Method and apparatus for managing digital certificate
View Patent ↗Provided are a method and apparatus for managing a digital certificate. A specific implementation of the method includes: receiving a digital certificate generation request sent by a user; according to a digital certificate application scenario, determining a preset threshold value corresponding to the digital certificate application scenario; broadcasting first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, where the aggregated public key corresponding to the threshold value is generated by means of aggregating public key components of the blockchain node on the basis of a signature generation algorithm; and aggregating the first signature information to generate a digital certificate for the user.
1 . A method for managing a digital certificate, comprising:
receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user and a digital certificate application scenario;
determining a preset threshold value corresponding to the digital certificate application scenario according to the digital certificate application scenario, wherein the threshold value indicates a number of blockchain nodes, which participate in digital certificate generation, in all blockchain nodes;
broadcasting the first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, wherein the aggregated public key corresponding to the threshold value is generated by means of aggregating a public key component of the blockchain node on the basis of a signature generation algorithm; and
aggregating the first signature information to generate the digital certificate for the user.
2 . The method for managing the digital certificate as claimed in claim 1 , further comprising:
uploading the digital certificate to the blockchain, so as to allow a blockchain node needing to verify the digital certificate or a smart contract to verify the digital certificate according to the aggregated public key corresponding to the threshold value.
3 . The method for managing the digital certificate as claimed in claim 1 , further comprising:
receiving a digital certificate revocation request sent by the user, wherein the digital certificate revocation request indicates second user information of the user and a digital certificate to be revoked;
broadcasting the second user information to the blockchain according to a threshold value when the digital certificate to be revoked is generated, to enable a blockchain node, which participates in generation of an aggregated public key corresponding to the threshold value, to sign the second user information by using the private key component of the blockchain node, so as to generate second signature information; and
aggregating the second signature information to generate a revocation certificate corresponding to the digital certificate to be revoked.
4 . The method for managing the digital certificate as claimed in claim 3 , further comprising:
uploading the revocation certificate to the blockchain, so as to allow a blockchain node needing to verify the digital certificate or a smart contract to verify the revocation certificate according to the aggregated public key corresponding to the threshold value.
5 . The method for managing the digital certificate as claimed in claim 1 , wherein before receiving the digital certificate generation request sent by the user, the method further comprises:
according to the threshold value, determining, from all blockchain nodes, one or more blockchain nodes that participate in generation of the aggregated public key corresponding to the threshold value;
aggregating public key components of the determined one or more blockchain nodes on the basis of a signature algorithm, so as to generate, for each blockchain node, the same aggregated public key corresponding to the threshold value; and
calculating one blockchain node from the determined blockchain nodes, so as to write the aggregated public key into a genesis block of the blockchain, and to allow other blockchain nodes, which participate generation of the aggregated public key corresponding to the threshold value, to verify the aggregated public key in the genesis block.
6 . The method for managing the digital certificate as claimed in claim 5 , further comprising:
broadcasting preset root certificate information to the blockchain when a verification of the aggregated public key is passed, to enable the blockchain node, which participates in generation of the aggregated public key, to sign the preset root certificate information by using the private key component of the blockchain node, so as to generate third signature information; and
aggregating the third signature information to generate a root certificate corresponding to the aggregated public key, and writing the root certificate into the genesis block of the blockchain.
7 . The method for managing the digital certificate as claimed in claim 1 ,
wherein the digital certificate indicates identifier information of the one or more blockchain nodes.
8 . The method for managing the digital certificate as claimed in claim 1 , further comprising:
generating an asymmetric key pair for each blockchain node, wherein the asymmetric key pair indicates a public key component and a private key component, corresponding to the blockchain node.
9 . The method for managing the digital certificate as claimed in claim 1 , further comprising:
generating an asymmetric key pair for a newly-added blockchain node when there is one or more newly-added blockchain nodes on a blockchain, wherein the asymmetric key pair indicates a public key component and a private key component, corresponding to the newly-added blockchain node;
aggregating public key components of the one or more blockchain nodes on the blockchain on the basis of a signature generation algorithm, so as to generate one or more first aggregated public keys; and
updating, according to the one or more first aggregated public keys, one or more second aggregated public keys already present in a genesis block of the blockchain, wherein the second aggregated public key is generated by means of aggregating public key components of the one or more blockchain nodes on the blockchain on the basis of the signature generation algorithm before the one or more nodes are newly added to the blockchain.
10 . The method for managing the digital certificate as claimed in claim 9 , wherein updating, according to the one or more first aggregated public keys, the one or more second aggregated public keys already present in the genesis block of the blockchain comprises:
writing the one or more first aggregated public keys in the genesis block of the blockchain, and reserving the one or more second aggregated public keys already present in the genesis block;
wherein the method further comprising:
receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user;
broadcasting the first user information to the blockchain, to enable a blockchain node on the blockchain, which participates in generation of the same first aggregated public key, to sign the first user information by using a corresponding private key component, so as to generate first signature information; and
aggregating the first signature information to generate a digital certificate for the user, wherein the digital certificate indicates identifier information of the blockchain node.
11 . The method for managing the digital certificate as claimed in claim 1 , further comprising:
when one or more blockchain nodes are deleted from a blockchain, aggregating public key components of one or more blockchain nodes on the blockchain on the basis of a signature generation algorithm, so as to generate one or more first aggregated public keys; and
updating, according to the one or more first aggregated public keys, one or more second aggregated public keys already present in a genesis block of the blockchain, wherein the second aggregated public key is generated by means of aggregating the public key components of one or more blockchain nodes on the blockchain on the basis of the signature generation algorithm before the one or more blockchain nodes are deleted.
12 . An electronic device for managing a digital certificate, comprising:
one or more processors; and
a storage apparatus, configured to store one or more programs, wherein
when the one or more programs are executed by the one or more processors, the one or more processors are enabled to implement following actions:
receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user and a digital certificate application scenario;
determining a preset threshold value corresponding to the digital certificate application scenario according to the digital certificate application scenario, wherein the threshold value indicates a number of blockchain nodes, which participate in digital certificate generation, in all blockchain nodes;
broadcasting the first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, wherein the aggregated public key corresponding to the threshold value is generated by means of aggregating a public key component of the blockchain node on the basis of a signature generation algorithm; and
aggregating the first signature information to generate the digital certificate for the user.
13 . A non-transitory computer-readable medium, having a computer program stored thereon, wherein when the program is executed by a processor, the processor is enable to implement following actions: receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user and a digital certificate application scenario; determining a preset threshold value corresponding to the digital certificate application scenario according to the digital certificate application scenario, wherein the threshold value indicates a number of blockchain nodes, which participate in digital certificate generation, in all blockchain nodes; broadcasting the first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, wherein the aggregated public key corresponding to the threshold value is generated by means of aggregating a public key component of the blockchain node on the basis of a signature generation algorithm; and aggregating the first signature information to generate the digital certificate for the user.