TCG protocol function test method and device, readable storage medium and electronic equipment
By defining a Trusted Computing Organization (TCG) test interface, low-cost and reliable testing of the TCG protocol functionality was achieved, overcoming the limitations and high costs of existing testing methods and ensuring the comprehensiveness and accuracy of the tests.
Patent Information
- Application Number
- CN202511441663.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2025-12-30
AI Technical Summary
Existing TCG protocol functional testing methods cannot perform detailed testing of tables, methods, and objects in the TCG storage protocol, and rely on third-party paid tools, which are costly.
Define the trusted computing organization test interface, including the interface for opening sessions with specific permissions, operations, and recovery operations, and conduct specialized tests through the receiving method.
It enables automated testing of TCG protocol functions, reducing testing costs and improving testing reliability.
Smart Images

Figure CN121237166A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of hard disk testing technology, and in particular to a TCG protocol function testing method, apparatus, readable storage medium, and electronic device. Background Technology
[0002] The Trusted Computing Group (TCG) protocol functional testing is a testing method for the security functions of solid-state drives (SSDs). Most existing TCG protocol functional tests are implemented using the kernel-space sedutil-cli tool (a command-line tool for managing and configuring self-encrypting drives compliant with the TCG OPAL 2.0 standard) or user-space third-party tools. Using sedutil-cli can only verify basic functions and cannot perform detailed testing of tables, methods, and objects in the TCG storage protocol, making it unsuitable for development and testing. User-space testing relies on paid third-party tools, which are costly. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a TCG protocol function testing method, apparatus, readable storage medium and electronic device to achieve low-cost and reliable TCG protocol function testing.
[0004] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: A TCG protocol functional testing method includes the following steps: Define a Trusted Computing Organization Test Interface, which includes an interface for opening a session with specific permissions, an interface for manipulating tables, an interface for closing a session, and an interface for resuming operations. Receives a request for a functional test of the Trusted Computing Organization Protocol (TCP) for solid-state drives; According to the Trusted Computing Organization Protocol Functional Test Request, the interface for enabling sessions with specific permissions, the interface for the operation table, the interface for closing sessions, and the interface for recovery operations are invoked to perform specific recovery operation tests on the solid-state drive under different permissions.
[0005] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: A TCG protocol function testing device, comprising: The interface definition module is used to define the test interface of the Trusted Computing Organization. The test interface of the Trusted Computing Organization includes an interface for opening a session with specific permissions, an interface for operating the table, an interface for closing the session, and an interface for restoring the operation. The request receiving module is used to receive Trusted Computing Organization Protocol Functionality Test requests for solid-state drives. The testing module is used to call the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation to perform a special test on the solid-state drive under different permissions according to the Trusted Computing Organization Protocol Functional Test Request.
[0006] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the various steps in the above-described TCG protocol functional testing method.
[0007] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the various steps in the TCG protocol functional testing method described above.
[0008] The beneficial effects of this invention are as follows: It defines a Trusted Computing Organization (TCG) test interface, which includes an interface for opening sessions with specific permissions, an interface for operation tables, an interface for closing sessions, and a recovery operation interface. Based on the received TCG protocol function test request, it calls the interfaces for opening sessions with specific permissions, the interface for operation tables, the interface for closing sessions, and the recovery operation interface to perform special tests on the recovery operation of the solid-state drive under different permissions. It does not rely on third-party paid tools. By utilizing the defined multiple test interfaces, it can realize automated special tests on the recovery operation (Revert) of the TCG protocol function under different permissions, which is more comprehensive and detailed, thereby realizing low-cost and reliable TCG protocol function testing. Attached Figure Description
[0009] Figure 1 This is a flowchart illustrating the steps of a TCG protocol function testing method according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the structure of a TCG protocol function testing device according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention; Figure 4 This is a flowchart of the AdminSP Revert operation test under the enabled security identifier permission in a TCG protocol function test method according to an embodiment of the present invention. Figure 5 This is a flowchart of the LockingSP Revert operation test under the enabled security identifier permission in a TCG protocol function test method according to an embodiment of the present invention. Figure 6This is a flowchart of the AdminSPRevert operation test under Admin1 privileges in a TCG protocol function test method according to an embodiment of the present invention. Figure 7 This is a flowchart of the LockingSP Revert operation test under Admin1 privileges in a TCG protocol function test method according to an embodiment of the present invention. Detailed Implementation
[0010] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.
