CN121619102A - Certificate issuing method and related device - Google Patents
Certificate issuing method and related deviceInfo
- Publication number
- CN121619102A CN121619102A CN202411186320.0A CN202411186320A CN121619102A CN 121619102 A CN121619102 A CN 121619102A CN 202411186320 A CN202411186320 A CN 202411186320A CN 121619102 A CN121619102 A CN 121619102A
- Authority
- CN
- China
- Prior art keywords
- network device
- challenge
- result
- certificate
- remote
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
A certificate issuing method is used for improving the security of a certificate issuing process. In the certificate issuing method, when the certificate applying apparatus applies for issuing a certificate, the certificate issuing apparatus returns a challenge of which the challenge type is remote certification to the certificate applying apparatus to instruct the certificate applying apparatus to complete the challenge by performing the remote certification. And under the condition that the certificate issuing equipment verifies that the certificate applying equipment successfully completes the challenge, the certificate issuing equipment issues the certificate. When the certificate application device executes the remote certification, the remote certification server can verify the credibility of the certificate application device, and the remote certification process can be completed only after the credibility of the certificate application device passes the verification. Therefore, under the condition that the certificate applying equipment completes the challenge, the certificate issuing equipment can determine that the credibility of the certificate applying equipment is verified, so that the certificate issuing equipment is ensured to issue a certificate for the credible equipment, and the safety of the certificate issuing process is further ensured.
Description
Technical Field
The application relates to the technical field of computer security, in particular to a certificate issuing method and a related device.
Background
An Automated CERTIFICATE MANAGEMENT Environment (ACME) is a protocol for automating the processing of digital certificate issuing requests. Based on ACME, a certificate authority (CERTIFICATE AUTHORITY, CA) automatically verifies the domain name ownership of the certificate applicant, thereby issuing the corresponding certificate to the certificate applicant, so that the certificate issuing process does not require manual intervention.
In the process of realizing certificate issuing based on ACME, an ACME server device serving as a verifier can send challenges to an ACME client device serving as a certificate applicant, and issues a certificate for the ACME client device after the ACME client device successfully completes challenge. Wherein the challenge sent by the ACME server device is actually to verify ownership of a certain identifier (such as a domain name or company name) by the ACME client device. Thus, the condition for the ACME server device to issue a certificate is to verify that the ACME client device has ownership of a certain identifier.
Currently, certificate issuing is realized based on ACME, only the ACME client device can be proved to have ownership of a certain identifier, and the ACME client device itself cannot be proved to be safe and reliable, so that the security of the certificate issuing process is low.
Disclosure of Invention
The application provides a certificate issuing method and a related device, which can improve the safety of a certificate issuing process.
In a first aspect, a certificate issuing method is provided, applied to a first network device as a certificate issuing device. The certificate issuing method comprises the steps that a first network device receives a certificate application message sent by a second network device, wherein the certificate application message is used for applying for issuing a certificate.
In response to receiving the credential application message, the first network device sends a challenge message to the second network device, the challenge message for instructing the second network device to complete the challenge by performing the remote attestation. That is, the first network device instructs the second network device to complete the first network device specified challenge by sending a challenge message, and the first network device specified challenge is to perform remote attestation.
After the second network device completes the challenge, the first network device obtains a challenge result. Wherein the challenge result comprises a remote attestation result for indicating a result of the second network device performing the remote attestation process. Typically, the remote attestation result is generated by the remote attestation server after verifying the trustworthiness of the second network device for attesting to the trustworthiness of the second network device.
In this way, the first network device can further verify the obtained challenge result, and in the case where the challenge result passes the verification, the first network device issues a certificate to the second network device.
In the scheme, when the certificate applying device applies for issuing the certificate, the certificate issuing device returns a challenge with a challenge type of remote certification to the certificate applying device so as to instruct the certificate applying device to complete the challenge by executing the remote certification. And under the condition that the certificate issuing equipment verifies that the certificate applying equipment successfully completes the challenge, the certificate issuing equipment issues the certificate. When the certificate application device executes the remote certification, the remote certification server can verify the credibility of the certificate application device, and the remote certification process can be completed only after the credibility of the certificate application device passes the verification. Therefore, under the condition that the certificate applying equipment completes the challenge, the certificate issuing equipment can determine that the credibility of the certificate applying equipment is verified, so that the certificate issuing equipment is ensured to issue a certificate for the credible equipment, and the safety of the certificate issuing process is further ensured.
In one possible implementation, the remote attestation result includes attributes of the second network device. In the process of verifying the challenge result, the first network device verifies the authenticity of the remote proof result. For example, the first network device verifies the digital signature in the remote proof result through a digital signature verification manner, so as to verify the authenticity of the remote proof result.
When the remote certification result passes the verification, the first network device verifies whether the attribute of the second network device meets the certificate issuing condition based on the remote certification result. And, in the event that the attribute of the second network device meets the certificate issuance condition, the first network device determines that the challenge result is validated.
In the scheme, the certificate issuing equipment further verifies whether the attribute of the certificate application equipment included in the remote proof result accords with the certificate issuing condition or not besides verifying the authenticity of the remote proof result, so that the verification range is expanded to a series of attributes of the certificate application equipment, the certificate issuing equipment can conveniently reject to issue certificates to the certificate application equipment with the attribute which does not accord with the condition, and the safety of the certificate issuing process is further improved. In addition, the certificate issuing equipment acquires the attribute of the certificate application equipment from the remote verification result of the authenticity passing verification, so that the certificate issuing equipment can ensure the authenticity of the acquired attribute of the certificate application equipment, the certificate issuing equipment is prevented from acquiring the forged attribute of the certificate application equipment, and the reliability of the attribute verification process of the certificate application equipment is ensured.
In one possible implementation, the attribute of the second network device includes a plurality of attribute identifications indicating different attributes of the second network device. For example, one of the plurality of attribute identifications is information indicating a certain hardware of the second network device, and another one of the plurality of attribute identifications is a version number indicating a certain software of the second network device. The certificate issuance condition includes at least one attribute condition for indicating that the attribute identification of the second network device is to satisfy the condition.
In the process of verifying whether the attribute of the second network device meets the certificate issuing condition, the first network device firstly determines at least one attribute identifier which needs to meet the attribute condition in a plurality of attribute identifiers based on the at least one attribute condition. The first network device then determines whether the at least one attribute identification satisfies a corresponding attribute condition, respectively, to determine whether the attribute of the second network device meets a certificate issuance condition.
In one possible implementation, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number.
Therefore, the first network device determines the version number of the target software in the second network device in the plurality of attribute identifiers, and judges whether the version number of the target software is not lower than a preset version number. And if the version number of the target software is lower than the preset version number, the attribute of the second network device is not in accordance with the certificate issuing condition.
For example, in the case that the certificate issuing condition includes that the version number of the target software is not lower than the preset version number, if the version number of the target software in the second network device is lower than the preset version number, the target software in the second network device is not updated in time and is at risk of being easily attacked, so that the first network device determines that the challenge result of the first network device is not verified, and then refuses to issue a certificate to the second network device, so as to avoid the security risk brought after issuing the certificate to the second network device.
In one possible implementation, the challenge message sent by the first network device to the second network device includes a challenge type and a challenge identifier, where the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote attestation, and the challenge identifier is used to identify a current challenge task to be completed by the second network device.
The challenge result obtained by the first network device comprises a remote proving result, a challenge identifier and signature information, wherein the signature information is obtained by signing the remote proving result and the challenge identifier by the second network device. That is, the second network device, after obtaining the remote attestation result, simultaneously feeds back the remote attestation result and the challenge identification to the first network device to declare that the second network device completes the challenge specified by the first network device.
In one possible implementation, to facilitate the first network device determining the challenge type supported by the second network device, the credential application message sent by the second network device to the first network device is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message sent by the first network device to the second network device includes a challenge type and a challenge identifier, where the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote attestation, and the challenge identifier is used to identify a current challenge task to be completed by the second network device. The challenge message is used to instruct the second network device to perform remote attestation with the challenge identification as part of the attribute proof.
The verification of the challenge result specifically comprises that the authenticity of the remote proving result is verified, and the remote proving result comprises a challenge identifier.
