Password usability evaluation method, device, equipment, storage medium and product
By comprehensively evaluating the independence of the password, the ease of operation during the auxiliary use phase, and the performance compliance during the formal use phase, this technology solves the problem of the inability to quantify the usability of passwords in existing technologies. It enables a comprehensive and objective evaluation of password products in actual use, thereby improving user experience and application efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HAOFU CIPHER DETECTION TECH (CHENGDU) CO LTD
- Filing Date
- 2025-12-18
- Publication Date
- 2026-08-04
AI Technical Summary
Existing technologies lack a systematic focus on the ease of use of cryptography, making it impossible to achieve a quantitative assessment of cryptographic usability.
This paper proposes a method for evaluating the usability of cryptography. It evaluates the independence of cryptography by determining whether it meets the usage requirements of the application scenario, and comprehensively assesses the usability of cryptography by combining the ease of operation for participants in the auxiliary stage and the performance compliance in the formal use stage.
A comprehensive, objective, and quantifiable cryptographic usability evaluation system has been constructed, which can reflect the convenience and operational burden of cryptography in actual use, and improve the user experience and industrial application of cryptographic products.
Smart Images

Figure CN121682813B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a method, apparatus, device, storage medium and product for evaluating cryptographic usability. Background Technology
[0002] With the implementation of the Cryptography Law and the comprehensive advancement of digitalization across all industries, the application scope of cryptographic technology has gradually expanded from traditional important information systems to a wider range of fields such as finance, industrial internet, government services, and public services.
[0003] Cryptography not only manifests in various product forms such as software, chips, modules, boards, complete machines, and systems, but also covers multiple functional categories including cryptographic algorithms, data encryption and decryption, authentication and verification, certificate management, key management, cryptographic anti-counterfeiting, and comprehensive applications. Against this backdrop of ever-expanding application scale, the ease of use, operability, and overall user experience of cryptography are increasingly becoming key factors influencing the promotion and industrialization of cryptographic products. However, existing research and evaluation systems primarily focus on traditional indicators such as security, performance, reliability, and environmental adaptability, lacking a systematic focus on the usability of cryptographic processes. Therefore, a comprehensive usability evaluation technology is needed that can quantitatively assess cryptographic independence, the complexity of auxiliary processes, and performance in actual use, to compensate for the shortcomings of existing technologies in terms of cryptographic usability. Summary of the Invention
[0004] The main objective of this application is to provide a method, apparatus, device, and storage medium for evaluating cryptographic usability, aiming to solve the technical problem that related technologies cannot evaluate cryptographic usability.
[0005] To achieve the above objectives, this application proposes a method for evaluating cryptographic usability, the method comprising: Determine whether the password to be tested meets the usage requirements of the current usage scenario. For the passwords to be tested that meet the usage requirements, conduct an independence evaluation to obtain the independence evaluation results. The independence evaluation results are negatively correlated with the number of passwords to be tested. Based on the ease of operation for the participants involved in the auxiliary use phase of the cipher under test and the performance compliance of the cipher under test in the formal use phase, the usability evaluation results of the cipher under test are determined. Based on the combined results of the independence assessment and the ease of use assessment, the password ease of use assessment result of the password to be tested is determined.
[0006] In one embodiment, the steps of determining whether the password to be tested meets the usage requirements of the current usage scenario, and performing an independence evaluation on the passwords to be tested that meet the usage requirements to obtain the independence evaluation results include: If the password to be tested meets the usage requirements of the current usage scenario, then determine the password type and number of passwords to be tested; The independence evaluation results of the cipher under test are determined based on the types and number of ciphers; the independence evaluation results of the cipher under test are negatively correlated with the sum of the types and number of ciphers.
[0007] In one embodiment, the steps for determining the usability evaluation result of the cipher under test based on the ease of operation for participating parties during the auxiliary use phase and the performance compliance of the cipher under test during the formal use phase include: The usage phases of the password to be tested are divided into the auxiliary usage phase and the formal usage phase. For the auxiliary stage of using the password under test, the ease of operation for the participants is determined based on the number of participants, the total number of operation steps for the participants, and the total number of operation steps that need to be crossed.