[0011] Please refer to Figure 1 A TCG protocol functional testing method, comprising the following steps: Define a Trusted Computing Organization Test Interface, which includes an interface for opening a session with specific permissions, an interface for manipulating tables, an interface for closing a session, and an interface for resuming operations. Receives a request for a functional test of the Trusted Computing Organization Protocol (TCP) for solid-state drives; According to the Trusted Computing Organization Protocol Functional Test Request, the interface for enabling sessions with specific permissions, the interface for the operation table, the interface for closing sessions, and the interface for recovery operations are invoked to perform specific recovery operation tests on the solid-state drive under different permissions.
[0012] As can be seen from the above description, the beneficial effects of the present invention are as follows: A Trusted Computing Organization (TCG) test interface is defined, which includes an interface for opening sessions with specific permissions, an interface for operation tables, an interface for closing sessions, and a recovery operation interface. Based on the received TCG protocol function test request, the interface for opening sessions with specific permissions, the interface for operation tables, the interface for closing sessions, and the recovery operation interface are called to perform specialized recovery operation tests on the solid-state drive under different permissions. This eliminates the need to rely on third-party paid tools. Utilizing the defined multiple test interfaces, specialized automated testing of the recovery operation (Revert) of the TCG protocol function under different permissions can be achieved, providing a more comprehensive and detailed result, thereby realizing low-cost and reliable TCG protocol function testing.
[0013] Furthermore, the Trusted Computing Organization Protocol Functionality Test Request includes a Management Security Parameter Recovery Operation Test Request under Security Identifier Permissions; The interface for enabling sessions with specific permissions includes the interface for enabling sessions with security identifier permissions. The recovery operation interface includes a recovery management security parameter interface; The specific test of performing recovery operations on the solid-state drive under different permissions by calling the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation according to the Trusted Computing Organization Protocol Functional Test Request includes: The interface for the session with security identifier permission is called according to the test request for the recovery operation of the management security parameters under the security identifier permission to start a session with security identifier permission. The session with the security identifier permission calls the restore management security parameter interface to perform a restore operation on the management security parameters; Invoke the close session interface to close the session with security identifier permissions; Call the interface of the session with security identifier permission to start the session with security identifier permission; Check whether the opening of the session with security identifier permissions failed. If it did, the first test result of the management security parameter recovery operation test request under the security identifier permissions is determined to be successful. If not, the first test result of the management security parameter recovery operation test request under the security identifier permissions is determined to be unsuccessful.
[0014] As described above, testing under security identifier permissions can verify whether the device correctly performs the recovery operation at a low privilege level, enhancing the comprehensiveness of TCG protocol function testing. By checking whether session opening fails, it can be verified whether the recovery operation successfully resets the device's security state, ensuring that the device can correctly deny low-privilege access after recovery, thereby improving the system's security and reliability.
[0015] Furthermore, the Trusted Computing Organization Protocol Functional Test Request also includes a Locked Security Parameter Recovery Operation Test Request under Security Identifier Permissions; The interface for the operation table includes a query table interface; The recovery operation interface also includes a recovery lock security parameter interface; The specific test of performing recovery operations on the solid-state drive under different permissions by calling the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation according to the Trusted Computing Organization Protocol Functional Test Request includes: The interface of the session with security identifier permission is called according to the lock security parameter recovery operation test request under the security identifier permission to open the session with security identifier permission. The session with the security identifier permission calls the query table interface to obtain the status of the locked security parameters; Check if the status of the locked security parameter is in the factory unactivated state. If not, determine that the second test result of the lock security parameter recovery operation test request under the security identifier permission is a failure. If yes, call the close session interface to close the session with the security identifier permission. Activate the lock security parameters; Check if the locked security parameter is in factory default state. If not, determine that the second test result of the locked security parameter recovery operation test request under security identifier permission is a failure. If yes, call the interface of the session with security identifier permission to open the session with security identifier permission. The session with the security identifier permission calls the restore lock security parameter interface to perform a restore operation on the lock security parameters; Call the query table interface to obtain the status of the lock security parameters; Check if the status of the locked security parameter is in the factory unactivated state. If not, determine that the second test result of the lock security parameter recovery operation test request under the security identifier permission is a failure. If yes, call the close session interface to close the session with the security identifier permission, and determine that the second test result of the lock security parameter recovery operation test request under the security identifier permission is a success.
