Dynamic trustworthy verification function test method and related device for trusted DCS controller
By establishing a network connection between the test terminal and the trusted DCS controller, using Python test programs and policy configuration instructions, dynamic trusted verification policy marking is performed on process files, processes and applications, and tampering is simulated to query the trusted status. This solves the problems of slow testing speed and low efficiency in the existing technology, and realizes efficient and comprehensive dynamic trusted verification function testing.
Patent Information
- Application Number
- CN202510145500.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-02-10
AI Technical Summary
The existing trusted DCS controller dynamic trust verification function test speed is slow, the test efficiency is low, and it is unable to effectively test the stability of the function.
A method for testing the dynamic trust verification function of a trusted DCS controller is provided. A network connection is established between the test terminal and the controller to be tested. The Python test program and policy configuration instructions are used to dynamically mark the process files, processes, applications and object files with trust verification policies. The trusted status is queried after tampering is simulated and the test results are output.
The stability test of the dynamic trust verification function of the trusted DCS controller in the face of malicious tampering is realized, which improves the test efficiency, reduces the error of manual intervention, ensures the comprehensiveness and accuracy of the test, and reduces the test cost.
Smart Images

Figure CN119718960B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of functional testing, and in particular relates to a dynamic trusted verification function testing method for a trusted DCS controller and a related device. Background Art
[0002] A distributed control system (DCS) is a new type of control device that uses computer technology to centrally monitor, operate, manage, and decentralized control industrial production processes. A trusted DCS is based on a traditional DCS and improves system security by introducing a trusted computing architecture.
[0003] At present, the controllers of domestic trusted DCS systems are all integrated with dynamic trusted verification functions, that is, all system programs need to undergo dynamic trusted verification regularly to prevent tampering by malicious software; specifically, by turning on the dynamic trusted verification function module, dynamic periodic measurement is performed on the process marked with the dynamic trusted verification periodic measurement strategy to monitor whether the periodic measurement process is trustworthy; when the periodic measurement process is tampered with, the process status will become untrustworthy, thereby triggering a system alarm; secondly, by turning on the dynamic trusted verification function module, dynamic periodic measurement is performed on the application program and object file marked with the dynamic trusted verification subject and object strategy to monitor whether the dynamic monitoring subject and object are trustworthy; when the subject and object process is tampered with, the process status will become untrustworthy, thereby triggering a system alarm.
[0004] In actual projects, the dynamic trusted verification function of the trusted DCS controller needs to be tested after deployment. Since the controllers in domestic trusted DCS systems generally use the Yihui SylixOS operating system, and the configuration procedures of each controller are different in different application scenarios, it is impossible to perform automatic testing locally through mainstream scripts such as shell. Manual testing is slow, inefficient, and cannot test the stability of the function. Summary of the Invention
[0005] In response to the technical problems existing in the prior art, the present invention provides a dynamic trusted verification function testing method and related devices for a trusted DCS controller to solve the technical problems of the existing dynamic trusted verification function testing process of a trusted DCS controller, which are slow, low in test efficiency and unable to test the stability of the function.
[0006] In order to achieve the above object, the technical solution adopted by the present invention is:
[0007] The present invention provides a method for testing a dynamic trustworthy verification function of a trusted DCS controller, which is applied to a test terminal, wherein a network connection is established between the test terminal and the controller to be tested;
[0008] The method for testing the dynamic trustworthy verification function of a trusted DCS controller includes:
[0009] Performing file dynamic trust verification periodic measurement strategy marking on a predetermined process file in the controller to be tested, and obtaining a process file of the marking verification strategy; wherein the controller to be tested responds to the process file of the marking verification strategy and generates an execution process;
[0010] Tampering with the execution process and querying the trust status of the execution process;
[0011] Performing process dynamic trust verification periodic measurement strategy marking on a predetermined process in the controller to be tested, and obtaining a process of the marking verification strategy;
[0012] Tampering with the process of the tag verification policy and querying the trust status of the process of the tag verification policy;
[0013] Performing dynamic trustworthy verification of subject-object policy tags on predetermined applications and object files in the controller under test to obtain a dynamic subject-object policy file; wherein the controller under test responds to the dynamic subject-object policy file and generates a preset policy point execution process;
[0014] Tampering with the execution process of the preset policy point and querying the trust status of the execution process of the preset policy point;
[0015] Output the query results of the trusted state of the execution process, the trusted state of the process of the mark verification strategy, and the trusted state of the execution process of the preset strategy point to obtain the dynamic trusted verification function test result of the controller to be tested.
[0016] Furthermore, the test terminal pre-stores a preset Python test program and a test program configuration file; wherein, the preset Python test program is used to implement the steps of the dynamic trusted verification function test method of the trusted DCS controller, and the preset Python test program is connected to the controller to be tested via Telnet.
