Static trusted verification function test method for trusted controller and related device
By establishing a network connection with the trusted controller on the test client, configuring and deleting static trusted verification policies, and performing related operation verification, the problem of low testing efficiency of trusted controllers in the existing technology is solved, automated testing and stability verification are realized, and testing efficiency and quality are improved.
Patent Information
- Application Number
- CN202510676970.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-05-26
AI Technical Summary
The trusted controllers in existing domestic trusted DCS have low testing efficiency and cannot realize automated testing, and cannot effectively verify the stability of the static trusted verification function.
Provide a static trusted verification function test method for trusted controllers. By establishing a network connection between the test client and the trusted controller to be tested, configuring a static trusted verification policy, tampering and performing operation verification, deleting the policy and verifying it again, and outputting the test results.
Automatic testing of the static trusted verification function of the trusted controller is realized, which improves the testing efficiency and quality, can effectively detect the stability of the static trusted verification function, and significantly reduces the testing cost.
Smart Images

Figure CN120196092A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of controller testing, and particularly relates to a static trust verification function testing method and related device for a trusted controller. Background Art
[0002] A distributed control system (DCS) is a new type of control device that uses computer technology to centrally monitor, operate, manage, and decentralize the control of industrial production processes; a trusted DCS is based on a traditional DCS and improves the security of the system by introducing a trusted computing system.
[0003] In a trusted controller in a domestic trusted DCS, trusted computing technology is introduced into a traditional controller; currently, the trusted controller in a domestic trusted DCS integrates a static trust verification function to perform static trust verification on important files of the trusted controller during writing and execution, and only files that are verified to be trusted are allowed to be executed, while untrusted files are prohibited from execution; among them, ordinary files marked with static trust verification policies are prohibited from being tampered with, which can effectively protect the security of system files and programs, prevent the execution of illegal programs, and ensure the integrity of important programs and configurations of the system.
[0004] In actual applications, after the static trust verification function of a trusted controller is deployed, it often needs to be tested; since the trusted controllers in existing domestic trusted DCSs generally use the Yihui operating system (a large real-time operating system for mission-critical applications), automated testing cannot be performed locally, and automated testing through shell scripts (a text file for automatically executing command sequences) is also restricted by the small number of commands provided by the system and cannot achieve the expected effect; in addition, the speed of traditional manual testing is relatively slow, problems in functions cannot be discovered in the shortest time, and the stability of the static trust verification function cannot be tested. Summary of the Invention
[0005] Aiming at the technical problems existing in the prior art, the present invention provides a static trust verification function testing method and related device for a trusted controller to solve the technical problems of low testing efficiency and inability to achieve the expected testing effect of existing trusted controllers.
[0006] To achieve the above object, the technical solution adopted by the present invention is as follows: The present invention provides a static trust verification function testing method for a trusted controller, which is applied to a test client, and the test client establishes a network connection with the to-be-tested trusted controller; The static trust verification function testing method for a trusted controller includes: Configure static trusted verification policies for predetermined ordinary files and predetermined executable files respectively, to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy; Based on the ordinary file configured with a static trusted verification policy, verify the tampering operation on the to-be-tested trusted controller to obtain the tampering verification result of the ordinary file configured with a static trusted verification policy; based on the executable file configured with a static trusted verification policy, verify the execution operation on the to-be-tested trusted controller to obtain the execution verification result of the executable file configured with a static trusted verification policy; Perform static trusted verification policy deletion operations on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively, to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted; Based on the ordinary file with the verification policy deleted, verify the tampering operation on the to-be-tested trusted controller to obtain the tampering verification result of the ordinary file with the verification policy deleted; based on the executable file with the verification policy deleted, verify the execution operation on the to-be-tested trusted controller to obtain the execution verification result of the executable file with the verification policy deleted; Output the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the static trusted verification function test result of the to-be-tested trusted controller.
[0007] Further, the predetermined ordinary files include the configuration file and script file of the to-be-tested trusted controller; the predetermined executable files include the runnable process file and runnable command file of the to-be-tested trusted controller.
