Encryption Algorithm Compliance Detection Method, Device, Electronic Device and Storage Medium

By sending report information to the detection server before replacing the encryption algorithm, the detection server performs compliance detection, which solves the problem of communication failure caused by changes in the encryption algorithm after use, and improves the timeliness of detection and the reliability of communication.

CN115632781BActive Publication Date: 2025-05-30GUANGDONG SOUTHERN INFORMATION SECURITY RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211311001.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-25
Publication Date
2025-05-30
Estimated Expiration
2042-10-25

AI Technical Summary

Technical Problem

After the encryption device is put into use, the compliance changes in the encryption algorithm may occur due to software upgrades or plug-in updates. If it is not detected in time, it may cause the encrypted communication to fail.

Method used

It provides a compliance detection method for encryption algorithms. By sending report information to the detection server before replacing the encryption algorithm, the detection server determines whether compliance detection is required based on preset judgment rules, and calls corresponding detection data for detection.

Benefits of technology

It improves the timeliness of the compliance detection of encryption algorithms and reduces the probability of encryption communication failure due to the non-compliance of encryption algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632781B_ABST
    Figure CN115632781B_ABST
Patent Text Reader

Abstract

This application belongs to the field of encryption technology, and discloses an encryption algorithm compliance detection method, device, electronic device and storage medium. The method includes: in response to the report information sent by the encryption device before replacing the encryption algorithm for encrypted communication, obtaining the type of the target encryption algorithm to be used from the report information; based on a preset judgment rule, judging whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm; if so, calling corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device; thus, it is beneficial to timely detect the compliance of the encryption algorithm, and further reduce the occurrence probability of encrypted communication failure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of encryption technologies, and more particularly, to a method, apparatus, electronic device, and storage medium for detecting the compliance of encryption algorithms. Background Art

[0002] Encryption technology is the core technology in the field of information security and is widely used in various fields to solve the problems of information confidentiality, integrity, and authenticity. Encryption algorithms are the core of encryption technology, and the compliance of encryption algorithms is related to whether the encryption communication process between encryption devices (i.e., devices that perform encryption processing on information) and other devices can proceed smoothly. Therefore, generally, the compliance of the encryption algorithms of encryption devices is detected. Currently, when detecting the encryption algorithms of encryption devices, usually, all the encryption algorithms supported by the encryption device are uniformly detected for compliance before the encryption device is put into use, and usually no further detection is performed after the encryption device is put into use. However, after the encryption device is put into use, it may be upgraded with software and updated with plugins irregularly, which may cause changes in the software programs implementing the encryption algorithms. Such changes may affect the compliance of the encryption algorithms. If the compliance of the encryption algorithms cannot be detected in a timely manner, it is likely to cause the occurrence of encryption communication failures. Summary of the Invention

[0003] The purpose of this application is to provide a method, apparatus, electronic device, and storage medium for detecting the compliance of encryption algorithms, which is conducive to timely detecting the compliance of encryption algorithms, thereby reducing the probability of occurrence of encryption communication failures.

[0004] In a first aspect, this application provides a method for detecting the compliance of encryption algorithms, which is used to detect a server to detect the compliance of the encryption algorithms of an encryption device, and the encryption device is communicatively connected to the detection server; the method includes the steps of:

[0005] A1. In response to the report information sent by the encryption device before changing the encryption algorithm for encryption communication, obtaining the type of the target encryption algorithm to be used from the report information;

[0006] A2. Based on a preset judgment rule, judging whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm;

[0007] A3. If it is necessary, calling corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device.

[0008] Before each encryption communication with a new encryption algorithm, the encryption device sends a report message to the detection server. The report message includes the type of the target encryption algorithm to be used. When the detection server receives the report message, it determines whether compliance detection of the target encryption algorithm is required. If so, it performs compliance detection on the target encryption algorithm, thereby improving the timeliness of encryption algorithm compliance detection and reducing the probability of encryption communication failure caused by non-compliant encryption algorithms.

[0009] Preferably, the determination rule includes: if the type of the target encryption algorithm is a new encryption algorithm type that has not been used by the encryption device, it is determined that the target encryption algorithm needs to be detected;

[0010] Step A2 includes:

[0011] Obtain the types of encryption algorithms used by the encryption device, denoted as the first type;

[0012] If the type of the target encryption algorithm does not belong to the first type, it is determined that the target encryption algorithm needs to be detected.

[0013] Since a new encryption algorithm is an encryption algorithm for which compliance detection has not been performed in the encryption device, compliance detection needs to be performed on it to avoid communication failures caused by non-compliance of the new encryption algorithm.

[0014] Preferably, the determination rule includes: if the time interval between the time when the target encryption algorithm was last used for encryption communication and the current time exceeds a preset time threshold, it is determined that the target encryption algorithm needs to be detected;

[0015] Step A2 includes:

[0016] Obtain the time when the target encryption algorithm was last used for encryption communication by the encryption device, denoted as the first time;

[0017] Calculate the time interval between the current time and the first time;

[0018] If the time interval exceeds the preset time threshold, it is determined that the target encryption algorithm needs to be detected.

