Testing Method, Device, Testing Equipment and Storage Medium of Authentication System
By monitoring and authentication system calling the camera, disabling the shooting function and using identity image files for identity authentication, the problem that existing security testing is limited by the security protection mechanism of the authentication system is solved, and a wider range of security testing application and efficiency improvement is achieved.
Patent Information
- Application Number
- CN202111217533.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-19
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-10-19
AI Technical Summary
The security testing methods of existing certification systems are limited by the system's security protection mechanism and cannot be effectively tested.
By monitoring and authentication system, call the camera of the test device, disable the camera's shooting function, and use pre-stored identity image files for identity authentication to determine whether there are security vulnerabilities in the authentication system.
It realizes security testing that is not limited by the security protection mechanism of the certified system, broadens the scope of application of security testing methods, and saves manpower and development costs.
Smart Images

Figure CN113987506B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and particularly to a test method, device, test equipment and storage medium for an authentication system. Background Art
[0002] With the large-scale application and promotion of authentication systems in the Internet market, how to ensure the security of authentication systems has become the main problem faced by application programs (APPs) of each manufacturer. And an essential link to ensure the security of authentication systems is to test the security of authentication systems.
[0003] Currently, the security test scheme of authentication systems adopts traditional penetration testing means. Traditional penetration testing means require setting up a proxy between the test equipment and the server. The proxy intercepts the packets sent by the test equipment to the server, then tampers with the packet information and sends the tampered packet information to the server.
[0004] However, with the improvement of the security authentication and protection mechanism of authentication systems, it has led to the inability of testers to conduct tests through traditional penetration testing means. For example, if the server detects that the received packet is from the proxy, it will force the test equipment to log out of the APP account. Therefore, the traditional security test method has great limitations. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide a test method, device, test equipment and storage medium for an authentication system that can test the security of the authentication system on the premise of being not restricted by the security protection mechanism of the authentication system.
[0006] A test method for an authentication system, the method includes:
[0007] If it is monitored that the authentication system calls the camera of the test equipment, then execute the pre-obtained target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information;
[0008] Send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file, where the identity image file is used for the server to perform identity authentication;
[0009] Judge whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0010] A test device for an authentication system, the device includes:
[0011] An execution module, configured to, if it monitors that the authentication system calls the camera of the test device, execute the pre-acquired target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information;
[0012] A sending module, configured to send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file, where the identity image file is used for the server to perform identity authentication;
[0013] A judgment module, configured to judge whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0014] A test device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned method are implemented.
[0015] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned method are implemented.
[0016] For the above-mentioned test method, device, test device and storage medium of the authentication system, if the test device monitors that the authentication system calls the camera of the test device, it executes the pre-acquired target code information to disable the shooting function of the camera, obtains the pre-stored identity image file according to the target code information, sends the identity image file to the server and receives the identity authentication result returned by the server based on the identity image file, and then judges whether there is a security vulnerability in the authentication system according to the identity authentication result, so as to realize the security test of the authentication system by simulating the system level related to the camera of the test device being tampered with, and no longer test by intercepting the message sent by the test device to the server through the proxy end. Therefore, it can realize the security test of the authentication system without being restricted by the security protection mechanism of the authentication system, and broadens the applicable scope of the security test method. Description of the Drawings
[0017] Figure 1 It is an application environment diagram of a test method for an authentication system provided by an embodiment of the present application;
[0018] Figure 2 It is a flowchart of a test method for an authentication system provided by an embodiment of the present application;
[0019] Figure 3 It is a flowchart of a method for generating target code information provided by an embodiment of the present application;
[0020] Figure 4 It is a flowchart of a method for tampering with a system code file provided by an embodiment of the present application;
[0021] Figure 5 It is a schematic flowchart of a method for determining a system code file provided by an embodiment of the present application;
