied.
In this way, based on at least one of the certificate issuance conditions, the first network device determines at least one of the plurality of attribute identifications of the remote attestation result that is to satisfy the attribute condition. And the first network device respectively determines whether at least one attribute identifier in the remote attestation result meets the corresponding attribute condition so as to determine whether the attribute of the second network device meets the certificate issuing condition.
For example, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number. Therefore, the first network device determines the version number of the target software in the second network device in the plurality of attribute identifiers, and determines whether the version number of the target software is not lower than a preset version number. And if the version number of the target software is lower than the preset version number, the attribute of the second network device is not in accordance with the certificate issuing condition.
In the campus scenario, the second network device is, for example, a terminal device for checking products, and the target software is, for example, checking software for performing product checking in the second network device. Since the second network device is actually operated by a worker, there may be some workers who do not update the verification software in the second network device on demand. Thus, after obtaining the version number of the verification software in the second network device, if the first network device determines that the version number of the verification software in the second network device is lower than the version number set by the company (i.e., the preset version number), issuing of the certificate for the second network device is refused, so that the second network device cannot perform network communication using the certificate.
As another example, in an operator scenario, the second network device is, for example, a network device (e.g., a switch or gateway) in the communication network for performing data forwarding, and the target software is, for example, firmware in the second network device. Since the firmware on the second network device will often have a manufacturer recommended secure update channel and a minimum secure baseline configuration. Thus, after obtaining the version number of the verification software in the second network device, if the first network device determines that the version number of the verification software in the second network device is lower than the version number specified in the security baseline configuration (i.e., the preset version number), issuing of the certificate for the second network device is refused, thereby disabling the second network device from network communication using the certificate.
Further, in the case where at least one attribute condition included in the certificate issuance condition is a plurality of attribute conditions, the first network device needs to determine whether a plurality of attributes of the second network device satisfy the corresponding attribute conditions based on the plurality of attribute identifications in the remote attestation result. The first network device can determine that the attribute of the second network device meets the certificate issuance condition if the attribute of the second network device all meets a plurality of attribute conditions in the certificate issuance condition, or can determine that the attribute of the second network device meets the certificate issuance condition if the number of attribute conditions met by the attribute of the second network device reaches a specified number.
In general, in the case where one attribute condition is preset in the first network device, the first network device determines whether the attribute of the second network device meets the certificate issuing condition based on whether the attribute of the second network device meets the attribute condition.
In the case where a plurality of attribute conditions are preset in the first network device, the first network device determines whether the attribute of the second network device meets the certificate issuing condition based on a pre-specified policy. For example, the pre-specified policy is specifically that the attribute of the second network device meets the certificate issuing condition if the attribute of the second network device meets all the attribute conditions. Or the pre-designated strategy is specifically that when the number of attribute conditions met by the attributes of the second network equipment reaches the designated number, the attributes of the second network equipment meet the certificate issuing conditions.
Step 2403, the first network device determines that the challenge result is validated if the attribute of the second network device meets the certificate issuance condition.
In particular, if the attribute of the second network device meets the certificate issuance condition, the security requirement for certificate issuance is met on behalf of the second network device itself, so the first network device determines that the challenge result is verified. If the attribute of the second network device does not meet the certificate issuance condition, then the first network device determines that the challenge result is not validated on behalf of the second network device itself not meeting the security requirements of certificate issuance.
In the scheme, the certificate issuing equipment further verifies whether the attribute of the certificate application equipment included in the remote proof result accords with the certificate issuing condition or not besides verifying the authenticity of the remote proof result, so that the verification range is expanded to a series of attributes of the certificate application equipment, the certificate issuing equipment can conveniently reject to issue certificates to the certificate application equipment with the attribute which does not accord with the condition, and the safety of the certificate issuing process is further improved. In addition, the certificate issuing equipment acquires the attribute of the certificate application equipment from the remote verification result of the authenticity passing verification, so that the certificate issuing equipment can ensure the authenticity of the acquired attribute of the certificate application equipment, the certificate issuing equipment is prevented from acquiring the forged attribute of the certificate application equipment, and the reliability of the attribute verification process of the certificate application equipment is ensured.
For example, in the case that the certificate issuing condition includes that the version number of the target software is not lower than the preset version number, if the version number of the target software in the second network device is lower than the preset version number, the target software in the second network device is not updated in time and is at risk of being easily attacked, so that the first network device determines that the challenge result of the first network device is not verified, and then refuses to issue a certificate to the second network device, so as to avoid the security risk brought after issuing the certificate to the second network device.
In the present application, there are various ways for the second network device to complete the challenge indicated by the first network device, and how the second network device completes the challenge indicated by the first network device through various implementations will be described below.
In implementation 1, the second network device completes the remote attestation process in advance, and returns a remote attestation result obtained in advance to the first network device after obtaining the challenge indicated by the first network device.
In implementation 1, the second network device has completed the remote attestation process before issuing the certificate to the first network device. And, in the case where the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device can feed back to the first network device a remote attestation result obtained by previously performing the remote attestation process. That is, the second network device is actually multiplexing the existing remote attestation results.
Referring to fig. 4, fig. 4 is a schematic flow chart of applying a certificate by a second network device based on a remote certification result obtained in advance. As shown in fig. 4, the procedure of applying the certificate by the second network device based on the remote certification result obtained in advance includes the following steps 401 to 408.
The second network device sends the attribute evidence to a remote attestation server, step 401.
In the example shown in fig. 4, the second network device performs the remote attestation process before the second network device applies for credentials to the first network device. It should be noted that there are various reasons for triggering the second network device to perform remote attestation in advance. For example, in the case where the second network device has learned that the challenge needs to be completed by performing remote attestation when the second network device has acquired the subsequent application certificate, the second network device triggers the remote attestation to be performed prior to applying the certificate. As another example, the second network device may be triggered to perform remote attestation because of a need to participate in trusted computing or to authenticate itself at an initial start-up. Remote attestation, among other things, is one of the key technologies in trusted computing global solutions, which is commonly used to authenticate whether a device is in a trusted state.
Specifically, in performing the remote attestation, the second network device sends the attribute evidence to the remote attestation server. Wherein the attribute evidence includes a plurality of attribute identifiers and information for verifying the credibility of the plurality of attribute identifiers (such as a running log of the second network device), the plurality of attribute identifiers are used for indicating different attributes of the second network device (such as a metric value obtained in a starting process of the second network device, information of hardware in the second network device, a version number of software in the second network device, configuration information of the second network device, and the like).
The remote attestation server sends the remote attestation result to the second network device, step 402.
After the attribute evidence sent by the second network device is obtained, the remote attestation server verifies the attribute evidence sent by the second network device, so that the verified attribute is determined. In this way, the remote attestation server is able to generate a remote attestation result based on the verified attributes in the second network device and send the generated remote attestation result to the second network device. The remote attestation result includes an attribute of the second network device (i.e., an attribute identifier submitted to the remote attestation device when the second network device performs remote attestation) and a digital signature obtained based on the attribute of the second network device.
In general, the process by which the second network device performs remote attestation is similar to an existing remote attestation process, and in particular reference may be made to an existing remote attestation process.
