Information processing method

By integrating a detection application into the USIM card, the detection data is used to pre-detect the USIM card chip, solving the problem of long detection cycle for USIM card chips and achieving efficient generation of detection results and shortening the delivery cycle.

CN119363359BActive Publication Date: 2026-02-24CHINA MOBILE INTERNET CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411345539.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2026-02-24
Estimated Expiration
2044-09-25

AI Technical Summary

Technical Problem

In existing technologies, the testing cycle for USIM card chips is long, and repeated submissions for testing extend the testing process and testing cycle, affecting information security.

Method used

By integrating a detection application into the USIM card, the detection application stores detection data corresponding to various cryptographic algorithms, receives selection values ​​and detection values, sends selection and algorithm parameters to the chip, calculates and compares the results, generates detection results, and achieves pre-detection.

Benefits of technology

This reduces the probability of chip failure during testing, shortens the testing cycle, and improves testing efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363359B_ABST
    Figure CN119363359B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose an information processing method. The method is applied to a detection application, and the detection application stores a plurality of groups of detection data corresponding to a plurality of cryptographic algorithms. The method comprises: receiving a detection instruction, the detection instruction comprising a target selection value and a target detection value; determining target detection data corresponding to the detection instruction from the plurality of groups of detection data, the target detection data comprising target algorithm parameters of a target cryptographic algorithm and a standard result; sending the target selection value, the target detection value and the target algorithm parameters to a target chip; receiving a second calculation result sent by the target chip; and generating a detection result of the target cryptographic algorithm in the target chip according to the second calculation result and the standard result. Embodiments of the present application can pre-detect a cryptographic algorithm preset in a chip, thereby reducing the probability of repeated submission for detection and shortening the submission period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of security detection technology, and in particular relates to an information processing method. Background Technology

[0002] With the development of communication technology, while enjoying the convenience of the internet, people have also become aware of the importance of network and information security. During communication, data can be encrypted to enhance information security.

[0003] The chip in a Universal Subscriber Identity Module (USIM) card typically has multiple pre-installed cryptographic algorithms. During communication using a smartphone, the chip can encrypt data. Therefore, to meet network and information security requirements, USIM cards usually need to be sent to a professional testing organization to have the cryptographic algorithms in the chip tested.

[0004] However, in the existing testing process, the queuing time for testing is usually quite long. If the chip fails the test, it needs to be returned to the card manufacturer for further investigation and then resubmitted for testing. This leads to repeated testing steps and further extends the testing cycle. Summary of the Invention

[0005] This application provides an information processing method, apparatus, device, computer storage medium, and computer program product that can pre-detect cryptographic algorithms pre-installed on a chip, thereby reducing the probability of repeated submissions for testing and shortening the testing cycle.

[0006] In a first aspect, embodiments of this application provide an information processing method applied to a detection application, the detection application storing multiple sets of detection data corresponding to various cryptographic algorithms; the method includes:

[0007] Receive detection instructions, which include target selection value and target detection value, wherein the target selection value is used to select the target cryptographic algorithm;

[0008] The target detection data corresponding to the detection command is determined from multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and the standard result. The standard result is the first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm.

[0009] The target selection value, target detection value, and target algorithm parameters are sent to the target chip so that the target chip can select the target cryptographic algorithm through the target selection value and calculate the target detection value using the target algorithm parameters as algorithm parameters to obtain the second calculation result.

[0010] Receive the second calculation result sent by the target chip;

[0011] Based on the second calculation result and the standard result, the detection result of the target cryptographic algorithm in the target chip is generated.

[0012] In one alternative implementation, before receiving the detection instruction, the method further includes:

[0013] Upon receiving the application selection command sent by the USIM card, it enters the target working state;

[0014] When the detection application is in the target working state, receive the detection command.

[0015] In an optional implementation, after entering the target working state upon receiving an application selection command sent by the USIM card, the method further includes:

[0016] Send first feedback information to the USIM card so that the USIM card can send a detection command based on the first feedback information. The first feedback information includes the version information of the detection application and the execution information of the selected command.

[0017] In one alternative implementation, the detection application is a USIM card application, and the target chip and the detection application are integrated into the same USIM card.

[0018] In one alternative implementation, before receiving the detection instruction, the method further includes:

[0019] Obtain the preset application file, which includes multiple sets of detection data corresponding to various cryptographic algorithms;

[0020] Store application files;

[0021] In response to the status detection command sent by the USIM card, a second feedback message is sent to the USIM card. The second feedback message is used to indicate that the application file is stored in the detection application.

[0022] In an optional implementation, before sending the target selection value, target detection value, and target algorithm parameters to the target chip, the method further includes:

[0023] Determine the target application programming interface (API) corresponding to the target cryptographic algorithm;

[0024] Send the target selection value, target detection value, and target algorithm parameters to the target chip, including:

[0025] The target selection value, target detection value, and target algorithm parameters are sent to the target chip via the target API.

[0026] In one optional implementation, after receiving the second calculation result sent by the target chip, the method further includes:

[0027] The third calculation result is obtained by the target detection agency using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm to calculate the target detection value;

[0028] The third calculation result is compared with the second calculation result to obtain the verification result;

[0029] Send the verification results to the target testing agency.

[0030] In one alternative implementation, the plurality of cryptographic algorithms include at least one of the following: SM4 Electronic Codebook (ECB) mode encryption algorithm, SM4 ECB mode decryption algorithm, SM4 Cipher Block Chaining (CBC) mode encryption algorithm, SM4 CBC mode decryption algorithm, SM4 Message Authentication (MAC) algorithm, SM3, SM2 signature algorithm, and SM2 signature verification algorithm.

