DCS upper computer dynamic credibility verification function test method and related device

By configuring the dynamic trusted verification policy for the executable files of the DCS host computer and monitoring its process status, the problem of time-consuming testing of the dynamic trusted verification function is solved, automated testing and risk assessment are realized, and testing efficiency and quality are improved.

CN120540924APending Publication Date: 2025-08-26XIAN THERMAL POWER RES INST CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510642793.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

The dynamic trusted verification function test process of existing DCS host computers takes a long time and is inefficient in testing.

Method used

It provides a dynamic trusted verification function test method for DCS host computers. By configuring a dynamic trusted verification policy for a predetermined executable file, an execution process is generated, and its trusted state is queried and monitored to generate test results.

Benefits of technology

It realizes automated testing of DCS upper-level computer dynamic trusted verification function, improves testing speed and quality, can promptly detect problems and evaluate risks, and reduces the need for manual monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120540924A_ABST
    Figure CN120540924A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of industrial control system function testing, and discloses a DCS upper computer dynamic credibility verification function testing method and a related device, and the method comprises the steps: configuring a dynamic credibility verification strategy for a predetermined executable file; the to-be-tested DCS upper computer is used for executing the executable file configured with the credible verification strategy, and an execution process is generated; querying the trusted state of the execution process to obtain a state query result of the execution process; tampering a preset data segment of the execution process; monitoring the trusted state of the tampered execution process to obtain a state monitoring result of the tampered execution process; generating a dynamic credible verification function test result of the DCS upper computer to be tested based on the state query result of the execution process and the tampered state monitoring result of the execution process; according to the invention, the automatic test of the dynamic credible verification function of the DCS upper computer is realized, and the test speed and quality of the dynamic credible verification function of the credible DCS upper computer are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control system function testing, and in particular relates to a DCS host computer dynamic trustworthy verification function testing method and related devices. Background Art

[0002] A distributed control system (DCS) is a new type of control device that uses computer technology to centrally monitor, operate, manage, and decentralized control industrial production processes. Trusted DCS is based on traditional DCS and improves system security by introducing a trusted computing architecture. Currently, the host computers of domestically produced trusted DCS systems generally integrate dynamic trusted verification functions to measure the trustworthiness of the memory, execution environment, and behavior of running processes in the host computer, thereby determining whether the running processes meet expectations.

[0003] In practical applications, the dynamic trusted verification function of the DCS host computer needs to be tested after deployment. Existing testing methods mostly use manual execution of test commands and require manual monitoring of the process status, resulting in time-consuming and inefficient testing. Summary of the Invention

[0004] In view of the technical problems existing in the prior art, the present invention provides a DCS host computer dynamic trustworthy verification function testing method and related devices to solve the technical problems of the existing DCS host computer dynamic trustworthy verification function testing process being time-consuming and having low testing efficiency.

[0005] In order to achieve the above object, the technical solution adopted by the present invention is: The present invention provides a method for testing a dynamic trustworthy verification function of a DCS host computer, comprising: Configuring a dynamic trusted verification policy for a predetermined executable file to obtain an executable file configured with the trusted verification policy; Use the DCS host computer to execute the executable file configured with the trusted verification strategy to generate the execution process; Query the trusted status of the execution process and obtain the status query result of the execution process; Tampering with a preset data segment of an execution process; wherein the preset data segment of an execution process includes a code segment and a read-only data segment of the execution process; Monitor the trusted state of the tampered execution process and obtain the state monitoring result of the tampered execution process; Based on the status query results of the execution process and the status monitoring results of the tampered execution process, the dynamic trustworthy verification function test results of the DCS host computer to be tested are generated.

[0006] Furthermore, the process of configuring a dynamic trusted verification policy for a predetermined executable file and obtaining the executable file configured with the trusted verification policy is as follows: The dynamic trusted verification policy configuration command provided by the dynamic trusted verification function in the DCS host computer to be tested is used to configure the pre-selected dynamic trusted verification policy in a predetermined executable file to obtain the executable file configured with the trusted verification policy.