In step 403, the first network device receives the certificate application message sent by the second network device.
In the case that the remote certification result has been obtained and the second network device needs to request the first network device to issue a certificate, the second network device sends a certificate application message to the first network device.
Optionally, because the second network device has completed the remote attestation process and obtained the remote attestation result, the second network device can carry the identifier of the remote attestation result in the sent certificate application message, thereby declaring to the first network device that the second network device has the remote attestation result. Or the certificate application message carries an identifier of the remote proving client, and the identifier of the remote proving client is used for representing the identity of the remote proving client used by the second network device when executing the remote proving process.
In general, the present application is not limited to the implementation manner of the identifier carried in the certificate application message, as long as it is ensured that the identifier carried in the certificate application message can indicate that the second network device supports remote attestation or that the second network device has completed the remote attestation process.
The first network device sends a challenge message to the second network device, the challenge message instructing the second network device to complete the challenge by performing a remote attestation, step 404.
In this example, the challenge message sent by the first network device includes a challenge type and a challenge identification. Wherein the type of challenge is used to indicate that the second network device is to perform the challenge task includes remote attestation. It should be noted that, in some cases, the challenge message sent by the first network device may also be used to indicate that the challenge task to be completed by the second network device includes other challenge types. That is, the challenge types that the second network device needs to accomplish the challenge task include both remote attestation and other challenge types, such as a hypertext transfer protocol (Hypertext Transfer Protocol, HTTP) challenge type or a Domain name system (Domain NAME SYSTEM, DNS) challenge type.
The challenge identification is used to identify a current challenge task that the second network device is required to complete. For example, the challenge is identified as a random number generated by the first network device, or the challenge is identified as a sequence number generated by the first network device based on the number of received credential application messages. In general, the challenge identification is used to uniquely identify a challenge task that the second network device is currently required to complete, so that the subsequent first network device can confirm to which challenge task the challenge result fed back by the second network device corresponds.
In step 405, the first network device obtains a challenge result including a remote attestation result.
The first network device obtains the challenge result in a plurality of ways.
In one possible implementation, a first network device receives a challenge result sent by a second network device. Specifically, the challenge result includes a remote attestation result, a challenge identification, and signature information. The signature information is a digital signature obtained by signing the remote proving result and the challenge identifier by the second network device. That is, the second network device generates a challenge result based on the obtained remote attestation result, and transmits the challenge result to the second network device.
In another possible implementation manner, the first network device receives a challenge completion notification sent by the second network device, and obtains a challenge result based on the challenge completion notification, where the challenge completion notification is used to indicate a location where the challenge result is stored. That is, after generating the challenge result based on the remote attestation result, the second network device does not directly transmit the challenge result to the first network device, but stores the challenge result in a specific location, and notifies the first network device to acquire the challenge result from the specific location. In such implementations, the challenge types that the first network device indicates the challenge tasks that the second network device needs to accomplish include, among other challenge types, remote attestation. For example, when the challenge type of the challenge task to be completed by the second network device specifically includes remote proof and HTTP challenge type, the second network device stores the challenge result at the address of a certain web page, and notifies the first network device to obtain the challenge result from the web page. For another example, when the challenge type of the challenge task to be completed by the second network device specifically includes a remote attestation and a DNS challenge type, the second network device deposits the challenge result on the resolved address of the DNS, and notifies the first network device to obtain the challenge result from the resolved address of the DNS.
In step 406, the first network device verifies the authenticity of the remote attestation result in the challenge result.
After obtaining the challenge result, the first network device verifies the authenticity of the challenge result. Specifically, the first network device verifies the authenticity of the challenge result by adopting a digital signature verification mode based on the signature information in the challenge result, so as to determine whether the challenge result obtained by the first network device is the challenge result generated by the second network device.
And under the condition that the challenge result passes the verification, the first network equipment re-verifies the authenticity of the remote proof result in the challenge result. Specifically, since the remote proof result includes a digital signature, the first network device may verify the digital signature of the remote proof result by adopting a digital signature verification method, thereby implementing verification of authenticity of the remote proof result.
In step 407, in the case that the authenticity of the remote attestation result is verified, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuing condition.
Step 407 is similar to step 2042, and please refer to step 2042, which is not described herein.
In step 408, the first network device issues a certificate to the second network device in case the challenge result is verified.
And under the condition that the first network device determines that the attribute of the second network device in the remote proving result meets the certificate issuing condition, the first network device determines that the challenge result passes verification, so that the certificate is issued to the second network device.
Implementation 2, after obtaining the challenge indicated by the first network device, the second network device performs a remote attestation process, and returns a remote attestation result to the first network device.
In implementation 2, the second network device does not perform the remote attestation process until a certificate is applied to the first network device. When the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device re-performs the remote attestation process.
For example, referring to fig. 5, fig. 5 is a schematic flow chart of a second network device according to the present application, after obtaining an instruction, performing a remote attestation process to apply for a certificate. As shown in fig. 5, the second network device, after acquiring the indication of the first network device, performs a remote attestation process to implement the certificate application, which includes the following steps 501-508.
In step 501, the first network device receives a certificate application message sent by the second network device.
It should be noted that, unlike step 403 described above, in step 501, since the second network device has not completed the remote attestation process, the certificate application message sent by the second network device only indicates that the second network device supports the remote attestation process, and does not carry the identifier of the remote attestation result or the identifier of the remote attestation client.
Step 502, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
The challenge message sent by the first network device includes a challenge type and a challenge identifier. The type of challenge is used to indicate that the second network device is required to complete the challenge task, including remote attestation, and the challenge identifier is used to identify the current challenge task that the second network device is required to complete.
Optionally, the challenge message further includes a remote attestation server (Verifier) list, where the remote attestation server list is used to instruct the second network device of a remote attestation server that can be selected when performing the remote attestation. That is, the first network device specifies in the challenge message through the remote attestation server list which remote attestation servers the second network device needs to select one of to complete the remote attestation process. Wherein the remote attestation server list includes one or more remote attestation servers, and the remote attestation servers included in the remote attestation server list are all remote attestation servers trusted by the first network device.
The second network device sends the attribute evidence to the remote attestation server, step 503.
Upon receiving the challenge message, the second network device determines that a remote attestation process needs to be performed to complete the challenge indicated by the first network device, and thus the second network device sends the attribute evidence to the remote attestation server.
Optionally, in the case that the challenge message further includes a list of remote attestation servers, the second network device needs to select one of the remote attestation servers in the list of remote attestation servers and send the attribute evidence to the remote attestation server.
The remote attestation server sends 504 the remote attestation result to the second network device.
After the remote attestation server verifies the attribute evidence sent by the second network device, the remote attestation server generates a remote attestation result based on the verified attribute in the attribute evidence and sends the remote attestation result to the second network device.
In step 505, the first network device obtains a challenge result including a remote attestation result.
After obtaining the remote attestation result, the second network device may generate a challenge result based on the remote attestation result, thereby enabling the first network device to obtain the challenge result including the remote attestation result. The manner in which the first network device obtains the challenge result is similar to the above-mentioned step 405, and the detailed description of the step 405 is omitted herein.
In step 506, the first network device verifies the authenticity of the remote attestation result in the challenge result.