[0016] As described above, firstly, by checking whether the locked security parameters are in a factory-inactive state, it can be verified whether the device is in the correct initial state before performing the recovery operation. Secondly, by activating the locked security parameters and checking their status again, it can be ensured that the device can correctly transition from the initial state to the activated state. Finally, by performing the recovery operation and verifying whether the locked security parameters can return to the factory-inactive state, it can be ensured that the device's security parameters can be correctly reset when needed. This ensures that the SSD's security parameters can be correctly restored under different states, thereby reliably verifying the effectiveness of the device's TCG protocol function.
[0017] Furthermore, the Trusted Computing Organization Protocol Functional Test Request also includes a Management Security Parameter Recovery Operation Test Request under Level 1 Administrator Privileges; The interface for operating the table includes a table modification interface; The interface for opening sessions with specific permissions also includes an interface for opening sessions with first-level administrator permissions; The specific test of performing recovery operations on the solid-state drive under different permissions by calling the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation according to the Trusted Computing Organization Protocol Functional Test Request includes: The interface for the session with security identifier permission is called according to the management security parameter recovery operation test request under the first-level administrator privileges to open a session with security identifier permission; The session with the security identifier permission calls the modify table interface to set the password for the first-level administrator privileges; Call the interface for opening a session with level 1 administrator privileges to open a session with level 1 administrator privileges; The session with Level 1 administrator privileges invokes the restore management security parameter interface to perform a restore operation on the management security parameters; Call the session close interface to close the session with first-level administrator privileges; Call the interface for opening a session with level 1 administrator privileges to open the session with level 1 administrator privileges; Check whether the opening of the session with first-level administrator privileges failed. If it did, the third test result of the management security parameter recovery operation test request under first-level administrator privileges is determined to be successful. If not, the third test result of the management security parameter recovery operation test request under first-level administrator privileges is determined to be failed.
[0018] As described above, by first enabling a security identifier permission session and setting a level-one administrator password, and then switching to level-one administrator privileges to perform a recovery operation, the process of permission changes and security settings in a real environment can be simulated. After closing the session, try to enable a level-one administrator privilege session again. If it fails, it indicates that the recovery operation has successfully returned the device to a secure state, preventing unauthorized access. If it succeeds, it indicates the existence of a security vulnerability. Such testing helps to confirm that the device's behavior under different permission levels is as expected, enhancing the security and reliability of the system.
[0019] Furthermore, the Trusted Computing Organization Protocol Functional Test Request also includes a lock security parameter recovery operation test request under first-level administrator privileges; The interface for the operation table also includes a query table interface; The recovery operation interface also includes a recovery lock security parameter interface; The specific test of performing recovery operations on the solid-state drive under different permissions by calling the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation according to the Trusted Computing Organization Protocol Functional Test Request includes: The interface for the session with security identifier permission is called according to the lock security parameter recovery operation test request under the first-level administrator privileges to open the session with security identifier permission; The session with the security identifier permission calls the query table interface to obtain the status of the locked security parameters; Check if the status of the locked security parameter is in the factory unactivated state. If not, determine that the fourth test result of the locked security parameter recovery operation test request under the first-level administrator privilege is a failure. If yes, call the modified table interface to set the password of the first-level administrator privilege. Invoke the close session interface to close the session with security identifier permissions; Activate the lock security parameters; Check if the locked security parameter is in factory default state. If not, determine that the fourth test result of the locked security parameter recovery operation test request under the first-level administrator privilege is a failure. If yes, call the interface for opening the session with the first-level administrator privilege to open the session with the first-level administrator privilege. The session with Level 1 administrator privileges invokes the restore lock security parameter interface to perform a restore operation on the lock security parameters; Call the query table interface to obtain the status of the lock security parameters; Check if the status of the locked security parameter is in the factory unactivated state. If not, determine that the fourth test result of the lock security parameter recovery operation test request under the first-level administrator privilege is a failure. If yes, call the close session interface to close the session with the first-level administrator privilege, and determine that the fourth test result of the lock security parameter recovery operation test request under the first-level administrator privilege is a success.
[0020] As described above, by checking and setting the password under the security identifier privileges, the correct escalation of privileges is ensured. By activating the locked security parameters and verifying their status, the device is ensured to correctly transition from the initial state to the activated state. By performing the recovery operation under the first-level administrator privileges and verifying the locked security parameter status again, the device is ensured to be safely reset. This fully verifies the TCG protocol function of the solid-state drive's ability to manage locked security parameters under different privilege levels, ensuring that the device can be correctly reset to the factory safe state after performing the recovery operation.
