Static Trusted Verification Function Testing Method and Related Devices for a Trusted Controller
By establishing a network connection with the trusted controller on the test client, configuring a static trusted verification strategy and performing operation verification, the problem of low testing efficiency in domestic trusted DCS is solved, and efficient and accurate static trusted verification function testing is achieved.
Patent Information
- Application Number
- CN202510676970.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-26
AI Technical Summary
The trusted controllers in existing domestic trusted DCS are inefficient in static trusted verification function testing, unable to implement automated testing, and traditional manual testing is slow, so it is impossible to quickly discover functional problems and test stability.
By establishing a network connection between the test client and the trusted controller, configuring a static trusted verification policy, tampering with and performing operations on ordinary files and executable files, deleting the verification policy and verifying it again, and outputting the test results.
It realizes automated testing of the static trusted verification function of the trusted controller, improves testing efficiency and quality, reduces testing costs, and can quickly discover functional problems and test stability.
Smart Images

Figure CN120196092B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of controller testing, and particularly relates to a static trust verification function testing method and related device for a trusted controller. Background Art
[0002] A distributed control system (DCS) is a new type of control device that uses computer technology to centrally monitor, operate, manage, and decentralize the control of industrial production processes; a trusted DCS is based on a traditional DCS and improves the system's security by introducing a trusted computing system.
[0003] In the trusted controller of domestic trusted DCS, trusted computing technology is introduced into the traditional controller; currently, the trusted controller in domestic trusted DCS integrates a static trust verification function to perform static trust verification on important files of the trusted controller during writing and execution, and only files that are verified to be trusted are allowed to execute, while untrusted files are prohibited from execution; among them, ordinary files marked with static trust verification policies are prohibited from being tampered with, which can effectively protect the security of system files and programs, prevent the execution of illegal programs, and ensure the integrity of important programs and configurations of the system.
[0004] In practical applications, after the static trust verification function of the trusted controller is deployed, it often needs to be tested; since the trusted controllers in existing domestic trusted DCS generally use the Yihui operating system (a large real-time operating system for mission-critical applications), it cannot be automatically tested locally, and automated testing through shell scripts (a text file for automatically executing command sequences) is also restricted by the few commands provided by the system and cannot achieve the expected effect; in addition, the speed of traditional manual testing is relatively slow, functional problems cannot be found in the fastest time, and the stability of the static trust verification function cannot be tested. Summary of the Invention
[0005] Aiming at the technical problems existing in the prior art, the present invention provides a static trust verification function testing method and related device for a trusted controller to solve the technical problems of low testing efficiency and inability to achieve the expected testing effect of existing trusted controllers.
[0006] To achieve the above object, the technical solution adopted by the present invention is as follows:
[0007] The present invention provides a static trust verification function testing method for a trusted controller, which is applied to a test client, and the test client establishes a network connection with the to-be-tested trusted controller;
[0008] Static Trusted Verification Function Testing Method for a Trusted Controller, including:
[0009] Configure static trusted verification policies for a predetermined ordinary file and a predetermined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy;
[0010] Based on the ordinary file configured with a static trusted verification policy, perform a tampering operation verification on the to-be-tested trusted controller to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy; based on the executable file configured with a static trusted verification policy, perform an execution operation verification on the to-be-tested trusted controller to obtain an execution verification result of the executable file configured with a static trusted verification policy;
[0011] Perform a static trusted verification policy deletion operation on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted;
[0012] Based on the ordinary file with the verification policy deleted, perform a tampering operation verification on the to-be-tested trusted controller to obtain a tampering verification result of the ordinary file with the verification policy deleted; based on the executable file with the verification policy deleted, perform an execution operation verification on the to-be-tested trusted controller to obtain an execution verification result of the executable file with the verification policy deleted;
[0013] Output the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted as the static trusted verification function test result of the to-be-tested trusted controller.
[0014] Furthermore, the predetermined ordinary files include the configuration file and script file of the to-be-tested trusted controller; the predetermined executable files include the runnable process file and runnable command file of the to-be-tested trusted controller.
