Method for generating a default password, method for performing user authentication, apparatus and device
By combining timestamps and encryption algorithms when generating default passwords in electronic devices, the problem of default passwords being easily cracked and leaked is solved, thereby improving the security of electronic devices and the complexity of user authentication.
Patent Information
- Application Number
- CN202511145167.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-08-15
AI Technical Summary
The default passwords of existing electronic devices are easily cracked and leaked, resulting in low security. Furthermore, the fact that the default passwords of the same product from the same manufacturer are consistent poses a significant security risk.
When generating a default password, a combination of an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field is used. The default password is dynamically generated based on a preset default plaintext and the current date, and a double encryption operation is performed to update the encryption timestamp and ciphertext fields.
It enables dynamic updates of default passwords, improving password complexity and security, reducing security risks associated with the same product from the same manufacturer, and ensuring the efficiency and security of user verification.
Smart Images

Figure CN120750634B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of user authentication and default password technology, and more specifically, to a method for generating a default password, a method for performing user authentication, an apparatus, and a device. Background Technology
[0002] In the security mechanisms of electronic devices, the setting of default passwords is a crucial factor affecting device security. Device manufacturers typically pre-set default passwords for electronic devices so that users can quickly access them upon first use.
[0003] However, the default passwords used for electronic devices have problems such as simple password structure, easy to crack and leak, and low security, which can pose potential security risks to electronic devices. Summary of the Invention
[0004] In view of the above problems, this application provides a method for generating a default password, a method, apparatus and device for performing user authentication, and also provides a storage medium and program product.
[0005] According to one aspect of this application, a method for generating a default password is provided, comprising: determining a preset default plaintext based on default password information, the default password information including an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field; obtaining a default password based on the preset default plaintext and the current date, the default password being used for user authentication; performing a first encryption on the default password using an encryption algorithm indicated by the encryption algorithm identifier field; performing a second encryption on the first-encrypted default password based on the current timestamp to obtain a target ciphertext; and updating the encryption timestamp field and the ciphertext field based on the current timestamp and the target ciphertext, respectively.
[0006] Another aspect of this application provides a method for user authentication, comprising: in response to receiving an authentication password from a user, obtaining default password information, the default password information including an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field; performing a third decryption on the ciphertext field using the timestamp indicated by the encryption timestamp field; performing a fourth decryption on the third decrypted ciphertext field using the encryption algorithm indicated by the encryption algorithm identifier field to obtain a default password for authentication; and performing a consistency verification on the authentication password based on the default password for authentication to obtain an authentication result.
[0007] Another aspect of this application provides an apparatus for generating a default password, comprising: a first determining module for determining a preset default plaintext based on default password information, the default password information including an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field; a second determining module for obtaining a default password based on the preset default plaintext and the current date, the default password being used for user verification; a first encryption module for performing a first encryption on the default password using an encryption algorithm indicated by the encryption algorithm identifier field; a second encryption module for performing a second encryption on the first-encrypted default password based on the current timestamp to obtain a target ciphertext; and an updating module for updating the encryption timestamp field and the ciphertext field based on the current timestamp and the target ciphertext, respectively.
[0008] Another aspect of this application provides an apparatus for user authentication, comprising: a second acquisition module for acquiring default password information in response to receiving an authentication password from a user, the default password information including an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field; a third decryption module for performing a third decryption on the ciphertext field using the timestamp indicated by the encryption timestamp field; a fourth decryption module for performing a fourth decryption on the third decrypted ciphertext field using the encryption algorithm indicated by the encryption algorithm identifier field to obtain a default password for authentication; and an authentication module for performing consistency verification on the authentication password based on the default password for authentication to obtain an authentication result.
[0009] Another aspect of this application provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.
[0010] Another aspect of this application provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.
[0011] Another aspect of this application provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method.
[0012] According to embodiments of this application, a default password for a target electronic device can be obtained based on a preset default plaintext and the current date. Each time the target electronic device is powered on, a default password is generated in real-time based on the date it was powered on, ensuring that the default password is not fixed but dynamically updated with the current date. The generated default password includes a user-customizable CODE portion and a date portion that fluctuates based on the date, changing the high-risk approach of consistent default passwords for the same model of electronic device from the same manufacturer, and significantly improving the security of the default password and the electronic device. Furthermore, by performing a double dynamic encryption operation on the newly generated default password (plaintext) based on an encryption algorithm and the current timestamp to obtain the target ciphertext, the security of the default password and the electronic device can be further improved. Therefore, even if the user does not update the default password, the default password used for user verification still possesses high complexity and security, without affecting user convenience. Attached Figure Description
[0013] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments of this application with reference to the accompanying drawings.