[0021] Furthermore, before defining the Trusted Computing Organization Test Interface, the following is also included: Use the NVMe command-line tool to encapsulate the interface send command and interface receive command to obtain the encapsulated interface send command and interface receive command.
[0022] As described above, the encapsulated commands conform to the NVMe protocol standard, ensuring command consistency and compatibility, facilitating operation on different NVMe devices, and allowing for convenient testing and verification in a test environment, ensuring the correctness and reliability of the commands, and providing a foundation for subsequent trusted computing organization test interface definitions.
[0023] Furthermore, the definition of the Trusted Computing Organization Test Interface includes: The trusted computing organization test interface is defined based on the command sending and command receiving of the encapsulated interface.
[0024] As can be seen from the above description, the functionality of the TCG protocol can be verified more reliably by defining standardized interfaces for testing.
[0025] Please refer to Figure 2 Another embodiment of the present invention provides a TCG protocol function testing device, comprising: The interface definition module is used to define the test interface of the Trusted Computing Organization. The test interface of the Trusted Computing Organization includes an interface for opening a session with specific permissions, an interface for operating the table, an interface for closing the session, and an interface for restoring the operation. The request receiving module is used to receive Trusted Computing Organization Protocol Functionality Test requests for solid-state drives. The testing module is used to call the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation to perform a special test on the solid-state drive under different permissions according to the Trusted Computing Organization Protocol Functional Test Request.
[0026] Another embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the various steps in the above-described TCG protocol function testing method.
[0027] Please refer to Figure 3 Another embodiment of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements each step of the above-described TCG protocol function testing method.
[0028] The TCG protocol function testing method, apparatus, readable storage medium, and electronic device described above are applicable to the TCG protocol function testing scenario of solid-state drives. The following detailed embodiments illustrate these methods: Please refer to Figure 1 , Figures 4-7 Embodiment 1 of the present invention is as follows: Setting up the test environment: Prepare a test motherboard with NVMe-CLI tools (NVMe command-line tools) installed. The entire test process is carried out in kernel mode.
[0029] A TCG protocol functional testing method includes the following steps: S0. Use the NVMe command-line tool to encapsulate the interface send command and interface receive command to obtain the encapsulated interface send command and interface receive command.
[0030] When sending commands using the opcode sending interface in the NVMe-CLI tool, parameters are required, including the Protocol ID, Command ID, transmission length, and transmission payload. When receiving commands using the opcode sending interface in the NVMe-CLI tool, parameters are required, including the expected status code of the command response, whether to retrieve response data, and whether to check the status code. "Retrieve response data" indicates retrieval (True) or non-retrieval (False). "Check status code" indicates checking (True) or non-checking (False).
[0031] S1. Define a Trusted Computing Organization Test Interface, which includes an interface for opening a session with specific permissions, an interface for manipulating tables, an interface for closing a session, and an interface for resuming operations.
[0032] Specifically, a trusted computing organization test interface is defined based on the command sent by the encapsulated interface and the command received by the encapsulated interface.
[0033] The interfaces for enabling sessions with specific permissions include interfaces for enabling sessions with security identifier permissions and interfaces for enabling sessions with Level 1 administrator (Admin1) permissions. The recovery operation interfaces include interfaces for restoring administrative security parameters (Revert AdminSP) and restoring lockout security parameters (Revert LockingSP). The interfaces for operating tables include interfaces for querying tables and interfaces for modifying tables.
[0034] The interface for enabling a session with security identifier permissions can open an AdminSP session with security identifier permissions. The Revert method can only be called after the session is opened. The input parameters of this interface include the ID requested by the host for the session, the password for opening the session, the session read / write flag, and the permission session specified in the permission table. A session read / write flag of 1 indicates True (opening a write session), and 0 indicates False (opening a read session). When the permission session specified in the permission table is 0, it represents a security identifier; 1 indicates Admin1. To open an AdminSP session with security identifier permissions, simply pass the input parameters to the interface and send the command.
[0035] The interface for enabling a session with Admin1 privileges can open an AdminSP session with Admin1 privileges. The Revert method can only be called after the session is opened. The input parameters for this interface include the ID requested by the host for the session, the password for opening the session, the session read / write flag, and the privileged session specified in the permission table. When calling the interface for enabling a session with Admin1 privileges, the input parameters are passed to the interface, and a command is sent to open an AdminSP session with Admin1 privileges.
