Cryptographic security quantitative evaluation method, system, device and storage medium thereof

CN122533758APending Publication Date: 2026-08-07HAOFU CIPHER DETECTION TECH (CHENGDU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HAOFU CIPHER DETECTION TECH (CHENGDU) CO LTD
Filing Date
2026-05-11
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0012]本发明的目的在于克服现有技术的缺点,提供一种密码安全量化评估方法、系统、设备及其存储介质,旨在解决现有技术存在:评估结果缺乏量化标准,无法进行客观比较;评估维度碎片化,缺乏系统整合;评估成本高、周期长,难以常态化;环境与使用因素被严重忽视;评估静态化,无法适应动态威胁的技术问题

Benefits of technology

1、本发明通过构建多维度量化评估框架,将传统定性或二值化的安全评价(通过/不通过)转化为数值化的综合安全指数和等级划分。通过对密码算法、工程实现、物理安全、密钥管理等维度的指标进行精细化测量和无量纲化处理,使不同密码产品之间的安全水平具备了统一的度量标尺。用户可依据量化评分直观地进行产品选型对比,厂商也可清晰定位自身产品在行业中的安全水平层级;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122533758A_ABST
    Figure CN122533758A_ABST
Patent Text Reader

Abstract

The application provides a cryptographic security quantitative evaluation method, system, device and storage medium thereof, and belongs to the technical field of cryptographic security quantification; the method comprises the following steps: determining an evaluation object and obtaining a basic security evaluation result; establishing a quantitative evaluation framework comprising multiple evaluation dimensions of cryptographic algorithms and protocols, cryptographic engineering implementation, physical security, key management and the like, and configuring weights for each dimension; determining specific evaluation indexes under each dimension and performing quantitative processing, and adopting a dimensionless method to convert indexes that cannot be directly quantified; calculating dimension scores according to index quantitative values and dimension weights; introducing an environmental attenuation coefficient to correct the dimension scores, calculating a comprehensive security index and dividing a security level; and generating a standardized evaluation report; the application converts traditional qualitative evaluation into a quantifiable comprehensive security index, realizes comprehensive multi-dimensional measurement, and has the advantages of objective and comparable evaluation results, high consistency and repeatability, short evaluation period and low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cryptographic security quantification technology, and in particular to a cryptographic security quantification assessment method, system, device and its storage medium. Background Technology

[0002] Cryptography is a core support for ensuring network and information security, and is widely used in finance, government affairs, communications, and critical information infrastructure. With the continuous expansion of cryptographic application scenarios and the ongoing evolution of attack techniques, security assessment of cryptographic products has become a crucial step in ensuring they possess sufficient protective capabilities in actual deployments.

[0003] Currently, security assessments of cryptographic products primarily rely on the following methods: 1. Compliance Certification Major domestic and international cryptographic product security certifications include my country's Commercial Cryptographic Product Certification and international standards such as FIPS 140-3 (US Federal Information Processing Standard) and Common Criteria. These certifications typically test the cryptographic product's design documentation, module interfaces, role authentication, and physical security against predefined security level requirements. However, the results of these certifications are mostly qualitative, such as "pass / fail" or "meets security level X," failing to provide numerical security metrics and hindering detailed comparisons of security levels between different products.

[0004] 2. Penetration Testing Penetration testing simulates attacker behavior to discover and verify vulnerabilities in cryptographic products, thereby assessing their resilience. This method can uncover some implementation-level security issues, but its effectiveness is highly dependent on the individual experience and skill level of the testing team, making it difficult to guarantee test coverage and depth. Furthermore, due to the lack of standardized testing procedures and judgment criteria, different teams often produce significantly different results for the same product, leading to poor repeatability and consistency of evaluation results.

[0005] 3. Self-assessment checklist Based on best practices or industry standards, some assessments employ a checklist approach, where assessors check the security configuration and implementation of products against each item on the checklist. While simple to implement, this method is inherently subjective; the determination of checklist items often depends on the assessor's understanding and judgment, failing to generate objective quantitative data and thus failing to reflect the true differences in the overall security level of products.

[0006] The above evaluation method has the following technical shortcomings in practical applications: Lack of quantitative standards: Existing methods cannot provide numerical security scores, making it difficult for users to make horizontal comparisons and selection decisions between different cryptographic products, and product manufacturers are also unable to clearly identify the security shortcomings of their own products.

[0007] The evaluation dimensions are too narrow: most evaluation methods focus too much on the compliance of the cryptographic algorithm itself, while neglecting key dimensions such as engineering implementation security (such as code quality and vulnerability response), physical security (such as anti-tampering and side-channel protection), and key lifecycle management, resulting in incomplete evaluation coverage.

[0008] Gaps in Side-Channel Protection Assessment: For side-channel attacks such as timing attacks, power consumption analysis, electromagnetic radiation analysis, and fault injection, the existing standardized assessment system lacks effective and quantifiable testing methods and judgment criteria, resulting in the inability to accurately measure the actual physical protection capabilities of products.

[0009] Environmental factors are ignored: Existing assessments often treat products as isolated objects, failing to fully consider the impact of their actual deployment environment (such as physical access control, temperature and humidity conditions) and management practices (such as key management systems and personnel operating procedures) on the final security, resulting in discrepancies between laboratory assessment results and actual on-site security levels.