[0022] Figure 6 It is an application environment diagram of another test method for an authentication system provided by an embodiment of the present application;
[0023] Figure 7 It is a structural block diagram of a configuration subsystem provided by an embodiment of the present application;
[0024] Figure 8 It is a structural block diagram of a test subsystem provided by an embodiment of the present application;
[0025] Figure 9 It is a schematic flowchart of another test method for an authentication system provided by an embodiment of the present application;
[0026] Figure 10 It is a structural block diagram of a test device for an authentication system provided by an embodiment of the present application;
[0027] Figure 11 It is an internal structure diagram of a test device provided by an embodiment of the present application. Detailed implementation manners
[0028] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0029] The test method for the authentication system provided by the present application can be applied to an application environment as Figure 1 shown. Figure 1 It is an application environment diagram of a test method for an authentication system provided by an embodiment of the present application. Among them, the test device 102 communicates with the server 104 through a network. When using the test device 102 to perform identity authentication testing, the test device 102 can monitor whether the authentication system installed on the test device 102 calls the camera of the test device. If the test device 102 monitors that the authentication system calls the camera of the test device, it executes the pre-acquired target code information to disable the shooting function of the camera, obtains the pre-stored identity image file according to the target code information, sends the identity image file to the server, and receives the identity authentication result returned by the server based on the identity image file. The identity image file is used for the server to perform identity authentication, and it is determined whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0030] Among them, the test device 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices, and the server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0031] Referring to Figure 2 , Figure 2 FIG. is a schematic flowchart of a test method for an authentication system provided by an embodiment of the present application. Taking the method applied to the test device in Figure 1 as an example for description, the method includes the following steps:
[0032] S201. If it is monitored that the authentication system calls the camera of the test device, execute the pre-acquired target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information.
[0033] The identity image file in the embodiment of the present application can be a picture file or a recorded video file, and the authentication system can be an application system with a face recognition function. The test device monitors whether the authentication system calls the camera of the test device. When it is monitored that the authentication system calls the camera of the test device, execute the pre-acquired target code information to disable the shooting function of the camera, so as to be able to prohibit the camera from collecting the face information during face authentication.
[0034] For example, the identity image file of user B is pre-stored in the test device. When tester A uses the test device for testing, tester A can use B's mobile phone number and verification code to log in to the application system. After that, when performing a transfer or other operations, click the "face recognition authentication" button provided by the application system. The normal face authentication process is that after clicking the "face recognition authentication" button, the application system prompts the user to perform actions such as blinking, turning left, and turning right, and the camera will collect the face information of the user when performing actions such as blinking, turning left, and turning right. In the present application, if the test device monitors that the authentication system calls the camera of the test device, execute the pre-acquired target code information to disable the shooting function of the camera, and obtain the identity image file of user B according to the target code information. That is to say, by using the method provided by the present application, control the camera to no longer collect the face information of tester A when performing actions such as blinking, turning left, and turning right, but obtain the identity image file of user B, so as to realize the security test of the authentication system after the system level related to the camera of the test device is tampered with.
[0035] S202. Send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file. The identity image file is used for the server to perform identity authentication.
[0036] Combined with the above example, if the testing device sends the identity image file of user B to the server, the server compares the identity image file of user B with the identity image information of user B stored in the server. If the comparison is successful, it means that the identity authentication result is authentication passed; if the comparison fails, it means that the identity authentication result is not authenticated.
[0037] S203. Determine whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0038] If the identity authentication result is authentication passed, it means that tester A can successfully pass the face recognition authentication using the identity image file of user B. In this case, there is a security vulnerability in the authentication system.
[0039] In traditional penetration security testing, a proxy needs to be set up. After the security protection mechanism of the authentication system is improved, for example, the message sent by the testing device is an encrypted message, and the sent encrypted message cannot be recognized or changed. Therefore, traditional penetration security testing has great limitations.
