CN111881462A - Online analysis technology for commercial password application encryption effectiveness - Google Patents

Online analysis technology for commercial password application encryption effectiveness Download PDF

Info

Publication number
CN111881462A
CN111881462A CN202010690005.7A CN202010690005A CN111881462A CN 111881462 A CN111881462 A CN 111881462A CN 202010690005 A CN202010690005 A CN 202010690005A CN 111881462 A CN111881462 A CN 111881462A
Authority
CN
China
Prior art keywords
module
commercial
password
analysis
test
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202010690005.7A
Other languages
Chinese (zh)
Inventor
张睿
刘峰瑞
王小龙
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Priority to CN202010690005.7A priority Critical patent/CN111881462A/en
Publication of CN111881462A publication Critical patent/CN111881462A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/36Preventing errors by testing or debugging software
    • G06F11/3668Software testing
    • G06F11/3672Test management
    • G06F11/3692Test management for test results analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Quality & Reliability (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

The invention discloses an online analysis technology for commercial password application encryption validity, wherein the commercial password encryption validity analysis equipment comprises a password generation module, an input module, an analysis module, a test module, a generation module, an evaluation module and an output module, the analysis module has the functions of password algorithm analysis, password module analysis and password system analysis, and the test module has the functions of multivariate test, interference item side view and cycle test. According to the invention, through the password generation module, the input module and the output module, the efficiency of the commercial password on-line analysis is effectively improved, the difficulty of manual input is greatly reduced, the automation of the commercial password analysis is improved, and the method is simpler and quicker.