[0010] Poor dynamic adaptability: Traditional authentication models are mostly one-time static assessments, which cannot adapt to the rapid evolution of attack techniques and the continuous emergence of new vulnerabilities. The assessment results are easily outdated over time and lack the ability to continuously track and update dynamically.

[0011] The aforementioned deficiencies have led to a dilemma for both the supply and demand sides of cryptographic products: application users find it difficult to accurately select cryptographic products that meet their business risk level requirements based on objective data; while cryptographic product manufacturers are unable to optimize product design and improve security capabilities in a targeted manner through precise quantitative feedback, thus hindering the high-quality development of the cryptographic industry. Summary of the Invention

[0012] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method, system, device and storage medium for quantitative evaluation of cryptographic security. It aims to solve the technical problems of the prior art, such as: lack of quantitative standards for evaluation results, making objective comparison impossible; fragmented evaluation dimensions, lack of systematic integration; high evaluation cost and long cycle, making it difficult to normalize; serious neglect of environmental and usage factors; and static evaluation, which cannot adapt to dynamic threats.

[0013] To achieve the above objectives, this application proposes a method for quantitative evaluation of cryptographic security, comprising the following steps: Step 1: Determine the evaluation target of the cryptographic product to be evaluated, and obtain the basic security evaluation results of the evaluation target; Step 2: Establish a quantitative evaluation framework that includes multiple preset evaluation dimensions, and configure corresponding dimension weights for each evaluation dimension; Step 3: Based on the evaluation object, determine the specific evaluation indicators under each evaluation dimension, and quantify each evaluation indicator to obtain the quantitative value of the indicator; Step 4: Calculate the dimensional score of each evaluation dimension based on the quantified value of the indicator and the dimensional weight. Step 5: Calculate the comprehensive security index of the evaluation object based on the dimensional scores and the preset comprehensive security index model.

[0014] As a further solution, the multiple preset evaluation dimensions in step 2 include: cryptographic algorithm and protocol dimension, cryptographic engineering implementation dimension, physical security dimension, and key management dimension; The dimensional weights are dynamically adjusted based on cryptographic application scenarios and / or the development trends of attack techniques.

[0015] As a further solution, step 3 involves quantifying each of the evaluation indicators, specifically including: For the first type of indicators that can be directly measured, the measurement data is directly output as the quantitative value of the indicator. For the second type of indicators that cannot be directly measured, a judgment rule is established to determine compliance, and a dimensionless method is used to convert the judgment result into a quantitative value of the indicator.

[0016] As a further solution, step 4 specifically includes: According to formula D j =∑(w i ×S i )×VF j Calculate the dimensional score of the j-th evaluation dimension; Among them, D j For the dimension score, w i S represents the weight of the i-th indicator within this dimension. i VF is the individual score for the i-th indicator. j To verify the integrity factor.

[0017] As a further solution, step 5 is preceded by: Determine the environmental attenuation coefficient K; The environmental attenuation coefficient K is determined comprehensively based on the positive and negative factors of the deployment environment and management practices of the evaluation object, and is limited to a preset threshold range; The formula for calculating the comprehensive safety index in step 5 is as follows: Q = (αD1 + βD2 + γD3 + δD4) × K; Where Q is the comprehensive security index, α, β, γ, and δ are the dimensional weights of each evaluation dimension, and α+β+γ+δ=1, K is the environmental attenuation coefficient, D1 is the score of the cryptographic algorithm and protocol dimension, D2 is the score of the cryptographic engineering implementation dimension, D3 is the score of the physical security dimension, and D4 is the score of the key management dimension.

[0018] As a further solution, step 5 also includes: generating the security level of the evaluation object based on the comprehensive security index Q and a preset security level classification standard.

[0019] As a further solution, it also includes: generating a standardized evaluation report; the evaluation report shall include at least one or more of the following: detection data and judgment results for each indicator, detailed scores for each dimension, analysis of key risk points, improvement suggestions, and comparative analysis with similar products.

[0020] On the other hand, the present invention also provides a cryptographic security quantitative evaluation system for implementing the method described in any of the above claims, characterized in that the system comprises: A data acquisition module is used to acquire evaluation data and document information of the cryptographic product to be evaluated; wherein, the data acquisition module includes: The test interface is used to connect cryptographic algorithm testing tools, random number detection tools, or signal acquisition devices. A document parser used to parse product documents and certification reports; Configuration checker, used to check system configuration and parameter settings. A quantitative calculation module is used to store and manage the weights of each evaluation dimension and indicator, and to execute quantitative algorithms to calculate the quantitative values ​​of indicators, dimension scores, and a comprehensive security index; wherein, the quantitative calculation module includes: The indicator calculation engine is used to execute quantitative algorithms; The weight management unit is used to store and manage the weights of each indicator and dimension; A model calibrator is used to adjust the computational model based on test results.

[0021] A verification and testing module is used to verify the quantization results and perform side-channel testing and penetration testing; wherein, the verification and testing module includes: The penetration testing management unit is used to manage the penetration testing process; Side-channel test unit, used to perform standardized side-channel tests; The result validator is used to verify the accuracy of the quantification results.

[0022] The report generation module is used to generate a standardized evaluation report based on the outputs of the quantization calculation module and the verification test module.

