Digital certificate obtaining method and apparatus

US12413570B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12413570-B2
Application numberUS-202118011591-A
CountryUS
Kind codeB2
Filing dateMay 20, 2021
Priority dateJul 6, 2020
Publication dateSep 9, 2025
Grant dateSep 9, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A digital certificate obtaining method and apparatus. The method includes: a routing device receives a network access request sent by a terminal on the basis of a first virtual local area network, wherein the first virtual local area network is associated with a uniform resource locator (URL) of a server, so that the terminal obtains, by means of the server, a digital certificate used for accessing a second virtual local area network; and in response to the network access request sent by the terminal on the basis of the first virtual local area network, the routing device sends the URL of the server to the terminal, so that the terminal obtains the digital certificate from the server according to the URL.

First claim

Opening claim text (preview).

What is claimed is: 1. A digital certificate obtaining method, comprising: receiving, by a routing device, a network access request sent by a terminal based on a first virtual local area network, wherein the first virtual local area network is associated with a Uniform Resource Locator (URL) of a server such that the terminal obtains a digital certificate for accessing a second virtual local area network by the server; sending, by the routing device, the URL of the server to the terminal in response to the network access request sent by the terminal based on the first virtual local area network such that the terminal obtains the digital certificate from the server according to the URL. 2. The method according to claim 1 , further comprising: receiving, by the routing device, a network access request sent by the terminal based on the second virtual local area network; performing, by the routing device, a digital certificate authentication with the terminal according to the network access request sent by the terminal based on the second virtual local area network, and establishing a network connection with the terminal after the authentication passes. 3. The method according to claim 2 , wherein the routing device is configured with a first service set identification and a second service set identification, the first service set identification being configured to identify the first virtual local area network and the second service set identification being configured to identify the second virtual local area network. 4. The method according to claim 1 , wherein the sending, by the routing device, the URL of the server to the terminal in response to the network access request sent by the terminal based on the first virtual local area network, comprises: sending a DNS resolution response to the terminal after a proxy domain name system (DNS) service in the routing device receives a DNS resolution request sent by the terminal based on the first virtual local area network, the DNS resolution response carrying an IP address of a proxy WEB service in the routing device; and receiving, by the proxy WEB service, a network access request sent by the terminal according to the IP address of the proxy WEB service and based on the first virtual local area network, and sending redirection information carrying the URL of the server to the terminal, wherein the server enables the terminal to obtain a digital certificate for accessing the second virtual local area network. 5. The method according to claim 4 , wherein the routing device is configured with a first service set identification and a second service set identification, the first service set identification being configured to identify the first virtual local area network and the second service set identification being configured to identify the second virtual local area network. 6. The method according to claim 1 , wherein the sending, by the routing device, the URL of the server to the terminal in response to the network access request sent by the terminal based on the first virtual local area network, comprises: sending the redirection information carrying the URL of the server to the terminal after the proxy DNS service in the routing device receives the DNS resolution request sent by the terminal based on the first virtual local area network, wherein the server enables the terminal to obtain a digital certificate for accessing the second virtual local area network. 7. The method according to claim 6 , wherein the routing device is configured with a first service set identification and a second service set identification, the first service set identification being configured to identify the first virtual local area network and the second service set identification being configured to identify the second virtual local area network. 8. The method according to claim 1 , wherein the routing device is configured with a first service set identification and a second service set identification, the first service set identification being configured to identify the first virtual local area network and the second service set identification being configured to identify the second virtual local area network. 9. A routing device, comprising a processor, a memory, and a communication interface; wherein the communication interface receives and sends data under control of the processor; the memory stores computer instructions; and the processor is configured to read the computer instructions to perform followings: receiving a network access request sent by a terminal based on a first virtual local area network, wherein the first virtual local area network is associated with a Uniform Resource Locator (URL) of a server such that the terminal obtains a digital certificate for accessing a second virtual local area network by the server; sending the URL of the server to the terminal in response to the network access request sent by the terminal based on the first virtual local area network such that the terminal obtains the digital certificate from the server according to the URL. 10. The routing device according to claim 9 , wherein the processor is further configured to read the computer instructions to perform followings: receiving a network access request sent by the terminal based on the second virtual local area network; performing a digital certificate authentication with the terminal according to the network access request sent by the terminal based on the second virtual local area network, and establishing a network connection with the terminal after the authentication passes. 11. The routing device according to claim 9 , wherein the processor is configured to read the computer instructions to send the URL of the server to the terminal in response to the network access request sent by the terminal based on the first virtual local area network, by: sending a DNS resolution response to the terminal after a proxy domain name system (DNS) service in the routing device receives a DNS resolution request sent by the terminal based on the first virtual local area network, the DNS resolution response carrying an IP address of a proxy WEB service in the routing device; and receiving, by the proxy WEB service, a network access request sent by the terminal according to the IP address of the proxy WEB service and based on the first virtual local area network, and sending redirection information carrying the URL of the server to the terminal, wherein the server enables the terminal to obtain a digital certificate for accessing the second virtual local area network. 12. The routing device according to claim 9 , wherein the processor is configured to read the computer instructions to send the URL of the server to the terminal in response to the network access request sent by the terminal based on the first virtual local area network, by: sending the redirection information carrying the URL of the server to the terminal after the proxy DNS service in the routing device receives the DNS resolution request sent by the terminal based on the first virtual local area network, wherein the server enables the terminal to obtain a digital certificate for accessing the second virtual local area network. 13. The routing device according to claim 9 , wherein the routing device is configured with a first service set identification and a second service set identification, the first service set identification being configured to identify the first virtual local area network and the second service set identification being configured to identify the second virtual local area network. 14. A non-transitory computer-readable storage

Assignees

Inventors

Classifications

  • Virtual private networks · CPC title

  • Proxies · CPC title

  • across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP] · CPC title

  • Network architectures or network communication protocols for network security (cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00; network architectures or network communication protocols for wireless network security H04W12/00; security arrangements for protecting computers or computer systems against unauthorised activity G06F21/00) · CPC title

  • including means for verifying the identity or authority of a user of the system {or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials} · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12413570B2 cover?
A digital certificate obtaining method and apparatus. The method includes: a routing device receives a network access request sent by a terminal on the basis of a first virtual local area network, wherein the first virtual local area network is associated with a uniform resource locator (URL) of a server, so that the terminal obtains, by means of the server, a digital certificate used for acces…
Who is the assignee on this patent?
China Iwncomm Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 09 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).