[0017] Furthermore, the test program configuration file includes the identity information of the controller to be tested, the test file directory on the controller to be tested, and the threshold number of network connections with the controller to be tested; wherein, the test file directory on the controller to be tested is a directory of predetermined process files, predetermined processes, and predetermined applications and object files in the controller to be tested.
[0018] Furthermore, the process of marking the predetermined process file in the controller to be tested with a dynamic trustworthy verification periodic measurement strategy and obtaining the process file of the marking verification strategy is specifically as follows:
[0019] The policy configuration instruction provided by the dynamic trust verification function in the controller to be tested is called, and the predetermined file dynamic trust verification periodic measurement policy is configured in the predetermined process file to obtain the process file of the marking verification policy.
[0020] Furthermore, the process of performing dynamic trustworthy verification periodic measurement strategy marking on the predetermined process in the controller to be tested and obtaining the process of the marking verification strategy is specifically as follows:
[0021] The policy configuration instruction provided by the dynamic trust verification function in the controller to be tested is called, and the predetermined process dynamic trust verification periodic measurement policy is configured in the predetermined process to obtain a process of the marking verification policy.
[0022] Furthermore, the process of performing dynamic trustworthy verification of the subject-object policy tag on the predetermined application and object files in the controller to be tested and obtaining the dynamic subject-object policy file is as follows:
[0023] The policy configuration instruction provided by the dynamic trust verification function in the controller to be tested is called, and the predetermined dynamic trust verification periodic measurement policy is configured in the predetermined application program and object file to obtain a dynamic subject-object policy file.
[0024] Furthermore, when tampering with the execution process or the process of the tag verification policy, tampering is performed on the preset data segment of the execution process or the process of the tag verification policy; wherein, the preset data segment is a code segment or a read-only data segment of the execution process or the process of the tag verification policy.
[0025] The present invention also provides a dynamic trustworthy verification function test system for a trusted DCS controller, which is applied to a test terminal, wherein a network connection is established between the test terminal and the controller to be tested;
[0026] The trusted DCS controller dynamic trusted verification function test system includes:
[0027] A file strategy marking module is used to perform a file dynamic trust verification periodic measurement strategy marking on a predetermined process file in the controller under test, and obtain a process file of the marking verification strategy; wherein, the controller under test responds to the process file of the marking verification strategy and generates an execution process;
[0028] a first tampering query module, configured to tamper with the execution process and query the trustworthy status of the execution process;
[0029] The process strategy marking module is used to perform process dynamic trust verification periodic measurement strategy marking on the predetermined process in the controller to be tested, and obtain the process of the marking verification strategy;
[0030] a second tampering query module, configured to tamper with the process of the tag verification policy and query the trust status of the process of the tag verification policy;
[0031] A subject-object policy marking module is used to perform dynamic trustworthy verification of the subject-object policy marking of predetermined application programs and object files in the controller under test, and obtain a dynamic subject-object policy file; wherein the controller under test responds to the dynamic subject-object policy file and generates a preset policy point execution process;
[0032] a third tampering query module, configured to tamper with the execution process of the preset policy point and query the trustworthy status of the execution process of the preset policy point;
[0033] The result output module is used to output the query results of the trusted state of the execution process, the trusted state of the process of the mark verification strategy and the trusted state of the execution process of the preset strategy point, and obtain the dynamic trusted verification function test result of the controller to be tested.
[0034] The present invention also provides a trusted DCS controller dynamic trusted verification function test device, comprising:
[0035] a processor suitable for executing a computer program;
[0036] A computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the method for testing the dynamic trusted verification function of the trusted DCS controller is executed.
[0037] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for testing the dynamic trusted verification function of a trusted DCS controller is implemented.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] The present invention provides a method for testing the dynamic trusted verification function of a trusted DCS controller. The method performs file dynamic trusted verification periodic measurement policy marking on the execution process corresponding to a predetermined process file, performs process dynamic trusted verification periodic measurement policy marking on the predetermined process, and performs dynamic trusted verification subject-object policy marking on the predetermined application. By querying the trusted status of the process after the process is tampered with, it is possible to verify whether the dynamic trusted verification function of the trusted DCS controller is stable and effective when facing malicious tampering. Secondly, through the network connection between the test terminal and the controller to be tested, the automatic sending of test instructions and the automatic collection of test results are realized, which greatly improves the test efficiency and reduces the errors and delays that may be caused by manual intervention. In addition, the test process can cover different types of execution units in the controller, ensuring the comprehensiveness of the test. The present invention can simulate potential security threats in actual operation, discover problems with the dynamic trusted verification function earlier, effectively improve the test speed and test quality, and at the same time meet the requirements for testing the stability of the dynamic trusted verification function, significantly reducing the test cost.
