Product detection method and system capable of providing multiple password functions
By conducting correlation and security isolation tests on all-in-one password products, the security problem of the existing technology that is unable to fully test all-in-one password products is solved, and security testing and improvement of multiple password functions are achieved.
Patent Information
- Application Number
- CN202510880825.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-10-03
AI Technical Summary
Existing technologies are unable to conduct comprehensive testing on all-in-one cryptographic products, resulting in the inability to discover functional conflicts and security risks, and the inability to effectively detect security issues between multiple cryptographic functions.
By conducting security tests on multiple related cryptographic applications on all-in-one cryptographic products, the correlation and security isolation between cryptographic applications are detected, warnings and error messages are output, and security issues are resolved and risks are improved based on this information.
We have achieved comprehensive security testing of all-in-one cryptographic products, discovered and resolved security and isolation issues between cryptographic applications, and ensured the security and stable operation of cryptographic products.
Smart Images

Figure CN120744898A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of password product detection, and in particular to a product detection method and system providing multiple password functions. Background Art
[0002] With the continuous development of science and technology, more and more scenarios require the use of cryptographic products to ensure data security; among them, traditional cryptographic products are mainly single cryptographic product types, and their cryptographic applications and cryptographic functions are set in a single way; therefore, the current detection methods for conventional cryptographic products are designed and implemented according to the functions of a single cryptographic product type.
[0003] At present, with the complexity and diversification of usage scenarios, the functions of cryptographic products are also constantly expanding; currently, all-in-one cryptographic products have been developed, which have multiple cryptographic applications and cryptographic functions at the same time, and a type of configuration parameters of all-in-one cryptographic products provide input for multiple cryptographic applications at the same time.
[0004] Currently, the testing of all-in-one cryptographic products can only test their functions separately according to a single product type. It lacks the overall consideration of the product and the potential security risks such as functional conflicts, interface conflicts, and key management conflicts that may arise when the functions of different types of cryptographic products are concentrated in the same cryptographic product.
[0005] Therefore, the present invention provides a product detection method and system that provides multiple password functions to solve the technical problem that the existing technology cannot perform product detection of comprehensive password functions on all-in-one password products, thereby failing to effectively detect possible security risks. Summary of the Invention
[0006] The purpose of the present invention is to overcome the shortcomings of the prior art and provide a product testing method and system that provides multiple cryptographic functions. By running multiple related cryptographic applications of a cryptographic product and performing correlation security tests between cryptographic applications on the cryptographic product, security issues existing between multiple related cryptographic applications can be discovered.
[0007] To achieve the above objectives, the present application proposes a product testing method that provides multiple cryptographic functions, which is used to test an all-in-one cryptographic product that provides multiple cryptographic functions; wherein the product testing includes: Collect the cryptographic product information of the tested cryptographic product and verify the roles, compile the functional test task list and functional test task data based on the roles and the provided cryptographic functions, and run the various cryptographic functions of the product; Run multiple related cryptographic applications of the cryptographic product, perform security tests on the correlation between cryptographic applications of the cryptographic product, and output warning and error messages generated during the test; Conduct cryptographic application and cryptographic function security isolation tests on cryptographic products, and output warning and error messages generated during the test; Solve security issues of the tested cryptographic products based on error information, and improve security risks of the tested cryptographic products based on alarm information.
[0008] As a further solution, the integrity of the cryptographic functions is checked; wherein, the cryptographic functions at least include device initialization, administrator management, configuration policy, log auditing, key lifecycle management and API interface calling.
[0009] As a further solution, the security test of the correlation between the cryptographic applications is performed by the following steps: Collect cryptographic product information of the tested cryptographic products, verify the correlation between the cryptographic functions of the cryptographic products, and compile a correlation test list and correlation test task data based on the correlation; Run multiple related cryptographic applications of the cryptographic product to detect whether each cryptographic application uses independent input / output. If not, there is a security issue with the correlation between the cryptographic applications, and an error message is output; Run multiple related cryptographic applications of the cryptographic product and check whether each cryptographic application is started independently. If they are not started independently, there is a security issue with the correlation between the cryptographic applications, and an error message is output; Run multiple related cryptographic applications of the cryptographic product and detect whether the operation of each cryptographic application affects other applications; if other applications are affected, output an alarm message; Among them, the impact on other applications includes memory space impact, performance efficiency impact, running step impact and running result impact.