Description

Online analysis technology for commercial password application encryption effectiveness
Technical Field
The invention relates to the technical field of information security, in particular to an online analysis technology for commercial password application encryption effectiveness.
Background
The commercial password refers to a password technology and a password product used for performing encryption protection or security authentication on information that does not relate to national secret content. The commercial password technology is the core of the commercial password and is an important tool for protecting self rights and interests of social groups, organizations, enterprises and public institutions and individuals in the information era. The country puts the commercial cryptography into the national secrets, and any entity or person has responsibility and obligation to protect the secrets of the commercial cryptography.
Through massive search, the public number of the prior art is found to be CN111030815A, and the online detection device for the commercial password application encryption effectiveness comprises: the device comprises a data acquisition module, a data analysis module, a data randomness detection module and a statistical analysis module; the data acquisition module is accessed into a network where an information system is located and acquires data generated by channel encryption or information source encryption in the information system; the data analysis module strips the packet header of the acquired data packet to obtain load data, and the load ciphertext data are spliced into data with the length meeting the data randomness detection requirement; the data randomness detection module carries out randomness analysis detection on the spliced data to be detected, and the randomness of the data is respectively calculated from six dimensions of 01 balance detection, poker detection, serial detection, run-length distribution detection, autocorrelation detection and maximum run-length detection in a block; and the statistical analysis module is used for counting a plurality of groups of results subjected to randomness analysis detection and judging the data encryption effectiveness according to rules. Has the advantages that: the encryption effectiveness can be detected under the condition of non-invasive password equipment without knowing an encryption algorithm, an encryption working mode and an encryption key.
In summary, the existing commercial cryptogram analysis equipment and method have low degree of automation of cryptogram analysis, mainly use manual test as the main, the detection methods are overlapped, whether the cryptogram algorithm meets the regulations or not and whether the cryptogram algorithm is safe or not can not be effectively evaluated, and simultaneously, multivariate test, interference item test and cycle test are lacked, so that a plurality of uncertain factors exist in the test process, and the detection effect of the commercial cryptogram validity is reduced.
Disclosure of Invention
The invention aims to provide an online analysis technology for the encryption validity of commercial passwords, so as to solve the problems in the background technology.
In order to achieve the purpose, the invention provides the following technical scheme: the utility model provides an on-line analysis technique of commercial password application encryption validity, commercial password encryption validity analysis equipment includes password generation module, input module, analysis module, test module, generation module, evaluation module and output module, the analysis module function has cryptographic algorithm analysis, cryptographic module analysis and cryptosystem analysis, the test module function has multivariable test, interference item looks sideways at, the circulation test.
Preferably, the password generation module is connected to the input module via a network, the password generation module can generate a commercial password through a computer terminal, the password generation module can output the commercial password to the input module, and the input module can input the commercial password to the analysis module.
Preferably, the analysis module, the input module and the test module construct a connection relationship;
the cipher algorithm analysis can analyze the algorithm of the commercial cipher and mainly comprises a grouping algorithm, a sequence algorithm and a public key algorithm;
the cipher module analysis can analyze a module of the commercial cipher, and the main realization method comprises a hardware realization mode, a software realization mode and a software and hardware mixed realization mode;
the cryptosystem analysis can evaluate the commercial cryptosystem, and is used for the functions of information safety and application system stability.
Preferably, the test module, the analysis module and the generation module construct a connection relationship;
the multivariate test can add single or multiple variables in the analysis process to satisfy multiple keys of the commercial cipher;
the disturbance term test can add disturbance term technology in the analysis process, so that the comprehensiveness of the analysis is increased;
the circulation test can be used for carrying out preset circulation test on the test flow of the commercial password after the multivariate test and the interference item test are finished.
Preferably, after the test module finishes the test of the commercial password, the side-looking result is transmitted to the generating module;
the generating module can generate comprehensive information from the test result and transmit the comprehensive information to the evaluation module, and the evaluation module evaluates the test result and transmits the result to the computer terminal through the output module.
Preferably, the commercial cryptanalysis process is as follows:
the method comprises the following steps: a worker uses a password generation module carried by a computer terminal to generate a commercial password;
step two: the password generation module can transmit the commercial password to the analysis module through the input module;
step three: after receiving the commercial password, the analysis module analyzes the algorithm, the module and the system of the commercial password and transmits the algorithm, the module and the system to the test module;
step four: the test module adds multivariable and interference items in the commercial password test process, and performs preset cyclic detection after detection is completed;
step five: after the test module detects the commercial password, the test module can output the information to the generation module;
step six: the generation module transmits the information to the evaluation module, and the evaluation module can evaluate the commercial password and transmit the information to the computer terminal through the output module.
Compared with the prior art, the invention has the beneficial effects that: in the process of detecting the validity of the commercial password, the input module and the output module are arranged at the computer terminal, the validity of the commercial password can be detected through a test program carried by the computer terminal, the input module and the output module can respectively and automatically input the commercial password generated by the computer terminal into the test program, and the test result can be output to the computer terminal through the output module, so that the time for manual input and output is effectively saved, and the automation degree of the validity test of the commercial password is greatly improved; through the analysis module, can carry out classification analysis to the cryptographic algorithm, cryptographic module and the cryptosystem of commercial password, test module can carry out multivariable, the interference item is tested with commercial password simultaneously to carry out the circulation test, effectively improve the comprehensiveness of commercial password validity test, be fit for studying the risk assessment of commercial cryptosystem, the index system of system security demand, including the establishment of evaluation criterion, risk index system, effectively improve the basic theory of password evaluation, make commercial password safe and reliable more.