[0040] At the same time, after the security protection mechanism of the authentication system is improved, SSL authentication will be performed on the message. The process of SSL authentication is as follows: after the proxy receives the message from the testing device, it will forge a certificate corresponding to the application system on the testing device. If the forged certificate is not authentic, when the server recognizes that the certificate is not authentic, it will directly filter out the message and not return the test result to the client, and even force the testing device to log out of the account in the authentication system, resulting in the inability to perform security testing. Therefore, traditional penetration testing security testing has great limitations. Among them, SSL authentication refers to the authentication from the client to the server, mainly used to provide authentication for users and servers, encrypt and hide the transmitted data, and ensure that the data is not changed during transmission, that is, to ensure the integrity of the data.
[0041] For the above reasons, if testers need to perform security testing, they need to dock with developers and require developers to make additional modifications or add branches to the source code of the authentication system, which is rather cumbersome, wastes manpower, and increases development costs. However, the method provided in this embodiment does not require developers to modify the source code of the authentication system. Therefore, it can save manpower and development costs and ensure the testing efficiency.
[0042] For the test method of the authentication system provided in this embodiment, if the test device monitors that the authentication system calls the camera of the test device, it executes the pre-acquired target code information to disable the shooting function of the camera, obtains the pre-stored identity image file according to the target code information, sends the identity image file to the server, and receives the identity authentication result returned by the server based on the identity image file. Then, it determines whether there is a security vulnerability in the authentication system according to the identity authentication result, so as to realize the security test of the authentication system by simulating the tampering of the system level related to the camera of the test device, and no longer test by intercepting the message sent by the test device to the server through the proxy. Therefore, it can test the security of the authentication system without being restricted by the security protection mechanism of the authentication system, and broadens the applicable scope of the security test method.
[0043] It should be noted that by using the method provided in the embodiment of the present application, the traditional message encryption and message interception mechanisms can be broken through. Even if message encryption and message interception are carried out, testers can still perform security tests on the authentication system. Therefore, the method provided in the embodiment of the present application has a wider applicable scope.
[0044] Refer to Figure 3 , Figure 3 is a schematic flowchart of a method for generating target code information provided in an embodiment of the present application. This embodiment relates to an optional implementation manner of how to generate target code information. On the basis of the above embodiment, the method includes the following steps:
[0045] S301. In response to the user's configuration operation, obtain the storage path of the identity image file and the attribute information of the image function, where the image function is used to obtain the identity image file under the storage path.
[0046] Optionally, the attribute information includes the class information, call format, and parameter type to which the image function belongs.
[0047] Specifically, the test device can, in response to the user's configuration operation, obtain the storage path of the identity image file and the attribute information of the image function, and generate target code information according to the storage path and the attribute information of the image function.
[0048] S302. Generate target code information according to the storage path and the attribute information of the image function.
[0049] In this embodiment, by responding to the user's configuration operation, the storage path of the identity image file and the attribute information of the image function are obtained, and target code information is generated according to the storage path and the attribute information of the image function. Furthermore, it can be realized that if the test device monitors that the authentication system calls the camera of the test device, the pre-obtained target code information is executed to disable the shooting function of the camera, and the pre-stored identity image file is obtained according to the target code information, so as to realize the security test of the authentication system after the system level related to the camera of the test device is simulated to be tampered with. Instead of intercepting the packets sent by the test device to the server through the proxy for testing, the security of the authentication system is tested on the premise of not being restricted by the security protection mechanism of the authentication system, thus broadening the applicable scope of the security test method.
[0050] Referring to Figure 4 , Figure 4 FIG. is a schematic flowchart of a method for tampering with a system code file provided by an embodiment of the present application. What this embodiment relates to is an optional implementation manner of how to tamper with a system code file. The execution of this embodiment can occur before executing the pre-obtained target code information to disable the shooting function of the camera. On the basis of the above embodiment, the method provided by this embodiment includes the following steps:
[0051] S401. Determine the system code file related to the camera.
[0052] The determined system code file related to the camera can be the entire system code file related to the camera or a partial code file in the entire system code file.
[0053] S402. Replace the system code file with the target code information.
