A detection method and system for improving the efficiency of security evaluation of commercial cryptographic applications

By generating a security assessment task list, collecting task characteristics and equipment capability information, and utilizing a task allocation model and a load-efficiency balance parameter screening scheme, the problem of balancing accuracy and efficiency in commercial cryptography assessment is solved, thereby improving the credibility of the assessment.

CN116108426BActive Publication Date: 2026-05-15JIANGSU GUOBAO INFORMATION SYST EVALUATION CENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JIANGSU GUOBAO INFORMATION SYST EVALUATION CENT CO LTD
Filing Date
2023-03-30
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing commercial cryptographic security detection strategies are converging, making it impossible to balance the requirements of accuracy and efficiency in the evaluation process, resulting in insufficient credibility of the evaluation results.

Method used

By collecting application evaluation requirements information, a security evaluation task list is generated. The system is connected to the commercial cryptographic application system, task characteristics are collected, equipment processing capacity information is obtained, and multiple execution schemes are output using a task allocation model. The schemes are then selected by combining the load-efficiency balance parameters to achieve security testing of commercial cryptographic applications.

Benefits of technology

It achieves a balance between the requirements of accuracy and efficiency in commercial cryptography evaluation, thereby improving the credibility of the evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116108426B_ABST
    Figure CN116108426B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data processing, and provides a detection method and system for improving the security evaluation efficiency of commercial cryptographic application. Security evaluation task list and task characteristics of each task in the list are obtained by task analysis application evaluation demand information, device processing capacity information, the security evaluation task list and the task characteristics are input into a task allocation model to obtain multiple execution schemes, and the execution scheme is obtained by screening from the multiple execution schemes through a running load-efficiency balance parameter to perform security detection of commercial cryptographic application of each task in the security evaluation task list. The technical problems that the existing commercial cryptographic security detection strategies are similar, the evaluation accuracy requirement and the evaluation efficiency requirement cannot be balanced when the commercial cryptographic security evaluation is performed, and the evaluation result credibility is insufficient are solved, the commercial cryptographic evaluation accuracy and efficiency requirement are balanced, and the technical effect of improving the commercial cryptographic application security evaluation credibility is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a detection method and system for improving the efficiency of security assessment in commercial cryptography applications. Background Technology

[0002] Security assessment of commercial cryptography applications is an important means of evaluating the compliance, correctness, and effectiveness of cryptographic technologies used to achieve encryption protection in networks and information systems built using commercial cryptographic technologies, products, and services, as well as after commercial cryptography has been put into operation, in order to ensure that commercial cryptography can properly perform its security protection function.

[0003] It should be understood that relying solely on users of commercial cryptography to conduct security assessments of their applications periodically is limited by their professional capabilities. This can result in ineffective assessments, an inability to effectively and promptly eliminate compliance deficiencies, and the potential for information security vulnerabilities. On the other hand, outsourcing these assessments to third parties can lead to issues with timeliness and the reliability of the results.

[0004] In summary, existing technologies suffer from a convergence of commercial cryptographic security detection strategies, which makes it impossible to balance the requirements for accuracy and efficiency in commercial cryptographic security assessments, resulting in insufficient reliability of assessment results. Summary of the Invention

[0005] Therefore, it is necessary to provide a detection method and system that can balance the requirements of accuracy and efficiency in commercial cryptography evaluation and improve the credibility of commercial cryptography application security evaluation, thereby improving the efficiency of commercial cryptography application security evaluation.

[0006] A detection method for improving the efficiency of security assessment of commercial cryptographic applications includes: collecting application assessment requirement information; parsing the application assessment requirement information to generate a security assessment task list; connecting to a commercial cryptographic application system and collecting task characteristics of each task in the security assessment task list, wherein the task characteristics include efficiency identifiers and accuracy identifiers; obtaining device processing capacity information of the detection device; inputting the device processing capacity information, the security assessment task list, and the task characteristics into a task allocation model and outputting task allocation results, wherein the task allocation results include multiple execution schemes; collecting runtime-efficiency balance parameters and filtering the multiple execution schemes using the runtime-efficiency balance parameters to obtain a filtered execution scheme; and performing commercial cryptographic application security detection on each task in the security assessment task list based on the filtered execution scheme.