[0019] When the time interval between the time when the target encryption algorithm was last used for encryption communication and the current time is too long, the probability that the software program implementing the target encryption algorithm has been updated is relatively high. At this time, compliance detection of the target encryption algorithm should be performed to reduce the probability that the target encryption algorithm changes from being compliant to non-compliant and cannot be detected in a timely manner, ensuring the timeliness of compliance detection.

[0020] Preferably, the determination rule includes: if at least one of the encryption algorithms used within the time period from the time of the last encrypted communication using the target encryption algorithm to the current moment is detected as non-compliant, it is determined that the target encryption algorithm needs to be detected;

[0021] Step A2 includes:

[0022] Obtain the time of the last encrypted communication using the target encryption algorithm by the encryption device, denoted as the first time;

[0023] Obtain the detection times of each detection for which the detection result of the used encryption algorithm is non-compliant, denoted as the second time;

[0024] If at least one of the second times falls within the time period from the first time to the current moment, it is determined that the target encryption algorithm needs to be detected.

[0025] Sometimes, when a user updates the encryption algorithm program in the encryption device, multiple encryption algorithm programs may be updated simultaneously. Therefore, if other used encryption algorithms are detected as non-compliant within the time period from the time when the target encryption algorithm was last used to the current moment, the probability that the target encryption algorithm also becomes non-compliant will be greatly increased. Therefore, the target encryption algorithm should be detected to ensure that it can be discovered in a timely manner when the target encryption algorithm becomes non-compliant.

[0026] Preferably, step A3 includes:

[0027] A301. According to the type of the target encryption algorithm, retrieve the detection data of the corresponding type of encryption algorithm from the local database; the detection data includes sample data, a standard key, and a standard ciphertext, and the standard ciphertext is the ciphertext obtained by encrypting the sample data with a standard encryption algorithm of the same type as the target encryption algorithm according to the standard key;

[0028] A302. Send the sample data and the standard key to the encryption device;

[0029] A303. Obtain the test ciphertext obtained and sent by the encryption device by encrypting the sample data with the standard key through the target encryption algorithm;

[0030] A304. Compare whether the standard ciphertext is the same as the test ciphertext to determine whether the target encryption algorithm is compliant.

[0031] Preferably, step A301 includes:

[0032] Retrieve multiple detection data of the corresponding type of encryption algorithm from the local database according to the type of the target encryption algorithm; the types of the sample data of each of the detection data are different;

[0033] Step A304 includes:

[0034] If at least one of the test ciphertexts is different from the corresponding standard ciphertext, it is determined that the target encryption algorithm is non-compliant.

[0035] Preferably, after step A3, it further includes:

[0036] A4. Send a warning message to the encryption device according to the detection result.

[0037] In a second aspect, the present application provides an encryption algorithm compliance detection device for detecting a server to detect the compliance of the encryption algorithm of an encryption device, and the encryption device is communicatively connected to the detection server; it includes:

[0038] An acquisition module, configured to obtain the type of the target encryption algorithm to be used from the report information in response to the report information sent by the encryption device before replacing the encryption algorithm for encrypted communication;

[0039] A judgment module, configured to judge whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm based on a preset judgment rule;

[0040] A detection module, configured to, when the target encryption algorithm needs to be detected, call the corresponding detection data to detect the compliance of the target encryption algorithm in the encryption device according to the type of the target encryption algorithm.

[0041] The encryption device sends report information to the detection server before each replacement of the encryption algorithm for encrypted communication, and the report information includes the type of the target encryption algorithm to be used. When the detection server receives the report information, it judges whether it is necessary to perform compliance detection on the target encryption algorithm. If necessary, it performs compliance detection on the target encryption algorithm, thereby improving the timeliness of encryption algorithm compliance detection and reducing the occurrence probability of the situation of encrypted communication failure due to non-compliance of the encryption algorithm.

[0042] In a third aspect, the present application provides an electronic device, including a processor and a memory, the memory stores a computer program executable by the processor, and when the processor executes the computer program, it runs the steps in the encryption algorithm compliance detection method described above.

[0043] Fourthly, the present application provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it runs the steps in the encryption algorithm compliance detection method described above.

[0044] Beneficial effects:

[0045] In the encryption algorithm compliance detection method, device, electronic device and storage medium provided by the present application, before each encryption communication with a replaced encryption algorithm, the encryption device sends a report message to the detection server, and the report message includes the type of the target encryption algorithm to be used. When receiving the report message, the detection server determines whether it is necessary to perform compliance detection on the target encryption algorithm. If necessary, compliance detection is performed on the target encryption algorithm, thereby improving the timeliness of encryption algorithm compliance detection and reducing the occurrence probability of encryption communication failure caused by non-compliant encryption algorithms. Description of the drawings

[0046] Figure 1 It is a flowchart of the encryption algorithm compliance detection method provided by an embodiment of the present application.

[0047] Figure 2 It is a schematic structural diagram of the encryption algorithm compliance detection device provided by an embodiment of the present application.

[0048] Figure 3 It is a schematic structural diagram of the electronic device provided by an embodiment of the present application. Detailed implementation manners

[0049] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.