[0054] The target code information can be the code information generated according to the storage path and the attribute information of one image function, or the target code information is the code information generated according to the storage path and the attribute information of multiple image functions.
[0055] In the case where the target code information is the code information generated according to the storage path and the attribute information of one image function, a partial code file in the entire system code file related to the camera is replaced with the target code information.
[0056] In the case where the target code information is the code information generated according to the storage path and the attribute information of multiple image functions, the entire system code file related to the camera is replaced with the target code information.
[0057] In this embodiment, by determining the system code file related to the camera and replacing the system code file with target code information, it is realized that when the test device monitors that the authentication system calls the camera of the test device, the target code information is executed to disable the shooting function of the camera, and the pre-stored identity image file is obtained according to the target code information, and then the identity image file is sent to the server, so as to realize the security test of the authentication system by simulating the tampering of the system level related to the camera of the test device. Instead of intercepting the packets sent by the test device to the server through the proxy for testing, the security of the authentication system is tested on the premise of not being restricted by the security protection mechanism of the authentication system, thus broadening the applicable scope of the security test method.
[0058] Referring to Figure 5 , Figure 5 FIG. is a schematic flowchart of a method for determining a system code file provided by an embodiment of the present application. This embodiment relates to an optional implementation manner of how to determine the system code file related to the camera. On the basis of the above embodiment, the above S401 includes the following steps:
[0059] S501. Analyze the target code information to determine the class information, call format, and parameter type of the image function.
[0060] S502. Determine the system code file related to the camera according to the class information, call format, and parameter type of the image function.
[0061] In this embodiment, by analyzing the target code information, determining the class information, call format, and parameter type of the image function, and determining the location of the system code file related to the camera according to the class information, call format, and parameter type of the image function, and then determining the system code file related to the camera according to the location, so as to further replace the system code file with the target code information, so as to realize the security test of the authentication system by simulating the tampering of the system level related to the camera of the test device.
[0062] To introduce the test method of the authentication system provided by the embodiment of the present application more clearly, the subsystems included in the test device and each module included in the subsystems will be described first. Referring to Figure 6 , Figure 6 FIG. is an application environment diagram of another test method of the authentication system provided by the embodiment of the present application. Figure 6The shown test device 620 is deployed with a configuration subsystem 601 and a test subsystem 602. The tester 660 can perform configuration operations through the configuration subsystem 601 on the test device 620 to conduct security tests on the authentication system to be tested installed on the test device 620. The test device 620 sends an identity image file to the server 640, and the server 640 performs identity authentication based on the identity image file.
[0063] Referring to Figure 7 , Figure 7 is a structural block diagram of a configuration subsystem provided by an embodiment of the present application. The configuration subsystem may include a network transmission module 701, a test result analysis module 702, a collaborative transmission module 703, a generation module 704, and a parameter configuration module 705. Specifically, the tester can perform configuration operations through the parameter configuration module 705.
[0064] Referring to Figure 8 , Figure 8 is a structural block diagram of a test subsystem provided by an embodiment of the present application. Figure 8 The shown test subsystem may include a monitoring module 801, a code replacement module 802, a collaborative transmission module 803, and an intelligent analysis module 804.
[0065] Referring to Figure 6 , Figure 7 , Figure 8 and Figure 9 , Figure 9 is a schematic flowchart of another test method for an authentication system provided by an embodiment of the present application. It should be noted that when performing the test, the tester needs to import the image file used for the test into the test device and configure the storage path of the image file and the attribute information of the image function into the parameter configuration module. The method specifically includes the following steps:
[0066] S901. The generation module receives the configuration parameters sent by the parameter configuration module, generates target code information according to the configuration parameters, and sends the target code information to the collaborative transmission module of the test subsystem.
[0067] The generation module 704 receives the configuration parameters sent by the parameter configuration module 705. The configuration parameters include the storage path of the identity image file and the attribute information of the image function. The generation module 704 generates target code information according to the storage path and the attribute information of the image function included in the configuration parameters, and sends the target code information to the collaborative transmission module 703.