In step 507, in the case that the authenticity of the remote attestation result is verified, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuing condition.
In step 508, the first network device issues a certificate to the second network device if the challenge result is verified.
Steps 506-508 are similar to steps 406-408 described above, and refer to steps 406-408 specifically, and are not repeated here.
Implementation 3, after acquiring the challenge indicated by the first network device, the second network device performs a remote attestation process based on the challenge identifier provided by the first network device, and returns a remote attestation result including the challenge identifier to the first network device.
In implementation 3, the second network device does not perform the remote attestation process until a certificate is applied to the first network device. When the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device re-performs the remote attestation process. And, when the second network device performs the remote attestation process, the challenge identifier provided by the first network device needs to be submitted to the remote attestation server as attribute evidence, so as to obtain a remote attestation result including the challenge identifier.
Referring to fig. 6, fig. 6 is a schematic flow chart of a second network device according to another embodiment of the present application, after obtaining an indication, performing a remote attestation process to apply for a certificate. As shown in fig. 6, the second network device, after acquiring the indication of the first network device, performs a remote attestation process to implement the certificate application, which includes the following steps 601-609.
In step 601, the first network device receives a certificate application message sent by the second network device.
In step 602, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
Steps 601-602 are similar to steps 501-502 described above, and refer to steps 501-502 specifically.
It should be noted that, the challenge message sent by the first network device includes a challenge type and a challenge identifier, where the challenge type is used to indicate that the type of the challenge task to be completed by the second network device includes remote attestation, and the challenge identifier is used to identify the current challenge task to be completed by the second network device. And, the challenge message is specifically further for instructing the second network device to perform remote attestation with the challenge identification as part of the attribute proof.
The second network device sends 603 attribute evidence including the challenge identification to the remote attestation server.
Since the challenge message is also used to instruct the second network device to perform remote attestation with the challenge identity as part of the attribute evidence, to deeply couple the certificate issuing process with the remote attestation process, the second network device transmits the challenge identity transmitted by the first network device to the remote attestation server as part of the attribute evidence. That is, in the attribute proof transmitted by the second network device, the challenge identifier, the plurality of attribute identifiers, and information for verifying the trustworthiness of the plurality of attribute identifiers are included.
The remote attestation server sends the remote attestation result to the second network device, step 604.
In this step, after receiving the attribute evidence, the remote attestation server can verify the challenge identifier in the attribute evidence in addition to verifying the plurality of attribute identifiers in the attribute evidence, and finally generates a remote attestation result including the challenge identifier and the plurality of attribute identifiers. That is, the challenge identifier and the plurality of attribute identifiers are actually included in the remote attestation results received by the second network device.
In step 605, the first network device obtains a challenge result including a remote attestation result.
In step 605, the first network device obtains the challenge result in a manner similar to that described in step 405 above, and refer to step 405 above.
It should be noted that, in step 605, the remote proof result in the challenge result obtained by the first network device includes the challenge identifier.
In step 606, the first network device verifies the authenticity of the remote attestation result in the challenge result.
In step 607, in case the authenticity of the remote attestation result is verified, the first network device verifies whether the correct challenge identification is included in the remote attestation result.
That is, the first network device needs to verify whether the remote attestation result includes the correct challenge identifier in addition to verifying the authenticity of the remote attestation result itself. Specifically, the first network device verifies whether the remote proof result includes the challenge identifier. In the case that the challenge identifier is included in the remote proof result, the first network device re-verifies whether the challenge identifier included in the remote proof result is a correct challenge identifier, that is, whether the challenge identifier included in the remote proof result is the same as the challenge identifier of the second network device to which the first network device sends.
In step 608, in the case that the remote attestation result includes the correct challenge identifier, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuance condition.
In the case that the authenticity of the remote attestation result is verified, and the challenge identifier included in the remote attestation result is the same as the challenge identifier of the second network device sent by the first network device, the first network device determines that the remote attestation result is verified. That is, the first network device can determine that the second network device did complete the challenge task indicated by the first network device. Thus, the first network device continues to verify whether the attribute of the second network device in the remote attestation result meets the certificate issuance condition.
In step 609, the first network device issues a certificate to the second network device if the challenge result is verified.
In implementation 4, after the first network device indicates the challenge to be completed to the second network device, the first network device is used as a proxy device to assist the second network device to complete the remote attestation process, and the remote attestation result is obtained.
In implementation 4, the second network device does not perform the remote attestation process until a certificate is applied to the first network device. When the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device re-performs the remote attestation process. And the second network device sends the attribute evidence to the first network device when the remote proving process is executed, and the first network device is used as a proxy device to assist the second network device to complete the remote proving process.
Referring to fig. 7, fig. 7 is a flow chart of a first network device as a proxy device for assisting a second network device in completing a remote attestation process according to the present application. As shown in fig. 7, the process of the first network device acting as a proxy device to assist the second network device in completing the remote attestation process includes the following steps 701-708.
In step 701, the first network device receives a certificate application message sent by the second network device.
In step 702, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
Steps 701-702 are similar to steps 501-502 described above, and refer to steps 501-502 described above.
It should be noted that, in the challenge message sent by the first network device to the second network device, the challenge identifier is optional. That is, the challenge message can be one that includes a challenge identification, or the challenge message can be one that does not include a challenge identification.
Optionally, the challenge message sent by the first network device to the second network device is further used to instruct the second network device to complete the remote attestation process through the first network device.
The second network device sends attribute evidence to the first network device, step 703.
Upon receiving the challenge message, the second network device, upon performing the remote attestation, no longer transmits the attribute evidence to the remote attestation server, but rather transmits the attribute evidence to the first network device.
The first network device forwards the attribute evidence to a remote attestation server, step 704.
Because the first network device assists the second network device in completing the remote attestation process, the first network device needs to forward the attribute evidence to the remote attestation server after receiving the attribute evidence sent by the second network device.
Step 705, the first network device obtains a remote attestation result from the remote attestation server, and uses the remote attestation result as a challenge result.
And after the remote proving server verifies the attribute of the second network device based on the attribute evidence forwarded by the first network device, a remote proving result can be generated. At this time, the first network device can directly obtain the remote certification result from the remote certification server, and use the remote certification result as the challenge result of the second network device. That is, the second network device no longer needs to acquire the remote attestation result and send the acquired remote attestation result to the first network device, thereby reducing communication overhead of the second network device.
In step 706, the first network device verifies the authenticity of the remote attestation result.
In step 707, in the case that the authenticity of the remote attestation result is verified, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuing condition.
Step 708, the first network device issues a certificate to the second network device in case the challenge result is verified.
Steps 706-708 are similar to steps 406-408 described above, and refer to steps 406-408 specifically, and are not repeated here.
Having described the certificate issuing method provided by the present application, an apparatus for performing the above-described certificate issuing method will be described below.
Referring to fig. 8, fig. 8 is a schematic structural diagram of a certificate issuing apparatus according to the present application. As shown in fig. 8, the certificate issuing apparatus is deployed on the first network device, and the certificate issuing apparatus includes a receiving module 801 for receiving a certificate application message sent by the second network device, where the certificate application message is used to apply for issuing a certificate, a sending module 802 for sending a challenge message to the second network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, a receiving module 801 further for obtaining a challenge result after the second network device completes the challenge, where the challenge result includes a remote attestation result, where the remote attestation result is used to instruct the second network device to perform a result of the remote attestation process, and a sending module 802 further for issuing the certificate to the second network device if the challenge result passes verification.