Drawings
FIG. 1 is a schematic diagram of an analysis process according to the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention.
In the description of the present invention, it should be noted that the terms "upper", "lower", "inner", "outer", "front", "rear", "both ends", "one end", "the other end", and the like indicate orientations or positional relationships based on those shown in the drawings, and are only for convenience of description and simplicity of description, but do not indicate or imply that the referred device or element must have a specific orientation, be constructed in a specific orientation, and be operated, and thus, should not be construed as limiting the present invention. Furthermore, the terms "first" and "second" are used for descriptive purposes only and are not to be construed as indicating or implying relative importance.
In the description of the present invention, it is to be noted that, unless otherwise explicitly specified or limited, the terms "mounted," "disposed," "connected," and the like are to be construed broadly, such as "connected," which may be fixedly connected, detachably connected, or integrally connected; can be mechanically or electrically connected; they may be connected directly or indirectly through intervening media, or they may be interconnected between two elements. The specific meanings of the above terms in the present invention can be understood in specific cases to those skilled in the art.
Referring to fig. 1, an embodiment of the present invention:
the first embodiment is as follows:
the utility model provides an on-line analysis technique of commercial password application encryption validity, commercial password encryption validity analysis equipment includes password generation module, input module, analysis module, test module, generation module, evaluation module and output module, and the analysis module function has cryptographic algorithm analysis, cryptographic module analysis and cryptosystem analysis, and the test module function has multivariable test, interference item and looks sideways at, circulation test.
The password generation module is connected with the input module through a network, the password generation module can generate a commercial password through a computer terminal, the password generation module can output the commercial password to the embedding module, and the input module can input the commercial password into the analysis module.
The analysis module, the input module and the test module construct a connection relation;
the cipher algorithm analysis can analyze the algorithm of the commercial cipher, and mainly comprises a grouping algorithm, a sequence algorithm and a public key algorithm;
the cipher module analysis can analyze a module of the commercial cipher, and the main realization method comprises a hardware realization mode, a software realization mode and a software and hardware mixed realization mode;
the cryptosystem analysis can evaluate the commercial cryptosystem, and is used for the functions of information safety and application system stability.
The test module, the analysis module and the generation module construct a connection relation;
multivariate tests can add single or multiple variables during analysis to satisfy multiple keys of a commercial cipher;
the disturbance term test can add disturbance term technology in the analysis process, and the comprehensiveness of the analysis is increased.
Through the analysis module, can carry out classification analysis to the cryptographic algorithm, cryptographic module and the cryptosystem of commercial password, test module can carry out multivariable, the interference item is tested with commercial password simultaneously to carry out the circulation test, effectively improve the comprehensiveness of commercial password validity test, be fit for studying the risk assessment of commercial cryptosystem, the index system of system security demand, including the establishment of evaluation criterion, risk index system, effectively improve the basic theory of password evaluation, make commercial password safe and reliable more.
After the testing module tests the commercial passwords, the side-looking result is transmitted to the generating module;
the generating module can generate comprehensive information from the test result and transmit the comprehensive information to the evaluating module, the evaluating module evaluates the test result and transmits the result to the computer terminal through the output module, and after the multivariate test and the interference item test are completed, the preset cycle test is carried out on the test flow of the commercial password.
The input module and the output module are arranged at the computer terminal, the effectiveness of the commercial password can be detected through a test program carried by the computer terminal, the input module and the output module can respectively automatically input the commercial password generated by the computer terminal into the test program, and the test result can be output to the computer terminal through the output module, so that the time of manual input and output is effectively saved, and the automation degree of the effectiveness test of the commercial password is greatly improved.
Example two:
the commercial cryptanalysis procedure is as follows:
the method comprises the following steps: a worker uses a password generation module carried by a computer terminal to generate a commercial password;
step two: the password generation module can transmit the commercial password to the analysis module through the input module;
step three: after receiving the commercial password, the analysis module analyzes the algorithm, the module and the system of the commercial password and transmits the algorithm, the module and the system to the test module;
step four: the test module adds multivariable and interference items in the commercial password test process, and performs preset cyclic detection after detection is completed;
step five: after the test module detects the commercial password, the test module can output the information to the generation module;
step six: the generation module transmits the information to the evaluation module, and the evaluation module can evaluate the commercial password and transmit the information to the computer terminal through the output module.
It will be evident to those skilled in the art that the invention is not limited to the details of the foregoing illustrative embodiments, and that the present invention may be embodied in other specific forms without departing from the spirit or essential attributes thereof. The present embodiments are therefore to be considered in all respects as illustrative and not restrictive, the scope of the invention being indicated by the appended claims rather than by the foregoing description, and all changes which come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein. Any reference sign in a claim should not be construed as limiting the claim concerned.