[0014] Figure 1 The illustration shows a method for generating a default password, a method for performing user authentication, and application scenarios of corresponding apparatus, devices, media, and program products according to embodiments of this application.
[0015] Figure 2 A flowchart of a method for generating a default password according to an embodiment of this application is shown.
[0016] Figure 3 A schematic diagram of data flow related to a radio wave receiving module according to an embodiment of this application is shown.
[0017] Figure 4 A flowchart of a method for performing user authentication according to an embodiment of this application is shown.
[0018] Figure 5 A schematic diagram illustrating the process of generating a default password and performing user authentication according to an embodiment of this application is shown.
[0019] Figure 6 A structural block diagram of an apparatus for generating a default password according to an embodiment of this application is shown.
[0020] Figure 7 A structural block diagram of a user authentication apparatus according to an embodiment of this application is shown.
[0021] Figure 8A block diagram of an electronic device suitable for implementing a method for generating a default password and / or performing a method for user authentication, according to embodiments of this application, is shown. Detailed Implementation
[0022] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.
[0023] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0024] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0025] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0026] In the technical solution of this application, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0027] Cryptography is the study of how to securely store and transmit information, providing technical means for encryption and decryption. As part of information storage, the design and use of default passwords must adhere to cryptographic principles. For example, default passwords should have sufficient complexity to prevent them from being cracked by simple brute-force or dictionary attacks. Furthermore, the storage and transmission of default passwords must be secure to prevent them from being stolen or tampered with.
[0028] In the security mechanisms of electronic devices, the setting of a default password is a crucial factor affecting device security. Device manufacturers typically pre-set default passwords for their electronic devices so that users can quickly access them upon first use. This default password must be complex enough and difficult to guess to ensure device security. Furthermore, device manufacturers need to consider how to provide users with guidance on changing the default password and encourage them to change it immediately upon first use.
[0029] However, default passwords used for electronic devices often pose the following security risks: 1. Weak passwords: Some devices, software, or services may use overly simple default passwords that are easily cracked; 2. Password leakage: If the default password is leaked, attackers can use it to access the user's account and data; 3. Users neglecting to change: Although device manufacturers usually provide guidelines for changing default passwords, some users may ignore this step and continue to use the default weak password.
[0030] In related technologies, a device's default password can be generated, for example, as follows: The system (e.g., the CPU (Central Processing Unit)) uses a hash function to convert the default password (plaintext) into a fixed-length byte sequence, obtaining a default password hash value. This default password hash value can be stored, for example, in the ` / etc / shadow` file. When a user attempts to log in, the system prompts the user for a username and password (which should be the default password if the user hasn't changed it). The username and password entered by the user are captured by the system and used in subsequent verification processes. The system hashes the entered password using the same hash function as when the user set the password. This hashing process produces a hash value corresponding to the user's password. The system compares the hash value of the entered password with the corresponding user's password hash value stored in the ` / etc / shadow` file. If they match, the user logs in successfully; otherwise, the login fails. For the same product, the default password is consistent and saved in a configuration file. This configuration file is loaded when the system starts, ensuring the default password is loaded by the system. When the user's entered password matches the default password, the user successfully logs in.
[0031] Among the aforementioned technologies, the method of loading default passwords based on configuration files may have the following problems: 1. The default password is written to and saved in the configuration file, which is easily accessible to attackers, who can then obtain the configuration file and thus understand the default password configuration and activation mechanism; 2. The default passwords of the same product from the same manufacturer are the same, resulting in poor confidentiality of the default passwords. Moreover, once an attacker cracks the default password of a certain product, it will affect a large number of the same products, creating a huge security risk.
[0032] In view of this, embodiments of this application provide a method for generating a default password, a method for user authentication, and corresponding apparatus, devices, media, and program products. The method for generating a default password according to embodiments of this application includes: determining a preset default plaintext based on default password information, the default password information including an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field; obtaining a default password based on the preset default plaintext and the current date, the default password being used for user authentication; performing a first encryption on the default password using an encryption algorithm indicated by the encryption algorithm identifier field; performing a second encryption on the first-encrypted default password based on the current timestamp to obtain a target ciphertext; and updating the encryption timestamp field and the ciphertext field based on the current timestamp and the target ciphertext, respectively.
[0033] Figure 1 The illustration shows a method for generating a default password, a method for performing user authentication, and application scenarios of corresponding apparatus, devices, media, and program products according to embodiments of this application.
[0034] like Figure 1 As shown, application scenario 100 according to this embodiment may include a target electronic device 101 and a processor 102 for the target electronic device 101. Exemplarily, the target electronic device 101 may include a processor 102, which may be, for example, a CPU.