[0007] A detection system for improving the efficiency of security assessment of commercial cryptographic applications, the system comprising: a task list generation module for collecting application assessment requirement information, parsing the application assessment requirement information into tasks, and generating a security assessment task list; a task feature acquisition module for connecting to the commercial cryptographic application system and collecting task features of each task in the security assessment task list, wherein the task features include efficiency identifiers and accuracy identifiers; a capability information acquisition module for obtaining device processing capability information of the detection device; a task allocation analysis module for inputting the device processing capability information, the security assessment task list, and the task features into a task allocation model and outputting task allocation results, wherein the task allocation results include multiple execution schemes; an execution scheme filtering module for collecting runtime-efficiency balance parameters, filtering the multiple execution schemes using the runtime-efficiency balance parameters, and obtaining filtered execution schemes; and an application security detection module for performing commercial cryptographic application security detection on each task in the security assessment task list based on the filtered execution schemes.

[0008] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program performing the following steps:

[0009] The application evaluation requirement information is collected and processed to generate a security evaluation task list.

[0010] Connect to the commercial cryptography application system and collect the task characteristics of each task in the security assessment task list, wherein the task characteristics include efficiency identifiers and accuracy identifiers;

[0011] Obtain information on the processing capacity of the testing equipment;

[0012] The device processing capacity information, the security assessment task list, and the task characteristics are input into the task allocation model, and the task allocation result is output, wherein the task allocation result includes multiple execution schemes;

[0013] The load-efficiency balance parameters are collected, and the various execution schemes are screened using the load-efficiency balance parameters to obtain the selected execution scheme.

[0014] Based on the aforementioned screening and execution scheme, the security of commercial cryptographic applications for each task in the security assessment task list is tested.

[0015] A computer-readable storage medium having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0016] The application evaluation requirement information is collected and processed to generate a security evaluation task list.

[0017] Connect to the commercial cryptography application system and collect the task characteristics of each task in the security assessment task list, wherein the task characteristics include efficiency identifiers and accuracy identifiers;

[0018] Obtain information on the processing capacity of the testing equipment;

[0019] The device processing capacity information, the security assessment task list, and the task characteristics are input into the task allocation model, and the task allocation result is output, wherein the task allocation result includes multiple execution schemes;

[0020] The load-efficiency balance parameters are collected, and the various execution schemes are screened using the load-efficiency balance parameters to obtain the selected execution scheme.

[0021] Based on the aforementioned screening and execution scheme, the security of commercial cryptographic applications for each task in the security assessment task list is tested.

[0022] The aforementioned detection method and system for improving the efficiency of security assessment of commercial cryptography applications solves the technical problem in the prior art where the convergence of commercial cryptography security detection strategies leads to an inability to balance the requirements for assessment accuracy and efficiency, resulting in insufficient credibility of assessment results. It achieves the technical effect of balancing the requirements for accuracy and efficiency in commercial cryptography assessment and improving the credibility of security assessment of commercial cryptography applications.

[0023] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0024] Figure 1 This is a flowchart illustrating a detection method for improving the efficiency of security assessment in commercial cryptographic applications, as shown in one embodiment.

[0025] Figure 2 This is a flowchart illustrating the process of obtaining task allocation results in a detection method for improving the efficiency of security assessment of commercial cryptographic applications, as described in one embodiment.

[0026] Figure 3 This is a block diagram of a detection system for improving the efficiency of security assessment in commercial cryptographic applications, as shown in one embodiment.

[0027] Figure 4This is an internal structural diagram of a computer device in one embodiment;

[0028] Figure labeling: Task list generation module 1, Task feature acquisition module 2, Capability information acquisition module 3, Task allocation and analysis module 4, Execution scheme screening module 5, Application security detection module 6. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0030] like Figure 1 As shown, this application provides a detection method to improve the efficiency of security assessment for commercial cryptography applications, the method comprising:

[0031] S100: Collect and obtain application evaluation requirement information, perform task parsing on the application evaluation requirement information, and generate a security evaluation task list.

[0032] Specifically, it should be understood that commercial cryptography refers to cryptographic technologies and products used for encrypting or authenticating information that does not involve secret content. The security assessment of commercial cryptography applications involves evaluating the compliance, correctness, and effectiveness of the cryptographic technologies used for encryption protection in networks and information systems built using integrated commercial cryptographic technologies, products, and services. Furthermore, even after commercial cryptography is put into operation, regular security assessments are still required.

[0033] In this embodiment, a detection device is set up, and a security assessment of commercial cryptography applications used by multiple users within a certain area is performed based on the detection device. At the same time, in order to improve the efficiency of multi-user commercial cryptography application security assessment, a certain assessment strategy is set up.

[0034] The application evaluation requirements are the encryption level of the commercial cryptography used by the user and the customized encryption security level within the encryption level. Only the evaluation results obtained by the testing device in accordance with the encryption level of the commercial cryptography used by the user and the customized encryption security level requirements within the encryption level are credible.