[0036] The modified table interface can modify values with write attributes in a table. The input parameters for this interface include a timestamp counter, hardware serial number, caller unique identifier, column number, and the value to be modified. When calling the modified table interface, the input parameters are passed to the interface, and a command is sent to modify the values with write attributes in the table.
[0037] The query table interface can retrieve values with the read attribute from a table. The input parameters for this interface include a timestamp counter, hardware serial number, caller unique identifier, column number, and the value to be queried. When calling the query table interface, the input parameters are passed to the interface, and a command is sent to retrieve values with the read attribute from the table.
[0038] The session close interface can close an already opened session. The input parameters of this interface include a timestamp counter and a hardware serial number.
[0039] The Revert AdminSP interface can perform Revert operations on AdminSP, used to restore table contents, erase passwords, and restore AdminSP to its factory state. The input parameters of this interface include TPerSN and HostSN. TPerSN is assigned by the Trusted Platform Entity (TPer) and is unique, while HostSN is assigned by the host.
[0040] The Revert LockingSP interface can perform Revert operations on LockingSP, used to restore table contents, erase passwords, and restore LockingSP to its factory state. The input parameters for this interface are the same as those for the Revert AdminSP interface.
[0041] S2. Receive the Trusted Computing Organization Protocol Functionality Test Request for the solid-state drive.
[0042] The Trusted Computing Organization Protocol Functional Test Request includes a Management Security Parameter Recovery Operation Test Request under Security Identifier Permission, a Locked Security Parameter Recovery Operation Test Request under Security Identifier Permission, a Management Security Parameter Recovery Operation Test Request under Level 1 Administrator Permission, and a Locked Security Parameter Recovery Operation Test Request under Level 1 Administrator Permission.
[0043] S3. Based on the Trusted Computing Organization Protocol Functional Test Request, call the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation to perform a special test of recovery operation under different permissions on the solid-state drive.
[0044] In one alternative implementation, such as Figure 4 As shown, S3 can include S31-S35: S31. Based on the management security parameter recovery operation test request under the security identifier permission, call the interface of the session with the security identifier permission to start the session with the security identifier permission.
[0045] S32. Based on the session with the security identifier permission, the recovery management security parameter interface is invoked to perform a recovery operation on the management security parameters.
[0046] S33. Call the session close interface to close the session with security identifier permissions.
[0047] S34. Call the interface of the session with security identifier permission to start the session with security identifier permission.
[0048] S35. Check whether the opening of the session with the security identifier permission has failed. If yes, execute S351; otherwise, execute S352.
[0049] S351. Determine that the first test result of the management security parameter recovery operation test request under the security identifier permission is successful.
[0050] S352. Determine that the first test result of the management security parameter recovery operation test request under the security identifier permission is a failure.
[0051] In one alternative implementation, such as Figure 5 As shown, S3 can include S31-S38: S31. Based on the lock security parameter recovery operation test request under the security identifier permission, call the interface of the session with the security identifier permission to open the session with the security identifier permission.
[0052] S32. Based on the session with the security identifier permission, call the query table interface to obtain the status of the locked security parameters.
[0053] S33. Check if the status of the locked security parameter is in the factory unactivated state. If not, execute S331; if yes, execute S332.
[0054] S331. The second test result of the lock security parameter recovery operation test request under the security identifier permission is determined to be a failure.
[0055] S332, Invoke the close session interface to close the session with security identifier permissions.
[0056] S34. Activate the lock security parameters.
[0057] S35. Check if the locked security parameters are in factory default state. If not, execute S351; if yes, execute S352.
[0058] S351. The second test result of the lock security parameter recovery operation test request under the security identifier permission is determined to be a failure.
[0059] S352. Call the interface of the session with security identifier permission to start the session with security identifier permission.
[0060] S36. Based on the session with the security identifier permission, call the restore lock security parameter interface to perform a restore operation on the lock security parameters.
[0061] S37. Call the query table interface to obtain the status of the lock security parameters.
[0062] S38. Check if the status of the locked security parameter is in the factory unactivated state. If not, execute S381; if yes, execute S382.
[0063] S381. The second test result of the lock security parameter recovery operation test request under the security identifier permission is determined to be a failure.