[0068] The collaborative transmission module 703 can save the received target code information sent by the generation module 704. When the collaborative transmission module 703 receives a message sent by the network transmission module 701 and analyzes the message, if it identifies that the message is a request message for face authentication, that is, when the authentication system starts to test the face recognition related functions, the collaborative transmission module 703 can package the saved target code information and send the packaged target code information to the collaborative transmission module 803 of the test subsystem.
[0069] S902. The test device sends a request message for face authentication to the server.
[0070] The tester can click on the "Face Authentication" control of the authentication system installed on the test device to enter the face recognition service of the authentication system to be tested. After the tester clicks on the "Face Authentication" control of the authentication system installed on the test device, the sent request message is intercepted by the network transmission module 701.
[0071] S903. The network transmission module identifies whether the intercepted message is a request message for face authentication through the intercepted message. If the intercepted message is a request message for face authentication, the network transmission module sends the request message for face authentication to the collaborative transmission module of the configuration subsystem.
[0072] It should be noted that the network transmission module 701 sends the request message for face authentication to the collaborative transmission module 703, or sends a trigger message to the collaborative transmission module 703, and the trigger message is used to indicate that the collaborative transmission module has received the request message for face authentication.
[0073] S904. After the collaborative transmission module of the configuration subsystem receives the request message for face authentication, it sends the previously received target code information to the collaborative transmission module of the test subsystem.
[0074] After the collaborative transmission module 703 of the configuration subsystem receives the request message for face authentication, it sends the target code information previously received from the generation module 704 to the collaborative transmission module 803 of the test subsystem.
[0075] The collaborative transmission module 803 of the test subsystem is responsible for the transmission work of the target code information. This module is responsible for receiving and decompressing the target code information sent by the collaborative transmission module 703 of the configuration subsystem. If it is a collaborative transmission module between devices, the collaborative transmission module 803 acts as a client, while the collaborative transmission module 703 acts as a server.
[0076] S905. The collaborative transmission module of the test subsystem receives the target code information and sends the target code information to the code replacement module and the intelligent analysis module.
[0077] If the collaborative transmission module of the test subsystem receives the target code information as compressed target code information, it can decompress the compressed target code information and send the decompressed target code information to the code replacement module 902 and the intelligent analysis module 904.
[0078] S906. The intelligent analysis module analyzes and judges the received target code information, determines the trigger condition, and sends the trigger condition to the monitoring module.
[0079] The intelligent analysis module 804 is responsible for the analysis of the target code information and the analysis and positioning of the system code files related to the camera. This module is not only responsible for receiving and analyzing the target code information sent by the collaborative transmission module 803, but also determines the trigger condition for replacing the system code file with the target code information.
[0080] The intelligent analysis module 804 not only analyzes and judges the received target code information, but also analyzes the system code files related to the camera to determine information such as the class to which the code to be replaced in the system code files related to the camera belongs, the call format, and the parameter type.
[0081] S907. When the monitoring module monitors that the authentication system in the test device calls the camera, it sends a trigger signal to the code replacement module to enable the code replacement module to activate the hijacking function.
[0082] The monitoring module 801 is responsible for the startup task of the test subsystem. This module needs to monitor the authentication system of the test device and the application process of the camera. When it monitors that the authentication system makes a call to the application process of the camera, it sends a trigger signal to the code replacement module 802 to enable the code replacement module 802 to start the code interception and hijacking functions.
[0083] S908. The code replacement module receives the trigger signal sent by the monitoring module and replaces the system code file that was originally to be executed with the target code information.
[0084] The code replacement module 802 is responsible for performing code replacement operations on the system code related to the camera. When it recognizes the trigger signal sent by the monitoring module 801, the code replacement module 802 will tamper with the system code related to the camera to hijack the application process of the authentication system calling the camera, and change the originally to-be-executed system code or function to the target code information, so as to achieve that the captured image of the system camera is changed to the image file of the pre-stored identity image.