[0031] In one optional implementation, based on the second calculation result and the standard result, a detection result of the target cryptographic algorithm in the target chip is generated, including:

[0032] Compare the second calculation result with the standard result;

[0033] If the second calculation result is consistent with the standard result, a first detection result is generated. The first detection result is used to characterize that the target cryptographic algorithm in the target chip has passed the detection.

[0034] In one optional implementation, after comparing the second calculation result with the standard result, the method further includes:

[0035] If the second calculation result is inconsistent with the standard result, a second detection result is generated. The second detection result is used to characterize that the target cryptographic algorithm in the target chip fails the detection.

[0036] Output a prompt message, which includes the second detection result and the second calculation result.

[0037] Secondly, embodiments of this application provide an information processing apparatus for use in a detection application, wherein the detection application stores multiple sets of detection data corresponding to various cryptographic algorithms; the apparatus includes:

[0038] The receiving module is used to receive detection instructions, which include target selection values ​​and target detection values, wherein the target selection value is used to select a target cryptographic algorithm;

[0039] The determination module is used to determine the target detection data corresponding to the detection command from multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and the standard result. The standard result is the first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm.

[0040] The sending module is used to send a target selection value, a target detection value, and target algorithm parameters to the target chip, so that the target chip can select a target cryptographic algorithm through the target selection value and calculate the target detection value using the target algorithm parameters as algorithm parameters to obtain a second calculation result;

[0041] The receiving module is also used to receive the second calculation result sent by the target chip;

[0042] The generation module is used to generate the detection results of the target cryptographic algorithm in the target chip based on the second calculation result and the standard result.

[0043] Thirdly, embodiments of this application provide an electronic device, the device including: a processor and a memory storing computer program instructions;

[0044] When the processor executes computer program instructions, it implements an information processing method as described in any optional embodiment of the first aspect of this application.

[0045] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement an information processing method as described in any optional embodiment of the first aspect of this application.

[0046] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform an information processing method as described in any optional embodiment of the first aspect of this application.

[0047] The information processing method, apparatus, device, computer storage medium, and computer program product of this application can be applied to a detection application that stores multiple sets of detection data corresponding to various cryptographic algorithms. This application can receive a detection instruction, which includes a target selection value and a target detection value. The target selection value is used to select a target cryptographic algorithm. Then, the target detection data corresponding to the detection instruction is determined from the multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and a standard result. The standard result is a first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm. Next, the target selection value, the target detection value, and the target algorithm parameters are sent to the target chip so that the target chip can select the target cryptographic algorithm using the target selection value and calculate the target detection value using the target algorithm parameters as the algorithm parameters to obtain a second calculation result. Thus, the second calculation result is a calculation result obtained by using the same calculation process as the standard result to calculate the same detection value. Then, the second calculation result sent by the target chip can be received. Based on the second calculation result and the standard result, a detection result of the target cryptographic algorithm in the target chip is generated. In this way, the correctness of the second calculation result can be checked using the pre-set standard results of the testing application, thereby enabling pre-testing of the target cryptographic algorithm pre-installed on the target chip. Thus, if the pre-test passes, the USIM card can then be sent to a professional institution for testing, reducing the probability of failure, the risk of repeated submissions, and shortening the testing cycle. Attached Figure Description

[0048] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0049] Figure 1 This is a flowchart illustrating an information processing method provided in one embodiment of this application;

[0050] Figure 2 This is a flowchart illustrating an information processing method provided in another embodiment of this application;

[0051] Figure 3 This is a schematic diagram of the structure of an information processing apparatus provided in another embodiment of this application;

[0052] Figure 4 This is a schematic diagram of the structure of an electronic device provided in another embodiment of this application. Detailed Implementation

[0053] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0054] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0055] With the development of communication technology, while enjoying the convenience of the internet, people have also become aware of the importance of network and information security. During communication, data can be encrypted to enhance information security.

[0056] Currently, card manufacturers typically integrate their self-developed Card Operating System (COS) and chip into a USIM card. The chip has multiple pre-installed cryptographic algorithms. During communication using a smartphone, the chip can encrypt data. To meet network and information security requirements, the USIM card usually needs to be sent to a professional testing institution to test the cryptographic algorithms of the chip within the USIM card.

[0057] However, in the existing testing process, the queuing period for testing is usually quite long. If the chip fails the test, it needs to be returned to the card manufacturer for further investigation and then resubmitted for testing. On the one hand, the card manufacturer needs a long time for research; on the other hand, resubmission for testing still requires a long queuing period. This leads to repeated testing processes and a further extension of the testing cycle.

[0058] In view of this, the inventor, after in-depth consideration, ingeniously proposed an information processing method, device, equipment, computer storage medium, and computer program product.

[0059] In this embodiment of the application, the information processing method can be implemented based on the relevant architecture of the USIM card.

[0060] A USIM card can be an integrated carrier of card applications, card COS, chip, and chip API. The chip is the hardware component of the USIM card, and it can integrate cryptographic algorithms such as national cryptographic algorithms, providing hardware computing capabilities. The chip API can be an API provided for external calls, which can be invoked by the card COS or card applications.

[0061] The testing application can be used to verify the correctness of cryptographic algorithms integrated into the chip hardware. For example, the testing application can be a card application pre-installed on the USIM card. The testing application can execute Application Protocol Data Unit (APDU) instructions and can also call the chip API. For example, the testing application can also be integrated into a mobile device, executing the testing process as a mobile application (APP). During the verification of the correctness of the cryptographic algorithms integrated into the chip hardware, the USIM card can send APDU instructions to the testing application through the Trusted Service Manager (TSM) tool, causing the testing application to execute the corresponding operations.

