Stability testing method and equipment for static trusted verification function of trusted DCS controller
By obtaining and analyzing the information of programs and configuration files in the stability test of the static trusted verification function, and automating stability testing, the existing testing methods are solved, and the problem of slow speed and inability to use random parameter values is achieved, achieving an efficient and good-quality testing process.
Patent Information
- Application Number
- CN202510212498.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The existing static trusted verification function stability testing methods cannot execute shell scripts locally for automated testing, resulting in slow testing and the inability to use random parameter values for stability testing, affecting the test progress and quality.
A stability test method for the static trusted verification function of the trusted DCS controller is provided. By obtaining the required programs and configuration files, the configuration mark status of the configuration file is obtained, and stability test is carried out based on the configuration mark status of the program, the configuration file, and the trusted module status of the static trusted verification function module and the corresponding operation results, the first test result and the second test result are obtained, and the results are written to the file to generate a test report.
Automatic testing is realized, which improves the test speed and quality, significantly reduces the testing cost, and can promptly detect problems during long-term random testing through the generated test report, reducing risks.
Smart Images

Figure CN119717742B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of distributed control systems, and in particular relates to a stability testing method and equipment for a static trusted verification function of a trusted DCS controller. Background Art
[0002] Domestic trusted DCS (Distributed Control System) controllers integrate static trusted verification functions. After configuring the static trusted verification strategy, files can be read and executed, but cannot be modified, deleted, or renamed. When a file is untrusted, it cannot be read, executed, modified, deleted, or renamed. This function can effectively prevent malicious tampering and program execution by attackers, thereby protecting the file integrity of the operating system.
[0003] The stability test of the static trusted verification function mainly ensures reliable operation by verifying the configuration of the controller, the stability and security of the software and hardware. The test method covers aspects such as system configuration check, software function verification, security audit, resource consumption analysis and redundant function verification, while the stability test system includes hardware test platform, software verification tools, security analysis tools, etc. Through this series of tests and verifications, the credibility and stability of the DCS controller in a static environment can be ensured to meet the requirements of high reliability and security of the control system.
[0004] After the trusted module is deployed on the DCS controller, it needs to be tested. The operating system used on the controller is SylixOS, which cannot execute shell and other script programs locally for automated testing. Traditional manual testing is slow, and random parameter values cannot be used to perform stability tests on the static trusted verification function. If static trusted verification is to be fully performed, a lot of testing time is required, which affects the test progress and quality. Summary of the invention
[0005] The invention provides a stability testing method and equipment for a static trusted verification function of a trusted DCS controller, which are used to solve the existing problems.
[0006] The purpose of the present invention can be achieved by the following technical solutions:
[0007] The first aspect of the present invention is to provide a stability testing method for a static trusted verification function of a trusted DCS controller, comprising:
[0008] Obtain the programs and configuration files required for the DCS controller stability test in static state;
[0009] Obtaining the configuration mark status of the configuration file, performing stability testing according to the configuration mark status of the program and the configuration file and the trusted module status of the static trusted verification function module and the result of the corresponding operation; and obtaining a first test result and a second test result;
[0010] Obtain all configuration policies and first test results and second test results corresponding to parameters according to the program, write all first test results and second test results and corresponding configuration policies and parameters into a specified file, and generate a test report.
[0011] Furthermore, the programs required in the stability test process include: a C program for testing the static trusted verification function and a C program for analyzing the randomness of the stability test.
[0012] Further, the obtaining of the configuration mark status of the configuration file includes:
[0013] When policies and parameters are configured in the configuration file, the configuration mark state of the configuration file is recorded as the marked state Marked; when policies and parameters are not configured in the configuration file, the configuration mark state of the configuration file is recorded as the unmarked state Unmarked.
[0014] Further, the stability test is performed according to the configuration mark status of the program and configuration file and the trusted module status of the static trusted verification function module and the result of the corresponding operation; and the first test result and the second test result are obtained, including:
[0015] By testing the C program of the static trusted verification function, an analysis test is performed according to the configuration mark state of the configuration file and the operation result of the configuration file to obtain a first test result;
[0016] By testing the C program of the static trusted verification function, an analysis test is performed according to the trusted module state of the static trusted verification function module and the result of the corresponding operation to obtain a second test result; wherein the trusted module state of the static trusted verification function module includes two states: on and off.