[0064] S382. Call the session close interface to close the session with security identifier permissions, and determine that the second test result of the lock security parameter recovery operation test request under the security identifier permissions is successful.
[0065] In one alternative implementation, such as Figure 6 As shown, S3 may include S31-S37: S31. Based on the management security parameter recovery operation test request under the first-level administrator privileges, call the interface of the session with security identifier permission to start the session with security identifier permission.
[0066] S32. Based on the session with the security identifier permission, call the modify table interface to set the password for the first-level administrator privileges.
[0067] S33. Call the interface for opening a session with first-level administrator privileges to open a session with first-level administrator privileges.
[0068] S34. Based on the session with first-level administrator privileges, the recovery management security parameter interface is invoked to perform a recovery operation on the management security parameters.
[0069] S35. Call the session close interface to close the session with first-level administrator privileges.
[0070] S36. Call the interface for opening a session with first-level administrator privileges to open the session with first-level administrator privileges.
[0071] S37. Check whether the opening of the session with first-level administrator privileges failed. If yes, execute S371; otherwise, execute S372.
[0072] S371. Determine that the third test result of the management security parameter recovery operation test request under the first-level administrator privileges is successful.
[0073] S372. The third test result of the management security parameter recovery operation test request under the first-level administrator privilege is determined to be a failure.
[0074] In one alternative implementation, such as Figure 7 As shown, S3 can include S31-S39: S31. Based on the lock security parameter recovery operation test request under the first-level administrator privileges, call the interface of the session with the security identifier permission to open the session with the security identifier permission.
[0075] S32. Based on the session with the security identifier permission, call the query table interface to obtain the status of the locked security parameters.
[0076] S33. Check if the status of the locked security parameter is in the factory unactivated state. If not, execute S331; if yes, execute S332.
[0077] S331. The fourth test result of the lock security parameter recovery operation test request under the first-level administrator privilege is determined to be a failure.
[0078] S332. Call the modified table interface to set the password for the first-level administrator privileges.
[0079] S34. Call the close session interface to close the session with security identifier permissions.
[0080] S35. Activate the lock security parameters.
[0081] S36. Check if the locked security parameters are in factory default state. If not, execute S361; if yes, execute S362.
[0082] S361. The fourth test result of the lock security parameter recovery operation test request under the first-level administrator privilege is determined to be a failure.
[0083] S362. Call the interface for opening a session with first-level administrator privileges to open the session with first-level administrator privileges.
[0084] S37. Based on the session with first-level administrator privileges, the recovery lock security parameter interface is called to perform a recovery operation on the lock security parameters.
[0085] S38. Call the query table interface to obtain the status of the lock security parameters.
[0086] S39. Check if the status of the locked security parameter is in the factory unactivated state. If not, execute S391; if yes, execute S392.
[0087] S391. The fourth test result of the lock security parameter recovery operation test request under the first-level administrator privilege is determined to be a failure.
[0088] S392. Call the session close interface to close the session with first-level administrator privileges, and determine that the fourth test result of the lock security parameter recovery operation test request under first-level administrator privileges is successful.
[0089] By combining the aforementioned automated testing interfaces, specific tests for Revert under different TCG permissions can be completed.
[0090] Please refer to Figure 2 Embodiment two of the present invention is as follows: A TCG protocol function testing device, comprising: The interface definition module is used to define the test interface of the Trusted Computing Organization. The test interface of the Trusted Computing Organization includes an interface for opening a session with specific permissions, an interface for operating the table, an interface for closing the session, and an interface for restoring the operation. The request receiving module is used to receive Trusted Computing Organization Protocol Functionality Test requests for solid-state drives. The testing module is used to call the interface for opening a session with specific permissions, the interface for the operation table, the interface for closing the session, and the interface for the recovery operation to perform a special test on the solid-state drive under different permissions according to the Trusted Computing Organization Protocol Functional Test Request.
[0091] Embodiment 3 of the present invention is as follows: A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the various steps of the TCG protocol function testing method in Embodiment 1.
[0092] Embodiment four of the present invention is as follows: Please refer to Figure 3 An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the various steps of the TCG protocol function testing method in Embodiment 1.