[0015] Furthermore, configuring static trusted verification policies for the predetermined ordinary file and the predetermined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy includes:
[0016] Use a predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary file and the predetermined executable file respectively to obtain the trusted benchmark value of the ordinary file and the trusted benchmark value of the executable file;
[0017] Configure a predetermined trusted verification algorithm and a trusted benchmark value of a normal file in a predetermined normal file to obtain a normal file configured with a static trusted verification policy;
[0018] Configure a predetermined trusted verification algorithm and a trusted benchmark value of an executable file in a predetermined executable file to obtain an executable file configured with a static trusted verification policy.
[0019] Furthermore, based on the normal file configured with a static trusted verification policy, verify the tampering operation of the to-be-tested trusted controller to obtain a tampering verification result of the normal file configured with a static trusted verification policy, including:
[0020] Send the normal file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the normal file configured with a static trusted verification policy to obtain a tampering verification result of the normal file configured with a static trusted verification policy; wherein, the tampering verification result of the normal file configured with a static trusted verification policy includes a file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the normal file configured with a static trusted verification policy.
[0021] Furthermore, based on the executable file configured with a static trusted verification policy, verify the execution operation of the to-be-tested trusted controller to obtain an execution verification result of the executable file configured with a static trusted verification policy, including:
[0022] Send the executable file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with a static trusted verification policy to obtain an execution verification result of the executable file configured with a static trusted verification policy; wherein, the execution verification result of the executable file configured with a static trusted verification policy includes a file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with a static trusted verification policy.
[0023] Furthermore, the static trusted verification function test result of the to-be-tested trusted controller is output in the format of HyperText Markup Language.
[0024] The present invention also provides a static trusted verification function test system for a trusted controller, which is used to test a client, and the test client establishes a network connection with the to-be-tested trusted controller;
[0025] The static trusted verification function test system for the trusted controller includes:
[0026] A policy configuration module, which is used to respectively configure static trusted verification policies for a predetermined normal file and a predetermined executable file to obtain a normal file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy;
[0027] The first verification module is used to verify the tampering operation of the to-be-tested trusted controller based on a normal file configured with a static trusted verification policy, and obtain the tampering verification result of the normal file configured with the static trusted verification policy; verify the execution operation of the to-be-tested trusted controller based on an executable file configured with a static trusted verification policy, and obtain the execution verification result of the executable file configured with the static trusted verification policy.
[0028] The policy deletion module is used to perform static trusted verification policy deletion operations on the normal file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy respectively, and obtain the normal file with the verification policy deleted and the executable file with the verification policy deleted.
[0029] The second verification module is used to verify the tampering operation of the to-be-tested trusted controller based on the normal file with the verification policy deleted, and obtain the tampering verification result of the normal file with the verification policy deleted; verify the execution operation of the to-be-tested trusted controller based on the executable file with the verification policy deleted, and obtain the execution verification result of the executable file with the verification policy deleted.
[0030] The result output module is used to output the tampering verification result of the normal file configured with the static trusted verification policy, the execution verification result of the executable file configured with the static trusted verification policy, the tampering verification result of the normal file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the static trusted verification function test result of the to-be-tested trusted controller.
[0031] The present invention also provides an electronic device, including:
[0032] A processor, suitable for executing a computer program;
[0033] A computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by the processor, it executes the static trusted verification function test method for a trusted controller.
[0034] The present invention also provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the static trusted verification function test method for a trusted controller.
[0035] The present invention also provides a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, it implements the static trusted verification function test method for a trusted controller.
[0036] Compared with the prior art, the beneficial effects of the present invention are:
[0037] The static trusted verification function testing method for a trusted controller provided by the present invention establishes a network connection between a test client and the to-be-tested trusted controller, and executes the specific steps of the static trusted verification function testing method on the test client to automate the testing of the static trusted verification function of the to-be-tested trusted controller. There is no need for manual setting of commands at the underlying layer of the to-be-tested trusted controller to verify whether the function is normal, saving manpower and time, effectively improving the testing efficiency, and at the same time being able to accurately achieve the expected testing effect. Specifically, by respectively configuring static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file, the to-be-tested trusted controller is verified for tampering operations based on the ordinary file configured with the static trusted verification policy, and the to-be-tested trusted controller is verified for execution operations based on the executable file configured with the static trusted verification policy. Secondly, by respectively performing static trusted verification policy deletion operations on the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy, and respectively performing tampering operation verification and execution operation verification, the normal operation of the deletion function of the static trusted verification policy is tested. The present invention can effectively improve the testing speed and testing quality of the static trusted verification function of the trusted controller, and at the same time can meet the testing of the stability of the static trusted verification function of the trusted controller, and can significantly reduce the testing cost.