[0050] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.

[0051] Please refer to Figure 1 , Figure 1A method for detecting compliance of encryption algorithms in some embodiments of the present application is used to detect a server for detecting the compliance of encryption algorithms of an encryption device (i.e., a device for encrypting information, such as a mobile phone, a computer, an industrial device that needs to perform encrypted communication, etc.). The encryption device is communicatively connected to the detection server; the method includes the steps:

[0052] A1. In response to the report information sent by the encryption device before changing the encryption algorithm for encrypted communication, obtain the type of the target encryption algorithm to be used from the report information;

[0053] A2. Based on a preset judgment rule, determine whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm;

[0054] A3. If it is necessary, according to the type of the target encryption algorithm, call the corresponding detection data to detect the compliance of the target encryption algorithm in the encryption device.

[0055] The encryption device sends report information to the detection server before each change of the encryption algorithm for encrypted communication. The report information contains the type of the target encryption algorithm to be used. When the detection server receives the report information, it determines whether it is necessary to perform compliance detection on the target encryption algorithm. If it is necessary, it performs compliance detection on the target encryption algorithm, thereby improving the timeliness of encryption algorithm compliance detection and reducing the probability of occurrence of encrypted communication failure due to non-compliant encryption algorithms.

[0056] Among them, the types of encryption algorithms mainly include md5 algorithm, sha1 algorithm, sha256 algorithm, sm3 algorithm, aes-128-cbc algorithm, aes-128-ecb algorithm, sms4-cbc algorithm, sms4-ecb algorithm, ZUC algorithm, sm2 algorithm, sm9 algorithm, etc., but are not limited thereto. For example, if the encryption device currently uses the sm2 algorithm for encrypted communication and is going to use the sm9 algorithm in the next communication, at this time, the encryption device will send report information to the detection server to report that it will use the sm9 algorithm for encrypted communication. The detection server determines whether detection is required.

[0057] In some embodiments, the judgment rule includes: if the type of the target encryption algorithm is a new encryption algorithm type that the encryption device has not used, it is determined that the target encryption algorithm needs to be detected;

[0058] Thus, step A2 includes:

[0059] Obtain the types of encryption algorithms used by the encryption device, denoted as the first type;

[0060] If the type of the target encryption algorithm does not belong to the first type, it is determined that the target encryption algorithm needs to be detected.

[0061] The type of unused new encryption algorithm refers to the type of encryption algorithm that the encryption device did not support originally but can support currently. For example, the types of algorithms that the encryption device could support originally included the MD5 algorithm, the SHA1 algorithm, and the SM2 algorithm. After software or hardware upgrade, the types of algorithms that can be supported include the MD5 algorithm, the SHA1 algorithm, the SM2 algorithm, and the SM9 algorithm. The SM9 algorithm is the new encryption algorithm type for this encryption device.

[0062] Since the new encryption algorithm is the one that has not undergone compliance detection in the encryption device, therefore, before its first use, it is necessary to conduct compliance detection on it to avoid communication failures caused by non-compliance of the new encryption algorithm.

[0063] Among them, each time the detection server conducts compliance detection on the encryption algorithm of the encryption device, it will record the type of the encrypted algorithm being detected, thereby forming a list of the types of encryption algorithms used by the encryption device, hereinafter referred to as the first list. The type of the encryption algorithm used by the encryption device can be extracted from this first list. The type of the target encryption algorithm does not belong to the first type, that is, the type of the target encryption algorithm is not in the first list, indicating that the target encryption algorithm is the type of unused new encryption algorithm for this encryption device.

[0064] In some embodiments, the judgment rule further includes: if the time interval between the time when the target encryption algorithm was last used for encrypted communication and the current moment exceeds a preset time threshold, it is determined that the target encryption algorithm needs to be detected;

[0065] Thus, step A2 includes:

[0066] Obtain the time when the encryption device last used the target encryption algorithm for encrypted communication, denoted as the first time;

[0067] Calculate the time interval between the current moment and the first time;

[0068] If the time interval exceeds the preset time threshold, it is determined that the target encryption algorithm needs to be detected.

[0069] When the time interval between the time when the target encryption algorithm was last used for encrypted communication and the current moment is too long, the probability that the software program implementing the target encryption algorithm has been updated is relatively high. At this time, compliance detection should be conducted on the target encryption algorithm to reduce the probability that the target encryption algorithm changes from being compliant originally to non-compliant and cannot be detected in time, and ensure the timeliness of compliance detection.

[0070] In some embodiments, the determination rule further includes: if at least one of the used encryption algorithms is detected as non-compliant within the time period from the time of the last encrypted communication using the target encryption algorithm to the current moment, it is determined that the target encryption algorithm needs to be detected;

[0071] Thus, step A2 includes:

[0072] Obtain the time when the encryption device last used the target encryption algorithm for encrypted communication, denoted as the first time;

[0073] Obtain the detection times of each detection for which the detection result of the used encryption algorithm is non-compliant, denoted as the second time;

[0074] If at least one second time falls within the time period from the first time to the current moment, it is determined that the target encryption algorithm needs to be detected.