[0010] As a further solution, the cryptographic application and cryptographic function security isolation test is performed through the following steps: Detect whether different password applications and password functions of password products use different API interfaces; if different API interfaces are not used, output alarm information; Detect whether the cryptographic product key is used in multiple cryptographic application scenarios simultaneously. If it is detected that the key is used in multiple cryptographic application scenarios simultaneously, there is a security isolation issue and an error message is output; Check whether different administrators are established to manage different password applications and password functions in the password product; if the administrator's permissions cannot be allocated according to the password application scenario, an alarm message will be output; Detect whether the keys of different cryptographic applications of cryptographic products are identified; if not, output an alarm message; Check whether cryptographic products have independent management methods for keys with different identifiers; if there are no independent management methods, output an alarm message; Check whether different types of password applications of the password product are configured with separate whitelists; if any password business function is not configured with a separate whitelist, an alarm message will be output.
[0011] As a further solution, the cryptographic algorithms of cryptographic products are also tested; among them, Identify the cryptographic algorithm used based on the cryptographic product documentation; if any of the symmetric, asymmetric, public-key, and hash cryptographic algorithms is missing, output a warning message; If a symmetric cryptographic algorithm is available, the supported cryptographic algorithm and encrypted sample data of various modes are substituted for encryption and decryption calculations. If this is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output. If an asymmetric cryptographic algorithm is available, the sample data for encryption, decryption, and signature verification is substituted for the operation. If this is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output. If a hash cryptographic algorithm is available, the sample data for calculating the hash value is substituted for the operation; if it is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output.
[0012] As a further solution, the random numbers of the cryptographic products are also tested; among them, Identify the random source generator based on the cryptographic product information; if the random source generator is missing, output a warning message; Collect random numbers and test their randomness and significance level; if the randomness or significance level does not meet the preset results, there is a random number security issue and an error message is output.
[0013] As a further solution, key management testing is also performed on cryptographic products; among them, Check whether key generation relies on random numbers. If it does not, there is a key management security issue and an error message is output. Identify the key type used by the cryptographic product based on the cryptographic product information; if there is no key, output an alarm message; Check whether the plaintext of the symmetric key and private key can be directly read. If the plaintext key can be directly read, there is a key management security issue and an error message is output. Check whether the key distribution process uses cryptographic technology to ensure key authenticity, cryptographic technologies such as digital signatures and HMAC to ensure key integrity, and symmetric encryption and public key encryption to ensure key confidentiality. If any of authenticity, integrity, and confidentiality are not protected, there is a key management security issue and an error message is output. Check whether encryption or knowledge splitting is used during key import and export. If encryption or knowledge splitting is not used, there is a key management security issue and an error message is output. Check whether the key can be accessed, used, or tampered with by unauthorized access roles. If the key can be accessed, used, or tampered with by unauthorized access roles, an error message will be output. Check whether the key in the cryptographic product supports update; if the key is not updated, output a warning message; Detects whether the cryptographic product key backup is performed in ciphertext or using a threshold algorithm. If it is not, there is a key management security issue and an error message is output. Checks whether the cryptographic product has an asymmetric key pair that identifies the device. If the asymmetric key pair does not exist, a warning is output.
[0014] As a further solution, role management detection is also carried out on password products; among them, Identify, based on the password product information, whether the administrator identity authentication mechanism of the password product adopts an authentication mechanism based on password technology; if the authentication mechanism based on password technology is not adopted, output a warning message; Based on the password product information, check whether the management role has permissions that exceed the authorized scope; if there are permissions that exceed the authorized scope, there is a role management security issue and an error message is output.
[0015] As a further solution, log auditing and testing of cryptographic products are also carried out; among them, Check whether the log audit function records the operation time, operation role, operation behavior, and operation results. If any of these items are not recorded, there is a log audit security issue and an error message is output. Check whether the log supports the anti-tampering function. If the anti-tampering function is not supported, there is a log audit security issue and an error message is output; Check whether the anti-tampering technology used in the log uses cryptographic technology; if cryptographic technology is not used, output an alarm message.
[0016] In another aspect, the present invention further provides a product detection system providing multiple password functions, comprising: A data collection module, used to collect the cryptographic product data of the cryptographic product under inspection; A detection execution module, configured to execute a product detection method providing multiple cryptographic functions as described in any one of the above items to perform product detection on the cryptographic product under detection; Information output module: outputs the warning information and error information generated during the test process; wherein, the error information is used to solve the security problems of the tested cryptographic product, and the warning information is used to improve the security risks of the tested cryptographic product.