[0007] Furthermore, the process of querying the trusted status of the execution process and obtaining the status query result of the execution process is as follows: The trusted status of the execution process is queried through the dynamic trusted verification status query command provided by the dynamic trusted verification function in the DCS host computer to be tested, and the status query result of the execution process is obtained.

[0008] Furthermore, the trusted state of the tampered execution process is monitored to obtain the state monitoring result of the tampered execution process. The specific process is as follows: Through the dynamic trust verification status query command provided by the dynamic trust verification function in the DCS host computer to be tested, the trust status of the tampered execution process is monitored and queried to obtain the status monitoring result of the tampered execution process.

[0009] Furthermore, the dynamic trustworthy verification function test result of the DCS host computer to be tested is output in the format of Hypertext Markup Language HTML.

[0010] Furthermore, if the status query result of the execution process changes as the preset data segment of the execution process is tampered with, and the status monitoring result of the tampered execution process is able to control the execution process according to the control measures of the configured dynamic trustworthy verification policy, the dynamic trustworthy verification function test result of the DCS host computer to be tested is normal; When the status query result of the execution process does not change even though the preset data segment of the execution process is tampered with, and the status monitoring result of the tampered execution process is that the execution process cannot be controlled according to the control measures of the configured dynamic trustworthy verification policy, the dynamic trustworthy verification function test result of the DCS host computer to be tested is abnormal.

[0011] The present invention also provides a DCS host computer dynamic trustworthy verification function test system, comprising: A policy configuration module is used to configure a dynamic trusted verification policy for a predetermined executable file and obtain an executable file configured with the trusted verification policy; The file execution module is used to use the DCS host computer to execute the executable file configured with the trusted verification strategy to generate an execution process; The status query module is used to query the trusted status of the execution process and obtain the status query result of the execution process; A process tampering module is used to tamper with a preset data segment of an execution process; wherein the preset data segment of the execution process includes a code segment and a read-only data segment of the execution process; A state monitoring module is used to monitor the trusted state of the tampered execution process and obtain the state monitoring result of the tampered execution process; The result output module is used to generate the dynamic trustworthy verification function test results of the DCS host computer to be tested based on the status query results of the execution process and the status monitoring results of the tampered execution process.

[0012] The present invention also provides an electronic device, comprising: a processor suitable for executing a computer program; A computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the DCS host computer dynamic trust verification function testing method is executed.

[0013] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for testing the dynamic trustworthy verification function of a DCS host computer is implemented.

[0014] The present invention also provides a computer program product, characterized in that the computer program product includes a computer program, and when the computer program is executed by a processor, the DCS host computer dynamic trustworthy verification function testing method is implemented.

[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention provides a method for testing the dynamic trusted verification function of a DCS host computer. The method executes an executable file configured with a trusted verification strategy on a DCS host computer to be tested, and queries the process status of the executable file configured with the trusted verification strategy; tampering with a preset data segment of the execution process and monitoring the trusted state of the tampered execution process achieves automated testing of the dynamic trusted verification function of the DCS host computer, effectively improving the test speed and quality of the dynamic trusted verification function of the trusted DCS host computer. The present invention can automatically configure the dynamic trusted verification strategy for the executable file through the dynamic trusted verification configuration command, and query the process status after the file is executed and the process is generated, and can monitor the process status and control status after the code segment or read-only data segment of the execution process is tampered. The control measures are tracked, so that the basic functions of the dynamic trusted verification function of the DCS host computer can be initialized and tested. Among them, considering that some process files will run for a long time, after configuring the dynamic trusted verification strategy and running it, the process will also be monitored by the dynamic trusted verification function for a long time. After the code segment or read-only data segment of the executing process is tampered with, the status and control measures of the process can be continuously tracked. Therefore, the stability of the dynamic trusted verification function can be tested, and the test process does not require manual monitoring throughout the process. Through the output of the dynamic trusted verification function test results of the DCS host computer to be tested, test problems can be discovered in time, and the risks of the dynamic trusted verification function software can be evaluated, which helps testers understand the risk status and take corresponding measures to reduce the risk in time.