[0008] In one embodiment, the step of determining the ease of operation for each participant based on the number of participants in the password to be tested, the total number of operation steps for each participant, and the total number of operation steps that need to be overlapped includes: Set the weights for the number of participants, the total number of operation steps of the participants, and the total number of operation steps that need to be crossed; wherein, the weight of the total number of operation steps that need to be crossed is not less than the weight of the total number of operation steps of the participants, and the weight of the total number of operation steps of the participants is not less than the weight of the number of participants. Based on the weight of the number of participants, the weight of the total number of operation steps of the participants, and the weight of the total number of operation steps that need to be crossed, determine the weighted item of the number of participants, the weighted item of the total number of operation steps of the participants, and the weighted item of the total number of operation steps that need to be crossed. The ease of operation for each participant is determined by the sum of the weighted terms for the number of participants, the weighted terms for the total number of operation steps for each participant, and the weighted terms for the total number of operation steps that need to be crossed. The ease of operation for each participant is negatively correlated with the sum of the weighted terms for the number of participants, the weighted terms for the total number of operation steps for each participant, and the weighted terms for the total number of operation steps that need to be crossed.
[0009] In one embodiment, the steps for determining the usability evaluation result of the cipher under test based on the ease of operation for participating parties during the auxiliary use phase and the performance compliance of the cipher under test during the formal use phase include: The performance of the password under test is tested, and the performance test results are obtained; The performance compliance rate is determined based on the ratio of the performance test results to the performance requirement values. Based on performance compliance and ease of operation for participants, the usability evaluation results of the password under test are determined.
[0010] In one embodiment, the auxiliary phase includes password installation, password login, password configuration, password debugging, password update, password backup and recovery, password repair, password replacement, and password destruction.
[0011] Secondly, to achieve the above objectives, this application further provides a cryptographic usability evaluation device, the device comprising: The independence evaluation module is used to determine whether the password under test meets the usage requirements of the current usage scenario. For passwords under test that meet the usage requirements, the independence evaluation is performed to obtain the independence evaluation result. The independence evaluation result is negatively correlated with the number of passwords under test. The usability evaluation module is used to determine the usability evaluation results of the password under test based on the ease of operation for the participants involved in the auxiliary use phase and the performance compliance of the password under test in the formal use phase. The comprehensive evaluation module is used to combine the independence evaluation results and the usability evaluation results to determine the password usability evaluation result of the password under test.
[0012] Thirdly, to achieve the above objectives, this application further provides a cryptographic usability evaluation device, the device comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the cryptographic usability evaluation method as described above.
[0013] Fourthly, to achieve the above objectives, this application further provides a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the cryptographic usability evaluation method as described above.
[0014] Fifthly, to achieve the above objectives, this application further provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the above-described cryptographic usability evaluation method.
[0015] One or more technical solutions proposed in this application have at least the following technical effects: This application constructs a comprehensive, objective, and quantifiable cryptographic usability evaluation system by uniformly quantifying cryptographic independence, ease of operation for participants in the auxiliary use phase, and performance compliance in the formal use phase. Through weighted modeling, it effectively characterizes the contribution of different operational stages to overall usability, achieving a comprehensive evaluation of the convenience, operational burden, and performance of cryptographic products throughout the entire actual use process. This provides a scientific basis for cryptographic product selection, optimized design, and application promotion, improving the efficiency of cryptographic technology implementation and user experience in a wider range of fields. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without creative effort.
[0018] Figure 1 This is a flowchart illustrating an embodiment of the cryptographic usability evaluation method of this application.
[0019] Figure 2 This is a schematic diagram of the cryptographic usability evaluation device of this application.
[0020] Figure 3 This is a schematic diagram of the cryptographic usability evaluation device of this application.