[0017] Compared with related technologies, the product detection method and system providing multiple password functions provided by the present invention have the following advantages: The present invention compiles a functional test task list and functional test task data according to the role and the provided cryptographic function, runs various cryptographic functions of the product, then runs multiple related cryptographic applications of the cryptographic product, and performs correlation security tests between cryptographic applications on the cryptographic product, thereby discovering security issues between multiple related cryptographic applications; on this basis, the cryptographic product is subjected to security isolation tests of cryptographic applications and cryptographic functions, thereby discovering security isolation issues between cryptographic applications and cryptographic functions; this solves the technical problem that the current detection of all-in-one cryptographic products can only detect their functions separately according to a single product type, and forms a universal and reusable detection method for all-in-one products. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0020] Figure 1 This is an overall flow chart of a product detection method providing multiple password functions provided by the present invention; Figure 2 This is a structural diagram of a product detection system providing multiple password functions provided by the present invention.
[0021] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0022] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.
[0023] Example 1 See also Figure 1 The present invention provides a method for testing a product that provides multiple password functions, which is used to test an all-in-one password product that provides multiple password functions. The method includes: Collect the cryptographic product information of the tested cryptographic product and verify the roles, compile the functional test task list and functional test task data based on the roles and the provided cryptographic functions, and run the various cryptographic functions of the product; Run multiple related cryptographic applications of the cryptographic product, perform security tests on the correlation between cryptographic applications of the cryptographic product, and output warning and error messages generated during the test; Conduct cryptographic application and cryptographic function security isolation tests on cryptographic products, and output warning and error messages generated during the test; Solve security issues of the tested cryptographic products based on error information, and improve security risks of the tested cryptographic products based on alarm information.
[0024] It should be noted that the current testing of all-in-one cryptographic products can only test their functions separately according to a single product type. Therefore, it is impossible to discover security issues between multiple related cryptographic applications, nor can it discover security isolation issues between cryptographic applications and cryptographic functions. Therefore, conventional cryptographic detection technology cannot detect functional conflicts and security design risks in all-in-one cryptographic products.
[0025] To this end, this embodiment compiles a functional test task list and functional test task data based on the role and the provided cryptographic functions, runs the various cryptographic functions of the product, then runs multiple related cryptographic applications of the cryptographic product, and performs correlation security tests between cryptographic applications on the cryptographic product, thereby discovering security issues between multiple related cryptographic applications; on this basis, the cryptographic product is subjected to security isolation tests of cryptographic applications and cryptographic functions, thereby discovering security isolation issues between cryptographic applications and cryptographic functions.
[0026] Furthermore, the integrity of the cryptographic functions is checked; wherein, the cryptographic functions at least include device initialization, administrator management, configuration policy, log auditing, key lifecycle management and API interface calling; if basic cryptographic functions are lacking, the security and normal operation of the cryptographic product cannot be guaranteed.
[0027] When performing security testing for correlation between cryptographic applications, it's necessary to determine the correlation between the cryptographic functions of cryptographic products, thereby compiling an effective correlation test checklist and correlation test task data. Specifically, correlation between cryptographic applications refers to the correlation between the input and output, configuration parameters, and key lifecycle management of various types of cryptographic products. For example, both timestamp servers and signature verification servers require time signals from a trusted time source, and both SSL VPN products and IPSec products require device keys for key negotiation.
[0028] Specifically, the security test of the correlation between cryptographic applications is carried out through the following steps: Collect cryptographic product information of the tested cryptographic products, verify the correlation between the cryptographic functions of the cryptographic products, and compile a correlation test list and correlation test task data based on the correlation; Run multiple related cryptographic applications of the cryptographic product to detect whether each cryptographic application uses independent input / output. If not, there is a security issue with the correlation between the cryptographic applications, and an error message is output; Run multiple related cryptographic applications of the cryptographic product and check whether each cryptographic application is started independently. If they are not started independently, there is a security issue with the correlation between the cryptographic applications, and an error message is output; Run multiple related cryptographic applications of the cryptographic product and detect whether the operation of each cryptographic application affects other applications; if other applications are affected, output an alarm message; Among them, the impact on other applications includes memory space impact, performance efficiency impact, running step impact and running result impact.