[0016] The DCS host computer dynamic trustworthy verification function test system, electronic equipment, computer-readable storage medium and computer program product provided by the present invention have all the advantages of the above-mentioned DCS host computer dynamic trustworthy verification function test method. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 Flowchart of the DCS host computer dynamic trustworthy verification function testing method provided by the present invention; Figure 2 Flowchart of the DCS host computer dynamic trust verification function testing method provided in Example 1; Figure 3 A structural block diagram of the DCS host computer dynamic trustworthy verification function test system provided in Example 2; Figure 4 This is a structural block diagram of the electronic device provided in Example 3. DETAILED DESCRIPTION

[0018] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention more clearly understood, the present invention is further described in detail in the following specific embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0019] As attached Figure 1 As shown, the present invention provides a method for testing the dynamic trustworthy verification function of a DCS host computer, comprising the following steps: Step 100: Configure a dynamic trusted verification policy for a predetermined executable file to obtain an executable file configured with the trusted verification policy.

[0020] Step 200: Utilize the DCS host computer to be tested to execute the executable file configured with the trusted verification policy to generate an execution process.

[0021] Step 300: Query the trusted status of the execution process and obtain the status query result of the execution process.

[0022] Step 400: tampering with a preset data segment of the execution process; wherein the preset data segment of the execution process includes a code segment and a read-only data segment of the execution process.

[0023] Step 500: Monitor the trusted state of the tampered execution process to obtain a state monitoring result of the tampered execution process.

[0024] Step 600: Generate a dynamic trustworthy verification function test result of the DCS host computer to be tested based on the status query result of the execution process and the status monitoring result of the tampered execution process.

[0025] The present invention provides a method for testing the dynamic trusted verification function of a DCS host computer. The method comprises the following steps: a DCS host computer to be tested executes an executable file configured with a trusted verification policy, and queries the process status of the executable file configured with the trusted verification policy; tampering with a preset data segment of the execution process, and monitoring the trusted status of the tampered execution process, thereby realizing automated testing of the dynamic trusted verification function of the DCS host computer, effectively improving the test speed and test quality of the dynamic trusted verification function of the trusted DCS host computer, and eliminating the need for manual full-process monitoring of the test process; and outputting the dynamic trusted verification function test results of the DCS host computer to be tested. Test problems can be discovered in a timely manner, and risks existing in the dynamic trusted verification function software can be assessed, thereby helping testers understand the risk status and take corresponding measures to reduce the risk in a timely manner.

[0026] The following is a further explanation of the DCS host computer dynamic trust verification function testing method provided by the embodiment of the present invention with some specific examples: Example 1 This embodiment 1 provides a DCS host computer dynamic trust verification function test method for automated testing of the dynamic trust verification function of the host computer in a domestically produced trustworthy DCS; Figure 2 As shown, the DCS host computer dynamic trust verification function testing method includes the following steps: Step 1: Enable the dynamic trust verification function of the DCS host computer under test. This function is used by the DCS host computer under test to periodically verify the trustworthiness of the dynamic execution of the running process. Specifically, the trusted verification targets include the running process itself and the code segments and read-only data segments of all dynamic link libraries used by the running process.

[0027] Step 2: Configure a dynamic trusted verification policy for a predetermined executable file in a preset directory to obtain an executable file configured with the trusted verification policy. Specifically, utilize the dynamic trusted verification policy configuration command provided by the dynamic trusted verification function in the DCS host computer to be tested to configure the pre-selected dynamic trusted verification policy in the predetermined executable file to obtain the executable file configured with the trusted verification policy. The pre-selected dynamic trusted verification policy is used to trigger the dynamic trusted verification function of the DCS host computer to be tested to perform periodic trusted verification on the processes during the execution of the executable file. It should be noted that the predetermined executable file is an executable file that can run continuously within a preset time period.

