Reliability and Security Testing Method for a Multi-Morphological Cryptography Product
A systematic testing method for cryptographic products addresses the lack of universal assessment by evaluating performance and security across diverse conditions, enhancing network and data security.
Patent Information
- Application Number
- CN202411861728.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-12-17
AI Technical Summary
The prior art lacks comprehensive and systematic reliability and security detection methods for multi-form cryptographic products under different environmental conditions. Especially under extreme conditions such as high temperature, low temperature, and lighting, the reliability and security detection of cryptographic products is insufficient, affecting network and data security.
It provides a reliability and security testing method for multi-form cryptographic products, including initial testing and multi-component testing, covering operation testing, random number comparison testing, safety testing, constant pressure high and low temperature testing, changing temperature testing, constant humidity and heat testing, low air pressure testing, impact testing, lighting testing, vibration testing, drop testing and aging testing, ensuring the reliability and safety of cryptographic products under various environmental conditions.
It realizes systematic inspection of various types of cryptographic products, ensuring that they can operate normally and generate compliant random numbers in extreme environments, protect network and data security, and improves the reliability and security of cryptographic products.
Smart Images

Figure CN119803885B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cryptographic product detection, and particularly to a method for testing the reliability and security of multi-form cryptographic products. Background Art
[0002] Cryptography is the cornerstone for protecting network security and data security. There are significant differences in the forms of cryptographic products. According to modules, they can be divided into hardware cryptographic modules, software cryptographic modules, firmware cryptographic modules, hybrid software cryptographic modules, and hybrid firmware cryptographic modules. Specifically, there are products such as server cryptographic machines in the form of electronic products, and there are also products that are a mixture of electronic product forms and quantum technologies like quantum key distribution systems, as well as those in the form of software and firmware. Currently, cryptographic products no longer simply appear in the form of electronic products such as server cryptographic machines and are used in an environment with temperature and humidity control. Instead, they appear in various forms including electronic product forms, quantum technology product forms, software, and firmware, and are widely used in various indoor and outdoor, high-temperature, and low-temperature scenarios. For example, under conditions such as high temperature and light, the hardware coating protecting cryptographic sensitive parameters will be damaged, leading to security and reliability problems. The reliability of the product is related to whether the password can be used normally, and is related to the stability and security of the entire network space and data. It has become an essential consideration in the detection of cryptographic products. However, so far, there are only requirements for protection measures for cryptographic products under ultra-high temperature and ultra-high voltage conditions, and there is no comprehensive, systematic, and general reliability detection method for cryptographic products, especially for cryptographic products of various forms. Different from the reliability detection of conventional electrical products that focuses on electrical safety, the reliability detection of passwords focuses on different conditions. That is, from the perspective of cryptographic appliances, they are safe, but the quality of cryptographic random numbers and the operation of passwords may deviate, resulting in insecure passwords, thus affecting the network security and data security of products and systems using passwords.
[0003] In view of the deficiencies of the prior art, the present invention proposes a method and system for testing the reliability and security of multi-form cryptographic products. Summary of the Invention
[0004] The purpose of the present invention is to overcome the shortcomings of the prior art and provide a method for testing the reliability and security of multi-form cryptographic products, which is applicable to cryptographic products of various forms. It can be systematically detected through comprehensive detection of the operation correctness, performance stability, compliance of random number generation, and product security of cryptographic products, thereby overall forming a detection method for the reliability of cryptographic products and ensuring the reliability and security of cryptographic products.
[0005] A method for testing the reliability and security of multi-form cryptographic products includes:
[0006] Performing an initial test and multi-component item tests on the cryptographic product to be tested in a preset order,
[0007] The initial test includes: operation detection, random number comparison detection, and security detection;
[0008] The multi-component test includes: constant pressure high and low temperature test, variable temperature test, constant humidity and heat test, low air pressure test, shock test, light test, vibration test, drop test, and aging test;
[0009] If any one of the initial test and the multi-component test fails, the reliability and security detection of the password product fails;
[0010] In the initial test,
[0011] The operation detection includes:
[0012] Operate the password product to be tested according to the product manual;
[0013] If it operates normally, input the operation detection data of the password;
[0014] If it cannot operate normally, terminate the detection and output that the operation detection fails;
[0015] After inputting the prepared operation detection data of the password and capturing the output data; compare the output data with the prepared operation detection data of the password to determine whether the password calculation is correct;
[0016] If it is correct, calculate the password performance according to the output data;
[0017] If it is wrong, terminate the detection and output that the detection fails;
[0018] Calculate the password performance according to the output data, and compare the calculated performance with the password performance;
[0019] If the difference between the calculated performance and the password performance exceeds the allowable range, output that the operation detection fails;
[0020] If the difference between the calculated performance and the password performance does not exceed the allowable range, output that the operation detection passes; and conduct the random number comparison detection;
[0021] The random number comparison detection includes:
[0022] Obtain the random number output by the password product and conduct random number qualification detection on the random number;
[0023] If the detection is unqualified, output that the random number comparison detection fails;
[0024] If the detection is qualified, output that the random number comparison detection passes; and conduct the security detection;
[0025] The security detection includes:
[0026] Verify whether the cryptographic product and its supporting environment have a physical enclosure;
[0027] If there is a physical enclosure, detect whether an external physical object can pass through the physical enclosure of the cryptographic product and directly contact the cryptographic components inside the cryptographic product;
[0028] If it is possible to directly contact the cryptographic components, terminate the security detection and output that the security detection fails;
[0029] If not, verify whether the physical enclosure has a trace coating, a disassembly response and a zeroing circuit, and a disassembly detection and response envelope;
[0030] If any one of the trace coating, the disassembly response and the zeroing circuit, and the disassembly detection and response envelope is missing, output that the security detection fails;
[0031] If each of the trace coating, the disassembly response and the zeroing circuit, and the disassembly detection and response envelope exists, the security detection passes.