[0029] Through security testing of the correlation between cryptographic applications, we can discover security issues hidden between related cryptographic applications and propose improvement measures. For example, if the input / output is not independent, we develop independent input / output interfaces and incorporate them. If we detect that each cryptographic application is not started independently, we rewrite the initialization startup program to start it in isolation. If we detect that the operation of each cryptographic application affects other applications, we can make device adjustments based on the impact. When memory space is affected, the memory space of each cryptographic application is isolated; when performance efficiency is affected, it is determined whether the impact comes from software conflict or hardware limitation. If it is a software conflict, software performance optimization is performed; if it is a hardware limitation, the corresponding hardware module is expanded to enhance hardware performance; when the operation steps are affected, asynchronous processing is used to stagger the operation steps to run in the common frame. If there is an impact on the operation results, the results are compared and the valid result data is retained.
[0030] Furthermore, the cryptographic application and cryptographic function security isolation test is carried out through the following steps: Detect whether different password applications and password functions of password products use different API interfaces; if different API interfaces are not used, output alarm information; Note: Only the input parameters of the API interfaces are different. If no input is given, they do not belong to different API interfaces. We need to identify the API interfaces to truly determine whether they are different API interfaces.
[0031] Detect whether the cryptographic product key is used in multiple cryptographic application scenarios simultaneously. If it is detected that the key is used in multiple cryptographic application scenarios simultaneously, there is a security isolation issue and an error message is output; Check whether different administrators are established to manage different password applications and password functions in the password product; if the administrator's permissions cannot be allocated according to the password application scenario, an alarm message will be output; Detect whether the keys of different cryptographic applications of cryptographic products are identified; if not, output an alarm message; Check whether cryptographic products have independent management methods for keys with different identifiers; if there are no independent management methods, output an alarm message; Check whether different types of password applications of the password product are configured with separate whitelists; if any password business function is not configured with a separate whitelist, an alarm message will be output.
[0032] Through the security isolation test of cryptographic applications and cryptographic functions, we can realize the isolation test of cryptographic products, so as to ensure the isolation of cryptographic applications and cryptographic functions that need to run independently, thereby solving the problem that the current technology of testing the functions of a single product type cannot discover the security isolation problem between cryptographic applications and cryptographic functions.
[0033] Furthermore, in order to ensure that the cryptographic algorithms of cryptographic products are reliable and effective, we also test the cryptographic algorithms of cryptographic products; Identify the cryptographic algorithm used based on the cryptographic product documentation; if any of the symmetric, asymmetric, public-key, and hash cryptographic algorithms is missing, output a warning message; If a symmetric cryptographic algorithm is available, the supported cryptographic algorithm and encrypted sample data of various modes are substituted for encryption and decryption calculations. If this is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output. If an asymmetric cryptographic algorithm is available, the sample data for encryption, decryption, and signature verification is substituted for the operation. If this is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output. If a hash cryptographic algorithm is available, the sample data for calculating the hash value is substituted for the operation; if it is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output.
[0034] By testing the cryptographic algorithms of cryptographic products, we can ensure that all-in-one cryptographic products have different cryptographic algorithms and that each cryptographic algorithm is reliable and effective, thereby ensuring the stable use of all-in-one cryptographic products.
[0035] All-in-one password products must use random number generators; therefore, we also test the random numbers of password products; Identify the random source generator based on the cryptographic product information; if the random source generator is missing, output a warning message; Collect random numbers and test their randomness and significance level; if the randomness or significance level does not meet the preset results, there is a random number security issue and an error message is output.
[0036] In cryptography or scientific experiments, random number generators are usually required to pass multiple tests, and the significance level is set more strictly. Among them, randomness is the unpredictable and patternless property of the sequence, which needs to be verified through statistical tests. The significance level α is the threshold for judging randomness and controlling the risk of false positives.
[0037] Randomness refers to the unpredictable and irregular nature of data or sequences. An ideal random number should satisfy the following properties: Uniform distribution: All possible values have equal probability of occurring.
[0038] Independence: Each number in the sequence is independent of other numbers, and historical data cannot predict future values.
[0039] Irreproducibility: The inability to reproduce a sequence from known information (especially in cryptography).
[0040] Randomness test method Randomness is verified through statistical tests. Common tests include: Monobit Test: Test whether the distribution of 0 and 1 is balanced.
[0041] Runs Test: Checks whether the length of consecutive runs of the same value is random.
[0042] Chi-square Test: Evaluates the deviation of observed values from the theoretical distribution.