[0075] Sometimes, when the user updates the encryption algorithm program in the encryption device, multiple encryption algorithm programs are updated simultaneously. Therefore, if other used encryption algorithms are detected as non-compliant within the time period from the time when the target encryption algorithm was last used to the current moment, the probability that the target encryption algorithm also becomes non-compliant will be greatly increased. Therefore, the target encryption algorithm should be detected to ensure that it can be detected in a timely manner when the target encryption algorithm becomes non-compliant.

[0076] Among them, the report information sent by the encryption device also includes the type of the currently used encryption algorithm. Thus, each time the detection server receives the report information sent by the encryption device, it will record the type of the currently used encryption algorithm and the reception time of the report information. Thus, in the local database of the detection server, the type and usage time of the encryption algorithm last used before each encryption algorithm replacement are recorded, and a first query table recording the usage times of various encryption algorithms when they were last used is formed. The time when the encryption device last used the target encryption algorithm for encrypted communication can be obtained by querying in the first query table according to the type of the target encryption algorithm.

[0077] Among them, after each encryption algorithm compliance detection, the detection server will record the type of the encrypted algorithm being detected, the detection result (the detection result is compliant or non-compliant), and the detection time to form a second list. Thus, the detection times of each detection for which the detection result of the used encryption algorithm is non-compliant can be directly extracted from the second list.

[0078] Among them, when none of the conditions for detecting the target encryption algorithm to be detected are met, it can be determined that the target encryption algorithm does not need to be detected. If it is determined that the target encryption algorithm does not need to be subject to compliance detection, the detection server can send a first prompt message indicating that no compliance detection is required to the encryption device. After receiving this prompt message, the encryption device can directly replace the target encryption algorithm for encrypted communication. Further, if it is determined that the target encryption algorithm needs to be subject to compliance detection, (before step A3) a second prompt message indicating that compliance detection is required can be sent to the encryption device first to prompt the encryption device to wait for the detection result and prevent the encryption device from using the target encryption algorithm for encrypted communication before the detection is completed.

[0079] Specifically, step A3 includes:

[0080] A301. According to the type of the target encryption algorithm, retrieve the detection data of the corresponding type of encryption algorithm from the local database; the detection data includes sample data, a standard key, and a standard ciphertext, and the standard ciphertext is the ciphertext obtained by encrypting the sample data with a standard encryption algorithm of the same type as the target encryption algorithm according to the standard key;

[0081] A302. Send the sample data and the standard key to the encryption device;

[0082] A303. Obtain the test ciphertext obtained and sent by the encryption device by encrypting the sample data with the standard key through the target encryption algorithm;

[0083] A304. Compare whether the standard ciphertext is the same as the test ciphertext to determine whether the target encryption algorithm is compliant.

[0084] After receiving the sample data and the standard key sent by the detection server, the encryption device will use the local program implementing the target encryption algorithm to encrypt the sample data according to the standard key to obtain a test ciphertext, and then send the test ciphertext back to the detection server for comparative analysis.

[0085] Among them, the sample data and the standard key of various encryption algorithms can be pre-recorded in the local database of the detection server, and then the detection server uses the corresponding standard encryption algorithm to encrypt the sample data according to the standard key to obtain the corresponding standard ciphertext; a sample data and the corresponding standard key and standard ciphertext are stored as a set of detection data.

[0086] Among them, the sample data and the standard key can be set according to actual needs or according to the corresponding cryptographic algorithm standards (such as national cryptographic algorithm standards or various international cryptographic algorithm standards), and the specific content and format thereof are not limited herein; the standard encryption algorithm is a verified and compliant encryption algorithm.

[0087] Among them, each encryption algorithm can correspondingly store one or more groups of detection data. When each encryption algorithm correspondingly stores multiple groups of detection data, the types of sample data in each group of detection data (such as text data, voice data, picture data, video data, etc.) can be the same or different, and the standard keys in each group of detection data can be the same or different.

[0088] When detecting a target encryption algorithm, one group of detection data can be retrieved for detection, or multiple groups of detection data can be retrieved for detection.

[0089] For example, in some embodiments, step A301 includes:

[0090] According to the type of the target encryption algorithm, multiple detection data of the corresponding type of encryption algorithm are retrieved from the local database; the types of sample data in each detection data are different;

[0091] Thus, step A304 includes:

[0092] If at least one test ciphertext is different from the corresponding standard ciphertext, it is determined that the target encryption algorithm is non-compliant.

[0093] By using multiple groups of sample data of different types to detect the target encryption algorithm, its compliance can be more fully verified to improve the reliability of the detection result.

[0094] Among them, the report information sent by the encryption device may also include the types of data (such as text data, voice data, picture data, video data, etc.) encrypted and processed by the encryption device within a preset time period (which can be set according to actual needs) before the current moment. After receiving the report information, the detection server updates the historical data type list of the encryption device (the historical data type list records the types of data encrypted and processed by the encryption device) according to the data types included in the report information. Thus, when retrieving multiple detection data of the corresponding type of encryption algorithm from the local database, the detection data whose types of included sample data are recorded in the historical data type list are retrieved. Generally, for data types not recorded in the historical data type list, it can be considered that the probability of their being encrypted and processed by the encryption device in the future is relatively small. At this time, only using the data types recorded in the historical data type list for detection can not only ensure the full verification of the target encryption algorithm, but also help reduce the data processing volume and improve the detection efficiency.