[0040] The trusted DCS controller dynamic trusted verification function test system, trusted DCS controller dynamic trusted verification function test device, computer-readable storage medium and computer program product provided by the present invention have all the advantages of the trusted DCS controller dynamic trusted verification function test method described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0042] Figure 1 Flowchart of the method for testing the dynamic trustworthy verification function of a trusted DCS controller provided by the present invention;
[0043] Figure 2 A structural block diagram of the dynamic trustworthy verification function test system for a trusted DCS controller provided by the present invention;
[0044] Figure 3 This is a structural block diagram of the dynamic trustworthy verification function testing equipment for a trusted DCS controller provided by the present invention. DETAILED DESCRIPTION
[0045] In order to make the technical problems, technical solutions, and beneficial effects solved by this application more clearly understood, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application; it is obvious that the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of this application.
[0046] This embodiment 1 provides a method for testing the dynamic trustworthy verification function of a trusted DCS controller, which is applied to a test terminal; a preset Python test program and a test program configuration file are pre-stored on the test terminal; wherein the preset Python test program is used to implement the steps of the method for testing the dynamic trustworthy verification function of a trusted DCS controller, and the test program configuration file includes the identity information of the controller to be tested, a test file directory on the controller to be tested, and a threshold value for the number of network connections established with the controller to be tested; specifically, the identity information of the controller to be tested includes the IP address, user name, and password of the controller to be tested, and the test file directory on the controller to be tested is a directory of predetermined process files, predetermined processes, and predetermined applications and object files in the controller to be tested.
[0047] As attached Figure 1 As shown, the trusted DCS controller dynamic trust verification function testing method includes the following steps:
[0048] Step 1: Use Telnet to attempt to establish a network connection between a pre-set Python test program stored on the test terminal and the controller under test. The test terminal and the controller under test are in the same network environment. It should be noted that the pre-set Python test program is a program launched in an execution environment based on a Python script, and the execution environment is an environment launched based on the test program configuration file.
[0049] Step 2: Determine whether the network connection between the preset Python test program and the controller under test is successful. If the network connection is successful, jump to step 3; if the network connection fails, output a network connection failure prompt and the reason for the network connection failure, and attempt to reconnect. If the number of times the network connection is reestablished exceeds the threshold number of network connections with the controller under test, and the network connection result is still not recognized, the preset Python test program exits, and the method ends.
[0050] Step 3: According to the test state requirement of the dynamic trustworthy verification function of the controller under test, the dynamic trustworthy verification function of the controller under test is turned on or off, so that the dynamic trustworthy verification function of the controller under test is in the on state or the off state.
[0051] Step 4: Mark the predetermined process file in the controller under test with the file dynamic trustworthy verification periodic measurement policy to obtain the file marked with the verification policy. Specifically, the process of marking the predetermined process file in the controller under test with the file dynamic trustworthy verification periodic measurement policy and obtaining the file marked with the verification policy comprises: calling the policy configuration instruction provided by the dynamic trustworthy verification function in the controller under test, configuring the predetermined file dynamic trustworthy verification periodic measurement policy in the predetermined process file, and obtaining the process file marked with the verification policy; wherein, the file dynamic trustworthy verification periodic measurement policy is used to trigger the dynamic trustworthy verification function of the controller under test to perform periodic measurement verification on the predetermined process during the execution of the file.
[0052] Step 5: Trigger the controller under test to run the file of the tag verification strategy and generate an execution process.
[0053] Step 6: Invoke the trusted status query command provided by the dynamic trusted verification function in the controller under test to query the trusted status of the execution process and obtain the correctness judgment result of the file dynamic trusted verification periodic measurement policy. It should be noted that when a predetermined process file is marked with the file dynamic trusted verification periodic measurement policy, when the file marked with the verification policy is run, the trusted status of the corresponding execution process is defaulted to trusted; by querying the trusted status of the execution process and based on the query result of the trusted status of the execution process, it can be determined whether the file dynamic trusted verification periodic measurement policy is correct.
[0054] Step 7: Tamper with the execution process to change its trusted state to untrusted. Specifically, the trusted state of the execution process is changed to untrusted by tampering with a preset data segment of the execution process. The preset data segment of the execution process includes a code segment or a read-only data segment of the execution process. The code segment of the execution process is used to store predetermined operating instructions of the process file. The read-only data segment of the execution process is used to store initialized global variables in the predetermined process file.
[0055] Step 8: Query the trusted status of the execution process. Specifically, call the trusted status query command provided by the dynamic trusted verification function of the controller under test to query the trusted status of the tampered execution process to check whether the process has been terminated or whether an alarm prompt is returned, and obtain the query result of the trusted status of the execution process. When the trusted status of the tampered execution process is untrustworthy, the dynamic trusted verification function of the controller under test will terminate the execution process or issue an alarm prompt.