That is, the second network device, when performing the remote attestation process, needs to submit the challenge identifier provided by the first network device to the remote attestation server as proof of the attribute, thereby obtaining a remote attestation result including the challenge identifier.
In one possible implementation, the challenge message includes a remote attestation server (Verifier) list that indicates remote attestation servers that the second network device is able to select when performing remote attestation. The remote proving server list comprises one or more remote proving servers, and the remote proving servers in the remote proving server list are all remote proving servers trusted by the first network device.
In one possible implementation, the first network device may obtain the challenge result in a variety of ways. For example, the first network device receives the challenge result sent by the second network device. Or the first network device receives a challenge completion notification sent by the second network device, and obtains a challenge result based on the challenge completion notification, wherein the challenge completion notification is used for indicating a position where the challenge result is stored. That is, after generating the challenge result based on the remote attestation result, the second network device does not directly transmit the challenge result to the first network device, but stores the challenge result in a specific location, and notifies the first network device to acquire the challenge result from the specific location.
In one possible implementation, the first network device can act as a proxy device to assist the second network device in performing the remote attestation process to obtain the challenge result from the remote attestation server. Specifically, the first network device receives attribute evidence sent by the second network device. The first network device then sends the attribute proof to a remote attestation server that verifies the attribute proof and generates a remote attestation result. After the remote certification server generates the remote certification result, the first network device receives a challenge result from the remote certification server, wherein the challenge result is the remote certification result generated by the remote certification server.
In a second aspect, a certificate issuing method is provided, which is applied to a second network device as a certificate applying device. The certificate issuing method comprises the steps that a second network device sends a certificate application message to a first network device, the certificate application message is used for applying for issuing certificates, the second network device receives a challenge message sent by the first network device, the challenge message is used for indicating the second network device to finish challenges through executing remote certification, and the second network device receives the certificates issued by the first network device under the condition that the second network device finishes the challenges and the challenge result of the second network device passes verification, wherein the challenge result comprises a remote certification result, and the remote certification result is used for indicating the second network device to execute the result of the remote certification process.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by signing the remote attestation result and the challenge content by the second network device.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used to indicate that the type of challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used to identify a current challenge task to be completed by the second network device, and the challenge message is used to indicate that the second network device performs remote attestation using the challenge identifier as part of the attribute evidence.
The challenge result is verified, including that the authenticity of the remote proof result is verified and the remote proof result includes the challenge identification.
In a possible implementation, the challenge message includes a remote attestation server list, where the remote attestation server list is used to instruct the second network device to select a remote attestation server that can be selected when performing remote attestation, and the certificate issuing method further includes the second network device selecting one remote attestation server from the remote attestation server list to perform a remote attestation process, and obtaining a remote attestation result.
In one possible implementation, after the second network device completes the challenge, the certificate issuing method further comprises the step that the second network device sends a challenge result to the first network device, or the second network device sends a challenge completion notification to the first network device, wherein the challenge completion notification is used for indicating a position where the challenge result is stored.
In one possible implementation, the certificate issuing method further comprises the second network device sending the attribute evidence to the first network device, wherein the first network device is configured to forward the attribute evidence to a remote attestation server, and the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result.
In a third aspect, a certificate issuing apparatus is provided, the certificate issuing apparatus is deployed on a first network device, and the certificate issuing apparatus includes a receiving module configured to receive a certificate application message sent by a second network device, where the certificate application message is used to apply for issuing a certificate, a sending module configured to send a challenge message to the second network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, the receiving module is further configured to obtain a challenge result after the second network device completes the challenge, where the challenge result includes a remote attestation result, where the remote attestation result is used to instruct the second network device to perform a result of the remote attestation process, and the sending module is further configured to issue a certificate to the second network device if the challenge result passes verification.
In one possible implementation, the remote attestation result comprises an attribute of the second network device, and the certificate issuing apparatus further comprises a processing module, wherein the processing module is used for verifying the authenticity of the remote attestation result, verifying whether the attribute of the second network device meets the certificate issuing condition based on the remote attestation result when the remote attestation result is verified, and determining that the challenge result is verified when the attribute of the second network device meets the certificate issuing condition.
In one possible implementation, the attribute of the second network device comprises a plurality of attribute identifiers, the plurality of attribute identifiers are used for indicating different attributes of the second network device, the certificate issuing condition comprises at least one attribute condition, the at least one attribute condition is used for indicating a condition to be met by the attribute identifier of the second network device, the processing module is specifically used for determining at least one attribute identifier which needs to meet the attribute condition in the plurality of attribute identifiers by the first network device based on the at least one attribute condition, and the first network device is used for determining whether the at least one attribute identifier meets the corresponding attribute condition or not respectively so as to determine whether the attribute of the second network device meets the certificate issuing condition or not.
In one possible implementation, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by the second network device by signing the remote attestation result and the challenge identifier.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list for indicating remote attestation servers that the second network device is able to select when performing remote attestation.
In one possible implementation, the receiving module is further configured to receive a challenge result sent by the second network device, or receive a challenge completion notification sent by the second network device, and obtain the challenge result based on the challenge completion notification, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the receiving module is further configured to receive the attribute evidence sent by the second network device, the sending module is further configured to send the attribute evidence to a remote attestation server, the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result, and the receiving module is further configured to receive the challenge result from the remote attestation server.
In a fourth aspect, a certificate applying apparatus is provided, where the certificate applying apparatus is disposed on a second network device, and the certificate applying apparatus includes a sending module configured to send a certificate applying message to a first network device, where the certificate applying message is used to apply for issuing a certificate, a receiving module configured to receive a challenge message sent by the first network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, and receive, when the second network device completes the challenge and a challenge result of the second network device passes verification, a certificate issued by the first network device, where the challenge result includes a remote attestation result, and where the remote attestation result is used to instruct the second network device to perform a result of a remote attestation process.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by signing the remote attestation result and the challenge content by the second network device.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list, where the remote attestation server list is used to instruct the second network device to select a remote attestation server that can be selected when performing remote attestation, and the sending module is further used to select, by the second network device, one remote attestation server from the remote attestation server list to perform a remote attestation process, and obtain a remote attestation result.
In one possible implementation, the sending module is further configured to send a challenge result to the first network device, or send a challenge completion notification to the first network device, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the sending module is further configured to send the attribute evidence to a first network device, where the first network device is configured to forward the attribute evidence to a remote attestation server, and the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result.
A fifth aspect of the application provides a network device comprising a processor and a memory, wherein the memory is for storing program code, the processor being for invoking the program code in the memory to cause the network device to perform the method as in any of the implementations of the first to second aspects.
A sixth aspect of the present application provides a certificate issuing system comprising a first network device with apparatus as in any of the implementations of the third aspect deployed, and a second network device with apparatus as in any of the implementations of the fourth aspect deployed.
A seventh aspect of the application provides a computer readable storage medium storing instructions that when run on a computer cause the computer to perform a method as any one of the embodiments of the first to second aspects.
An eighth aspect of the application provides a computer program product which, when run on a computer, causes the computer to perform the method as any one of the embodiments of the first to second aspects.
A ninth aspect of the application provides a chip comprising one or more processors. Some or all of the processor is configured to read and execute computer instructions stored in the memory to perform the method of any of the possible implementations of any of the aspects described above. Optionally, the chip further comprises a memory. Optionally, the chip further comprises a communication interface, and the processor is connected with the communication interface. The communication interface is used for receiving data and/or information to be processed, and the processor acquires the data and/or information from the communication interface, processes the data and/or information and outputs a processing result through the communication interface. Optionally, the communication interface is an input-output interface or a bus interface. The method provided by the application is realized by one chip or a plurality of chips in a cooperative manner.
The solutions provided in the third aspect to the ninth aspect are used to implement or cooperatively implement the methods provided in the first aspect to the second aspect, so that the same or corresponding beneficial effects as those in the first aspect to the second aspect can be achieved, and are not described herein.