[0035] The application evaluation requirement information is a collection of information consisting of application evaluation requirement information given by multiple users who are conducting application security evaluations of commercial cryptography applications based on the same testing equipment, for the application security evaluation of the commercial cryptography they are currently using.

[0036] Multiple users performing commercial cryptography application security assessments using the same testing equipment correspond to multiple tasks. The application assessment requirement information is parsed to generate a security assessment task list. In the security assessment task list, each user is marked with a security assessment task, and each security assessment task specifically includes the encryption level information of the commercial cryptography used by the user, and the customized encryption security level requirements within the encryption level.

[0037] S200: Connect to the commercial cryptographic application system and collect the task characteristics of each task in the security assessment task list, wherein the task characteristics include efficiency identifier and accuracy identifier;

[0038] Specifically, in this embodiment, the commercial cryptography application system is the carrier in which commercial cryptography actually performs encryption protection or security authentication functions. Users use the commercial cryptography application system to realize the required login security protection functions and data security upload and storage functions. The commercial cryptography application system is called in different functions.

[0039] Each user is equipped with a commercial cryptographic application system. The detection device actually collects assessment data characteristics of the commercial cryptographic application security evaluation within the commercial cryptographic application system. It should be understood that the user using the commercial cryptographic application system for login security protection and data security upload and storage functions actually includes multiple sub-users. When different numbers of sub-users simultaneously use the commercial cryptographic application system to perform login tasks or data protection tasks, the computing power resource utilization rate of the commercial cryptographic application system is different, resulting in differences in the amount of real-time data stream information generated. Consequently, the data collection rate of the detection device from the commercial cryptographic application system varies, and the reliability of the analysis results based on the collected data for commercial cryptographic application security analysis varies.

[0040] It should be understood that each user corresponds to one assessment task in the security assessment task list. The task characteristics are the data collection characteristics of the assessment data collected by the detection device in the user's commercial cryptographic application system, which can effectively perform commercial cryptographic application security assessment. Specifically, it includes an efficiency indicator and an accuracy indicator. The efficiency indicator is the efficiency of data collection and capture under different computing resource occupancy conditions of the commercial cryptographic application system. The higher the computing resource occupancy rate, the slower the data capture rate through the detection device. The accuracy indicator is the accuracy of the analysis results obtained by the detection device from the data collected under different computing resource occupancy rates of the commercial cryptographic application system for commercial cryptographic application security analysis.

[0041] The detection device is connected to the commercial cryptographic application system equipped by each user, and the task characteristics of each task in the security assessment task list are collected. The task characteristics include the efficiency and accuracy indicators of the commercial cryptographic application system performing data collection and application security analysis under different computing resource occupancy conditions.

[0042] S300: Obtain information on the processing capacity of the testing equipment;

[0043] Specifically, in this embodiment, the detection device is a comprehensive functional device with data acquisition and data analysis capabilities. Based on the data acquisition function, it collects evaluation data for the security assessment of commercial cryptography applications, and based on the data analysis capability, it performs a security assessment of commercial cryptography applications on the collected data.

[0044] The device processing capacity information includes data acquisition capacity information representing the amount of data collected per unit time, and device operating load limit representing the device data analysis and processing based on the collected data for security assessment of commercial cryptographic applications per unit time.

[0045] S400: Input the device processing capability information, the security assessment task list and the task characteristics into the task allocation model, and output the task allocation result, wherein the task allocation result includes multiple execution schemes;

[0046] In one embodiment, such as Figure 2 As shown, the method steps provided in this application further include:

[0047] S410: Perform task parsing on the security assessment task list to obtain the initial task level and task tolerance of each task;

[0048] S420: Generate task constraint information based on the initial task level and the task tolerance;

[0049] S430: Input the task constraint information and the task characteristics into the node allocation module of the task allocation model, and obtain the task allocation result based on the output result and the device processing capability information.

[0050] In one embodiment, the method steps provided in this application further include:

[0051] S431: Input the output result and the device processing capability information into the processing allocation module of the task allocation model;

[0052] S432: Generate processing constraint values ​​based on the device processing capability information, and apply execution constraints to the task allocation results in the output results using the processing constraint values;

[0053] S433: Generate the task allocation result based on the execution constraint result.

[0054] In one embodiment, the method steps provided in this application further include:

[0055] S432-1: Obtain the historical usage information of the testing equipment;

[0056] S432-2: Based on the historical usage information, perform equipment stability analysis of the testing equipment to obtain the stability influence coefficient;

[0057] S432-3: Adjust the processing constraint value using the stability influence coefficient, and apply execution constraints to the task allocation results in the output result based on the adjusted processing constraint value.