[0038] The static trusted verification function testing system, electronic device, computer-readable storage medium and computer program product for a trusted controller provided by the present invention have all the advantages of the above-mentioned static trusted verification function testing method for a trusted controller. Brief Description of the Drawings
[0039] Figure 1 It is a flowchart of the static trusted verification function testing method for a trusted controller provided by the present invention;
[0040] Figure 2 It is a flowchart of the static trusted verification function testing method for a trusted controller provided in Embodiment 1;
[0041] Figure 3 It is a structural block diagram of the static trusted verification function testing system for a trusted controller provided in Embodiment 2;
[0042] Figure 4 It is a structural block diagram of the electronic device provided in Embodiment 3. Detailed Embodiments
[0043] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention clearer, the following specific embodiments are used to further elaborate on the present invention. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0044] As shown in the appended Figure 1 drawing, the appended Figure 1 shows a schematic flowchart of a static trusted verification function test method for a trusted controller provided by the present invention; the static trusted verification function test method for a trusted controller is applied to a test client, and the test client establishes a network connection with the to-be-tested trusted controller; the method includes the following steps:
[0045] Step 100: Configure static trusted verification policies for a pre-determined ordinary file and a pre-determined executable file respectively to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy.
[0046] Step 200: Based on the ordinary file configured with a static trusted verification policy, perform a tampering operation verification on the to-be-tested trusted controller to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy; based on the executable file configured with a static trusted verification policy, perform an execution operation verification on the to-be-tested trusted controller to obtain an execution verification result of the executable file configured with a static trusted verification policy.
[0047] Step 300: Perform a static trusted verification policy deletion operation on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted.
[0048] Step 400: Based on the ordinary file with the verification policy deleted, perform a tampering operation verification on the to-be-tested trusted controller to obtain a tampering verification result of the ordinary file with the verification policy deleted; based on the executable file with the verification policy deleted, perform an execution operation verification on the to-be-tested trusted controller to obtain an execution verification result of the executable file with the verification policy deleted.
[0049] Step 500: Output the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted as the static trusted verification function test result of the to-be-tested trusted controller.
[0050] In the above embodiments, after establishing a network connection between the test client and the to-be-tested trusted controller, the following test process is automatically executed: static trusted verification policies are respectively configured for a pre-determined ordinary file and a pre-determined executable file, and tampering operation verification and execution operation verification are respectively performed; by performing static trusted verification policy deletion operations on the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy respectively, and then performing tampering operation verification and execution operation verification respectively; no underlying command operations are required throughout the test, significantly improving the test efficiency and accurately covering the full-process test requirements of policy configuration, execution verification, and policy lifecycle management.
[0051] The following uses some specific embodiments to further explain and illustrate the static trusted verification function test method provided by the present invention for a trusted controller:
[0052] Embodiment 1
[0053] Embodiment 1 of the present invention provides a static trusted verification function test method for a trusted controller. The method is applied to a test client, and the test client establishes a network connection with the to-be-tested trusted controller.
[0054] It should be noted that the test client realizes the steps of the static trusted verification function test method by executing a preset python (a high-level programming language) program; the test client establishes a network connection with the to-be-tested trusted controller through Telnet (Teletype Network, a remote login protocol); among them, during the process of the test client establishing a network connection with the to-be-tested trusted controller through Telnet, the connection parameters of the to-be-tested trusted controller need to be pre-configured in the configuration file of the test client; the connection parameters of the to-be-tested trusted controller include the IP (Internet Protocol) address and account password of the to-be-tested trusted controller; the number of loop times for executing the test is also pre-set in the configuration file of the test client; a static trusted verification module is pre-installed in the to-be-tested trusted controller, and the static trusted verification module is used to realize the static trusted verification function.
[0055] As shown in the Figure 2 appendix, the steps of the static trusted verification function test method are specifically as follows:
[0056] Step 1: Configure static trusted verification policies for predetermined ordinary files and predetermined executable files respectively, to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy. Among them, the predetermined ordinary files include the configuration files and script files of the to-be-tested trusted controller, such as the / etc / passwd file (a file used to store user account information in the trusted controller, containing the basic information of all users in the trusted controller) and the / etc / startup.sh file (a custom startup script used to execute initialization tasks when the trusted controller starts); the predetermined executable files include the runnable process files and runnable command files of the to-be-tested trusted controller.
