Commercial password detection method of certificate system with high test efficiency

By implementing efficient commercial password detection methods in the certificate system, the secret key algorithm of the target to be detected complies with preset standards, the problem of low detection efficiency in the prior art is solved, and more efficient network and information security guarantees and market order specifications are achieved.

CN120200758AInactive Publication Date: 2025-06-24SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510415421.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing commercial password detection methods are inefficient and cannot effectively ensure network and information security.

Method used

Provide a commercial password detection method for a certificate system with high testing efficiency. Through several steps, it detects whether the key algorithm of the target to be detected complies with the preset key standards, including firewall channel establishment, TLS firewall channel creation, key detection and other processes.

Benefits of technology

It has improved the efficiency of commercial password detection, ensured network and information security, regulated market order, and promoted the healthy development of the commercial password industry.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to the technical field of commercial password detection methods, and discloses a commercial password detection method of a certificate system with high test efficiency, and the commercial password detection method comprises the following steps: if a firewall channel establishment process is triggered, obtaining system information of a to-be-detected connection point, and meanwhile, carrying out information communication with a to-be-detected target; obtaining a communication result; and generating a firewall channel establishment instruction according to the system information of the to-be-detected connection point, and sending the firewall channel establishment instruction to the environment connection point to control the environment connection point to start a TLS firewall channel establishment process based on the system information. According to the commercial password detection method of the certificate system with high test efficiency and the commercial password detection, the compliance, the correctness and the effectiveness of a password technology are detected, so that a network and an information system are ensured to carry out encryption protection by using the commercial password, information leakage and illegal access are effectively prevented, and the security of the network and the information is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of commercial cipher detection methods, and specifically to a commercial cipher detection method for a certificate system with high test efficiency. Background Art

[0002] The content of cipher evaluation includes three aspects of cipher application security: compliance, correctness, and effectiveness.

[0003] 1. Commercial cipher application compliance evaluation; Commercial cipher application compliance evaluation refers to determining whether the cipher algorithms, cipher protocols, and key management used in an information system comply with the provisions of laws and regulations and the relevant requirements of national and industrial standards related to ciphers, and whether the cipher products and cipher services used have been approved by the national cipher management department or certified by qualified institutions.

[0004] 2. Commercial cipher application correctness evaluation; Commercial cipher application correctness evaluation refers to determining whether the cipher algorithms, cipher protocols, key management, cipher products, and services are used correctly, that is, whether the standard cipher algorithms, protocols, and key management mechanisms adopted in the system are correctly designed and implemented in accordance with the corresponding national and industrial standards for ciphers, whether the design and implementation of custom cipher protocols and key management mechanisms are correct, whether the security meets the requirements, and whether the deployment and application of cipher products and services during the construction or transformation of the cipher protection system are correct.

[0005] 3. Commercial cipher application effectiveness evaluation; Commercial cipher application effectiveness evaluation refers to determining whether the cipher protection system implemented in the information system has played an actual role during the operation of the information system, whether it meets the security requirements of the information system, and whether it has effectively solved the security problems faced by the information system; However, the existing commercial cipher detection methods have low efficiency and cannot guarantee network and information security. Therefore, there is an urgent need for a commercial cipher detection method for a certificate system with high test efficiency to solve the above deficiencies. Summary of the Invention

[0006] In view of the deficiencies of the prior art, the present invention provides a commercial cipher detection method for a certificate system with high test efficiency, which solves the existing problems.

[0007] The present invention provides the following technical solution: A commercial cipher detection method for a certificate system with high test efficiency, the commercial cipher detection method includes the following steps: Step 1: If the firewall channel establishment process is triggered, obtain the system information of the connection point to be detected, and at the same time communicate with the target to be detected to obtain the communication result; Step 2: Generate a firewall channel establishment instruction based on the system information of the connection point to be detected, and send the firewall channel establishment instruction to the environment connection point to control the environment connection point to start the TLS firewall channel creation process based on the system information, generate a first response message according to the execution result of the firewall channel creation process, and at the same time call a preset key standard module to detect the connection result to obtain a detection result; Step 3: Receive the first response message sent by the detected environment connection point, and generate a first key detection result according to the first response message; Step 4: Finally, analyze the detection result to determine whether the key algorithm of the target to be detected meets the preset key standard.

[0008] Preferably, the firewall channel establishment process in Step 1 includes the following steps: Step 1: Provide the software development kit of TravelingSalesmanProblem, namely the TravelingSalesmanProblem API package and the TravelingSalesmanProblemService service process; Step 2: The TravelingSalesmanProblem API package encapsulates the network information required by the TravelingSalesmanProblem API and the TravelingSalesmanProblemService service process; Step 3: The TravelingSalesmanProblem API and the TravelingSalesmanProblemService service process interact with the message push server through Aidl.