[0062] The information processing method provided in this application embodiment will be described below with reference to the accompanying drawings and through specific embodiments and application scenarios. The information processing method provided in this application embodiment can be executed by an information processing device, or a partial module within that information processing device for executing the information processing method. This application embodiment uses an information processing device executing the information processing method as an example to describe in detail the information processing method provided in this application embodiment.

[0063] The following is in conjunction with the appendix Figure 1 The information processing method provided in the embodiments of this application will be described in detail.

[0064] Figure 1 A flowchart illustrating an embodiment of the information processing method provided in this application is shown. This information processing method can be specifically applied to a detection application, which stores multiple sets of detection data corresponding to various cryptographic algorithms. The detection data can be pre-set detection data or detection data written to the detection application using dynamically installed data; no limitation is made here. Figure 1 As shown, the information processing method may include the following steps S110 to S150.

[0065] S110, Receive detection instruction, the detection instruction includes target selection value and target detection value, wherein the target selection value is used to select target cryptographic algorithm.

[0066] In step S110, the target detection value can represent the input value used to execute the target cryptographic algorithm. For example, if the target cryptographic algorithm is an encryption algorithm, the target detection value can be the plaintext data to be encrypted; if the target cryptographic algorithm is a decryption algorithm, the target detection value can be the ciphertext data to be decrypted.

[0067] S120, determine the target detection data corresponding to the detection command from multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and the standard result. The standard result is the first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm.

[0068] In step S120, determining the target detection data corresponding to the detection instruction from multiple sets of detection data may include: determining the detection data corresponding to the target cryptographic algorithm based on the target selection value, and using this as the target detection data. In one example, a cryptographic algorithm may correspond to multiple sets of detection data, and each set of detection data may include different detection values, algorithm parameters, and standard results. Determining the target detection data corresponding to the detection instruction from multiple sets of detection data may include: determining the multiple sets of detection data corresponding to the target cryptographic algorithm based on the target selection value, and determining the target detection data from the multiple sets of detection data corresponding to the target cryptographic algorithm based on the target detection value.

[0069] In step S120, the detection data can be generated using algorithm tools. In one example, after generating the detection data, its correctness can be verified, and it is then stored in the detection application after successful verification. Thus, the standard result of step S120 can be considered as obtaining the correct result by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm.

[0070] S130, send the target selection value, target detection value and target algorithm parameters to the target chip, so that the target chip can select the target cryptographic algorithm by the target selection value, and calculate the target detection value by using the target algorithm parameters as algorithm parameters to obtain the second calculation result.

[0071] Accordingly, the target chip can receive the target selection value, the target detection value, and the target algorithm parameters. Based on the target selection value, a target cryptographic algorithm is selected from the cryptographic algorithms preset in the chip. The target algorithm parameters are used as algorithm parameters to calculate the target detection value, resulting in a second calculation result.

[0072] S140 receives the second calculation result sent by the target chip.

[0073] S150, Based on the second calculation result and the standard result, generate the detection result of the target cryptographic algorithm in the target chip.

[0074] The information processing method of this application embodiment can be applied to a detection application that stores multiple sets of detection data corresponding to various cryptographic algorithms. This application embodiment can receive a detection instruction, which includes a target selection value and a target detection value. The target selection value is used to select a target cryptographic algorithm. Then, the target detection data corresponding to the detection instruction is determined from the multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and a standard result. The standard result is a first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm. Next, the target selection value, the target detection value, and the target algorithm parameters are sent to the target chip so that the target chip can select the target cryptographic algorithm using the target selection value and calculate the target detection value using the target algorithm parameters as the algorithm parameters to obtain a second calculation result. Thus, the second calculation result is a calculation result obtained by using the same calculation process as the standard result to calculate the same detection value. Then, the second calculation result sent by the target chip can be received. Based on the second calculation result and the standard result, a detection result of the target cryptographic algorithm in the target chip is generated.

[0075] In one embodiment, before receiving the detection instruction, the method may further include:

[0076] Upon receiving the application selection command sent by the USIM card, it enters the target working state.

[0077] When the detection application is in the target working state, receive the detection command.

[0078] In the above implementation, the application selection instruction (SELECT instruction) can be used to select a detection application. Upon receiving the application selection instruction, the detection application can be selected and enter a target operating state. This target operating state includes a state where the correctness of the cryptographic algorithm in the chip can be detected.

[0079] According to the above implementation method, before testing the built-in cryptographic algorithm of the chip through the testing application, the testing application can be activated by the SELECT command to ensure that the testing application is in a normal working state. This allows the testing application to respond to subsequent testing commands in a timely manner, improving testing efficiency.

[0080] In one embodiment, after entering the target working state upon receiving an application selection instruction sent by the USIM card, the method may further include:

[0081] Send first feedback information to the USIM card so that the USIM card can send a detection command based on the first feedback information. The first feedback information includes the version information of the detection application and the execution information of the selected command.

[0082] According to the above implementation method, after the detection application is selected and successfully activated, it can send first feedback information to the USIM card. This first feedback information includes the version information of the detection application and the execution information of the selection command. This helps the USIM card confirm the status of the detection application based on the feedback information and generate or select appropriate detection commands, thereby improving the efficiency and accuracy of the detection.

[0083] In one embodiment, the detection application can be a USIM card application, and the target chip and the detection application are integrated into the same USIM card.

[0084] According to the above implementation method, the detection application is a card application integrated with the target chip on the same USIM card. Compared with other integration methods, the card application can be used to detect various types of chips, for example, it can be used for all Java cards. This improves the flexibility of detection. In addition, the detection application is pre-installed in the USIM card, which facilitates the rapid reception and execution of APDU commands and the sending of corresponding data to the target chip, thereby improving detection efficiency.