[0058] Specifically, in this embodiment, the multiple execution schemes refer to the sequence of data collection for multiple users (tasks) in the commercial cryptographic application system when evaluating the security of commercial cryptographic applications for multiple users (tasks).

[0059] To ensure that the commercial cryptographic application system data collection for multiple users based on the multiple execution schemes, and the commercial cryptographic security assessment based on the collected data, can achieve highly reliable commercial cryptographic application security assessment results, this embodiment pre-constructs the task allocation model to obtain multiple execution schemes.

[0060] The task allocation model includes a node allocation submodule and a processing allocation module. The node allocation submodule is connected to the processing allocation module, and the output of the node allocation submodule is the input data of the processing allocation module.

[0061] In this embodiment, in step S100, the security assessment task list is obtained. Each user is marked with a security assessment task, and each security assessment task specifically includes the encryption level information of the commercial password used by the user, and the customized encryption security level requirements within the encryption level.

[0062] The initial task level is the encryption level information of the commercial password used by the user, and the task tolerance is the user-defined encryption security level requirement information within the encryption level.

[0063] Therefore, this embodiment parses the security assessment task list to obtain the initial task level and tolerance of each task, integrates the initial task level and tolerance to generate task constraint information, and uses the task constraint information to constrain the data types collected by the detection device in each task, so as to avoid data that does not belong to the initial task level and tolerance of the task being mixed into the collected data, which would lead to deviations in the security assessment of commercial cryptography applications.

[0064] The node allocation module is constructed based on a neural network. It collects and obtains multiple sample task constraint information, multiple sample task constraint features and multiple sample task allocation results from the historical commercial cryptographic application security detection of the detection device. Each sample task allocation result contains multiple sample execution schemes.

[0065] Multiple sample task constraint information, multiple sample task constraint features, and multiple sample task allocation results are identified and divided according to a 17:2:1 ratio to obtain a training set, a test set, and a validation set. The supervised model training and testing of the node allocation module are performed based on the training set and the test set. The accuracy of the model output results is verified based on the validation set until the output accuracy of the node allocation module is higher than 97%.

[0066] The task constraint information and the task characteristics are input into the node allocation module of the task allocation model to obtain the output result, which is the task allocation result, and the task allocation result includes multiple execution schemes.

[0067] As can be seen from the foregoing, by performing data collection from multiple users' commercial cryptographic application systems based on the aforementioned multiple execution schemes, and by conducting commercial cryptographic security assessments based on the collected data, it is possible to obtain highly reliable commercial cryptographic application security assessment results.

[0068] Meanwhile, it should be understood that the actual efficiency of assessing the security of commercial cryptographic applications for multiple users is objectively limited by the data acquisition capabilities and security assessment and analysis capabilities of the detection device. Therefore, in this embodiment, the output results obtained from the node allocation module analysis and the device processing capability information are input to the processing allocation module of the task allocation model. Based on the analysis of the processing allocation module, the processing constraint value is determined. The processing constraint value is the upper limit of the device operation for the detection device to perform task data acquisition and application security analysis. The task allocation result is marked with the processing constraint value in the processing allocation module.

[0069] The method for constructing the processing allocation module is based on a neural network. It collects and obtains the processing constraint values ​​given by multiple commercial cryptographic security experts to multiple sample detection devices. The processing constraint values ​​are the upper limit of the device operation for the detection device to perform task data collection and application security analysis. When the detection device performs data collection and application security analysis within the processing constraint values, it will not cause the detection device to overload and crash or slow down the data collection and analysis rate.

[0070] Multiple sample detection devices and multiple sample processing constraint values ​​are labeled and divided in an 8:1:1 ratio to obtain a training set, a test set, and a validation set. The supervised model training and testing of the processing allocation module are performed based on the training set and the test set. The accuracy of the model output results is verified based on the validation set until the output accuracy of the processing allocation module is higher than 97%.

[0071] The output results obtained from the analysis of the node allocation module and the device processing capability information are input into the processing allocation module of the task allocation model. The processing allocation module first analyzes the detection device to obtain the processing constraint value, and then marks the processing constraint value on the output result to complete the execution constraint on the task allocation result in the output result through the processing constraint value. The task allocation result is generated according to the execution constraint result, and the task allocation result includes multiple execution schemes marked with processing constraint values.