[0095] In some embodiments, after step A3, it further includes:

[0096] A4. Sending a warning message to the encryption device according to the detection result.

[0097] If the detection result is compliant, send a first warning message indicating that the target encryption algorithm is compliant; if the detection result is non-compliant, send a second warning message indicating that the target encryption algorithm is non-compliant. When the encryption device receives the first warning message, it can replace the target encryption algorithm for encrypted communication. When the encryption device receives the second warning message, it can suspend replacing the target encryption algorithm for encrypted communication and take corrective measures for repair.

[0098] As can be seen from the above, for the encryption algorithm compliance detection method, in response to the report information sent by the encryption device before replacing the encryption algorithm for encrypted communication, obtain the type of the target encryption algorithm to be used from the report information; based on a preset judgment rule, according to the type of the target encryption algorithm, judge whether the target encryption algorithm needs to be detected; if so, according to the type of the target encryption algorithm, call the corresponding detection data to detect the compliance of the target encryption algorithm in the encryption device; thus, it is beneficial to timely detect the compliance of the encryption algorithm, and further reduce the occurrence probability of encrypted communication failure.

[0099] Reference Figure 2 , this application provides an encryption algorithm compliance detection device for detecting a server to detect the compliance of the encryption algorithm of an encryption device. The encryption device is communicatively connected to the detection server; it includes:

[0100] An acquisition module 1, configured to obtain the type of the target encryption algorithm to be used from the report information in response to the report information sent by the encryption device before replacing the encryption algorithm for encrypted communication;

[0101] A judgment module 2, configured to judge whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm based on a preset judgment rule;

[0102] A detection module 3, configured to, when the target encryption algorithm needs to be detected, call the corresponding detection data to detect the compliance of the target encryption algorithm in the encryption device according to the type of the target encryption algorithm.

[0103] The encryption device sends report information to the detection server before each replacement of the encryption algorithm for encrypted communication. The report information includes the type of the target encryption algorithm to be used. When the detection server receives the report information, it judges whether it is necessary to perform compliance detection on the target encryption algorithm. If so, it performs compliance detection on the target encryption algorithm, thereby improving the timeliness of encryption algorithm compliance detection and reducing the occurrence probability of encrypted communication failure caused by non-compliant encryption algorithms.

[0104] Among them, the types of encryption algorithms mainly include the MD5 algorithm, the SHA1 algorithm, the SHA256 algorithm, the SM3 algorithm, the AES-128-CBC algorithm, the AES-128-ECB algorithm, the SMS4-CBC algorithm, the SMS4-ECB algorithm, the ZUC algorithm, the SM2 algorithm, the SM9 algorithm, etc., but not limited to these. For example, the encryption device currently uses the SM2 algorithm for encrypted communication and is going to adopt the SM9 algorithm in the next communication. At this time, the encryption device will send a report message to the detection server to report that it will use the SM9 algorithm for encrypted communication. The detection server will judge whether detection is required.

[0105] In some embodiments, the judgment rule includes: if the type of the target encryption algorithm is a new encryption algorithm type that the encryption device has not used before, it is determined that the target encryption algorithm needs to be detected;

[0106] Thus, when the judgment module 2 judges whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm based on the preset judgment rule, it executes:

[0107] Obtain the type of the encryption algorithm used by the encryption device, denoted as the first type;

[0108] If the type of the target encryption algorithm does not belong to the first type, it is determined that the target encryption algorithm needs to be detected.

[0109] The new encryption algorithm type that has not been used refers to the encryption algorithm type that the encryption device did not support originally but can support currently; for example, the algorithm types that the encryption device could support originally include the MD5 algorithm, the SHA1 algorithm, and the SM2 algorithm. After software or hardware upgrade, the algorithm types that can be supported include the MD5 algorithm, the SHA1 algorithm, the SM2 algorithm, and the SM9 algorithm. The SM9 algorithm is the new encryption algorithm type for this encryption device.

[0110] Since the new encryption algorithm is an encryption algorithm that has not undergone compliance detection in the encryption device, therefore, before the first use, it is necessary to perform compliance detection on it to avoid communication failures caused by non-compliance of the new encryption algorithm.

[0111] Among them, each time the detection server performs compliance detection on the encryption algorithm of the encryption device, it will record the type of the detected encryption algorithm, thereby forming a list of the types of the encryption algorithms used by this encryption device, hereinafter referred to as the first list. The type of the encryption algorithm used by the encryption device can be extracted from this first list. The type of the target encryption algorithm does not belong to the first type, that is, the type of the target encryption algorithm is not in the first list, indicating that the type of the target encryption algorithm is a new encryption algorithm type that has not been used for this encryption device.