[0085] In one embodiment, before receiving the detection instruction, the method may further include:

[0086] Obtain the preset application file, which includes multiple sets of detection data corresponding to various cryptographic algorithms.

[0087] Store application files.

[0088] In response to the status detection command sent by the USIM card, a second feedback message is sent to the USIM card. The second feedback message is used to indicate that the application file is stored in the detection application.

[0089] In the above embodiments, the multiple sets of test data can be test data generated by tools. As an example, after the test data is generated, it can be verified using verification tools or manual review to ensure its accuracy.

[0090] According to the above implementation method, a preset application file can be stored in the detection application. After successful storage, in response to the status detection command sent by the USIM card, a second feedback message can be sent to the USIM card. This facilitates the USIM card's monitoring of the detection application's status and reduces the risk of the detection application malfunctioning.

[0091] In one embodiment, before sending the target selection value, target detection value, and target algorithm parameters to the target chip, the method may further include:

[0092] Determine the target application programming interface (API) corresponding to the target cryptographic algorithm.

[0093] Sending target selection values, target detection values, and target algorithm parameters to the target chip, which may specifically include:

[0094] The target selection value, target detection value, and target algorithm parameters are sent to the target chip via the target API.

[0095] According to the above implementation method, when detecting the correctness of different target cryptographic algorithms, different chip APIs can be called to send the target selection value, target detection value and target algorithm parameters to the target chip, thereby ensuring the correct processing and efficient transmission of the target selection value, target detection value and target algorithm parameters.

[0096] In one embodiment, after receiving the second calculation result sent by the target chip, the method may further include:

[0097] The third calculation result is obtained by the target detection agency using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm to calculate the target detection value.

[0098] The third calculation result is compared with the second calculation result to obtain the verification result.

[0099] Send the verification results to the target testing agency.

[0100] In the above embodiments, the target testing institution can be the submitting institution or other third-party testing institutions. According to the above embodiments, the calculation results of the target chip can be compared with the calculation results of the target testing institution, thereby enabling third-party verification of the target cryptographic algorithm built into the target chip. In this way, the testing results can be verified, improving the credibility of the testing results.

[0101] In one embodiment, after receiving the second calculation result sent by the target chip, the method may further include:

[0102] The second calculation result is sent to the target detection agency so that the target detection agency can compare the third calculation result with the second calculation result to obtain the verification result. The third calculation result is the calculation result obtained by the target detection agency using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm to calculate the target detection value.

[0103] According to the above implementation method, the calculation results of the target chip can be sent to the target testing agency, which can then compare the calculation results of the target chip with its own calculation results, thereby enabling a third party to verify the target cryptographic algorithm built into the target chip. This allows for verification of the testing results and improves their reliability.

[0104] In one embodiment, the multiple cryptographic algorithms may include at least one of the following: SM4 Electronic Codebook ECB Mode (SM4-ECB) encryption algorithm, SM4 ECB Mode (SM4-ECB) decryption algorithm, SM4 Cipher Block Chaining CBC Mode (SM4-CBC) encryption algorithm, SM4 CBC Mode (SM4-CBC) decryption algorithm, SM4 Message Authentication MAC (SM4-MAC) algorithm, SM3, SM2 signature algorithm, and SM2 signature verification algorithm.

[0105] According to the above implementation method, the detection card application stores detection data corresponding to various national cryptographic algorithms, thereby enabling the detection of various national cryptographic algorithms in the target chip and improving the comprehensiveness of the detection.

[0106] In one embodiment, the multiple sets of detection data corresponding to various cryptographic algorithms may include multiple sets of detection data generated in advance using algorithm tools.

[0107] Taking a set of detection data corresponding to one cryptographic algorithm as an example, detection datasets for each type of cryptographic algorithm can be generated using algorithm tools according to the category of cryptographic algorithms. Detection data for each cryptographic algorithm can then be extracted from the detection datasets.

[0108] As an example, detection datasets for the SM4, SM3, and SM2 algorithms can be generated separately using algorithm tools.

[0109] For example, the detection dataset for the SM4 algorithm may include a random number key for the SM4-CBC, SM4-ECB, and SM4-MAC algorithms, an initialization vector for the random numbers, plaintext data for the SM4-CBC and SM4-ECB algorithms, ciphertext data for the SM4-CBC and SM4-ECB algorithms, and SM4-MAC result data. The random numbers are not all zeros, and padding in the SM4-MAC result data is not mandatory.

[0110] The detection data for the SM4 algorithm can be extracted from the detection dataset for the SM4-ECB encryption algorithm, SM4-ECB decryption algorithm, SM4-CBC encryption algorithm, SM4-CBC decryption algorithm, and SM4-MAC algorithm. Specifically, the detection data for the SM4-ECB encryption algorithm can include plaintext data as the detection value; the SM4-ECB algorithm key and initialization vector as algorithm parameters; and the ciphertext data of the SM4-ECB algorithm as the standard result. Similarly, the detection data for the SM4-ECB decryption algorithm can include ciphertext data as the detection value; the SM4-ECB algorithm key and initialization vector as algorithm parameters; and the plaintext data of the SM4-ECB algorithm as the standard result. Finally, the detection data for the SM4-CBC encryption algorithm can include plaintext data as the detection value; the SM4-CBC algorithm key and initialization vector as algorithm parameters; and the ciphertext data of the SM4-CBC algorithm as the standard result. The detection data for the SM4-CBC decryption algorithm can include ciphertext data as the detection value; the SM4-CBC algorithm key and the SM4-CBC algorithm initialization vector as algorithm parameters; and the plaintext data of the SM4-CBC algorithm as the standard result. The detection data for the SM4-MAC algorithm can include plaintext data as the detection value; the SM4-MAC algorithm key as algorithm parameters; and the SM4-MAC result data as the standard result.