[0008] Further, configuring static trusted verification policies for the predetermined ordinary files and predetermined executable files respectively, to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy, includes: Use a predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary files and predetermined executable files respectively, to obtain the trusted reference value of the ordinary file and the trusted reference value of the executable file; Configure the predetermined trusted verification algorithm and the trusted reference value of the ordinary file in the predetermined ordinary file, to obtain an ordinary file configured with a static trusted verification policy; Configure the predetermined trusted verification algorithm and the trusted reference value of the executable file in the predetermined executable file, to obtain an executable file configured with a static trusted verification policy.
[0009] Further, based on ordinary files configured with static trusted verification policies, perform tampering operation verification on the to-be-tested trusted controller to obtain the tampering verification result of the ordinary files configured with static trusted verification policies, including: Send an ordinary file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the ordinary file configured with the static trusted verification policy, and obtain the tampering verification result of the ordinary file configured with the static trusted verification policy; wherein, the tampering verification result of the ordinary file configured with the static trusted verification policy includes the file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the ordinary file configured with the static trusted verification policy.
[0010] Further, based on executable files configured with static trusted verification policies, perform execution operation verification on the to-be-tested trusted controller to obtain the execution verification result of the executable files configured with static trusted verification policies, including: Send an executable file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy, and obtain the execution verification result of the executable file configured with the static trusted verification policy; wherein, the execution verification result of the executable file configured with the static trusted verification policy includes the file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy.
[0011] Further, the static trusted verification function test result of the to-be-tested trusted controller is output in the format of HyperText Markup Language.
[0012] The present invention also provides a static trusted verification function test system for a trusted controller, which is used for a test client, and the test client establishes a network connection with the to-be-tested trusted controller; The static trusted verification function test system for a trusted controller includes: A policy configuration module, which is used to respectively configure static trusted verification policies for a predetermined ordinary file and a predetermined executable file to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy; A first verification module, which is used to perform tampering operation verification on the to-be-tested trusted controller based on the ordinary file configured with the static trusted verification policy to obtain the tampering verification result of the ordinary file configured with the static trusted verification policy; and perform execution operation verification on the to-be-tested trusted controller based on the executable file configured with the static trusted verification policy to obtain the execution verification result of the executable file configured with the static trusted verification policy; A policy deletion module is used to perform static trusted verification policy deletion operations on ordinary files configured with static trusted verification policies and executable files configured with static trusted verification policies respectively, to obtain ordinary files with the verification policies deleted and executable files with the verification policies deleted; A second verification module is used to verify the tampering operation of the to-be-tested trusted controller based on the ordinary file with the verification policy deleted, to obtain the tampering verification result of the ordinary file with the verification policy deleted; and verify the execution operation of the to-be-tested trusted controller based on the executable file with the verification policy deleted, to obtain the execution verification result of the executable file with the verification policy deleted; A result output module is used to output the tampering verification result of the ordinary file configured with the static trusted verification policy, the execution verification result of the executable file configured with the static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the static trusted verification function test result of the to-be-tested trusted controller.
[0013] The present invention also provides an electronic device, including: A processor, suitable for executing a computer program; A computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by the processor, it executes the static trusted verification function test method for a trusted controller as described above.
[0014] The present invention also provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, it implements the static trusted verification function test method for a trusted controller as described above.
[0015] The present invention also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the static trusted verification function test method for a trusted controller as described above.
[0016] Compared with the prior art, the beneficial effects of the present invention are: The static trusted verification function test method for a trusted controller provided by the present invention establishes a network connection between a test client and the to-be-tested trusted controller, and executes the specific steps of the static trusted verification function test method on the test client to automate the test of the static trusted verification function of the to-be-tested trusted controller. There is no need for manual setting of commands at the underlying layer of the to-be-tested trusted controller to verify whether the function is normal, saving manpower and time, effectively improving the test efficiency, and at the same time being able to accurately achieve the expected test effect. Specifically, by respectively configuring static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file, the to-be-tested trusted controller is verified for tampering operations based on the ordinary file configured with the static trusted verification policy, and the to-be-tested trusted controller is verified for execution operations based on the executable file configured with the static trusted verification policy. Secondly, by respectively performing deletion operations on the static trusted verification policies for the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy, and respectively performing tampering operation verification and execution operation verification, the normal operation of the deletion function of the static trusted verification policy is tested. The present invention can effectively improve the test speed and test quality of the static trusted verification function of the trusted controller, and at the same time can meet the test of the stability of the static trusted verification function of the trusted controller, significantly reducing the test cost.