[0021] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0022] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0023] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0024] The main solution of this application embodiment is: to determine whether the password to be tested meets the usage requirements of the current usage scenario, to conduct an independence evaluation on the password to be tested that meets the usage requirements, and to obtain the independence evaluation result; wherein, the independence evaluation result is negatively correlated with the number of passwords to be tested, and based on the ease of operation of the participants involved in the use assistance stage of the password to be tested and the performance compliance of the password to be tested in the formal use stage, the usability evaluation result of the password to be tested is determined, and the password usability evaluation result of the password to be tested is determined by combining the independence evaluation result and the usability evaluation result.
[0025] Based on this, embodiments of this application provide a method for evaluating cryptographic usability, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the cryptographic usability evaluation method of this application.
[0026] In this embodiment, the cryptographic usability evaluation method includes steps S10 to S30: Step S10: Determine whether the password to be tested meets the usage requirements of the current usage scenario. Perform an independence evaluation on the passwords to be tested that meet the usage requirements and obtain the independence evaluation results. The independence evaluation results are negatively correlated with the number of passwords to be tested.
[0027] Step S20: Based on the ease of operation of the participants involved in the auxiliary use phase of the password under test and the performance compliance of the password under test in the formal use phase, determine the usability evaluation result of the password under test.
[0028] Step S30: Combine the independence evaluation results and the usability evaluation results to determine the password usability evaluation result of the password to be tested.
[0029] It should be noted that the password under test refers to all password products used in a specific scenario. In this embodiment, the usage phase of the password under test is divided into a support phase and a formal usage phase. The support phase refers to the necessary operations required for password use, including password installation, password login, password configuration, password debugging, password update, password backup and recovery, password maintenance, password replacement, and password destruction. Formal usage refers to the phase of normal password use.
[0030] Specifically, this embodiment first determines whether the password under test meets the requirements of the current use scenario, and evaluates the independence of passwords that meet the requirements based on the number of passwords; the more passwords there are, the lower the independence evaluation result. Then, by analyzing the ease of operation for participants in the auxiliary use phase and the performance compliance in the formal use phase, the usability evaluation result of the password is obtained. Finally, the independence evaluation result and the usability evaluation result are combined to obtain the final evaluation result that can comprehensively reflect the usability level of the password in actual application.
[0031] In one feasible implementation, step S10 includes steps A10 to A20: Step A10: If the password to be tested meets the usage requirements of the current usage scenario, then determine the password type and number of passwords to be tested. Step A20: Determine the independence evaluation result of the password to be tested based on the password type and number of passwords.
[0032] Among them, the independence evaluation results of the passwords under test are negatively correlated with the sum of the password types and the number of passwords.
[0033] For example, first, the use case is determined, the security requirements of the scenario are analyzed, and the functionality, performance, and security of the password under test are tested to see if they meet the requirements. If the requirements are met, the independence of the password is evaluated.
[0034] The way to evaluate independence is as follows: the fewer the types and quantities of passwords used, the higher the independence. When there is only one type of password and only one password in this type, the independence is the highest.
[0035] Establish a password independence detection model and calculate the password independence evaluation result: Among them, y 1 is the password independence evaluation result. x 1 is the number of types of passwords to be tested, x 2 is the number of passwords to be tested. a and b are weight coefficients, a + b = 1, 0 < a < b Take values according to the actual situation.
[0036] It can be understood that the coefficient b for the number of passwords is set to be greater than the coefficient a for the number of password types because increasing the total number of passwords will directly increase the management burden, memory difficulty, and potential vulnerability risk of the system. Even if all passwords belong to the same type, this makes its negative impact on independence more significant. While increasing the number of password types mainly increases complexity by needing to adapt to different mechanisms, but if the principles between types are similar, its impact is relatively small; therefore, the setting of 0 < a < b and a + b = 1 is adopted, emphasizing the priority of minimizing the total number of passwords to achieve the highest independence, while allowing adjustment of the coefficients according to specific scenarios.
[0037] In this embodiment, step S20 includes steps B10 to step B50: Step B10, divide the usage stage of the password to be tested into an auxiliary usage stage and a formal usage stage.