[0035] The target electronic device 101 can be a variety of electronic devices with a display screen and support for user input, including but not limited to NAS (Network Attached Storage) devices, smartphones, tablets, laptops, and desktop computers.
[0036] It should be noted that the method for generating a default password and the method for performing user authentication provided in the embodiments of this application can generally be executed by the target electronic device 101. Accordingly, the device for generating a default password and the device for performing user authentication provided in the embodiments of this application can generally be located in the target electronic device 101, or can be the target electronic device 101 itself.
[0037] Figure 2 A flowchart of a method for generating a default password according to an embodiment of this application is shown.
[0038] like Figure 2 As shown, the method 200 includes operations S210 to S250.
[0039] In operation S210, a preset default plaintext is determined based on the default password information, which includes an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field.
[0040] In operation S220, a default password is obtained based on the preset default plaintext and the current date. The default password is used for user authentication.
[0041] In operation S230, the default password is first encrypted using the encryption algorithm indicated by the encryption algorithm identification field.
[0042] In operation S240, based on the current timestamp, the default password that has been encrypted in the first encryption is encrypted in the second encryption to obtain the target ciphertext.
[0043] In operation S250, based on the current timestamp and the target ciphertext, the encryption timestamp field and the ciphertext field are updated respectively.
[0044] According to one embodiment of this application, a default password for a target electronic device can be obtained based on a preset default plaintext and the current date. Exemplarily, the default password for the target electronic device can be designed with a structure of a fixed CODE portion and a floating DATE portion. The CODE portion (as the name suggests, the password) corresponds to the aforementioned preset default plaintext, and the DATE portion (as the name suggests, the date) corresponds to the aforementioned current date. It should be noted that the CODE portion can be set according to the application scenario or the needs of the customizer (for example, the CODE portion can be set to a fixed password), and this is not limited here. The DATE portion will float according to the date the target electronic device is powered on.
[0045] According to one embodiment of this application, the default password information may include an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field, and the CODE part of the default password can be determined based on the default password information.
[0046] In one embodiment, the CODE portion can be fixed as "password". Assuming the target electronic device's power-on date is August 1, 2025, the DATE portion would be 20250801. Based on the CODE and DATE portions, the default password can be determined as "password20250801" (plaintext). In another embodiment, the CODE portion can be fixed as "password". Assuming the target electronic device's power-on date is August 6, 2025, the DATE portion would be 20250806. Based on the CODE and DATE portions, the default password can be determined as "password20250806" (plaintext).
[0047] Understandably, the default password includes a user-customizable CODE portion (i.e., the default plaintext) and a date portion that can fluctuate based on the date (i.e., the current date). This allows the default password of the target electronic device to not only support personalization but also to be updated in real time with the date of power-on. This changes the high-risk approach of having the same default password for the same electronic device from the same manufacturer, and can significantly improve the security of the default password and the electronic device.
[0048] According to one embodiment of this application, after the target electronic device is powered on, a default password (such as password20250806) is generated in real time based on the date it was powered on. This default password, password20250806, will be used for user authentication. For example, the user manual of the target electronic device can inform the user that the CODE part of the default password is fixed as "password," and agree with the user that each time they log in using the default password, they need to enter "password" plus the date the device was powered on for password verification. In this way, even if the user does not change the default password, the default password of the target electronic device still has high complexity and security, while not affecting the user's convenience. It should be noted that the aforementioned default password, password20250806, is in plaintext form. However, for security reasons, the default password cannot be stored directly in plaintext. Therefore, it is necessary to encrypt the default password, password20250806, to store the corresponding ciphertext.
[0049] In one embodiment, a default password (such as password20250806) can be first encrypted using the encryption algorithm indicated by the encryption algorithm identifier field to obtain first ciphertext. The first encrypted default password (i.e., the first ciphertext) can then be second encrypted based on the current timestamp to obtain the target ciphertext. The current timestamp can be determined based on the current power-on / boot-up time of the target electronic device.
[0050] In one embodiment, the encryption algorithm identifier field indicates the encryption algorithm, which can be used to perform a first encryption on the newly generated default password (plaintext) to obtain the first ciphertext. Those skilled in the art can select a suitable encryption algorithm (preferably a symmetric encryption algorithm) according to actual needs or application scenarios, such as including but not limited to AES (Advanced Encryption Standard), DES (Data Encryption Standard), 3DES (Triple Data Encryption Standard), RC4 (an abbreviation of Rivest Cipher 4, a stream encryption algorithm), etc., without specific limitations here.