[0093] In summary, this invention provides a TCG protocol functional testing method, apparatus, readable storage medium, and electronic device. It defines a Trusted Computing Organization (TCO) test interface, which includes interfaces for opening sessions with specific permissions, operation tables, closing sessions, and recovery operations. Based on a received TCO protocol functional test request, the interface for opening sessions with specific permissions, the operation table interface, the session closing interface, and the recovery operation interface are invoked to perform specific recovery operation tests on the solid-state drive (SSD) under different permission levels. This eliminates the need for third-party paid tools. Utilizing the defined multiple test interfaces, automated testing of TCG protocol functional recovery operations (Revert) under different permissions can be achieved, providing a more comprehensive and detailed solution, thus realizing low-cost and reliable TCG protocol functional testing. Furthermore, the NVMe command-line tool is used to encapsulate the interface sending and receiving commands. The encapsulated commands conform to the NVMe protocol standard, ensuring command consistency and compatibility, facilitating operation on different NVMe devices, and allowing for convenient testing and verification in a test environment, ensuring command correctness and reliability. This provides a foundation for subsequent TCO test interface definitions.
[0094] In the embodiments provided in this application, it should be understood that the disclosed methods, apparatuses, computer-readable storage media, and electronic devices can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple components or modules may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices, components, or modules may be electrical, mechanical, or other forms.
[0095] The components described as separate parts may or may not be physically separate. The components shown as components may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the components can be selected to achieve the purpose of this embodiment according to actual needs.
[0096] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each component can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0097] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0098] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0099] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0100] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method of testing TCG protocol functionality, the method comprising: The method comprises the steps of: defining a trusted computing organization test interface, the trusted computing organization test interface comprising an interface for opening a session with specific permissions, an interface for operating a table, an interface for closing a session, and an interface for resuming operation; receiving a trusted computing organization protocol function test request for a solid state disk; performing a special test for a recovery operation under different permissions on the solid state disk according to the trusted computing organization protocol function test request by calling the interface for opening a session with specific permissions, the interface for operating a table, the interface for closing a session, and the interface for resuming operation.
2. The method of claim 1, wherein, The trusted computing organization protocol function test request comprises a management security parameter recovery operation test request under a security identifier permission; The interface for opening a session with specific permissions comprises an interface for opening a session with a security identifier permission; The interface for resuming operation comprises a management security parameter recovery interface; The special test for a recovery operation under different permissions on the solid state disk according to the trusted computing organization protocol function test request by calling the interface for opening a session with specific permissions, the interface for operating a table, the interface for closing a session, and the interface for resuming operation comprises: opening a session with a security identifier permission according to the management security parameter recovery operation test request under a security identifier permission by calling the interface for opening a session with a security identifier permission; performing a recovery operation on a management security parameter based on the session with a security identifier permission by calling the management security parameter recovery interface; closing the session with a security identifier permission by calling the interface for closing a session; opening the session with a security identifier permission by calling the interface for opening a session with a security identifier permission; checking whether the opening of the session with a security identifier permission fails, and if so, determining that a first test result of the management security parameter recovery operation test request under a security identifier permission is success, and if not, determining that the first test result of the management security parameter recovery operation test request under a security identifier permission is failure.
3. The method of claim 2, wherein the TCG protocol function test method is characterized by, The trusted computing organization protocol function test request further comprises a locking security parameter recovery operation test request under a security identifier permission; The interface for operating a table comprises a table query interface; The interface for resuming operation further comprises a locking security parameter recovery interface; The special test for a recovery operation under different permissions on the solid state disk according to the trusted computing organization protocol function test request by calling the interface for opening a session with specific permissions, the interface for operating a table, the interface for closing a session, and the interface for resuming operation comprises: opening a session with a security identifier permission according to the locking security parameter recovery operation test request under a security identifier permission by calling the interface for opening a session with a security identifier permission; obtaining a state of a locking security parameter based on the session with a security identifier permission by calling the table query interface; checking whether the state of the lock security parameter is a factory non-activated state, if not, determining that a second test result of the lock security parameter recovery operation test request under the security identifier permission is failure, if yes, calling the close session interface to close the session with the security identifier permission; activating the lock security parameter; checking whether the lock security parameter is a factory state, if not, determining that a second test result of the lock security parameter recovery operation test request under the security identifier permission is failure, if yes, calling the interface of opening the session with the security identifier permission to open the session with the security identifier permission; calling the recovery lock security parameter interface to perform a recovery operation on the lock security parameter based on the session with the security identifier permission; calling the query table interface to obtain the state of the lock security parameter; checking whether the state of the lock security parameter is a factory non-activated state, if not, determining that a second test result of the lock security parameter recovery operation test request under the security identifier permission is failure, if yes, calling the close session interface to close the session with the security identifier permission, and determining that a second test result of the lock security parameter recovery operation test request under the security identifier permission is success.