[0085] The shooting function of the camera can be disabled through S908, and the pre-stored identity image file can be obtained according to the target code information, so that the shooting screen of the system camera is changed to the screen of the pre-stored identity image file.
[0086] S909. The test device sends the obtained identity image file to the server for the server to perform identity authentication based on the identity image file.
[0087] Correspondingly, after receiving the identity image file, the server compares the received identity image file of user B with the stored image file of user B to obtain the identity authentication result, and returns the identity authentication result to the test result analysis module 702 of the test device.
[0088] S910. The test result analysis module determines whether there is a security vulnerability in the authentication system according to the identity authentication result returned by the server and can save the identity authentication result.
[0089] It should be noted that the above-mentioned network transmission module 701 is responsible for connecting the test device 420 and the server 440, receiving the network packets of the test device 420, identifying the request packet for the face recognition function obtained by the test device 420 and the receipt packet returned by the server 440. If the request packet for the face recognition function is identified, the network transmission module 701 sends the request packet for the face recognition function to the cooperative transmission module 703.
[0090] If the network transmission module 701 identifies the receipt packet returned by the server 440, it sends the received receipt packet from the server 440 to the test result analysis module 702, and the test result analysis module 702 analyzes the receipt packet and determines whether there is a security vulnerability in the authentication system according to the analysis result.
[0091] It should be noted that the above-mentioned receipt packet returned by the server 440 may include the identity authentication result returned by the server 440 to the test device 420 based on the identity image file. After analyzing the identity authentication result, if the identity authentication result is authentication passed, it is determined that there is a security vulnerability in the authentication system; if the identity authentication result is not authenticated passed, it is determined that there is no security vulnerability in the authentication system.
[0092] In one embodiment, the following steps may further be included:
[0093] Analyze the target code information to determine the trigger condition for replacing the system code file with the target code information.
[0094] In this embodiment, the intelligent analysis module 704 can analyze the target code information to determine the trigger condition for replacing the system code file with the target code information.
[0095] In one embodiment, the above S602, replacing the system code file with the target code information can be implemented in the following manner:
[0096] If it is monitored that the authentication system calls the camera of the test device, it is determined that the trigger condition is met, and the system code file is replaced with the target code information.
[0097] The device monitoring module 701 can monitor whether the authentication system calls the camera of the test device. If the device monitoring module 701 monitors that the authentication system calls the camera of the test device, a trigger signal can be sent to the code replacement module 702. The trigger signal is used to trigger the code replacement module 702 to replace the system code file with the target code information, so that the camera is in a hijacked state. Wherein, when the camera is in a hijacked state, the shooting function of the camera is prohibited.
[0098] It should be understood that although Figures 2 - 5 and Figure 9 the steps in the flowcharts are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figures 2 - 5 and Figure 9 at least a part of the steps in
[0099] In one embodiment, as Figure 10 shown, Figure 10 is a structural block diagram of a test device for an authentication system provided by an embodiment of the present application. The device 1000 includes: an execution module 1001, a sending module 1002, and a judgment module 1003, wherein:
[0100] The execution module 1001 is configured to, if it is monitored that the authentication system calls the camera of the test device, execute the pre-acquired target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information;
[0101] The sending module 1002 is configured to send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file. The identity image file is used for the server to perform identity authentication.
[0102] A judgment module 1003, configured to determine whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0103] In one embodiment, the device may further include an acquisition module, configured to acquire a storage path of the identity image file and attribute information of an image function in response to a configuration operation of a user, where the image function is used to acquire the identity image file under the storage path; a generation module, configured to generate the target code information according to the storage path and the attribute information of the image function.
[0104] In one embodiment, the attribute information includes class information, a call format, and a parameter type to which the image function belongs.
[0105] In one embodiment, the device may further include: a determination module, configured to determine a system code file related to the camera; a replacement module, configured to replace the system code file with the target code information.