[0038] Step B20, for the auxiliary usage stage of the password to be tested, determine the simplicity of the operation of the participating parties based on the number of participating parties, the total number of operation steps of the participating parties, and the total number of operation steps that need to be crossed.
[0039] Among them, step B20 includes steps B21 to step B23: Step B21, set the weight of the number of participating parties, the weight of the total number of operation steps of the participating parties, and the weight of the total number of operation steps that need to be crossed; among them, the weight of the total number of operation steps that need to be crossed is not less than the weight of the total number of operation steps of the participating parties and the weight of the total number of operation steps of the participating parties is not less than the weight of the number of participating parties.
[0040] Step B22: Based on the weight of the number of participants, the weight of the total number of operation steps of the participants, and the weight of the total number of operation steps that need to be crossed, determine the weighted item of the number of participants, the weighted item of the total number of operation steps of the participants, and the weighted item of the total number of operation steps that need to be crossed.
[0041] Step B23: Determine the ease of operation for each participant based on the sum of the weighted terms for the number of participants, the weighted terms for the total number of operation steps for each participant, and the weighted terms for the total number of operation steps that need to be crossed. The ease of operation for each participant is negatively correlated with the sum of the weighted terms for the number of participants, the weighted terms for the total number of operation steps for each participant, and the weighted terms for the total number of operation steps that need to be crossed.
[0042] Step B30: Perform a performance test on the password to be tested and obtain the performance test results.
[0043] Step B40: Determine the performance compliance rate based on the ratio of the performance test results to the performance requirement values.
[0044] Step B50: Based on performance compliance and ease of operation for participants, determine the usability evaluation results of the password under test.
[0045] For example, the usage phase of the password to be tested can be divided into a support phase and a formal usage phase.
[0046] The auxiliary usage phase refers to the necessary operations required for password use, such as password installation, login, configuration, debugging, updating, backup and recovery, repair, replacement, and destruction. Formal use refers to the password being usable normally.
[0047] For the auxiliary phase, a list is created based on the auxiliary items available to the password being tested during this phase. The number of participants, the total number of operational steps for each participant, and the total number of overlapping operational steps are then identified for each auxiliary item. A participant refers to the entity that performs the corresponding auxiliary operation to enable the password to function normally; the participants in this auxiliary item can be individuals, programs, or other entities.
[0048] It's understandable that fewer participants result in higher usability. Fewer operational steps for each participant also lead to higher usability. Fewer overlapping operational steps further enhance usability. These judgments can be quantified: in, y 2 represents the ease of use value. c Weighted by the number of participants. d The weight of the total number of operation steps of the participants. e The weight is the total number of operation steps that need to be crossed. c+d+e =1, e ≥d ≥ c > 0 , c , d , e The value should be determined based on the actual situation. x 1 represents the number of participants. x 2 represents the total number of operation steps performed by the participating parties. x 3 represents the total number of operation steps that need to be crossed.
[0049] It is understandable that crossover operations ( x 3) This typically involves coordination and interaction among multiple stakeholders, which is often the most complex aspect of usability and can lead to higher error risks, time consumption, and user frustration. Therefore, its weight e is set to the maximum to emphasize its strongest negative impact on overall usability. In contrast, the total number of steps per stakeholder ( x 2) Primarily affects the operational burden of a single entity, with importance secondary, hence d falls in the middle; number of participants ( x 1) Although it will increase the overall complexity, if the steps are simple and there is no overlap, its impact is relatively small, so c is set to the minimum.
[0050] During the formal use phase, the usability of a password is reflected in its performance. Password performance is tested, and performance test results are obtained: Among them, the performance requirement value can be the technical standard value, the requirement value of the prepared plan, etc. y 3 represents performance compliance. If the ratio of test result data to performance requirement value is ≥1, f(test result data / performance requirement value) is 1; otherwise, f(test result data / performance requirement value) is less than 1.