Drawings
FIG. 1A is a schematic diagram of a remote attestation model provided by the present application;
FIG. 1B is a schematic diagram of challenge types and identifiers of ACME existing in the related art;
FIG. 2 is a schematic flow chart of a method for issuing certificates;
fig. 3 is a schematic flow chart of verifying a challenge result by a first network device according to the present application;
fig. 4 is a schematic flow chart of applying a certificate by a second network device based on a remote certification result obtained in advance;
fig. 5 is a schematic flow chart of a second network device according to the present application, after obtaining an instruction, performing a remote attestation process to apply for a certificate;
FIG. 6 is a flowchart of a second network device according to another embodiment of the present application, after obtaining an instruction, performing a remote attestation process to apply for a certificate;
fig. 7 is a schematic flow chart of a first network device as a proxy device for assisting a second network device in completing a remote certification process according to the present application;
FIG. 8 is a schematic diagram of a certificate issuing apparatus according to the present application;
Fig. 9 is a schematic structural diagram of a certificate applying apparatus provided by the present application;
fig. 10 is a schematic structural diagram of a network device according to the present application.
Detailed Description
In order to make the objects, technical solutions and advantages of the present application more apparent, embodiments of the present application will be described below with reference to the accompanying drawings, and it is apparent that the described embodiments are only some embodiments of the present application, not all embodiments. As a person skilled in the art can know, with the appearance of a new application scenario, the technical scheme provided by the embodiment of the application is also applicable to similar technical problems.
The terms first, second and the like in the description and in the claims and in the above-described figures, are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order.
In order to facilitate understanding, some technical terms related to the present application are described below.
(1) Digital certificate
A digital certificate (hereinafter referred to as a certificate) refers to a digital certificate that marks the identity information of each party in communication in internet communication. A digital certificate is essentially a file issued by a CA that contains public key owner information and a public key. The simplest certificate typically contains a public key, certificate name, and the digital signature of the CA.
(2) Remote attestation
The network equipment (such as a switch, a server, a gateway or terminal equipment and other equipment) sends the security attribute (such as a measurement value of software and hardware, configuration information and node state) of the network equipment to the remote proving equipment through a certain format and an interaction flow, and the remote proving equipment verifies according to a certain strategy to finally prove whether the network equipment is credible or not. In addition, in order to ensure the security of devices and communications throughout the remote attestation protocol interaction process, a certificate mechanism (e.g., a certificate application) must be pre-deployed to support the necessary operations such as checksum viewing of the certificates during the protocol interaction process.
Referring to fig. 1A, fig. 1A is a schematic diagram of a remote certification model according to the present application. As shown in fig. 1A, for a server, a gateway, a terminal device, or other devices that need remote attestation, all may be abstracted to be an attestation Platform (Attest Platform). During the process of the attach Platform, the calculation and recording of the metric values are performed from the TPM trusted Platform module (Trusted Platform Module, TPM) to the basic input output system (Basic Input Output System, BIOS), operating system (Kernel), application (APP). In addition, the Attest Platform interacts with an external certificate authority (Certification Authority, CA) to perform certificate applications and the like. Remote attestation may be performed between the Attest Platform and the remote attestation server (ATTEST SERVER) using a challenge-response approach. That is, the remote attestation device actively initiates a challenge request for attributes of the Attest Platform, and in response to the challenge request, encrypts and signs the attributes such as the metrics and the like recorded by the Attest Platform and information (e.g., device log) for attesting the trustworthiness of the attributes using the certificate applied from the CA, and returns the encrypted and signed security attributes to the remote attestation server. That is, attest Platform is to submit attribute evidence to a remote attestation server for verification. In this way, the remote attestation device and the CA interact to verify that the certificate of Attest Platform is legitimate and to decrypt and verify the security attributes received from Attest Platform. In the case that the security attribute sent by the Attest Platform is verified, the remote attestation server sends a remote attestation result to the Attest Platform.
(3) Digital signature
A digital signature (also called public key digital signature) is a digital string that cannot be forged by others only the signer of the information, and is also a valid proof of the authenticity of the information sent by the signer of the information. Digital signatures are a common physical signature written on paper-like, essentially implemented using techniques in the field of public key cryptography, and are used to authenticate digital information.
When generating a digital signature, a signer processes text by using a hash function to generate a text digest, then encrypts the text digest by using a private key of the signer, and the encrypted digest is used as the digital signature of the text.
In general, digital signatures have two functions, namely, determining that text is indeed signed and sent out by a signer, because others cannot impersonate the signer's signature, and determining the integrity of the text. Because the digital signature is characterized in that it represents a feature of text, if the text changes, the value of the digital signature will also change. That is, different text will get different digital signatures.
(4) Digital signature verification mode
The digital signature verification method is a method for determining the integrity of a text by verifying a digital signature of the text.
Specifically, when verifying the digital signature of the text, the signer first calculates a text digest from the acquired text using the same hash function as the signer, and then decrypts the digital signature transmitted by the signer using the public key to obtain the text digest. If the text abstract calculated by the signer through the hash function is the same as the text abstract obtained by decryption, the signer can confirm that the obtained text is truly complete.
Currently, in automatically issuing a certificate for an ACME client device by an ACME server device, the condition for the ACME server device to issue a certificate is to verify that the ACME client device has ownership of a certain identifier. Thus, implementing certificate issuance based on ACME can only prove that an ACME client device has ownership of a certain identifier, and cannot prove that the ACME client device itself is safe and trusted, resulting in lower security of the certificate issuance process.
Specifically, referring to fig. 1B, fig. 1B is a schematic diagram of challenge types and identifiers of ACME existing in the related art. As shown in fig. 1B, a plurality of AMCE challenge types have been defined in the prior art, and each ACME challenge type typically has a corresponding identifier. In the prior art, however, the type of challenge returned by the ACME server device to the ACME client device is typically to verify whether the ACME client device has ownership of a certain identifier. For example, in the case where the challenge type is hypertext transfer protocol (Hypertext Transfer Protocol, HTTP) -01, the ACME server device is to verify whether the ACME client has ownership of a certain web page. For another example, in the case where the challenge type is Domain name system (Domain NAME SYSTEM, DNS) -01, the ACME server device is to verify whether the ACME client has ownership of DNS.
In view of this, upon the certificate applying apparatus applying for issuing a certificate, the certificate applying apparatus returns a challenge whose challenge type is a remote certification (and whose challenge type is newly defined) to the certificate applying apparatus to instruct the certificate applying apparatus to complete the challenge by performing the remote certification. And under the condition that the certificate issuing equipment verifies that the certificate applying equipment successfully completes the challenge, the certificate issuing equipment issues the certificate. When the certificate application device executes the remote certification, the remote certification server can verify the credibility of the certificate application device, and the remote certification process can be completed only after the credibility of the certificate application device passes the verification. Therefore, under the condition that the certificate applying equipment completes the challenge, the certificate issuing equipment can determine that the credibility of the certificate applying equipment is verified, so that the certificate issuing equipment is ensured to issue a certificate for the credible equipment, and the safety of the certificate issuing process is further ensured.
Specifically, the certificate issuing method provided by the application can be applied to the certificate application scene of various network devices (such as switches, gateways, routers, hubs, servers, personal computers or smart phones and other devices with certificate application requirements), so that only network devices meeting security requirements can obtain certificates.
For example, in a campus scenario, each worker holds a terminal device for checking products, and the terminal device is a network device attributed to a company. To ensure the security of the terminal device, companies will generally continuously update the verification software in the terminal device. But since the terminal device is actually operated by a worker, there may be some workers who do not update the verification software in the terminal device as required (i.e., do not upgrade the verification software to the latest version). In this case, based on the certificate issuing method provided by the application, the certificate issuing device can require the terminal device to execute remote certification and obtain the remote certification result of the terminal device in the process that the worker applies for the certificate by using the terminal device. Then, based on the remote certification result of the terminal device, the certificate issuing device can obtain the version number of the verification software in the terminal device, thereby determining whether to issue a certificate to the terminal device. For example, if the version number of the verification software in the terminal device is lower than the version number set by the company, the issuing of the certificate for the terminal device is refused, so that the terminal device cannot use the certificate for network communication.
As another example, in an operator scenario, firmware or configuration information on a network device (e.g., a router or gateway, etc.) operating in a communication network often has a manufacturer recommended security update channel and a minimum security baseline configuration. Therefore, an operator can perform security baseline management on network equipment in a communication network by adopting the certificate issuing method provided by the application. That is, when the network device applies for a certificate, the certificate issuing device acquires and verifies firmware or configuration information in the network device through the certificate issuing method provided by the application. And when the firmware or the configuration information in the network equipment does not accord with the security baseline configuration, the certificate issuing equipment refuses to issue the certificate for the network equipment, thereby ensuring the security of the network equipment.