In a possible implementation manner, the remote proof result comprises the attribute of the second network device, the certificate issuing apparatus further comprises a processing module 803, and the processing module 803 is used for verifying the authenticity of the remote proof result, verifying whether the attribute of the second network device meets the certificate issuing condition based on the remote proof result when the remote proof result is verified, and determining that the challenge result is verified when the attribute of the second network device meets the certificate issuing condition.
In one possible implementation, the attribute of the second network device includes a plurality of attribute identifiers, the plurality of attribute identifiers are used for indicating different attributes of the second network device, the certificate issuing condition includes at least one attribute condition, the at least one attribute condition is used for indicating a condition to be met by the attribute identifier of the second network device, the processing module 803 is specifically used for determining at least one attribute identifier to be met by the first network device in the plurality of attribute identifiers based on the at least one attribute condition, and the first network device respectively determines whether the at least one attribute identifier meets the corresponding attribute condition to determine whether the attribute of the second network device meets the certificate issuing condition.
In one possible implementation, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by the second network device by signing the remote attestation result and the challenge identifier.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list for indicating remote attestation servers that the second network device is able to select when performing remote attestation.
In a possible implementation manner, the receiving module 801 is further configured to receive a challenge result sent by the second network device, or receive a challenge completion notification sent by the second network device, and obtain the challenge result based on the challenge completion notification, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the receiving module 801 is further configured to receive the attribute evidence sent by the second network device, the sending module 802 is further configured to send the attribute evidence to a remote attestation server, where the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result, and the receiving module 801 is further configured to receive the challenge result from the remote attestation server.
Referring to fig. 9, fig. 9 is a schematic structural diagram of a certificate applying apparatus provided by the present application. As shown in fig. 9, the certificate applying apparatus is disposed on the second network device, and the certificate applying apparatus includes a sending module 901 configured to send a certificate applying message to the first network device, where the certificate applying message is used to apply for issuing a certificate, a receiving module 902 configured to receive a challenge message sent by the first network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, and the receiving module 902 is further configured to receive, when the second network device completes the challenge and a challenge result of the second network device passes verification, the certificate issued by the first network device, where the challenge result includes a remote attestation result, and the remote attestation result is used to instruct the second network device to perform a result of the remote attestation process.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by signing the remote attestation result and the challenge content by the second network device.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list, where the remote attestation server list is used to instruct the second network device to select a remote attestation server that can be selected when performing remote attestation, and the sending module 901 is further configured to select, by the second network device, one remote attestation server from the remote attestation server list to perform a remote attestation process, and obtain a remote attestation result.
In one possible implementation, the sending module 901 is further configured to send a challenge result to the first network device, or send a challenge completion notification to the first network device, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the sending module 901 is further configured to send the attribute evidence to a first network device, where the first network device is configured to forward the attribute evidence to a remote attestation server, and the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result.
Fig. 10 is a schematic structural diagram of a network device according to the present application. As shown in fig. 10, the network device 1000 is equipped with the above-described certificate issuing apparatus or certificate applying apparatus. The network device 1000 is implemented by a general bus architecture.
The network device 1000 includes at least one processor 1001, a communication bus 1002, a memory 1003, and at least one communication interface 1004.
Alternatively, the processor 1001 is a general-purpose CPU, NP, microprocessor, or one or more integrated circuits for implementing aspects of the application, such as an application-specific integrated circuit (ASIC), a programmable logic device (programmable logic device, PLD), or a combination thereof. The PLD is a complex programmable logic device (complex programmable logic device, CPLD), a field-programmable gate array (FPGA) GATE ARRAY, a generic array logic (GENERIC ARRAY logic, GAL), or any combination thereof.
Communication bus 1002 is used to transfer information between the aforementioned components. The communication bus 1002 is classified into an address bus, a data bus, a control bus, and the like. For ease of illustration, the figures are shown with only one bold line, but not with only one bus or one type of bus.
Alternatively, the memory 1003 is a read-only memory (ROM) or other type of static storage device that can store static information and instructions. Memory 1003 is alternatively a random access memory (random access memory, RAM) or other type of dynamic storage device that can store information and instructions. Alternatively, memory 1003 is an electrically erasable programmable read-only Memory (EEPROM), a compact disk (compact disc read-only Memory, CD-ROM) or other optical disk storage, optical disk storage (including compact disk, laser disk, optical disk, digital versatile disk, blu-ray disk, etc.), magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to such. Alternatively, the memory 1003 is separate and coupled to the processor 1001 by a communication bus 1002. Optionally, memory 1003 and processor 1001 are integrated.
The communication interface 1004 uses any transceiver-like device for communicating with other devices or communication networks. Communication interface 1004 includes a wired communication interface. Optionally, the communication interface 1004 further includes a wireless communication interface. The wired communication interface is, for example, an ethernet interface. The ethernet interface is an optical interface, an electrical interface, or a combination thereof. The wireless communication interface is a wireless local area network (wireless local area networks, WLAN) interface, a cellular network communication interface, a combination thereof, or the like.
In a particular implementation, as one embodiment, the processor 1001 includes one or more CPUs, such as CPU0 and CPU1 shown in FIG. 10.
In a specific implementation, as an embodiment, the network device 1000 includes a plurality of processors, such as processor 1001 and processor 1005 shown in fig. 10. Each of these processors is a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein refers to one or more devices, circuits, and/or processing cores for processing data (e.g., computer program instructions).
In some embodiments, memory 1003 is used to store program code 1006 for performing aspects of the present application, and processor 1001 executes program code 1006 stored in memory 1003. That is, the network device 1000 implements the above-described method embodiments by the processor 1001 and the program code 1006 in the memory 1003.
The application also provides a certificate issuing system, which comprises a first network device and a second network device, wherein the first network device is provided with a certificate issuing device according to the embodiment corresponding to fig. 8, and the second network device is provided with a certificate applying device according to the embodiment corresponding to fig. 9.
In this specification, each embodiment is described in a progressive manner, and identical and similar parts of each embodiment are referred to each other, and each embodiment is mainly described as a difference from other embodiments.
A refers to B, referring to a simple variation where A is the same as B or A is B.
The terms first and second and the like in the description and in the claims of embodiments of the application, are used for distinguishing between different objects and not necessarily for describing a particular sequential or chronological order of the objects, and should not be interpreted to indicate or imply relative importance. For example, a first speed limiting channel and a second speed limiting channel are used to distinguish between different speed limiting channels, rather than to describe a particular order of speed limiting channels, nor should the first speed limiting channel be understood to be more important than the second speed limiting channel.
In the embodiments of the present application, unless otherwise indicated, the meaning of "at least one" means one or more, and the meaning of "a plurality" means two or more.
The above-described embodiments may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in software, may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When loaded and executed on a computer, produces a flow or function in accordance with embodiments of the present application, in whole or in part. The computer may be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions may be stored in or transmitted from one computer-readable storage medium to another, for example, by wired (e.g., coaxial cable, optical fiber, digital Subscriber Line (DSL)), or wireless (e.g., infrared, wireless, microwave, etc.). The computer readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that contains an integration of one or more available media. The usable medium may be a magnetic medium (e.g., floppy disk, hard disk, tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk Solid STATE DISK (SSD)), etc.
The foregoing embodiments are merely for illustrating the technical solution of the present application, but not for limiting the same, and although the present application has been described in detail with reference to the foregoing embodiments, it will be understood by those skilled in the art that modifications may be made to the technical solution described in the foregoing embodiments or equivalents may be substituted for parts of the technical features thereof, and such modifications or substitutions do not depart from the spirit of the corresponding technical solution from the scope of the technical solution of the embodiments of the present application.