[0017] The static trusted verification function test system, electronic device, computer-readable storage medium and computer program product for a trusted controller provided by the present invention have all the advantages of the above-mentioned static trusted verification function test method for a trusted controller. Description of the Drawings
[0018] Figure 1 is a flowchart of the static trusted verification function test method for a trusted controller provided by the present invention; Figure 2 is a flowchart of the static trusted verification function test method for a trusted controller provided in Embodiment 1; Figure 3 is a structural block diagram of the static trusted verification function test system for a trusted controller provided in Embodiment 2; Figure 4 is a structural block diagram of the electronic device provided in Embodiment 3. Detailed Embodiments
[0019] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention clearer, the following specific embodiments are used to further elaborate on the present invention in detail. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0020] As shown in the Figure 1 drawings, the Figure 1The flowchart of a static trusted verification function test method for a trusted controller provided by the present invention is shown; the static trusted verification function test method for the trusted controller is applied to a test client, and the test client establishes a network connection with the to-be-tested trusted controller; the method includes the following steps: Step 100: Configure static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy.
[0021] Step 200: Based on the ordinary file configured with a static trusted verification policy, perform a tampering operation verification on the to-be-tested trusted controller to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy; based on the executable file configured with a static trusted verification policy, perform an execution operation verification on the to-be-tested trusted controller to obtain an execution verification result of the executable file configured with a static trusted verification policy.
[0022] Step 300: Perform static trusted verification policy deletion operations on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted.
[0023] Step 400: Based on the ordinary file with the verification policy deleted, perform a tampering operation verification on the to-be-tested trusted controller to obtain a tampering verification result of the ordinary file with the verification policy deleted; based on the executable file with the verification policy deleted, perform an execution operation verification on the to-be-tested trusted controller to obtain an execution verification result of the executable file with the verification policy deleted.
[0024] Step 500: Output the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted as the static trusted verification function test result of the to-be-tested trusted controller.
[0025] In the above embodiment, after the test client establishes a network connection with the to-be-tested trusted controller, the following test process is automatically executed: configure static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file respectively, and perform tampering operation verification and execution operation verification respectively; perform static trusted verification policy deletion operations on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively, and then perform tampering operation verification and execution operation verification respectively; no underlying command operations are required throughout the test, significantly improving the test efficiency and accurately covering the full-process test requirements of policy configuration, execution verification, and policy lifecycle management.
[0026] The following uses some specific embodiments to further explain the static trusted verification function test method provided by the present invention for a trusted controller: Embodiment 1 Embodiment 1 of the present invention provides a static trusted verification function test method for a trusted controller. The method is applied to a test client, and the test client establishes a network connection with the to-be-tested trusted controller.
[0027] It should be noted that the test client executes a preset Python (a high-level programming language) program to implement the steps of the static trusted verification function test method; the test client establishes a network connection with the to-be-tested trusted controller through Telnet (Teletype Network, a remote login protocol); among them, in the process of the test client establishing a network connection with the to-be-tested trusted controller through Telnet, the connection parameters of the to-be-tested trusted controller need to be pre-configured in the configuration file of the test client; the connection parameters of the to-be-tested trusted controller include the IP (Internet Protocol) address and account password of the to-be-tested trusted controller; the configuration file of the test client is also pre-set with the number of loop times for executing the test; a static trusted verification module is pre-installed in the to-be-tested trusted controller, and the static trusted verification module is used to implement the static trusted verification function.
[0028] As shown in the appendix Figure 2 The steps of the static trusted verification function test method are specifically as follows: Step 1: Configure static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy. Among them, the pre-determined ordinary files include the configuration file and script file of the to-be-tested trusted controller, such as the / etc / passwd file (a file used to store user account information in the trusted controller, containing the basic information of all users in the trusted controller) and the / etc / startup.sh file (a custom startup script used to execute initialization tasks when the trusted controller starts); the pre-determined executable files include the runnable process file and runnable command file of the to-be-tested trusted controller.