[0023] In another aspect, the present invention also provides a cryptographic security quantitative evaluation device, comprising: The main control unit is the core software used to run the quantitative evaluation method as described in any of the above items; The test interface unit provides physical and logical interfaces for connecting to the cryptographic product under test. The signal acquisition unit is used to acquire the physical signals of the cryptographic product under test with high precision. Side-channel test unit, used to integrate power consumption analysis and / or electromagnetic analysis functions; The fault injection unit is used to inject controllable voltage and / or clock glitches into the cryptographic product under test. Secure storage unit for protecting evaluation data and keys.

[0024] In another aspect, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the cryptographic security quantitative evaluation method as described in any of the preceding claims.

[0025] Compared with related technologies, the cryptographic security quantitative assessment method, system, device, and storage medium provided by this invention have the following advantages: 1. This invention constructs a multi-dimensional quantitative evaluation framework, transforming traditional qualitative or binary security evaluations (pass / fail) into numerical comprehensive security indices and level classifications. By refining and dimensionlessly processing indicators across dimensions such as cryptographic algorithms, engineering implementation, physical security, and key management, a unified benchmark for measuring the security level of different cryptographic products is established. Users can intuitively compare and select products based on the quantitative scores, and manufacturers can clearly define the security level of their products within the industry. 2. This invention overcomes the limitations of traditional evaluation methods that overemphasize algorithm compliance, and for the first time incorporates key security dimensions such as cryptographic engineering implementation, side-channel protection, physical anti-tampering, and key lifecycle management into a unified evaluation system. Through multi-dimensional comprehensive weighted calculation, it can comprehensively reflect the true security capabilities of cryptographic products in terms of theoretical design, engineering implementation, and physical protection, filling the evaluation gaps in existing standards in areas such as side-channel protection and physical security, and improving the completeness and coverage of the evaluation results. 3. This invention shortens the evaluation cycle and reduces the evaluation cost through standardized quantitative processes and automated testing equipment. Through standardized indicator definitions, quantitative judgment rules, and systematic testing processes, this invention effectively eliminates the subjective dependence on human experience in traditional penetration testing and other methods. This transforms cryptographic security assessment from an expensive professional service into a scalable and repeatable engineering process, providing feasible technical means for routine security measurement needs such as product version iteration and supply chain security audits. 4. This invention innovatively introduces an environmental attenuation coefficient K, comprehensively considering both positive management factors (such as strict access control) and negative risk factors (such as harsh physical environments) in the actual deployment environment of the product, and dynamically corrects the laboratory test results. Compared with the static evaluation model of traditional evaluation methods that treats the product as an isolated object, the evaluation results of this invention can better reflect the actual security level of cryptographic products in real application scenarios, avoiding the problem of the disconnect between laboratory results and field effects.

[0026] 5. This invention supports dynamically adjusting the weights of each evaluation dimension based on the evolution of attack techniques, and the knowledge base module can integrate the latest vulnerability information and best practice cases. This enables the evaluation system to quickly respond to new attack methods and threat situations, overcoming the static and outdated shortcomings of traditional authentication models, and providing a sustainable and dynamically updated security measurement mechanism for cryptographic products. Attached Figure Description

[0027] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0028] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without creative effort.

[0029] Figure 1 This invention provides a schematic diagram of the steps involved in a method for quantitatively evaluating cryptographic security. Figure 2 This invention provides a schematic diagram of the structure of a cryptographic security quantitative evaluation system. The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0031] Example 1 Please see Figure 1 This embodiment provides a method for quantitative evaluation of cryptographic security, including the following steps: Step 1: Determine the evaluation target of the cryptographic product to be evaluated, and obtain the basic security evaluation results of the evaluation target; Step 2: Establish a quantitative evaluation framework that includes multiple preset evaluation dimensions, and configure corresponding dimension weights for each evaluation dimension; Step 3: Based on the evaluation object, determine the specific evaluation indicators under each evaluation dimension, and quantify each evaluation indicator to obtain the quantitative value of the indicator; Step 4: Calculate the dimensional score of each evaluation dimension based on the quantified value of the indicator and the dimensional weight. Step 5: Calculate the comprehensive security index of the evaluation object based on the dimensional scores and the preset comprehensive security index model.

[0032] It should be noted that the core of this embodiment lies in establishing a complete transformation process from "raw evaluation data" to "final quantitative index". This method first identifies the cryptographic product to be evaluated (the evaluation object) and obtains its basic evaluation results (such as whether it has passed a certain certification). Then, it constructs a quantitative framework containing multiple dimensions and assigns weights to each dimension, thereby building the "skeleton" of the evaluation. Next, specific measurable indicators are broken down for each dimension, and the raw measurement data of these indicators are converted into standardized scores according to rules.

[0033] Finally, this method employs a hierarchical weighted calculation: first, it aggregates the index scores to obtain the scores for each dimension; then, it combines the weights of each dimension for comprehensive calculation, ultimately generating a comprehensive security index representing the overall security level of the product. In short, this embodiment essentially defines a general method for transforming scattered, qualitative cryptographic security testing information into a unified, comparable numerical security measurement result through multi-dimensional weighting and dimensionless processing.

[0034] Furthermore, the multiple preset evaluation dimensions in step 2 include: cryptographic algorithm and protocol dimension, cryptographic engineering implementation dimension, physical security dimension, and key management dimension; The dimensional weights are dynamically adjusted based on cryptographic application scenarios and / or the development trends of attack techniques.