[0056] Step 9: Mark a predetermined process in the controller under test with the process dynamic trust verification periodic measurement policy to obtain a process with the marked verification policy. Specifically, the policy configuration instructions provided by the dynamic trust verification function in the controller under test are called, and the predetermined process dynamic trust verification periodic policy is configured in the predetermined process to obtain a process with the marked verification policy.
[0057] Step 10: Invoke the trusted status query command provided by the dynamic trusted verification function in the controller under test to query the trusted status of the process marked with the verification policy, and obtain the correctness judgment result of the dynamic trusted verification periodic measurement policy of the process. It should be noted that when a predetermined process is marked with the dynamic trusted verification periodic measurement policy, the trusted status of the corresponding process is defaulted to trusted; by querying the trusted status of the process and based on the process trusted status query result, it is possible to determine whether the dynamic trusted verification periodic measurement policy of the process is correct.
[0058] Step 11: Tamper with the process of the tag verification policy to change the trust status of the process of the tag verification policy to untrusted. Specifically, the preset data segment of the process of the tag verification policy is tampered with to change the trust status of the process of the tag verification policy to untrusted. The preset data segment of the process of the tag verification policy includes a code segment or a read-only data segment of the process of the tag verification policy. It should be noted that the operation of tampering with the preset data segment of the process of the tag verification policy is basically the same as the tampering operation in step 7 above, and will not be repeated here.
[0059] Step 12: Query the trusted status of the process of the tag verification policy. Specifically, call the trusted status query command provided by the dynamic trusted verification function of the controller under test to query the trusted status of the process of the tampered tag verification policy to check whether the process has been terminated or whether an alarm prompt is returned, and obtain the trusted status query result of the process of the tag verification policy. It should be noted that when the trusted status of the process of the tampered tag verification policy is untrustworthy, the dynamic trusted verification function of the controller under test will terminate the process or issue an alarm prompt.
[0060] Step 13: Dynamically authenticate the application and object files in the controller under test using the subject-object policy tag to obtain a dynamic subject-object policy file. Specifically, the policy configuration instructions provided by the dynamic authentication function in the controller under test are invoked, and the predetermined dynamic authentication periodic measurement policy is configured in the predetermined application and object files to obtain the dynamic subject-object policy file.
[0061] Step 14: triggering a predetermined execution strategy point in the controller to be tested to run the dynamic subject-object strategy file and generate a preset strategy point execution process.
[0062] Step 15: Invoke the trusted status query command provided by the dynamic trusted verification function in the controller under test to query the trusted status of the process executing at the preset policy point, and obtain a result of determining the correctness of the dynamic trusted verification subject-object policy. It should be noted that when predetermined application programs and object files are marked with the dynamic trusted verification subject-object policy, the trusted status of the corresponding process is defaulted to trusted when the dynamic subject-object policy file is executed. By querying the trusted status of the process executing at the preset policy point and based on the query result of the trusted status of the process executing at the preset policy point, it is possible to determine whether the dynamic trusted verification subject-object policy is correct.
[0063] Step 16: Tamper with the preset policy point execution process to make the trusted state of the preset policy point execution process untrustworthy. Specifically, the trusted state of the preset policy point execution process is made untrustworthy by tampering with a preset data segment of the preset policy point execution process; wherein the preset data segment of the preset policy point execution process includes a code segment or a read-only data segment of the preset policy point execution process.
[0064] Step 17: Query the trusted status of the preset policy point execution process. Specifically, call the trusted status query command provided by the dynamic trusted verification function of the controller under test to query the trusted status of the preset policy point execution process after tampering to check whether the process has been terminated or whether an alarm prompt is returned, and obtain the query result of the trusted status of the preset policy point execution process. When the trusted status of the preset policy point execution process after tampering is untrustworthy, the dynamic trusted verification function of the controller under test will terminate the preset policy point execution process or issue an alarm prompt.
[0065] Step 18: Output the correctness judgment result of the file dynamic trust verification periodic measurement strategy, the query result of the trusted status of the execution process, the correctness judgment result of the process dynamic trust verification periodic measurement strategy, the query result of the trusted status of the process of the mark verification strategy, the correctness judgment result of the dynamic trust verification subject and object strategy, and the query result of the trusted status of the execution process of the preset strategy point to obtain the dynamic trust verification function test result of the controller to be tested.
[0066] Specifically, the output process of the test results is as follows:
[0067] Return the correctness judgment result of the file dynamic trustworthy verification periodic measurement strategy, the query result of the trusted status of the execution process, the correctness judgment result of the process dynamic trustworthy verification periodic measurement strategy, the query result of the trusted status of the process of the marking verification strategy, the correctness judgment result of the dynamic trustworthy verification subject and object strategy, and the query result of the trusted status of the execution process of the preset strategy point, and save them to the test log file, and output the test log file in HTML format to obtain the dynamic trustworthy verification function test result of the controller to be tested.