[0111] For example, the detection dataset for the SM3 algorithm may include plaintext data of the SM3 algorithm and corresponding hash data of the SM3 algorithm. The detection data corresponding to SM3 may include plaintext data as detection values ​​and hash data as standard results. Algorithm parameters can be empty, that is, it is not necessary to send algorithm parameters to the chip.

[0112] For example, the detection dataset for the SM2 algorithm may include a random pair of SM2 public and private keys, SM2 plaintext data, SM2 private key signature data, and SM2 public key verification data. The SM2 private key signature data may contain preprocessed values ​​(E-values ​​and Z-values).

[0113] The detection data for the SM2 algorithm can be extracted from the detection dataset for both the SM2 signature algorithm and the SM2 signature verification algorithm. The detection data for the SM2 signature algorithm can include plaintext data as the detection value; the SM2 signature algorithm public and private keys (SM2 public-private key pairs) as algorithm parameters; and the SM2 private key signature data as the standard result. Similarly, the detection data for the SM2 signature verification algorithm can include plaintext data as the detection value; the SM2 signature verification algorithm public and private keys (SM2 public-private key pairs) as algorithm parameters; and the SM2 public key signature verification data as the standard result.

[0114] In one embodiment, based on the second calculation result and the standard result, a detection result of the target cryptographic algorithm in the target chip is generated, which may specifically include:

[0115] The second calculation result is compared with the standard result.

[0116] If the second calculation result is consistent with the standard result, a first detection result is generated. The first detection result is used to characterize that the target cryptographic algorithm in the target chip has passed the detection.

[0117] According to the above implementation method, the second calculation result can be compared with the standard result. If the second calculation result is consistent with the standard result, it is determined that the target cryptographic algorithm in the target chip has passed the test. In this way, the correctness of the second calculation result can be checked using the standard result preset by the testing application, thereby enabling pre-testing of the target cryptographic algorithm preset in the target chip. Thus, if the pre-test passes, the USIM card can be sent to a professional institution for testing, thereby reducing the probability of failure, reducing the risk of repeated submissions, and shortening the testing cycle.

[0118] In one embodiment, after comparing the second calculation result with the standard result, the method may further include:

[0119] If the second calculation result is inconsistent with the standard result, a second detection result is generated. The second detection result is used to characterize the failure of the target cryptographic algorithm detection in the target chip.

[0120] Output a prompt message, which includes the second detection result and the second calculation result.

[0121] According to the above implementation method, if the second calculation result is inconsistent with the standard result, it can be determined that the target cryptographic algorithm in the target chip has failed the detection, and a corresponding prompt message can be output. In this way, the card vendor can use the prompt message to analyze and study the cryptographic algorithm built into the chip, thereby shortening the research cycle. Thus, research and adjustments can be made in a timely manner if the pre-detection fails, thereby reducing the probability of repeated submissions for testing.

[0122] To better describe the overall solution, a specific example is given based on the above embodiments to illustrate the information processing method of this application. This will be explained in detail below. It should be noted that the following example is only for explaining the embodiments of this application and does not constitute a limitation on the embodiments of this application.

[0123] In this embodiment, the detection application can be a card application pre-installed on the USIM card or a mobile app. The detection application stores multiple sets of detection data corresponding to various cryptographic algorithms; one cryptographic algorithm can correspond to one set of detection data or multiple sets of detection data. The detection application can detect the correctness of the cryptographic algorithms in response to detection commands. For ease of description, the following uses a card application pre-installed on the USIM card as an example, specifying that one cryptographic algorithm corresponds to one set of detection data, to illustrate the information processing method of this embodiment. For example, the commands described below can be APDU commands. APDU commands can be sent by the USIM card through tools provided by TSM.

[0124] In one example, before executing the information processing method of this application embodiment, it is necessary to first install the detection card application onto the USIM card. The installation process may include steps (1) to (2).

[0125] (1) Generate the Converted Applet Package (cap) file for the test card application.

[0126] Step (1) may specifically include: generating detection data. The detection data is packaged and pre-loaded into a .cap file to obtain the detection card application .cap file. This detection data may include detection data corresponding to the SM4-ECB encryption algorithm, SM4-ECB decryption algorithm, SM4-CBC encryption algorithm, SM4-CBC decryption algorithm, SM4-MAC algorithm, SM3, SM2 signature algorithms, and SM2 signature verification algorithm. Thus, the detection card application can pre-load a complete set of detection data corresponding to the SM2, SM3, and SM4 algorithms during initialization.

[0127] (2) Install the generated detection card application CAP file onto the USIM card.

[0128] For example, the process of installing the generated detection card application .cap file onto the USIM card may include: selecting the primary security domain of the USIM card, completing external authentication, and using preset loading and installation parameters to complete the detection card application installation. Then, an APDU command is sent to the detection card application, and the installation success is verified based on the status word (SW) returned by the detection card application.

[0129] After successful installation of the detection card application, it can determine one or more national cryptographic algorithms of the detection chip based on the parameter fields of the customized APDU command upon receiving it. Customized APDU commands can include the SELECT command for activating and selecting the installed detection card application, and the ALDO DETECTION command for selecting different input detection values ​​and returning detection results during the detection process. Below are some examples of the formats related to the SELECT and ALDO DETECTION commands. For brevity, the English terms used in these formats will be explained first.