[0035] Specifically, this embodiment concretizes the abstract "multiple preset evaluation dimensions" into four key dimensions: cryptographic algorithms and protocols, cryptographic engineering implementation, physical security, and key management. These four dimensions together constitute a complete evaluation system, corresponding to the theoretical design security of cryptographic products, the quality of software code implementation, the hardware's resistance to physical attacks, and the full lifecycle management of keys, thereby solving the technical problems of traditional evaluation dimensions being singular and incomplete.

[0036] Furthermore, this embodiment introduces a dynamic weight adjustment mechanism, allowing for flexible configuration of the weights across the four dimensions based on "cryptographic application scenarios" or "attack technology development trends." For example, in cloud application scenarios, the weight of the "engineering implementation" dimension can be appropriately increased, while in edge computing devices exposed to physical environments, the weight of the "physical security" dimension can be strengthened. Simultaneously, when a new side-channel attack technique emerges, the weight of the corresponding protection indicator can be promptly increased. This feature enables the evaluation system to adapt dynamically, avoiding the problem of traditional static evaluation standards becoming outdated as threats evolve.

[0037] Furthermore, step 3 involves quantifying each of the evaluation indicators, specifically including: For the first type of indicators that can be directly measured, the measurement data is directly output as the quantitative value of the indicator. For the second type of indicators that cannot be directly measured, a judgment rule is established to determine compliance, and a dimensionless method is used to convert the judgment result into a quantitative value of the indicator.

[0038] Specifically, the core of this embodiment lies in establishing a set of differentiated quantification rules for different types of indicators. In actual cryptographic product evaluation, the raw data collected varies in form and cannot be directly used for unified calculation. Therefore, this embodiment creatively divides the evaluation indicators into two categories and processes them separately: for the "first type of indicator" (such as physical quantities like power consumption signal-to-noise ratio and fault detection rate) for which measurement data can be directly obtained, the measured values ​​are directly output as the basis for quantification; for the "second type of indicator" (such as qualitative indicators like code standardization and the completeness of key management processes) for which direct measurement is not possible, clear judgment rules are first established to make compliance judgments, and then these judgment results are converted into standard scores through a mathematical dimensionless method.

[0039] This design essentially builds a bridge between "raw test data" and "standardized scores." By employing a combined approach of "direct quantification" and "indirect transformation" for both types of indicators, this embodiment ensures that all indicators across all evaluation dimensions can ultimately participate in subsequent weighted calculations in a unified numerical form. This categorized quantification method preserves the accuracy of objective measurement data while resolving the technical challenge of quantifying and comparing qualitative indicators, thus laying the foundation for the integrity and operability of the entire evaluation system.

[0040] Furthermore, step 4 specifically includes: According to formula D j =∑(w i ×S i )×VF j Calculate the dimensional score of the j-th evaluation dimension; Among them, D j For the dimension score, wi S represents the weight of the i-th indicator within this dimension. i VF is the individual score for the i-th indicator. j To verify the integrity factor.

[0041] Specifically, this embodiment specifies the score D for the j-th evaluation dimension. j It consists of two parts: First, the individual scores S of all indicators under this dimension. i Its corresponding indicator weight w i Perform a weighted summation to obtain the base score for that dimension; then multiply by a validation integrity factor VF. j This allows for the generation of the final dimensional score. This design not only reflects the differences in importance among different indicators within the same dimension, but also enables fine-tuning through indicator weights.

[0042] More importantly, verify the integrity factor VF j The introduction of this factor addresses the problem of "testing incompletely" in traditional assessments. This factor characterizes the extent to which each safety requirement in this dimension is verified—if a safety boundary or applicable condition is not fully verified during testing, VF... j The value of will be reduced accordingly, thus reducing the dimensional score. This mechanism ensures that the dimensional score depends not only on the performance of the indicator, but also on the depth and breadth of the testing and validation, effectively avoiding the problem of inflated scores due to incomplete testing, and making the evaluation results more rigorous and credible.

[0043] Furthermore, step 5 is preceded by: Determine the environmental attenuation coefficient K; The environmental attenuation coefficient K is determined comprehensively based on the positive and negative factors of the deployment environment and management practices of the evaluation object, and is limited to a preset threshold range; The formula for calculating the comprehensive safety index in step 5 is as follows: Q = (αD1 + βD2 + γD3 + δD4) × K; Where Q is the comprehensive security index, α, β, γ, and δ are the dimensional weights of each evaluation dimension, and α+β+γ+δ=1, K is the environmental attenuation coefficient, D1 is the score of the cryptographic algorithm and protocol dimension, D2 is the score of the cryptographic engineering implementation dimension, D3 is the score of the physical security dimension, and D4 is the score of the key management dimension.

[0044] Specifically, this embodiment further introduces an environmental attenuation coefficient K as a key correction factor and fully defines the final calculation formula for the comprehensive safety index. The claim first clarifies that an environmental attenuation coefficient K needs to be determined before calculating the final comprehensive safety index. This coefficient is not generated arbitrarily but is comprehensively determined based on the actual deployment environment and management practices of the evaluated object—if the actual environment has positive factors such as strict access control and backup mechanisms, the K value is increased; if there are negative factors such as harsh temperature and humidity conditions and weak physical protection, the K value is reduced accordingly. At the same time, to maintain the reasonableness of the score, the K value is usually limited to a reasonable threshold range (e.g., 0.8 to 1.2) to prevent over-correction.