[0068] It should be noted that the test results of the dynamic trusted verification function of the controller to be tested include test pass or test fail; among them, when the test fails, the information returned at the time of failure will be recorded with the log record to facilitate the investigation of the cause of the failure and locate the problem; in the case of failure of the previous test, the functional modules that failed to pass the verification during the test and the functional modules that passed the verification will be distinguished; and in the next test process, only the functional modules that failed to pass the verification will be tested, and the functional modules that passed the verification last time will not be tested, thereby shortening the overall test time.
[0069] Example description:
[0070] The process of performing dynamic file trustworthiness verification and periodic measurement strategy marking on a predetermined process file in the controller to be tested is as follows:
[0071] To mark the periodic measurement policy for dynamic trust verification of a process file, use the dtmv_mark -f file -b -kabcd command. The -f parameter specifies the process file for which the periodic dynamic trust verification policy is configured. The -b parameter starts dynamic trust verification of a running process immediately without restarting it. The -k parameter specifies the password for executing this operation.
[0072] To mark the process PID dynamic trust verification periodic measurement policy, use the dtmv_mark -p 1234 -P 10 -c1 -l 1 -k abcd command. The -p parameter specifies the process PID, which means configuring a periodic trust verification policy based on the process PID for the process. The -P parameter specifies the time period (in seconds) for periodic dynamic trust verification of the process. The -c parameter sets the control policy to be adopted when the process is verified as untrustworthy. The -l parameter specifies the audit policy, which determines the content of the log record when an object is verified as untrustworthy.
[0073] To delete the periodic measurement policy for dynamic trust verification of process files, use the dtmv_unmark -f file -d 1 -k abcd command. The -d parameter specifies whether to clear the dynamic trust verification policy for the corresponding process or file when setting a policy for deleting process files or process PIDs. To delete the periodic measurement policy for dynamic trust verification of process PIDs, use the dtmv_unmark -p 1234 -k abcd command.
[0074] The process of dynamic trust verification and subject-object policy marking of pre-determined application and object files in the controller under test is as follows:
[0075] Mark the subject and object policies for dynamic trusted verification. For example, to configure the subject process subjA to perform dynamic trusted verification when opening the object file objB, use the command dtmv_mark -s subjA -o objB -a file_open -k abcd. The parameter -s is used to specify the subject process file name; the parameter -o is used to specify the name of the object accessed by the subject process; and the parameter -a is used to specify the execution control point name. To delete all execution control point policies of subject subjA for object objB, use the command dtmv_unmark -s subjA -o objB -k abcd. To delete the access policy of subject subjA for all objects, use the command dtmv_unmark -s subjA -c -k abcd.
[0076] Configure an execution control point for a process undergoing dynamic trust verification. This triggers trust verification for the process when the execution reaches this control point. Use the dtmv_config -a file_open -s 5 -k abcd command. The -a parameter specifies the name of the execution control point. Currently, four execution control points are supported: file opening (file_open), file renaming (inode_rename), file deletion (inode_unlink), and directory deletion (inode_rmdir). The -s parameter specifies the control measures to be taken for the process if the process is untrustworthy.
[0077] The method for testing the dynamic trust verification function of a trusted DCS controller described in Example 1 performs policy marking on process files, processes, and applications, then tampering with the execution process and querying its trust status to verify whether the dynamic trust verification function of the controller is stable and effective when facing malicious tampering. This method can simulate potential security threats in actual operation, improve the authenticity and reliability of the test, and automatically send test instructions and automatically collect test results through the network connection between the test terminal and the controller to be tested, greatly improving test efficiency and reducing errors and delays that may be caused by manual intervention.
[0078] Example 2
[0079] As attached Figure 2 As shown, this embodiment 2 provides a trusted DCS controller dynamic trust verification function test system, including: a network connection module, a function status setting module, a file policy marking module, a first policy judgment module, a first tampering query module, a process policy marking module, a second policy judgment module, a second tampering query module, a subject-object policy marking module, a third policy judgment module, a third tampering query module and a result output module.