[0130] TLV is an abbreviation for "Tag-Length-Value". It is a data representation format commonly used to encode data units in communication protocols.

[0131] CLA stands for Class type, which can represent a level type.

[0132] INS stands for Instruction type, which can represent the instruction type.

[0133] P1: Full name is Parameter 1, which can represent parameter 1.

[0134] P2: Full name is Parameter 2, which can represent parameter 2.

[0135] LC stands for Length Coding, which can represent the encoding length.

[0136] LE stands for Length Encoding, which can represent length encoding.

[0137] DATA: Data.

[0138] AID: Short for Application Identifier, it can represent an application identifier.

[0139] In one example, the SELECT command format can be as shown in Table 1.

[0140] Table 1: SELECT Command Format

[0141] data describe CLA 00 INS A4 P1 04 P2 00 LC Application Example AID Length DATA Application Example AID LE 00

[0142] In one example, the response format for a SELECT command can be as shown in Table 2.

[0143] Table 2: SELECT Command Response Format

[0144]

[0145] In one example, the response status code format for the SELECT command can be as shown in Table 3.

[0146] Table 3: SELECT Command Response Status Code Format

[0147] SW describe 9000 Execution successful 6A82 File not found 6A86 P1P2 parameter error

[0148] In one example, the ALDO DETECTION instruction format can be as shown in Table 4.

[0149] Table 4: ALDO DETECTION Command Format

[0150] data describe CLA 00 INS A2 P1 xx P2 00 LC Data field length DATA Data domain LE 00

[0151] In one example, the format of the P1 parameter can be described as shown in Table 5. In Table 5, b8 to b1 can identify the individual bits (BIT) of the P1 parameter.

[0152] Table 5: Description of P1 parameter format

[0153] b8 b7 b6 b5 b4 b3 b2 b1 illustrate 0 1 - - - - - - Not the last instruction 1 0 - - - - - - The last instruction or all data - - 0 1 - - - - Get the first set or all data - - 1 0 - - - - Get the next set of data

[0154] In one example, the DATA field format can be as shown in Table 6. In Table 6, 0x can represent a binary flag bit. The fields in the DATA field can be combined arbitrarily.

[0155] Table 6: DATA Field Format

[0156]

[0157] In one example, the ALDO DETECTION command response format can be as shown in Table 7.

[0158] Table 7: ALDO DETECTION Command Response Format

[0159]

[0160]

[0161] In one example, the ALDO DETECTION instruction response status code format can be as shown in Table 8.

[0162] Table 8: ALDO DETECTION Command Response Status Code Format

[0163] SW describe 9000 Execution successful 6310 Subsequent data reading 6A86 P1P2 parameter error

[0164] Next, based on the aforementioned instruction formats, examples are provided to illustrate the information processing methods. For instance... Figure 2 As shown, the information processing method may include the following steps S210 to S280.

[0165] S210, the USIM card sends a SELECT command to the detection card application.

[0166] Accordingly, the detection card application responds to the SELECT command and activates the detection card application.

[0167] S220, after the detection card application is activated, the detection card application returns version information and SW status word to the USIM card.

[0168] For example, the AID of the detection card application is: D156000101800000000000009B0069D02. Referring to the format in Table 1, the SELECT command can be: 00A4040010D15600010180000000000009B0069D0200. The response format of the detection card application can be: 4403010000. The SW status word of the detection card application response can be: 9000 (indicating that the card application is selected).

[0169] S230, the USIM card sends the ALDO DETECTIO command to the detection card application.

[0170] For example, the ALDO DETECTIO instruction may include a selection value and a detection value. The selection value can be used to indicate the Chinese cryptographic algorithm being detected. The detection value can be used by the chip to perform calculations on the detection value based on a preset Chinese cryptographic algorithm. The selection values ​​can be combined arbitrarily; that is, one algorithm or multiple algorithms can be selected for detection.

[0171] S240, the detection card application responds to the ALDO DETECTIO command and starts the algorithm detection function of the detection card application.

[0172] S250: The detection card application calls the chip API corresponding to the selection value in the ALDO DETECTIO instruction, and sends the selection value, detection value and algorithm parameters to the chip.

[0173] Taking the ALDO DETECTIO instruction corresponding to the SM4-ECB encryption algorithm as an example, the AID of the detection card application is: D15600010180000000000009B0069D02. The plaintext data (i.e., the detection value) is: 091CAA18794C5AE5FF8396761C177061. The algorithm parameters may include the SM4-ECB algorithm key: 3AB4BED9F22C406AB1C579847B9A444F, and the SM4-ECB algorithm initialization vector: 7D9F159E9A66C677A6E1C13F42964F8E. Referring to the formats in Tables 4, 5, and 6, the ALDO DETECTIO command can be: 00A28000120310091CAA18794C5AE5FF8396761C177061. In this command, Tag = 0x03 in the DATA field, meaning Tag = 0x03 is the selection value. The plaintext data is: 091CAA18794C5AE5FF8396761C177061, which is the detection value, indicating that the SM4-ECB encryption algorithm is selected for detection.

[0174] S260: Based on the received selection value, detection value, and algorithm parameters, the chip uses a national cryptographic algorithm pre-installed in the chip hardware to calculate the detection value and obtain the calculation result.

[0175] For example, if the ALDO DETECTIO instruction is: 00A28000120310091CAA18794C5AE5FF8396761C177061, the chip receives plaintext data (i.e., the detection value): 091CAA18794C5AE5FF8396761C177061. The received algorithm parameters include the SM4-ECB algorithm key: 3AB4BED9F22C406AB1C579847B9A444F, and the SM4-ECB algorithm initialization vector: 7D9F159E9A66C677A6E1C13F42964F8E. Thus, the chip can select the SM4-ECB encryption algorithm, using the received SM4-ECB algorithm key and SM4-ECB algorithm initialization vector as algorithm parameters, to calculate the result from the plaintext data.