[0112] In some embodiments, the determination rule further includes: if the time interval between the time when the target encryption algorithm was last used for encrypted communication and the current moment exceeds a preset time threshold, it is determined that the target encryption algorithm needs to be detected;

[0113] Thus, when the determination module 2 determines whether the target encryption algorithm needs to be detected based on the preset determination rule according to the type of the target encryption algorithm, it performs:

[0114] Obtain the time when the encryption device last used the target encryption algorithm for encrypted communication, denoted as the first time;

[0115] Calculate the time interval between the current moment and the first time;

[0116] If the time interval exceeds the preset time threshold, it is determined that the target encryption algorithm needs to be detected.

[0117] When the time interval between the time when the target encryption algorithm was last used for encrypted communication and the current moment is too long, the probability that the software program implementing the target encryption algorithm has been updated is relatively high. At this time, compliance detection should be performed on the target encryption algorithm to reduce the probability that the target encryption algorithm changes from being compliant to non-compliant and cannot be detected in a timely manner, and to ensure the timeliness of compliance detection.

[0118] In some embodiments, the determination rule further includes: if at least one of the encryption algorithms used during the period from the time when the target encryption algorithm was last used for encrypted communication to the current moment is detected as non-compliant, it is determined that the target encryption algorithm needs to be detected;

[0119] Thus, when the determination module 2 determines whether the target encryption algorithm needs to be detected based on the preset determination rule according to the type of the target encryption algorithm, it performs:

[0120] Obtain the time when the encryption device last used the target encryption algorithm for encrypted communication, denoted as the first time;

[0121] Obtain the detection times of each detection for which the detection result of the used encryption algorithm is non-compliant, denoted as the second time;

[0122] If at least one second time falls within the period from the first time to the current moment, it is determined that the target encryption algorithm needs to be detected.

[0123] Sometimes, when the user updates the encryption algorithm program in the encryption device, multiple encryption algorithm programs are updated simultaneously. Therefore, if other used encryption algorithms are detected as non-compliant within the time period from the last time the target encryption algorithm was used to the current moment, the probability that the target encryption algorithm also becomes non-compliant will increase significantly. Therefore, the target encryption algorithm should be detected to ensure that it can be discovered in a timely manner when it becomes non-compliant.

[0124] Among them, the report information sent by the encryption device also includes the type of the currently used encryption algorithm. Thus, each time the detection server receives the report information sent by the encryption device, it records the type of the currently used encryption algorithm and the reception time of the report information. In the local database of the detection server, the type and usage time of the last used encryption algorithm before each encryption algorithm replacement are recorded, and a first query table recording the usage time of each encryption algorithm when it was last used is formed. By querying in this first query table according to the type of the target encryption algorithm, the time when the encryption device last used the target encryption algorithm for encrypted communication can be obtained.

[0125] Among them, after each encryption algorithm compliance detection, the detection server records the type of the detected encryption algorithm, the detection result (the detection result is compliant or non-compliant), and the detection time to form a second list. Thus, the detection times of each detection where the detection result of the used encryption algorithm is non-compliant can be directly extracted from the second list.

[0126] Among them, when none of the above conditions for determining that the target encryption algorithm needs to be detected are met, it can be determined that the target encryption algorithm does not need to be detected. If it is determined that the target encryption algorithm does not need to be subject to compliance detection, the detection server can send a first prompt message indicating that no compliance detection is required to the encryption device. After receiving this prompt message, the encryption device can directly replace the target encryption algorithm; further, if it is determined that the target encryption algorithm needs to be subject to compliance detection, a second prompt message indicating that compliance detection is required can be sent to the encryption device first to prompt the encryption device to wait for the detection result and prevent the encryption device from using the target encryption algorithm for encrypted communication before the detection is completed.

[0127] Specifically, the detection module 3 is used to, when the target encryption algorithm needs to be detected, call corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device, specifically including:

[0128] Retrieve the detection data of the corresponding type of encryption algorithm from the local database according to the type of the target encryption algorithm; the detection data includes sample data, a standard key, and a standard ciphertext, and the standard ciphertext is the ciphertext obtained by encrypting the sample data with a standard encryption algorithm of the same type as the target encryption algorithm according to the standard key;

[0129] Send the sample data and the standard key to the encryption device;

[0130] Obtain the test ciphertext obtained by the encryption device through encrypting the sample data with the target encryption algorithm using the standard key and sent back;

[0131] Compare whether the standard ciphertext is the same as the test ciphertext to determine whether the target encryption algorithm is compliant.

[0132] After receiving the sample data and the standard key sent by the detection server, the encryption device will use the local program implementing the target encryption algorithm to encrypt the sample data according to the standard key to obtain the test ciphertext, and then send the test ciphertext back to the detection server for comparative analysis.

[0133] Among them, the sample data and the standard key of various encryption algorithms can be pre-recorded in the local database of the detection server, and then the detection server uses the corresponding standard encryption algorithm to encrypt the sample data according to the standard key to obtain the corresponding standard ciphertext; a sample data and the corresponding standard key and standard ciphertext are stored as a set of detection data.

[0134] Among them, the sample data and the standard key can be set according to actual needs or according to the corresponding cryptographic algorithm standards (such as national cryptographic algorithm standards or various international cryptographic algorithm standards), and the specific content and format thereof are not limited herein; the standard encryption algorithm is a verified and compliant encryption algorithm.