Referring to fig. 2, fig. 2 is a schematic flow chart of a certificate issuing method provided by the present application. As shown in fig. 2, the execution flow of the certificate issuing method provided by the present application includes the following steps 201 to 204.
In step 201, the first network device receives a certificate application message sent by the second network device, where the certificate application message is used to apply for issuing a certificate.
In the application, the first network device is a certificate issuing device, for example, an ACME server (i.e. ACME server), and can automatically issue a certificate for the certificate applying device. The second network device is a certificate applying device and needs to request to issue a certificate from a certificate issuing device. The second network device is illustratively a device such as a switch, gateway, router, hub, server, personal computer or smart phone.
When the second network device needs to apply for the certificate, the second network device sends a certificate application message to the first network device so as to apply for the first network device to issue the certificate for the second network device.
Optionally, to facilitate the first network device determining the challenge type supported by the second network device, the credential application message is further used to instruct the second network device to support performing remote attestation. In this way, based on the certificate application message, the first network device confirms that the second network device currently applying the certificate is capable of performing remote attestation, and thus the first network device can instruct the second network device to complete the challenge in the certificate issuing process by performing remote attestation.
Step 202, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
In order to ensure the security of the certificate issuing process, the first network device sends a challenge message to the second network device after receiving the certificate application message, so as to instruct the second network device to complete the challenge specified by the first network device. Wherein the challenge message sent by the first network device specifically indicates that the second network device needs to complete the challenge by performing a remote attestation.
Optionally, since remote attestation is not included in the existing challenge types, a challenge type can be newly defined based on the existing challenge types, and the newly defined challenge type is remote attestation. Based on this, the challenge message sent by the first network device to the second network device includes a challenge type, which is a type for indicating that the second network device needs to complete a challenge task, including remote attestation. For example, the challenge message includes a newly defined challenge type identifier, which can indicate that the challenge task is of a remote attestation type.
In step 203, after the second network device completes the challenge, the first network device obtains a challenge result, where the challenge result includes a remote proof result, and the remote proof result is used to instruct the second network device to execute a result of the remote proof process.
Since the challenge message indicates that the second network device completes the challenge by performing the remote attestation, after the second network device completes the remote attestation and obtains the remote attestation result, the second network device completes the challenge specified by the second network device, thereby obtaining the challenge result.
Wherein the first network device obtains the challenge result from the second network device or other device. Since the challenge performed by the first network device is specifically a process of performing remote attestation, the challenge result may include a remote attestation result to instruct the second network device to perform the result of the remote attestation process.
In general, remote attestation results are generated by a remote attestation server. The second network device submits attribute evidence (evidence) to the remote proving server in the process of executing remote proving, wherein the attribute evidence comprises a plurality of attribute identifiers and information (such as a running log of the second network device) for verifying the credibility of the attribute identifiers, and the attribute identifiers are used for indicating different attributes of the second network device (such as information of hardware in the second network device, version numbers of software in the second network device, configuration information of the second network device and the like). The remote attestation server verifies the proof of the attribute submitted by the second network device (e.g., compares the proof of the attribute submitted by the second network device with a reference value for the device attribute) and generates a remote attestation result based on the verified attribute.
Step 204, in case the challenge result is verified, the first network device issues a certificate to the second network device.
After the challenge result corresponding to the second network device is obtained, the first network device verifies the challenge result. For example, in one alternative implementation, the first network device verifies a remote attestation result of the challenge results to determine the authenticity of the remote attestation result. If the remote proof result is not able to pass the verification, the representative challenge result is not able to pass the verification.
The first network device issues a certificate to the second network device if the challenge result is not capable of verification, and the first network device refuses to issue a certificate to the second network device if the challenge result is not capable of verification.
In the scheme, the certificate issuing process and the remote certification are combined, so that the certificate application equipment can be ensured to verify the credibility of the certificate application equipment by the remote certification server when the certificate is applied, and the remote certification process can be completed only after the credibility of the certificate application equipment passes the verification. Therefore, under the condition that the certificate applying device completes the challenges specified by the certificate issuing device, the certificate issuing device can determine that the credibility of the certificate applying device is verified, so that the certificate issuing device is ensured to issue a certificate for the credible device, and the safety of the certificate issuing process is ensured.
For ease of understanding, the process by which the first network device verifies the challenge results will be described in detail below.
Referring to fig. 3, fig. 3 is a flow chart illustrating a verification of a challenge result by a first network device according to the present application. As shown in fig. 3, the above-described step 204 specifically includes the following steps 2401-2403.
Step 2401, the first network device verifies the authenticity of the remote attestation result.
Since the challenge result includes the remote attestation result, the first network device needs to verify the authenticity of the remote attestation result itself first to determine that the second network device has indeed performed the remote attestation process.
Specifically, the remote attestation result typically includes an attribute of the second network device (i.e., an attribute identifier submitted to the remote attestation device when the second network device performs the remote attestation) and a digital signature derived based on the attribute of the second network device. Therefore, the first network device adopts a digital signature verification mode to verify the digital signature in the remote proof result, so that the authenticity of the remote proof result can be determined, and the authenticity of the remote proof result is verified. The description of the digital signature verification method can be explained with reference to the above technical terms, and will not be repeated here.
Step 2402, when the remote attestation result passes the verification, the first network device verifies whether the attribute of the second network device meets the certificate issuing condition based on the remote attestation result.
The remote proof result includes attributes of the second network device, such as information of hardware in the second network device, version number of software in the second network device, configuration information of the second network device, and the like. And, the first network device is preset with a certificate issuing condition for further verifying whether the second network device applying for the certificate meets the certificate issuing condition.
Specifically, if the authenticity of the remote attestation result is verified, the first network device obtains the attribute of the second network device from the remote attestation result and further verifies whether the attribute of the second network device meets the certificate issuing condition.
Optionally, in the remote attestation result, the attribute of the second network device specifically includes a plurality of attribute identifiers, where the plurality of attribute identifiers are used to indicate different attributes of the second network device. For example, one of the plurality of attribute identifications is information indicating a certain hardware of the second network device, and another one of the plurality of attribute identifications is a version number indicating a certain software of the second network device. The preset certificate issuing conditions in the first network device comprise at least one attribute condition, wherein the at least one attribute condition is used for indicating conditions to be met by the attribute identification of the second network device. For example, each attribute condition in the at least one attribute condition corresponds to one attribute identifier, and each attribute condition is a condition for indicating that the corresponding attribute identifier needs to be satisfied.
In this way, based on at least one of the certificate issuance conditions, the first network device determines at least one of the plurality of attribute identifications of the remote attestation result that is to satisfy the attribute condition. And the first network device respectively determines whether at least one attribute identifier in the remote attestation result meets the corresponding attribute condition so as to determine whether the attribute of the second network device meets the certificate issuing condition.
For example, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number. Therefore, the first network device determines the version number of the target software in the second network device in the plurality of attribute identifiers, and determines whether the version number of the target software is not lower than a preset version number. And if the version number of the target software is lower than the preset version number, the attribute of the second network device is not in accordance with the certificate issuing condition.
In the campus scenario, the second network device is, for example, a terminal device for checking products, and the target software is, for example, checking software for performing product checking in the second network device. Since the second network device is actually operated by a worker, there may be some workers who do not update the verification software in the second network device on demand. Thus, after obtaining the version number of the verification software in the second network device, if the first network device determines that the version number of the verification software in the second network device is lower than the version number set by the company (i.e., the preset version number), issuing of the certificate for the second network device is refused, so that the second network device cannot perform network communication using the certificate.
As another example, in an operator scenario, the second network device is, for example, a network device (e.g., a switch or gateway) in the communication network for performing data forwarding, and the target software is, for example, firmware in the second network device. Since the firmware on the second network device will often have a manufacturer recommended secure update channel and a minimum secure baseline configuration. Thus, after obtaining the version number of the verification software in the second network device, if the first network device determines that the version number of the verification software in the second network device is lower than the version number specified in the security baseline configuration (i.e., the preset version number), issuing of the certificate for the second network device is refused, thereby disabling the second network device from network communication using the certificate.