Claims (24)

1.一种证书颁发方法,其特征在于,包括:1. A certificate issuance method, characterized in that it includes: 第一网络设备接收第二网络设备发送的证书申请消息,所述证书申请消息用于申请颁发证书;The first network device receives a certificate request message sent by the second network device, the certificate request message being used to request the issuance of a certificate; 所述第一网络设备向所述第二网络设备发送挑战消息,所述挑战消息用于指示所述第二网络设备通过执行远程证明来完成挑战;The first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing remote proof; 在所述第二网络设备完成挑战后,所述第一网络设备获取挑战结果,所述挑战结果包括远程证明结果,所述远程证明结果用于指示所述第二网络设备执行远程证明过程的结果;After the second network device completes the challenge, the first network device obtains the challenge result, which includes a remote proof result. The remote proof result is used to indicate the result of the second network device performing the remote proof process. 在所述挑战结果通过验证的情况下,所述第一网络设备向所述第二网络设备颁发证书。If the challenge result is verified, the first network device issues a certificate to the second network device. 2.根据权利要求1所述的方法,其特征在于,所述远程证明结果包括所述第二网络设备的属性,所述方法还包括:2. The method according to claim 1, wherein the remote verification result includes the attributes of the second network device, and the method further includes: 所述第一网络设备对所述远程证明结果的真实性进行验证;The first network device verifies the authenticity of the remote verification result; 在所述远程证明结果通过验证时,所述第一网络设备基于所述远程证明结果验证所述第二网络设备的属性是否符合证书颁发条件;When the remote verification result passes the verification, the first network device verifies whether the attributes of the second network device meet the certificate issuance conditions based on the remote verification result. 在所述第二网络设备的属性符合所述证书颁发条件的情况下,所述第一网络设备确定所述挑战结果通过验证。If the attributes of the second network device meet the certificate issuance conditions, the first network device determines that the challenge result has been verified. 3.根据权利要求2所述的方法,其特征在于,所述第二网络设备的属性包括多个属性标识,所述多个属性标识用于指示所述第二网络设备的不同属性,所述证书颁发条件包括至少一个属性条件,所述至少一个属性条件用于指示所述第二网络设备的属性标识需满足的条件;3. The method according to claim 2, wherein the attributes of the second network device include a plurality of attribute identifiers, the plurality of attribute identifiers being used to indicate different attributes of the second network device, and the certificate issuance conditions include at least one attribute condition, the at least one attribute condition being used to indicate the conditions that the attribute identifiers of the second network device must satisfy; 所述第一网络设备基于所述远程证明结果验证所述第二网络设备的属性是否符合证书颁发条件,包括:The first network device verifies whether the attributes of the second network device meet the certificate issuance conditions based on the remote authentication result, including: 基于所述至少一个属性条件,所述第一网络设备在所述多个属性标识中确定需满足属性条件的至少一个属性标识;Based on the at least one attribute condition, the first network device determines at least one attribute identifier from the plurality of attribute identifiers that needs to satisfy the attribute condition; 所述第一网络设备分别确定所述至少一个属性标识是否满足对应的属性条件,以确定所述第二网络设备的属性是否符合所述证书颁发条件。The first network device determines whether the at least one attribute identifier meets the corresponding attribute conditions, thereby determining whether the attributes of the second network device meet the certificate issuance conditions. 4.根据权利要求3所述的方法,其特征在于,4. The method according to claim 3, characterized in that, 所述多个属性标识包括所述第二网络设备中目标软件的版本号,所述至少一个属性条件包括所述目标软件的版本号不低于预设版本号。The plurality of attribute identifiers include the version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number. 5.根据权利要求1-4任意一项所述的方法,其特征在于,所述挑战消息中包括挑战类型以及挑战标识,所述挑战类型用于指示所述第二网络设备需完成的挑战任务的类型包括远程证明,所述挑战标识用于标识所述第二网络设备需完成的当前挑战任务,所述挑战结果包括所述远程证明结果、所述挑战标识以及签名信息,所述签名信息是所述第二网络设备对所述远程证明结果和所述挑战标识进行签名得到的。5. The method according to any one of claims 1-4, wherein the challenge message includes a challenge type and a challenge identifier, the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote proof, the challenge identifier is used to identify the current challenge task to be completed by the second network device, and the challenge result includes the remote proof result, the challenge identifier and signature information, wherein the signature information is obtained by the second network device signing the remote proof result and the challenge identifier. 6.根据权利要求1-5任意一项所述的方法,其特征在于,所述证书申请消息还用于指示所述第二网络设备支持执行远程证明。6. The method according to any one of claims 1-5, wherein the certificate request message is further used to instruct the second network device to support performing remote certification. 7.根据权利要求1-4任意一项所述的方法,其特征在于,所述挑战消息中包括挑战类型以及挑战标识,所述挑战类型用于指示所述第二网络设备需完成的挑战任务的类型包括远程证明,所述挑战标识用于标识所述第二网络设备需完成的当前挑战任务,所述挑战消息用于指示所述第二网络设备将所述挑战标识作为属性证据的一部分来执行远程证明;7. The method according to any one of claims 1-4, wherein the challenge message includes a challenge type and a challenge identifier, the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote proof, the challenge identifier is used to identify the current challenge task to be completed by the second network device, and the challenge message is used to instruct the second network device to perform remote proof by using the challenge identifier as part of the attribute evidence; 所述挑战结果通过验证,包括:The challenge results were verified, including: 所述远程证明结果的真实性通过验证且所述远程证明结果中包括所述挑战标识。The authenticity of the remote proof result is verified, and the remote proof result includes the challenge identifier. 8.根据权利要求7所述的方法,其特征在于,所述挑战消息中包括远程证明服务器列表,所述Verifier列表用于指示所述第二网络设备执行远程证明时所能够选择的远程证明服务器。8. The method according to claim 7, wherein the challenge message includes a list of remote verification servers, and the Verifier list is used to indicate the remote verification servers that the second network device can select when performing remote verification. 9.根据权利要求1-8任意一项所述的方法,其特征在于,所述第一网络设备获取挑战结果,包括:9. The method according to any one of claims 1-8, characterized in that the first network device obtains the challenge result, comprising: 所述第一网络设备接收所述第二网络设备发送的所述挑战结果;The first network device receives the challenge result sent by the second network device; 或者,所述第一网络设备接收所述第二网络设备发送的挑战完成通知,并基于所述挑战完成通知获取所述挑战结果,其中所述挑战完成通知用于指示所述挑战结果所存放的位置。