[0051] A timestamp is a data format used in computer systems to record the specific time an event occurred. It typically represents the number of seconds or milliseconds counted from a fixed point in time (called the epoch time). Timestamp encryption algorithms are symmetric encryption algorithms that encrypt data along with a timestamp, ensuring that only the person holding the key can decrypt and verify the integrity and authenticity of the data. In one embodiment, a timestamp encryption algorithm can be used to encrypt the first ciphertext based on the current timestamp to obtain the target ciphertext.
[0052] Understandably, the current timestamp also fluctuates with the boot time; in other words, the aforementioned second encryption is dynamic. By performing a double dynamic encryption operation on the newly generated default password based on the encryption algorithm and the current timestamp to obtain the target ciphertext, the security of the default password and electronic devices is further improved.
[0053] In this embodiment, the encryption timestamp field of the default password information can be updated based on the current timestamp. The ciphertext field of the default password information can also be updated based on the target ciphertext. For example, the current timestamp can be written to the encryption timestamp field, and the target ciphertext can be written to the ciphertext field.
[0054] According to embodiments of this application, a default password for a target electronic device can be obtained based on a preset default plaintext and the current date. Each time the target electronic device is powered on, a default password is generated in real-time based on the date it was powered on, ensuring that the default password is not fixed but dynamically updated with the current date. The generated default password includes a user-customizable CODE portion and a date portion that fluctuates based on the date, changing the high-risk approach of consistent default passwords for the same model of electronic device from the same manufacturer, and significantly improving the security of the default password and the electronic device. Furthermore, by performing a double dynamic encryption operation on the newly generated default password (plaintext) based on an encryption algorithm and the current timestamp to obtain the target ciphertext, the security of the default password and the electronic device can be further improved. Therefore, even if the user does not update the default password, the default password used for user verification still possesses high complexity and security, without affecting user convenience.
[0055] According to an embodiment of this application, the default password information is part of the device configuration information, which is stored in a preset non-volatile memory of the target electronic device.
[0056] According to one embodiment of this application, the device configuration information can be VPD (Vital Product Data) information. VPD can be used to record information such as the part number and serial number of the target electronic device, and can uniquely identify the software and hardware of the system, and can also store system microinstructions.
[0057] In one embodiment, the VPD may include a read-only key portion and a read-write key portion. The read-only key portion may record information such as the device part number and device serial number, while the read-write key portion may record information such as the default password and other key device information (such as the performance parameters and error codes of the target electronic device).
[0058] According to one embodiment of this application, the preset non-volatile memory can be selected as, for example, an EEPROM (Electrically Erasable Programmable Read Only Memory). An EEPROM is a type of memory that retains data even when power is lost, making it suitable for storing default password information.
[0059] According to embodiments of this application, VPD information can be used to record default password information, and a default password for user authentication can be generated based on the default password information. Compared to the method of loading based on configuration files, the method for generating default passwords provided in embodiments of this application can better prevent attacks by attackers.
[0060] According to embodiments of this application, determining a preset default plaintext based on default password information may include: obtaining default password information in response to a power-on command for starting a target electronic device; performing a first decryption on a ciphertext field using a historical timestamp indicated by an encryption timestamp field; and performing a second decryption on the first decrypted ciphertext field using an encryption algorithm indicated by an encryption algorithm identifier field to obtain the preset default plaintext.
[0061] According to one embodiment of this application, each time the target electronic device is powered on, it generates a new default password based on the current date and stores the target ciphertext corresponding to the newly generated default password in the ciphertext field. This results in the plaintext of the CODE portion being fixed, but the ciphertext field storing ciphertext representing the complete information of the [fixed CODE portion + floating DATE portion] (the target ciphertext generated at the last startup). Therefore, before generating a new default password after each startup, the target ciphertext generated at the last startup stored in the ciphertext field can be decrypted to restore the default password (plaintext) generated at the last startup, and then the plaintext of the CODE portion can be extracted from the default password (plaintext) generated at the last startup.
[0062] In one embodiment, the historical timestamp can be understood as the "current timestamp" corresponding to the last startup of the target electronic device. In response to the power-on command, the target electronic device powers on and obtains the default password information. The default password information includes an encryption algorithm identifier field, an encryption timestamp field, and a ciphertext field. The encryption timestamp field stores the "current timestamp" from the last startup, i.e., the historical timestamp. The ciphertext field stores the "target ciphertext" from the last startup (hereinafter referred to as the historical target ciphertext).
[0063] The historical target ciphertext can be decrypted for the first time using the historical timestamp indicated by the encryption timestamp field. The encryption algorithm indicated by the encryption algorithm identifier field can be used to decrypt the first decrypted historical target ciphertext for the second time, obtaining the default password plaintext from the last startup (hereinafter referred to as the historical default password). The CODE portion plaintext can be extracted from the historical default password to obtain the preset default plaintext. The aforementioned use of the historical timestamp for the first decryption corresponds to the explanation above regarding the use of the current timestamp for the second encryption; the aforementioned use of the encryption algorithm for the second decryption corresponds to the explanation above regarding the use of the encryption algorithm for the first encryption, and will not be repeated here.