[0045] In the calculation phase, this embodiment provides a complete formula for the comprehensive security index, which clearly demonstrates the logic behind the evaluation result generation: First, the scores of the four dimensions (D1 to D4) are weighted and summed with their corresponding weights (α to δ) to obtain the product's baseline security score; then, this is multiplied by the environmental attenuation coefficient K to obtain the final comprehensive security index Q. The ingenuity of this design lies in its decoupling and recombining of the product's intrinsic security capabilities (reflected by the dimensional scores obtained from laboratory testing) with environmental influencing factors (reflected by the K value). This means that a cryptographic module that scores highly in the laboratory, if deployed in an environment with extremely poor physical protection, will have its final Q value accurately reflect this risk due to the reduction in the K value, thus making the evaluation results more practically instructive.

[0046] Furthermore, after step 5, the method further includes: generating the security level of the evaluation object based on the comprehensive security index Q and a preset security level classification standard.

[0047] Specifically, this embodiment maps the calculated comprehensive security index to an intuitive and easy-to-understand security level, thus completing the final transformation from "numerical calculation" to "value judgment." Specifically, after calculating the comprehensive security index Q using the formula in claim 5, the method does not stop at an abstract number, but further compares it with a preset security level classification standard, assigning the Q value to the corresponding level range (e.g., S-level Excellent, A-level Good, B-level Good, C-level Basic, D-level Risk). This design transforms what might otherwise be a difficult-to-interpret quantitative score into a level label with clear business meaning, greatly improving the readability of the assessment results and their value for decision-making guidance.

[0048] Furthermore, it also includes: generating a standardized evaluation report; the evaluation report shall include at least one or more of the following: detection data and judgment results for each indicator, detailed scores for each dimension, analysis of key risk points, improvement suggestions, and comparative analysis with similar products.

[0049] Specifically, after calculating the comprehensive security index and classifying the security level, this embodiment further includes a report generation step. This report contains at least one or more of the following: detection data and judgment results for each indicator, detailed scores for each dimension, analysis of key risk points, improvement suggestions, and comparative analysis with similar products. This design ensures that the evaluation results are no longer limited to an abstract score or level, but are transformed into a complete set of traceable, analyzable, and actionable information.

[0050] Example 2 Please see Figure 2 The present invention also provides a cryptographic security quantitative evaluation system for implementing the method described in any of the above embodiments, characterized in that the system comprises: A data acquisition module is used to acquire evaluation data and document information of the cryptographic product to be evaluated; wherein, the data acquisition module includes: The test interface is used to connect cryptographic algorithm testing tools, random number detection tools, or signal acquisition devices. A document parser used to parse product documents and certification reports; Configuration checker, used to check system configuration and parameter settings. A quantitative calculation module is used to store and manage the weights of each evaluation dimension and indicator, and to execute quantitative algorithms to calculate the quantitative values ​​of indicators, dimension scores, and a comprehensive security index; wherein, the quantitative calculation module includes: The indicator calculation engine is used to execute quantitative algorithms; The weight management unit is used to store and manage the weights of each indicator and dimension; A model calibrator is used to adjust the computational model based on test results.

[0051] A verification and testing module is used to verify the quantization results and perform side-channel testing and penetration testing; wherein, the verification and testing module includes: The penetration testing management unit is used to manage the penetration testing process; Side-channel test unit, used to perform standardized side-channel tests; The result validator is used to verify the accuracy of the quantification results.

[0052] The report generation module is used to generate a standardized evaluation report based on the outputs of the quantization calculation module and the verification test module.

[0053] In a more specific embodiment, this embodiment provides a cryptographic security quantitative assessment system. This system implements the cryptographic security quantitative assessment method described in this invention. The system includes: a data acquisition module, a quantitative calculation module, a verification and testing module, a report generation module, and a knowledge base module. The functions of each module are described in detail below with reference to a specific assessment process.

[0054] I. Assessment Preparation Phase In the assessment preparation phase, the first step is to identify the assessment targets and conduct basic security assessments, a process mainly completed by the data acquisition module.

[0055] 1. Identify the assessment target The data acquisition module reads the technical documents of the cryptographic product to be evaluated, including product specifications, design documents, and certification reports, through its document parser. It automatically extracts information on product type, security boundaries, and core protected assets to establish an evaluation scope matrix. For example, for a hardware security module, the following information can be extracted: Product Type: Hardware Security Module Security boundaries: cryptographic module boundary (PCIe interface), physical boundary (metal enclosure), logical boundary (API call interface). Core assets: root key (stored in tamper-proof storage), user key (session key), security policy (access control policy). 2. Conduct basic safety assessments. The data acquisition module connects to various testing tools via a testing interface to perform basic security assessments on the product under evaluation. The testing interface supports connections to cryptographic algorithm testing tools (for verifying the correctness of algorithm implementations), protocol analyzers (for analyzing TLS / SSL protocol configurations), compliance testing tools, and more. Test results are output as pass / fail, serving as the entry criteria for subsequent quantitative evaluations. If the basic assessment fails, the product is directly deemed unqualified, and the evaluation process is terminated.

[0056] II. Establishment Phase of Quantitative Assessment Framework The quantitative evaluation framework is established by the quantitative calculation module, which includes a weight management unit and a model calibrator.