[0072] It should be further understood that, in actual operation, the testing equipment is subject to fluctuations in operational stability due to external factors or changes in its own computing resource consumption. Therefore, this embodiment obtains the historical usage information of the testing equipment, calculates the frequency of stoppage failures within the historical usage period based on this information, and uses the stoppage failure frequency divided by 100 as the stability impact coefficient. The stability impact coefficient is then multiplied by the processing constraint value to obtain an adjusted processing constraint value. Based on this adjusted processing constraint value, the task allocation results in the output are subjected to execution constraints. This achieves the goal of obtaining multiple execution schemes that truly reflect the performance of the testing device and provide a high-reliability assessment of the security of commercial cryptographic applications for each user. This provides a technical effect for selecting the optimal execution scheme for efficient commercial cryptographic application security assessment.

[0073] S500: Collect and obtain the operating load-efficiency balance parameters, and use the operating load-efficiency balance parameters to filter the multiple execution schemes to obtain the selected execution scheme;

[0074] In one embodiment, the method steps provided in this application further include:

[0075] S510: Fit and read the load trigger value and load trigger frequency data of the various execution schemes;

[0076] S520: Fitting the efficiency results of the various execution schemes;

[0077] S530: Calculate the load coefficient based on the load trigger value and the load trigger frequency, perform data normalization processing on the load coefficient and the efficiency result, and calculate the final value of the comparison of the multiple execution schemes based on the processing result and the operating load-efficiency balance parameter.

[0078] S540: Based on the comparison final value calculation results, perform adaptation filtering to obtain the filtering execution plan.

[0079] Specifically, in this embodiment, the detection device performs commercial cryptographic application security assessments for multiple users according to the various execution schemes. The load trigger value is the specific overload value of the detection device during the process of performing commercial cryptographic application security assessments for multiple users according to any execution scheme. The load trigger frequency data is the number of times the detection device operates under overload during the process of performing commercial cryptographic application security assessments for multiple users according to any execution scheme, with each number corresponding to a specific overload value.

[0080] The device obtains multiple load trigger values ​​and multiple load trigger frequency data for the commercial cryptographic application security assessment of multiple users according to the multiple execution schemes, as well as multiple efficiency results reflecting the time consumed to complete the execution of the multiple execution schemes.

[0081] The average value calculated based on the load trigger value and the normalized load trigger frequency is used as the load coefficient. The load coefficient and the efficiency result are then subjected to data normalization again to obtain the processing result, which is the load coefficient-efficiency result for multiple execution schemes.

[0082] The operating load-efficiency balance parameter represents the operating balance state of the testing equipment when it is operating close to its load limit but not overloaded, and when the testing equipment continues to work in its optimal operating state.

[0083] The processing results and the operating load-efficiency balance parameters are compared and filtered once to remove execution schemes whose operating load or efficiency result values ​​exceed the operating load-efficiency balance parameters. For the remaining execution schemes, the final comparison value is calculated. The final comparison value is a combination of multiple sets of data, which are the load coefficient minus the operating load data and the efficiency result minus the efficiency balance parameter.

[0084] By sorting multiple sets of data from smallest to largest and selecting the execution scheme corresponding to the smallest set of data as the filtering execution scheme, a multi-user commercial cryptographic application security assessment execution scheme with the shortest time consumption and high reliability of the obtained results is obtained. This achieves the technical effect of balancing the accuracy and efficiency requirements of commercial cryptographic assessment and improving the reliability of commercial cryptographic application security assessment.

[0085] S600: Based on the filtering execution scheme, perform commercial cryptographic application security testing on each task in the security assessment task list.

[0086] In one embodiment, the method steps provided in this application further include:

[0087] S610: Perform execution monitoring on the selected execution scheme to detect the security of commercial cryptographic applications, and obtain the execution monitoring results;

[0088] S620: Perform efficiency error analysis based on the execution monitoring results to obtain efficiency error analysis results;

[0089] S630: The efficiency error analysis results are correlated with the error task, and feedback information is generated based on the correlation results;

[0090] S640: Optimize and adjust subsequent scheme selection based on the feedback information.

[0091] Specifically, in this embodiment, commercial cryptographic application security testing is performed on each task in the security assessment task list based on the filtering execution scheme, and the time consumption data of completing the filtering execution scheme is timed to obtain the execution monitoring results. The execution monitoring results include commercial cryptographic application security assessment time data for multiple tasks.

[0092] Based on step S500, the efficiency results of the security assessment of multiple tasks in commercial cryptographic applications are obtained using the theory of screening execution schemes. The efficiency results include the time taken to assess the security of multiple tasks in commercial cryptographic applications.

