首页 | 本学科首页   官方微博 | 高级检索  
     

基于动态二进制插桩的密钥安全性检测
作者姓名:林昊  康绯  光焱
作者单位:信息工程大学数学工程与先进计算国家重点实验室,河南 郑州 450001
摘    要:针对加密软件中的密钥安全性问题,提出一种基于动态二进制插桩的密钥安全性检测方法。该方法面向CryptoAPI加密应用程序,首先通过对CryptoAPI密钥应用模式的分析,指出潜在的密钥安全性漏洞;然后以动态二进制分析平台Pin为支撑,动态记录程序运行期间的加解密过程信息;在此基础上设计关联性漏洞检测算法,实现对密钥安全性的检测。测试结果表明,该方法能够有效检测出两大类密钥安全性漏洞。

关 键 词:密钥安全性检测  动态二进制插桩  Pin平台  CryptoAPI加密应用程序  

Key security detection based on dynamic binary instrumentation
Authors:Hao LIN  Fei KANG  Yan GUANG
Affiliation:State Key Laboratory of Mathematical Engineering and Advanced Computing,PLA Information Engineering University,Zhengzhou 450001,China
Abstract:For the key security problem in the cryptographic software,the method of key security detection based on dynamic binary instrumentation was proposed.Aimed at CryptoAPI cryptographic software,the method firstly pointed out the potential key security vulnerabilities by analyzing the key applying patterns of CryptoAPI.Then it recorded cryptographic data information during the execution of the program dynamically using Pin platform.On this basis,a relevance vulnerability detection algorithm was designed to detect the key security.Test result indicated that it can effectively detect the two kinds of key security vulnerabilities.
Keywords:key security detection  dynamic binary instrumentation  Pin platform  CryptoAPI cryptographic software  
点击此处可从《》浏览原始摘要信息
点击此处可从《》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号