Further, in the case where at least one attribute condition included in the certificate issuance condition is a plurality of attribute conditions, the first network device needs to determine whether a plurality of attributes of the second network device satisfy the corresponding attribute conditions based on the plurality of attribute identifications in the remote attestation result. The first network device can determine that the attribute of the second network device meets the certificate issuance condition if the attribute of the second network device all meets a plurality of attribute conditions in the certificate issuance condition, or can determine that the attribute of the second network device meets the certificate issuance condition if the number of attribute conditions met by the attribute of the second network device reaches a specified number.
In general, in the case where one attribute condition is preset in the first network device, the first network device determines whether the attribute of the second network device meets the certificate issuing condition based on whether the attribute of the second network device meets the attribute condition.
In the case where a plurality of attribute conditions are preset in the first network device, the first network device determines whether the attribute of the second network device meets the certificate issuing condition based on a pre-specified policy. For example, the pre-specified policy is specifically that the attribute of the second network device meets the certificate issuing condition if the attribute of the second network device meets all the attribute conditions. Or the pre-designated strategy is specifically that when the number of attribute conditions met by the attributes of the second network equipment reaches the designated number, the attributes of the second network equipment meet the certificate issuing conditions.
Step 2403, the first network device determines that the challenge result is validated if the attribute of the second network device meets the certificate issuance condition.
In particular, if the attribute of the second network device meets the certificate issuance condition, the security requirement for certificate issuance is met on behalf of the second network device itself, so the first network device determines that the challenge result is verified. If the attribute of the second network device does not meet the certificate issuance condition, then the first network device determines that the challenge result is not validated on behalf of the second network device itself not meeting the security requirements of certificate issuance.
In the scheme, the certificate issuing equipment further verifies whether the attribute of the certificate application equipment included in the remote proof result accords with the certificate issuing condition or not besides verifying the authenticity of the remote proof result, so that the verification range is expanded to a series of attributes of the certificate application equipment, the certificate issuing equipment can conveniently reject to issue certificates to the certificate application equipment with the attribute which does not accord with the condition, and the safety of the certificate issuing process is further improved. In addition, the certificate issuing equipment acquires the attribute of the certificate application equipment from the remote verification result of the authenticity passing verification, so that the certificate issuing equipment can ensure the authenticity of the acquired attribute of the certificate application equipment, the certificate issuing equipment is prevented from acquiring the forged attribute of the certificate application equipment, and the reliability of the attribute verification process of the certificate application equipment is ensured.
For example, in the case that the certificate issuing condition includes that the version number of the target software is not lower than the preset version number, if the version number of the target software in the second network device is lower than the preset version number, the target software in the second network device is not updated in time and is at risk of being easily attacked, so that the first network device determines that the challenge result of the first network device is not verified, and then refuses to issue a certificate to the second network device, so as to avoid the security risk brought after issuing the certificate to the second network device.
In the present application, there are various ways for the second network device to complete the challenge indicated by the first network device, and how the second network device completes the challenge indicated by the first network device through various implementations will be described below.
In implementation 1, the second network device completes the remote attestation process in advance, and returns a remote attestation result obtained in advance to the first network device after obtaining the challenge indicated by the first network device.
In implementation 1, the second network device has completed the remote attestation process before issuing the certificate to the first network device. And, in the case where the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device can feed back to the first network device a remote attestation result obtained by previously performing the remote attestation process. That is, the second network device is actually multiplexing the existing remote attestation results.
Referring to fig. 4, fig. 4 is a schematic flow chart of applying a certificate by a second network device based on a remote certification result obtained in advance. As shown in fig. 4, the procedure of applying the certificate by the second network device based on the remote certification result obtained in advance includes the following steps 401 to 408.
The second network device sends the attribute evidence to a remote attestation server, step 401.
In the example shown in fig. 4, the second network device performs the remote attestation process before the second network device applies for credentials to the first network device. It should be noted that there are various reasons for triggering the second network device to perform remote attestation in advance. For example, in the case where the second network device has learned that the challenge needs to be completed by performing remote attestation when the second network device has acquired the subsequent application certificate, the second network device triggers the remote attestation to be performed prior to applying the certificate. As another example, the second network device may be triggered to perform remote attestation because of a need to participate in trusted computing or to authenticate itself at an initial start-up. Remote attestation, among other things, is one of the key technologies in trusted computing global solutions, which is commonly used to authenticate whether a device is in a trusted state.
Specifically, in performing the remote attestation, the second network device sends the attribute evidence to the remote attestation server. Wherein the attribute evidence includes a plurality of attribute identifiers and information for verifying the credibility of the plurality of attribute identifiers (such as a running log of the second network device), the plurality of attribute identifiers are used for indicating different attributes of the second network device (such as a metric value obtained in a starting process of the second network device, information of hardware in the second network device, a version number of software in the second network device, configuration information of the second network device, and the like).
The remote attestation server sends the remote attestation result to the second network device, step 402.
After the attribute evidence sent by the second network device is obtained, the remote attestation server verifies the attribute evidence sent by the second network device, so that the verified attribute is determined. In this way, the remote attestation server is able to generate a remote attestation result based on the verified attributes in the second network device and send the generated remote attestation result to the second network device. The remote attestation result includes an attribute of the second network device (i.e., an attribute identifier submitted to the remote attestation device when the second network device performs remote attestation) and a digital signature obtained based on the attribute of the second network device.
In general, the process by which the second network device performs remote attestation is similar to an existing remote attestation process, and in particular reference may be made to an existing remote attestation process.
In step 403, the first network device receives the certificate application message sent by the second network device.
In the case that the remote certification result has been obtained and the second network device needs to request the first network device to issue a certificate, the second network device sends a certificate application message to the first network device.
Optionally, because the second network device has completed the remote attestation process and obtained the remote attestation result, the second network device can carry the identifier of the remote attestation result in the sent certificate application message, thereby declaring to the first network device that the second network device has the remote attestation result. Or the certificate application message carries an identifier of the remote proving client, and the identifier of the remote proving client is used for representing the identity of the remote proving client used by the second network device when executing the remote proving process.
In general, the present application is not limited to the implementation manner of the identifier carried in the certificate application message, as long as it is ensured that the identifier carried in the certificate application message can indicate that the second network device supports remote attestation or that the second network device has completed the remote attestation process.
The first network device sends a challenge message to the second network device, the challenge message instructing the second network device to complete the challenge by performing a remote attestation, step 404.
In this example, the challenge message sent by the first network device includes a challenge type and a challenge identification. Wherein the type of challenge is used to indicate that the second network device is to perform the challenge task includes remote attestation. It should be noted that, in some cases, the challenge message sent by the first network device may also be used to indicate that the challenge task to be completed by the second network device includes other challenge types. That is, the challenge types that the second network device needs to accomplish the challenge task include both remote attestation and other challenge types, such as a hypertext transfer protocol (Hypertext Transfer Protocol, HTTP) challenge type or a Domain name system (Domain NAME SYSTEM, DNS) challenge type.
The challenge identification is used to identify a current challenge task that the second network device is required to complete. For example, the challenge is identified as a random number generated by the first network device, or the challenge is identified as a sequence number generated by the first network device based on the number of received credential application messages. In general, the challenge identification is used to uniquely identify a challenge task that the second network device is currently required to complete, so that the subsequent first network device can confirm to which challenge task the challenge result fed back by the second network device corresponds.
In step 405, the first network device obtains a challenge result including a remote attestation result.
The first network device obtains the challenge result in a plurality of ways.
In one possible implementation, a first network device receives a challenge result sent by a second network device. Specifically, the challenge result includes a remote attestation result, a challenge identification, and signature information. The signature information is a digital signature obtained by signing the remote proving result and the challenge identifier by the second network device. That is, the second network device generates a challenge result based on the obtained remote attestation result, and transmits the challenge result to the second network device.
In another possible implementation manner, the first network device receives a challenge completion notification sent by the second network device, and obtains a challenge result based on the challenge completion notification, where the challenge completion notification is used to indicate a location where the challenge result is stored. That is, after generating the challenge result based on the remote attestation result, the second network device does not directly transmit the challenge result to the first network device, but stores the challenge result in a specific location, and notifies the first network device to acquire the challenge result from the specific location. In such implementations, the challenge types that the first network device indicates the challenge tasks that the second network device needs to accomplish include, among other challenge types, remote attestation. For example, when the challenge type of the challenge task to be completed by the second network device specifically includes remote proof and HTTP challenge type, the second network device stores the challenge result at the address of a certain web page, and notifies the first network device to obtain the challenge result from the web page. For another example, when the challenge type of the challenge task to be completed by the second network device specifically includes a remote attestation and a DNS challenge type, the second network device deposits the challenge result on the resolved address of the DNS, and notifies the first network device to obtain the challenge result from the resolved address of the DNS.