Alternatively, the first network device receives a challenge completion notification sent by the second network device and obtains the challenge result based on the challenge completion notification, wherein the challenge completion notification is used to indicate the location where the challenge result is stored. 10.根据权利要求1-4任意一项所述的方法,其特征在于,所述第一网络设备获取挑战结果包括:10. The method according to any one of claims 1-4, wherein the first network device obtains the challenge result by: 所述第一网络设备接收所述第二网络设备发送的属性证据;The first network device receives attribute evidence sent by the second network device; 所述第一网络设备向远程证明服务器发送所述属性证据,所述远程证明服务器用于验证所述属性证据并生成所述远程证明结果;The first network device sends the attribute evidence to a remote proof server, which verifies the attribute evidence and generates the remote proof result. 所述第一网络设备从所述远程证明服务器接收所述挑战结果。The first network device receives the challenge result from the remote proof server. 11.一种证书颁发方法,其特征在于,包括:11. A certificate issuance method, characterized in that it includes: 第二网络设备向第一网络设备发送证书申请消息,所述证书申请消息用于申请颁发证书;The second network device sends a certificate request message to the first network device, the certificate request message being used to request the issuance of a certificate; 所述第二网络设备接收所述第一网络设备发送的挑战消息,所述挑战消息用于指示所述第二网络设备通过执行远程证明来完成挑战;The second network device receives a challenge message sent by the first network device, the challenge message being used to instruct the second network device to complete the challenge by performing remote proof; 在所述第二网络设备完成挑战且所述第二网络设备的挑战结果通过验证的情况下,所述第二网络设备接收所述第一网络设备颁发的证书,所述挑战结果包括远程证明结果,所述远程证明结果用于指示所述第二网络设备执行远程证明过程的结果。If the second network device completes the challenge and the challenge result of the second network device is verified, the second network device receives a certificate issued by the first network device. The challenge result includes a remote proof result, which is used to instruct the second network device on the result of performing a remote proof process. 12.根据权利要求11所述的方法,其特征在于,所述挑战消息中包括挑战类型以及挑战标识,所述挑战类型用于指示所述第二网络设备需完成的挑战任务的类型包括远程证明,所述挑战标识用于标识所述第二网络设备需完成的当前挑战任务,所述挑战结果包括所述远程证明结果、所述挑战标识以及签名信息,所述签名信息是所述第二网络设备对所述远程证明结果和所述挑战内容进行签名得到的。12. The method according to claim 11, wherein the challenge message includes a challenge type and a challenge identifier, the challenge type indicating that the type of challenge task to be completed by the second network device includes remote proof, the challenge identifier identifying the current challenge task to be completed by the second network device, and the challenge result including the remote proof result, the challenge identifier, and signature information, wherein the signature information is obtained by the second network device signing the remote proof result and the challenge content. 13.根据权利要求11所述的方法,其特征在于,13. The method according to claim 11, characterized in that, 所述挑战消息中包括挑战类型以及挑战标识,所述挑战类型用于指示所述第二网络设备需完成的挑战任务的类型包括远程证明,所述挑战标识用于标识所述第二网络设备需完成的当前挑战任务,所述挑战消息用于指示所述第二网络设备将所述挑战标识作为属性证据的一部分来执行远程证明;The challenge message includes a challenge type and a challenge identifier. The challenge type indicates the type of challenge task that the second network device needs to complete, including remote proof. The challenge identifier identifies the current challenge task that the second network device needs to complete. The challenge message instructs the second network device to use the challenge identifier as part of the attribute evidence to perform remote proof. 所述挑战结果通过验证,包括:The challenge results were verified, including: 所述远程证明结果的真实性通过验证且所述远程证明结果中包括所述挑战标识。The authenticity of the remote proof result is verified, and the remote proof result includes the challenge identifier. 14.根据权利要求13所述的方法,其特征在于,所述挑战消息中包括远程证明服务器列表,所述远程证明服务器列表用于指示所述第二网络设备执行远程证明时所能够选择的远程证明服务器,所述方法还包括:14. The method according to claim 13, wherein the challenge message includes a list of remote proof servers, the list of remote proof servers being used to indicate the remote proof servers that the second network device can select when performing remote proof, and the method further includes: 所述第二网络设备从远程证明服务器列表中选择一个远程证明服务器来执行远程证明过程,得到所述远程证明结果。The second network device selects a remote verification server from the list of remote verification servers to perform the remote verification process and obtain the remote verification result. 15.根据权利要求11所述的方法,其特征在于,所述方法还包括:15. The method according to claim 11, characterized in that the method further comprises: 所述第二网络设备向所述第一网络设备发送属性证据,其中所述第一网络设备用于向远程证明服务器转发所述属性证据,所述远程证明服务器用于验证所述属性证据并生成所述远程证明结果。The second network device sends attribute evidence to the first network device, wherein the first network device is used to forward the attribute evidence to a remote proof server, and the remote proof server is used to verify the attribute evidence and generate the remote proof result. 16.一种证书颁发装置,其特征在于,所述装置部署在第一网络设备上,所述装置包括:16. A certificate issuing device, characterized in that the device is deployed on a first network device, the device comprising: 接收模块,用于接收第二网络设备发送的证书申请消息,所述证书申请消息用于申请颁发证书;The receiving module is used to receive a certificate request message sent by the second network device, wherein the certificate request message is used to request the issuance of a certificate; 发送模块,用于向所述第二网络设备发送挑战消息,所述挑战消息用于指示所述第二网络设备通过执行远程证明来完成挑战;A sending module is configured to send a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing remote proof; 所述接收模块,还用于在所述第二网络设备完成挑战后,获取挑战结果,所述挑战结果包括远程证明结果,所述远程证明结果用于指示所述第二网络设备执行远程证明过程的结果;The receiving module is further configured to obtain the challenge result after the second network device completes the challenge, the challenge result including the remote proof result, the remote proof result being used to instruct the second network device on the result of performing the remote proof process; 所述发送模块,还用于在所述挑战结果通过验证的情况下,向所述第二网络设备颁发证书。The sending module is also used to issue a certificate to the second network device if the challenge result is verified. 17.