[0057] 1. Select quantitative evaluation dimensions The quantitative calculation module reads preset evaluation dimension templates from the knowledge base module, which by default include four core dimensions: cryptographic algorithms and protocols, cryptographic engineering implementation, physical security, and key management. The predefined evaluation content for each dimension is as follows: Cryptographic Algorithms and Protocols: Compliance, Implementation Correctness, Protocol Security, Implementation Performance Cryptographic engineering implementation: code security, vulnerability management, and side-channel protection (timing analysis, power analysis, fault injection). Physical security: tamper protection, detection resistance, environmental protection (voltage, temperature, clock anomalies). Key management: random number quality, key generation, key storage, key lifecycle management (transfer, replacement, destruction).

[0058] 2. Assign weights to quantitative evaluation dimensions The weight management unit stores the weight configurations for each dimension and supports dynamic adjustments. The default configuration is: Cryptographic algorithms and protocols: 20% (weight W1=20%) Cryptographic engineering implementation: 35% (weight W2=35%) Physical security: 25% (weight W3=25%) Key management: 20% (weight W4=20%) The model calibrator allows for adjustments to weights based on cryptographic use cases (such as financial payments, IoT, and cloud services) or attack technology trends. For example, when new breakthroughs occur in side-channel attack techniques, the weight of the "cryptographic engineering implementation" dimension can be increased through the model calibrator.

[0059] III. Quantitative Evaluation Stage The quantitative evaluation of indicators is completed collaboratively by the data acquisition module, the quantitative calculation module, and the verification and testing module.

[0060] 1. Establish applicable safety boundaries The data acquisition module's document parser continues to analyze the product documentation, extracting applicable conditions and technical parameters for each dimension. For security boundaries not clearly defined in the documentation, the verification testing module initiates specific tests to define them. For example: Cryptographic Algorithms and Protocols: Detect whether the product uses insecure algorithms or protocols (such as MD5, SSL 2.0, RSA 1024-bit) and record the relevant configurations.

[0061] Cryptographic engineering implementation: Evaluate protection capabilities through side-channel testing units to identify the types of attacks that can be defended and the accuracy of detection. Physical security: The activation threshold of the password protection mechanism is tested by fault injection unit when the shell is damaged to different proportions.

[0062] Key management: Measure the quality of random numbers using random number detection tools and record the pass rate data.

[0063] 2. Determine the indicators The quantitative calculation module retrieves the corresponding indicator template from the knowledge base module based on the selected evaluation dimension to determine the specific evaluation indicators. These indicators are typically consistent with the content being evaluated, but can also be adjusted according to the characteristics of the evaluation object.

[0064] 3. Quantification of Indicators The indicator calculation engine of the quantitative calculation module is responsible for converting the raw measurement data into standardized indicator quantification values. The processing method is as follows: Failure scenario: If the basic safety assessment fails, it will be directly judged as unqualified and no further quantification will be carried out.

[0065] For metrics that can be directly quantified: For metrics that can be directly measured, such as random number pass rate (99.5%), fault detection rate (99.8%), and response time (50ns), the metric calculation engine directly outputs the measured value.

[0066] For indicators that cannot be directly quantified: For qualitative indicators that cannot be directly quantified, such as code standardization and vulnerability management process completeness, the indicator calculation engine performs compliance judgment based on preset judgment rules, and then uses dimensionless methods (such as thresholding or linear interpolation) to convert the judgment result into a standard quantitative value. The judgment rules can be pre-stored in the best practice library of the knowledge base module.

[0067] 4. Scoring Calculation and Standardization The indicator calculation engine converts the quantified values ​​of each indicator into standardized scores. A dimensionless method is used, and the calculation formula is as follows: The minimum requirement data and best practice data are obtained from the benchmark database of the knowledge base module.

[0068] Subsequently, the metrics calculation engine calculates the scores for each dimension: D j =∑(w i ×S i )×VF j ; where D j For the dimension score, w i S represents the weight of the i-th indicator within this dimension. i Let VFj be the score for the i-th indicator, and VFj be the validation completeness factor. The validation completeness factor is determined by the result validator of the validation test module based on the test coverage. If all applicable conditions for a certain dimension are validated, then VFj is valid. j =1.0; if there are unverified items, reduce them proportionally.

[0069] 5. Environmental degradation coefficient The quantitative calculation module calculates the environmental attenuation coefficient K based on the environmental information collected by the data acquisition module. Environmental information includes the deployment environment (such as the physical security level of the data center, temperature and humidity conditions) and management practices (such as access control systems, backup mechanisms, and personnel training), extracted by the document parser from on-site survey reports or maintenance documents. The calculation formula is: The specific values ​​for positive factor bonuses and negative factor deductions are obtained from the best practice library in the knowledge base module. The quantitative calculation module limits the K value to the range of [0.8, 1.2]. If the evaluation object has deficiencies in the establishment of the applicable condition safety boundary, then K is directly taken as the lowest value of 0.8.

