Automatic detection method for application interface of password equipment
Through the automated detection method, the algorithm interface of the cryptographic device is verified by using the hardware cryptographic module and detection parameters, which solves the problem of difficulty in effectively detecting whether the cryptographic device complies with the interface specifications in the prior art, and improves the security and reliability of the information system.
Patent Information
- Application Number
- CN202510248290.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-03
AI Technical Summary
It is difficult for the prior art to effectively detect whether the password device complies with the specifications of the password device application interface, which makes it difficult to ensure the security and reliability of the information system.
An automated detection method for cryptographic device application interface is adopted, and the algorithm interface of the detected cryptographic device is verified through the hardware cryptographic module, and the detection parameters such as key index and SDF dynamic library are configured. These parameters are used to inject keys and detect them to ensure that the interface of the cryptographic device complies with the specifications.
This method can automatically detect whether the password device complies with the interface specifications, improve the security and reliability of the password device, reduce manual intervention, and improve detection efficiency and accuracy.
Smart Images

Figure CN120090798A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to an automated detection method for the application interface of cryptographic devices. Background Art
[0002] With the rapid development of information technology, cryptographic devices are increasingly widely used in information systems. To ensure the security and integrity of information, the application interfaces of cryptographic devices need to meet certain specifications and standards.
[0003] The GM / T 0018 "Application Interface of Cryptographic Devices" specification defines the requirements for the application interface of cryptographic devices. However, in actual applications, how to effectively detect and verify whether a cryptographic device complies with this specification remains an urgent problem to be solved. Summary of the Invention
[0004] The purpose of the present invention is to provide an automated detection method for the application interface of cryptographic devices to overcome the defects of the prior art, which can effectively detect whether a cryptographic device complies with relevant interface specifications, thereby improving the security and reliability of cryptographic devices.
[0005] The purpose of the present invention is achieved by the following technical solutions:
[0006] An automated detection method for the application interface of cryptographic devices, characterized in that the method includes:
[0007] Configuring detection parameters for the cryptographic device to be tested, where the detection parameters include the key index participating in the cryptographic operation;
[0008] Injecting a key into the key index of the cryptographic device to be tested;
[0009] Verifying the algorithm interface of the cryptographic device to be tested through a hardware cryptographic module to generate a detection result;
[0010] The hardware cryptographic module is used to generate a corresponding key on the specified key index and detect the correctness of the algorithm interface of the cryptographic device to be tested.
[0011] Further, the detection parameters further include an SDF dynamic library configured for the cryptographic device to be tested. The SDF dynamic library is used as a middleware for communicating with the cryptographic device to be tested through a detection tool, and communicates with the cryptographic device to be tested by calling the SDF dynamic library.
[0012] Further, the key index participating in the cryptographic operation includes an encryption key index and a signature key index, and the algorithm interface includes an asymmetric cryptographic algorithm interface, a symmetric cryptographic algorithm interface, and a hashing algorithm interface.
[0013] Further, when the algorithm interface is an asymmetric cryptographic algorithm interface, the detection parameter further includes a private key access control code, and the corresponding private key access control code is set when injecting the key on the key index;
[0014] The verification of the algorithm interface of the password device under test by the hardware password module specifically includes:
[0015] Detecting the key generation of the algorithm interface:
[0016] Derive the first encryption public key and the first signature public key from the device under test, and derive the second encryption public key and the second signature key from the hardware password module;
[0017] Call the private key access permission interfaces of the password device under test and the hardware password module to obtain the private key access permissions respectively;
[0018] Call the password device under test to generate a key pair, calculate the corresponding public key using the private key. If the public key calculated by the private key is the same as the public key generated by the device under test, the key generation detection passes; otherwise, the key generation detection fails.
[0019] Further, the method further includes detecting the encryption operation of the algorithm interface, specifically including:
[0020] Generate the first plaintext data, encrypt the first plaintext data using the second encryption public key to obtain ciphertext data, decrypt the ciphertext data using the private key corresponding to the second encryption public key to obtain the second plaintext data, and compare whether the second plaintext data is the same as the first plaintext data. If they are the same, the encryption operation detection passes; otherwise, the encryption operation detection fails.
[0021] Further, the method further includes detecting the signature operation of the algorithm interface, specifically including:
[0022] Call the signature interface of the internal key of the password device under test to perform a signature operation on the first plaintext data to obtain a first signature value, where the internal key is the key injected on the key index;
[0023] Call the hardware password module, and use the first signature public key to perform a signature verification operation on the first signature value and the first plaintext data. If the signature verification passes, the signature operation detection passes; otherwise, the signature operation fails.