根据权利要求16所述的装置,其特征在于,所述远程证明结果包括所述第二网络设备的属性,所述装置还包括处理模块,所述处理模块,用于:17. The apparatus according to claim 16, wherein the remote authentication result includes attributes of the second network device, and the apparatus further includes a processing module, the processing module being configured to: 对所述远程证明结果的真实性进行验证;The authenticity of the remote proof result is verified; 在所述远程证明结果通过验证时,基于所述远程证明结果验证所述第二网络设备的属性是否符合证书颁发条件;When the remote verification result passes, the attributes of the second network device are verified based on the remote verification result to see if they meet the certificate issuance conditions. 在所述第二网络设备的属性符合所述证书颁发条件的情况下,确定所述挑战结果通过验证。If the attributes of the second network device meet the certificate issuance conditions, the challenge result is determined to be verified. 18.根据权利要求17所述的装置,其特征在于,所述第二网络设备的属性包括多个属性标识,所述多个属性标识用于指示所述第二网络设备的不同属性,所述证书颁发条件包括至少一个属性条件,所述至少一个属性条件用于指示所述第二网络设备的属性标识需满足的条件;18. The apparatus according to claim 17, wherein the attributes of the second network device include a plurality of attribute identifiers, the plurality of attribute identifiers being used to indicate different attributes of the second network device, and the certificate issuance conditions include at least one attribute condition, the at least one attribute condition being used to indicate the conditions that the attribute identifiers of the second network device need to satisfy; 所述处理模块,具体用于:The processing module is specifically used for: 基于所述至少一个属性条件,所述第一网络设备在所述多个属性标识中确定需满足属性条件的至少一个属性标识;Based on the at least one attribute condition, the first network device determines at least one attribute identifier from the plurality of attribute identifiers that needs to satisfy the attribute condition; 所述第一网络设备分别确定所述至少一个属性标识是否满足对应的属性条件,以确定所述第二网络设备的属性是否符合所述证书颁发条件。The first network device determines whether the at least one attribute identifier meets the corresponding attribute conditions, thereby determining whether the attributes of the second network device meet the certificate issuance conditions. 19.根据权利要求18所述的装置,其特征在于,19. The apparatus according to claim 18, characterized in that, 所述多个属性标识包括所述第二网络设备中目标软件的版本号,所述至少一个属性条件包括所述目标软件的版本号不低于预设版本号。The plurality of attribute identifiers include the version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number. 20.根据权利要求16-19任意一项所述的装置,其特征在于,所述挑战消息中包括挑战类型以及挑战标识,所述挑战类型用于指示所述第二网络设备需完成的挑战任务的类型包括远程证明,所述挑战标识用于标识所述第二网络设备需完成的当前挑战任务,所述挑战结果包括所述远程证明结果、所述挑战标识以及签名信息,所述签名信息是所述第二网络设备对所述远程证明结果和所述挑战标识进行签名得到的。20. The apparatus according to any one of claims 16-19, wherein the challenge message includes a challenge type and a challenge identifier, the challenge type indicating that the type of challenge task to be completed by the second network device includes remote proof, the challenge identifier identifying the current challenge task to be completed by the second network device, and the challenge result including the remote proof result, the challenge identifier, and signature information, wherein the signature information is obtained by the second network device signing the remote proof result and the challenge identifier. 21.根据权利要求16-20任意一项所述的装置,其特征在于,所述挑战消息中包括挑战类型以及挑战标识,所述挑战类型用于指示所述第二网络设备需完成的挑战任务的类型包括远程证明,所述挑战标识用于标识所述第二网络设备需完成的当前挑战任务,所述挑战消息用于指示所述第二网络设备将所述挑战标识作为属性证据的一部分来执行远程证明;21. The apparatus according to any one of claims 16-20, wherein the challenge message includes a challenge type and a challenge identifier, the challenge type indicating that the type of challenge task to be completed by the second network device includes remote proof, the challenge identifier identifying the current challenge task to be completed by the second network device, and the challenge message instructing the second network device to perform remote proof using the challenge identifier as part of attribute evidence; 所述挑战结果通过验证,包括:The challenge results were verified, including: 所述远程证明结果的真实性通过验证且所述远程证明结果中包括所述挑战标识。The authenticity of the remote proof result is verified, and the remote proof result includes the challenge identifier. 22.一种证书申请装置,其特征在于,所述装置部署于第二网络设备上,所述装置包括:22. A certificate application device, characterized in that the device is deployed on a second network device, the device comprising: 发送模块,用于向第一网络设备发送证书申请消息,所述证书申请消息用于申请颁发证书;The sending module is used to send a certificate request message to the first network device, the certificate request message being used to request the issuance of a certificate; 接收模块,用于接收所述第一网络设备发送的挑战消息,所述挑战消息用于指示所述第二网络设备通过执行远程证明来完成挑战;A receiving module is configured to receive a challenge message sent by the first network device, the challenge message being used to instruct the second network device to complete the challenge by performing remote proof; 所述接收模块,还用于在所述第二网络设备完成挑战且所述第二网络设备的挑战结果通过验证的情况下,接收所述第一网络设备颁发的证书,所述挑战结果包括远程证明结果,所述远程证明结果用于指示所述第二网络设备执行远程证明过程的结果。The receiving module is further configured to receive a certificate issued by the first network device when the second network device completes the challenge and the challenge result of the second network device is verified. The challenge result includes a remote proof result, which is used to instruct the second network device to perform the remote proof process. 23.一种证书颁发系统,包括第一网络设备和第二网络设备,所述第一网络设备部署有如权利要求16-21任一项所述的装置,所述第二网络设备部署有如权利要求22所述的装置。23. A certificate issuance system, comprising a first network device and a second network device, wherein the first network device is equipped with the means as described in any one of claims 16-21, and the second network device is equipped with the means as described in claim 22. 24.一种计算机可读存储介质,存储有指令,当所述指令在计算机上运行时,使得计算机执行如权利要求1-15任一项所述的方法。24. A computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-15.
CN202411186320.0A 2024-08-27 2024-08-27 Certificate issuing method and related device Pending CN121619102A (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202411186320.0A CN121619102A (en) 2024-08-27 2024-08-27 Certificate issuing method and related device
PCT/CN2025/071975 WO2026045076A1 (en) 2024-08-27 2025-01-13 Certificate issuance method and related apparatus

