A DER-encoded digital certificate OID-based positioning and mutation system and usage method
By designing a DER-encoded digital certificate OID positioning and mutation system, the problem of the inability to accurately locate and mutate DER-encoded digital certificate OID in the prior art is solved, and high-quality and efficient digital certificate generation and testing are achieved, and the testing efficiency of certificate verification is improved.
Patent Information
- Application Number
- CN202211160264.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-22
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-09-22
AI Technical Summary
The existing digital certificate mutation technology cannot accurately locate and modify the specific OID in the digital certificate, resulting in low quality of test cases and ineffective detection of the security implemented by the SSL/TLS protocol software.
A system of OID positioning and mutation based on DER encoded digital certificates is designed. Through modules such as DER encoded digital certificate acquisition, parsing, OID acquisition and parsing, OID positioning and mutation, the OID is accurately positioned using the KMP string matching algorithm, and the leaf nodes or intermediate nodes are mutated.
The precise positioning and variation of DER coded digital certificates is realized, and the generated digital certificates are more diverse and quality, which improves the testing efficiency of certificate verification, and avoids the problems of random uncontrollability and singularity in the existing technology.
Smart Images

Figure CN115549921B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of software security testing, and particularly relates to a DER-encoded digital certificate OID positioning and mutation system and a usage method thereof. Background Art
[0002] With the development of network attack technologies and tools, the Hypertext Transfer Protocol (HTTP) using plaintext transmission cannot guarantee the security of data transmission over the network. According to data from the Global Times, network security problems in China are serious, and the Chinese economy loses tens of billions of US dollars annually due to network security problems. Even more severe is that the losses caused by network security problems are increasing, and various network attack means emerge in an endless stream, bringing great harm to ordinary network users.
[0003] To ensure the security of data communication between users and servers, and between users, websites use data encryption to protect the security of user data, and the Hypertext Transfer Protocol Secure (HTTPS) emerges as the times require. The HTTPS protocol uses the data encryption function provided by the Secure Sockets Layer or Transport Layer Security (SSL / TLS) protocol and relies on verifying X.509 digital certificates (encoded by DER) to ensure the security of data communication.
[0004] The X.509 standard is the format standard for public key certificates in cryptography. X.509 certificates have been applied in many Internet protocols including SSL / TLS, and at the same time, they also have many non-online application scenarios, such as electronic signature services. An X.509 certificate contains a public key and an identity (hostname, organization, or individual), and is signed (or self-signed) by a certificate authority (CA). For a certificate signed by a trusted certificate issuing authority (or can be verified by other means), the owner of the certificate can use the certificate and the corresponding private key to create secure communication and digitally sign documents.
[0005] OID is a special data structure in the X.509 certificate, which represents a specific value in the X.509 certificate.
[0006] In theory, websites using the HTTPS protocol are secure during data communication because the SSL / TLS protocol, which ensures secure communication, is designed to be secure. However, due to inaccurate understanding of protocol rules by developers or coding errors during development, the SSL / TLS protocol, which is secure in design, may not be as secure as designed in actual use, especially in the module of digital certificate verification. Therefore, it is very important to detect the security of the software implementation of the SSL / TLS protocol. When detecting the security of the SSL / TLS software implementation, the X.509 digital certificate (encoded by DER) is usually used as the test case input.
[0007] In this context, more and more attention is paid to the security testing of the software implementation of the SSL / TLS protocol. The quality of the test cases used as test inputs determines the reliability of the security testing of the software implementation of the SSL / TLS protocol. Therefore, a method with high quality and high efficiency is needed to generate test digital certificates.
[0008] In the prior art, Frankencert, Mucert, and RFCcert are for Base64-encoded digital certificates and are limited by the security checks of programming languages; although NEZHA can mutate the binary content of digital certificates, the mutation positions and operations are random, and it cannot perform specified operations on the specific positions and structures of digital certificates; although SADT can mutate DER-encoded digital certificates, it can only randomly select leaf nodes for mutation, cannot specify leaf nodes or intermediate nodes for mutation, nor can it perform structural mutation, and has great limitations in generating digital certificates. Summary of the Invention
[0009] To solve the above technical problems, the present invention provides the following technical solutions: a DER-encoded digital certificate OID positioning and mutation system, including a DER-encoded digital certificate acquisition module, a DER-encoded digital certificate parsing module, an OID acquisition and parsing module, an OID positioning and mutation module, and a digital certificate writing-back module;
[0010] The DER-encoded digital certificate acquisition module acquires the DER-encoded digital certificate;
[0011] The DER-encoded digital certificate parsing module parses the acquired DER-encoded digital certificate;
[0012] The OID acquisition and parsing module acquires and parses common OIDs;
[0013] The OID positioning and mutation module uses the KMP string matching algorithm to locate the position of the OID to be located, and then inputs the OID value into the mutation module for mutation;
[0014] The write-back digital certificate module writes the mutated binary-form characters back into a digital certificate.