[0024] Further, the method further includes detecting the signature verification operation of the algorithm interface, specifically including:
[0025] Call the hardware password module, and use the key corresponding to the signature key index of the hardware password module to perform a signature operation on the first plaintext data to obtain a second signature value;
[0026] Call the second signature public key to perform signature verification operations on the second signature value and the first plaintext data. If the signature verification passes, the signature verification operation is detected to pass; otherwise, the signature verification operation is detected to fail.
[0027] Further, when the algorithm interface is a symmetric cryptography algorithm interface, the specific steps of verifying the algorithm interface of the password device to be tested through the hardware password module include:
[0028] Generate the third plaintext data and the initialization vector, and export the third encryption public key from the hardware password module;
[0029] Call the password device to be tested to generate a session key, and export it using the third encryption public key to obtain the session key ciphertext and the first session key handle;
[0030] Import the session key ciphertext into the hardware password module. The hardware password module decrypts the session key ciphertext using the private key corresponding to the third encryption public key to obtain the session key, and returns the second session key handle corresponding to the hardware password module;
[0031] Respectively call the password device to be tested and the hardware password module to perform cryptographic operations on the third plaintext data using the session key, and complete the algorithm interface detection after comparison.
[0032] Further, when the algorithm interface is a re-signature algorithm interface, the specific steps of verifying the algorithm interface of the password device to be tested through the hardware password module include:
[0033] Generate the fourth plaintext data, and export the fourth encryption public key from the hardware password module;
[0034] Call the password device to be tested to perform a hashing operation on the fourth plaintext data to obtain the first hash value, and call the hardware password module to perform a hashing operation on the fourth plaintext data to obtain the second hash value;
[0035] Compare whether the first hash value and the second hash value are equal. If they are equal, the hashing operation is detected to pass; otherwise, the hashing operation is detected to fail.
[0036] Further, the method further includes performing a preprocessing operation detection on the algorithm interface, specifically including:
[0037] Call the password device to be tested to perform a preprocessing operation on the fourth plaintext data and the fourth encryption public key to obtain the first preprocessing detection value, and call the hardware password module to perform a preprocessing operation on the fourth plaintext data and the fourth encryption public key to obtain the second preprocessing detection value;
[0038] Compare whether the first preprocessing detection value and the second preprocessing detection value are equal. If they are equal, the preprocessing operation is detected to pass; otherwise, the preprocessing operation is detected to fail.
[0039] The beneficial effects of the present invention are as follows:
[0040] (1) The present invention provides an automated detection method for a cryptographic device application interface. This method and system can effectively detect whether a cryptographic device complies with the interface specification, thereby improving the security and reliability of the cryptographic device.
[0041] (2) The present invention covers detections in multiple aspects such as asymmetric algorithms, symmetric algorithms, and hash algorithms to ensure the overall compliance of the cryptographic device application interface.
[0042] (3) The detection process of the present invention has a high degree of automation, reducing manual intervention and improving the detection efficiency and accuracy. Brief Description of the Drawings
[0043] Figure 1 is a flowchart of the automated detection method for the cryptographic device application interface according to an embodiment of the present invention;
[0044] Figure 2 is a flowchart of the asymmetric cryptographic algorithm detection according to an embodiment of the present invention;
[0045] Figure 3 is a flowchart of the symmetric cryptographic algorithm detection according to an embodiment of the present invention;
[0046] Figure 4 is a flowchart of the hash algorithm detection according to an embodiment of the present invention. Detailed Embodiments
[0047] The following uses specific specific examples to illustrate the embodiments of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0048] Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts fall within the scope of protection of the present invention.
[0049] In practical applications, how to effectively detect and verify whether a cryptographic device complies with relevant specifications is an urgent problem to be solved.
[0050] To solve the above technical problems, the following various embodiments of an automated detection method for a cryptographic device application interface of the present invention are proposed.
[0051] Embodiment 1
[0052] This embodiment provides an automated detection method for the application interface of a cryptographic device. This method needs to be implemented using a hardware cryptographic module (such as a cryptographic card). When initializing, the hardware cryptographic module needs to generate SM2 encryption keys, SM2 signature keys, RSA encryption keys, RSA signature keys, and private key access control codes on their specified indexes respectively, for detecting the correctness of the cryptographic operation interfaces of the cryptographic device.