[0032] Furthermore, the constant voltage high and low temperature test includes:
[0033] S201. Obtain the upper limit value and the lower limit value of the operating temperature of the cryptographic product to be tested;
[0034] S202. Adjust the ambient temperature of the test environment to the upper limit value or the lower limit value;
[0035] S203. When the ambient temperature is stable, place the cryptographic product in the test environment and continuously operate for a first preset time;
[0036] S204. During continuous operation, conduct an initial test on the cryptographic product. If any one of the initial tests fails, the constant voltage high and low temperature test fails;
[0037] S205. Place the cryptographic product in a standard environment until the temperature of the cryptographic product is stable;
[0038] S206. Adjust the ambient temperature of the test environment to above the upper limit value or below the lower limit value;
[0039] S207. When the ambient temperature is stable, place the cryptographic product in the test environment and continuously operate for a first preset time;
[0040] S208. During continuous operation, conduct an initial test on the cryptographic product. If any one of the initial tests fails, the constant voltage high and low temperature test fails.
[0041] Furthermore, the variable temperature test includes:
[0042] S211. Adjust the environmental temperature of the test environment to a low temperature, place the cryptographic product in the test environment for continuous exposure, and keep running; the low temperature is the lower limit of the operating temperature of the cryptographic product to be tested; the continuous running time is not less than 30 minutes;
[0043] S212. Raise the environmental temperature to the upper limit of the operating temperature; keep the cryptographic product to be tested continuously exposed and keep running; the rate of temperature increase is 10°C per minute or the temperature increase is a fluctuating increase;
[0044] S213. When the environmental temperature is rising, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the variable temperature test fails;
[0045] S214. Place the cryptographic product in a standard environment until the temperature of the cryptographic product stabilizes;
[0046] S215. Place the cryptographic product in the test environment, and lower the environmental temperature to the lower limit of the operating temperature; the rate of temperature decrease is 10°C per minute or the temperature decrease is a fluctuating decrease;
[0047] S216. The cryptographic product is continuously exposed and kept running; the continuous running time is not less than 30 minutes;
[0048] S217. When the environmental temperature is decreasing, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the variable temperature test fails.
[0049] Further, the damp heat test under constant conditions includes:
[0050] S221. Adjust the humidity and temperature of the test environment to the specified humidity and temperature according to the product manual of the cryptographic product to form a damp heat environment;
[0051] S222. The cryptographic product to be tested is continuously exposed and kept running in the damp heat environment;
[0052] S223. Conduct an initial test on the cryptographic product to be tested running in the damp heat environment. If any one of the detections in the initial test fails, the damp heat test under constant conditions fails.
[0053] Further, the low air pressure test includes:
[0054] S231. Adjust the air pressure of the test environment to the lowest operating air pressure in the product manual of the cryptographic product;
[0055] S232. Place the cryptographic product to be tested in the test environment; power on the cryptographic product to be tested and keep running for a specified time;
[0056] S233. Remove the cryptographic product from the test environment and place it under standard atmospheric pressure, or use a detection tool to restore the air pressure to standard atmospheric pressure;
[0057] S233. Keep the cryptographic product under standard atmosphere for restoration, where 1h ≤ restoration time ≤ 2h;
[0058] S234. Conduct an initial test on the cryptographic product to be tested. If any one of the detections in the initial test fails, the low air pressure test fails.
[0059] Further, the shock test includes:
[0060] S241. Apply shocks with a preset shock intensity to the cryptographic product to be tested in the directions of three orthogonal axes in sequence; multiple shocks are applied in the directions of all three orthogonal axes;
[0061] S242. Immediately conduct an initial test on the cryptographic product after the shocks in the directions of the three orthogonal axes are completed. If any one of the detections in the initial test fails, the shock test fails.
[0062] Further, the light exposure test includes:
[0063] S251. For the cryptographic product to be tested, check whether the light exposure protection film of the cryptographic product to be tested is intact:
[0064] If there are defects, the detection is unqualified;
[0065] If it is intact, conduct a light intensity detection;
[0066] S252. Select a standard light source, set different light intensities, and continuously irradiate the hardware cryptographic product at a preset angle for a certain preset time; check whether there is any color change in the light exposure protection film;
[0067] If the color of the light exposure protection film changes, output that the detection is unqualified, and record the degree and position of the change of the light exposure protection film;
[0068] If the color of the light exposure protection film does not change, conduct an initial detection;
[0069] S253. Conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the light exposure test fails.