[0029] It should be noted that the static trusted verification function of the trusted controller uses trusted computing technology to perform trusted measurement verification on predetermined applications or files to ensure the integrity of the predetermined applications and files; the applications or files configured with static trusted verification policies will be protected by the static trusted verification function of the trusted controller; the process of configuring the static trusted verification policy is as follows: through the static trusted verification policy configuration command provided by the static trusted verification function of the trusted controller, the static trusted verification policy is configured for the specified application or file to be protected.
[0030] Specifically, the process of configuring static trusted verification policies for predetermined ordinary files and predetermined executable files is as follows: Step 101: Use a predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary file and the predetermined executable file to obtain the trusted reference value of the ordinary file and the trusted reference value of the executable file; among them, the predetermined trusted verification algorithm is, for example, SHA-256 (Secure Hash Algorithm 256-bit, an encryption hash function), SM3 (SM3 Cryptographic Algorithm, a cryptographic hash function standard).
[0031] Step 102: Use the static trusted verification policy configuration command provided by the static trusted verification function to configure the predetermined trusted verification algorithm and the trusted reference value of the ordinary file in the predetermined ordinary file to obtain an ordinary file configured with a static trusted verification policy.
[0032] Step 103: Use the static trusted verification policy configuration command provided by the static trusted verification function to configure the predetermined trusted verification algorithm and the trusted reference value of the executable file in the predetermined executable file to obtain an executable file configured with a static trusted verification policy.
[0033] Step 2: Turn on the static trusted verification module of the trusted controller to be tested so that the static trusted verification module is in an on state.
[0034] Step 3: With the static trusted verification module in the enabled state, verify the tampering operation on the to-be-tested trusted controller based on the ordinary file configured with the static trusted verification policy, and obtain the tampering verification result of the ordinary file configured with the static trusted verification policy. Specifically, send the ordinary file configured with the static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the ordinary file configured with the static trusted verification policy, and record the file tampering action log to obtain the tampering verification result of the ordinary file configured with the static trusted verification policy; among them, the tampering verification result of the ordinary file configured with the static trusted verification policy includes the file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the ordinary file configured with the static trusted verification policy.
[0035] It should be noted that after the static trusted verification policy is configured for the pre-determined ordinary file, that is, the ordinary file configured with the static trusted verification policy will be protected by the static trusted verification module and cannot be tampered with at this time; when attempting to perform a file tampering operation on the ordinary file configured with the static trusted verification policy, a file tampering failure will be prompted and the file tampering action log will be recorded.
[0036] Step 4: Verify the execution operation on the to-be-tested trusted controller based on the executable file configured with the static trusted verification policy, and obtain the execution verification result of the executable file configured with the static trusted verification policy. Specifically, send the executable file configured with the static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy, record the file execution operation log, and obtain the execution verification result of the executable file configured with the static trusted verification policy; among them, the execution verification result of the executable file configured with the static trusted verification policy includes the file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy.
[0037] It should be noted that the process of verifying the execution operation on the to-be-tested trusted controller based on the executable file configured with the static trusted verification policy is mainly to verify the impact of the static trusted verification function of the to-be-tested trusted controller on the executable file configured with the static trusted verification policy; if the trusted state of the executable file configured with the static trusted verification policy is trusted, then when the to-be-tested trusted controller performs an execution operation on the executable file configured with the static trusted verification policy, the execution result is successful; if the trusted state of the executable file configured with the static trusted verification policy is untrusted, then when the to-be-tested trusted controller performs an execution operation on the executable file configured with the static trusted verification policy, the execution result is failed; by recording the file execution operation log, the execution verification result of the executable file configured with the static trusted verification policy can be obtained.
[0038] It should also be noted that when the trusted status of the pre-determined executable file is trusted, the pre-determined executable file cannot be tampered with but can be executed normally; when the trusted status of the pre-determined executable file is untrusted, the pre-determined executable file cannot be tampered with and cannot be executed normally.