[0015] A method of using a DER-encoded digital certificate OID positioning and mutation system, characterized by comprising:
[0016] Step 1: The DER-encoded digital certificate module obtains a DER-encoded digital certificate and saves it locally for future use;
[0017] Step 2: The DER-encoded digital certificate parsing module parses the DER-encoded digital certificate obtained in Step 1;
[0018] Step 3: The OID acquisition and parsing module obtains common OIDs and parses them;
[0019] Step 4: Input the common OIDs obtained in Step 3 into the OID positioning and mutation module for OID positioning and mutation;
[0020] Step 5: Use the binary-form character file mutated in Step 4 as input, and write the binary character file back into a digital certificate through a series of encoding algorithms.
[0021] Preferably, the specific content of Step 2 is:
[0022] Parse the DER-encoded digital certificate saved locally in Step 1 into a tree structure of binary-form characters.
[0023] Preferably, the specific content of Step 3 is:
[0024] Crawl common OIDs in the DER-encoded digital certificate on the website and parse the crawled OIDs into binary character forms.
[0025] Preferably, the OID positioning in Step 4 is specifically:
[0026] Input the binary OID parsed in Step 3 into the binary string of the DER-encoded digital certificate parsed in Step 2 for positioning to obtain a positioning point.
[0027] Preferably, the mutation in Step 4 is:
[0028] Mutate the positioning points obtained by OID positioning, that is, mutate the values of leaf nodes and mutate the structures of tree nodes.
[0029] Compared with the prior art, the beneficial effects of the present invention are:
[0030] 1. Accurately locate the leaf nodes or intermediate nodes to be mutated in the DER-encoded digital certificate based on OIDs. The digital certificate generated through positioning and then mutation helps to locate software defects in certificate verification and improve the test efficiency of certificate verification;
[0031] 2. When mutating DER-encoded numbers, it is possible to mutate the content of leaf nodes or intermediate nodes as well as their structures, and the generated digital certificates are more diverse, improving the quality of the generated digital certificates and helping to improve the test efficiency of certificate verification;
[0032] 3. It avoids the problem that the Base64-encoded digital certificate mutation technology is limited by the security check of programming languages, and avoids the random uncontrollability and singularity problems of the existing DER-encoded digital certificate mutation technologies. It has the characteristics of strong user customization and diverse operations, making it convenient for users to use. Description of the Drawings
[0033] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention.
[0034] In the drawings:
[0035] Figure 1 is the flowchart of the method of the present invention; Detailed Embodiments
[0036] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.
[0037] Embodiment 1:
[0038] A DER-encoded digital certificate OID positioning and mutation system, including a DER-encoded digital certificate acquisition module, a DER-encoded digital certificate parsing module, an OID acquisition and parsing module, an OID positioning and mutation module, and a digital certificate writing-back module;
[0039] The DER-encoded digital certificate acquisition module acquires DER-encoded digital certificates;
[0040] The DER-encoded digital certificate parsing module parses the acquired DER-encoded digital certificates;
[0041] The OID acquisition and parsing module acquires and parses common OIDs;
[0042] The OID positioning and mutation module includes two units: OID positioning and OID mutation. First, the binary OID parsed in step 3 is input into the binary string of the DER-encoded digital certificate parsed in step 2 for positioning to obtain a positioning point, and then the positioning point is input into the mutation module for mutation;
[0043] The digital certificate writing-back module writes the mutated binary character form back into a digital certificate.
[0044] Example 2:
[0045] Refer to the appendix Figure 1 As shown, a method for locating and mutating the OID of a DER-encoded digital certificate includes:
[0046] Step 1: The DER-encoded digital certificate acquisition module acquires the DER-encoded digital certificate and saves it locally for later use;
[0047] Step 2: The DER-encoded digital certificate parsing module takes the DER-encoded digital certificate saved locally in Step 1 as input, parses these DER-encoded digital certificates into a tree structure in an operable binary character form, and then outputs the operable binary characters into a file and saves it locally for later use;
[0048] Step 3: The OID acquisition and parsing module first obtains the commonly used OIDs of digital certificates from the OID official document, and then parses the obtained OIDs into binary character form according to the rules.