[0070] Further, the vibration test includes:
[0071] S261. Apply sinusoidal vibration to the cryptographic product within a preset vibration time period;
[0072] The number of axes and the vibration position of the sinusoidal vibration are carried out according to the product manual of the cryptographic product;
[0073] The vibration direction of the cryptographic product under sinusoidal vibration is to be vibrated successively on three mutually perpendicular sinusoidal vibration axes;
[0074] S262. Conduct vibration durability testing on the cryptographic product within the specified frequency range;
[0075] The vibration durability testing is as follows:
[0076] Adopt a sweep-frequency durability test, and conduct a sweep frequency on the cryptographic product for a second preset time by setting the frequency within a preset range, the sweep frequency within a preset range, and the amplitude within a preset range;
[0077] Or
[0078] The vibration durability testing is as follows:
[0079] Adopt a fixed-frequency durability test, and continuously input a frequency to the cryptographic product at a predetermined frequency and a preset amplitude within a second preset time; the predetermined frequency is the center resonance frequency or an approximate fixed frequency;
[0080] S263. After completing the sinusoidal vibration and vibration durability testing, place the cryptographic product in the same test environment as during the initial testing;
[0081] S264. Conduct an initial test on the cryptographic product to be tested. If any one of the tests in the initial test fails, the vibration test fails.
[0082] Furthermore, the drop test includes:
[0083] S271. Conduct a face-tilt drop test on the cryptographic product to be tested;
[0084] Place the cryptographic product on the test tabletop so that the bottom surface of the cryptographic product forms a preset angle with the test tabletop, and then let the cryptographic product freely tilt and fall on the test tabletop.
[0085] S272. Conduct a corner-tilt drop test on the cryptographic product to be tested;
[0086] Place the cryptographic product in its normal use position, and use wooden stakes or other available equipment to make one corner of the cryptographic product present a specified height and the other adjacent corner present another different specified height. The difference between the two heights should comply with the provisions of relevant specifications. Raise the cryptographic product around the edge between the above two corners to a certain height or make the cryptographic product form a specified angle with the test tabletop, usually taking the smaller value of the two. Let the cryptographic product freely tilt and fall on the test tabletop, and conduct a tilt and fall test on each of the 4 corners of the cryptographic product.
[0087] S273. Conduct a tipping (or pushing down) test on the cryptographic product to be tested
[0088] Place the cryptographic product in its normal operating position and tilt it about one of its bases until it is in an unstable position. Then let it fall freely onto an adjacent face. The tipping test shall be carried out once for each of the four bases.
[0089] S274. Conduct a free fall test on the cryptographic product to be tested.
[0090] Select the drop height according to the relevant specifications. The test height shall be the vertical distance between the lowest point of the cryptographic product and the test bench. Release the cryptographic product with minimal interference to complete the free fall. The free fall process can be repeated for a specified number of tests on the cryptographic product.
[0091] S275. Conduct an initial test on the cryptographic product to be tested. If any of the tests in the initial test fails, the drop test fails.
[0092] Further, the aging test includes:
[0093] Optionally, conduct aging on the cryptographic product to be tested using one of the thermal acceleration factor aging test, the comprehensive thermal acceleration factor aging test, and the Hallberg - Peck model aging test;
[0094] After aging, conduct an initial test on the cryptographic product to be tested. If any of the tests in the initial test fails, the aging test fails;
[0095] The thermal acceleration factor aging test includes: Aging the cryptographic product to be tested using the heating factor effect. The expression for the heating factor is:
[0096] ;
[0097] In the formula:
[0098] AF: Thermal acceleration factor;
[0099] Ea: Activation energy; The value of the activation energy is between 0.3 eV and 1.2 eV;
[0100] K: Boltzmann constant, whose value is 8.617385×10^ - 5;
[0101] Tu: Temperature value in the non - accelerated state under the use conditions, in units of K (Kelvin);
[0102] Tt: Temperature value in the accelerated state under the test conditions, in units of K (Kelvin);
[0103] The comprehensive thermal acceleration factor aging test includes: obtaining a second thermal acceleration factor by integrating temperature and humidity factors, and aging the password product to be tested through the second thermal acceleration factor. The expression of the second thermal acceleration factor after integrating temperature and humidity factors is:
[0104]
[0105] In the formula:
[0106] AF2: The second thermal acceleration factor;
[0107] RHu: The relative humidity value under the use condition (non-accelerated state);
[0108] RHt: The relative humidity value under the test condition (accelerated state);
[0109] n: The humidity acceleration rate constant, and this value usually ranges between 2 and 3, depending on the material and environmental conditions.