[0057] It should be noted that the static trusted verification function of the trusted controller uses trusted computing technology to perform trusted measurement verification on predetermined application programs or files to ensure the integrity of the predetermined application programs and files; the application programs or files configured with static trusted verification policies will be protected by the static trusted verification function of the trusted controller; the process of configuring the static trusted verification policy is: through the static trusted verification policy configuration command provided by the static trusted verification function of the trusted controller, configure the static trusted verification policy for the specified application program or file to be protected.
[0058] Specifically, the process of configuring static trusted verification policies for predetermined ordinary files and predetermined executable files respectively is as follows:
[0059] Step 101: Use a predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary files and predetermined executable files to obtain the trusted benchmark values of the ordinary files and the trusted benchmark values of the executable files; among them, the predetermined trusted verification algorithms are, for example, SHA-256 (Secure Hash Algorithm 256-bit, a cryptographic hash function) and SM3 (SM3 Cryptographic Algorithm, a cryptographic hash function standard).
[0060] Step 102: Use the static trusted verification policy configuration command provided by the static trusted verification function to configure the predetermined trusted verification algorithm and the trusted benchmark value of the ordinary file in the predetermined ordinary file to obtain an ordinary file configured with a static trusted verification policy.
[0061] Step 103: Use the static trusted verification policy configuration command provided by the static trusted verification function to configure the predetermined trusted verification algorithm and the trusted benchmark value of the executable file in the predetermined executable file to obtain an executable file configured with a static trusted verification policy.
[0062] Step 2: Turn on the static trust verification module of the to-be-tested trusted controller to make the static trust verification module in an on state.
[0063] Step 3: When the static trust verification module is in an on state, verify the tampering operation of the to-be-tested trusted controller based on the ordinary file configured with the static trust verification policy, and obtain the verification result of the tampering of the ordinary file configured with the static trust verification policy. Specifically, send the ordinary file configured with the static trust verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the ordinary file configured with the static trust verification policy, and record the file tampering action log to obtain the verification result of the tampering of the ordinary file configured with the static trust verification policy; among them, the verification result of the tampering of the ordinary file configured with the static trust verification policy includes the file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the ordinary file configured with the static trust verification policy.
[0064] It should be noted that after the static trust verification policy is pre-configured for the ordinary file, that is, the ordinary file configured with the static trust verification policy will be protected by the static trust verification module and cannot be tampered with at this time; when attempting to perform a file tampering operation on the ordinary file configured with the static trust verification policy, it will prompt that the file tampering fails and record the file tampering action log.
[0065] Step 4: Verify the execution operation of the to-be-tested trusted controller based on the executable file configured with the static trust verification policy, and obtain the verification result of the execution of the executable file configured with the static trust verification policy. Specifically, send the executable file configured with the static trust verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with the static trust verification policy, record the file execution operation log, and obtain the verification result of the execution of the executable file configured with the static trust verification policy; among them, the verification result of the execution of the executable file configured with the static trust verification policy includes the file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with the static trust verification policy.
[0066] It should be noted that in the process of verifying the execution operation of the to-be-tested trusted controller based on the executable file configured with the static trusted verification policy, it is mainly to verify the impact of the static trusted verification function of the to-be-tested trusted controller on the executable file configured with the static trusted verification policy; when the trusted state of the executable file configured with the static trusted verification policy is trusted, when the to-be-tested trusted controller performs an execution operation on the executable file configured with the static trusted verification policy, the execution result is successful; when the trusted state of the executable file configured with the static trusted verification policy is untrusted, when the to-be-tested trusted controller performs an execution operation on the executable file configured with the static trusted verification policy, the execution result is failed; by recording the file execution operation log, the execution verification result of the executable file configured with the static trusted verification policy can be obtained.
[0067] It should also be noted that when the trusted state of the predetermined executable file is trusted, the predetermined executable file cannot be tampered with but can be executed normally; when the trusted state of the predetermined executable file is untrusted, the predetermined executable file cannot be tampered with and cannot be executed normally.
[0068] Step 5: Perform static trusted verification policy deletion operations on the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy respectively to obtain the ordinary file with the verification policy deleted and the executable file with the verification policy deleted. Among them, by performing static trusted verification policy deletion operations on the ordinary file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy respectively, it is to verify whether the deletion function of the static trusted verification module in the to-be-tested trusted controller is normal; at the same time, it can avoid the residue of the static trusted verification policy in the executable file.