[0070] 6. Calculation of Comprehensive Safety Index The index calculation engine calculates the comprehensive security index Q = (αD1 + βD2 + γD3 + δD4) × K according to the following formula; where Q is the comprehensive security index, α, β, γ, and δ are the dimensional weights of each evaluation dimension, and α + β + γ + δ = 1, K is the environmental attenuation coefficient, D1 is the score of the cryptographic algorithm and protocol dimension, D2 is the score of the cryptographic engineering implementation dimension, D3 is the score of the physical security dimension, and D4 is the score of the key management dimension. 7. Security Level Classification The quantitative calculation module determines the security level of the assessment object by comparing the calculated Q value with the security level classification standards stored in the knowledge base module. For example: Example 3 In one test implementation, this implementation performs a quantitative evaluation of the Hardware Security Module (HSM); Assessment Preparation: Select a specific model of hardware security module as the evaluation object and configure the test environment: Test equipment: ChipWhisperer-Lite, Teledyne LeCroy HDO6104 oscilloscope Testing software: Custom Python test scripts based on scipy, numpy, and matplotlib. Test dataset: 100 randomly generated 256-bit AES keys Dimension Selection: Select the effectiveness of side-channel protection capabilities in the engineering implementation security dimension, including timing attack, power consumption analysis, and fault injection protection.

[0071] Scoring Calculation: Timing attack protection score Measurement results: TVR=0.92, correlation coefficient=0.003.

[0072] Scoring rules: TVR score: TVR<0.05 gets 4 points, 0.05≤TVR<0.1 gets 3 points, 0.1≤TVR<0.2 gets 2 points, and TVR≥0.2 gets 1 point.

[0073] Correlation coefficient score: 4 points for correlation coefficient <0.001, 3 points for 0.001-0.005, 2 points for 0.005-0.01, and 1 point for correlation coefficient >0.01.

[0074] Overall score calculation: Time protection score = (TVR score × 0.6) + (correlation coefficient score × 0.4) = (3 points × 0.6) + (3 points × 0.4) = 3.0 points.

[0075] Power consumption analysis and protection score Measurement results: SNRRF=85, the required number of trajectories has increased by 500 times.

[0076] Scoring rules: SNRRF score: SNRRF>100 gets 4 points, 50-100 gets 3 points, 10-50 gets 2 points, <10 gets 1 point.

[0077] Track number improvement rating: >1000 times improvement gets 4 points, 500-1000 times improvement gets 3 points, 100-500 times improvement gets 2 points, <100 times improvement gets 1 point.

[0078] Overall score calculation: Power consumption protection score = (SNRRF score × 0.5) + (Trajectory number improvement score × 0.5) = (3 points × 0.5) + (3 points × 0.5) = 3.0 points.

[0079] Fault Injection Protection Rating Measurement results: Voltage glitch fault detection rate (FDR) = 99.5%.

[0080] Clock glitch detection rate (FDR) = 98.8%.

[0081] Safety response time = 50ns.

[0082] Key clearing success rate = 100%.

[0083] Scoring rules: FDR rating: ≥99.9% gets 4 points, 99-99.9% gets 3 points, 95-99% gets 2 points, <95% gets 1 point.

[0084] Response time rating: <100ns = 4 points, 100-500ns = 3 points, 500ns-1µs = 2 points, >1µs = 1 point.

[0085] Success rate rating: 100% gets 4 points, 95-100% gets 3 points, 90-95% gets 2 points, <90% gets 1 point.

[0086] Fault protection score = (Average FDR score × 0.4) + (Response time score × 0.3) + (Reset success rate score × 0.3) =[(3 points+3 points) / 2×0.4]+(4 points×0.3)+(4 points×0.3) =(3 points×0.4)+1.2 points+1.2 points=3.6 points Electromagnetic radiation protection rating Measurement results: Radiation attenuation = 32dB Mutual information = 0.02 bits Directional index = 1.8 Scoring rules: Attenuation rating: >40dB = 4 points, 30-40dB = 3 points, 20-30dB = 2 points, <20dB = 1 point Mutual information score: <0.01 bits = 4 points, 0.01-0.05 bits = 3 points, 0.05-0.1 bits = 2 points, >0.1 bits = 1 point Directionalism rating: 1.0-1.5 = 4 points, 1.5-2.0 = 3 points, 2.0-3.0 = 2 points, >3.0 = 1 point Overall score calculation: Electromagnetic protection score = (attenuation score × 0.4) + (mutual information score × 0.4) + (directivity score × 0.2) =(3 points×0.4)+(3 points×0.4)+(3 points×0.2)=3.0 points Dimensional comprehensive calculation The engineering safety dimension score = (Timing protection score × Timing weight) + (Power consumption protection score × Power consumption weight) + (Fault protection score × Fault weight) + (Electromagnetic protection score × Electromagnetic weight) = (3.0 × 0.20) + (3.0 × 0.35) + (3.6 × 0.30) + (3.0 × 0.15) = 0.6 + 1.05 + 1.08 + 0.45 = 3.18 points (out of 4 points) Standardized to a percentage system: 3.18 ÷ 4.0 × 100 = 79.5 points Implementation effect verification Table 1 shows a comparison with traditional evaluation methods: Table 1 Results compared with traditional evaluation methods Consistency verification of evaluation results Five different types of cryptographic products were selected and evaluated by three independent teams using the method of this invention. The results are shown in Table 2. Table 2 Comparison of different types of cryptographic products The results showed that the evaluation results were in good agreement (the standard deviation was less than 1.0).