[0064] Taking a fixed CODE setting as "password", with the current date being 20250806 and the last startup date being 20250801 as an example, the process of dynamically generating a new default password after the target electronic device is powered on can be as follows:
[0065] 1. Double decryption: Obtain the target ciphertext stored at the last startup (i.e., the historical target ciphertext) stored in the ciphertext field, and the historical timestamp stored in the encryption timestamp field. Perform double decryption on the historical target ciphertext based on the historical timestamp and the encryption algorithm indicated by the encryption algorithm identifier field to restore the default password plaintext (password20250801) at the last startup.
[0066] 2. Extract CODE: Extract the fixed CODE portion (password) from the default password plaintext (password20250801) from the last startup.
[0067] 3. Dynamically generate the new default password plaintext (password) by combining the plaintext CODE part with the current date (20250806).
[0068] 4. Double encryption: Double encryption is performed based on the encryption algorithm indicated by the encryption algorithm identifier field and the current timestamp to obtain the target ciphertext corresponding to the new default password plaintext (password20250806);
[0069] 5. Update and store: Store the current timestamp in the encrypted timestamp field and the target ciphertext in the ciphertext field.
[0070] According to the embodiments of this disclosure, by designing the default password as a combination password structure of [fixed CODE part + floating DATE part], and combining it with a dual dynamic encryption and decryption mechanism of encryption algorithm and timestamp, the above-mentioned closed loop of "dual decryption → CODE extraction → dynamic generation → dual encryption → update and storage" is formed. This can realize the dynamic update of the default password, ensure the high complexity and high security of the default password, and ensure the stable traceability of the plaintext CODE.
[0071] According to an embodiment of this application, obtaining a default password based on a preset default plaintext and the current date may include: determining the current date in response to a power-on command for starting a target electronic device, wherein the current date represents the date on which the power-on command is triggered; and combining the preset default plaintext and the current date to obtain a default password.
[0072] In one embodiment, assuming a user activates the target electronic device on August 6, 2025, in response to the power-on command, the current date can be determined as 20250806. A preset default plaintext (such as password) determined based on default password information can be combined with the current date to obtain a newly generated default password, password20250806. Although this embodiment generates the default password by directly concatenating the preset default plaintext with the current date, this application is not limited to this, and the method of combining the preset default plaintext with the current date is not limited to this.
[0073] According to embodiments of this application, the method for generating a default password may further include: receiving a standard time signal via a radio wave receiving module in response to a power-on command for starting a target electronic device; decoding the standard time signal to determine standard time data; and determining the current date and current timestamp based on the standard time data.
[0074] According to one embodiment of this application, the standard time signal can be a radio wave signal broadcast by a designated time service center via a shortwave (or longwave) radio station. A radio wave receiving module can be used to receive the standard time signal.
[0075] In one embodiment, in response to a power-on command, the radio wave receiving module powers on and receives a standard time signal. The CPU can decode the standard time signal to determine the standard time data, and thus determine the current date and current timestamp based on the standard time data.
[0076] Figure 3 A schematic diagram of data flow related to a radio wave receiving module according to an embodiment of this application is shown.
[0077] like Figure 3 As shown, the data flow between the radio wave receiving module and various components such as the BMC (Baseboard Management Controller), BIOS (Basic Input / Output System), PHC (Platform Controller Hub), and CPU can be as follows:
[0078] Procedure 1: The system is powered on, and the BIOS on the BMC controls the power-on of the radio wave receiving module;
[0079] Procedure 2: After the radio wave receiving module is powered on, it sends feedback to the BIOS on the BMC;
[0080] Process 3: The radio wave receiving module acquires the standard time signal, parses and converts it into an electrical signal, and then transmits it to the PCH system bus;
[0081] Process 4: The PCH system bus transmits standard time data to the CPU according to the clock system;
[0082] Step 5: The CPU writes the obtained standard time data into memory;
[0083] Process 6: The OS (Operation System) sends a request to obtain standard time, and the request information is sent to the PCH system bus;
[0084] Procedures 7 & 8: The PCH system bus calls the CPU thread to read the latest standard time value from memory;
[0085] Process 9: The PCH passes the read standard time to the OS, which then performs an internal time update operation to determine the current date and timestamp based on the updated system time.