[0009] Preferably, the specific process of the step where the TravelingSalesmanProblem API package encapsulates the network information required by the TravelingSalesmanProblem API and the TravelingSalesmanProblemService service process is as follows: The interfaces provided for the external WindLink APP are set in the TravelingSalesmanProblemManager class. The TravelingSalesmanProblemManager class adopts the singleton pattern. The interfaces in the TravelingSalesmanProblemManager class are divided into three categories according to their functions: springboot interfaces, CGI interfaces, and integrated services digital network interfaces. Among them, the springboot interface is the basis for the CGI interface and the integrated services digital network interface. That is, initialization must be completed before using the CGI interface or the integrated services digital network interface. At the same time, the springboot interface is an asynchronous interface responsible for notifying each module to prepare for Internet access. The CGI interface part includes a push interface and a credential interface. The push interface is responsible for receiving push messages from the cloud. The credential interface includes interfaces for setting credentials, obtaining credentials, obtaining the validity period of credentials, and detecting whether the credentials are invalid. Among them, the interface for setting credentials is only for account applications. The integrated services digital network interface uses the https protocol for two-way authentication with the message push server. The InitManager class is designed in the singleton pattern, interfaces with the springboot interface and the CGI interface, and instantiates ParamManager, ServiceManager, TokenManager, and TravelingSalesmanProblemAidl. The TravelingSalesmanProblemService is divided into three modules, namely the electrical parameter measurement module, the PUSH module, and the account credential cache module. Among them, the electrical parameter measurement module is used to obtain various basic information required for Internet access. The PUSH module establishes a long connection with the MQTT server to receive instant messages from the MQTT server. The account credential cache module is used to store account credentials and share them with each application. The valid data existing after logging in to the account credential cache module will be cleared after exiting or shutting down.

[0010] Preferably, the detection system is communicatively connected to the environmental node and the node to be detected. The method further includes: If a certificate download detection process is triggered, obtain the device information of the environmental node; Generate a certificate download detection instruction according to the device information of the environmental node, and send the certificate download detection instruction to the environmental node to control the environmental node to generate a certificate status query request based on the certificate download detection instruction and send the certificate status query request to the certificate system to obtain the environmental node certificate information; Receive the environmental node certificate information sent by the environmental node, and generate a certificate download detection result according to the environmental node certificate information.

[0011] Preferably, interacting with the target to be detected to obtain an interaction result includes: invoking a preset simulation module to perform simulation encryption and decryption operations on the password used by the target to be detected, and obtaining a simulation result.

[0012] Preferably, invoking a preset simulation module to perform simulation encryption and decryption operations on the password used by the target to be detected, and obtaining a simulation result includes: selecting a standard public key algorithm A, a public key e, a private key d, and a plaintext P; signing the plaintext P through the standard public key algorithm A to obtain a signature value SIGN.

[0013] Compared with the prior art, the present invention has the following beneficial effects: A method for detecting commercial passwords of a certificate system with high test efficiency according to the present invention: 1. Ensure network and information security: Commercial password detection ensures that network and information systems use commercial passwords for encryption protection by detecting the compliance, correctness, and effectiveness of password technologies, thereby effectively preventing information leakage and illegal access, ensuring network and information security, and at the same time having high detection efficiency, greatly reducing the detection time.

[0014] 2. Standardize the market order: The construction and maintenance of the commercial password detection and certification system help standardize the commercial password market order, prevent unqualified products from entering the market, protect the rights and interests of consumers, and promote the healthy development of the commercial password industry.

[0015] 3. Promote industrial development: Through detection and certification, the quality and security of commercial password products can be improved, market confidence can be enhanced, market vitality can be stimulated, and the innovation and development of the commercial password industry can be promoted. Specific implementation manners

[0016] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Some components will be omitted, enlarged, or reduced, which does not represent the size of the actual product. For those skilled in the art, it is understandable that some well-known structures, components, and their descriptions may be omitted. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0017] In the description of the present invention, it should also be noted that, unless otherwise clearly specified and defined, the terms "set" and "connect" should be understood in a broad sense. For example, it can be a fixed connection, a movable connection, a detachable connection, or an integral connection. It can be a mechanical connection or an electrical connection. It can be directly connected or indirectly connected through an intermediate medium. It can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations. The present application will be described in detail below with reference to the embodiments.