[0093] Efficiency error analysis is performed by comparing the execution detection results and the efficiency results of the selected execution schemes according to the task name. The efficiency error analysis results are the actual time consumed by error tasks that do not meet the efficiency result time requirements for commercial cryptographic application security assessment. The efficiency error analysis results are associated with the error tasks, and feedback information is generated based on the association results. The feedback information is used to optimize and adjust the subsequent scheme selection. This realizes the verification and optimization of the actual execution of the selected execution schemes, and obtains a multi-user commercial cryptographic application security assessment execution scheme that achieves the shortest execution time and high reliability of the results in both theoretical and practical applications. This balances the accuracy and efficiency requirements of commercial cryptographic assessment and improves the reliability of commercial cryptographic application security assessment.

[0094] In one embodiment, the method steps provided in this application further include:

[0095] S441: Evaluate the task execution priority of the security assessment task list and obtain the task execution priority evaluation result;

[0096] S442: Based on the task execution priority evaluation results, perform task order allocation to obtain task order allocation calibration data;

[0097] S443: Input the task allocation calibration data as incremental data into the task allocation model;

[0098] S444: Output the task allocation result.

[0099] Specifically, based on step S100, in this embodiment, each user is marked with a security assessment task in the security assessment task list, and each security assessment task specifically includes the encryption level information of the commercial password used by the user, and the customized encryption security level requirement information within the encryption level.

[0100] Therefore, this embodiment initially divides multiple users based on encryption level to obtain multiple users belonging to the same encryption level. Within each encryption level, multiple users within the same encryption level are sorted according to the user-defined encryption security requirement information. Specifically, the higher the encryption security requirement, the higher the ranking.

[0101] Based on the sorting information of multiple users within the same level and the division of multiple users with the same encryption level, the task execution priority evaluation result is obtained. Based on the task execution priority evaluation result, the task order is allocated to each user to obtain task order allocation calibration data.

[0102] The task allocation calibration data is used as incremental data and input into the task allocation model. Each task in the multiple execution schemes of the task allocation result output by the task allocation model is marked to obtain the optimized task allocation result. This achieves the technical effect of providing a reference for the detection device to collect and analyze data in the order of commercial cryptographic application security assessment of each task in the multiple execution schemes of the task allocation result.

[0103] In one embodiment, such as Figure 3 As shown, a detection system for improving the efficiency of security assessment of commercial cryptographic applications is provided, comprising: a task list generation module 1, a task feature collection module 2, a capability information acquisition module 3, a task allocation and analysis module 4, an execution scheme screening module 5, and an application security detection module 6, wherein:

[0104] Task list generation module 1 is used to collect application evaluation requirement information, parse the application evaluation requirement information into tasks, and generate a security evaluation task list.

[0105] Task feature acquisition module 2 is used to connect to the commercial cryptography application system and acquire the task features of each task in the security assessment task list, wherein the task features include efficiency identifiers and accuracy identifiers;

[0106] Capability information acquisition module 3 is used to obtain the equipment processing capability information of the testing equipment;

[0107] The task allocation analysis module 4 is used to input the device processing capacity information, the security assessment task list and the task characteristics into the task allocation model and output the task allocation result, wherein the task allocation result includes multiple execution schemes;

[0108] The execution scheme screening module 5 is used to collect and obtain the operating load-efficiency balance parameters, and to screen the multiple execution schemes through the operating load-efficiency balance parameters to obtain the screened execution scheme.

[0109] Application security detection module 6 is used to perform commercial cryptographic application security detection on each task in the security assessment task list based on the filtering execution scheme.

[0110] In one embodiment, the system further includes:

[0111] The task parsing and execution unit is used to parse the security assessment task list to obtain the initial task level and task tolerance of each task.

[0112] A constraint information generation unit is used to generate task constraint information based on the initial task level and the task tolerance.

[0113] The task allocation obtaining unit is used to input the task constraint information and the task characteristics into the node allocation module of the task allocation model, and obtain the task allocation result based on the output result and the device processing capability information.

[0114] In one embodiment, the system further includes:

[0115] The data input unit is used to input the output results and the device processing capability information into the processing allocation module of the task allocation model;

[0116] The constraint information generation unit is used to generate processing constraint values ​​based on the device processing capability information, and to apply execution constraints to the task allocation results in the output results through the processing constraint values.

[0117] The task allocation obtaining unit is used to generate the task allocation result based on the execution constraint result.

[0118] In one embodiment, the system further includes:

[0119] The information acquisition unit is used to obtain the historical usage information of the detection equipment.

[0120] The equipment analysis execution unit is used to perform equipment stability analysis of the testing equipment based on the historical usage information, and obtain the stability impact coefficient.

[0121] The constraint execution processing unit is used to adjust the processing constraint value through the stability influence coefficient, and to apply execution constraints to the task allocation result in the output result according to the adjusted processing constraint value.