[0080] A network connection module is used to attempt to establish a network connection between the preset Python test program pre-stored on the test terminal and the controller to be tested through Telnet; determine whether the network connection between the preset Python test program and the controller to be tested is successful; a function status setting module is used to turn on or off the dynamic trusted verification function of the controller to be tested according to the dynamic trusted verification function test status requirements of the controller to be tested, so that the dynamic trusted verification function of the controller to be tested is in the on state or the off state; a file strategy marking module is used to mark the process file predetermined in the controller to be tested with a file dynamic trusted verification periodic measurement strategy and obtain a file with a marked verification strategy; trigger the controller to be tested to run the file with the marked verification strategy and generate an execution process; a first strategy judgment module is used to call the trusted status query command provided by the dynamic trusted verification function in the controller to be tested, query the trusted status of the execution process, and obtain the correctness judgment result of the file dynamic trusted verification periodic measurement strategy; a first tampering query module is used to tamper with the execution process to make the trusted status of the execution process untrustworthy; query the trusted status of the execution process; a process strategy marking module is used to mark the process dynamic trusted verification of the process predetermined in the controller to be tested. Verify the periodic measurement strategy mark and obtain the process of the mark verification strategy; the second strategy judgment module is used to call the trusted status query command provided by the dynamic trusted verification function in the controller to be tested, query the trusted status of the process of the mark verification strategy, and obtain the correctness judgment result of the process dynamic trusted verification periodic measurement strategy; the second tampering query module is used to tamper with the process of the mark verification strategy to make the trusted status of the process of the mark verification strategy untrustworthy; query the trusted status of the process of the mark verification strategy; the subject-object strategy marking module is used to dynamically tamper with the predetermined application and object files in the controller to be tested. Trusted verification subject and object policy tag, obtain dynamic subject and object policy file; trigger predetermined execution policy point in the controller to be tested to run the dynamic subject and object policy file, generate preset policy point execution process; third policy judgment module, used to call the trusted status query command provided by the dynamic trusted verification function in the controller to be tested, query the trusted status of the preset policy point execution process, and obtain the correctness judgment result of the dynamic trusted verification subject and object policy; third tampering query module, used to tamper with the preset policy point execution process to make the trusted status of the preset policy point execution process untrustworthy; query the trusted status of the preset policy point execution process;The result output module is used to output the correctness judgment results of the file dynamic trust verification periodic measurement strategy, the query results of the trusted status of the execution process, the correctness judgment results of the process dynamic trust verification periodic measurement strategy, the query results of the trusted status of the process of the tag verification strategy, the correctness judgment results of the dynamic trust verification subject and object strategy, and the query results of the trusted status of the execution process at the preset strategy point, thereby obtaining the dynamic trust verification function test results of the controller under test.
[0081] Example 3
[0082] As attached Figure 3 As shown, this embodiment 3 provides a trusted DCS controller dynamic trusted verification function test device, including: a memory for storing a computer program; a processor for implementing the steps of the trusted DCS controller dynamic trusted verification function test method when executing the computer program; or, when the processor executes the computer program, implementing the functions of each module in the above-mentioned trusted DCS controller dynamic trusted verification function test system.
[0083] The steps of the method for testing the dynamic trustworthy verification function of the trusted DCS controller include, for example:
[0084] Through Telnet, try to establish a network connection between the preset Python test program pre-stored on the test terminal and the controller to be tested; determine whether the network connection between the preset Python test program and the controller to be tested is successful; according to the dynamic trustworthy verification function test status requirements of the controller to be tested, turn on or off the dynamic trustworthy verification function of the controller to be tested, so that the dynamic trustworthy verification function of the controller to be tested is in the on state or the off state; perform file dynamic trustworthy verification periodic measurement strategy marking on the process file predetermined in the controller to be tested, and obtain the file of the marking verification strategy; trigger the controller to be tested to run the marking verification function The method comprises the following steps: first, performing a trusted state query command provided by the dynamic trusted verification function in the controller to be tested, querying the trusted state of the execution process, and obtaining the correctness judgment result of the dynamic trusted verification periodic measurement strategy of the file; tampering with the execution process to make the trusted state of the execution process untrustworthy; querying the trusted state of the execution process; marking the process predetermined in the controller to be tested with the process dynamic trusted verification periodic measurement strategy, and obtaining the process of the marked verification strategy; calling the trusted state query command provided by the dynamic trusted verification function in the controller to be tested, and querying the trusted state of the process of the marked verification strategy, Obtain the correctness judgment result of the process dynamic trustworthy verification periodic measurement strategy; tamper with the process of the tag verification strategy to make the trustworthy state of the process of the tag verification strategy untrustworthy; query the trustworthy state of the process of the tag verification strategy; perform dynamic trustworthy verification of the subject-object strategy tag on the predetermined application and object files in the controller to be tested, and obtain the dynamic subject-object strategy file; trigger the predetermined execution strategy point in the controller to be tested to run the dynamic subject-object strategy file, and generate the preset strategy point execution process; call the trustworthy state query command provided by the dynamic trustworthy verification function in the controller to be tested, and perform the trustworthy state of the preset strategy point execution process. Perform a query to obtain the correctness judgment result of the dynamic trusted verification subject and object strategy; tamper with the preset strategy point execution process to make the trusted state of the preset strategy point execution process untrustworthy; query the trusted state of the preset strategy point execution process; output the correctness judgment result of the file dynamic trusted verification periodic measurement strategy, the query result of the execution process, the correctness judgment result of the process dynamic trusted verification periodic measurement strategy, the trusted state query result of the mark verification strategy process, the correctness judgment result of the dynamic trusted verification subject and object strategy and the query result of the trusted state of the preset strategy point execution process to obtain the dynamic trusted verification function test result of the controller to be tested.