[0110] The Hallberg Peck model aging test includes: reconstructing the thermal acceleration factor using the Hallberg Peck model to obtain a third thermal acceleration factor, and aging the password of the product to be tested. The expression of the third thermal acceleration factor is:
[0111]
[0112] Wherein:
[0113] AF3: The third thermal acceleration factor.
[0114] The present invention has the following advantages:
[0115] (1) In the present invention, there are clear and systematic reliability and security test methods applicable to various types of password products; the present invention has universality.
[0116] (2) The present invention can detect password products with higher reliability for different environments, such as outdoor high temperature, low temperature, and light environments, etc., so as to ensure the long-term stability and security of the cyberspace and data. BRIEF DESCRIPTION OF THE DRAWINGS
[0117] Figure 1 is the method step diagram of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0118] The present invention will be further described below in conjunction with the drawings, but the protection scope of the present invention is not limited to the following.
[0119] It should be noted that the orientation or positional relationship indicated by "left", "right", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use, or the orientation or positional relationship commonly understood by those skilled in the art. Such terms are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation on the present invention.
[0120] It should be noted that, without conflict, the embodiments in the present invention and the features and technical solutions in the embodiments may be combined with each other.
[0121] As Figure 1 shown, the present invention provides a method for testing the reliability and security of a multi-modal password product.
[0122] A method for testing the reliability and security of a multi-modal password product includes:
[0123] Performing an initial test and multi-component item tests on the password product to be tested in a preset order.
[0124] The initial test includes: operation detection, random number comparison detection, and security detection;
[0125] The multi-component item tests include: constant pressure high and low temperature test, variable temperature test, constant humidity test, low air pressure test, shock test, light test, vibration test, drop test, and aging test;
[0126] If any one of the initial test and the multi-component item tests fails, the reliability and security detection of the password product fails; in the initial test,
[0127] The operation detection includes:
[0128] Operating the password product to be tested according to the product manual;
[0129] If it operates normally, perform operation detection data input for the entered password;
[0130] If it cannot operate normally, terminate the detection and output that the operation detection fails;
[0131] After inputting the prepared operation detection data for the password and capturing the output data; compare the output data with the prepared operation detection data for the password to determine whether the password calculation is correct;
[0132] If it is correct, calculate the password performance based on the output data;
[0133] If it is incorrect, terminate the detection and output that the detection fails;
[0134] Calculate the password performance based on the output data, and compare the calculated performance with the password performance;
[0135] If the difference between the calculated performance and the password performance exceeds the allowable range, output that the operation detection fails;
[0136] If the difference between the calculated performance and the password performance does not exceed the allowable range, output that the operation detection passes; and perform a random number comparison detection;
[0137] The random number comparison detection includes:
[0138] Obtain the random numbers output by the password product, and perform a random number qualification detection on the random numbers; Perform a random number qualification detection on the password product in accordance with the documents GM / T 0005 and GM / T 0062;
[0139] If the detection is unqualified, output that the random number comparison detection fails;
[0140] If the detection is qualified, output that the random number comparison detection passes; and perform a security detection;
[0141] The security detection includes:
[0142] Verify whether the password product and its relying environment have a physical enclosure;
[0143] If there is a physical enclosure, detect whether an external physical object can pass through the physical enclosure of the password product and directly contact the password components inside the password product;
[0144] If it is possible to directly contact the password components, terminate the security detection and output that the security detection fails;
[0145] If not, verify whether the physical enclosure has a trace coating, a disassembly response and a zeroing circuit, a disassembly detection and a response envelope;
[0146] If any one of the trace coating, the disassembly response and the zeroing circuit, the disassembly detection and the response envelope is missing, output that the security detection fails;
[0147] If each of the trace coating, the disassembly response and the zeroing circuit, the disassembly detection and the response envelope exists, the security detection passes.
[0148] Further, the constant voltage high and low temperature test includes:
[0149] S201. Obtain the upper limit value and the lower limit value of the operating temperature of the password product to be tested;
[0150] S202. Adjust the ambient temperature of the test environment to the upper limit value or the lower limit value;
[0151] S203. After the environmental temperature stabilizes, place the cryptographic product in the test environment and continuously run it for a first preset time;
[0152] S204. During continuous operation, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the constant voltage high and low temperature test fails;
[0153] S205. Place the cryptographic product in the standard environment until the temperature of the cryptographic product stabilizes;
[0154] S206. Adjust the environmental temperature of the test environment to above the upper limit value or below the lower limit value;
[0155] S207. After the environmental temperature stabilizes, place the cryptographic product in the test environment and continuously run it for a first preset time;
[0156] S208. During continuous operation, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the constant voltage high and low temperature test fails.