[0018] A commercial cipher detection method for a certificate system with high test efficiency, the commercial cipher detection method comprising the following steps: Step 1: If a firewall channel establishment process is triggered, obtain the system information of the connection point to be detected, and at the same time communicate with the target to be detected to obtain a communication result; Step 2: Generate a firewall channel establishment instruction according to the system information of the connection point to be detected, and send the firewall channel establishment instruction to the environment connection point to control the environment connection point to start a TLS firewall channel creation process based on the system information, and generate a first response message according to the execution result of the firewall channel creation process. At the same time, call a preset secret key standard module to detect the communication result to obtain a detection result; Step 3: Receive the first response message sent by the detection environment connection point, and generate a first secret key detection result according to the first response message; Step 4: Finally, analyze the detection result to determine whether the secret key algorithm of the target to be detected meets the preset secret key standard.

[0019] Preferably, the firewall channel establishment process in Step 1 includes the following steps: Step 1: Provide a software development kit for TravelingSalesmanProblem, namely the TravelingSalesmanProblem API package and the TravelingSalesmanProblemService service process; Step 2: The TravelingSalesmanProblem API package encapsulates the network information required by the TravelingSalesmanProblem API and the TravelingSalesmanProblemService service process; Step 3: The TravelingSalesmanProblem API and the TravelingSalesmanProblemService service process interact with the message push server through Aidl.

[0020] Preferably, the specific process of the encapsulation step of the TravelingSalesmanProblemAPI package for the network information required by the TravelingSalesmanProblemAPI and TravelingSalesmanProblemService service processes is as follows: The interfaces provided for the external WindLink APP are set in the TravelingSalesmanProblemManager class. The TravelingSalesmanProblemManager class is a singleton pattern. The interfaces in the TravelingSalesmanProblemManager class are divided into three categories according to their functions: springboot interfaces, CGI interfaces, and integrated services digital network interfaces. Among them, the springboot interface is the basis for the CGI interface and the integrated services digital network interface. That is, initialization must be completed before using the CGI interface or the integrated services digital network interface. At the same time, the springboot interface is an asynchronous interface responsible for notifying each module to prepare for Internet access. The CGI interface part includes a push interface and a credential interface. The push interface is responsible for receiving push messages from the cloud. The credential interface includes interfaces for setting credentials, obtaining credentials, obtaining the validity period of credentials, and detecting whether the credentials are invalid. Among them, the interface for setting credentials is only used by the account application. The integrated services digital network interface uses the https protocol for two-way authentication with the message push server. The InitManager class is designed in a singleton pattern, interfaces with the springboot interface and the CGI interface, and instantiates ParamManager, ServiceManager, TokenManager, and TravelingSalesmanProblemAidl. The TravelingSalesmanProblemService is divided into three modules, namely the electrical parameter measurement module, the PUSH module, and the account credential cache module. Among them, the electrical parameter measurement module is used to obtain various basic information required for Internet access. The PUSH module establishes a long connection with the MQTT server and receives instant messages from the MQTT server. The account credential cache module is used to store account credentials and share them with each application. The valid data existing after logging in to the account credential cache module is cleared after logout or shutdown.

[0021] Among them, the detection system is communicatively connected to the environmental node and the node to be detected. This method further includes: If the certificate download detection process is triggered, obtain the device information of the environmental node; Generate a certificate download detection instruction based on the device information of the environment node, and send the certificate download detection instruction to the environment node to control the environment node to generate a certificate status query request based on the certificate download detection instruction, and send a certificate status query request to the certificate system to obtain the environment node certificate information; Receive the environment node certificate information sent by the environment node, and generate a certificate download detection result based on the environment node certificate information.

[0022] Preferably, perform information interaction with the target to be detected, and the obtained interaction result includes: calling a preset simulation module to perform simulation encryption and decryption operations on the password used by the target to be detected, and obtaining the simulation result.

[0023] Preferably, calling a preset simulation module to perform simulation encryption and decryption operations on the password used by the target to be detected, and obtaining the simulation result includes: selecting a standard public key algorithm A, a public key e, a private key d, and a plaintext P; signing the plaintext P through the standard public key algorithm A to obtain a signature value SIGN.

[0024] It should be noted that the commercial cipher detection method of this certificate system with high test efficiency: 1. Ensure network and information security: Commercial cipher detection ensures that the network and information system use commercial ciphers for encryption protection by detecting the compliance, correctness, and effectiveness of cipher technologies, thereby effectively preventing information leakage and illegal access, ensuring network and information security. At the same time, the detection efficiency is high, greatly reducing the detection time.

[0025] 2. Standardize the market order: The construction and maintenance of the commercial cipher detection and certification system help standardize the commercial cipher market order, prevent unqualified products from entering the market, protect the rights and interests of consumers, and promote the healthy development of the commercial cipher industry.

[0026] 3. Promote industrial development: Through detection and certification, the quality and security of commercial cipher products can be improved, market confidence can be enhanced, market vitality can be stimulated, and the innovation and development of the commercial cipher industry can be promoted.