[0085] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing preset functions, and the instruction segments are used to describe the execution process of the computer program in the trusted DCS controller dynamic trusted verification function test device.
[0086] The trusted DCS controller dynamic trust verification function test device can be a computing device such as a desktop computer, a notebook, a PDA, and a cloud server. The trusted DCS controller dynamic trust verification function test device may include, but is not limited to, a processor and a memory. Those skilled in the art will understand that the above is an example of a trusted DCS controller dynamic trust verification function test device and does not constitute a limitation on the trusted DCS controller dynamic trust verification function test device. It may include more components than the above, or a combination of certain components, or different components. For example, the trusted DCS controller dynamic trust verification function test device may also include input and output devices, network access devices, buses, etc.
[0087] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor. The processor serves as the control center of the trusted DCS controller dynamic trusted verification function test equipment, connecting various parts of the entire trusted DCS controller dynamic trusted verification function test equipment using various interfaces and lines.
[0088] The memory can be used to store the computer program and / or module, and the processor implements various functions of the trusted DCS controller dynamic trusted verification function test device by running or executing the computer program and / or module stored in the memory and calling the data stored in the memory.
[0089] The memory may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as sound playback or image playback); the data storage area may store data generated based on the use of the mobile phone (such as audio data and a phone book). Furthermore, the memory may include high-speed random access memory (RAM) and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0090] Example 4
[0091] This embodiment 4 further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the method for testing the dynamic trustworthy verification function of a trusted DCS controller are implemented.
[0092] If the modules / units integrated in the trusted DCS controller dynamic trusted verification function test system are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0093] Based on this understanding, the present invention implements all or part of the process of the above-mentioned trusted DCS controller dynamic trust verification function testing method, and can also be completed by using a computer program to instruct related hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned trusted DCS controller dynamic trust verification function testing method. The computer program includes computer program code, which can be in source code form, object code form, executable file, or preset intermediate form.
[0094] The computer-readable storage medium may include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc.
[0095] It should be noted that the content contained in the computer-readable storage medium can be appropriately increased or decreased according to the requirements of legislation and patent practices in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practices, computer-readable storage media do not include electrical carrier signals and telecommunication signals.
[0096] The method for testing the dynamic trusted verification function of a trusted DCS controller of the present invention performs file dynamic trusted verification periodic measurement policy marking on predetermined process files, performs process dynamic trusted verification periodic measurement policy marking on predetermined processes, and performs dynamic trusted verification subject-object policy marking on predetermined application and object files. After marking the process files, processes, and applications, the method tamperes with these execution units and queries their trusted status to achieve a comprehensive test of the dynamic trusted verification function of the trusted DCS controller. The method has the advantages of high testing efficiency and automation, as well as intuitive and analyzable test results.
[0097] The above embodiment is only one of the implementation methods that can realize the technical solution of the present invention. The scope of protection claimed by the present invention is not limited only to this embodiment, but also includes changes, replacements and other implementation methods that can be easily thought of by any technician familiar with this technical field within the technical scope disclosed by the present invention.
Claims
1. A method for testing the dynamic trustworthiness verification function of a trusted DCS controller, characterized in that: Applied to a test terminal, a network connection is established between the test terminal and the controller to be tested; The method for testing the dynamic trustworthy verification function of a trusted DCS controller includes: Performing file dynamic trust verification periodic measurement strategy marking on a predetermined process file in the controller to be tested, and obtaining a process file of the marking verification strategy; wherein the controller to be tested responds to the process file of the marking verification strategy and generates an execution process; Tampering with the execution process and querying the trust status of the execution process; Performing process dynamic trust verification periodic measurement strategy marking on a predetermined process in the controller to be tested, and obtaining a process of the marking verification strategy; Tampering with the process of the tag verification policy and querying the trust status of the process of the tag verification policy; Performing dynamic trustworthy verification of subject-object policy tags on predetermined applications and object files in the controller under test to obtain a dynamic subject-object policy file; wherein the controller under test responds to the dynamic subject-object policy file and generates a preset policy point execution process; Tampering with the execution process of the preset policy point and querying the trust status of the execution process of the preset policy point; Output the query results of the trusted state of the execution process, the trusted state of the process of the mark verification strategy, and the trusted state of the execution process of the preset strategy point, and obtain the dynamic trusted verification function test result of the controller to be tested; When tampering with the execution process, the process of the mark verification policy or the execution process of the preset policy point, the code segment or read-only data segment of the execution process, the process of the mark verification policy or the execution process of the preset policy point is used to tamper with it.