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202411186320.0A CN121619102A (en) 2024-08-27 2024-08-27 Certificate issuing method and related device

Publications (1)

Publication Number Publication Date
CN121619102A true CN121619102A (en) 2026-03-06

Family

ID=98915230

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202411186320.0A Pending CN121619102A (en) 2024-08-27 2024-08-27 Certificate issuing method and related device

Country Status (2)

Country Link
CN (1) CN121619102A (en)
WO (1) WO2026045076A1 (en)

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103179129B (en) * 2013-03-29 2016-04-13 华南理工大学 A kind of remote certification method based on cloud computing IaaS environment
WO2016195708A1 (en) * 2015-06-05 2016-12-08 Hewlett Packard Enterprise Development Lp Remote attestation of a network endpoint device
US10944578B2 (en) * 2019-07-24 2021-03-09 Advanced New Technologies Co., Ltd. Identity verification
CN112187771B (en) * 2020-09-23 2023-04-07 华控清交信息科技(北京)有限公司 Authentication method, device and device for authentication
CN115334506B (en) * 2022-08-08 2025-05-02 国网智能电网研究院有限公司 A user trusted access system and method for 5G edge computing nodes
CN116318728B (en) * 2023-03-20 2024-03-26 中国科学院软件研究所 Distributed certificate automatic issuing method, device and system
CN116896463A (en) * 2023-07-10 2023-10-17 北京微芯区块链与边缘计算研究院 Trusted environment authentication method and device based on blockchain

Also Published As

Publication number Publication date
WO2026045076A1 (en) 2026-03-05

Similar Documents

Publication Publication Date Title
CN115333792B (en) Identity authentication method, device and related equipment
US11711219B1 (en) PKI-based user authentication for web services using blockchain
JP2023541599A (en) Service communication methods, systems, devices and electronic equipment
CN111526159B (en) Method and device for establishing data connection, terminal equipment and storage medium
US20170099148A1 (en) Securely authorizing client applications on devices to hosted services
CN113678131B (en) Protecting online applications and websites using blockchain
US10516653B2 (en) Public key pinning for private networks
CN111783068A (en) Device authentication method, system, electronic device and storage medium
CN111414640B (en) Key access control method and device
US11240246B2 (en) Secure confirmation exchange for offline industrial machine
CN114553480A (en) Cross-domain single sign-on method and device
US11296878B2 (en) Private key updating
US20210037005A1 (en) System And Method Of Single Sign On To Master Website And Silent Authentication For Subservient Websites
US12323466B1 (en) Policy exceptions for assessment of network system assets
CN115276998A (en) IoT authentication method, device and IoT device
EP4540966A1 (en) Certificate issuing for virtual network functions
CN117595996A (en) An electronic signature processing method, device, electronic equipment and storage medium
WO2019184206A1 (en) Identity authentication method and apparatus
CN111031067A (en) Monitoring data transmission method, device and electronic device for distributed system
CN108228280A (en) The configuration method and device of browser parameters, storage medium, electronic equipment
CN121619102A (en) Certificate issuing method and related device
US20230155842A1 (en) Method and apparatus for certifying an application-specific key and for requesting such certification
CN119316144A (en) Certificate issuance method, device, system, storage medium and computer program product
US12388662B2 (en) Automated security certificate techniques
US12022002B2 (en) Apparatus, methods, and program products for generating secure short universal resource locators

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication