IP Library › Granted Patent US 12,676,759
Granted Patent B2
US 12,676,759 · App. 18/288,811 · Granted Jul 7, 2026

Method and apparatus for managing digital certificate

Inventors: Yun Huo (Beijing, CN); Gang Di (Beijing, CN)
Assignee: DIGITAL CURRENCY INSTITUTE, THE PEOPLE'S BANK OF CHINA
H04L9/3263H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,676,759
App. No.
18/288,811
Filed
Oct 28, 2023
Granted
Jul 7, 2026
Kind
B2
Art Unit
2407
USPC
713/171
Abstract

Provided are a method and apparatus for managing a digital certificate. A specific implementation of the method includes: receiving a digital certificate generation request sent by a user; according to a digital certificate application scenario, determining a preset threshold value corresponding to the digital certificate application scenario; broadcasting first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, where the aggregated public key corresponding to the threshold value is generated by means of aggregating public key components of the blockchain node on the basis of a signature generation algorithm; and aggregating the first signature information to generate a digital certificate for the user.

Claims (46)

1 . A method for managing a digital certificate, comprising:

receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user and a digital certificate application scenario;

determining a preset threshold value corresponding to the digital certificate application scenario according to the digital certificate application scenario, wherein the threshold value indicates a number of blockchain nodes, which participate in digital certificate generation, in all blockchain nodes;

broadcasting the first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, wherein the aggregated public key corresponding to the threshold value is generated by means of aggregating a public key component of the blockchain node on the basis of a signature generation algorithm; and

aggregating the first signature information to generate the digital certificate for the user.

2 . The method for managing the digital certificate as claimed in claim 1 , further comprising:

uploading the digital certificate to the blockchain, so as to allow a blockchain node needing to verify the digital certificate or a smart contract to verify the digital certificate according to the aggregated public key corresponding to the threshold value.

3 . The method for managing the digital certificate as claimed in claim 1 , further comprising:

receiving a digital certificate revocation request sent by the user, wherein the digital certificate revocation request indicates second user information of the user and a digital certificate to be revoked;

broadcasting the second user information to the blockchain according to a threshold value when the digital certificate to be revoked is generated, to enable a blockchain node, which participates in generation of an aggregated public key corresponding to the threshold value, to sign the second user information by using the private key component of the blockchain node, so as to generate second signature information; and

aggregating the second signature information to generate a revocation certificate corresponding to the digital certificate to be revoked.

4 . The method for managing the digital certificate as claimed in claim 3 , further comprising:

uploading the revocation certificate to the blockchain, so as to allow a blockchain node needing to verify the digital certificate or a smart contract to verify the revocation certificate according to the aggregated public key corresponding to the threshold value.

5 . The method for managing the digital certificate as claimed in claim 1 , wherein before receiving the digital certificate generation request sent by the user, the method further comprises:

according to the threshold value, determining, from all blockchain nodes, one or more blockchain nodes that participate in generation of the aggregated public key corresponding to the threshold value;

aggregating public key components of the determined one or more blockchain nodes on the basis of a signature algorithm, so as to generate, for each blockchain node, the same aggregated public key corresponding to the threshold value; and

calculating one blockchain node from the determined blockchain nodes, so as to write the aggregated public key into a genesis block of the blockchain, and to allow other blockchain nodes, which participate generation of the aggregated public key corresponding to the threshold value, to verify the aggregated public key in the genesis block.

6 . The method for managing the digital certificate as claimed in claim 5 , further comprising:

broadcasting preset root certificate information to the blockchain when a verification of the aggregated public key is passed, to enable the blockchain node, which participates in generation of the aggregated public key, to sign the preset root certificate information by using the private key component of the blockchain node, so as to generate third signature information; and

aggregating the third signature information to generate a root certificate corresponding to the aggregated public key, and writing the root certificate into the genesis block of the blockchain.

7 . The method for managing the digital certificate as claimed in claim 1 ,

wherein the digital certificate indicates identifier information of the one or more blockchain nodes.

8 . The method for managing the digital certificate as claimed in claim 1 , further comprising:

generating an asymmetric key pair for each blockchain node, wherein the asymmetric key pair indicates a public key component and a private key component, corresponding to the blockchain node.

9 . The method for managing the digital certificate as claimed in claim 1 , further comprising:

generating an asymmetric key pair for a newly-added blockchain node when there is one or more newly-added blockchain nodes on a blockchain, wherein the asymmetric key pair indicates a public key component and a private key component, corresponding to the newly-added blockchain node;

aggregating public key components of the one or more blockchain nodes on the blockchain on the basis of a signature generation algorithm, so as to generate one or more first aggregated public keys; and

updating, according to the one or more first aggregated public keys, one or more second aggregated public keys already present in a genesis block of the blockchain, wherein the second aggregated public key is generated by means of aggregating public key components of the one or more blockchain nodes on the blockchain on the basis of the signature generation algorithm before the one or more nodes are newly added to the blockchain.

10 . The method for managing the digital certificate as claimed in claim 9 , wherein updating, according to the one or more first aggregated public keys, the one or more second aggregated public keys already present in the genesis block of the blockchain comprises:

writing the one or more first aggregated public keys in the genesis block of the blockchain, and reserving the one or more second aggregated public keys already present in the genesis block;

wherein the method further comprising:

receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user;

broadcasting the first user information to the blockchain, to enable a blockchain node on the blockchain, which participates in generation of the same first aggregated public key, to sign the first user information by using a corresponding private key component, so as to generate first signature information; and

aggregating the first signature information to generate a digital certificate for the user, wherein the digital certificate indicates identifier information of the blockchain node.

11 . The method for managing the digital certificate as claimed in claim 1 , further comprising:

when one or more blockchain nodes are deleted from a blockchain, aggregating public key components of one or more blockchain nodes on the blockchain on the basis of a signature generation algorithm, so as to generate one or more first aggregated public keys; and

updating, according to the one or more first aggregated public keys, one or more second aggregated public keys already present in a genesis block of the blockchain, wherein the second aggregated public key is generated by means of aggregating the public key components of one or more blockchain nodes on the blockchain on the basis of the signature generation algorithm before the one or more blockchain nodes are deleted.

12 . An electronic device for managing a digital certificate, comprising:

one or more processors; and

a storage apparatus, configured to store one or more programs, wherein

when the one or more programs are executed by the one or more processors, the one or more processors are enabled to implement following actions:

receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user and a digital certificate application scenario;

determining a preset threshold value corresponding to the digital certificate application scenario according to the digital certificate application scenario, wherein the threshold value indicates a number of blockchain nodes, which participate in digital certificate generation, in all blockchain nodes;

broadcasting the first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, wherein the aggregated public key corresponding to the threshold value is generated by means of aggregating a public key component of the blockchain node on the basis of a signature generation algorithm; and

aggregating the first signature information to generate the digital certificate for the user.

13 . A non-transitory computer-readable medium, having a computer program stored thereon, wherein when the program is executed by a processor, the processor is enable to implement following actions: receiving a digital certificate generation request sent by a user, wherein the digital certificate generation request indicates first user information of the user and a digital certificate application scenario; determining a preset threshold value corresponding to the digital certificate application scenario according to the digital certificate application scenario, wherein the threshold value indicates a number of blockchain nodes, which participate in digital certificate generation, in all blockchain nodes; broadcasting the first user information to a blockchain, to enable a blockchain node, which knows an aggregated public key corresponding to the threshold value, to sign the first user information by using a private key component of the blockchain node, so as to generate first signature information, wherein the aggregated public key corresponding to the threshold value is generated by means of aggregating a public key component of the blockchain node on the basis of a signature generation algorithm; and aggregating the first signature information to generate the digital certificate for the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2023
From: HUO, YUN; DI, GANG
To: DIGITAL CURRENCY INSTITUTE,THE PEOPLE'S BANK OF CHINA
Reel/Frame 065392/0648 →
Priority Claims (7)
CN 202110474081.9 · Apr 29, 2021 · national
CN 202110474125.8 · Apr 29, 2021 · national
CN 202110474136.6 · Apr 29, 2021 · national
CN 202110474167.1 · Apr 29, 2021 · national
CN 202110475858.3 · Apr 29, 2021 · national
CN 202110475946.3 · Apr 29, 2021 · national
CN 202110488948.6 · Apr 29, 2021 · national
Continuity (1)
Related Publication 20240372733A1 · Nov 7, 2024
References Cited (44)
US 10708068B2 · Cheng · 2020 [cited by examiner]
US 10848325B1 · Duccini et al. · 2020 [cited by applicant]
US 10938578B2 · Finlow-Bates · 2021 [cited by examiner]
US 11722318B2 · Sun · 2023 [cited by examiner]
US 11863692B2 · Yan · 2024 [cited by examiner]
US 12309296B2 · Duccini · 2025 [cited by examiner]
US 20200082399A1 · Deshpande et al. · 2020 [cited by applicant]
US 20200327537A1 · Garg et al. · 2020 [cited by applicant]
US 20210083882A1 · Venable, Sr. · 2021 [cited by applicant]
US 20210167973A1 · Yan · 2021 [cited by examiner]
US 20210328816A1 · Wei · 2021 [cited by examiner]
CN 108712261A · 2018 [cited by applicant]
CN 108900310A · 2018 [cited by applicant]
CN 109495478A · 2019 [cited by applicant]
CN 109714165A · 2019 [cited by applicant]
CN 109992953A · 2019 [cited by applicant]
CN 110266482A · 2019 [cited by applicant]
CN 110365488A · 2019 [cited by applicant]
CN 111047324A · 2020 [cited by applicant]
CN 111104686A · 2020 [cited by applicant]
CN 111277417A · 2020 [cited by applicant]
CN 111340485A · 2020 [cited by applicant]
CN 111639361A · 2020 [cited by applicant]
CN 111819827A · 2020 [cited by applicant]
CN 111934889A · 2020 [cited by applicant]
CN 112132560A · 2020 [cited by applicant]
CN 112671541A · 2021 [cited by applicant]
CN 113179169A · 2021 [cited by applicant]
CN 113193961A · 2021 [cited by applicant]
CN 113206738A · 2021 [cited by applicant]
CN 113206745A · 2021 [cited by applicant]
CN 113206746A · 2021 [cited by applicant]
CN 113242132A · 2021 [cited by applicant]
CN 113242133A · 2021 [cited by applicant]
WO 2020143470A1 · 2020 [cited by applicant]
The search report of counterpart EP application No. 22794893.2 issued on Mar. 14, 2025. [cited by applicant]
Harn L et al: “Strong (n,t,n) verifiable 1-36secret sharing scheme”, Information Sciences, Elsevier, Amsterdam, NL, vol. 180, No. 16, Aug. 15, 2010 (Aug. 15, 2010), pp. 3059-3064, XP027066561. [cited by applicant]
The Partial search report of counterpart EP application No. 22794893.2 issued on Sep. 25, 2024. [cited by applicant]
Reis Miguel Reis Egidio, “Blockchain-Enabled DPKI Framework”, Dissertation submitted in partial fulfillment of the requirements for the degree of Master of Science in Computer Science and Informatics Engineering,Sep. 1,… [cited by applicant]
Murat Yasin Kubilay et al: “KORGAN: An Efficient PKI Architecture Based on Permissioned-Blockchain by Modifying PBFT Through Dynamic Threshold Signatures”, IACR, International Association for Cryptologic Research,Oct. 3… [cited by applicant]
Dykcik Lukasz et al:“BlockPKI:An Automated, Resilient, and Transparent Public-Key Infrastructure”, 2018 IEEE International Conference on Data Mining Workshops(ICDMW), IEEE,Nov. 17, 2018, XP033516256. [cited by applicant]
Shao J et al:“A traceable threshold signature scheme with multiple signing policies”, Computers &Security, Elsevier Science Publishers.Amsterdam, NL,May 1, 2006,XP027896428. [cited by applicant]
Anonymous: “Multi-signature”, Bitcoin Wiki, Mar. 21, 2021,XP093204830. [cited by applicant]
Han Kyunghyun et al: “A PKI without TTP based on conditional trust in blockchain”, Neural Computing and Applications, Springer London, London,Aug. 6, 2019,XP037221044. [cited by applicant]