Claims (6)

1. An on-line analysis technique for commercial cipher application encryption validity is characterized in that: the commercial password encryption effectiveness analysis equipment comprises a password generation module, an input module, an analysis module, a test module, a generation module, an evaluation module and an output module, wherein the analysis module has the functions of password algorithm analysis, password module analysis and password system analysis, and the test module has the functions of multivariate test, interference item side view and cycle test.
2. The on-line analysis technique for commercial cryptography application encryption validity of claim 1, wherein: the password generation module is connected with the input module through a network, the password generation module can generate a commercial password through a computer terminal, the password generation module can output the commercial password to the placement module, and the input module can input the commercial password into the analysis module.
3. The on-line analysis technique for commercial cryptography application encryption validity of claim 1, wherein: the analysis module, the input module and the test module construct a connection relation;
the cipher algorithm analysis can analyze the algorithm of the commercial cipher and mainly comprises a grouping algorithm, a sequence algorithm and a public key algorithm;
the cipher module analysis can analyze a module of the commercial cipher, and the main realization method comprises a hardware realization mode, a software realization mode and a software and hardware mixed realization mode;
the cryptosystem analysis can evaluate the commercial cryptosystem, and is used for the functions of information safety and application system stability.
4. The on-line analysis technique for commercial cryptography application encryption validity of claim 1, wherein: the test module, the analysis module and the generation module construct a connection relation;
the multivariate test can add single or multiple variables in the analysis process to satisfy multiple keys of the commercial cipher;
the disturbance term test can add disturbance term technology in the analysis process, so that the comprehensiveness of the analysis is increased;
the circulation test can be used for carrying out preset circulation test on the test flow of the commercial password after the multivariate test and the interference item test are finished.
5. The on-line analysis technique for commercial cryptography application encryption validity of claim 1, wherein: after the test module finishes testing the commercial password, the side-looking result is transmitted to the generating module;
the generating module can generate comprehensive information from the test result and transmit the comprehensive information to the evaluation module, and the evaluation module evaluates the test result and transmits the result to the computer terminal through the output module.
6. The on-line analysis technique for commercial cryptography application encryption validity of claim 1, wherein: the commercial cryptanalysis process is as follows:
the method comprises the following steps: a worker uses a password generation module carried by a computer terminal to generate a commercial password;
step two: the password generation module can transmit the commercial password to the analysis module through the input module;
step three: after receiving the commercial password, the analysis module analyzes the algorithm, the module and the system of the commercial password and transmits the algorithm, the module and the system to the test module;
step four: the test module adds multivariable and interference items in the commercial password test process, and performs preset cyclic detection after detection is completed;
step five: after the test module detects the commercial password, the test module can output the information to the generation module;
step six: the generation module transmits the information to the evaluation module, and the evaluation module can evaluate the commercial password and transmit the information to the computer terminal through the output module.
CN202010690005.7A 2020-07-17 2020-07-17 Online analysis technology for commercial password application encryption effectiveness Pending CN111881462A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202010690005.7A CN111881462A (en) 2020-07-17 2020-07-17 Online analysis technology for commercial password application encryption effectiveness

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202010690005.7A CN111881462A (en) 2020-07-17 2020-07-17 Online analysis technology for commercial password application encryption effectiveness

Publications (1)

Publication Number Publication Date
CN111881462A true CN111881462A (en) 2020-11-03

Family

ID=73156389

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202010690005.7A Pending CN111881462A (en) 2020-07-17 2020-07-17 Online analysis technology for commercial password application encryption effectiveness

Country Status (1)

Country Link
CN (1) CN111881462A (en)

Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050177716A1 (en) * 1995-02-13 2005-08-11 Intertrust Technologies Corp. Systems and methods for secure transaction management and electronic rights protection
US20080208560A1 (en) * 2007-02-23 2008-08-28 Harold Joseph Johnson System and method of interlocking to protect software - mediated program and device behaviors
US20120022938A1 (en) * 2010-07-26 2012-01-26 Revguard, Llc Automated Multivariate Testing Technique for Optimized Customer Outcome
US8239836B1 (en) * 2008-03-07 2012-08-07 The Regents Of The University Of California Multi-variant parallel program execution to detect malicious code injection
US20130236007A1 (en) * 2012-03-07 2013-09-12 Digital Lobe, Llc Methods for creating secret keys using radio and device motion and devices thereof
CN103516511A (en) * 2013-09-11 2014-01-15 国家电网公司 Method and device for detecting encryption algorithm and secret key
CN203941522U (en) * 2014-07-03 2014-11-12 深圳华视微电子有限公司 A kind of proving installation of national commercial cipher algorithm
CN104335219A (en) * 2012-03-30 2015-02-04 爱迪德加拿大公司 Securing accessible systems using variable dependent coding
US9020873B1 (en) * 2012-05-24 2015-04-28 The Travelers Indemnity Company Decision engine using a finite state machine for conducting randomized experiments
CN107612698A (en) * 2017-08-08 2018-01-19 北京中海闻达信息技术有限公司 A kind of commercial cipher detection method, device and system
CN111030815A (en) * 2019-12-26 2020-04-17 中科信息安全共性技术国家工程研究中心有限公司 Online detection method and device for commercial password application encryption effectiveness

Patent Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050177716A1 (en) * 1995-02-13 2005-08-11 Intertrust Technologies Corp. Systems and methods for secure transaction management and electronic rights protection
US20080208560A1 (en) * 2007-02-23 2008-08-28 Harold Joseph Johnson System and method of interlocking to protect software - mediated program and device behaviors
US8239836B1 (en) * 2008-03-07 2012-08-07 The Regents Of The University Of California Multi-variant parallel program execution to detect malicious code injection
US20120022938A1 (en) * 2010-07-26 2012-01-26 Revguard, Llc Automated Multivariate Testing Technique for Optimized Customer Outcome
US20130236007A1 (en) * 2012-03-07 2013-09-12 Digital Lobe, Llc Methods for creating secret keys using radio and device motion and devices thereof
CN104335219A (en) * 2012-03-30 2015-02-04 爱迪德加拿大公司 Securing accessible systems using variable dependent coding
US9020873B1 (en) * 2012-05-24 2015-04-28 The Travelers Indemnity Company Decision engine using a finite state machine for conducting randomized experiments
CN103516511A (en) * 2013-09-11 2014-01-15 国家电网公司 Method and device for detecting encryption algorithm and secret key
CN203941522U (en) * 2014-07-03 2014-11-12 深圳华视微电子有限公司 A kind of proving installation of national commercial cipher algorithm
CN107612698A (en) * 2017-08-08 2018-01-19 北京中海闻达信息技术有限公司 A kind of commercial cipher detection method, device and system
CN111030815A (en) * 2019-12-26 2020-04-17 中科信息安全共性技术国家工程研究中心有限公司 Online detection method and device for commercial password application encryption effectiveness

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
唐刚 等: "数据加密有效性测试的探究", 《信息网络安全》, no. 1, pages 117 - 118 *
崔应霞;李龙澍;: "基于输入输出关系的综合黑盒测试方法", 计算机工程与设计, no. 23, pages 11 - 14 *
金丽娜: "密码算法测试平台——算法实现技术研究", 《中国优秀博硕士学位论文全文数据库(硕士)信息科技辑 2007年第06期》 *

Similar Documents

Publication Publication Date Title
Xiao et al. Non-repudiation in neighborhood area networks for smart grid
CN110460425B (en) Attack method and system for side channel password energy leakage signal
CN114460495A (en) Sound-vibration integration-based large transformer operation state sensing system
CN104023352B (en) A kind of instant communication software side channel testing system towards mobile communication platform
CN207283595U (en) User power utilization data analysis integrated system based on power information collection
WO2021129200A1 (en) Online test method and device for commercial code application encryption effectiveness
Liu et al. Game attack–defense graph approach for modeling and analysis of cyberattacks and defenses in local metering system
CN104850467A (en) Computer self-protection system and computer self-protection method
CN111881462A (en) Online analysis technology for commercial password application encryption effectiveness
CN112087301A (en) Gas meter safety certification system based on state cryptographic algorithm
CN110097017B (en) Power transmission network special-type ammeter monitoring system and method
CN115600189A (en) Commercial password application security evaluation system
CN113204775B (en) Data security protection method and system
CN109450630A (en) A kind of quantum safety direct communication method based on Omega state and ultra dense coding
He et al. Smart grid nontechnical loss detection based on power gateway consortium blockchain
CN107947969A (en) Integrated circuit fault-resistant injection attacks safety evaluation method based on comentropy
CN113162947A (en) System and method for testing sensor network password security protocol
Jiang et al. A lightweight defense scheme for industrial data transmission against eavesdropping attacks and integrity attacks
CN109859831A (en) A kind of medical information management system
CN114896615B (en) Data security access system based on big data
CN110572250A (en) Automatic integral analysis method and system based on three-set separation attribute
CN108881273A (en) Wireless humiture sensor and its communication means based on national secret algorithm
Alotaibi et al. Detection of cyber attacks with access to partial data in power system using spy nodes
CN117811842B (en) Power grid security risk assessment method based on privacy calculation
CN110445255B (en) Smart power grid system based on lot signcryption and construction method thereof

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20201103

WD01 Invention patent application deemed withdrawn after publication