[0069] Step 6: With the static trusted verification module in the enabled state, perform tampering operation verification on the to-be-tested trusted controller based on the ordinary file with the verification policy deleted to obtain the tampering verification result of the ordinary file with the verification policy deleted. Among them, the process of performing tampering operation verification on the to-be-tested trusted controller based on the ordinary file with the verification policy deleted is basically the same as the operation in Step 3 above, and will not be elaborated here.
[0070] Step 7: With the static trusted verification module in the enabled state, perform execution operation verification on the to-be-tested trusted controller based on the executable file with the verification policy deleted to obtain the execution verification result of the executable file with the verification policy deleted. Among them, the process of performing execution operation verification on the to-be-tested trusted controller based on the executable file with the verification policy deleted is basically the same as the operation in Step 4 above, and will not be elaborated here.
[0071] Step 8: Reconfigure the static trusted verification policy for the ordinary files and executable files with the deletion verification policy removed, to obtain the ordinary files with the static trusted verification policy reconfigured and the executable files with the static trusted verification policy reconfigured. It should be noted that the process of reconfiguring the static trusted verification policy for the ordinary files and executable files with the deletion verification policy removed is basically the same as the operation in Step 1 above, and will not be elaborated here.
[0072] Step 9: Turn off the static trusted verification module of the to-be-tested trusted controller, so that the static trusted verification module is in the off state.
[0073] Step 10: While the static trusted verification module is in the off state, tamper with the ordinary files with the static trusted verification policy reconfigured and the executable files with the static trusted verification policy reconfigured, to obtain the tampered ordinary files and the tampered executable files.
[0074] Specifically, while the static trusted verification module is in the off state, perform tampering operations on the ordinary files with the static trusted verification policy reconfigured and the executable files with the static trusted verification policy reconfigured, to add preset characters to the ordinary files with the static trusted verification policy reconfigured and the executable files with the static trusted verification policy reconfigured respectively, so that the file content is changed, and the tampered ordinary files and the tampered executable files are obtained.
[0075] It should be noted that the trusted states of the tampered ordinary files and the tampered executable files are both untrusted. Then, the static trusted verification function of the to-be-tested trusted controller is tested based on the untrusted files.
[0076] Step 11: Re-open the static trusted verification module of the to-be-tested trusted controller, so that the static trusted verification module is in the on state.
[0077] Step 12: While the static trusted verification module is in the on state, verify the tampering operation on the to-be-tested trusted controller based on the tampered ordinary files, to obtain the tampering verification result of the untrusted ordinary files. It should be noted that the process of verifying the tampering operation on the to-be-tested trusted controller based on the tampered ordinary files is basically the same as the operation in Step 3 or Step 6 above, and will not be elaborated here.
[0078] Step 13: While the static trusted verification module is in the on state, verify the execution operation on the to-be-tested trusted controller based on the tampered executable files, to obtain the execution verification result of the untrusted executable files. It should be noted that the process of verifying the execution operation on the to-be-tested trusted controller based on the tampered executable files is basically the same as the operation in Step 4 or Step 7 above, and will not be elaborated here.
[0079] Step 14: Recover the tampered ordinary file and the tampered executable file. It should be noted that the process of recovering the tampered ordinary file and the tampered executable file is the reverse of the operation in Step 10, that is, deleting the preset characters in the tampered ordinary file and the tampered executable file.
[0080] Step 15: Return the tampering verification results of the ordinary file configured with the static trusted verification policy, the execution verification results of the executable file configured with the static trusted verification policy, the tampering verification results of the ordinary file with the verification policy deleted, the execution verification results of the executable file with the verification policy deleted, the tampering verification results of the untrusted ordinary file, and the execution verification results of the untrusted executable file, and save them to a preset log file; output the preset log file in the format of HyperText Markup Language to obtain the static trusted verification function test results of the to-be-tested trusted controller.
[0081] In this Embodiment 1, by executing a preset Python program on the test client to implement the static trusted verification function test method, and then automatically testing the static trusted verification function of the to-be-tested trusted controller, it can effectively improve the test efficiency and test result quality of the static trusted verification function of the trusted controller in the domestic trusted DCS, and can lock the location where the problem occurs through the output static trusted verification function test results of the to-be-tested trusted controller; at the same time, it can meet the test of the stability of the static trusted verification function of the trusted controller in the domestic trusted DCS and significantly reduce the test cost.