[0028] Step 3: Use the DCS host computer to execute the executable file configured with the trusted verification strategy to generate an execution process.

[0029] Step 4: Query the trusted status of the execution process and obtain the status query result of the execution process. The trusted status of the execution process is queried using the dynamic trusted verification status query command provided by the dynamic trusted verification function in the DCS host computer to obtain the status query result of the execution process.

[0030] Specifically, the dynamic trusted verification status query command provided by the dynamic trusted verification function is used to view the trusted status of all processes that are configured with dynamic trusted verification policies and are running. The dynamic trusted verification status query command followed by the process pid is used to view the trusted status of the specified process code segment and read-only data segment. It should be noted that when the executable file is configured with a dynamic trusted verification policy, the trusted status of the corresponding execution process when running the executable file configured with the trusted verification policy is trusted by default.

[0031] Step 5: Tamper with the preset data segment of the execution process to change its trusted status to untrusted. The preset data segment of the execution process includes the code segment or read-only data segment of the execution process. The code segment of the execution process is used to store the operating instructions of the executable file, that is, the image of the executable file in the memory of the DCS host computer under test. The read-only data segment of the execution process is used to store the initialized global variables in the executable file, that is, the variables statically allocated by the program and global variables.

[0032] Specifically, since a PID is generated after the executable file is run, the memory address of the code segment or read-only data segment of the executing process can be set by attaching the PID of the program with gdb; when the memory address of the code segment or read-only data segment of the executing process is set inconsistently, the code segment or read-only data segment will be in an untrusted state, causing the executing process itself to be in an untrusted state.

[0033] Step 6: Monitor the trusted status of the tampered execution process using the dynamic trusted verification function in the DCS host computer under test, and obtain the status monitoring results of the tampered execution process. When the trusted status of the execution process is untrustworthy, the DCS host computer under test will issue an alarm or terminate the operation according to the pre-configured dynamic trusted verification policy. The trusted status of the tampered execution process is monitored using the dynamic trusted verification status query command to determine whether the tampered execution process issues an alarm or terminates.

[0034] Step 7: Repeat steps 2-6 until the preset test goal is completed.

[0035] Step 8: Return the status query result of the execution process and the status monitoring result of the tampered execution process, save them to the test log file, and output the test log file in the format of Hypertext Markup Language HTML to obtain the dynamic trust verification function test result of the DCS host computer to be tested.

[0036] It should be noted that the dynamic trustworthy verification function test results of the DCS host computer to be tested are as follows: When the status query result of the execution process changes as the preset data segment of the execution process is tampered with, and the status monitoring result of the tampered execution process is able to control the execution process according to the control measures of the configured dynamic trust verification strategy, the dynamic trust verification function test result of the DCS host computer to be tested is normal.

[0037] When the status query result of the execution process does not change even though the preset data segment of the execution process is tampered with, and the status monitoring result of the tampered execution process is that the execution process cannot be controlled according to the control measures of the configured dynamic trustworthy verification strategy, the dynamic trustworthy verification function test result of the DCS host computer to be tested is abnormal.

[0038] The method for testing the dynamic trusted verification function of a DCS host computer described in Example 1 implements the steps of the testing method by executing a preset shell script on the DCS host computer to be tested, thereby completing the automated testing of the dynamic trusted verification function of the DCS host computer to be tested; wherein, . / startup.sh start is executed by the bottom layer of the DCS host computer to be tested to start executing the shell script, and . / startup.sh stop is executed to terminate the execution of the shell script.