[0122] In one embodiment, the system further includes:

[0123] The load information reading unit is used to fit and read the load trigger value and load trigger frequency data of the various execution schemes.

[0124] An efficiency result fitting unit is used to fit the efficiency results of the various execution schemes.

[0125] The load factor calculation unit is used to calculate the load factor based on the load trigger value and the load trigger frequency, perform data normalization processing on the load factor and the efficiency result, and calculate the final value of the comparison of the multiple execution schemes based on the processing result and the operating load-efficiency balance parameter.

[0126] An adaptation and filtering execution unit is used to perform adaptation and filtering based on the comparison final value calculation results to obtain the filtering execution scheme.

[0127] In one embodiment, the system further includes:

[0128] The task priority evaluation unit is used to evaluate the task execution priority of the security assessment task list and obtain the task execution priority evaluation result.

[0129] The task order allocation unit is used to allocate tasks in order based on the task execution priority evaluation results and obtain task order allocation calibration data.

[0130] The model input execution unit is used to input the task allocation calibration data as incremental data into the task allocation model.

[0131] The allocation result acquisition unit is used to output the task allocation result.

[0132] In one embodiment, the system further includes:

[0133] The security monitoring execution unit is used to perform execution monitoring on the selected execution scheme for commercial cryptographic application security detection, and to obtain the execution monitoring results.

[0134] An efficiency error analysis unit is used to perform efficiency error analysis based on the execution monitoring results and obtain efficiency error analysis results.

[0135] The feature association execution unit is used to associate the efficiency error analysis results with the error task and generate feedback information based on the association results.

[0136] The screening and optimization adjustment unit is used to optimize and adjust the subsequent scheme screening based on the feedback information.

[0137] For a specific embodiment of a detection system for improving the efficiency of security assessment of commercial cryptographic applications, please refer to the embodiment of a detection method for improving the efficiency of security assessment of commercial cryptographic applications described above, which will not be repeated here. Each module in the aforementioned detection device for improving the efficiency of security assessment of commercial cryptographic applications can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0138] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores news data and data such as time decay factors. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements a detection method to improve the efficiency of security assessment for commercial cryptographic applications.

[0139] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0140] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps: acquiring application evaluation requirement information; parsing the application evaluation requirement information to generate a security evaluation task list; connecting to a commercial cryptographic application system to acquire task characteristics of each task in the security evaluation task list, wherein the task characteristics include efficiency identifiers and accuracy identifiers; acquiring device processing capability information of a detection device; inputting the device processing capability information, the security evaluation task list, and the task characteristics into a task allocation model, and outputting a task allocation result, wherein the task allocation result includes multiple execution schemes; acquiring a load-efficiency balance parameter; filtering the multiple execution schemes using the load-efficiency balance parameter to obtain a filtered execution scheme; and performing commercial cryptographic application security detection on each task in the security evaluation task list based on the filtered execution scheme.

[0141] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0142] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A detection method for improving the efficiency of security assessment in commercial cryptography applications, characterized in that, The method includes: The application evaluation requirement information is collected and processed by task parsing to generate a security evaluation task list. Multiple users who conduct commercial cryptography application security evaluation based on the same testing device correspond to multiple tasks. In the security evaluation task list, each user is marked with a security evaluation task, and each security evaluation task specifically includes the encryption level information of the commercial cryptography used by the user and the user-defined encryption security level requirements within the encryption level. The system connects to a commercial cryptographic application system and collects task characteristics of each task in the security assessment task list. The task characteristics include an efficiency identifier and an accuracy identifier. The efficiency identifier is the efficiency of data collection and capture under different computing resource occupancy rates of the commercial cryptographic application system. The higher the computing resource occupancy rate, the slower the data capture efficiency through the detection device. The accuracy identifier is the accuracy identifier of the analysis results obtained by the detection device from the data collected under different computing resource occupancy rates of the commercial cryptographic application system for commercial cryptographic application security analysis. Obtain information on the processing capacity of the testing equipment; The device processing capacity information, the security assessment task list, and the task characteristics are input into the task allocation model, and the task allocation result is output, wherein the task allocation result includes multiple execution schemes; The load-efficiency balance parameters are collected, and the various execution schemes are screened using the load-efficiency balance parameters to obtain the selected execution scheme. Based on the aforementioned screening and execution scheme, perform commercial cryptographic application security testing on each task in the security assessment task list; The security assessment task list is parsed to obtain the initial task level and task tolerance of each task. The initial task level is the encryption level information of the commercial password used by the user, and the task tolerance is the encryption security level requirement information customized by the user within the encryption level. Task constraint information is generated based on the initial task level and the task tolerance. The task constraint information and the task characteristics are input into the node allocation module of the task allocation model, and the task allocation result is obtained based on the output result and the device processing capability information; The output results and the device processing capacity information are input into the processing allocation module of the task allocation model; Based on the device processing capability information, a processing constraint value is generated, and the task allocation result in the output result is constrained by the processing constraint value. The task allocation result is generated based on the execution constraint result.