[0157] Further, the variable temperature test includes:
[0158] S211. Adjust the environmental temperature of the test environment to low temperature, place the cryptographic product in the test environment and continuously expose and run it; the low temperature is the lower limit value of the operating temperature of the cryptographic product to be tested; the continuous operation time is not less than 30 minutes;
[0159] S212. Raise the environmental temperature to the upper limit value of the operating temperature; keep the cryptographic product to be tested continuously exposed and running; the amplitude of temperature increase is 10°C per minute or the temperature increase is a fluctuating increase;
[0160] S213. During the increase of the environmental temperature, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the variable temperature test fails;
[0161] S214. Place the cryptographic product in the standard environment until the temperature of the cryptographic product stabilizes;
[0162] S215. Place the cryptographic product in the test environment, and lower the environmental temperature to the lower limit value of the operating temperature; the amplitude of temperature decrease is 10°C per minute or the temperature decrease is a fluctuating decrease;
[0163] S216. The cryptographic product is continuously exposed and running; the continuous operation time is not less than 30 minutes;
[0164] S217. During the decrease of the environmental temperature, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the variable temperature test fails.
[0165] Further, the damp heat test includes:
[0166] S221. Adjust the humidity and temperature of the test environment to the specified humidity and temperature according to the product manual of the cryptographic product to form a damp heat environment;
[0167] S222. The cryptographic product to be tested is continuously exposed and continuously operated in the damp heat environment;
[0168] S223. Conduct an initial test on the cryptographic product to be tested operating in the damp heat environment. If any one of the detections in the initial test fails, the damp heat test fails.
[0169] Further, the low air pressure test includes:
[0170] S231. Adjust the air pressure of the test environment to the lowest operating air pressure in the product manual of the cryptographic product;
[0171] S232. Place the cryptographic product to be tested in the test environment; power on the cryptographic product to be tested and continuously operate for a specified time;
[0172] S233. Remove the cryptographic product from the test environment and place it under standard atmospheric pressure, or restore the air pressure to standard atmospheric pressure through a detection tool;
[0173] S233. Keep the cryptographic product under standard atmosphere for recovery, where 1h ≤ recovery time ≤ 2h;
[0174] S234. Conduct an initial test on the cryptographic product to be tested. If any one of the detections in the initial test fails, the low air pressure test fails.
[0175] Further, the shock test includes:
[0176] S241. Apply shocks with a preset shock force to the three orthogonal axes of the cryptographic product to be tested in sequence; multiple shocks are applied to all three orthogonal axes;
[0177] S242. Immediately conduct an initial test on the cryptographic product after the shocks on the three orthogonal axes are completed. If any one of the detections in the initial test fails, the shock test fails.
[0178] Further, the light exposure test includes:
[0179] S251. For the cryptographic product to be tested, check whether the light protection film of the cryptographic product to be tested is intact:
[0180] If there are defects, the detection is unqualified;
[0181] If it is intact, conduct a light intensity detection;
[0182] S252. Select a standard light source, set different light intensities, and continuously irradiate the hardware password product at a preset angle for a certain preset time; detect whether there is any color change in the light-protective film;
[0183] If the color of the light-protective film changes, output that the detection is unqualified, and record the degree and position of the change in the light-protective film;
[0184] If the color of the light-protective film does not change, conduct an initial detection;
[0185] S253. Conduct an initial test on the password product. If any one of the detections in the initial test fails, the light test fails.
[0186] Furthermore, the vibration test includes:
[0187] S261. Apply sinusoidal vibration to the password product within a preset vibration time period;
[0188] The number of axes and the vibration position of the sinusoidal vibration are carried out according to the product manual of the password product;
[0189] The vibration direction of the password product receiving the sinusoidal vibration is to be vibrated sequentially on three mutually perpendicular sinusoidal vibration axes;
[0190] S262. Conduct vibration durability detection on the password product within a specified frequency range;
[0191] The vibration durability detection is:
[0192] Adopt a sweep-frequency durability test, and conduct sweep-frequency on the password product for a second preset time by setting a preset frequency range, a preset sweep-frequency range, and a preset amplitude range;
[0193] Or
[0194] The vibration durability detection is:
[0195] Adopt a fixed-frequency durability test, and continuously input a frequency to the password product at a predetermined frequency and a preset amplitude within a second preset time; the predetermined frequency is the center resonance frequency or an approximate fixed frequency;
[0196] S263. After completing the sinusoidal vibration and vibration durability detection, place the password product in the same test environment as in the initial detection;
[0197] S264. Conduct an initial test on the password product to be tested. If any one of the detections in the initial test fails, the vibration test fails.
[0198] Furthermore, the drop test includes:
[0199] S271. Conduct a surface tilting test on the password product to be tested;
[0200] Place the password product on the test bench so that the bottom surface of the password product forms a preset angle with the test bench, and then let the password product freely tilt and fall on the test bench.
[0201] S272. Conduct a corner tilting test on the password product to be tested;
[0202] Place the password product in its normal use position. Use wooden stakes or other available equipment to make one corner of the password product present a specified height, and the other adjacent corner present another different specified height. The difference between the two heights should comply with the regulations of relevant specifications. Lift the password product around the edge between the above two corners to a certain height or make the password product form a specified angle with the test bench, usually taking the smaller value of the two. Let the password product freely tilt and fall on the test bench, and a tilting test should be conducted on each of the 4 corners of the password product.