[0039] Step 5: Perform static trusted verification policy deletion operations on the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy respectively, to obtain the ordinary file with the verification policy deleted and the executable file with the verification policy deleted. Among them, by performing static trusted verification policy deletion operations on the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy respectively, to verify whether the deletion function of the static trusted verification module in the to-be-tested trusted controller is normal; at the same time, it can avoid the residue of the static trusted verification policy in the executable file.
[0040] Step 6: With the static trusted verification module in the enabled state, perform tampering operation verification on the to-be-tested trusted controller based on the ordinary file with the verification policy deleted, to obtain the tampering verification result of the ordinary file with the verification policy deleted. Among them, the process of performing tampering operation verification on the to-be-tested trusted controller based on the ordinary file with the verification policy deleted is basically the same as the operation in Step 3 above, which will not be elaborated here.
[0041] Step 7: With the static trusted verification module in the enabled state, perform execution operation verification on the to-be-tested trusted controller based on the executable file with the verification policy deleted, to obtain the execution verification result of the executable file with the verification policy deleted. Among them, the process of performing execution operation verification on the to-be-tested trusted controller based on the executable file with the verification policy deleted is basically the same as the operation in Step 4 above, which will not be elaborated here.
[0042] Step 8: Reconfigure the static trusted verification policy for the ordinary file with the verification policy deleted and the executable file with the verification policy deleted, to obtain the ordinary file with the static trusted verification policy reconfigured and the executable file with the static trusted verification policy reconfigured. It should be noted that the process of reconfiguring the static trusted verification policy for the ordinary file with the verification policy deleted and the executable file with the verification policy deleted is basically the same as the operation in Step 1 above, which will not be elaborated here.
[0043] Step 9: Turn off the static trusted verification module of the to-be-tested trusted controller to make the static trusted verification module in the closed state.
[0044] Step 10: With the static trusted verification module in the closed state, tamper with the ordinary file with the static trusted verification policy reconfigured and the executable file with the static trusted verification policy reconfigured, to obtain the tampered ordinary file and the tampered executable file.
[0045] Specifically, when the static trusted verification module is in the closed state, perform tampering operations on the ordinary file with the reconfigured static trusted verification policy and the executable file with the reconfigured static trusted verification policy, so as to add preset characters to the ordinary file with the reconfigured static trusted verification policy and the executable file with the reconfigured static trusted verification policy respectively, causing the file content to change, and obtaining the tampered ordinary file and the tampered executable file.
[0046] It should be noted that the trusted states of both the tampered ordinary file and the tampered executable file are untrusted. Furthermore, based on the untrusted files, test the static trusted verification function of the device under test for trusted control.
[0047] Step 11: Re-enable the static trusted verification module of the device under test for trusted control to make the static trusted verification module in the enabled state.
[0048] Step 12: When the static trusted verification module is in the enabled state, based on the tampered ordinary file, perform tampering operation verification on the device under test for trusted control to obtain the tampering verification result of the untrusted ordinary file. It should be noted that the process of performing tampering operation verification on the device under test for trusted control based on the tampered ordinary file is basically the same as the operation in Step 3 or Step 6 above, and will not be elaborated here.
[0049] Step 13: When the static trusted verification module is in the enabled state, based on the tampered executable file, perform execution operation verification on the device under test for trusted control to obtain the execution verification result of the untrusted executable file. It should be noted that the process of performing execution operation verification on the device under test for trusted control based on the tampered executable file is basically the same as the operation in Step 4 or Step 7 above, and will not be elaborated here.
[0050] Step 14: Restore the tampered ordinary file and the tampered executable file. It should be noted that the process of restoring the tampered ordinary file and the tampered executable file is the reverse of the operation in Step 10, that is, deleting the preset characters in the tampered ordinary file and the tampered executable file.
[0051] Step 15: Return the tampering verification result of the ordinary file with the configured static trusted verification policy, the execution verification result of the executable file with the configured static trusted verification policy, the tampering verification result of the ordinary file with the deleted verification policy, the execution verification result of the executable file with the deleted verification policy, the tampering verification result of the untrusted ordinary file, and the execution verification result of the untrusted executable file, and save them to a preset log file; output the preset log file in the format of HyperText Markup Language to obtain the test result of the static trusted verification function of the device under test for trusted control.