[0087] In summary, this invention, through technological innovation, transforms the field of cryptographic security assessment from relying on subjective expert judgment to objective, data-driven measurement, achieving new industry standards in consistency and repeatability. It transforms expensive professional services into a scalable engineering process, improving detection efficiency and significantly reducing costs. Furthermore, it upgrades assessment from a single, qualitative method to a multi-dimensional, quantitative approach, increasing integrity coverage to 100%. The above are only some embodiments of this application and do not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A method for quantitatively evaluating cryptographic security, characterized in that, Includes the following steps: Step 1: Determine the evaluation target of the cryptographic product to be evaluated, and obtain the basic security evaluation results of the evaluation target; Step 2: Establish a quantitative evaluation framework that includes multiple preset evaluation dimensions, and configure corresponding dimension weights for each evaluation dimension; Step 3: Based on the evaluation object, determine the specific evaluation indicators under each evaluation dimension, and quantify each evaluation indicator to obtain the quantitative value of the indicator; Step 4: Calculate the dimensional score of each evaluation dimension based on the quantified value of the indicator and the dimensional weight. Step 5: Calculate the comprehensive security index of the evaluation object based on the dimensional scores and the preset comprehensive security index model.

2. The method for quantitative evaluation of cryptographic security according to claim 1, characterized in that, The multiple preset evaluation dimensions in step 2 include: cryptographic algorithm and protocol dimension, cryptographic engineering implementation dimension, physical security dimension, and key management dimension; The dimensional weights are dynamically adjusted based on cryptographic application scenarios and / or the development trends of attack techniques.

3. The method for quantitative evaluation of cryptographic security according to claim 1, characterized in that, Step 3 involves quantifying each of the evaluation indicators, specifically including: For the first type of indicators that can be directly measured, the measurement data is directly output as the quantitative value of the indicator. For the second type of indicators that cannot be directly measured, a judgment rule is established to determine compliance, and a dimensionless method is used to convert the judgment result into a quantitative value of the indicator.

4. The method for quantitative evaluation of cryptographic security according to claim 1, characterized in that, Step 4 specifically includes: According to formula D j =∑(w i ×S i )×VF j Calculate the dimensional score of the j-th evaluation dimension; Among them, D j For the dimension score, w i S represents the weight of the i-th indicator within this dimension. i VF is the individual score for the i-th indicator. j To verify the integrity factor.

5. The method for quantitative evaluation of cryptographic security according to claim 1, characterized in that, Before step 5, the following also applies: Determine the environmental attenuation coefficient K; The environmental attenuation coefficient K is determined comprehensively based on the positive and negative factors of the deployment environment and management practices of the evaluation object, and is limited to a preset threshold range; The formula for calculating the comprehensive safety index in step 5 is as follows: Q = (αD1 + βD2 + γD3 + δD4) × K; Where Q is the comprehensive security index, α, β, γ, and δ are the dimensional weights of each evaluation dimension, and α+β+γ+δ=1, K is the environmental attenuation coefficient, D1 is the score of the cryptographic algorithm and protocol dimension, D2 is the score of the cryptographic engineering implementation dimension, D3 is the score of the physical security dimension, and D4 is the score of the key management dimension.

6. The method for quantitative evaluation of cryptographic security according to claim 1, characterized in that, Step 5 is followed by: generating the security level of the evaluation object based on the comprehensive security index Q and a preset security level classification standard.

7. A method for quantitative evaluation of cryptographic security according to any one of claims 1 to 6, characterized in that, It also includes: generating a standardized evaluation report; the evaluation report shall include at least one or more of the following: detection data and judgment results for each indicator, detailed scores for each dimension, analysis of key risk points, improvement suggestions, and comparative analysis with similar products.

8. A cryptographic security quantitative evaluation system, used to implement the method according to any one of claims 1 to 7, characterized in that, The system includes: A data acquisition module is used to acquire evaluation data and document information of the cryptographic product to be evaluated; wherein, the data acquisition module includes: The test interface is used to connect cryptographic algorithm testing tools, random number detection tools, or signal acquisition devices. A document parser used to parse product documents and certification reports; Configuration checker, used to check system configuration and parameter settings. A quantitative calculation module is used to store and manage the weights of each evaluation dimension and indicator, and to execute quantitative algorithms to calculate the quantitative values ​​of indicators, dimension scores, and a comprehensive security index; wherein, the quantitative calculation module includes: The indicator calculation engine is used to execute quantitative algorithms; The weight management unit is used to store and manage the weights of each indicator and dimension; A model calibrator is used to adjust the computational model based on test results. A verification and testing module is used to verify the quantization results and perform side-channel testing and penetration testing; wherein, the verification and testing module includes: The penetration testing management unit is used to manage the penetration testing process; Side-channel test unit, used to perform standardized side-channel tests; The result validator is used to verify the accuracy of the quantification results. The report generation module is used to generate a standardized evaluation report based on the outputs of the quantization calculation module and the verification test module.

9. A cryptographic security quantitative evaluation device, characterized in that, include: The main control unit is used to run the core software of the quantitative evaluation method as described in any one of claims 1 to 7; The test interface unit provides physical and logical interfaces for connecting to the cryptographic product under test. The signal acquisition unit is used to acquire the physical signals of the cryptographic product under test with high precision. Side-channel test unit, used to integrate power consumption analysis and / or electromagnetic analysis functions; The fault injection unit is used to inject controllable voltage and / or clock glitches into the cryptographic product under test. Secure storage unit for protecting evaluation data and keys.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the cryptographic security quantitative evaluation method as described in any one of claims 1 to 7.