[0086] According to embodiments of this application, the encryption algorithm identifier field may include an encryption algorithm identifier sequence, which includes N identifier information arranged in a specified order. Each of the N identifier information indicates one of N different encryption algorithms, where N is a positive integer and N≥3. The method for generating a default password may further include: determining the encryption algorithm used for second decryption based on the identifier information located at the end of the encryption algorithm identifier sequence along a direction (e.g., from left to right); and determining the encryption algorithm used for first encryption based on the identifier information located at the beginning of the encryption algorithm identifier sequence along the said direction.
[0087] According to one embodiment of this disclosure, the encryption algorithm identifier field can store a sequence of encryption algorithm identifiers.
[0088] As an example, the encryption algorithm identifier sequence can be [A, B, C, D], where identifier A indicates, for example, the AES algorithm, identifier B indicates, for example, the DES algorithm, identifier C indicates, for example, the 3DES algorithm, and identifier D indicates, for example, the RC4 algorithm.
[0089] In one embodiment, the encryption algorithm identifier sequence can be, for example, [A, B, C, D], where the direction is from left to right. The encryption algorithm used for the first encryption can be determined to be AES based on the identifier A, which is the first identifier in the encryption algorithm identifier sequence along the left-to-right direction. The encryption algorithm used for the second decryption can be determined to be RC4 based on the identifier D, which is the last identifier in the encryption algorithm identifier sequence along the left-to-right direction.
[0090] In another optional embodiment, the encryption algorithm identifier sequence can be, for example, [A, B, C, D], where the direction is from right to left. The encryption algorithm used for the first encryption can be determined to be RC4 based on the identifier D, which is the first identifier in the right-to-left direction of the encryption algorithm identifier sequence. The encryption algorithm used for the second decryption can be determined to be AES based on the identifier A, which is the last identifier in the right-to-left direction of the encryption algorithm identifier sequence.
[0091] According to an embodiment of this application, the method for generating a default password may further include: after determining that the user has passed the verification, moving the first identifier information in the encryption algorithm identifier sequence along the direction to the last position in the encryption algorithm identifier sequence along the direction, and causing the remaining sequence consisting of the remaining N-1 identifier information to be shifted forward one position in the encryption algorithm identifier sequence along the opposite direction (e.g., from right to left) to obtain an updated encryption algorithm identifier sequence.
[0092] In one embodiment, the encryption algorithm identifier sequence may include four identifiers: A, B, C, and D. Identifier A, for example, indicates the AES algorithm; identifier B, for example, indicates the DES algorithm; identifier C, for example, indicates the 3DES algorithm; and identifier D, for example, indicates the RC4 algorithm. These four identifiers are arranged in a specified order. After successful user authentication, the specified order can be updated to obtain an updated encryption algorithm identifier sequence. For example, when the target electronic device is started for the i-th time, the four identifiers are arranged in a first order. After successful user authentication, the order of the four identifiers is updated to a second order. When the target electronic device is started for the (i+1)-th time, the four identifiers are arranged in a second order. After successful user authentication, the order of the four identifiers is updated to a third order, and so on.
[0093] The method for updating the specified order will be described in detail below with specific illustrative embodiments.
[0094] Assume the four positions in the encryption algorithm's identifier sequence are denoted from left to right as [position 1, position 2, position 3, position 4]. For example, if the direction is from left to right, position 4 is the last position along the direction, and position 1 is the first position along the direction. Similarly, if the direction is from right to left, position 1 is the last position along the direction, and position 4 is the first position along the direction.
[0095] In one embodiment, the direction is from left to right, so the method for updating the specified order can be called the first-position shift update scheme (it should be noted that the first position here refers to position 1 in the encryption algorithm identifier sequence, not the first position along the left-to-right direction). For ease of understanding, the first position in the following examples refers to position 1, and the last position refers to position 4. For example:
[0096] When i=1, the encryption algorithm identifier sequence (hereinafter referred to as the identifier sequence) is [A, B, C, D]. At this time, based on the identifier D located at the end of the identifier sequence (i.e., position 4), it can be determined that the encryption algorithm used for the second decryption is the RC4 algorithm. Based on the identifier A located at the beginning of the identifier sequence (i.e., position 1), it can be determined that the encryption algorithm used for the first encryption is the AES algorithm. After confirming that the user verification is successful, the identifier A located at the beginning of the identifier sequence can be moved to the end of the identifier sequence, and the remaining sequence B, C, D, consisting of the remaining 3 identifiers, can be shifted forward by one position in the identifier sequence to obtain the updated identifier sequence [B, C, D, A].
[0097] When i=2, the identifier sequence is [B, C, D, A]. Based on identifier A, which is at the end of the sequence, the encryption algorithm used for the second decryption is determined to be AES. Based on identifier B, which is at the beginning of the sequence, the encryption algorithm used for the first encryption is determined to be DES. After user verification, identifier B, which is at the beginning of the sequence, is moved to the end of the sequence, and the remaining three identifiers (C, D, A) are shifted forward one position to obtain the updated identifier sequence [C, D, A, B].