[0052] In this Embodiment 1, a preset Python program is executed by a test client to implement a static trusted verification function test method, thereby automatically testing the static trusted verification function of a to-be-tested trusted controller. This can effectively improve the test efficiency and the quality of test results for the static trusted verification function of the trusted controller in a domestic trusted DCS, and can lock the location where the problem occurs through the test results of the static trusted verification function of the to-be-tested trusted controller. At the same time, it can meet the test of the stability of the static trusted verification function of the trusted controller in a domestic trusted DCS and significantly reduce the test cost.
[0053] Embodiment 2 This Embodiment 2 provides a static trusted verification function test system for a trusted controller, which is used for a test client. The test client establishes a network connection with the to-be-tested trusted controller; as shown in the appendix Figure 3 The static trusted verification function test system for the trusted controller includes a policy configuration module, a first verification module, a policy deletion module, a second verification module, and a result output module.
[0054] The policy configuration module is used to respectively configure static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file, to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy. The first verification module is used to verify the tampering operation of the to-be-tested trusted controller based on the ordinary file configured with a static trusted verification policy, to obtain the tampering verification result of the ordinary file configured with a static trusted verification policy; verify the execution operation of the to-be-tested trusted controller based on the executable file configured with a static trusted verification policy, to obtain the execution verification result of the executable file configured with a static trusted verification policy. The policy deletion module is used to respectively perform static trusted verification policy deletion operations on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy, to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted. The second verification module is used to verify the tampering operation of the to-be-tested trusted controller based on the ordinary file with the verification policy deleted, to obtain the tampering verification result of the ordinary file with the verification policy deleted; verify the execution operation of the to-be-tested trusted controller based on the executable file with the verification policy deleted, to obtain the execution verification result of the executable file with the verification policy deleted. The result output module is used to output the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the test results of the static trusted verification function of the to-be-tested trusted controller.
[0055] Optionally, the predetermined ordinary files include the configuration file and the script file of the trusted controller to be tested; the predetermined executable files include the runnable process file and the runnable command file of the trusted controller to be tested.
[0056] Optionally, the policy configuration module is specifically configured to: use the predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary files and the predetermined executable files respectively, to obtain the trusted benchmark values of the ordinary files and the trusted benchmark values of the executable files; configure the predetermined trusted verification algorithm and the trusted benchmark values of the ordinary files in the predetermined ordinary files to obtain ordinary files configured with static trusted verification policies; configure the predetermined trusted verification algorithm and the trusted benchmark values of the executable files in the predetermined executable files to obtain executable files configured with static trusted verification policies.
[0057] Optionally, the first verification module is specifically configured to: send the ordinary files configured with static trusted verification policies to the trusted controller to be tested, so that the trusted controller to be tested performs file tampering operations on the ordinary files configured with static trusted verification policies, to obtain the file tampering verification results of the ordinary files configured with static trusted verification policies; wherein, the file tampering verification results of the ordinary files configured with static trusted verification policies include the file tampering action logs recorded when the trusted controller to be tested performs file tampering operations on the ordinary files configured with static trusted verification policies.
[0058] Optionally, the first verification module is specifically configured to: send the executable files configured with static trusted verification policies to the trusted controller to be tested, so that the trusted controller to be tested executes the executable files configured with static trusted verification policies, to obtain the execution verification results of the executable files configured with static trusted verification policies; wherein, the execution verification results of the executable files configured with static trusted verification policies include the file execution operation logs recorded when the trusted controller to be tested executes the executable files configured with static trusted verification policies.
[0059] Optionally, the static trusted verification function test results of the trusted controller to be tested are output in the format of HyperText Markup Language.
[0060] Optionally, the static trusted verification function test system for a trusted controller described in Embodiment 2 further includes a file tampering module and a third verification module; the file tampering module is used to reconfigure the static trusted verification policy for a normal file with the verification policy deleted and an executable file with the verification policy deleted, to obtain a normal file with the reconfigured static trusted verification policy and an executable file with the reconfigured static trusted verification policy; and to tamper with the normal file with the reconfigured static trusted verification policy and the executable file with the reconfigured static trusted verification policy, to obtain a tampered normal file and a tampered executable file. The third verification module is used to verify the tampering operation on the to-be-tested trusted controller based on the tampered normal file, to obtain the tampering verification result of the untrusted normal file; and to verify the execution operation on the to-be-tested trusted controller based on the tampered executable file, to obtain the execution verification result of the untrusted executable file.