[0106] In one embodiment, the determination module is specifically configured to parse the target code information, determine class information, a call format, and a parameter type to which the image function belongs; and determine a system code file related to the camera according to the class information, the call format, and the parameter type to which the image function belongs.
[0107] In one embodiment, the device may further include: an analysis module, configured to analyze the target code information and determine that a trigger condition for replacing the system code file with the target code information is: if it is monitored that the authentication system calls the camera of the test device, then replace the system code file with the target code information.
[0108] In one embodiment, the judgment module 1003 is specifically configured to, if the identity authentication result is authentication passed, determine that there is a security vulnerability in the authentication system; if the identity authentication result is authentication not passed, determine that there is no security vulnerability in the authentication system.
[0109] For specific limitations on the test device for the authentication system, reference may be made to the limitations on the test method for the authentication system in the foregoing text, which will not be elaborated herein. Each module in the foregoing test device for the authentication system may be implemented in whole or in part by software, hardware, and a combination thereof. The foregoing modules may be embedded in or independent of a processor in the test device in a hardware form, or may be stored in a memory in the test device in a software form, so as to be called by the processor to execute operations corresponding to the foregoing respective modules.
[0110] In one embodiment, a test device is provided. The test device may be a terminal, and its internal structure diagram may be asFigure 11 as shown Figure 11 Figure 11 is an internal structure diagram of a test device provided by an embodiment of the present application. The test device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the test device is used to provide computing and control capabilities. The memory of the test device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the test device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a test method for an authentication system. The display screen of the test device can be a liquid crystal display screen or an electronic ink display screen. The input device of the test device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the test device, or an external keyboard, a touchpad, or a mouse, etc.
[0111] Those skilled in the art can understand that Figure 11 the structure shown in Figure 11 is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the test device to which the solution of the present application is applied. The specific test device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0112] In one embodiment, a test device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0113] If it is monitored that the authentication system calls the camera of the test device, then execute the pre-acquired target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information;
[0114] Send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file. The identity image file is used for the server to perform identity authentication;
[0115] Judge whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0116] In one embodiment, when the processor executes the computer program, the following steps are further implemented: in response to a configuration operation of the user, obtain the storage path of the identity image file and the attribute information of the image function, where the image function is used to obtain the identity image file under the storage path; generate the target code information according to the storage path and the attribute information of the image function.
[0117] In one embodiment, the attribute information includes the class information to which the image function belongs, the call format, and the parameter type.
[0118] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the system code file related to the camera; replace the system code file with the target code information.
[0119] In one embodiment, when the processor executes the computer program, the following steps are further implemented: parse the target code information, determine the class information to which the image function belongs, the call format, and the parameter type; determine the system code file related to the camera according to the class information, the call format, and the parameter type to which the image function belongs.
[0120] In one embodiment, when the processor executes the computer program, the following steps are further implemented: analyze the target code information, and determine that the trigger condition for replacing the system code file with the target code information is: if it is monitored that the authentication system calls the camera of the test device, then replace the system code file with the target code information.
[0121] In one embodiment, when the processor executes the computer program, the following steps are further implemented: if the identity authentication result is authentication passed, determine that there is a security vulnerability in the authentication system; if the identity authentication result is not authenticated passed, determine that there is no security vulnerability in the authentication system.
[0122] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0123] If it is monitored that the authentication system calls the camera of the test device, execute the pre-obtained target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information;
[0124] Send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file, where the identity image file is used for the server to perform identity authentication;
[0125] Judge whether there is a security vulnerability in the authentication system according to the identity authentication result.
[0126] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: in response to a configuration operation of a user, obtain a storage path of the identity image file and attribute information of an image function, where the image function is used to obtain the identity image file under the storage path; generate the target code information according to the storage path and the attribute information of the image function.
[0127] In one embodiment, the attribute information includes class information to which the image function belongs, a call format, and a parameter type.
[0128] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a system code file related to the camera; replace the system code file with the target code information.