[0082] Embodiment 2
[0083] This Embodiment 2 provides a static trusted verification function test system for a trusted controller, which is used for a test client. The test client establishes a network connection with the to-be-tested trusted controller; as shown in the appendix Figure 3 The static trusted verification function test system for the trusted controller includes a policy configuration module, a first verification module, a policy deletion module, a second verification module, and a result output module.
[0084] A policy configuration module is used to respectively configure static trusted verification policies for predetermined ordinary files and predetermined executable files, obtaining ordinary files configured with static trusted verification policies and executable files configured with static trusted verification policies. A first verification module is used to verify the tampering operation of a to-be-tested trusted controller based on the ordinary file configured with a static trusted verification policy, obtaining a tampering verification result of the ordinary file configured with a static trusted verification policy; verify the execution operation of the to-be-tested trusted controller based on the executable file configured with a static trusted verification policy, obtaining an execution verification result of the executable file configured with a static trusted verification policy. A policy deletion module is used to respectively perform static trusted verification policy deletion operations on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy, obtaining an ordinary file with the verification policy deleted and an executable file with the verification policy deleted. A second verification module is used to verify the tampering operation of the to-be-tested trusted controller based on the ordinary file with the verification policy deleted, obtaining a tampering verification result of the ordinary file with the verification policy deleted; verify the execution operation of the to-be-tested trusted controller based on the executable file with the verification policy deleted, obtaining an execution verification result of the executable file with the verification policy deleted. A result output module is used to output the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted as the static trusted verification function test result of the to-be-tested trusted controller.
[0085] Optionally, the predetermined ordinary files include the configuration file and script file of the to-be-tested trusted controller; the predetermined executable files include the runnable process file and runnable command file of the to-be-tested trusted controller.
[0086] Optionally, the policy configuration module is specifically used to: respectively perform trusted measurement calculations on the predetermined ordinary files and predetermined executable files using a predetermined trusted verification algorithm, obtaining the trusted reference value of the ordinary file and the trusted reference value of the executable file; configure the predetermined trusted verification algorithm and the trusted reference value of the ordinary file in the predetermined ordinary file, obtaining an ordinary file configured with a static trusted verification policy; configure the predetermined trusted verification algorithm and the trusted reference value of the executable file in the predetermined executable file, obtaining an executable file configured with a static trusted verification policy.
[0087] Optionally, the first verification module is specifically configured to: send a general file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the general file configured with the static trusted verification policy, and obtain a file tampering verification result of the general file configured with the static trusted verification policy; wherein, the file tampering verification result of the general file configured with the static trusted verification policy includes a file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the general file configured with the static trusted verification policy.
[0088] Optionally, the first verification module is specifically configured to: send an executable file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy, and obtain an execution verification result of the executable file configured with the static trusted verification policy; wherein, the execution verification result of the executable file configured with the static trusted verification policy includes a file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy.
[0089] Optionally, the test result of the static trusted verification function of the to-be-tested trusted controller is output in the format of HyperText Markup Language.
[0090] Optionally, the static trusted verification function test system for the trusted controller described in Embodiment 2 further includes a file tampering module and a third verification module; the file tampering module is configured to reconfigure a static trusted verification policy for a general file with the verification policy deleted and an executable file with the verification policy deleted, to obtain a general file with the static trusted verification policy reconfigured and an executable file with the static trusted verification policy reconfigured; and perform tampering on the general file with the static trusted verification policy reconfigured and the executable file with the static trusted verification policy reconfigured, to obtain a tampered general file and a tampered executable file. The third verification module is configured to perform a tampering operation verification on the to-be-tested trusted controller based on the tampered general file, and obtain a tampering verification result of the untrusted general file; and perform an execution operation verification on the to-be-tested trusted controller based on the tampered executable file, and obtain an execution verification result of the untrusted executable file.
[0091] It should be noted that the result output module is further configured to output the tampering verification result of the untrusted general file and the execution verification result of the untrusted executable file.