2. A method for testing dynamic trustworthy verification function of a trusted DCS controller according to claim 1, characterized in that: The test terminal pre-stores a preset Python test program and a test program configuration file; wherein, the preset Python test program is used to implement the steps of the trusted DCS controller dynamic trusted verification function test method, and the preset Python test program is connected to the controller to be tested via Telnet.
3. A method for testing dynamic trustworthy verification function of a trusted DCS controller according to claim 2, characterized in that: The test program configuration file includes the identity information of the controller to be tested, the test file directory on the controller to be tested, and the threshold number of network connections with the controller to be tested; wherein the test file directory on the controller to be tested is a directory of predetermined process files, predetermined processes, and predetermined applications and object files in the controller to be tested.
4. A method for testing dynamic trustworthy verification function of a trusted DCS controller according to claim 1, characterized in that: The process of marking a predetermined process file in the controller under test with a dynamic trustworthy verification periodic measurement strategy and obtaining the process file of the marking verification strategy is as follows: The policy configuration instruction provided by the dynamic trust verification function in the controller to be tested is called, and the predetermined file dynamic trust verification periodic measurement policy is configured in the predetermined process file to obtain the process file of the marking verification policy.
5. A method for testing dynamic trustworthy verification function of a trusted DCS controller according to claim 1, characterized in that: The process of marking a predetermined process in the controller under test with a dynamic trustworthy verification periodic measurement strategy and obtaining a process of the marking verification strategy is as follows: The policy configuration instruction provided by the dynamic trust verification function in the controller to be tested is called, and the predetermined process dynamic trust verification periodic measurement policy is configured in the predetermined process to obtain a process of the marking verification policy.
6. A method for testing dynamic trustworthy verification function of a trusted DCS controller according to claim 1, characterized in that: The process of dynamically verifying the subject-object policy tag of the predetermined application and object files in the controller to be tested and obtaining the dynamic subject-object policy file is as follows: The policy configuration instruction provided by the dynamic trust verification function in the controller to be tested is called, and the predetermined dynamic trust verification periodic measurement policy is configured in the predetermined application program and object file to obtain a dynamic subject-object policy file.
7. A dynamic trustworthy verification function test system for a trusted DCS controller, characterized in that: Applied to a test terminal, a network connection is established between the test terminal and the controller to be tested; The trusted DCS controller dynamic trusted verification function test system includes: A file strategy marking module is used to perform a file dynamic trust verification periodic measurement strategy marking on a predetermined process file in the controller under test, and obtain a process file of the marking verification strategy; wherein, the controller under test responds to the process file of the marking verification strategy and generates an execution process; a first tampering query module, configured to tamper with the execution process and query the trustworthy status of the execution process; The process strategy marking module is used to perform process dynamic trust verification periodic measurement strategy marking on the predetermined process in the controller to be tested, and obtain the process of the marking verification strategy; a second tampering query module, configured to tamper with the process of the tag verification policy and query the trust status of the process of the tag verification policy; A subject-object policy marking module is used to perform dynamic trustworthy verification of the subject-object policy marking of predetermined application programs and object files in the controller under test, and obtain a dynamic subject-object policy file; wherein the controller under test responds to the dynamic subject-object policy file and generates a preset policy point execution process; a third tampering query module, configured to tamper with the execution process of the preset policy point and query the trustworthy status of the execution process of the preset policy point; A result output module is used to output the query results of the trusted state of the execution process, the trusted state of the process of the mark verification strategy, and the trusted state of the execution process of the preset strategy point, and obtain the dynamic trusted verification function test result of the controller to be tested; When tampering with the execution process, the process of the mark verification policy or the execution process of the preset policy point, the code segment or read-only data segment of the execution process, the process of the mark verification policy or the execution process of the preset policy point is used to tamper with it.
8. A dynamic trustworthy verification function test device for a trusted DCS controller, characterized in that: include: a processor suitable for executing a computer program; A computer-readable storage medium having a computer program stored therein, wherein when the computer program is executed by the processor, the method for testing the dynamic trusted verification function of a trusted DCS controller according to any one of claims 1 to 6 is executed.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method for testing the dynamic trustworthy verification function of a trusted DCS controller according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Security protection method and system for real-time operating system of trusted DCS (Distributed Control System) controller and medium
CN117195231A
Trusted DCS controller trusted function test method, electronic equipment and storage medium
CN117970907A