[0176] S270: The chip returns the calculation results to the detection card application via the chip API.

[0177] S280, the detection card application compares the received calculation result with the preset correct result, and judges the correctness of the Chinese cryptographic algorithm in the chip hardware based on the comparison result.

[0178] In step S280, the test card application can compare the selected value and the detected value with the preset detection data in the test card application. If the result value is consistent with the result value of the chip API response, the output result of the test card application is 00, that is, the test passed (refer to the definition in Table 7). If the result value is inconsistent with the result value of the chip API response, the output result of the test card application is 01, that is, the test failed (refer to the definition in Table 7).

[0179] Based on the same inventive concept as the information processing method, this application also provides an information processing device for use in a detection application, wherein the detection application stores multiple sets of detection data corresponding to various cryptographic algorithms.

[0180] like Figure 3 As shown, the information processing device 300 may include a receiving module 301, a determining module 302, a sending module 303, and a generating module 304.

[0181] The receiving module 301 is used to receive a detection instruction, which includes a target selection value and a target detection value, wherein the target selection value is used to select a target cryptographic algorithm.

[0182] The determination module 302 is used to determine the target detection data corresponding to the detection command from multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and the standard result. The standard result is the first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm.

[0183] The sending module 303 is used to send a target selection value, a target detection value, and target algorithm parameters to the target chip, so that the target chip can select a target cryptographic algorithm by means of the target selection value, and calculate the target detection value by means of the target algorithm parameters to obtain a second calculation result;

[0184] The receiving module 301 is also used to receive the second calculation result sent by the target chip;

[0185] The generation module 304 is used to generate the detection result of the target cryptographic algorithm in the target chip based on the second calculation result and the standard result.

[0186] The information processing apparatus of this application embodiment can be applied to a detection application that stores multiple sets of detection data corresponding to various cryptographic algorithms. This application embodiment can receive a detection instruction, which includes a target selection value and a target detection value. The target selection value is used to select a target cryptographic algorithm. Then, the target detection data corresponding to the detection instruction is determined from the multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and a standard result. The standard result is a first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm. Next, the target selection value, the target detection value, and the target algorithm parameters are sent to the target chip so that the target chip can select the target cryptographic algorithm using the target selection value and calculate the target detection value using the target algorithm parameters as the algorithm parameters to obtain a second calculation result. Thus, the second calculation result is a calculation result obtained by using the same calculation process as the standard result to calculate the same detection value. Then, the second calculation result sent by the target chip can be received. Based on the second calculation result and the standard result, a detection result of the target cryptographic algorithm in the target chip is generated. In this way, the correctness of the second calculation result can be checked using the pre-set standard results of the testing application, thereby enabling pre-testing of the target cryptographic algorithm pre-installed on the target chip. Thus, if the pre-test passes, the USIM card can then be sent to a professional institution for testing, reducing the probability of failure, the risk of repeated submissions, and shortening the testing cycle.

[0187] In one embodiment, the apparatus may further include:

[0188] The entry module is used to enter the target working state before receiving the application selection instruction sent by the USIM card of the general user authentication module, before receiving the detection instruction.

[0189] The receiving module is specifically used to receive detection instructions when the detection application is in the target working state.

[0190] In one embodiment, the sending module can also be used to send first feedback information to the USIM card after entering the target working state upon receiving the application selection instruction sent by the USIM card, so that the USIM card can send a detection instruction based on the first feedback information, wherein the first feedback information includes the version information of the detected application and the execution information of the selection instruction.

[0191] In one embodiment, the detection application can be a USIM card application, and the target chip and the detection application are integrated into the same USIM card.

[0192] In one embodiment, the apparatus may further include:

[0193] The acquisition module is used to acquire a preset application file before receiving the detection instruction. The application file includes multiple sets of detection data corresponding to various cryptographic algorithms.

[0194] The storage module is used to store application files.

[0195] The sending module can also be used to respond to the status detection command sent by the USIM card and send a second feedback information to the USIM card. The second feedback information is used to indicate that the application file is stored in the detection application.

[0196] In one embodiment, the determining module can also be used to determine the target application programming interface (API) corresponding to the target cryptographic algorithm before sending the target selection value, target detection value, and target algorithm parameters to the target chip.

[0197] The sending module is used to send target selection values, target detection values, and target algorithm parameters to the target chip, which may specifically include:

[0198] The sending module is used to send target selection values, target detection values, and target algorithm parameters to the target chip via the target API.

[0199] In one embodiment, the apparatus may further include:

[0200] The acquisition module is used to acquire, after receiving the second calculation result sent by the target chip, the third calculation result obtained by the target detection agency using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm to calculate the target detection value.

[0201] The comparison module is used to compare the third calculation result with the second calculation result to obtain the verification result.

[0202] The sending module is used to send the verification results to the target testing agency.

[0203] In one embodiment, the multiple cryptographic algorithms may include at least one of the following: SM4 Electronic Codebook (ECB) mode cryptographic algorithm, SM4 ECB mode decryption algorithm, SM4 Cipher Block Chaining (CBC) mode cryptographic algorithm, SM4 CBC mode decryption algorithm, SM4 Message Authentication (MAC) algorithm, SM3, SM2 signature algorithm, and SM2 signature verification algorithm.