[0129] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: parse the target code information, determine class information to which the image function belongs, a call format, and a parameter type; determine a system code file related to the camera according to the class information to which the image function belongs, the call format, and the parameter type.
[0130] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: analyze the target code information, and determine that a trigger condition for replacing the system code file with the target code information is: if it is monitored that the authentication system calls the camera of the test device, then replace the system code file with the target code information.
[0131] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: if the identity authentication result is authentication passed, determine that there is a security vulnerability in the authentication system; if the identity authentication result is authentication not passed, determine that there is no security vulnerability in the authentication system.
[0132] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0133] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0134] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A testing method for an authentication system, characterized in that, The method includes: If it is monitored that the authentication system calls the camera of the test device, execute the pre-acquired target code information to disable the shooting function of the camera, and obtain the pre-stored identity image file according to the target code information; Send the identity image file to the server and receive the identity authentication result returned by the server based on the identity image file, where the identity image file is used for the server to perform identity authentication; Judge whether there is a security vulnerability in the authentication system according to the identity authentication result; Wherein, before executing the pre-acquired target code information to disable the shooting function of the camera, it further includes: Determine the system code file related to the camera; Replace the system code file with the target code information; Wherein, judging whether there is a security vulnerability in the authentication system according to the identity authentication result includes: If the identity authentication result is authentication passed, it is determined that there is a security vulnerability in the authentication system; If the identity authentication result is not authenticated, it is determined that there is no security vulnerability in the authentication system; Wherein, replacing the system code file with the target code information includes: In the case that the target code information is the code information generated according to the storage path and the attribute information of an image function, replace part of the code files in the entire system code file related to the camera with the target code information; In the case that the target code information is the code information generated according to the storage path and the attribute information of multiple image functions, replace the entire system code file related to the camera with the target code information.
2. The method according to claim 1, characterized in that, The method further includes: In response to the user's configuration operation, obtain the storage path of the identity image file and the attribute information of the image function, where the image function is used to obtain the identity image file under the storage path; Generate the target code information according to the storage path and the attribute information of the image function.
3. The method according to claim 2, characterized in that, The attribute information includes the class information, call format, and parameter type to which the image function belongs.
4. The method according to claim 1, wherein Determining the system code file related to the camera includes: Analyze the target code information to determine the class information, call format, and parameter type to which the image function belongs; Determine the system code file related to the camera according to the class information, call format, and parameter type to which the image function belongs.
5. The method according to claim 4, characterized in that The method further includes: Analyze the target code information to determine that the trigger condition for replacing the system code file with the target code information is: if it is monitored that the authentication system calls the camera of the test device, then replace the system code file with the target code information.
6. A test device for an authentication system, characterized in that, The device includes: An execution module, configured to execute the pre-acquired target code information to disable the shooting function of the camera if it is monitored that the authentication system calls the camera of the test device, and obtain the pre-stored identity image file according to the target code information; A sending module, configured to send the identity image file to a server and receive an identity authentication result returned by the server based on the identity image file, where the identity image file is used for the server to perform identity authentication; A judging module, configured to judge whether there is a security vulnerability in the authentication system according to the identity authentication result; Wherein, the device may further include: a determining module, configured to determine a system code file related to the camera; a replacing module, configured to replace the system code file with the target code information; Wherein, the judging module is specifically configured to: if the identity authentication result is authentication passed, determine that there is a security vulnerability in the authentication system; if the identity authentication result is authentication not passed, determine that there is no security vulnerability in the authentication system; Wherein, the replacing module is specifically configured to: in a case where the target code information is code information generated according to a storage path and attribute information of an image function, replace a partial code file in the entire system code file related to the camera with the target code information; In a case where the target code information is code information generated according to a storage path and attribute information of multiple image functions, replace the entire system code file related to the camera with the target code information.
7. A test device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Method and system for realizing face recognition security evaluation based on black box confrontation sample attacks
CN111881437A
Simulated face manufacturing method
CN112489205A