[0203] S273. Conduct a tipping (or pushing down) test on the password product to be tested
[0204] Place the password product in its normal use position and tilt it around a bottom edge until it is in an unstable position, and then let it freely tip over onto an adjacent side from this position. A tipping test should be conducted on each of the 4 bottom edges.
[0205] S274. Conduct a free fall test on the password product to be tested
[0206] According to the regulations of relevant specifications, select the falling height. The test height should be the vertical distance between the lowest position of the password product and the test bench. Release the password product to minimize the interference it receives and complete the free fall. The free fall process can be repeated to conduct a specified number of tests on the password product.
[0207] S275. Conduct an initial test on the password product to be tested. If any one of the detections in the initial test fails, the drop test fails.
[0208] Furthermore, the aging test includes:
[0209] Optionally, conduct aging on the password product to be tested by choosing one of the thermal acceleration factor aging test, comprehensive thermal acceleration factor aging test, and Hallberg - Peck model aging test;
[0210] After aging, conduct an initial test on the password product to be tested. If any one of the detections in the initial test fails, the aging test fails;
[0211] The thermal acceleration factor aging test includes: aging the password product to be tested using the heating factor effect, and the expression of the heating factor is:
[0212] ;
[0213] In the formula:
[0214] AF: Thermal acceleration factor;
[0215] Ea: Activation energy; the value of the activation energy is between 0.3 eV and 1.2 eV, and for electronic products, the Ea value is usually selected between 0.6 eV and 0.7 eV
[0216] K: Boltzmann constant, and its value is 8.617385×10^-5;
[0217] Tu: Temperature value in the non-accelerated state under the use conditions, in units of K (Kelvin);
[0218] Tt: Temperature value in the accelerated state under the test conditions, in units of K (Kelvin);
[0219] The comprehensive thermal acceleration factor aging test includes: obtaining the second thermal acceleration factor by integrating temperature and humidity factors, and aging the password product to be tested through the second thermal acceleration factor. The expression of the second thermal acceleration factor after integrating temperature and humidity factors is:
[0220]
[0221] In the formula:
[0222] AF2: Second thermal acceleration factor;
[0223] RHu: Relative humidity value under the use conditions (non-accelerated state);
[0224] RHt: Relative humidity value under the test conditions (accelerated state);
[0225] n: Humidity acceleration rate constant, and this value usually ranges between 2 and 3, depending on the material and environmental conditions.
[0226] The Hallberg Peck model aging test includes: reconstructing the thermal acceleration factor using the Hallberg Peck model to obtain the third thermal acceleration factor, and aging the password of the product to be tested. The expression of the third thermal acceleration factor is:
[0227]
[0228] Among them:
[0229] AF3: Third thermal acceleration factor.
[0230] In some specific embodiments, a thermal acceleration factor aging test is selected to age the cryptographic product; a high-temperature test at 105 °C is required for a certain cryptographic product;
[0231] At this time, the activation energy Ea of the product is selected as 0.68;
[0232] According to the product manual of the cryptographic product, the service life requirement for this product is 10 years. Now, 5 identical cryptographic products to be tested are obtained; at this time, Tt = 25 °C, then the thermal acceleration factor AF can be obtained:
[0233] AF = exp{[0.68 / (8.617385*10^-5)]·{[1 / (273 + 25)] - [1 / (273 + 105)]}}
[0234] It can be obtained that AF ≈ 271.9518;
[0235] It is also known that its target service life is 10 years; L_target = 10y = 10 * 365 * 24h = 87600h
[0236] Therefore, it can be calculated:
[0237] L_test = L_target / AF = 87600 / 271.9518h = 322.1159h ≈ 23h
[0238] Now, the 5 samples are tested simultaneously, then the test duration is:
[0239] L_final = 323 / 5h = 65h
[0240] This means that if the product does not fail after 5 products are simultaneously tested at 105 °C for 65h, it indicates that the service life of the product has reached the requirement, and then the cryptographic product passes the aging test.
[0241] The above embodiments only represent relatively preferred implementation manners, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the present invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention.
Claims
1. A method for testing the reliability and security of a multi - form password product, characterized in that it includes: Conducting initial testing and multi - component itemized testing on the password product to be tested in a preset order, The initial testing includes: operation detection, random number comparison detection, and security detection; The multi - component itemized testing includes: constant - pressure high - low temperature testing, variable - temperature testing, constant - humidity testing, low - pressure testing, shock testing, light testing, vibration testing, drop testing, and aging testing; If any one of the initial testing and multi - component itemized testing fails, the reliability and security testing of the password product fails; In the initial testing, The operation detection includes: Operating the password product to be tested according to the product manual; If it operates normally, input the password operation detection data; If it cannot operate normally, terminate the detection and output that the operation detection fails; After inputting the prepared password operation detection data, capture the output data; compare the output data with the prepared password operation detection data to determine whether the password calculation is correct; If it is correct, calculate the password performance based on the output data; If it is incorrect, terminate the detection and output that the detection fails; Calculate the password performance based on the output data, and compare the calculated performance with the password performance; If the difference between the calculated performance and the password performance exceeds the allowable range, output that the operation detection fails; If the difference between the calculated performance and the password performance does not exceed the allowable range, output that the operation detection passes; and conduct random number comparison detection; The random number comparison detection includes: Obtaining the random number output by the password product and conducting random number qualification detection on the random number; If the detection is unqualified, output that the random number comparison detection fails; If the detection is qualified, output that the random number comparison detection passes; and conduct security detection; The security detection includes: Verifying whether the password product and its relying environment have a physical shell; If there is a physical shell, detect whether an external physical object can pass through the physical shell of the password product and directly contact the password components inside the password product through a trace - retaining coating or a photosensitive coating; If it can directly contact the password components, terminate the security detection and output that the security detection fails; If not, verify whether the physical shell has a trace - retaining coating, disassembly response and zero - setting circuit, disassembly detection and response envelope; If any one of the trace - retaining coating, disassembly response and zero - setting circuit, disassembly detection and response envelope is missing, output that the security detection fails; If each of the trace - retaining coating, disassembly response and zero - setting circuit, disassembly detection and response envelope exists, the security detection passes.