[0053] Refer to Figure 1 , such as Figure 1 shown in the flowchart of the automated detection method for the application interface of the cryptographic device in this embodiment. This method specifically includes the following steps:
[0054] (1) Detection parameter configuration:
[0055] Configure the SDF dynamic library of the cryptographic device to be detected and the relevant parameters for cryptographic operation detection. The SDF dynamic library is the middleware for communication between the detection tool and the cryptographic device. The cryptographic operation detection parameters include the SM2 encryption key index, SM2 signature key index, RSA encryption key index, RSA signature key index, and private key access control code.
[0056] (2) Cryptographic device configuration:
[0057] Inject keys on the corresponding key indexes of the cryptographic device to be detected according to the above cryptographic operation detection parameters, and set the corresponding private key access control code.
[0058] (3) Execute detection:
[0059] The detection tool first communicates with the device to be detected by calling the SDF dynamic library, and respectively calls the asymmetric cryptographic algorithm interface, symmetric cryptographic algorithm interface, and hash algorithm interface of the device to be detected to obtain the operation results. Then, the detection tool calls the hardware cryptographic module to verify the operation results returned by the device to be detected. The specific detection process for the asymmetric cryptographic algorithm is as Figure 1 , the detection interface process for the symmetric algorithm is as Figure 2 , and the detection process for the hash algorithm is as Figure 3 .
[0060] (4) Detection report generation:
[0061] Based on the detection results of the above steps, conduct a comprehensive evaluation and output a detailed detection report.
[0062] This embodiment provides an automated detection method for the application interface of a cryptographic device. This method and system can effectively detect whether the cryptographic device complies with the interface specifications, thereby improving the security and reliability of the cryptographic device.
[0063] Embodiment 2
[0064] In this embodiment, taking the asymmetric cryptographic algorithm as an example, the automated detection method for the cryptographic device application interface provided in the foregoing embodiment will be described.
[0065] Referring to Figure 2 , as Figure 2 shown is the flowchart of the asymmetric cryptographic algorithm detection process in this embodiment. In this embodiment, taking the SM2 asymmetric algorithm as an example, the specific detection steps are as follows:
[0066] Obtain detection parameters, including the SDF dynamic library of the device under test, the SM2 encryption key index, the SM2 signature key index, and the private key access control code;
[0067] Generate test data, including randomly generated plaintext data R, the SM2 encryption public key EP and signature public key SP exported from the device under test, the SM2 encryption public key EP1 and signature public key SP1 exported from the cryptographic card;
[0068] Call the private key access permission interfaces of the cryptographic card and the device under test respectively to obtain the access permissions of the SM2 encryption private key and the SM2 signature private key;
[0069] The detection tool calls the SM2 key generation interface of the device under test to generate an SM2 key pair. The detection tool calculates the public key using the private key. If the public key calculated using the private key is the same as the public key generated by the device under test, the SM2 key generation interface passes the detection; otherwise, it fails.
[0070] The detection tool calls the device under test to perform SM2 encryption on R using the encryption public key EP1 to obtain ciphertext data. The detection tool calls the cryptographic card to decrypt the ciphertext data using the private key corresponding to the encryption public key EP1 to obtain plaintext data, and compares whether the plaintext data is equal to R. If they are equal, the SM2 encryption operation passes the detection; otherwise, it fails.
[0071] The detection tool calls the SM2 signature interface of the internal key (the key corresponding to the SM2 signature key index) of the device under test to perform a signature operation on R to obtain a signature value; the detection tool calls the cryptographic card to perform an SM2 signature verification operation on the signature value and R using the signature public key SP of the device under test. If the signature verification passes, the SM2 signature operation passes the detection; otherwise, it fails.
[0072] The detection tool calls the cryptographic card to perform a signature operation on R using the key corresponding to its SM2 signature key index to obtain a signature value; the detection tool calls the device under test to perform an SM2 signature verification operation on the signature value and R using the signature public key SP1 of the cryptographic card. If the signature verification passes, the SM2 signature verification operation passes the detection; otherwise, it fails.
[0073] It should be noted that other asymmetric algorithms, such as the RSA asymmetric algorithm, have the same detection process as the SM2 asymmetric algorithm.
[0074] Example 3
[0075] In this example, taking the symmetric cryptography algorithm as an example, the automated detection method for the cryptographic device application interface provided in the foregoing example will be described.