[0092] Specifically, the result output module is used to return the verification results of ordinary file tampering with a static trusted verification policy configured, the verification results of executable file execution with a static trusted verification policy configured, the verification results of ordinary file tampering with the deletion verification policy, the verification results of executable file execution with the deletion verification policy, the verification results of tampering with untrusted ordinary files, and the verification results of execution of untrusted executable files, and save them to a preset log file; output the preset log file in the format of Hypertext Markup Language to obtain the static trusted verification function test results of the to-be-tested trusted controller.
[0093] Embodiment 3
[0094] As shown in the Figure 4 accompanying drawings, Embodiment 3 of the present invention provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of the static trusted verification function test method for a trusted controller when executing the computer program; or, the processor implements the functions of each module in the above-mentioned static trusted verification function test system for a trusted controller when executing the computer program.
[0095] Exemplarily, the computer program can be divided into one or more modules / units, and the one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of completing preset functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.
[0096] The electronic device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above are examples of the electronic device and do not constitute a limitation on the electronic device. It may include more components than the above, or combine some components, or different components. For example, the electronic device further includes a communication interface, an input / output device, a network access device, and a bus.
[0097] The so-called processor may be a central processing unit, or may also be other general-purpose processors, digital signal processors, application-specific integrated circuits, off-the-shelf programmable gate arrays, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc. The processor is the control center of the electronic device and connects various parts of the entire electronic device through various communication interfaces and lines.
[0098] The memory can be used to store the computer programs and / or modules. By running or executing the computer programs and / or modules stored in the memory, and invoking the data stored in the memory, the processor realizes various functions of the electronic device.
[0099] The memory may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card, a secure digital card, a flash memory card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0100] Embodiment 4
[0101] Embodiment 4 of the present invention also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the static trusted verification function test method for a trusted controller are realized.
[0102] If the modules / units integrated in the static trusted verification function test system for a trusted controller are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0103] Based on such an understanding, to implement all or part of the processes in the above-mentioned static trusted verification function test method for a trusted controller, the present invention can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned static trusted verification function test method for a trusted controller can be realized. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or a preset intermediate form, etc.
[0104] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory, a random access memory, an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0105] Embodiment 5
[0106] Embodiment 5 provides a computer product. The computer program product includes a computer program which is stored in a computer-readable storage medium. A processor of an electronic device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the electronic device can execute the static trusted verification function test method for a trusted controller described in Embodiment 1, which will not be elaborated here.
[0107] It should be noted that those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods.
[0108] The above embodiments are merely one of the implementation manners capable of implementing the technical solution of the present invention. The scope of protection required by the present invention is not limited only by this embodiment, but also includes any changes, substitutions and other implementation manners that are easily conceivable by those skilled in the art within the technical scope disclosed by the present invention.
Claims
1. A static trusted verification function test method for a trusted controller, characterized in that Applied to a test client, the test client establishes a network connection with the trusted controller to be tested; A static trusted verification function test method for a trusted controller, including: Configuring static trusted verification policies for a predetermined ordinary file and a predetermined executable file respectively, to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy; Based on the ordinary file configured with a static trusted verification policy, performing a tampering operation verification on the trusted controller to be tested, to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy; based on the executable file configured with a static trusted verification policy, performing an execution operation verification on the trusted controller to be tested, to obtain an execution verification result of the executable file configured with a static trusted verification policy; Performing static trusted verification policy deletion operations on the ordinary file configured with a static trusted verification policy and the executable file configured with a static trusted verification policy respectively, to obtain an ordinary file with the verification policy deleted and an executable file with the verification policy deleted; Based on the ordinary file with the verification policy deleted, performing a tampering operation verification on the trusted controller to be tested, to obtain a tampering verification result of the ordinary file with the verification policy deleted; based on the executable file with the verification policy deleted, performing an execution operation verification on the trusted controller to be tested, to obtain an execution verification result of the executable file with the verification policy deleted; Outputting the tampering verification result of the ordinary file configured with a static trusted verification policy, the execution verification result of the executable file configured with a static trusted verification policy, the tampering verification result of the ordinary file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the static trusted verification function test result of the trusted controller to be tested.
2. The static trusted verification function test method for a trusted controller according to claim 1, wherein, The predetermined ordinary files include the configuration file and script file of the trusted controller to be tested; the predetermined executable files include the runnable process file and runnable command file of the trusted controller to be tested.
3. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that, Configuring static trusted verification policies for a predetermined ordinary file and a predetermined executable file respectively, to obtain an ordinary file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy, including: Using a predetermined trusted verification algorithm to perform trusted measurement calculations on the predetermined ordinary file and the predetermined executable file respectively, to obtain a trusted reference value of the ordinary file and a trusted reference value of the executable file; Configuring the predetermined trusted verification algorithm and the trusted reference value of the ordinary file in the predetermined ordinary file, to obtain an ordinary file configured with a static trusted verification policy; Configuring the predetermined trusted verification algorithm and the trusted reference value of the executable file in the predetermined executable file, to obtain an executable file configured with a static trusted verification policy.
4. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that, Based on the ordinary file configured with a static trusted verification policy, performing a tampering operation verification on the trusted controller to be tested, to obtain a tampering verification result of the ordinary file configured with a static trusted verification policy, including: Send a normal file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller performs a file tampering operation on the normal file configured with the static trusted verification policy, and obtains a file tampering verification result of the normal file configured with the static trusted verification policy; wherein, the file tampering verification result of the normal file configured with the static trusted verification policy includes a file tampering action log recorded when the to-be-tested trusted controller performs a file tampering operation on the normal file configured with the static trusted verification policy.
5. A static trusted verification function test method for a trusted controller according to claim 1, characterized in that, Based on an executable file configured with a static trusted verification policy, perform an execution operation verification on the to-be-tested trusted controller, and obtain an execution verification result of the executable file configured with the static trusted verification policy, including: Send an executable file configured with a static trusted verification policy to the to-be-tested trusted controller, so that the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy, and obtains an execution verification result of the executable file configured with the static trusted verification policy; wherein, the execution verification result of the executable file configured with the static trusted verification policy includes a file execution operation log recorded when the to-be-tested trusted controller executes the executable file configured with the static trusted verification policy.
6. The static trusted verification function test method for a trusted controller according to claim 1, characterized in that The static trusted verification function test result of the to-be-tested trusted controller is output in the format of HyperText Markup Language.
7. A static trusted verification function test system for a trusted controller, characterized in that, For the test client, the test client establishes a network connection with the to-be-tested trusted controller; The static trusted verification function test system for the trusted controller includes: A policy configuration module, configured to respectively configure static trusted verification policies for a predetermined normal file and a predetermined executable file, and obtain a normal file configured with a static trusted verification policy and an executable file configured with a static trusted verification policy; A first verification module, configured to perform a tampering operation verification on the to-be-tested trusted controller based on the normal file configured with the static trusted verification policy, and obtain a file tampering verification result of the normal file configured with the static trusted verification policy; perform an execution operation verification on the to-be-tested trusted controller based on the executable file configured with the static trusted verification policy, and obtain an execution verification result of the executable file configured with the static trusted verification policy; A policy deletion module, configured to respectively perform a static trusted verification policy deletion operation on the normal file configured with the static trusted verification policy and the executable file configured with the static trusted verification policy, and obtain a normal file with the verification policy deleted and an executable file with the verification policy deleted; A second verification module, configured to perform a tampering operation verification on the to-be-tested trusted controller based on the normal file with the verification policy deleted, and obtain a file tampering verification result of the normal file with the verification policy deleted; perform an execution operation verification on the to-be-tested trusted controller based on the executable file with the verification policy deleted, and obtain an execution verification result of the executable file with the verification policy deleted; A result output module, configured to output the file tampering verification result of the normal file configured with the static trusted verification policy, the execution verification result of the executable file configured with the static trusted verification policy, the file tampering verification result of the normal file with the verification policy deleted, and the execution verification result of the executable file with the verification policy deleted, as the static trusted verification function test result of the to-be-tested trusted controller.
8. An electronic device, characterized in that, Including: A processor, adapted to execute a computer program; A computer-readable storage medium storing a computer program which, when executed by the processor, performs the static trusted verification function testing method for a trusted controller according to any one of claims 1-6.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the static trusted verification function testing method for a trusted controller according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program which, when executed by the processor, implements the static trusted verification function testing method for a trusted controller according to any one of claims 1-6.
Citation Information
Patent Citations
Trusted DCS controller trusted function test method, electronic equipment and storage medium
CN117970907A
Web-based static trusted verification function test method and system
CN118897795A
Method and related device for testing dynamic credible verification function of credible DCS (Distributed Control System) controller
CN119718960A