In step 406, the first network device verifies the authenticity of the remote attestation result in the challenge result.
After obtaining the challenge result, the first network device verifies the authenticity of the challenge result. Specifically, the first network device verifies the authenticity of the challenge result by adopting a digital signature verification mode based on the signature information in the challenge result, so as to determine whether the challenge result obtained by the first network device is the challenge result generated by the second network device.
And under the condition that the challenge result passes the verification, the first network equipment re-verifies the authenticity of the remote proof result in the challenge result. Specifically, since the remote proof result includes a digital signature, the first network device may verify the digital signature of the remote proof result by adopting a digital signature verification method, thereby implementing verification of authenticity of the remote proof result.
In step 407, in the case that the authenticity of the remote attestation result is verified, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuing condition.
Step 407 is similar to step 2042, and please refer to step 2042, which is not described herein.
In step 408, the first network device issues a certificate to the second network device in case the challenge result is verified.
And under the condition that the first network device determines that the attribute of the second network device in the remote proving result meets the certificate issuing condition, the first network device determines that the challenge result passes verification, so that the certificate is issued to the second network device.
Implementation 2, after obtaining the challenge indicated by the first network device, the second network device performs a remote attestation process, and returns a remote attestation result to the first network device.
In implementation 2, the second network device does not perform the remote attestation process until a certificate is applied to the first network device. When the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device re-performs the remote attestation process.
For example, referring to fig. 5, fig. 5 is a schematic flow chart of a second network device according to the present application, after obtaining an instruction, performing a remote attestation process to apply for a certificate. As shown in fig. 5, the second network device, after acquiring the indication of the first network device, performs a remote attestation process to implement the certificate application, which includes the following steps 501-508.
In step 501, the first network device receives a certificate application message sent by the second network device.
It should be noted that, unlike step 403 described above, in step 501, since the second network device has not completed the remote attestation process, the certificate application message sent by the second network device only indicates that the second network device supports the remote attestation process, and does not carry the identifier of the remote attestation result or the identifier of the remote attestation client.
Step 502, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
The challenge message sent by the first network device includes a challenge type and a challenge identifier. The type of challenge is used to indicate that the second network device is required to complete the challenge task, including remote attestation, and the challenge identifier is used to identify the current challenge task that the second network device is required to complete.
Optionally, the challenge message further includes a remote attestation server (Verifier) list, where the remote attestation server list is used to instruct the second network device of a remote attestation server that can be selected when performing the remote attestation. That is, the first network device specifies in the challenge message through the remote attestation server list which remote attestation servers the second network device needs to select one of to complete the remote attestation process. Wherein the remote attestation server list includes one or more remote attestation servers, and the remote attestation servers included in the remote attestation server list are all remote attestation servers trusted by the first network device.
The second network device sends the attribute evidence to the remote attestation server, step 503.
Upon receiving the challenge message, the second network device determines that a remote attestation process needs to be performed to complete the challenge indicated by the first network device, and thus the second network device sends the attribute evidence to the remote attestation server.
Optionally, in the case that the challenge message further includes a list of remote attestation servers, the second network device needs to select one of the remote attestation servers in the list of remote attestation servers and send the attribute evidence to the remote attestation server.
The remote attestation server sends 504 the remote attestation result to the second network device.
After the remote attestation server verifies the attribute evidence sent by the second network device, the remote attestation server generates a remote attestation result based on the verified attribute in the attribute evidence and sends the remote attestation result to the second network device.
In step 505, the first network device obtains a challenge result including a remote attestation result.
After obtaining the remote attestation result, the second network device may generate a challenge result based on the remote attestation result, thereby enabling the first network device to obtain the challenge result including the remote attestation result. The manner in which the first network device obtains the challenge result is similar to the above-mentioned step 405, and the detailed description of the step 405 is omitted herein.
In step 506, the first network device verifies the authenticity of the remote attestation result in the challenge result.
In step 507, in the case that the authenticity of the remote attestation result is verified, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuing condition.
In step 508, the first network device issues a certificate to the second network device if the challenge result is verified.
Steps 506-508 are similar to steps 406-408 described above, and refer to steps 406-408 specifically, and are not repeated here.
Implementation 3, after acquiring the challenge indicated by the first network device, the second network device performs a remote attestation process based on the challenge identifier provided by the first network device, and returns a remote attestation result including the challenge identifier to the first network device.
In implementation 3, the second network device does not perform the remote attestation process until a certificate is applied to the first network device. When the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device re-performs the remote attestation process. And, when the second network device performs the remote attestation process, the challenge identifier provided by the first network device needs to be submitted to the remote attestation server as attribute evidence, so as to obtain a remote attestation result including the challenge identifier.
Referring to fig. 6, fig. 6 is a schematic flow chart of a second network device according to another embodiment of the present application, after obtaining an indication, performing a remote attestation process to apply for a certificate. As shown in fig. 6, the second network device, after acquiring the indication of the first network device, performs a remote attestation process to implement the certificate application, which includes the following steps 601-609.
In step 601, the first network device receives a certificate application message sent by the second network device.
In step 602, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
Steps 601-602 are similar to steps 501-502 described above, and refer to steps 501-502 specifically.
It should be noted that, the challenge message sent by the first network device includes a challenge type and a challenge identifier, where the challenge type is used to indicate that the type of the challenge task to be completed by the second network device includes remote attestation, and the challenge identifier is used to identify the current challenge task to be completed by the second network device. And, the challenge message is specifically further for instructing the second network device to perform remote attestation with the challenge identification as part of the attribute proof.
The second network device sends 603 attribute evidence including the challenge identification to the remote attestation server.
Since the challenge message is also used to instruct the second network device to perform remote attestation with the challenge identity as part of the attribute evidence, to deeply couple the certificate issuing process with the remote attestation process, the second network device transmits the challenge identity transmitted by the first network device to the remote attestation server as part of the attribute evidence. That is, in the attribute proof transmitted by the second network device, the challenge identifier, the plurality of attribute identifiers, and information for verifying the trustworthiness of the plurality of attribute identifiers are included.
The remote attestation server sends the remote attestation result to the second network device, step 604.
In this step, after receiving the attribute evidence, the remote attestation server can verify the challenge identifier in the attribute evidence in addition to verifying the plurality of attribute identifiers in the attribute evidence, and finally generates a remote attestation result including the challenge identifier and the plurality of attribute identifiers. That is, the challenge identifier and the plurality of attribute identifiers are actually included in the remote attestation results received by the second network device.
In step 605, the first network device obtains a challenge result including a remote attestation result.
In step 605, the first network device obtains the challenge result in a manner similar to that described in step 405 above, and refer to step 405 above.
It should be noted that, in step 605, the remote proof result in the challenge result obtained by the first network device includes the challenge identifier.
In step 606, the first network device verifies the authenticity of the remote attestation result in the challenge result.
In step 607, in case the authenticity of the remote attestation result is verified, the first network device verifies whether the correct challenge identification is included in the remote attestation result.
That is, the first network device needs to verify whether the remote attestation result includes the correct challenge identifier in addition to verifying the authenticity of the remote attestation result itself. Specifically, the first network device verifies whether the remote proof result includes the challenge identifier. In the case that the challenge identifier is included in the remote proof result, the first network device re-verifies whether the challenge identifier included in the remote proof result is a correct challenge identifier, that is, whether the challenge identifier included in the remote proof result is the same as the challenge identifier of the second network device to which the first network device sends.
In step 608, in the case that the remote attestation result includes the correct challenge identifier, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuance condition.
In the case that the authenticity of the remote attestation result is verified, and the challenge identifier included in the remote attestation result is the same as the challenge identifier of the second network device sent by the first network device, the first network device determines that the remote attestation result is verified. That is, the first network device can determine that the second network device did complete the challenge task indicated by the first network device. Thus, the first network device continues to verify whether the attribute of the second network device in the remote attestation result meets the certificate issuance condition.