[0076] Refer to Figure 3 , as Figure 3 shown is the flow chart of the symmetric cryptography algorithm detection in this example. The specific detection steps are as follows:
[0077] Obtain detection parameters from the detection tool, including the SDF dynamic library of the cryptographic device to be detected;
[0078] Generate test data, including randomly generated plaintext data R, randomly generated initialization vector data IV, and SM2 encryption public key P exported from the cryptographic card;
[0079] Call the device to be detected to generate a session key and encrypt and export it using the external public key P to obtain the session key ciphertext SK and the session key handle KH;
[0080] Import the session key ciphertext SK into the cryptographic card. The cryptographic card decrypts SK using the private key corresponding to the public key P to obtain the session key, and returns the session key handle KH1 corresponding to the password card, so as to ensure that the session key data corresponding to KH and KH1 is the same;
[0081] The detection tool respectively calls the device to be detected and the cryptographic card to perform SM1 CMAC operation on R using the session key, and compares the result values of the operation. If they are consistent, the SM1 CMAC operation detection passes, otherwise it fails;
[0082] The detection tool calls the device under test to perform SM1 encryption operation on R using the session key to obtain ciphertext data. The detection tool calls the cryptographic card to perform SM1 decryption operation on the ciphertext data using the session key to obtain plaintext data, and compares whether the plaintext data is equal to R. If they are equal, the SM1 encryption operation detection passes, otherwise it fails;
[0083] The detection tool calls the cryptographic card to encrypt R using the session key to obtain ciphertext data. The detection tool calls the device to be detected to decrypt the ciphertext data using the session key to obtain plaintext data, and compares whether the plaintext data is equal to R. If they are equal, the SM1 decryption operation detection passes, otherwise it fails;
[0084] It should be noted that the detection method of the SM4 MAC operation is the same as that of the SM1 CMAC operation, the detection method of the SM4 encryption operation is the same as that of the SM1 encryption operation, and the detection method of the SM4 decryption operation is the same as that of the SM1 decryption operation.
[0085] Example 4
[0086] This embodiment takes the hashing algorithm as an example to illustrate the automated detection method for the cryptographic device application interface provided in the foregoing embodiment.
[0087] Refer to Figure 4 , as Figure 4 shown is the flowchart of the hashing algorithm detection process in this embodiment. The specific detection steps are as follows:
[0088] Obtain detection parameters from the detection tool, including the SDF dynamic library of the cryptographic device to be tested;
[0089] Generate test data, including randomly generating plaintext data R and exporting the SM2 encryption public key P from the cryptographic card;
[0090] The detection tool calls the cryptographic device to perform a hashing operation on R to obtain the hash value H. The detection tool calls the cryptographic card to perform a hashing operation on R to obtain the hash value H1. Compare whether the hash values H and H1 are equal. If they are equal, the SM3 hashing operation test passes; otherwise, the test fails;
[0091] The detection tool calls the cryptographic device to perform an SM2 preprocessing operation on R and P to obtain H. The detection tool calls the cryptographic card to perform an SM2 preprocessing operation on R and P to obtain H1. Compare whether H and H1 are equal. If they are equal, the SM2 preprocessing operation test passes; otherwise, the test fails.
[0092] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for automatic detection of a cryptographic device application interface, characterized in that: The method comprises: Configuring detection parameters for the detected cryptographic device, wherein the detection parameters include a key index involved in the cryptographic operation; Injecting a key into the key index of the cryptographic device under inspection; Verify the algorithm interface of the password device under test through the hardware password module and generate the test result; The hardware cryptographic module is used to generate a corresponding key on a specified key index and detect the correctness of the algorithm interface of the cryptographic device being tested.
2. The method for automatic detection of the application interface of a cryptographic device according to claim 1, characterized in that: The detection parameters also include an SDF dynamic library configured for the detected cryptographic device, and the SDF dynamic library is used as a middleware for the detection tool to communicate with the detected cryptographic device, and the detection tool communicates with the detected cryptographic device by calling the SDF dynamic library.
3. The method for automatic detection of the application interface of a cryptographic device according to claim 1, characterized in that: The key indexes involved in the cryptographic operation include an encryption key index and a signature key index, and the algorithm interface includes an asymmetric cryptographic algorithm interface, a symmetric cryptographic algorithm interface and a hash algorithm interface.