[0027] The content not described in detail in this specification belongs to the prior art well-known to those skilled in the art.

[0028] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or system comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system.

[0029] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A commercial password detection method for a certificate system with high testing efficiency, characterized in that: The commercial password detection method comprises the following steps: Step 1: If the firewall channel establishment process is triggered, the system information of the connection point to be detected is obtained, and information is communicated with the target to be detected to obtain the connection result; Step 2: Generate a firewall channel establishment instruction according to the system information of the connection point to be detected, and send the firewall channel establishment instruction to the environment connection point to control the environment connection point to start the TLS firewall channel creation process based on the system information, and generate a first response message according to the execution result of the firewall channel creation process, and at the same time call the preset secret key standard module to detect the connection result to obtain a detection result; Step 3: Receive a first response message sent by the detection environment connection point, and generate a first secret key detection result according to the first response message; Step 4. Finally, analyze the test results to determine whether the secret key algorithm of the target to be tested meets the preset secret key standard.

2. A commercial password detection method for a certificate system with high testing efficiency according to claim 1, characterized in that: The firewall channel establishment process in step 1 includes the following steps: Step 1: Provide the TravelingSalesmanProblem software development kit, namely the TravelingSalesmanProblemAPI package and the TravelingSalesmanProblemService service process; Step 2: The TravelingSalesmanProblemAPI package encapsulates the network information required by the TravelingSalesmanProblemAPI and TravelingSalesmanProblemService service processes; Step 3: The TravelingSalesmanProblemAPI and TravelingSalesmanProblemService service processes interact with the message push server through Aidl.

3. A commercial password detection method for a certificate system with high testing efficiency according to claim 1, characterized in that: The TravelingSalesmanProblemAPI package encapsulates the network information required by the TravelingSalesmanProblemAPI and TravelingSalesmanProblemService service processes. The specific process is as follows: The interface provided to the external WindLink APP is set in the TravelingSalesmanProblemManager class. The TravelingSalesmanProblemManager class is a singleton mode. The interfaces in the TravelingSalesmanProblemManager class are divided into three categories according to their functions: springboot interface, CGI interface and integrated services digital network interface; among them, the springboot interface is the basis of the CGI interface and the integrated services digital network interface, that is, the initialization must be completed before using the CGI interface or the integrated services digital network interface. At the same time, the springboot interface is an asynchronous interface responsible for notifying each module to prepare for Internet access; the CGI interface part includes a push interface and a credential interface. The push interface is responsible for receiving push messages from the cloud. The credential interface includes interfaces for setting credentials, obtaining credentials, obtaining credential validity period, and detecting whether credentials are invalid. Among them, the credential setting interface is only for account applications; the integrated services digital network interface uses the https protocol to perform two-way authentication with the message push server; The InitManager class adopts a singleton design, connects to the springboot interface and the CGI interface, and instantiates ParamManager, ServiceManager, TokenManager, and TravelingSalesmanProblemAidl; TravelingSalesmanProblemService is divided into three modules, namely, electrical parameter measurement module, PUSH module and account credential cache module. Among them, the electrical parameter measurement module is used to obtain various basic information required for Internet access; the PUSH module establishes a long connection with the MQTT server and receives instant messages from the MQTT server; the account credential cache module is used to store account credentials and share them with various applications. The valid data after logging into the account credential cache module will be cleared after logging out or shutting down.

4. A commercial password detection method for a certificate system with high testing efficiency according to claim 1, characterized in that: The detection system is in communication connection with the environment node and the node to be detected, and the method further comprises: If the certificate download detection process is triggered, obtain the device information of the environment node; Generate a certificate download detection instruction according to the device information of the environment node, and send the certificate download detection instruction to the environment node to control the environment node to generate a certificate status query request based on the certificate download detection instruction, and send the certificate status query request to the certificate system to obtain the environment node certificate information; Receive the environment node certificate information sent by the environment node, and generate a certificate download detection result based on the environment node certificate information.

5. A commercial password detection method for a certificate system with high testing efficiency according to claim 1, characterized in that: The information interaction with the target to be detected is performed to obtain the interaction result, including: calling a preset simulation module to simulate encryption operation and decryption operation with the password used by the target to be detected, and obtaining the simulation result.

6. A commercial password detection method for a certificate system with high testing efficiency according to claim 1, characterized in that: Calling a preset simulation module and the password used by the target to be detected to perform simulated encryption and decryption operations, and obtaining simulation results includes: selecting a standard public key algorithm A, a public key e, a private key d and a plaintext P; signing the plaintext P through the standard public key algorithm A to obtain a signature value SIGN.