[0051] Furthermore, by combining the results of the independence assessment and the usability assessment, the usability assessment result of the cipher to be tested is determined. Specifically, a system is established... y 1. y 2. y The association of 3 quantifies the ease of cryptography. For example, establishing Y= y 1× y 2× y 3, or Y= y 1+ y 2+ y 3. Y is the overall usability value of the password. y 1. y 2. y Both are dimensionless, allowing for various calculations such as multiplication and addition to establish relationships. A usability pass threshold is set. The Y value is compared with the threshold; if the threshold is met, the usability pass threshold and a usability value are output.
[0052] Table 1: Examples of Smart Password Key Usability Evaluation To more clearly illustrate this embodiment, in a specific example, referring to Table 1, "Examples of Smart Password Key Usability Evaluation," a smart password key is a cryptographic product, a terminal cryptographic device that implements cryptographic operations and key management functions, generally using a USB interface. Generally, a smart password key can independently perform its cryptographic functions. An evaluation was conducted using a smart password key with a built-in one-click driver installation. The independence, ease of use, and comprehensive evaluation information and values are shown in the table below. The comprehensive evaluation method uses Y=y1×y2×y3, calculating an ease of use value of 1. This value indicates that the cryptographic product can independently perform its functions, the operation can be completed in one step, and the performance meets the requirements.
[0053] Table 2 Examples of Security Authentication Gateway Usability Evaluation Table 3. Security Authentication Gateway Usage Support Table In another specific example, referring to Table 2 (Examples of Security Authentication Gateway Usability Evaluation) and Table 3 (Assistance Table for Security Authentication Gateway Usage), a security authentication gateway is a device that uses digital certificates to provide user management, identity authentication, single sign-on, transmission encryption, access control, and security auditing services to application systems. Generally, a security authentication gateway consists of various cryptographic product components. The evaluation of a conventional security authentication gateway, including its independence, ease of use, and comprehensive evaluation information and values, is shown in the table below. The comprehensive evaluation method uses Y=y1×y2×y3, resulting in a usability value of 0.017777778, rounded to three decimal places (0.018). Compared to smart keys, the usability is significantly reduced, consistent with the actual user experience of both types of cryptographic products.
[0054] Understandably, this embodiment constructs a comprehensive usability evaluation system covering the entire cryptographic lifecycle by uniformly and quantitatively evaluating cryptographic independence, ease of operation during the auxiliary use phase, and performance compliance during the formal use phase. This system objectively reflects the convenience and operational burden of cryptography in actual use. Compared to traditional evaluation methods that only focus on security and performance, this approach more comprehensively reveals the user experience of cryptography in real-world scenarios, providing a scientific basis for cryptographic product selection, optimization design, and promotion, thereby effectively improving the usability and industrial application level of cryptographic technology.
[0055] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the cryptographic usability evaluation method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0056] This application also provides a cryptographic usability evaluation device; please refer to [reference needed]. Figure 2 The password usability assessment device includes: The independence evaluation module 10 is used to determine whether the password to be tested meets the usage requirements of the current usage scenario, and to evaluate the independence of the password to be tested that meets the usage requirements, thereby obtaining the independence evaluation result; wherein, the independence evaluation result is negatively correlated with the number of passwords in the password to be tested.
[0057] The usability evaluation module 20 is used to determine the usability evaluation result of the password under test based on the ease of operation of the participants involved in the auxiliary use phase and the performance compliance of the password under test in the formal use phase.
[0058] The comprehensive evaluation module 30 is used to combine the independence evaluation results and the usability evaluation results to determine the password usability evaluation result of the password to be tested.
[0059] The cryptographic usability evaluation device provided in this application, employing the cryptographic usability evaluation method in the above embodiments, can solve the technical problem that related technologies cannot evaluate cryptographic usability. Compared with related technologies, the beneficial effects of the cryptographic usability evaluation device provided in this application are the same as those of the cryptographic usability evaluation method provided in the above embodiments, and other technical features in the cryptographic usability evaluation device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0060] This application provides a cryptographic usability evaluation device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the cryptographic usability evaluation method in the above embodiments.