2. The method as described in claim 1, characterized in that, The method includes: Obtain the historical usage information of the testing equipment; Based on the historical usage information, the stability of the testing equipment is analyzed to obtain the stability impact coefficient. The processing constraint value is adjusted by the stability influence coefficient, and the task allocation result in the output result is subjected to execution constraints based on the adjusted processing constraint value.

3. The method as described in claim 1, characterized in that, The method includes: The load trigger value and load trigger frequency data are read for the various execution schemes; Read the efficiency results of the various execution schemes; The load coefficient is calculated based on the load trigger value and the load trigger frequency. The load coefficient and the efficiency result are then normalized to obtain the processing result, which is the load coefficient-efficiency result of multiple execution schemes. The final value of the comparison of the multiple execution schemes is calculated based on the processing result and the operating load-efficiency balance parameter. The final value calculation results are used for adaptation and filtering to obtain the filtering execution plan.

4. The method as described in claim 1, characterized in that, The method includes: The security assessment task list is evaluated for task execution priority to obtain task execution priority evaluation results; Based on the task execution priority evaluation results, task order is allocated to obtain task order allocation calibration data. The task sequence allocation calibration data is used as incremental data and input into the task allocation model; The output will show the task allocation results.

5. The method as described in claim 1, characterized in that, The method includes: The execution monitoring of the selected execution scheme is performed to detect the security of commercial cryptographic applications, and the execution monitoring results are obtained. Efficiency error analysis is performed based on the execution monitoring results to obtain the efficiency error analysis results; The efficiency error analysis results are correlated with the error task, and feedback information is generated based on the correlation results. The feedback information is used to optimize and adjust subsequent solution selection.

6. A detection system for improving the efficiency of security assessment in commercial cryptography applications, characterized in that, The system includes: The task list generation module is used to collect application evaluation requirement information, parse the application evaluation requirement information into tasks, and generate a security evaluation task list. Multiple users who conduct commercial cryptography application security evaluation based on the same testing device correspond to multiple tasks. In the security evaluation task list, each user is marked with a security evaluation task, and each security evaluation task specifically includes the encryption level information of the commercial cryptography used by the user, and the encryption security level requirement information customized by the user within the encryption level. The task feature acquisition module is used to connect to the commercial cryptographic application system and acquire the task features of each task in the security assessment task list. The task features include an efficiency identifier and an accuracy identifier. The efficiency identifier is the efficiency of data acquisition and capture under different computing resource occupancy rates of the commercial cryptographic application system. The higher the computing resource occupancy rate, the slower the data capture efficiency through the detection device. The accuracy identifier is the accuracy identifier of the analysis results obtained by the detection device from the data acquired under different computing resource occupancy rates of the commercial cryptographic application system for commercial cryptographic application security analysis. The capability information acquisition module is used to obtain the equipment processing capability information of the testing equipment; The task allocation analysis module is used to input the device processing capacity information, the security assessment task list and the task characteristics into the task allocation model and output the task allocation result, wherein the task allocation result includes multiple execution schemes; The execution scheme filtering module is used to collect and obtain the operating load-efficiency balance parameters, and to filter the multiple execution schemes using the operating load-efficiency balance parameters to obtain the filtered execution scheme. An application security detection module is used to perform commercial cryptographic application security detection on each task in the security assessment task list based on the filtering execution scheme. The task parsing and execution unit is used to parse the security assessment task list to obtain the initial task level and task tolerance of each task. The initial task level is the encryption level information of the commercial password used by the user, and the task tolerance is the encryption security level requirement information defined by the user within the encryption level. A constraint information generation unit is used to generate task constraint information based on the initial task level and the task tolerance. The task allocation obtaining unit is used to input the task constraint information and the task characteristics into the node allocation module of the task allocation model, and obtain the task allocation result based on the output result and the device processing capability information; The data input unit is used to input the output results and the device processing capability information into the processing allocation module of the task allocation model; The constraint information generation unit is used to generate processing constraint values ​​based on the device processing capability information, and to apply execution constraints to the task allocation results in the output results through the processing constraint values. The task allocation obtaining unit is used to generate the task allocation result based on the execution constraint result.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.