[0061] It should be noted that the result output module is further used to output the tampering verification result of the untrusted normal file and the execution verification result of the untrusted executable file.
[0062] Specifically, the result output module is used to return the tampering verification result of the normal file configured with the static trusted verification policy, the execution verification result of the executable file configured with the static trusted verification policy, the tampering verification result of the normal file with the verification policy deleted, the execution verification result of the executable file with the verification policy deleted, the tampering verification result of the untrusted normal file, and the execution verification result of the untrusted executable file, and save them to a preset log file; and to output the preset log file in the format of HyperText Markup Language, to obtain the static trusted verification function test result of the to-be-tested trusted controller.
[0063] Embodiment 3 As shown in the Figure 4 accompanying drawings, Embodiment 3 provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of the static trusted verification function test method for a trusted controller when executing the computer program; or, the processor implements the functions of each module in the above-mentioned static trusted verification function test system for a trusted controller when executing the computer program.
[0064] Exemplarily, the computer program can be divided into one or more modules / units, and the one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of completing preset functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.
[0065] The electronic device may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above are examples of electronic devices and do not constitute a limitation on the electronic device. It may include more components than the above, or combine certain components, or different components. For example, the electronic device may further include a communication interface, an input / output device, a network access device, and a bus.
[0066] The so-called processor may be a central processing unit, or may also be other general-purpose processors, digital signal processors, application-specific integrated circuits, off-the-shelf programmable gate arrays, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc. The processor is the control center of the electronic device and connects all parts of the entire electronic device through various communication interfaces and lines.
[0067] The memory may be used to store the computer program and / or module. The processor realizes various functions of the electronic device by running or executing the computer program and / or module stored in the memory, and by calling the data stored in the memory.
[0068] The memory may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created according to the use of the mobile phone (such as audio data, a phone book, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card, a secure digital card, a flash memory card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0069] Embodiment 4 Embodiment 4 of the present invention further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the static trusted verification function test method for a trusted controller are realized.
[0070] If the modules / units integrated in the static trusted verification function test system for a trusted controller are implemented in the form of software function units and sold or used as independent products, they may be stored in a computer-readable storage medium.
[0071] Based on such understanding, all or part of the processes in the above-mentioned static trusted verification function test method for a trusted controller of the present invention can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned static trusted verification function test method for a trusted controller can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or preset intermediate form, etc.
[0072] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory, random access memory, electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0073] Embodiment 5 Embodiment 5 of the present invention provides a computer product. The computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium; a processor of an electronic device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the electronic device can execute the static trusted verification function test method described in Embodiment 1, which will not be elaborated here.
[0074] It should be noted that those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned method embodiments.
[0075] The above-mentioned embodiments are only one of the implementation manners capable of implementing the technical solution of the present invention. The scope of protection required by the present invention is not only limited by this embodiment, but also includes any changes, substitutions, and other implementation manners that are easily conceivable by those skilled in the art within the technical scope disclosed by the present invention.
Claims
1. A static trusted verification function test method for a trusted controller, characterized in that, Applied to a test client, the test client establishes a network connection with the trusted controller to be tested; A static trusted verification function test method for a trusted controller, including: Configuring static trusted verification policies for a predetermined ordinary file and a predetermined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy; Based on the ordinary file configured with a static trusted verification policy, performing a tampering operation verification on the trusted controller to be tested to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy; based on the executable file configured with a static trusted verification policy, performing an execution operation verification on the trusted controller to be tested to obtain an execution verification result of the executable file configured with a static trusted verification policy; Performing a static trusted verification policy deletion operation on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted; Based on the ordinary file with the verification policy deleted, performing a tampering operation verification on the trusted controller to be tested to obtain a tampering verification result of the ordinary file with the verification policy deleted; based on the executable file with the verification policy deleted, performing an execution operation verification on the trusted controller to be tested to obtain an execution verification result of the executable file with the verification policy deleted; Outputting the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted as the static trusted verification function test result of the trusted controller to be tested.