[0135] Among them, each encryption algorithm can correspond to storing one set or multiple sets of detection data. When each encryption algorithm corresponds to storing multiple sets of detection data, the types of the sample data in each set of detection data (such as text data, voice data, picture data, video data, etc.) can be the same or different, and the standard keys in each set of detection data can be the same or different.

[0136] When detecting the target encryption algorithm, one set of detection data can be retrieved for detection, or multiple sets of detection data can be retrieved for detection.

[0137] For example, in some embodiments, when the detection module 3 retrieves the detection data of the corresponding type of encryption algorithm from the local database according to the type of the target encryption algorithm, it executes:

[0138] Retrieve multiple detection data of the corresponding type of encryption algorithm from the local database according to the type of the target encryption algorithm; the types of sample data of each detection data are different;

[0139] Therefore, when the detection module 3 compares whether the standard ciphertext is the same as the test ciphertext to determine whether the target encryption algorithm is compliant, it executes:

[0140] If at least one test ciphertext is different from the corresponding standard ciphertext, it is determined that the target encryption algorithm is non-compliant.

[0141] By using multiple groups of sample data of different types to detect the target encryption algorithm, its compliance can be more fully verified to improve the reliability of the detection results.

[0142] Among them, the report information sent by the encryption device may also include the data types (such as text data, voice data, picture data, video data, etc.) encrypted and processed by the encryption device within a preset time period (which can be set according to actual needs) before the current moment. After receiving the report information, the detection server updates the historical data type list of the encryption device (the historical data type list records the data types encrypted and processed by the encryption device) according to the data types included in the report information. Therefore, when retrieving multiple detection data of the corresponding type of encryption algorithm from the local database, the detection data whose included sample data types are recorded in the historical data type list is retrieved. Generally, for data types not recorded in the historical data type list, it can be considered that the probability of their being encrypted and processed by the encryption device in the future is relatively small. At this time, only using the data types recorded in the historical data type list for detection can not only ensure the full verification of the target encryption algorithm, but also help reduce the data processing volume and improve the detection efficiency.

[0143] In some embodiments, the encryption algorithm compliance detection device further includes:

[0144] A warning module for sending a warning message to the encryption device according to the detection result.

[0145] If the detection result is compliant, a first warning message indicating that the target encryption algorithm is compliant is sent. If the detection result is non-compliant, a second warning message indicating that the target encryption algorithm is non-compliant is sent. When the encryption device receives the first warning message, it can replace the target encryption algorithm for encrypted communication. When the encryption device receives the second warning message, it can suspend replacing the target encryption algorithm for encrypted communication and take rectification measures for repair.

[0146] As can be seen from the above, the encryption algorithm compliance detection device, in response to the report information sent by the encryption device before replacing the encryption algorithm for encrypted communication, obtains the type of the target encryption algorithm to be used from the report information; based on a preset judgment rule, determines whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm; if so, calls the corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device; thus, it is beneficial to timely detect the compliance of the encryption algorithm, and further reduce the occurrence probability of encrypted communication failure.

[0147] Please refer to Figure 3 , Figure 3 FIG. Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The present application provides an electronic device, including: a processor 301 and a memory 302. The processor 301 and the memory 302 are interconnected and communicate with each other through a communication bus 303 and / or other forms of connection mechanisms (not shown). The memory 302 stores a computer program executable by the processor 301. When the electronic device runs, the processor 301 executes the computer program to execute the encryption algorithm compliance detection method in any optional implementation manner of the above embodiment to implement the following functions: in response to the report information sent by the encryption device before replacing the encryption algorithm for encrypted communication, obtaining the type of the target encryption algorithm to be used from the report information; based on a preset judgment rule, determining whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm; if so, calling the corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device.

[0148] An embodiment of the present application provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, it executes the encryption algorithm compliance detection method in any optional implementation manner of the above embodiment to implement the following functions: in response to the report information sent by the encryption device before changing the encryption algorithm for encrypted communication, obtain the type of the target encryption algorithm to be used from the report information; based on a preset judgment rule, judge whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm; if so, call corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device. Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disc.

[0149] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces, and the indirect coupling or communication connection of the devices or units may be in an electrical, mechanical or other form.

[0150] In addition, the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units. They may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0151] Furthermore, in each embodiment of the present application, each functional module may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.

[0152] In this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.