[0061] The following is for reference. Figure 3This document illustrates a structural schematic diagram of a cryptographic usability evaluation device suitable for implementing embodiments of this application. The cryptographic usability evaluation device in this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 3 The cryptographic usability evaluation device shown is merely an example and should not impose any limitations on the functionality and scope of the embodiments of this application.
[0062] like Figure 3 As shown, the cryptographic usability evaluation device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in the read-only memory 1002 (ROM) or a program loaded from the storage device 1003 into the random access memory 1004 (RAM). The random access memory 1004 also stores various programs and data required for the operation of the instructional video generation device. The processing unit 1001, the read-only memory 1002, and the random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 (I / O interface) is also connected to the bus 1005. Typically, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the instructional video generation device to communicate wirelessly or wiredly with other devices to exchange data. Although instructional video generation devices with various systems are shown in the figure, it should be understood that it is not required to implement or possess all the systems shown. More or fewer systems can be implemented alternatively.
[0063] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0064] The cryptographic usability evaluation device provided in this application, employing the cryptographic usability evaluation method in the above embodiments, can solve the technical problem that related technologies cannot evaluate cryptographic usability. Compared with related technologies, the beneficial effects of the cryptographic usability evaluation device provided in this application are the same as those of the cryptographic usability evaluation method provided in the above embodiments, and other technical features in this cryptographic usability evaluation device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0065] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0066] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0067] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the cryptographic usability evaluation method in the above embodiments.
[0068] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0069] The aforementioned computer-readable storage medium may be included in the cryptographic usability evaluation device; or it may exist independently and not assembled into the cryptographic usability evaluation device.
[0070] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the cryptographic usability evaluation device, the cryptographic usability evaluation device: determines the security evaluation items of the cryptographic product under test; establishes a security measurement model; the output value of the security measurement model is a security quantification value, which is determined based on the sum of the input parameters of the security measurement model; determines the input parameters based on the measurement uncertainty of the cryptographic operation component of the cryptographic product under test under each security evaluation item; determines the weight of each input parameter of the security measurement model; fills the input parameters into the security measurement model; and obtains the security quantification value of the cryptographic product under test as the cryptographic usability evaluation result of the cryptographic product under test. Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0071] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0072] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0073] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described cryptographic usability evaluation method, thereby solving the technical problem that related technologies cannot evaluate cryptographic usability. Compared with related technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the cryptographic usability evaluation method provided in the above embodiments, and will not be repeated here.
[0074] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the cryptographic usability evaluation method described above.
[0075] The computer program product provided in this application can solve the technical problem that related technologies cannot evaluate the usability of cryptography. Compared with related technologies, the beneficial effects of the computer program product provided in this application are the same as those of the cryptography usability evaluation method provided in the above embodiments, and will not be repeated here.
[0076] The above are only some embodiments of this application and do not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A method for evaluating the usability of cryptography, characterized in that, The method includes: Determine whether the password to be tested meets the usage requirements of the current usage scenario, and conduct an independence evaluation on the passwords to be tested that meet the usage requirements to obtain the independence evaluation results; wherein, the independence evaluation results are negatively correlated with the number of passwords to be tested; the passwords to be tested are all password products used in a certain scenario; Based on the ease of operation for the participants involved in the auxiliary use phase of the password under test and the performance compliance of the password under test in the formal use phase, the usability evaluation result of the password under test is determined. Based on the independence evaluation results and the usability evaluation results, the password usability evaluation result of the password to be tested is determined; The steps of determining whether the password to be tested meets the usage requirements of the current usage scenario, and conducting an independence evaluation on the passwords to be tested that meet the usage requirements to obtain the independence evaluation results include: If the password to be tested meets the usage requirements of the current usage scenario, then the password type and number of passwords to be tested are determined. Based on the types and number of passwords, the independence evaluation result of the password under test is determined; wherein the independence evaluation result of the password under test is negatively correlated with the sum of the types and number of passwords. The step of determining the usability evaluation result of the password under test based on the ease of operation for participating parties during the auxiliary use phase and the performance compliance of the password under test during the formal use phase includes: The usage phases of the password under test are divided into an auxiliary usage phase and a formal usage phase. For the auxiliary stage of using the password under test, the ease of operation for the participants is determined based on the number of participants, the total number of operation steps of the participants, and the total number of operation steps that need to be crossed. The step of determining the usability evaluation result of the password under test based on the ease of operation for participating parties during the auxiliary use phase and the performance compliance of the password under test during the formal use phase includes: The performance of the password to be tested is evaluated, and the performance evaluation results are obtained. The performance compliance rate is determined based on the ratio of the performance test results to the performance requirement values. Based on the performance compliance and the ease of operation for the participants, the usability evaluation result of the password under test is determined.