[0098] When i=3, the identifier sequence is [C, D, A, B]. Based on identifier B, which is at the end of the sequence, the encryption algorithm used for the second decryption is determined to be DES. Based on identifier C, which is at the beginning of the sequence, the encryption algorithm used for the first encryption is determined to be 3DES. After user verification, identifier C, which is at the beginning of the sequence, is moved to the end of the sequence, and the remaining three identifiers (D, A, B) are shifted forward one position to obtain the updated identifier sequence [D, A, B, C].
[0099] When i=4, the identifier sequence is [D, A, B, C]. Based on the identifier C at the end of the sequence, the encryption algorithm used for the second decryption is determined to be 3DES. Based on the identifier D at the beginning of the sequence, the encryption algorithm used for the first encryption is determined to be RC4. After user verification, the identifier D at the beginning of the sequence is moved to the end, and the remaining three identifiers (A, B, C) are shifted forward one position to obtain the updated identifier sequence [A, B, C, D].
[0100] When i=5, the processing method is the same as when i=1, and so on.
[0101] In another optional embodiment, the direction is from right to left, so the method for updating the specified order can be called the last-position-forward update scheme (again, the last position here refers to the 4th position in the encryption algorithm identifier sequence, not the last position along the right-to-left direction). Again, using the identifier sequence including the four identifiers A, B, C, and D mentioned above as an example, for ease of understanding, the first digit in the following examples refers to the aforementioned 1st position, and the last digit refers to the aforementioned 4th position. For example:
[0102] When i=1, the identifier sequence is [A, B, C, D]. Based on identifier A, which is at the beginning (position 1), the encryption algorithm used for the second decryption is determined to be AES. Based on identifier D, which is at the end (position 4), the encryption algorithm used for the first encryption is determined to be RC4. After user verification, identifier D, which is at the end of the identifier sequence, is moved to the beginning of the identifier sequence, and the remaining three identifiers (B, C, D) are shifted one position to the right, resulting in the updated identifier sequence [D, A, B, C].
[0103] When i=2, the identifier sequence is [D, A, B, C]. Based on the identifier D at the beginning of the sequence, the encryption algorithm used for the second decryption is determined to be RC4. Based on the identifier C at the end of the sequence, the encryption algorithm used for the first encryption is determined to be 3DES. After user verification, the identifier C at the end of the sequence is moved to the beginning, and the remaining three identifiers (D, A, B) are shifted one position to the right, resulting in the updated identifier sequence [C, D, A, B].
[0104] When i=3, the identifier sequence is [C, D, A, B]. Based on the identifier C at the beginning of the sequence, the encryption algorithm used for the second decryption is determined to be 3DES. Based on the identifier B at the end of the sequence, the encryption algorithm used for the first encryption is determined to be DES. After user verification, the identifier B at the end of the sequence is moved to the beginning, and the remaining three identifiers (C, D, A) are shifted one position to the right, resulting in the updated identifier sequence [B, C, D, A].
[0105] When i=4, the identifier sequence is [B, C, D, A]. Based on identifier B, which is at the beginning of the sequence, the encryption algorithm used for the second decryption is determined to be DES. Based on identifier A, which is at the end of the sequence, the encryption algorithm used for the first encryption is determined to be AES. After user verification, identifier A, which is at the end of the sequence, is moved to the beginning of the sequence, and the remaining three identifiers (B, C, D) are shifted one position to the right, resulting in the updated identifier sequence [A, B, C, D].
[0106] When i=5, the processing method is the same as when i=1, and so on.
[0107] According to embodiments of this application, the specified order can be updated using the above-described first-position shifting update scheme or last-position shifting update scheme to obtain the updated encryption algorithm identifier sequence. This method of periodically updating the encryption algorithm identifier sequence according to certain rules ensures that the encryption algorithm used each time a default password is generated changes dynamically, while maintaining the closed loop of "double decryption → CODE extraction → dynamic generation → double encryption → update and storage." This significantly increases the complexity and security of the default password, further increasing the difficulty of cracking it.
[0108] Figure 4 A flowchart of a method for performing user authentication according to an embodiment of this application is shown.
[0109] like Figure 4 As shown, the method 400 includes operations S410 to S440.
[0110] In operation S410, in response to receiving the verification password from the user, the default password information is obtained, which includes an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field.
[0111] When operating S420, the ciphertext field is decrypted using the timestamp indicated by the encryption timestamp field.