2. The static trusted verification function test method for a trusted controller according to claim 1, characterized in that The predetermined ordinary files include the configuration file and script file of the trusted controller to be tested; the predetermined executable files include the runnable process file and runnable command file of the trusted controller to be tested.
3. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that Configuring static trusted verification policies for a predetermined ordinary file and a predetermined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy, including: Using a predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary file and the predetermined executable file respectively to obtain a trusted reference value of the ordinary file and a trusted reference value of the executable file; Configuring the predetermined trusted verification algorithm and the trusted reference value of the ordinary file in the predetermined ordinary file to obtain an ordinary file configured with a static trusted verification policy; Configuring the predetermined trusted verification algorithm and the trusted reference value of the executable file in the predetermined executable file to obtain an executable file configured with a static trusted verification policy.
4. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that Based on the ordinary file configured with a static trusted verification policy, performing a tampering operation verification on the trusted controller to be tested to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy, including: Send a normal file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the normal file configured with the static trusted verification policy, and obtains a verification result of the normal file tampering configured with the static trusted verification policy; wherein, the verification result of the normal file tampering configured with the static trusted verification policy includes a file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the normal file configured with the static trusted verification policy.
5. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that Based on an executable file configured with a static trusted verification policy, perform an execution operation verification on the to-be-tested trusted controller, and obtain an execution verification result of the executable file configured with the static trusted verification policy, including: Send an executable file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy, and obtains an execution verification result of the executable file configured with the static trusted verification policy; wherein, the execution verification result of the executable file configured with the static trusted verification policy includes a file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy.
6. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that, The static trusted verification function test result of the to-be-tested trusted controller is output in the format of HyperText Markup Language.
7. A static trusted verification function test system for a trusted controller, characterized in that, For the test client, the test client establishes a network connection with the to-be-tested trusted controller; The static trusted verification function test system for the trusted controller includes: A policy configuration module, which is used to respectively configure static trusted verification policies for a predetermined normal file and a predetermined executable file, and obtain a normal file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy; A first verification module, which is used to perform a tampering operation verification on the to-be-tested trusted controller based on the normal file configured with the static trusted verification policy, and obtain a verification result of the normal file tampering configured with the static trusted verification policy; perform an execution operation verification on the to-be-tested trusted controller based on the executable file configured with the static trusted verification policy, and obtain an execution verification result of the executable file configured with the static trusted verification policy; A policy deletion module, which is used to respectively perform static trusted verification policy deletion operations on the normal file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy, and obtain a normal file with the verification policy deleted and an executable file with the verification policy deleted; A second verification module, which is used to perform a tampering operation verification on the to-be-tested trusted controller based on the normal file with the verification policy deleted, and obtain a verification result of the normal file tampering with the verification policy deleted; perform an execution operation verification on the to-be-tested trusted controller based on the executable file with the verification policy deleted, and obtain an execution verification result of the executable file with the verification policy deleted; A result output module, which is used to output the verification result of the normal file tampering configured with the static trusted verification policy, the execution verification result of the executable file configured with the static trusted verification policy, the verification result of the normal file tampering with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the static trusted verification function test result of the to-be-tested trusted controller.
8. An electronic device, characterized in that, Including: A processor, suitable for executing a computer program; A computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by the processor, it executes the static trusted verification function test method for a trusted controller according to any one of claims 1-6.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the static trusted verification function test method for a trusted controller according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by the processor, it implements the static trusted verification function test method for a trusted controller according to any one of claims 1-6.
Citation Information
Patent Citations
Security protection method and system for real-time operating system of trusted DCS (Distributed Control System) controller and medium
CN117195231A
DCS controller trusted policy downloading method, device and equipment and storage medium
CN117647965A
Trusted DCS controller trusted function test method, electronic equipment and storage medium
CN117970907A
Web-based static trusted verification function test method and system
CN118897795A
DCS controller application program access control automatic test method and system
CN119271558A