[0039] The test method described in this embodiment 1 can meet the initialization test of the dynamic trusted verification function and the stability test of the dynamic trusted verification function; specifically, the initialization test of the dynamic trusted verification function is used to verify whether the basic functions of the dynamic trusted verification function are normal; during the initialization test, the results generated by each parameter will be tested according to the parameters of the pre-configured dynamic trusted verification policy to complete the test of all policy setting methods; the stability test of the dynamic trusted verification function is used to repeatedly test the dynamic trusted verification function in a preset time period to monitor whether the function will be abnormal and whether it will have a significant impact on the operation of the system; during the stability test, by randomly setting the policy according to the parameters, when one policy method is tested, the policy is randomly set again according to the parameters, and the test is looped until the test is terminated by executing . / startup.sh stop; the test scenarios for implementing the initialization test of the dynamic trusted verification function and the stability test of the dynamic trusted verification function are pre-configured in the configuration file test.config of the DCS host computer to be tested.

[0040] In this embodiment 1, the DCS host computer to be tested executes an executable file configured with a trusted verification policy, and queries the process status of the executable file configured with the trusted verification policy; by tampering with the preset data segment of the execution process and monitoring the trusted status of the tampered execution process, the automatic test of the dynamic trusted verification function of the DCS host computer is realized. The entire test does not require manual execution of commands at the bottom layer, and can realize automated testing, saving testing time; if the test process detects a problem with the function, the test result can directly display the problem point; the test method is executed through scripts, and if different systems need to test the dynamic trusted verification function, the scripts are basically compatible.

[0041] Example 2 As attached Figure 3 As shown, this embodiment 2 provides a DCS host computer dynamic trust verification function test system, including a policy configuration module, a file execution module, a status query module, a process tampering module, a status monitoring module and a result output module.

[0042] The policy configuration module is used to enable the dynamic trusted verification function of the DCS host computer to be tested so that the dynamic trusted verification function is in an enabled state; configure the dynamic trusted verification policy for the predetermined executable file in the preset directory to obtain the executable file configured with the trusted verification policy.

[0043] The file execution module is used to use the DCS host computer to execute the executable file configured with the trusted verification strategy to generate an execution process.

[0044] The status query module is used to query the trusted status of the execution process and obtain the status query result of the execution process.

[0045] The process tampering module is used to tamper with the preset data segment of the execution process to make the trusted state of the execution process untrustworthy; wherein the preset data segment of the execution process includes the code segment or read-only data segment of the execution process.

[0046] The state monitoring module is used to monitor the trusted state of the tampered execution process through the dynamic trusted verification state query command provided by the dynamic trusted verification function in the DCS host computer to be tested, and obtain the state monitoring result of the tampered execution process.

[0047] The result output module is used to return the status query result of the execution process and the status monitoring result of the tampered execution process, save them to the test log file, and output the test log file in the format of Hypertext Markup Language HTML to obtain the dynamic trust verification function test result of the DCS host computer to be tested.

[0048] Optionally, the policy configuration module is specifically configured to configure a pre-selected dynamic trusted verification policy in a predetermined executable file using a dynamic trusted verification policy configuration command provided by a dynamic trusted verification function in the DCS host computer to be tested, thereby obtaining an executable file configured with the trusted verification policy.

[0049] Optionally, the status query module is specifically configured to query the trusted status of the execution process through a dynamic trusted verification status query command provided by a dynamic trusted verification function in the DCS host computer to be tested, and obtain a status query result of the execution process.

[0050] Optionally, the status monitoring module is specifically used to monitor and query the trusted status of the tampered execution process through the dynamic trusted verification status query command provided by the dynamic trusted verification function in the DCS host computer to be tested, and obtain the status monitoring result of the tampered execution process.

[0051] Optionally, the dynamic trustworthy verification function test result of the DCS host computer to be tested is output in a format of Hypertext Markup Language HTML.

[0052] Example 3 As attached Figure 4 As shown, this embodiment 3 provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of the DCS host computer dynamic trust verification function testing method when executing the computer program.