2. The cryptographic usability evaluation method as described in claim 1, characterized in that, The step of determining the ease of operation for each participant based on the number of participants, the total number of operation steps for each participant, and the total number of operation steps that need to be crossed includes: Set the weights for the number of participants, the total number of operation steps of the participants, and the total number of operation steps that need to be crossed; wherein, the weight of the total number of operation steps that need to be crossed is not less than the weight of the total number of operation steps of the participants, and the weight of the total number of operation steps of the participants is not less than the weight of the number of participants. Based on the weight of the number of participants, the weight of the total number of operation steps of the participants, and the weight of the total number of operation steps that need to be crossed, the weighted item of the number of participants, the weighted item of the total number of operation steps of the participants, and the weighted item of the total number of operation steps that need to be crossed are determined. The ease of operation for a participant is determined by summing the weighted terms of the number of participants, the total number of operation steps for each participant, and the total number of operation steps that need to be crossed. The ease of operation for a participant is negatively correlated with the sum of the weighted terms of the number of participants, the total number of operation steps for each participant, and the total number of operation steps that need to be crossed.
3. The cryptographic usability evaluation method as described in any one of claims 1-2, characterized in that, The auxiliary usage phase includes password installation, password login, password configuration, password debugging, password update, password backup and recovery, password repair, password replacement, and password destruction.
4. A device for evaluating the usability of cryptography, characterized in that, The device includes: The independence evaluation module is used to determine whether the password under test meets the usage requirements of the current usage scenario. It evaluates the independence of passwords under test that meet the usage requirements and obtains the independence evaluation result. The independence evaluation result is negatively correlated with the number of passwords under test. The passwords under test are all password products used in a certain scenario. The usability evaluation module is used to determine the usability evaluation result of the password under test based on the ease of operation for the participants involved in the auxiliary use phase and the performance compliance of the password under test in the formal use phase. The comprehensive evaluation module is used to combine the independence evaluation results and the usability evaluation results to determine the password usability evaluation result of the password under test; The independence assessment module is also used for: If the password to be tested meets the usage requirements of the current usage scenario, then the password type and number of passwords to be tested are determined. Based on the types and number of passwords, the independence evaluation result of the password under test is determined; wherein the independence evaluation result of the password under test is negatively correlated with the sum of the types and number of passwords. The ease-of-use evaluation module is also used for: The usage phases of the password under test are divided into an auxiliary usage phase and a formal usage phase. For the auxiliary stage of using the password under test, the ease of operation for the participants is determined based on the number of participants, the total number of operation steps of the participants, and the total number of operation steps that need to be crossed. The ease-of-use evaluation module is also used for: The performance of the password to be tested is evaluated, and the performance evaluation results are obtained. The performance compliance rate is determined based on the ratio of the performance test results to the performance requirement values. Based on the performance compliance and the ease of operation for the participants, the usability evaluation result of the password under test is determined.
5. A device for evaluating the usability of cryptography, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the cryptographic usability evaluation method as described in any one of claims 1 to 3.
6. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the cryptographic usability evaluation method as described in any one of claims 1 to 3.
7. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the cryptographic usability evaluation method as described in any one of claims 1 to 3.