4. The method of claim 2, wherein, the trusted computing group protocol function test request further comprises a management security parameter recovery operation test request under a first administrator permission; the interface of the operation table comprises a modification table interface; the interface of opening the session with the specific permission further comprises an interface of opening the session with the first administrator permission; the recovery operation special test of the solid state disk under different permissions according to the trusted computing group protocol function test request calling the interface of opening the session with the specific permission, the interface of the operation table, the close session interface and the recovery operation interface comprises: calling the interface of opening the session with the security identifier permission to open the session with the security identifier permission according to the management security parameter recovery operation test request under the first administrator permission; calling the modification table interface to set the password of the first administrator permission based on the session with the security identifier permission; calling the interface of opening the session with the first administrator permission to open the session with the first administrator permission; calling the recovery management security parameter interface to perform a recovery operation on the management security parameter based on the session with the first administrator permission; calling the close session interface to close the session with the first administrator permission; calling the interface of opening the session with the first administrator permission to open the session with the first administrator permission; checking whether the opening of the session with the first administrator permission fails, if yes, determining that a third test result of the management security parameter recovery operation test request under the first administrator permission is success, if not, determining that a third test result of the management security parameter recovery operation test request under the first administrator permission is failure.
5. The method of claim 4, wherein, The trusted computing group protocol function test request further comprises a lock security parameter recovery operation test request under a first administrator permission; The interface of the operation table further comprises a query table interface; The recovery operation interface further comprises a lock security parameter recovery interface; The recovery operation special test of the solid state disk under different permissions by the interface of starting the session with specific permissions, the interface of the operation table, the interface of closing the session, and the recovery operation interface according to the trusted computing group protocol function test request comprises: The interface of starting the session with the security identifier permission is called to start the session with the security identifier permission according to the lock security parameter recovery operation test request under the first administrator permission; The query table interface is called to obtain the state of the lock security parameter based on the session with the security identifier permission; It is checked whether the state of the lock security parameter is a factory state or not, if not, it is determined that the fourth test result of the lock security parameter recovery operation test request under the first administrator permission is failure, if yes, the modification table interface is called to set the password of the first administrator permission; The interface of closing the session is called to close the session with the security identifier permission; The lock security parameter is activated; It is checked whether the lock security parameter is a factory state or not, if not, it is determined that the fourth test result of the lock security parameter recovery operation test request under the first administrator permission is failure, if yes, the interface of starting the session with the first administrator permission is called to start the session with the first administrator permission; The recovery operation of the lock security parameter is performed based on the session with the first administrator permission by calling the lock security parameter recovery interface; The query table interface is called to obtain the state of the lock security parameter; It is checked whether the state of the lock security parameter is a factory state or not, if not, it is determined that the fourth test result of the lock security parameter recovery operation test request under the first administrator permission is failure, if yes, the interface of closing the session is called to close the session with the first administrator permission, and it is determined that the fourth test result of the lock security parameter recovery operation test request under the first administrator permission is success.
6. The method of claim 1, wherein, Before the definition of the trusted computing group test interface, the method further comprises: The NVMe command line tool encapsulation interface is used to send and receive commands, and encapsulated interface sending commands and encapsulated interface receiving commands are obtained.
7. The method of claim 6, wherein the TCG protocol function test method is characterized by, The definition of the trusted computing group test interface comprises: The trusted computing group test interface is defined based on the encapsulated interface sending commands and the encapsulated interface receiving commands.
8. A TCG protocol function testing apparatus, characterized by, It comprises: An interface definition module is configured to define a trusted computing group test interface, wherein the trusted computing group test interface comprises an interface of starting a session with specific permissions, an interface of an operation table, an interface of closing a session, and a recovery operation interface; A request receiving module is configured to receive a trusted computing group protocol function test request of a solid state disk; A request receiving module is configured to receive a trusted computing group protocol function test request of a solid state disk; The test module is configured to call interfaces of the session with the specific permission, the operation table, the session closing interface and the recovery operation interface to perform a recovery operation special test on the solid state disk under different permissions according to the TCG protocol function test request.
9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by a processor, implements each step of the TCG protocol function test method according to any one of claims 1 to 7.
10. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor, when executing the computer program, implements each step of the TCG protocol function test method according to any one of claims 1 to 7.