2. The reliability and security testing method of a multi-modal password product according to claim 1, characterized in that: The constant - pressure high - low temperature testing includes: S201. Obtaining the upper limit value and lower limit value of the operating temperature of the password product to be tested; S202. Adjusting the environmental temperature of the test environment to the upper limit value or the lower limit value; S203. When the environmental temperature is stable, placing the password product in the test environment and continuously operating it for the first preset time; S204. During continuous operation, conducting initial testing on the password product. If any one of the initial testing fails, the constant - pressure high - low temperature testing fails; S205. Placing the password product in a standard environment until the temperature of the password product is stable; S206. Adjust the environmental temperature of the test environment to above the upper limit value or below the lower limit value; S207. When the environmental temperature is stable, place the cryptographic product in the test environment and continuously operate it for the first preset time; S208. During continuous operation, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the constant temperature and humidity test fails.
3. The reliability and security testing method for a multi-modal password product according to claim 1, characterized in that: The variable temperature test includes: S211. Adjust the environmental temperature of the test environment to a low temperature, place the cryptographic product in the test environment, continuously expose it, and continuously operate; the low temperature is the lower limit value of the operating temperature of the cryptographic product to be tested; the continuous operation time is not less than 30 minutes; S212. Raise the environmental temperature to the upper limit value of the operating temperature; keep the cryptographic product to be tested continuously exposed and continuously operate; the amplitude of temperature increase is 10°C per minute or the temperature increase is a fluctuating increase; S213. When the environmental temperature is rising, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the variable temperature test fails; S214. Place the cryptographic product in a standard environment until the temperature of the cryptographic product is stable; S215. Place the cryptographic product in the test environment, and lower the environmental temperature to the lower limit value of the operating temperature; the amplitude of temperature reduction is 10°C per minute or the temperature reduction is a fluctuating reduction; S216. The cryptographic product is continuously exposed and continuously operated; the continuous operation time is not less than 30 minutes; S217. When the environmental temperature is decreasing, conduct an initial test on the cryptographic product. If any one of the detections in the initial test fails, the variable temperature test fails.
4. The reliability and security testing method for a multi-modal password product according to claim 1, characterized in that: The constant temperature and humidity test includes: S221. Adjust the humidity and temperature of the test environment to the specified humidity and temperature according to the product manual of the cryptographic product to form a humid and hot environment; S222. The cryptographic product to be tested is continuously exposed and continuously operated in the humid and hot environment; S223. Conduct an initial test on the cryptographic product to be tested operating in the humid and hot environment. If any one of the detections in the initial test fails, the constant temperature and humidity test fails.
5. The reliability and security testing method for a multi-modal password product according to claim 1, characterized in that: The low air pressure test includes: S231. Adjust the air pressure of the test environment to the lowest operating air pressure in the product manual of the cryptographic product; S232. Place the cryptographic product to be tested in the test environment; power on the cryptographic product to be tested and continuously operate for a specified time; S233. Remove the cryptographic product from the test environment and place it under standard atmospheric pressure, or restore the air pressure to standard atmospheric pressure through a detection tool; S233. Keep the cryptographic product restored under standard atmosphere, and the restoration time is 1h ≤ restoration time ≤ 2h; S234. Conduct an initial test on the cryptographic product to be tested. If any one of the detections in the initial test fails, the low air pressure test fails.
6. The reliability and security testing method for a multi - form password product according to claim 1, characterized in that: The shock test includes: S241. Apply shocks with a preset shock force to the three orthogonal axes of the cryptographic product to be tested in sequence; multiple shocks are applied to all three orthogonal axes; S242. Immediately conduct an initial test on the cryptographic product after the shocks on the three orthogonal axes are completed. If any one of the detections in the initial test fails, the shock test fails.