[0053] The processor implements the steps of the above-mentioned DCS host computer dynamic trust verification function test method when executing the computer program; for example: turning on the dynamic trust verification function of the DCS host computer to be tested, so that the dynamic trust verification function is in an turned-on state; configuring a dynamic trust verification strategy for a predetermined executable file in a preset directory to obtain an executable file configured with a trust verification strategy; using the DCS host computer to be tested to execute the executable file configured with the trust verification strategy to generate an execution process; querying the trust status of the execution process to obtain a status query result of the execution process; tampering with a preset data segment of the execution process to make the execution process The trusted state of the process is untrusted; wherein, the preset data segment of the execution process includes the code segment or read-only data segment of the execution process; the trusted state of the tampered execution process is monitored through the dynamic trusted verification state query command provided by the dynamic trusted verification function in the DCS host computer to be tested, and the state monitoring result of the tampered execution process is obtained; the state query result of the execution process and the state monitoring result of the tampered execution process are returned and saved to a test log file, and the test log file is output in the format of Hypertext Markup Language HTML to obtain the test result of the dynamic trusted verification function of the DCS host computer to be tested.

[0054] Alternatively, when the processor executes the computer program, the functions of each module in the above-mentioned DCS host computer dynamic trust verification function test system are realized; for example: a policy configuration module is used to enable the dynamic trust verification function of the DCS host computer to be tested, so that the dynamic trust verification function is in an enabled state; a dynamic trust verification policy is configured for a predetermined executable file in a preset directory to obtain an executable file configured with a trust verification policy; a file execution module is used to execute the executable file configured with a trust verification policy using the DCS host computer to be tested to generate an execution process; a status query module is used to query the trust status of the execution process and obtain the status query result of the execution process; a process tampering module is used to tamper with the preset status of the execution process; The invention discloses a method for tampering a data segment of an execution process so as to make the trusted state of the execution process untrustworthy; wherein, the preset data segment of the execution process includes a code segment or a read-only data segment of the execution process; a state monitoring module is used to monitor the trusted state of the tampered execution process through a dynamic trusted verification state query command provided by a dynamic trusted verification function in a DCS host computer to be tested, and obtain a state monitoring result of the tampered execution process; a result output module is used to return the state query result of the execution process and the state monitoring result of the tampered execution process, and save them to a test log file, and output the test log file in a hypertext markup language HTML format to obtain a test result of the dynamic trusted verification function of the DCS host computer to be tested.

[0055] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing preset functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.

[0056] The electronic device may be a computing device such as a desktop computer, laptop, PDA, or cloud server. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will appreciate that the above are examples of electronic devices and do not constitute a limitation on electronic devices. The electronic device may include more components than those described above, or a combination of certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.

[0057] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting all parts of the electronic device using various interfaces and lines.

[0058] The memory may be used to store the computer programs and / or modules, and the processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory.

[0059] The memory may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as sound playback or image playback); the data storage area may store data generated based on the use of the mobile phone (such as audio data and a phone book). Furthermore, the memory may include high-speed random access memory (RAM) and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0060] Example 4 This embodiment 4 further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the method for testing the dynamic trustworthy verification function of a DCS host computer are implemented.

[0061] If the modules / units integrated in the DCS host computer dynamic trustworthy verification function test system are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.

[0062] Based on this understanding, the present invention implements all or part of the process in the above-mentioned DCS host computer dynamic trust verification function test method, and can also be completed by using a computer program to instruct related hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned DCS host computer dynamic trust verification function test method. The computer program includes computer program code, which can be in source code form, object code form, executable file, or preset intermediate form.

[0063] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0064] Example 5 This embodiment 5 provides a computer product, which includes a computer program product, which is stored in a computer-readable storage medium; the processor of the electronic device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the electronic device can execute the DCS host computer dynamic trust verification function testing method described in embodiment 1, which will not be repeated here.

[0065] It should be noted that a person skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods.

[0066] The above embodiment is only one of the implementation methods that can realize the technical solution of the present invention. The scope of protection claimed by the present invention is not limited only to this embodiment, but also includes changes, replacements and other implementation methods that can be easily thought of by any technician familiar with this technical field within the technical scope disclosed by the present invention.