[0017] Further, the performing of analysis and testing according to the configuration mark state of the configuration file and the operation result of the configuration file to obtain a first test result includes:
[0018] When the configuration file is in the marked state and the trusted state is trusted, the program will return the result of the file operation when the configuration file is viewed, written, executed, deleted, and renamed. The program will match the file operation with the corresponding log file to check whether a log is generated and its correctness. If no log is generated or the log content is incorrect, the cause needs to be located and investigated. Then the execution test is recorded and recorded as the first test result.
[0019] When the configuration file is in the unmarked state, viewing, writing, executing, deleting and renaming operations on the configuration file can be performed normally, but no log is recorded; then the test result is recorded as the first test result.
[0020] Further, the analyzing and testing is performed according to the trusted module state of the static trusted verification function module and the result of the corresponding operation to obtain the second test result, including:
[0021] The trusted module status is turned on and off, and the specific operation of the trusted module status is matched with the log file corresponding to the trusted function to check whether a log is generated and its correctness. If no log is generated or the log content is incorrect, the cause needs to be located and investigated; then the test results are recorded as the second test results.
[0022] Furthermore, the obtaining of first test results and second test results corresponding to all configuration strategies and parameters according to the program includes:
[0023] Run the C program to analyze the randomness of the stability test, obtain the randomness of different configuration strategies and parameters, and obtain the corresponding first test results and second test results through different configuration strategies and parameters.
[0024] The second aspect of the present invention is to provide a stability testing device for the static trusted verification function of a trusted DCS controller, comprising a sensor, a DCS controller and a processor, wherein the sensor is responsible for collecting data, the DCS controller makes decisions based on the sensor data, and the processor implements a stability testing method for the static trusted verification function of the trusted DCS controller when executing a computer program based on the decision of the DCS controller.
[0025] The third aspect of the present invention is to provide an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements a stability testing method for a static trusted verification function of the trusted DCS controller when executing the computer program.
[0026] A fourth aspect of the present invention is to provide a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, a stability testing method for a static trusted verification function of the trusted DCS controller is implemented.
[0027] Compared with the prior art, the beneficial effects of the present invention are as follows: obtaining the program and configuration file required in the stability test process of the DCS controller under static conditions, performing automated testing through the program and configuration file, eliminating the traditional manual testing method, and the automated testing also improves the testing speed; obtaining the configuration mark status of the configuration file, performing stability testing according to the program, the configuration mark status of the configuration file, and the trusted module status of the static trusted verification function module and the results of the corresponding operations; and obtaining the first test result and the second test result; comprehensively testing the static trusted verification function on the DCS controller, effectively improving the overall test speed and quality, and significantly reducing the testing cost; obtaining the first test results and the second test results corresponding to all configuration strategies and parameters according to the program, writing all the first test results and the second test results and the corresponding configuration strategies and parameters into a specified file, and generating a test report; through the generated test report, problems occurring during long-term random numerical test can be discovered, and corresponding measures can be taken in time to reduce risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0029] Figure 1 A schematic flow chart of the steps of a stability testing method for a static trusted verification function of a trusted DCS controller is provided for the present invention;
[0030] Figure 2 A flow chart of a stability testing method for a static trusted verification function of a trusted DCS controller provided by the present invention. DETAILED DESCRIPTION
[0031] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0033] In view of the problems existing in the background technology, it is of great practical significance to study and design a stability testing method and equipment for the static trusted verification function of a trusted DCS controller.
[0034] like Figure 1 As shown, the first aspect of the present invention is to provide a stability testing method for a static trusted verification function of a trusted DCS controller, comprising the following steps:
[0035] Step S001: Determine the programs and configuration files required during the stability test of the DCS controller in static state.
[0036] It should be noted that since the DCS controller stability test is based on the static trusted verification function, a C program for testing the static trusted verification function and a C program for analyzing the randomness of the stability test are required; and the C program needs to read the content in the accessory file during execution. Among them, the C program is a C language program.
[0037] It should be further explained that the C program for testing the static trusted verification function is a set of programs for detecting whether the trusted verification function is trustworthy; and the C program for analyzing the randomness of the stability test is a set of programs for adjusting different strategies and parameters in the configuration file for analysis.
[0038] Step S002: configure different strategies and corresponding parameters in the configuration file.
[0039] It should be noted that when performing stability testing on the static trusted verification function of the DCS controller, it is first necessary to randomly determine a configuration strategy for the configuration file, and each configuration strategy corresponds to specific parameter values for each parameter; the stability test of the static trusted verification function is performed through the various parameter values under each configuration strategy in the configuration file, so as to determine the stability results corresponding to various parameters under each strategy.