7. The reliability and security testing method of a multi-modal password product according to claim 1, characterized in that: The light exposure test includes: S251. For the cryptographic product to be tested, check whether the light protection film of the cryptographic product to be tested is intact: If there are defects, the test fails. If it is intact, perform a light intensity test. S252. Select a standard light source, set different light intensities, and continuously irradiate the hardware cryptographic product at a preset angle for a certain preset time; check whether there is any color change in the light protection film. If the color of the light protection film changes, output that the test fails, and record the degree and location of the change in the light protection film. If the color of the light protection film does not change, perform an initial test. S253. Conduct an initial test on the cryptographic product. If any test fails in the initial test, the light test fails.
8. The reliability and security testing method for a multi-modal password product according to claim 1, characterized in that: The vibration test includes: S261. Apply sinusoidal vibration to the cryptographic product within a preset vibration time period. The number of axes and vibration positions of the sinusoidal vibration are carried out according to the product manual of the cryptographic product. The vibration directions for the cryptographic product to receive sinusoidal vibration are to be vibrated sequentially on three mutually perpendicular sinusoidal vibration axes. S262. Conduct vibration durability testing on the cryptographic product within a specified frequency range. The vibration durability testing is as follows: Adopt a sweep-frequency durability test, and continuously sweep the cryptographic product for a second preset time by setting a preset frequency range, a preset sweep-frequency range, and a preset amplitude range. Or The vibration durability testing is as follows: Adopt a fixed-frequency durability test, and continuously input a frequency to the cryptographic product at a predetermined frequency and a preset amplitude within a second preset time; the predetermined frequency is the center resonance frequency or an approximate fixed frequency. S263. After completing the sinusoidal vibration and vibration durability testing, place the cryptographic product in the same test environment as in the initial test. S264. Conduct an initial test on the cryptographic product to be tested. If any test fails in the initial test, the vibration test fails.
9. The reliability and security testing method for a multi-modal password product according to claim 1, characterized in that: The drop test includes: S271. Conduct a face-tilt drop test on the cryptographic product to be tested. Place the cryptographic product on the test table, make the bottom surface of the cryptographic product form a preset angle with the test table, and then let the cryptographic product freely tilt and fall on the test table. S272. Conduct a corner-tilt drop test on the cryptographic product to be tested. Place the cryptographic product in the normal use position, use wooden stakes or other available equipment to make one corner of the cryptographic product present a specified height, and the adjacent side's other corner present another different specified height. The difference between the two heights should comply with the regulations of relevant specifications; raise the cryptographic product around the edge between the above two corners to a certain height or make the cryptographic product form a specified angle with the test table, usually taking the smaller value of the two; let the cryptographic product freely tilt and fall on the test table, and conduct a tilt drop test on each of the 4 corners of the cryptographic product. S273. Conduct a tipping test on the cryptographic product to be tested. Place the cryptographic product in the normal use position, tilt it around a bottom edge until it is in an unstable position, and then let it freely tip over onto an adjacent side. Conduct a tipping test on each of the 4 bottom edges. S274. Conduct a free fall test on the cryptographic product to be tested. According to the regulations of relevant specifications, select the height of the drop. The test height shall be the vertical distance between the lowest position of the cryptographic product and the test bench; release the cryptographic product to minimize the interference it receives and complete the free fall; the free fall process can be repeated to conduct the test on the cryptographic product for a specified number of times; S275. Conduct an initial test on the cryptographic product to be tested. If any one of the detections in the initial test fails, the drop test fails.
10. The reliability and security testing method for a multi-modal password product according to claim 1, characterized in that: The aging test includes: Optionally select one of the thermal acceleration factor aging test, comprehensive thermal acceleration factor aging test, and Hallberg Peck model aging test to age the cryptographic product to be tested; After aging, conduct an initial test on the cryptographic product to be tested. If any one of the detections in the initial test fails, the aging test fails; The thermal acceleration factor aging test includes: aging the cryptographic product to be tested using the heating factor effect. The expression of the heating factor is: ; In the formula: AF: Thermal acceleration factor; Ea: Activation energy; K: Boltzmann constant, the value of which is 8.617385×10^-5; Tu: Temperature value in the non-accelerated state under the use conditions, in units of K (Kelvin); Tt: Temperature value in the accelerated state under the test conditions, in units of K (Kelvin); The comprehensive thermal acceleration factor aging test includes: obtaining the second thermal acceleration factor by integrating temperature and humidity factors, and aging the cryptographic product to be tested through the second thermal acceleration factor. The expression of the second thermal acceleration factor after integrating temperature and humidity factors is: In the formula: AF2: Second thermal acceleration factor; RHu: Relative humidity value under the use conditions (non-accelerated state); RHt: Relative humidity value under the test conditions (accelerated state); n: Humidity acceleration rate constant, between 2 and 3; The Hallberg Peck model aging test includes: reconstructing the thermal acceleration factor using the Hallberg Peck model to obtain the third thermal acceleration factor, and aging the cryptographic product of the product to be tested. The expression of the third thermal acceleration factor is: Where: AF3: Third thermal acceleration factor.
Citation Information
Patent Citations
Device and method for testing a chip on which a cryptographic method is implemented
DE102009031145A1
IC card and IC card reader
JP2001143046A