[0049] The specific rules are as follows: If the first two parts are defined as x.y, then they will be combined into a word 40*x + y, and the remaining parts are encoded separately as one byte. Each word is first divided into the minimum number of 7-bit numbers without leading zeros. These numbers are organized in big-endian format and combined into bytes one by one. Except for the last byte of the encoding, the most significant bit (8) of all other bytes is 1. For example: 30331 = 1*128^2 + 108*128 + 123, after being divided into 7-bit numbers (0x80), it becomes {1, 108, 123}, and after setting the most significant bit, it becomes {129, 236, 123}. If the word has only one 7-bit number, then the most significant bit is 0.
[0050] A specific example of Step 3 is as follows: The OID acquisition module first obtains the commonly used OIDs of digital certificates from the OID official document. For example, the OID of anyPolicy is 2.5.29.32.0. The OID parsing module parses 2.5.29.32.0 into a binary string: 40*2 + 5 = 85, and after getting {85, 29, 32, 0}, it is converted to binary as 01010101000111010010000000000000.
[0051] Step 4: Input the binary OID parsed in Step 3 into the OID location and mutation module, and the OID location and mutation module includes two units: OID location and mutation.
[0052] The method for OID positioning is as follows: Input the binary OID parsed in step 3, such as 01010101000111010010000000000000, into the DER-encoded digital certificate binary string parsed in step 2 to locate 01010101000111010010000000000000, and obtain the positioning point, which is the anyPolicy of this DER-encoded digital certificate.
[0053] The mutation method of the mutation unit: Mutate according to the positioning point located by the OID, such as deleting the anyPolicy. Specifically: Mutate the value of the leaf node and mutate the structure of the tree node, such as swapping the left and right nodes.
[0054] Step 5: Use the binary character file mutated in step 4 as the input, and write the binary character file back into a digital certificate through a series of encoding algorithms. Then save these digital certificates locally for future use.
[0055] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.
Claims
1. An OID Location and Mutation System Based on DER-Encoded Digital Certificates Characterized in that: It includes all the following modules: DER-Encoded Digital Certificate Acquisition Module, DER-Encoded Digital Certificate Parsing Module, OID Acquisition and Parsing Module, OID Location and Mutation Module, Digital Certificate Rewriting Module; The DER-Encoded Digital Certificate Acquisition Module acquires DER-encoded digital certificates; The DER-Encoded Digital Certificate Parsing Module parses the acquired DER-encoded digital certificates; The OID Acquisition and Parsing Module acquires and parses OIDs; The parsed OIDs are input into the parsed DER-encoded digital certificates to determine the location points, and the location points are input into the OID Location and Mutation Module for mutation; The Digital Certificate Rewriting Module rewrites the mutated OID values back into digital certificates.
2. A Usage Method of an OID Location and Mutation System Based on DER-Encoded Digital Certificates, applied to an OID Location and Mutation System Based on DER-Encoded Digital Certificates as described in Claim 1 Characterized in that: It includes: Step 1: The DER-Encoded Digital Certificate Acquisition Module acquires DER-encoded digital certificates and saves them locally for future use; Step 2: The DER-Encoded Digital Certificate Parsing Module parses the DER-encoded digital certificates acquired in Step 1; Step 3: The OID Acquisition and Parsing Module acquires and parses OIDs; Step 4: Input the OIDs acquired in Step 3 into the OID Location and Mutation Module for OID location and mutation; Step 5: Use the mutated OIDs in Step 4 as input, and write the binary character file back into a digital certificate through a series of encoding algorithms.
3. According to the usage method of an OID location and mutation system based on DER-encoded digital certificates as described in Claim 2 Characterized in that: The specific content of Step 2 is: Parse the DER-encoded digital certificates saved locally in Step 1 into a tree structure in binary character form.
4. According to the usage method of an OID location and mutation system based on DER-encoded digital certificates as described in Claim 3 Characterized in that: The specific content of Step 3 is: Crawl the commonly used OIDs in the DER-encoded digital certificates on the website and parse the crawled OIDs into binary character form.
5. According to the usage method of an OID location and mutation system based on DER-encoded digital certificates as described in Claim 4 Characterized in that: The OID location in Step 4 is specifically: Input the OIDs parsed in Step 3 into the DER-encoded digital certificates parsed in Step 2 for location to obtain location points.
6. According to the usage method of an OID location and mutation system based on DER-encoded digital certificates as described in Claim 5 Characterized in that: The mutation in Step 4 is: Mutate the location points obtained by OID location, that is, mutate the values of leaf nodes and mutate the structures of tree nodes.
Citation Information
Patent Citations
RFC-guided difference testing method for digital certificate verification modules in SSL / TLS implementations
CN108595318A
Systems and methods for enhanced online certificate status protocol
US20190260596A1