In step 609, the first network device issues a certificate to the second network device if the challenge result is verified.
In implementation 4, after the first network device indicates the challenge to be completed to the second network device, the first network device is used as a proxy device to assist the second network device to complete the remote attestation process, and the remote attestation result is obtained.
In implementation 4, the second network device does not perform the remote attestation process until a certificate is applied to the first network device. When the first network device instructs the second network device to complete the challenge by performing the remote attestation, the second network device re-performs the remote attestation process. And the second network device sends the attribute evidence to the first network device when the remote proving process is executed, and the first network device is used as a proxy device to assist the second network device to complete the remote proving process.
Referring to fig. 7, fig. 7 is a flow chart of a first network device as a proxy device for assisting a second network device in completing a remote attestation process according to the present application. As shown in fig. 7, the process of the first network device acting as a proxy device to assist the second network device in completing the remote attestation process includes the following steps 701-708.
In step 701, the first network device receives a certificate application message sent by the second network device.
In step 702, the first network device sends a challenge message to the second network device, the challenge message being used to instruct the second network device to complete the challenge by performing a remote attestation.
Steps 701-702 are similar to steps 501-502 described above, and refer to steps 501-502 described above.
It should be noted that, in the challenge message sent by the first network device to the second network device, the challenge identifier is optional. That is, the challenge message can be one that includes a challenge identification, or the challenge message can be one that does not include a challenge identification.
Optionally, the challenge message sent by the first network device to the second network device is further used to instruct the second network device to complete the remote attestation process through the first network device.
The second network device sends attribute evidence to the first network device, step 703.
Upon receiving the challenge message, the second network device, upon performing the remote attestation, no longer transmits the attribute evidence to the remote attestation server, but rather transmits the attribute evidence to the first network device.
The first network device forwards the attribute evidence to a remote attestation server, step 704.
Because the first network device assists the second network device in completing the remote attestation process, the first network device needs to forward the attribute evidence to the remote attestation server after receiving the attribute evidence sent by the second network device.
Step 705, the first network device obtains a remote attestation result from the remote attestation server, and uses the remote attestation result as a challenge result.
And after the remote proving server verifies the attribute of the second network device based on the attribute evidence forwarded by the first network device, a remote proving result can be generated. At this time, the first network device can directly obtain the remote certification result from the remote certification server, and use the remote certification result as the challenge result of the second network device. That is, the second network device no longer needs to acquire the remote attestation result and send the acquired remote attestation result to the first network device, thereby reducing communication overhead of the second network device.
In step 706, the first network device verifies the authenticity of the remote attestation result.
In step 707, in the case that the authenticity of the remote attestation result is verified, the first network device verifies whether the attribute of the second network device in the remote attestation result meets the certificate issuing condition.
Step 708, the first network device issues a certificate to the second network device in case the challenge result is verified.
Steps 706-708 are similar to steps 406-408 described above, and refer to steps 406-408 specifically, and are not repeated here.
Having described the certificate issuing method provided by the present application, an apparatus for performing the above-described certificate issuing method will be described below.
Referring to fig. 8, fig. 8 is a schematic structural diagram of a certificate issuing apparatus according to the present application. As shown in fig. 8, the certificate issuing apparatus is deployed on the first network device, and the certificate issuing apparatus includes a receiving module 801 for receiving a certificate application message sent by the second network device, where the certificate application message is used to apply for issuing a certificate, a sending module 802 for sending a challenge message to the second network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, a receiving module 801 further for obtaining a challenge result after the second network device completes the challenge, where the challenge result includes a remote attestation result, where the remote attestation result is used to instruct the second network device to perform a result of the remote attestation process, and a sending module 802 further for issuing the certificate to the second network device if the challenge result passes verification.
In a possible implementation manner, the remote proof result comprises the attribute of the second network device, the certificate issuing apparatus further comprises a processing module 803, and the processing module 803 is used for verifying the authenticity of the remote proof result, verifying whether the attribute of the second network device meets the certificate issuing condition based on the remote proof result when the remote proof result is verified, and determining that the challenge result is verified when the attribute of the second network device meets the certificate issuing condition.
In one possible implementation, the attribute of the second network device includes a plurality of attribute identifiers, the plurality of attribute identifiers are used for indicating different attributes of the second network device, the certificate issuing condition includes at least one attribute condition, the at least one attribute condition is used for indicating a condition to be met by the attribute identifier of the second network device, the processing module 803 is specifically used for determining at least one attribute identifier to be met by the first network device in the plurality of attribute identifiers based on the at least one attribute condition, and the first network device respectively determines whether the at least one attribute identifier meets the corresponding attribute condition to determine whether the attribute of the second network device meets the certificate issuing condition.
In one possible implementation, the plurality of attribute identifications includes a version number of the target software in the second network device, and the at least one attribute condition includes that the version number of the target software is not lower than a preset version number.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by the second network device by signing the remote attestation result and the challenge identifier.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list for indicating remote attestation servers that the second network device is able to select when performing remote attestation.
In a possible implementation manner, the receiving module 801 is further configured to receive a challenge result sent by the second network device, or receive a challenge completion notification sent by the second network device, and obtain the challenge result based on the challenge completion notification, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the receiving module 801 is further configured to receive the attribute evidence sent by the second network device, the sending module 802 is further configured to send the attribute evidence to a remote attestation server, where the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result, and the receiving module 801 is further configured to receive the challenge result from the remote attestation server.
Referring to fig. 9, fig. 9 is a schematic structural diagram of a certificate applying apparatus provided by the present application. As shown in fig. 9, the certificate applying apparatus is disposed on the second network device, and the certificate applying apparatus includes a sending module 901 configured to send a certificate applying message to the first network device, where the certificate applying message is used to apply for issuing a certificate, a receiving module 902 configured to receive a challenge message sent by the first network device, where the challenge message is used to instruct the second network device to complete a challenge by performing remote attestation, and the receiving module 902 is further configured to receive, when the second network device completes the challenge and a challenge result of the second network device passes verification, the certificate issued by the first network device, where the challenge result includes a remote attestation result, and the remote attestation result is used to instruct the second network device to perform a result of the remote attestation process.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge result includes a remote attestation result, a challenge identifier, and signature information, and the signature information is obtained by signing the remote attestation result and the challenge content by the second network device.
In one possible implementation, the credential application message is further used to instruct the second network device to support performing remote attestation.
In one possible implementation, the challenge message includes a challenge type and a challenge identifier, the challenge type is used for indicating that the type of the challenge task to be completed by the second network device includes remote attestation, the challenge identifier is used for identifying the current challenge task to be completed by the second network device, the challenge message is used for indicating that the second network device performs remote attestation by using the challenge identifier as part of attribute evidence, and the challenge result is verified, including that the authenticity of the remote attestation result is verified and the challenge identifier is included in the remote attestation result.
In one possible implementation, the challenge message includes a remote attestation server list, where the remote attestation server list is used to instruct the second network device to select a remote attestation server that can be selected when performing remote attestation, and the sending module 901 is further configured to select, by the second network device, one remote attestation server from the remote attestation server list to perform a remote attestation process, and obtain a remote attestation result.
In one possible implementation, the sending module 901 is further configured to send a challenge result to the first network device, or send a challenge completion notification to the first network device, where the challenge completion notification is used to indicate a location where the challenge result is stored.
In one possible implementation, the sending module 901 is further configured to send the attribute evidence to a first network device, where the first network device is configured to forward the attribute evidence to a remote attestation server, and the remote attestation server is configured to verify the attribute evidence and generate a remote attestation result.
Fig. 10 is a schematic structural diagram of a network device according to the present application. As shown in fig. 10, the network device 1000 is equipped with the above-described certificate issuing apparatus or certificate applying apparatus. The network device 1000 is implemented by a general bus architecture.
The network device 1000 includes at least one processor 1001, a communication bus 1002, a memory 1003, and at least one communication interface 1004.
Alternatively, the processor 1001 is a general-purpose CPU, NP, microprocessor, or one or more integrated circuits for implementing aspects of the application, such as an application-specific integrated circuit (ASIC), a programmable logic device (programmable logic device, PLD), or a combination thereof. The PLD is a complex programmable logic device (complex programmable logic device, CPLD), a field-programmable gate array (FPGA) GATE ARRAY, a generic array logic (GENERIC ARRAY logic, GAL), or any combination thereof.