Claims

1. A DCS host computer dynamic trust verification function testing method, characterized in that: include: Configuring a dynamic trusted verification policy for a predetermined executable file to obtain an executable file configured with the trusted verification policy; Use the DCS host computer to execute the executable file configured with the trusted verification strategy to generate the execution process; Query the trusted status of the execution process and obtain the status query result of the execution process; Tampering with a preset data segment of an execution process; wherein the preset data segment of an execution process includes a code segment and a read-only data segment of the execution process; Monitor the trusted state of the tampered execution process and obtain the state monitoring result of the tampered execution process; Based on the status query results of the execution process and the status monitoring results of the tampered execution process, the dynamic trustworthy verification function test results of the DCS host computer to be tested are generated.

2. A DCS host computer dynamic trust verification function testing method according to claim 1, characterized in that: The process of configuring a dynamic trusted verification policy for a predetermined executable file and obtaining the executable file configured with the trusted verification policy is as follows: The dynamic trusted verification policy configuration command provided by the dynamic trusted verification function in the DCS host computer to be tested is used to configure the pre-selected dynamic trusted verification policy in a predetermined executable file to obtain the executable file configured with the trusted verification policy.

3. A DCS host computer dynamic trust verification function testing method according to claim 1, characterized in that: The process of querying the trusted status of the execution process and obtaining the status query result of the execution process is as follows: The trusted status of the execution process is queried through the dynamic trusted verification status query command provided by the dynamic trusted verification function in the DCS host computer to be tested, and the status query result of the execution process is obtained.

4. A DCS host computer dynamic trust verification function testing method according to claim 1, characterized in that: The process of monitoring the trusted state of the tampered execution process and obtaining the state monitoring result of the tampered execution process is as follows: Through the dynamic trust verification status query command provided by the dynamic trust verification function in the DCS host computer to be tested, the trust status of the tampered execution process is monitored and queried to obtain the status monitoring result of the tampered execution process.

5. A DCS host computer dynamic trust verification function testing method according to claim 1, characterized in that: The dynamic trustworthy verification function test results of the DCS host computer to be tested are output in the format of Hypertext Markup Language HTML.

6. A DCS host computer dynamic trust verification function testing method according to claim 1, characterized in that: If the status query result of the execution process changes as the preset data segment of the execution process is tampered with, and the status monitoring result of the tampered execution process is able to control the execution process according to the control measures of the configured dynamic trustworthy verification policy, the dynamic trustworthy verification function test result of the DCS host computer to be tested is normal; When the status query result of the execution process does not change even though the preset data segment of the execution process is tampered with, and the status monitoring result of the tampered execution process is that the execution process cannot be controlled according to the control measures of the configured dynamic trustworthy verification strategy, the dynamic trustworthy verification function test result of the DCS host computer to be tested is abnormal.

7. A DCS host computer dynamic trust verification function test system, characterized in that: include: A policy configuration module is used to configure a dynamic trusted verification policy for a predetermined executable file and obtain an executable file configured with the trusted verification policy; The file execution module is used to use the DCS host computer to execute the executable file configured with the trusted verification strategy to generate an execution process; The status query module is used to query the trusted status of the execution process and obtain the status query result of the execution process; A process tampering module is used to tamper with a preset data segment of an execution process; wherein the preset data segment of the execution process includes a code segment and a read-only data segment of the execution process; A state monitoring module is used to monitor the trusted state of the tampered execution process and obtain the state monitoring result of the tampered execution process; The result output module is used to generate the dynamic trustworthy verification function test results of the DCS host computer to be tested based on the status query results of the execution process and the status monitoring results of the tampered execution process.

8. An electronic device, characterized in that: include: a processor suitable for executing a computer program; A computer-readable storage medium having a computer program stored therein, wherein when the computer program is executed by the processor, the method for testing the dynamic trusted verification function of a DCS host computer according to any one of claims 1 to 6 is executed.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the DCS host computer dynamic trustworthy verification function testing method according to any one of claims 1 to 6 is implemented.

10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the DCS host computer dynamic trust verification function testing method according to any one of claims 1 to 6 is implemented.