[0043] Serial Test: Verify whether the distribution of overlapping patterns is uniform.
[0044] Complexity tests (such as Lempel-Ziv): evaluate the difficulty of compressing a sequence.
[0045] Significance Level The significance level (α) is the threshold used in hypothesis testing to determine whether to reject the null hypothesis. It represents the maximum probability of making a Type I error (false positive). Common values are 0.05 (5%) or 0.01 (1%).
[0046] Application in randomness test: Null hypothesis (H0): The sequence is random. Alternative hypothesis (H1): The sequence is not random. Test process: Calculate statistics (such as p-values).
[0047] If the p-value is less than α, H0 is rejected and the sequence is considered non-random; otherwise, it is not rejected.
[0048] p-value: The probability of observing the current statistic or a more extreme value when H0 holds. Small p-values → strong evidence to reject H0; large p-values → insufficient evidence to reject H0. The choice of α: The smaller α, the stricter the test (for example, in cryptography, α = 0.001 may be required).
[0049] Furthermore, key management testing is also performed on cryptographic products; Check whether key generation relies on random numbers. If not, there is a key management security issue and an error message is output. Check whether the key generation algorithm uses a standard random number generator (such as DRBG in NIST SP 800-90A). Verify whether the random number seed has sufficient entropy (such as from a hardware noise source).
[0050] Identify the key type used by the cryptographic product based on the product documentation. If no key is available, an alarm message will be output. Analyze the product documentation or code to confirm the key usage (such as AES key, RSA public and private key, ECC key, etc.).
[0051] Check whether the symmetric key and private key can be directly read in plain text. If the plain text key can be directly read, there is a key management security issue and an error message is output. Check the key storage method in memory, disk, or database (such as whether it is encrypted or uses a hardware security module (HSM)).
[0052] Check whether the key distribution process uses cryptographic technology to ensure key authenticity, cryptographic technologies such as digital signatures and HMAC to ensure key integrity, and symmetric encryption and public key encryption to ensure key confidentiality. If any of authenticity, integrity, and confidentiality are not protected, there is a key management security issue and an error message is output. Detection logic: Authenticity: Whether a digital signature or HMAC is used to verify the sender's identity. Integrity: Whether a MAC or signature is used to protect the key from tampering. Confidentiality: Whether symmetric encryption (such as AES) or public key encryption (such as RSA-OAEP) is used to protect the key.
[0053] Detect whether encryption or knowledge splitting is used during key import and export. If encryption or knowledge splitting is not used, there is a key management security issue and an error message is output. Detection logic: Check whether the key exists in ciphertext form during transmission or storage. If splitting is used, verify whether the threshold algorithm meets the standard (for example, at least k / n shards are required for recovery). Checks whether the key can be accessed, used, or tampered with by unauthorized roles. If so, an error is output. Detection logic: Checks whether the permission model (such as RBAC) strictly isolates key operation permissions. Tests for unauthorized access (such as a regular user attempting to read an administrator's key).
[0054] Detect whether the key in the cryptographic product supports update; if the key is not updated, output a warning message; detection logic: check whether the product supports the key rotation policy (such as time period or event trigger).
[0055] Checks whether cryptographic product key backups are performed in ciphertext or using a threshold algorithm. If not, a key management security issue exists and an error message is output. Detection logic: Verifies whether the backup file is encrypted (e.g., using AES-GCM). If sharded backups are used, checks whether the shards are stored in a distributed manner.
[0056] Checks whether the cryptographic product has an asymmetric key pair that identifies the device. If the asymmetric key pair does not exist, a warning is output. Detection logic: Checks whether the device has a unique key pair (such as RSA / ECC) and is bound to a trusted CA.
[0057] Furthermore, role management testing is also conducted on password products; among them, Identify, based on the password product information, whether the administrator identity authentication mechanism of the password product adopts an authentication mechanism based on password technology; if the authentication mechanism based on password technology is not adopted, output a warning message; Detection logic: Check product documentation or configuration to confirm the administrator login method: Mechanisms that comply with cryptographic technology: public key authentication (such as X.509 certificate + digital signature), HMAC-based dynamic tokens (such as TOTP), biometric + password hybrid authentication (cryptographically protected template storage is required).
[0058] Mechanisms that do not comply with cryptographic technology: Weak authentication methods such as username / static password only (without encryption or hashing), IP whitelisting, or hardware characteristics (such as MAC address).