[0040] The commands and specific parameters included in the process of configuring policies and parameters for the configuration file are:
[0041] Command to configure static trusted verification policy: atmv_mark;
[0042] The various parameters and their corresponding parameter values specifically include:
[0043] (1) -f parameter: specifies the file for configuring the static trusted verification policy;
[0044] The parameter values are: / home / test1, / home / test2, / home / test3, / home / test4, etc.
[0045] (2) -m parameter: specifies the trusted authentication method;
[0046] The parameter value is: hash;
[0047] (3) -j parameter: specifies the method of calculating file hash;
[0048] Parameter values include: 0 and 1;
[0049] (4) -t parameter: specifies the trusted verification trigger method;
[0050] Parameter values include: 1, 2, 3, 4, 5, 6, 7;
[0051] (5) -c parameter: specifies the control mode;
[0052] Parameter values include: 0, 1, 2;
[0053] (6) -l parameter: specifies the audit policy;
[0054] Parameter values include: 1, 2, 3, 4;
[0055] (7) -b parameter: specifies whether to back up files when setting the trusted verification policy;
[0056] Parameter values include: 0 and 1;
[0057] (8) -a parameter: specifies the hash algorithm used for trusted authentication;
[0058] Parameter values include: sm3, sha256;
[0059] The commands for changing the static trusted authentication policy include atmv_enable -t and atmv_disable -t -kqwer1234. sm3 and sha256 are both 256-bit output encryption hash algorithms.
[0060] Among them, the parameters include: f parameter, m parameter, j parameter, t parameter, c parameter, l parameter, b parameter, and a parameter. Adding - before the letter in front of the parameter is the command input format.
[0061] Step S003: Determine the configuration mark state of the configuration file, perform stability test according to the configuration mark state of the configuration file and the trusted module state of the static trusted verification function module and the result of the corresponding operation, and obtain a first test result and a second test result.
[0062] Run the C program for testing the static trusted verification function to start executing the specific business functions of testing the static trusted verification strategy; the specific business functions include the following operations:
[0063] (1) Determine the configuration flag status of the configuration file; specifically:
[0064] When policies and parameters are configured in the configuration file, the configuration mark state of the configuration file is recorded as the marked state Marked; when policies and parameters are not configured in the configuration file, the configuration mark state of the configuration file is recorded as the unmarked state Unmarked.
[0065] (2) Performing analysis and testing according to the configuration mark status of the configuration file and the operation result of the configuration file to obtain a first test result; specifically:
[0066] When the configuration file is in the marked state and the trusted state is trusted, the program will return the result of the file operation when the configuration file is viewed, written, executed, deleted, and renamed. The program will match the file operation with the corresponding log file to check whether a log is generated and its correctness. If no log is generated or the log content is incorrect, the cause needs to be located and investigated. Then the execution test is recorded and recorded as the first test result.
[0067] When the configuration file is in the unmarked state, the operations of viewing, writing, executing, deleting and renaming the configuration file can be performed normally, but no log is recorded; then the test result is recorded as the first test result;
[0068] It should be noted that when a configuration file is in a marked state, its trustworthy state must be trustworthy.
[0069] (3) Performing analysis and testing based on the trusted module status of the static trusted verification function module and the result of the corresponding operation to obtain a second test result; specifically:
[0070] Among them, the trusted module status includes two states, namely, open and closed;
[0071] The trusted module status is turned on and off, and the specific operation of the trusted module status is matched with the log file corresponding to the trusted function to check whether a log is generated and its correctness. If no log is generated or the log content is incorrect, the cause needs to be located and investigated; then the test results are recorded as the second test results.
[0072] The first test result and the second test result include the result of success or failure of each business program execution. That is, successful execution means that the generated log matches successfully; failed execution means that no log is generated or the log content is wrong.
[0073] Step S004: Write the first test result and the second test result and the corresponding configuration policies and parameters into a specified file, and generate a test report.
[0074] Run the C program to analyze the randomness of the stability test, obtain the randomness of different configuration strategies and parameters, obtain the corresponding first test results and second test results through different configuration strategies and parameters, write all configuration strategies and parameters and the corresponding first test results and second test results into the specified file, and generate a test report. The output test report format is html format.
[0075] Among them, all programs and configuration files are uploaded to the DCS controller.
[0076] The flow chart of the stability test method of the static trust verification function of the trusted DCS controller is as follows: Figure 2 shown.
[0077] The second aspect of the present invention is to provide a stability testing device for the static trusted verification function of a trusted DCS controller, including a sensor, a DCS controller and a processor, wherein the sensor is responsible for collecting data, the DCS controller makes decisions based on the sensor data, and the processor implements a stability testing method for the static trusted verification function of the trusted DCS controller when executing a computer program based on the decision of the DCS controller.