Communication bus 1002 is used to transfer information between the aforementioned components. The communication bus 1002 is classified into an address bus, a data bus, a control bus, and the like. For ease of illustration, the figures are shown with only one bold line, but not with only one bus or one type of bus.
Alternatively, the memory 1003 is a read-only memory (ROM) or other type of static storage device that can store static information and instructions. Memory 1003 is alternatively a random access memory (random access memory, RAM) or other type of dynamic storage device that can store information and instructions. Alternatively, memory 1003 is an electrically erasable programmable read-only Memory (EEPROM), a compact disk (compact disc read-only Memory, CD-ROM) or other optical disk storage, optical disk storage (including compact disk, laser disk, optical disk, digital versatile disk, blu-ray disk, etc.), magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to such. Alternatively, the memory 1003 is separate and coupled to the processor 1001 by a communication bus 1002. Optionally, memory 1003 and processor 1001 are integrated.
The communication interface 1004 uses any transceiver-like device for communicating with other devices or communication networks. Communication interface 1004 includes a wired communication interface. Optionally, the communication interface 1004 further includes a wireless communication interface. The wired communication interface is, for example, an ethernet interface. The ethernet interface is an optical interface, an electrical interface, or a combination thereof. The wireless communication interface is a wireless local area network (wireless local area networks, WLAN) interface, a cellular network communication interface, a combination thereof, or the like.
In a particular implementation, as one embodiment, the processor 1001 includes one or more CPUs, such as CPU0 and CPU1 shown in FIG. 10.
In a specific implementation, as an embodiment, the network device 1000 includes a plurality of processors, such as processor 1001 and processor 1005 shown in fig. 10. Each of these processors is a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein refers to one or more devices, circuits, and/or processing cores for processing data (e.g., computer program instructions).
In some embodiments, memory 1003 is used to store program code 1006 for performing aspects of the present application, and processor 1001 executes program code 1006 stored in memory 1003. That is, the network device 1000 implements the above-described method embodiments by the processor 1001 and the program code 1006 in the memory 1003.
The application also provides a certificate issuing system, which comprises a first network device and a second network device, wherein the first network device is provided with a certificate issuing device according to the embodiment corresponding to fig. 8, and the second network device is provided with a certificate applying device according to the embodiment corresponding to fig. 9.
In this specification, each embodiment is described in a progressive manner, and identical and similar parts of each embodiment are referred to each other, and each embodiment is mainly described as a difference from other embodiments.
A refers to B, referring to a simple variation where A is the same as B or A is B.
The terms first and second and the like in the description and in the claims of embodiments of the application, are used for distinguishing between different objects and not necessarily for describing a particular sequential or chronological order of the objects, and should not be interpreted to indicate or imply relative importance. For example, a first speed limiting channel and a second speed limiting channel are used to distinguish between different speed limiting channels, rather than to describe a particular order of speed limiting channels, nor should the first speed limiting channel be understood to be more important than the second speed limiting channel.
In the embodiments of the present application, unless otherwise indicated, the meaning of "at least one" means one or more, and the meaning of "a plurality" means two or more.
The above-described embodiments may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in software, may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When loaded and executed on a computer, produces a flow or function in accordance with embodiments of the present application, in whole or in part. The computer may be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions may be stored in or transmitted from one computer-readable storage medium to another, for example, by wired (e.g., coaxial cable, optical fiber, digital Subscriber Line (DSL)), or wireless (e.g., infrared, wireless, microwave, etc.). The computer readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that contains an integration of one or more available media. The usable medium may be a magnetic medium (e.g., floppy disk, hard disk, tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk Solid STATE DISK (SSD)), etc.
The foregoing embodiments are merely for illustrating the technical solution of the present application, but not for limiting the same, and although the present application has been described in detail with reference to the foregoing embodiments, it will be understood by those skilled in the art that modifications may be made to the technical solution described in the foregoing embodiments or equivalents may be substituted for parts of the technical features thereof, and such modifications or substitutions do not depart from the spirit of the corresponding technical solution from the scope of the technical solution of the embodiments of the present application.
Claims (24)
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202411186320.0A CN121619102A (en) | 2024-08-27 | 2024-08-27 | Certificate issuing method and related device |
| PCT/CN2025/071975 WO2026045076A1 (en) | 2024-08-27 | 2025-01-13 | Certificate issuance method and related apparatus |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202411186320.0A CN121619102A (en) | 2024-08-27 | 2024-08-27 | Certificate issuing method and related device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| CN121619102A true CN121619102A (en) | 2026-03-06 |
Family
ID=98915230
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN202411186320.0A Pending CN121619102A (en) | 2024-08-27 | 2024-08-27 | Certificate issuing method and related device |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN121619102A (en) |
| WO (1) | WO2026045076A1 (en) |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103179129B (en) * | 2013-03-29 | 2016-04-13 | 华南理工大学 | A kind of remote certification method based on cloud computing IaaS environment |
| WO2016195708A1 (en) * | 2015-06-05 | 2016-12-08 | Hewlett Packard Enterprise Development Lp | Remote attestation of a network endpoint device |
| US10944578B2 (en) * | 2019-07-24 | 2021-03-09 | Advanced New Technologies Co., Ltd. | Identity verification |
| CN112187771B (en) * | 2020-09-23 | 2023-04-07 | 华控清交信息科技(北京)有限公司 | Authentication method, device and device for authentication |
| CN115334506B (en) * | 2022-08-08 | 2025-05-02 | 国网智能电网研究院有限公司 | A user trusted access system and method for 5G edge computing nodes |
| CN116318728B (en) * | 2023-03-20 | 2024-03-26 | 中国科学院软件研究所 | Distributed certificate automatic issuing method, device and system |
| CN116896463A (en) * | 2023-07-10 | 2023-10-17 | 北京微芯区块链与边缘计算研究院 | Trusted environment authentication method and device based on blockchain |
-
2024
- 2024-08-27 CN CN202411186320.0A patent/CN121619102A/en active Pending
-
2025
- 2025-01-13 WO PCT/CN2025/071975 patent/WO2026045076A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| WO2026045076A1 (en) | 2026-03-05 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN115333792B (en) | Identity authentication method, device and related equipment | |
| US11711219B1 (en) | PKI-based user authentication for web services using blockchain | |
| JP2023541599A (en) | Service communication methods, systems, devices and electronic equipment | |
| CN111526159B (en) | Method and device for establishing data connection, terminal equipment and storage medium | |
| US20170099148A1 (en) | Securely authorizing client applications on devices to hosted services | |
| CN113678131B (en) | Protecting online applications and websites using blockchain | |
| US10516653B2 (en) | Public key pinning for private networks | |
| CN111783068A (en) | Device authentication method, system, electronic device and storage medium | |
| CN111414640B (en) | Key access control method and device | |
| US11240246B2 (en) | Secure confirmation exchange for offline industrial machine | |
| CN114553480A (en) | Cross-domain single sign-on method and device | |
| US11296878B2 (en) | Private key updating | |
| US20210037005A1 (en) | System And Method Of Single Sign On To Master Website And Silent Authentication For Subservient Websites | |
| US12323466B1 (en) | Policy exceptions for assessment of network system assets | |
| CN115276998A (en) | IoT authentication method, device and IoT device | |
| EP4540966A1 (en) | Certificate issuing for virtual network functions | |
| CN117595996A (en) | An electronic signature processing method, device, electronic equipment and storage medium | |
| WO2019184206A1 (en) | Identity authentication method and apparatus | |
| CN111031067A (en) | Monitoring data transmission method, device and electronic device for distributed system | |
| CN108228280A (en) | The configuration method and device of browser parameters, storage medium, electronic equipment | |
| CN121619102A (en) | Certificate issuing method and related device | |
| US20230155842A1 (en) | Method and apparatus for certifying an application-specific key and for requesting such certification | |
| CN119316144A (en) | Certificate issuance method, device, system, storage medium and computer program product | |
| US12388662B2 (en) | Automated security certificate techniques | |
| US12022002B2 (en) | Apparatus, methods, and program products for generating secure short universal resource locators |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication |