Password Generation Method, Device, Computer Equipment, and Storage Medium
By associating user identification data with random numbers and encrypting them to generate passwords, the problem of easy stolen and insufficient randomness in the password generation process is solved, and a high-security password generation is achieved.
Patent Information
- Application Number
- CN202111263790.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-27
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-10-27
AI Technical Summary
The password generation process is easily stolen by illegal users. If the password is not random enough, it is easily cracked.
By obtaining multiple user identification data, for each user identification data, the random values corresponding to each digit are selected from the pre-generated random number queue, and modulo operation processing is performed to obtain the user identification processing data, and encrypt it to finally generate a password.
Ensure that the generated password has high security and uniqueness, and avoid the risk of password being cracked.
Smart Images

Figure CN113901437B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a password generation method, device, computer device, and storage medium. Background Art
[0002] With the development of Internet technology, users basically need to set up accounts and passwords when logging in to various information systems and applications. With the expansion of the scope of information applications, the security issue of passwords has become increasingly prominent. The password generation process is prone to being monitored and stolen by illegal users. If the password randomness is insufficient, it is easily cracked. Therefore, how to generate passwords securely is an important security issue. Summary of the Invention
[0003] Based on this, in view of the technical problem that the password generation process is prone to being monitored and stolen by illegal users and is easily cracked if the password randomness is insufficient, it is necessary to provide a password generation method, device, computer device, and storage medium.
[0004] A password generation method, the method comprising:
[0005] Obtain a plurality of user identification data;
[0006] For each of the user identification data, select the random values corresponding to the respective digits of the user identification data from a pre-generated random number queue;
[0007] Perform modulo operation processing on the user identification data and the random values corresponding to the respective digits of the user identification data to obtain user identification processing data corresponding to each of the user identification data;
[0008] Perform encryption processing on each of the user identification processing data to obtain a user identification encrypted data group;
[0009] Generate a password according to each of the user identification encrypted data in the user identification encrypted data group.
[0010] In one embodiment, the obtaining a plurality of user identification data includes:
[0011] Obtain a plurality of initial user identification data;
[0012] Perform digital conversion processing on each of the initial user identification data to obtain converted user identification data composed of digits in a target base corresponding to the initial user identification data, as the user identification data.
[0013] In one embodiment, the selecting the random values corresponding to the respective digits of the user identification data from a pre-generated random number queue includes:
[0014] Obtain the total number of digits of the user identification data;
[0015] Based on the total number of digits, select a random number of a target length from the pre-generated random number queue;
[0016] Based on the positions of each digit, respectively determine the random number values corresponding to each digit from the random number of the target length.
[0017] In one embodiment, the modulo operation processing of the user identification data and the random number values corresponding to each digit of the user identification data to obtain the user identification processing data corresponding to each user identification data includes:
[0018] Respectively sum the values on each digit in the user identification data and the random number values corresponding to each digit to obtain the arithmetic sum corresponding to each digit;
[0019] Perform a modulo operation on the arithmetic sum corresponding to each digit to obtain the remainder values corresponding to each digit of the user identification data;
[0020] Based on the remainder values corresponding to each digit, form the user identification processing data corresponding to the user identification data.
[0021] In one embodiment, the encrypting each user identification processing data to obtain a user identification encrypted data group includes:
[0022] Encrypt each user identification processing data through an encryption machine and a working key matching the encryption machine to obtain the user identification encrypted data group.
[0023] In one embodiment, the generating a password according to each user identification encrypted data in the user identification encrypted data group includes:
[0024] Perform an encryption operation on each user identification encrypted data in the user identification encrypted data group to obtain an encrypted value;
[0025] Perform a radix conversion process on the characters belonging to non-target radixes in the encrypted value to obtain the numbers corresponding to the characters of the non-target radixes;
[0026] Combine the numbers corresponding to the characters of the non-target radixes and the numbers of the target radix in the encrypted value to obtain a password.
[0027] In one embodiment, after generating a password according to each user identification encrypted data in the user identification encrypted data group, it further includes:
[0028] Obtain a storage master key with a preset number of digits; the preset number of digits is the same as the number of digits of the encryption value;
[0029] Select a target random number with the preset number of digits from the random number queue;
[0030] Perform an encryption calculation on the data assembled by the user identification data group, the user identification encrypted data group, the target random number, and the password through the storage master key to obtain the ciphertext of the password as the storage key.
[0031] A password generation device, the device includes:
[0032] An acquisition module for acquiring a plurality of user identification data;
[0033] A selection module for, for each of the user identification data, selecting random number values corresponding to each digit of the user identification data from a pre-generated random number queue;
[0034] A processing module for performing a modulo operation on the user identification data and the random number values corresponding to each digit of the user identification data to obtain user identification processing data corresponding to each of the user identification data;
[0035] An encryption module for encrypting each of the user identification processing data to obtain a user identification encrypted data group;
[0036] A generation module for generating a password according to each user identification encrypted data in the user identification encrypted data group.
[0037] A computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0038] Obtain a plurality of user identification data;
[0039] For each of the user identification data, select random number values corresponding to each digit of the user identification data from a pre-generated random number queue;
[0040] Perform a modulo operation on the user identification data and the random number values corresponding to each digit of the user identification data to obtain user identification processing data corresponding to each of the user identification data;
[0041] Encrypt each of the user identification processing data to obtain a user identification encrypted data group;
[0042] Generate a password according to each user identification encrypted data in the user identification encrypted data group.
[0043] A computer-readable storage medium stores a computer program thereon. When the computer program is executed by a processor, the following steps are implemented:
[0044] Obtain a plurality of user identification data;
[0045] For each of the user identification data, select the random number values corresponding to the respective digits of the user identification data from a pre-generated random number queue;
[0046] Perform modulo operation processing on the user identification data and the random number values corresponding to the respective digits of the user identification data to obtain user identification processing data corresponding to each of the user identification data;
[0047] Perform encryption processing on each of the user identification processing data to obtain a user identification encrypted data group;
[0048] Generate a password according to each of the user identification encrypted data in the user identification encrypted data group.
[0049] The above password generation method, device, computer device, and storage medium obtain a plurality of user identification data, and select the random number values corresponding to the respective digits of each user identification data from a pre-generated random number queue, perform modulo operation processing on each user identification data and the random number values corresponding to the respective digits of each user identification data to obtain user identification processing data corresponding to each of the user identification data, further perform encryption processing on each user identification processing data to obtain a user identification encrypted data group, and finally generate a password according to each of the user identification encrypted data in the user identification encrypted data group. This method uses the user identification data as the data source of the password data and associates the user identification data with random numbers, ensuring the security of the obtained user identification processing data, further ensuring the uniqueness of the user identification encrypted data obtained based on the user identification processing data, so that the password generated based on the user identification encrypted data is highly difficult to be cracked, ensuring the security of the generated password. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 It is a schematic flowchart of a password generation method in an embodiment;
[0051] Figure 2 It is a schematic flowchart of a password generation method in another embodiment;
[0052] Figure 3 It is a schematic structural diagram of a quantum-based password generation and storage system in an embodiment;
[0053] Figure 4 It is a block diagram of the structure of a password generation device in an embodiment;
[0054] Figure 5 It is the internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0055] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0056] It should be noted that the user identification data involved in this disclosure is data that has been authorized by the user or fully authorized by all parties.
[0057] In one embodiment, as Figure 1 shown, a password generation method is provided. In this embodiment, this method is exemplified by being applied to a terminal. It can be understood that this method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0058] Step S110, obtain multiple pieces of user identification data.
[0059] Among them, the user identification data represents the unique information of the user. For example, the user identification data can be the user's account, mobile phone number, ID number, etc. It can be understood that the user identification data can also be a combination of the unique information of the user. For example, a combination of account + mobile phone number, or a combination of mobile phone number + ID number, etc.
[0060] In specific implementation, after obtaining multiple pieces of user identification data, m pieces of user identification data can be selected from each piece of user identification data to form a user identification data group, which can be denoted as {user identification data 1, user identification data 2,..., user identification data m}.
[0061] Step S120, for each piece of user identification data, select the random numerical values corresponding to each digit of the user identification data from a pre-generated random number queue.
[0062] Among them, the pre-generated random number queue can be a decimal random number sequence.
[0063] Among them, the digit represents the position occupied by each digit in the user identification data. For example, if the user identification data is 150xxxx1234, the total number of digits of this user identification data is 11, and there are 11 digits: 1, 5, 0,..., 1, 2, 3, 4.
[0064] In a specific implementation, for each user identification data, before selecting the random values corresponding to each digit of the user identification data, the total number of digits N of the user identification data can be obtained first. Based on the total number of digits N, a random number of the target length is selected from a pre-generated random number queue, and then, based on the positions of the digits in the total number of digits N, the random values corresponding to each digit are respectively determined from the random numbers of the target length. Among them, the target length is the length determined based on the total number of digits N. For example, the target length can be N 2 , N 3 etc. The position can represent the order of each digit after arranging the user identification data horizontally, that is, the positions are 1, 2, … N
[0065] Among them, the random number queue can be obtained in the following way: generate a binary random number sequence, perform a radix conversion process on the binary random number sequence to obtain a random number sequence of the target radix as the pre-generated random number queue, where the target radix can be decimal
[0066] In practical applications, a random number sequence D0 in the form of a binary stream can be generated by a Quantum Random Number Generator (QRNG), and then the generated binary random number sequence is converted into decimal 0-9 or hexadecimal ABCDEF to form a sequence D1. Then, a modulo-ten conversion process is performed on the sequence D1. Specifically, the conversion rule can be that for the numbers 0-9 in the sequence D1, no conversion is required, and for the characters ABCDEF in the sequence D1, a modulo-ten conversion is performed to obtain a sequence D2, that is, the number is divided by 10 and the remainder is taken. The mapping relationship is shown in Table 1 below
[0067] Table 1 Mapping relationship table after modulo-ten processing of the original data
[0068] Original data 0-9 A B C D E F Modulo-ten result 0-9 0 1 2 3 4 5
[0069] After obtaining the converted sequence D2, the sequence D2 is stored in a preset queue. The queue can adopt a first-in-first-out queue modulo-ten to provide sufficient storage space. After the data is taken out of the queue, the taken-out data is discarded
[0070] Step S130, perform a modulo operation on the user identification data and the random values corresponding to each digit of the user identification data to obtain the user identification processing data corresponding to each user identification data
[0071] In a specific implementation, the modulo operation on the user identification data and the random values corresponding to each digit of the user identification data means performing a modulo operation after adding the values on each digit of the user identification data and the random values corresponding to each digit
[0072] For example, let the value of the digit i in the user identification data be a i , and the random value corresponding to the digit i selected from the pre-generated random number queue be b i . If i = 1, 2... N, then the modulo operation on the user identification data and the random values corresponding to each digit of the user identification data means performing the modulo operation on the value a i on the digit i of the user identification data and the random value b i corresponding to the digit i. That is, calculate the arithmetic sum of a i +b i and then take the remainder when divided by the modulus p, that is, calculate the remainder of (a i +b i ) / p. Similarly, the processed data values of each digit of the user identification data, (a1 + b1) / p, (a2 + b2) / p,... (a N +b N ) / p, can be calculated. The processed data values of each digit form the processed user identification data. Further, the processed user identification data corresponding to each user identification data form a processed user identification data group, denoted as {processed user identification data 1, processed user identification data 2,..., processed user identification data m}.
[0073] Step S140: Encrypt each processed user identification data to obtain a processed user identification data group.
[0074] In a specific implementation, each processed user identification data can be encrypted through an encryption machine and a working key matching the encryption machine to obtain the encrypted user identification data corresponding to each processed user identification data. The encrypted user identification data are combined to form an encrypted user identification data group, denoted as {encrypted user identification data 1, encrypted user identification data 2,..., encrypted user identification data m}.
[0075] Step S150: Generate a password based on each encrypted user identification data in the encrypted user identification data group.
[0076] In a specific implementation, an encryption operation can be performed on each encrypted user identification data in the encrypted user identification data group to obtain an encrypted value. A modulo operation is performed on the characters belonging to a non-target base in the encrypted value to obtain the numbers corresponding to the characters of the non-target base; the numbers corresponding to the characters of the non-target base and the numbers of the target base in the encrypted value are combined to obtain the password.
[0077] In the above password generation method, by obtaining multiple user identification data, and selecting the random number values corresponding to each digit of each user identification data from a pre-generated random number queue, performing a modulo operation on each user identification data and the random number values corresponding to each digit of each user identification data to obtain user identification processed data corresponding to each user identification data, further performing an encryption process on each user identification processed data to obtain a user identification encrypted data group, and finally generating a password based on each user identification encrypted data in the user identification encrypted data group. This method uses the user identification data as the data source of the password data, and associates the user identification data with random numbers, ensuring the security of the obtained user identification processed data, and further ensuring the uniqueness of the user identification encrypted data obtained based on the user identification processed data, so that the password generated based on the user identification encrypted data is highly difficult to be cracked, ensuring the security of the generated password.
[0078] In an exemplary embodiment, the above step S110 of obtaining multiple user identification data can be implemented through the following steps: obtaining multiple initial user identification data; performing a digital conversion process on each initial user identification data to obtain converted user identification data composed of digits in the target base corresponding to the initial user identification data, and using it as the user identification data.
[0079] Among them, the digital conversion process can represent converting data in a non-target base to digits in the target base, where the target base can be decimal.
[0080] In a specific implementation, after obtaining multiple initial user identification data, if the initial user identification data is not a pure decimal number, it is necessary to perform a digital conversion process on the initial user identification data to convert it into a pure decimal number. For example, for the initial user identification data: user account, if the user account is AE3001, where the characters AE are not decimal numbers, so, perform a modulo operation on AE to obtain the decimal number corresponding to AE: 04, so, the obtained converted user account is: 043001. After converting each user identification data into a pure decimal number, combine each converted user identification data into a user identification data group, and the user identification data group can be denoted as {user identification data 1, user identification data 2,... user identification data m}.
[0081] In this embodiment, by performing a digital conversion process on the obtained initial user identification data, and using the obtained converted user identification data composed of digits in the target base as the user identification data, it is convenient to directly perform a modulo operation on the user identification data subsequently.
[0082] In an exemplary embodiment, the above step S120 of selecting the random values corresponding to each digit of the user identification data from a pre-generated random number queue can be implemented through the following steps: obtaining the total number of digits of the user identification data; based on the total number of digits, selecting a random number with a target length from the pre-generated random number queue; and based on the position of each digit, respectively determining the random value corresponding to each digit from the random number with the target length.
[0083] Among them, the total number of digits represents the number of digits in the user identification data. For example, if the user identification data is 5122 and there are 4 digits, then the total number of digits of this user identification data is 4.
[0084] Among them, the target length is determined based on the total number of digits of the user identification data. If the total number of digits is denoted as N, then the target length can be N 2 , N 3 and so on.
[0085] Among them, the position can represent the order of each digit after arranging the user identification data horizontally. For example, for the user identification data 20146, the position of the digit 2 is 1, the position of the digit 0 is 2, the position of the digit 1 is 3, the position of the digit 4 is 4, and the position of the digit 6 is 5.
[0086] In a specific implementation, taking the target length as N 2 as an example, for any user identification data, assuming the total number of digits of this user identification data is N, then based on the total number of digits N, a random number with a length of N 2 can be selected from the pre-generated random number queue. Then, based on the position n of a certain digit in the user identification data, 1 ≤ n ≤ N, from the N 2 random numbers, the random number located at the nth 2 position is extracted as the random value corresponding to the digit with the position n. By analogy, the random values corresponding to each digit of the user identification data are obtained from the random number queue.
[0087] For example, assume the user identification data is 5123 and the total number of digits is 4. Then, a random number with a length of 4 2 = 16 bits can be selected from the pre-generated random number queue. For the digit where the number 5 is located, the position is 1. Then, from the 16-bit random number, the 1st 2 = 1 random number is selected as the random value corresponding to the digit where the number 5 is located. Similarly, for the digit where the number 2 is located, the position is 3. Then, from the 16-bit random number, the 3rd 2 one, that is, the 9th random number, is selected as the random value corresponding to the digit where the number 5 is located.
[0088] In this embodiment, first, based on the total number of digits of the user identification data, a random number with a target length is selected from a pre-generated random number queue, and then, based on the positions of each digit, random values corresponding to each digit are respectively determined from the random number with the target length. Compared with the method of directly selecting random values from the pre-generated random number queue, the security of each obtained random value is further improved.
[0089] In an exemplary embodiment, the above step S130 performs a modulo operation on the user identification data and the random values corresponding to each digit of the user identification data to obtain user identification processing data corresponding to each user identification data, which specifically includes: respectively summing the values on each digit in the user identification data and the random values corresponding to each digit to obtain the arithmetic sum corresponding to each digit; performing a modulo operation on the arithmetic sum corresponding to each digit to obtain the remainder value corresponding to each digit of the user identification data, and based on the remainder values corresponding to each of the digits, forming the user identification processing data corresponding to the user identification data.
[0090] Among them, the modulo operation represents calculating the remainder obtained by dividing the arithmetic sum corresponding to each digit by the modulus, and the modulus in this embodiment can be 10.
[0091] In specific implementation, assume the user identification data is: abcd, and the random values corresponding to each digit of this user identification data are respectively: a'b'c'd', and the modulus is p. Then, respectively summing the values on each digit in the user identification data and the random values corresponding to each digit means respectively calculating the arithmetic sums of a + a', b + b', c + c', d + d'. After obtaining the arithmetic sums of each digit, respectively performing a modulo operation on each arithmetic sum means respectively calculating the remainder of (a + a') divided by the modulus p, the remainder of (b + b') divided by the modulus p, the remainder of (c + c') divided by the modulus p, and the remainder of (d + d') divided by the modulus p. Assume the remainder values corresponding to each digit obtained after the modulo operation are respectively: a″, b″, c″, d″. Then, the user identification processing data corresponding to the user identification data abcd obtained based on the remainder values corresponding to each digit is: a″b″c″d″.
[0092] In this embodiment, by performing a modulo-ten addition operation on the values on each digit in the user identification data and the random values corresponding to each digit, user identification processing data corresponding to each user identification data is obtained. This processing method can improve the randomness and security of the obtained user identification processing data, thereby improving the security of the password obtained based on the user identification processing data.
[0093] In an exemplary embodiment, the above step S140 specifically includes: encrypting the processed data of each user identifier through an encryption machine and a working key matching the encryption machine to obtain a user identifier encrypted data group.
[0094] Among them, the encryption machine is a host encryption device, and encryption is mainly achieved through the communication between the encryption machine and the host.
[0095] In specific implementation, for the processed data of each user identifier, the processed data of the user identifier can be encrypted through a hardware encryption machine and a working key (for example, IMK1) matching the hardware encryption machine to obtain the encrypted data of the user identifier corresponding to each processed data of the user identifier. The encrypted data of each user identifier is combined into a user identifier encrypted data group, denoted as {encrypted data of user identifier 1, encrypted data of user identifier 2,..., encrypted data of user identifier m}.
[0096] In this embodiment, encrypting the processed data of the user identifier through the hardware encryption machine can prevent brute force cracking, password guessing, data recovery, etc.
[0097] In an exemplary embodiment, the above step S150 specifically includes: performing an encryption operation on each encrypted data of the user identifier in the user identifier encrypted data group to obtain an encrypted value; performing a base conversion process on the characters in the encrypted value that are not in the target base to obtain the numbers corresponding to the characters in the non-target base; combining the numbers corresponding to the characters in the non-target base and the numbers in the target base in the encrypted value to obtain a password.
[0098] Among them, the encryption operation method can adopt the national secret MAC operation.
[0099] Among them, the non-target base can be characters in other bases except the target base. If the target base is decimal, the non-target base can be hexadecimal.
[0100] In specific implementation, taking the encryption method of adopting the national secret MAC operation as an example, performing an encryption operation on each encrypted data of the user identifier in the user identifier encrypted data group can be specifically achieved by encrypting each encrypted data of the user identifier through the MAC key, expressed as: The 32-bit MAC value obtained by encryption can be used as the encrypted value. After obtaining the MAC value, all non-target base characters in the MAC value are extracted from left to right. For example, hexadecimal characters (A-F) are extracted, and all target base characters, such as decimal characters (0-9), are extracted. And perform base conversion processing on each non-target base character. For example, convert hexadecimal characters to decimal numbers. Arrange the decimal numbers obtained after converting the non-target base hexadecimal characters and the decimal numbers extracted from the MAC value from left to right. Use the first s digits in the obtained arrangement result as the generated password. Among them, the numbers after converting non-target base characters are located to the left of the target base numbers extracted from the MAC value.
[0101] In this embodiment, after obtaining the encrypted value obtained by encrypting data based on each user identifier, further processing and combination are performed on the encrypted value to generate a password. Through this calculation method, the security of the generated password can be greatly improved.
[0102] In an exemplary embodiment, after generating the password in step S150, it further includes: obtaining a storage master key with a preset number of digits; the preset number of digits is the same as the number of digits of the encrypted value; selecting a target random number with a preset number of digits from the random number queue; using the storage master key to perform an encryption calculation on the data assembled from the user identifier data group, the user identifier encrypted data group, the target random number, and the password to obtain the ciphertext of the password as the storage key.
[0103] In a specific implementation, after generating the password, the password also needs to be stored. For security, the password is not directly saved in plaintext but in ciphertext. Specifically, a storage master key with a preset number of digits can be set first, and a target random number with the preset number of digits is selected from the random number queue. Then, the user identifier data group, the user identifier encrypted data group, the target random number, and the password are assembled to obtain the assembled data:
[0104]
[0105] Then use the storage master key to perform an encryption calculation on the assembled data to obtain the ciphertext. The calculation formula of the ciphertext can be expressed as:
[0106]
[0107] The calculation process of the ciphertext includes: (1) Assembling data. If the data itself already meets an integer multiple of 32-bit grouping, no padding is required. If not, the least amount of 'X'00'' is padded until it reaches an integer multiple of 32-bit grouping. (2) After padding, the data is grouped by 32 bits. (3) Use 32-bit 0 to perform exclusive OR with the first group of data to obtain the first group of encrypted data, and then use the 32 bytes storing the key to perform CBC mode encryption on the data groups, that is, exclusive OR the encryption result of the previous group with the next group of data and then encrypt using the key, and keep processing until the last group (the last group is exclusive ORed with the encryption result of the previous group but not encrypted). Take the exclusive OR data of the last group as the ciphertext of the password.
[0108] After obtaining the ciphertext, the user identification data group, the user identification encrypted data group, the target random number, and the ciphertext are associated and saved.
[0109] In this embodiment, by associating the user identification data group, the user identification encrypted data group with the random number, and adding the generated password, the ciphertext is calculated, so that the obtained ciphertext also has high security, thereby improving the security of password storage.
[0110] In another exemplary embodiment, as Figure 2 shown, there is also provided a password generation method. In this embodiment, the method includes the following steps:
[0111] Step S201, obtain multiple user identification data;
[0112] Step S202, for any user identification data, obtain the total number of digits of the user identification data;
[0113] Step S203, based on the total number of digits, select a random number with a target length from a pre-generated random number queue;
[0114] Step S204, based on the positions of the digits of the user identification data, respectively determine the random number values corresponding to each digit from the random number with the target length;
[0115] Step S205, respectively sum the values on each digit of the user identification data and the random number values corresponding to each digit to obtain the arithmetic sum corresponding to each digit;
[0116] Step S206, perform a modulo operation on the arithmetic sum corresponding to each digit to obtain the remainder value corresponding to each digit of the user identification data;
[0117] Step S207, based on the remainder values corresponding to each digit, form the user identification processing data corresponding to the user identification data;
[0118] Step S208, perform encryption processing on each user identification processing data to obtain the user identification encrypted data group;
[0119] Step S209: Perform an encryption operation on each user identification encrypted data in the user identification encrypted data group to obtain an encrypted value.
[0120] Step S210: Perform a radix conversion process on the characters in the encrypted value that do not belong to the target radix to obtain the numbers corresponding to the characters that do not belong to the target radix.
[0121] Step S211: Combine the numbers corresponding to the characters that do not belong to the target radix and the numbers in the target radix in the encrypted value to obtain the password.
[0122] The password generation method provided in this embodiment uses the user identification data as the data source of the password data, and associates the user identification data with a random number, which ensures the security of the obtained user identification processed data, further ensures the uniqueness of the user identification encrypted data obtained based on the user identification processed data, so that the password generated based on the user identification encrypted data is highly difficult to be cracked, ensuring the security of the generated password.
[0123] In one embodiment, to facilitate those skilled in the art to understand the embodiments of the present application, specific examples in conjunction with the accompanying drawings will be described below. Refer to Figure 3 , which shows a schematic structural diagram of a quantum-based password generation and storage system, including: a random number sequence generation module 301, a password generation module 302, and a password storage module 303. Among them, the random number generation module 301 includes: a random binary sequence unit 301a, a sequence conversion unit 301b, and a sequence queue unit 301c; the password generation module 302 includes: a user identification data group collection unit 302a, a user identification processing unit 302b, a user identification encrypted data generation unit 302c, and a password generation unit 302d; the password storage module 303 includes: a storage key generation unit 303a, a ciphertext calculation unit 303b, and a user password information storage unit 303c. The function descriptions of each unit under each module are as follows:
[0124] Random number sequence generation module 301:
[0125] The random binary sequence unit 301a is used to generate a binary random number sequence. Specifically, through a quantum random number generator (QRNG), a random number sequence is generated and formed into a sequence D0 in the form of a binary stream.
[0126] The sequence conversion unit 301b is used to convert the binary sequence into a pure digital sequence. Specifically, it is used to convert the sequence D0 generated by the random binary sequence unit 301a. Every 4 bits, the 4-bit binary number is converted into a hexadecimal number from 0-9 or ABCDEF to form a sequence D1; then the sequence D1 is modulo-ten processed to form a sequence D2.
[0127] The sequence queue unit 301c is used to provide a storage space with sufficient capacity to store the sequence D2.
[0128] Password generation module 302:
[0129] The user identification data group acquisition unit 302a is used to acquire the user identification data D3, perform modulo-ten processing on the user identification data D3 to convert it into a pure decimal number D4, and select m user identification data to form a user identification data group {user identification data 1, user identification data 2,..., user identification data m}.
[0130] The user identification processing unit 302b is used to, for each user identification data, select N 2 bit data D5 from the sequence queue unit 301c based on the total number of digits N, and extract the n 2 th bit data Y n from the data D5 based on the position n of each digit, n concatenate the data Y n into D6, that is, D6 = {Y0...Y n}, and D6 is also N bits. Perform modulo-ten addition processing on the digits of D3 and D6, and form the processed values into user identification processed data, and further form a user identification processed data group {user identification processed data 1, user identification processed data 2,..., user identification processed data m}.
[0131] The user identification encrypted data generation unit 302c encrypts each user identification processed data through a hardware encryption machine and a working key (for example, IMK1) matching the hardware encryption machine to obtain the user identification encrypted data corresponding to each user identification processed data, and forms the user identification encrypted data into a user identification encrypted data group {user identification encrypted data 1, user identification encrypted data 2,..., user identification encrypted data m}.
[0132] The password generation unit 302d is used to obtain a password through the national secret MAC operation on the user identification encrypted data 1, user identification encrypted data 2, user identification encrypted data 3, user identification encrypted data m. Taking 9 as an example for the password length, the password generation process includes:
[0133] (1)
[0134] (2) Extract all the hexadecimal characters (A - F) in the MAC value from left to right, and perform radix conversion processing on each hexadecimal character, that is, convert the hexadecimal character into a decimal number;
[0135] (3)Extract all the decimal digits (0 - 9) in the MAC value from left to right;
[0136] (4)Arrange the data obtained in steps (2) and (3) from left to right, with the result of step 3 placed after the result of step 2;
[0137] (5)From the result obtained in step (4), take the first 9 digits as the password.
[0138] Password storage module 303:
[0139] Storage key generation unit 303a, used to set a 32 - bit storage master key, obtain a 32 - bit random number from the random number sequence generation module 001, encrypt the random number using the storage master key to obtain a 32 - bit ciphertext as the storage key.
[0140] Ciphertext calculation unit 303b, used to assemble the user identification data group, user identification encrypted data group, target random number, and password to obtain assembled data, and encrypt - calculate the assembled data through the storage key to obtain the ciphertext of the password.
[0141] User password information storage unit 303c, used to save the user identification data group, user identification encrypted data group, target random number, and ciphertext after association.
[0142] In the method for quantum - based password generation and storage provided by this application, random numbers are generated by using a quantum random number generator, and are randomly associated and converted with service data to ensure the security of the random numbers. In terms of storage, data conversion is performed through the user identification and random numbers, and the generated password is superimposed, and then encrypted using a hardware encryption machine for storage. In this way, the stored ciphertext is not only strongly associated with the user identification, but also the user identification and the generated password are used for calculation, improving the security of the ciphertext.
[0143] It should be understood that although Figures 1-3 the steps in the flowchart are shown in sequence according to the arrows, these steps do not necessarily execute in the order indicated by the arrows. Unless there is a clear description in this article, there is no strict order limit for the execution of these steps, and these steps can be executed in other orders. Moreover, Figures 1-3 at least a part of the steps in
[0144] In one embodiment, as Figure 4As shown in the figure, a password generation device is provided, including: an acquisition module 401, a selection module 402, a processing module 403, an encryption module 404, and a generation module 405, where:
[0145] The acquisition module 401 is used to acquire multiple user identification data;
[0146] The selection module 402 is used to select, for each user identification data, the random number values corresponding to the respective digits of the user identification data from a pre-generated random number queue;
[0147] The processing module 403 is used to perform modulo operation processing on the user identification data and the random number values corresponding to the respective digits of the user identification data to obtain user identification processing data corresponding to the respective user identification data;
[0148] The encryption module 404 is used to perform encryption processing on each user identification processing data to obtain a user identification encrypted data group;
[0149] The generation module 405 is used to generate a password according to the respective user identification encrypted data in the user identification encrypted data group.
[0150] In one embodiment, the above acquisition module 401 is specifically used to acquire multiple initial user identification data; perform digital conversion processing on each initial user identification data to obtain converted user identification data composed of digits in a target number system corresponding to the initial user identification data, and use the converted user identification data as the user identification data.
[0151] In one embodiment, the above selection module 402 is specifically used to obtain the total number of digits of the user identification data; based on the total number of digits, select a random number with a target length from the pre-generated random number queue; based on the positions of the respective digits, respectively determine the random number values corresponding to the respective digits from the random number with the target length.
[0152] In one embodiment, the above processing module 403 is specifically used to respectively sum the values on the respective digits in the user identification data and the random number values corresponding to the respective digits to obtain the arithmetic sum corresponding to each digit; perform modulo operation on the arithmetic sum corresponding to each digit to obtain the remainder value corresponding to each digit of the user identification data; based on the remainder values corresponding to the respective digits, form the user identification processing data corresponding to the user identification data.
[0153] In one embodiment, the above encryption module 404 is specifically used to encrypt each user identification processing data through an encryption machine and a working key matching the encryption machine to obtain a user identification encrypted data group.
[0154] In one embodiment, the above-mentioned generating module 405 is specifically configured to perform an encryption operation on each user identification encrypted data in the user identification encrypted data group to obtain an encrypted value; perform a radix conversion process on the characters belonging to a non-target radix in the encrypted value to obtain the numbers corresponding to the characters of the non-target radix; combine the numbers corresponding to the characters of the non-target radix and the numbers of the target radix in the encrypted value to obtain a password.
[0155] In one embodiment, the above-mentioned device further includes a ciphertext generating module, configured to obtain a stored master key with a preset number of digits; the preset number of digits is the same as the number of digits of the encrypted value; select a target random number with a preset number of digits from the random number queue; perform an encryption calculation on the data assembled by the user identification data group, the user identification encrypted data group, the target random number, and the password through the stored master key to obtain the ciphertext of the password, which is used as the stored key.
[0156] It should be noted that the password generation device of the present application corresponds one-to-one with the password generation method of the present application. The technical features and beneficial effects described in the embodiments of the above password generation method are all applicable to the embodiments of the password generation device. For specific content, reference can be made to the description in the method embodiments of the present application, which will not be repeated here. In addition, each module in the above password generation device can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above-mentioned modules.
[0157] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 5 shown. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be achieved through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a password generation method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad set on the shell of the computer device, or an external keyboard, a touchpad, or a mouse, etc.
[0158] Those skilled in the art can understand,Figure 5 The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0159] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0160] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0161] Those of ordinary skill in the art can understand that all or part of the processes of implementing the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0162] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0163] The above embodiments only represent several implementation manners of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of the patent of this application should be subject to the appended claims.
Claims
1. A password generation method, characterized in that, The method includes: Obtaining multiple user identification data; For each of the user identification data, selecting the random values corresponding to each digit of the user identification data from a pre-generated random number queue; Wherein, the step of selecting the random values corresponding to each digit of the user identification data from the pre-generated random number queue includes: Obtaining the total number of digits of the user identification data; Based on the total number of digits, selecting a random number with a target length from the pre-generated random number queue; Based on the positions of each digit, respectively determining the random values corresponding to each digit from the random number with the target length; Wherein, the random number queue is obtained by the following method: generating a binary random number sequence, performing a radix conversion process on the binary random number sequence to obtain a random number sequence of a target radix, and using it as the pre-generated random number queue; Performing a modulo operation on the user identification data and the random values corresponding to each digit of the user identification data to obtain user identification processing data corresponding to each of the user identification data; Performing an encryption process on each of the user identification processing data to obtain a user identification encrypted data group; Generating a password according to each user identification encrypted data in the user identification encrypted data group.
2. The method according to claim 1, characterized in that, The step of obtaining multiple user identification data includes: Obtaining multiple initial user identification data; Performing a digital conversion process on each of the initial user identification data to obtain converted user identification data composed of digits of a target radix corresponding to the initial user identification data, and using it as the user identification data.
3. The method according to claim 1, characterized in that, The step of performing a modulo operation on the user identification data and the random values corresponding to each digit of the user identification data to obtain user identification processing data corresponding to each of the user identification data includes: Respectively summing the values on each digit in the user identification data and the random values corresponding to each digit to obtain the arithmetic sum corresponding to each digit; Performing a modulo operation on the arithmetic sum corresponding to each digit to obtain the remainder value corresponding to each digit of the user identification data; Based on the remainder values corresponding to each digit, forming the user identification processing data corresponding to the user identification data.
4. The method according to claim 1, characterized in that, The step of performing an encryption process on each of the user identification processing data to obtain a user identification encrypted data group includes: Using an encryption machine and a working key matching the encryption machine to encrypt each of the user identification processing data to obtain the user identification encrypted data group.
5. The method according to claim 1, characterized in that, The step of generating a password according to each user identification encrypted data in the user identification encrypted data group includes: Performing an encryption operation on each user identification encrypted data in the user identification encrypted data group to obtain an encrypted value; Performing a radix conversion process on the characters in the encrypted value that belong to a non-target radix to obtain the numbers corresponding to the characters in the non-target radix; Combining the numbers corresponding to the characters in the non-target radix and the numbers in the target radix in the encrypted value to obtain a password.
6. The method according to claim 5, characterized in that, After generating a password according to each user identification encrypted data in the user identification encrypted data group, it further includes: Obtain a stored master key of a preset number of digits; the preset number of digits is the same as the number of digits of the encrypted value; Select a target random number of the preset number of digits from the random number queue; Perform an encryption calculation on the data assembled by the user identification data group, the user identification encrypted data group, the target random number, and the password through the stored master key to obtain the ciphertext of the password as the stored key; wherein, the user identification data group consists of multiple user identification data.
7. A password generation device, characterized in that, The device includes: An acquisition module, configured to acquire multiple user identification data; A selection module, configured to, for each of the user identification data, select random number values corresponding to each digit of the user identification data from a pre-generated random number queue; A processing module, configured to perform a modulo operation on the user identification data and the random number values corresponding to each digit of the user identification data to obtain user identification processed data corresponding to each of the user identification data; An encryption module, configured to encrypt each of the user identification processed data to obtain a user identification encrypted data group; A generation module, configured to generate a password according to each user identification encrypted data in the user identification encrypted data group; Among them, the selection module is specifically configured to obtain the total number of digits of the user identification data; based on the total number of digits, select a random number of a target length from the pre-generated random number queue; based on the positions of each digit, respectively determine the random number values corresponding to each digit from the random number of the target length; Among them, the random number queue is obtained by the following method: generate a binary random number sequence, perform a radix conversion process on the binary random number sequence to obtain a random number sequence of a target radix as the pre-generated random number queue.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium, having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Anti-counterfeiting intelligent recognition method for water purifier consumable part
CN106056390A
Security authentication method and device, electronic equipment and storage medium
CN111737679A