[0204] In one embodiment, the generation module can specifically be used for:

[0205] Compare the second calculation result with the standard result;

[0206] If the second calculation result is consistent with the standard result, a first detection result is generated. The first detection result is used to characterize that the target cryptographic algorithm in the target chip has passed the detection.

[0207] In one embodiment, the generation module can also be used to: generate a second detection result if the second calculation result is inconsistent with the standard result, the second detection result being used to characterize that the target cryptographic algorithm in the target chip fails the detection.

[0208] The device may also include an output module for outputting prompt information, which includes a second detection result and a second calculation result.

[0209] The information processing device provided in this application embodiment can achieve... Figure 1 The various processes implemented in the method implementation examples will not be described again here to avoid repetition.

[0210] Figure 4 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.

[0211] An electronic device may include a processor 401 and a memory 402 storing computer program instructions.

[0212] Specifically, the processor 401 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0213] Memory 402 may include mass storage for data or instructions. For example, and not limitingly, memory 402 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 402 may include removable or non-removable (or fixed) media. Where appropriate, memory 402 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 402 is non-volatile solid-state memory.

[0214] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.

[0215] The processor 401 reads and executes computer program instructions stored in the memory 402 to implement any of the information processing or information processing methods in the above embodiments.

[0216] As an example, the electronic device may also include a communication interface 403 and a bus 410. Wherein, such as Figure 4 As shown, the processor 401, memory 402, and communication interface 403 are connected through bus 410 and complete communication with each other.

[0217] The communication interface 403 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0218] Bus 410 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 410 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.

[0219] The electronic device can execute the information processing method described in the embodiments of this application, thereby achieving the combination Figure 1 and Figure 3 The described information processing methods and apparatus.

[0220] Furthermore, in conjunction with the information processing methods in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the information processing methods in the above embodiments.

[0221] This application also provides a computer program product, including a computer program, which, when executed, implements any of the information processing methods described in the above embodiments.

[0222] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0223] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0224] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0225] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0226] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. An information processing method, characterized in that, The method is applied to a detection application, which stores multiple sets of detection data corresponding to various cryptographic algorithms; the method includes: Receive a detection instruction, the detection instruction including a target selection value and a target detection value, wherein the target selection value is used to select a target cryptographic algorithm; The target detection data corresponding to the detection instruction is determined from the multiple sets of detection data. The target detection data includes the target algorithm parameters of the target cryptographic algorithm and the standard result. The standard result is a first calculation result obtained by calculating the target detection value using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm. The target selection value, the target detection value, and the target algorithm parameters are sent to the target chip so that the target chip can select the target cryptographic algorithm through the target selection value and calculate the target detection value using the target algorithm parameters as algorithm parameters to obtain a second calculation result; Receive the second calculation result sent by the target chip; Based on the second calculation result and the standard result, the detection result of the target cryptographic algorithm in the target chip is generated; The detection application is a USIM card application, and the target chip and the detection application are integrated into the same USIM card; After receiving the second calculation result sent by the target chip, the method further includes: A third calculation result is obtained by the target detection agency using the target algorithm parameters as the algorithm parameters of the target cryptographic algorithm to calculate the target detection value; The third calculation result is compared with the second calculation result to obtain the verification result; The verification result is sent to the target testing agency.

2. The method according to claim 1, characterized in that, Before receiving the detection instruction, the method further includes: Upon receiving the application selection instruction sent by the Universal User Authentication Module (USIM) card, it enters the target working state; When the detection application is in the target working state, a detection command is received.

3. The method according to claim 2, characterized in that, Upon receiving the application selection command sent by the USIM card and entering the target working state, the method further includes: Send first feedback information to the USIM card so that the USIM card can send the detection command based on the first feedback information, wherein the first feedback information includes the version information of the detection application and the execution information of the selection command.

4. The method according to claim 1, characterized in that, Before receiving the detection instruction, the method further includes: Obtain a preset application file, wherein the application file includes multiple sets of detection data corresponding to the various cryptographic algorithms; Store the application file; In response to the status detection command sent by the USIM card, a second feedback information is sent to the USIM card, the second feedback information being used to indicate that the application file is stored in the detection application.

5. The method according to claim 1, characterized in that, Before sending the target selection value, the target detection value, and the target algorithm parameters to the target chip, the method further includes: Determine the target application programming interface (API) corresponding to the target cryptographic algorithm; Sending the target selection value, the target detection value, and the target algorithm parameters to the target chip includes: The target selection value, the target detection value, and the target algorithm parameters are sent to the target chip via the target API.

6. The method according to claim 1, characterized in that, The various cryptographic algorithms include at least one of the following: SM4 Electronic Codebook (ECB) mode encryption algorithm, SM4 ECB mode decryption algorithm, SM4 Cipher Block Chaining (CBC) mode encryption algorithm, SM4 CBC mode decryption algorithm, SM4 Message Authentication (MAC) algorithm, SM3, SM2 signature algorithm, and SM2 signature verification algorithm.

7. The method according to claim 1, characterized in that, The step of generating the detection result of the target cryptographic algorithm in the target chip based on the second calculation result and the standard result includes: Compare the second calculation result with the standard result; If the second calculation result is consistent with the standard result, a first detection result is generated, which is used to characterize that the target cryptographic algorithm in the target chip has passed the detection.

8. The method according to claim 7, characterized in that, After comparing the second calculation result with the standard result, the method further includes: If the second calculation result is inconsistent with the standard result, a second detection result is generated. The second detection result is used to characterize that the target cryptographic algorithm in the target chip fails the detection. Output a prompt message, which includes the second detection result and the second calculation result.

Citation Information

Patent Citations

  • Algorithm test method, device and system for security chip

    CN118585439A