[0153] The above description is only for the embodiments of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for detecting the compliance of encryption algorithms, which is used to detect a server for detecting the compliance of encryption algorithms of an encryption device. The encryption device is communicatively connected to the detection server; Characterized in that, It includes the steps: A1. In response to the report information sent by the encryption device before changing the encryption algorithm for encrypted communication, obtain the type of the target encryption algorithm to be used from the report information; A2. Based on a preset judgment rule, judge whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm; A3. If it is necessary, according to the type of the target encryption algorithm, call the corresponding detection data to detect the compliance of the target encryption algorithm in the encryption device; The judgment rule includes: If the type of the target encryption algorithm is a new encryption algorithm type that the encryption device has not used before, it is determined that the target encryption algorithm needs to be detected; Step A2 includes: Obtain the type of encryption algorithm used by the encryption device, denoted as the first type; If the type of the target encryption algorithm does not belong to the first type, it is determined that the target encryption algorithm needs to be detected; The judgment rule also includes: If the time interval between the time when the target encryption algorithm was last used for encrypted communication and the current time exceeds a preset time threshold, it is determined that the target encryption algorithm needs to be detected; Step A2 includes: Obtain the time when the encryption device last used the target encryption algorithm for encrypted communication, denoted as the first time; Calculate the time interval between the current time and the first time; If the time interval exceeds the preset time threshold, it is determined that the target encryption algorithm needs to be detected; The judgment rule also includes: If at least one of the used encryption algorithms is detected as non-compliant during the period from the time when the target encryption algorithm was last used for encrypted communication to the current time, it is determined that the target encryption algorithm needs to be detected; Step A2 includes: Obtain the time when the encryption device last used the target encryption algorithm for encrypted communication, denoted as the first time; Obtain the detection time of each detection whose detection result for the used encryption algorithm is non-compliant, denoted as the second time; If at least one of the second times falls within the period from the first time to the current time, it is determined that the target encryption algorithm needs to be detected.

2. The method for detecting the compliance of encryption algorithms according to claim 1, Characterized in that, Step A3 includes: A301. According to the type of the target encryption algorithm, retrieve the detection data of the corresponding type of encryption algorithm from the local database; the detection data includes sample data, a standard key, and a standard ciphertext, and the standard ciphertext is the ciphertext obtained by encrypting the sample data with a standard encryption algorithm of the same type as the target encryption algorithm according to the standard key; A302. Send the sample data and the standard key to the encryption device; A303. Obtain the test ciphertext obtained and sent by the encryption device through encrypting the sample data using the standard key through the target encryption algorithm; A304. Compare whether the standard ciphertext is the same as the test ciphertext to determine whether the target encryption algorithm is compliant.

3. The encryption algorithm compliance detection method according to claim 2, characterized in that, step A301 includes: According to the type of the target encryption algorithm, retrieve multiple detection data of the corresponding type of encryption algorithm from the local database; the types of the sample data of each of the detection data are different; step A304 includes: If at least one of the test ciphertexts is different from the corresponding standard ciphertext, it is determined that the target encryption algorithm is non-compliant.

4. The encryption algorithm compliance detection method according to claim 1, characterized in that, after step A3, it further includes: A4. Send a warning message to the encryption device according to the detection result.

5. An encryption algorithm compliance detection device for detecting a server to detect the compliance of the encryption algorithm of an encryption device, the encryption device being communicatively connected to the detection server; characterized in that, it includes: An acquisition module, configured to, in response to the report information sent by the encryption device before encrypting and communicating after changing the encryption algorithm, acquire the type of the target encryption algorithm to be used from the report information; A judgment module, configured to judge whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm based on a preset judgment rule; A detection module, configured to, when the target encryption algorithm needs to be detected, call the corresponding detection data according to the type of the target encryption algorithm to detect the compliance of the target encryption algorithm in the encryption device; The judgment rule includes: if the type of the target encryption algorithm is a new encryption algorithm type not used by the encryption device, it is determined that the target encryption algorithm needs to be detected; Based on a preset judgment rule, judging whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm includes: Obtain the types of encryption algorithms used by the encryption device, denoted as the first type; If the type of the target encryption algorithm does not belong to the first type, it is determined that the target encryption algorithm needs to be detected; The judgment rule further includes: if the time interval between the time when the target encryption algorithm was last used for encrypting communication and the current moment exceeds a preset time threshold, it is determined that the target encryption algorithm needs to be detected; Based on a preset judgment rule, judging whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm includes: Obtain the time when the encryption device last used the target encryption algorithm for encrypting communication, denoted as the first time; Calculate the time interval between the current moment and the first time; If the time interval exceeds the preset time threshold, it is determined that the target encryption algorithm needs to be detected; The judgment rule further includes: if at least one of the encryption algorithms used during the period from the time of the last encrypted communication using the target encryption algorithm to the current moment is detected as non-compliant, it is determined that the target encryption algorithm needs to be detected; Based on a preset judgment rule, determining whether the target encryption algorithm needs to be detected according to the type of the target encryption algorithm includes: Obtaining the time of the last encrypted communication using the target encryption algorithm by the encryption device, denoted as the first time; Obtaining the detection times of each detection with a non-compliant detection result for the used encryption algorithms, denoted as the second time; If at least one of the second times falls within the period from the first time to the current moment, it is determined that the target encryption algorithm needs to be detected.

6. An electronic device, characterized in that it includes a processor and a memory, the memory stores a computer program executable by the processor, and when the processor executes the computer program, it runs the steps in the encryption algorithm compliance detection method according to any one of claims 1-4.

7. A storage medium, on which a computer program is stored, characterized in that when the computer program is executed by a processor, it runs the steps in the encryption algorithm compliance detection method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Method and device for detecting encryption algorithm and secret key

    CN103516511A

  • Verification method and device, device for verification, server and terminal

    CN111191250A