[0059] Based on the password product information, check whether the management role has permissions that exceed the authorized scope; if there are permissions that exceed the authorized scope, there is a role management security issue and an error message is output.
[0060] Detection logic Permission model analysis: Extract role permission definitions based on product documentation (such as the role-permission mapping table in the RBAC model). Compare actual permissions with the principle of least privilege. For example, a security administrator should only configure key policies and should not have direct access to plaintext keys. An auditor should only view logs and should not be able to modify configurations.
[0061] Test verification: Attempt to perform unauthorized operations (such as key export and policy modification) with an administrative role.
[0062] Furthermore, we also conduct log auditing and testing on cryptographic products; Check whether the log audit function records the operation time, operation role, operation behavior, and operation results. If any of these items are not recorded, there is a log audit security issue and an error message is output. Check whether the log supports the anti-tampering function. If the anti-tampering function is not supported, there is a log audit security issue and an error message is output; Check whether the anti-tampering technology used in the log uses cryptographic technology; if cryptographic technology is not used, output an alarm message.
[0063] Example 2 See also Figure 2 The present invention also provides a product detection system providing multiple password functions, including: A data collection module, used to collect the cryptographic product data of the cryptographic product under inspection; A detection execution module, configured to execute a product detection method providing multiple cryptographic functions as described in any one of the above items to perform product detection on the cryptographic product under detection; Information output module: outputs the warning information and error information generated during the test process; wherein, the error information is used to solve the security problems of the tested cryptographic product, and the warning information is used to improve the security risks of the tested cryptographic product.
[0064] The above are only some embodiments of the present application and are not intended to limit the patent scope of the present application. All equivalent structural transformations made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A product testing method providing multiple password functions, characterized in that: Used to test all-in-one cryptographic products that provide multiple cryptographic functions; wherein the product testing includes: Collect the cryptographic product information of the tested cryptographic product and verify the roles, compile the functional test task list and functional test task data based on the roles and the provided cryptographic functions, and run the various cryptographic functions of the product; Run multiple related cryptographic applications of the cryptographic product, perform security tests on the correlation between cryptographic applications of the cryptographic product, and output warning and error messages generated during the test; Conduct cryptographic application and cryptographic function security isolation tests on cryptographic products, and output warning and error messages generated during the test; Solve security issues of the tested cryptographic products based on error information, and improve security risks of the tested cryptographic products based on alarm information.
2. A product detection method providing multiple password functions according to claim 1, characterized in that: Verify the integrity of the cryptographic functions; wherein the cryptographic functions at least include device initialization, administrator management, configuration policy, log auditing, key lifecycle management and API interface calling.
3. The method for detecting a product providing multiple password functions according to claim 1, characterized in that: The security test of the correlation between the cryptographic applications is performed by the following steps: Collect cryptographic product information of the tested cryptographic products, verify the correlation between the cryptographic functions of the cryptographic products, and compile a correlation test list and correlation test task data based on the correlation; Run multiple related cryptographic applications of the cryptographic product to detect whether each cryptographic application uses independent input / output. If not, there is a security issue with the correlation between the cryptographic applications, and an error message is output; Run multiple related cryptographic applications of the cryptographic product and check whether each cryptographic application is started independently. If they are not started independently, there is a security issue with the correlation between the cryptographic applications, and an error message is output; Run multiple related cryptographic applications of the cryptographic product and detect whether the operation of each cryptographic application affects other applications; if other applications are affected, output an alarm message; Among them, the impact on other applications includes memory space impact, performance efficiency impact, running step impact and running result impact.
4. The method for detecting a product providing multiple password functions according to claim 1, wherein: The password application and password function security isolation test is carried out through the following steps: Detect whether different password applications and password functions of password products use different API interfaces; if different API interfaces are not used, output alarm information; Detect whether the cryptographic product key is used in multiple cryptographic application scenarios simultaneously. If it is detected that the key is used in multiple cryptographic application scenarios simultaneously, there is a security isolation issue and an error message is output; Check whether different administrators are established to manage different password applications and password functions in the password product; if the administrator's permissions cannot be allocated according to the password application scenario, an alarm message will be output; Detect whether the keys of different cryptographic applications of cryptographic products are identified; if not, output an alarm message; Check whether cryptographic products have independent management methods for keys with different identifiers; if there are no independent management methods, output an alarm message; Check whether different types of password applications of the password product are configured with separate whitelists; if any password business function is not configured with a separate whitelist, an alarm message will be output.