[0078] The third aspect of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and a stability testing method for implementing a static trusted verification function of a trusted DCS controller when the processor executes the computer program.
[0079] The stability test method of the static trusted verification function of the trusted DCS controller includes the following steps:
[0080] S1, determine the programs and configuration files required during the DCS controller stability test in static state;
[0081] S2, configure different strategies and corresponding parameters in the configuration file;
[0082] S3, determining the configuration mark state of the configuration file, performing stability testing according to the configuration mark state of the configuration file and the trusted module state of the static trusted verification function module and the result of the corresponding operation, and obtaining a first test result and a second test result;
[0083] S4, writing the first test result and the second test result and the corresponding configuration policies and parameters into a specified file, and generating a test report.
[0084] A fourth aspect of the present invention is to provide a computer-readable storage medium storing a computer program, which implements a stability testing method for a static trusted verification function of a trusted DCS controller when the computer program is executed by a processor.
[0085] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) containing computer-usable program code.
[0086] The present invention is described with reference to flowcharts and / or block diagrams of methods, systems, and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process in the flowchart. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0087] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0088] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the present invention.
Claims
1. A stability test method for the static trusted verification function of a trusted DCS controller, characterized in that: include: Obtain the programs and configuration files required for the DCS controller stability test in static state; The programs required in the stability test process include: a C program for testing static trusted verification functions and a C program for analyzing the randomness of stability tests; Obtaining a configuration mark state of a configuration file, wherein when policies and parameters are configured in the configuration file, the configuration mark state of the configuration file is recorded as a marked state Marked; when policies and parameters are not configured in the configuration file, the configuration mark state of the configuration file is recorded as an unmarked state Unmarked; performing stability testing according to the configuration mark state of the program and configuration file and the trusted module state of the static trusted verification function module and the results of corresponding operations; and obtaining a first test result and a second test result; By testing the C program of the static trusted verification function, an analysis test is performed according to the configuration mark state of the configuration file and the operation result of the configuration file to obtain a first test result; When the configuration file is in the marked state and the trusted state is trusted, the program will return the result of the file operation when the configuration file is viewed, written, executed, deleted, and renamed. The program will match the file operation with the corresponding log file to check whether a log is generated and its correctness. If no log is generated or the log content is incorrect, the cause needs to be located and investigated. Then the execution test is recorded and recorded as the first test result. When the configuration file is in the unmarked state, the operations of viewing, writing, executing, deleting and renaming the configuration file can be performed normally, but no log is recorded; then the test result is recorded as the first test result; By testing the C program of the static trusted verification function, analyzing and testing according to the trusted module state of the static trusted verification function module and the result of the corresponding operation, a second test result is obtained; wherein the trusted module state of the static trusted verification function module includes two states: open and closed; The trusted module status is turned on and off, and the specific operation of the trusted module status is matched with the log file corresponding to the trusted function to check whether a log is generated and its correctness. If no log is generated or the log content is wrong, the cause needs to be located and investigated; then the test result is recorded as the second test result; Obtain all configuration policies and first test results and second test results corresponding to parameters according to the program, write all first test results and second test results and corresponding configuration policies and parameters into a specified file, and generate a test report.
2. The stability testing method of the static trusted verification function of the trusted DCS controller according to claim 1 is characterized in that: The step of obtaining the first test results and the second test results corresponding to all configuration strategies and parameters according to the program includes: Run the C program to analyze the randomness of the stability test, obtain the randomness of different configuration strategies and parameters, and obtain the corresponding first test results and second test results through different configuration strategies and parameters.
3. The stability test equipment of the static trusted verification function of the trusted DCS controller is characterized by: The invention comprises a sensor, a DCS controller and a processor, wherein the sensor is responsible for collecting data, the DCS controller makes decisions according to the sensor data, and the processor implements the stability testing method of the static trusted verification function of the trusted DCS controller according to any one of claims 1-2 when executing a computer program according to the decision of the DCS controller.
4. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the stability testing method of the static trusted verification function of the trusted DCS controller according to any one of claims 1 to 2 when executing the computer program.
5. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the stability testing method of the static trusted verification function of the trusted DCS controller according to any one of claims 1 to 2 is implemented.
Citation Information
Patent Citations
Trusted monitoring method, device and system for applications and storage medium
CN111949977A
Trusted distributed control system upper computer configuration reading method and system
CN117055823A