4. The method for automatic detection of the application interface of a cryptographic device according to claim 3, characterized in that: When the algorithm interface is an asymmetric cryptographic algorithm interface, the detection parameter further includes a private key access control code, and the corresponding private key access control code is set when the key is injected on the key index; The verification of the algorithm interface of the password device under inspection by the hardware password module specifically includes: Check the key generation of the algorithm interface: Exporting a first encryption public key and a first signature public key from the detected device, and exporting a second encryption public key and a second signature key from the hardware cryptographic module; Call the private key access permission interface of the password device and hardware password module to obtain the private key access permission respectively; Call the cryptographic device under test to generate a key pair, and use the private key to calculate the corresponding public key. If the public key calculated by the private key is the same as the public key generated by the device under test, the key generation test passes, otherwise the key generation test fails.
5. The method for automatic detection of the application interface of a cryptographic device according to claim 4, characterized in that: The method further includes performing encryption operation detection on the algorithm interface, specifically including: Generate first plaintext data, use the second encryption public key to encrypt the first plaintext data to obtain ciphertext data, use the private key corresponding to the second encryption public key to decrypt the ciphertext data to obtain second plaintext data, and compare whether the second plaintext data and the first plaintext data are the same. If they are the same, the encryption operation test passes, otherwise the encryption operation test fails.
6. The method for automatic detection of the application interface of a cryptographic device according to claim 5, characterized in that: The method further includes performing a signature operation detection on the algorithm interface, specifically including: Calling the signature interface of the internal key of the cryptographic device to be checked to perform a signature operation on the first plaintext data to obtain a first signature value, where the internal key is the key injected into the key index; The hardware cryptographic module is called, and the first signature public key is used to perform a signature verification operation on the first signature value and the first plaintext data. If the signature verification passes, the signature operation detection passes, otherwise the signature operation fails.
7. The method for automatic detection of the application interface of a cryptographic device according to claim 6, characterized in that: The method further includes performing a signature verification operation on the algorithm interface, specifically including: Calling the hardware cryptographic module, and using the key corresponding to the signature key index of the hardware cryptographic module to perform a signature operation on the first plaintext data to obtain a second signature value; The second signature public key is called to perform a signature verification operation on the second signature value and the first plaintext data. If the signature verification passes, the signature verification operation test passes, otherwise the signature verification operation test fails.
8. The method for automatic detection of the application interface of a cryptographic device according to claim 3, characterized in that: When the algorithm interface is a symmetric cryptographic algorithm interface, the verifying the algorithm interface of the cryptographic device under inspection by the hardware cryptographic module specifically includes: Generate third plaintext data and an initialization vector, and derive a third encryption public key from the hardware cryptographic module; Calling the cryptographic device under inspection to generate a session key, and deriving it using the third encryption public key to obtain the session key ciphertext and the first session key handle; The session key ciphertext is imported into the hardware cryptographic module, and the hardware cryptographic module uses the private key corresponding to the third encryption public key to decrypt the session key ciphertext to obtain the session key, and returns the second session key handle corresponding to the hardware cryptographic module; The cryptographic device under inspection and the hardware cryptographic module are respectively called to perform cryptographic operations on the third plaintext data using the session key, and the algorithm interface detection is completed after comparison.
9. The method for automatic detection of the application interface of a cryptographic device according to claim 3, characterized in that: When the algorithm interface is a secondary algorithm interface, the verifying the algorithm interface of the password device under inspection by the hardware password module specifically includes: Generate fourth plaintext data, and derive a fourth encryption public key from the hardware cryptographic module; Calling the checked cryptographic device to perform a hash operation on the fourth plaintext data to obtain a first hash value, and calling the hardware cryptographic module to perform a hash operation on the fourth plaintext data to obtain a second hash value; The first hash value and the second hash value are compared to see if they are equal. If they are equal, the hash operation test passes; otherwise, the hash operation test fails.
10. The method for automatic detection of the application interface of a cryptographic device according to claim 9, characterized in that: The method further includes performing a preprocessing operation detection on the algorithm interface, specifically including: Calling the cryptographic device to be checked to perform a preprocessing operation on the fourth plaintext data and the fourth encrypted public key to obtain a first preprocessing detection value, and calling the hardware cryptographic module to perform a preprocessing operation on the fourth plaintext data and the fourth encrypted public key to obtain a second preprocessing detection value; The first preprocessing detection value and the second preprocessing detection value are compared to see if they are equal. If they are equal, the preprocessing operation detection is passed; otherwise, the preprocessing operation detection is failed.