5. The method for detecting a product providing multiple password functions according to claim 1, wherein: The cryptographic algorithms of cryptographic products are also tested; among them, Identify the cryptographic algorithm used based on the cryptographic product documentation; if any of the symmetric, asymmetric, public-key, and hash cryptographic algorithms is missing, output a warning message; If a symmetric cryptographic algorithm is available, the supported cryptographic algorithm and encrypted sample data of various modes are substituted for encryption and decryption calculations. If this is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output. If an asymmetric cryptographic algorithm is available, the sample data for encryption, decryption, and signature verification is substituted for the operation. If this is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output. If a hash cryptographic algorithm is available, the sample data for calculating the hash value is substituted for the operation; if it is not implemented correctly, there is a cryptographic algorithm security issue and an error message is output.
6. The method for detecting a product providing multiple password functions according to claim 1, wherein: The random numbers of cryptographic products are also tested; among them, Identify the random source generator based on the cryptographic product information; if the random source generator is missing, output a warning message; Collect random numbers and test their randomness and significance level; if the randomness or significance level does not meet the preset results, there is a random number security issue and an error message is output.
7. The method for detecting a product providing multiple password functions according to claim 1, wherein: Key management testing is also performed on cryptographic products; among them, Check whether key generation relies on random numbers. If it does not, there is a key management security issue and an error message is output. Identify the key type used by the cryptographic product based on the cryptographic product information; if there is no key, output an alarm message; Check whether the plaintext of the symmetric key and private key can be directly read. If the plaintext key can be directly read, there is a key management security issue and an error message is output. Check whether the key distribution process uses cryptographic technology to ensure key authenticity, cryptographic technologies such as digital signatures and HMAC to ensure key integrity, and symmetric encryption and public key encryption to ensure key confidentiality. If any of authenticity, integrity, and confidentiality are not protected, there is a key management security issue and an error message is output. Check whether encryption or knowledge splitting is used during key import and export. If encryption or knowledge splitting is not used, there is a key management security issue and an error message is output. Check whether the key can be accessed, used, or tampered with by unauthorized access roles. If the key can be accessed, used, or tampered with by unauthorized access roles, an error message will be output. Check whether the key in the cryptographic product supports update; if the key is not updated, output a warning message; Detects whether the cryptographic product key backup is performed in ciphertext or using a threshold algorithm. If it is not, there is a key management security issue and an error message is output. Checks whether the cryptographic product has an asymmetric key pair that identifies the device. If the asymmetric key pair does not exist, a warning is output.
8. The method for detecting a product providing multiple password functions according to claim 1, wherein: We also conduct role management testing on password products; among them, Identify, based on the password product information, whether the administrator identity authentication mechanism of the password product adopts an authentication mechanism based on password technology; if the authentication mechanism based on password technology is not adopted, output a warning message; Based on the password product information, check whether the management role has permissions that exceed the authorized scope; if there are permissions that exceed the authorized scope, there is a role management security issue and an error message is output.
9. The method for detecting a product providing multiple password functions according to claim 2, wherein: We also conduct log audits on cryptographic products; among them, Check whether the log audit function records the operation time, operation role, operation behavior, and operation results. If any of these items are not recorded, there is a log audit security issue and an error message is output. Check whether the log supports the anti-tampering function. If the anti-tampering function is not supported, there is a log audit security issue and an error message is output; Check whether the anti-tampering technology used in the log uses cryptographic technology; if cryptographic technology is not used, output an alarm message.
10. A product detection system providing multiple password functions, characterized in that: include: A data collection module, used to collect the cryptographic product data of the cryptographic product under inspection; A detection execution module, configured to execute the product detection method providing multiple cryptographic functions according to any one of claims 1 to 9 to perform product detection on the cryptographic product to be detected; Information output module: outputs the warning information and error information generated during the test process; wherein, the error information is used to solve the security problems of the tested cryptographic product, and the warning information is used to improve the security risks of the tested cryptographic product.
Citation Information
Patent Citations
Cloud password service product SDK automatic test method, system, medium and equipment
CN116010285A
Cloud password detection method and system
CN116260595A
Password application monitoring method, system and equipment and storage medium
CN116318777A
Method for detecting capability of relieving non-invasive attack for password product
CN118862076A
Database security detection method and system for password protection
CN119918041A