[0112] In operation S430, the encryption algorithm indicated by the encryption algorithm identification field is used to perform a fourth decryption on the ciphertext field that has been decrypted in the third decryption, to obtain the default password used for verification.
[0113] In operation S440, the verification password is validated against the default password used for verification to obtain the verification result.
[0114] According to one embodiment of this application, each time a user uses the target electronic device, upon powering on, the device generates a new default password using the method provided in this embodiment and updates the default password information. The user can input a verification password containing a CODE portion and the current date, and the target electronic device can verify the entered password.
[0115] In one embodiment, for example, if the CODE portion is fixed as "password" and the target electronic device is started on August 6, 2025, the newly generated default password (plaintext) would be password20250806. In response to receiving a verification password (plaintext) from the user, the updated default password information can be obtained. The ciphertext field can be decrypted a third time based on the timestamp indicated by the encryption timestamp field. The ciphertext field, decrypted a fourth time, can be decrypted using the encryption algorithm indicated by the encryption algorithm identifier field to obtain the default password (password20250806) used for verification. This default password (password20250806) can then be used to verify the consistency of the verification password from the user to obtain the verification result.
[0116] According to embodiments of this application, the encryption algorithm identifier field may include an encryption algorithm identifier sequence, which includes N identifier information arranged in a specified order. Each of the N identifier information indicates N different encryption algorithms, where N is a positive integer and N≥3. The user verification method may further include: determining the encryption algorithm used for the fourth decryption based on the identifier information located at the beginning of the encryption algorithm identifier sequence along one direction (e.g., from left to right).
[0117] As an example, the encryption algorithm identifier sequence can be [A, B, C, D], where identifier A indicates, for example, the AES algorithm, identifier B indicates, for example, the DES algorithm, identifier C indicates, for example, the 3DES algorithm, and identifier D indicates, for example, the RC4 algorithm.
[0118] In one embodiment, the encryption algorithm identifier sequence can be, for example, [A, B, C, D], with the direction from left to right. The encryption algorithm used for the fourth decryption can be determined to be the AES algorithm based on the identifier A, which is the first identifier in the encryption algorithm identifier sequence along the left-to-right direction.
[0119] In another alternative embodiment, the encryption algorithm identifier sequence can be, for example, [A, B, C, D], with the direction from right to left. The encryption algorithm used for the fourth decryption can be determined to be the RC4 algorithm based on the identifier D, which is the first identifier in the encryption algorithm identifier sequence along the right-to-left direction.
[0120] According to an embodiment of this application, the method for user verification may further include: logging into a target account when the verification result indicates that the consistency verification has passed, the target account having control permissions over the target electronic device; and refusing to log into the target account during a preset time period when the verification result indicates that the number of consistency verification failures is greater than or equal to a preset threshold.
[0121] In one embodiment, if the verification result indicates that the consistency verification is successful (i.e., the verification password entered by the user is consistent with the default password used for verification), the target account is logged in, and the target account has control permissions over the target electronic device.
[0122] In another embodiment, if the number of times the verification result indicates a consistency verification failure (i.e., the user-entered verification password does not match the default password used for verification) is greater than or equal to a preset threshold, login to the target account is refused for a preset period of time. Those skilled in the art can reasonably set the preset threshold and preset period of time according to actual needs or application scenarios, etc., and no specific limitations are made here.
[0123] Figure 5 A schematic diagram illustrating the process of generating a default password and performing user authentication according to an embodiment of this application is shown.
[0124] like Figure 5 As shown, in response to the power-on command, the target electronic device powers on, the EEPROM powers on, and the default password information is retrieved from the VPD information. Simultaneously, the motherboard powers on, the firmware program starts, and the radio wave receiving module acquires standard time radio waves. The default password information includes an encryption algorithm identifier field, an encryption timestamp field, and a ciphertext field.
[0125] like Figure 5 As shown, the ciphertext field can be decrypted for the first time based on the encryption timestamp field. The encryption algorithm used can be determined based on the encryption algorithm identifier field, and the determined encryption algorithm can be used to decrypt the first decrypted ciphertext field for the second time to obtain the plaintext CODE (such as password).
[0126] like Figure 5 As shown, the CPU can parse standard time radio waves and generate standard time data. Based on the standard time data, the current date (e.g., 20250806) and the current timestamp can be determined.
[0127] like Figure 5 As shown, CODE+DATE can be combined to generate a default password (e.g., password20250806). The encryption algorithm used can be determined based on the encryption algorithm identifier field, and the default password can be first encrypted using the determined algorithm. The current timestamp can be used to perform a second encryption on the first-encrypted default password to obtain the target ciphertext. The encryption timestamp field and the ciphertext field can be updated based on the current timestamp and the target ciphertext, respectively.
[0128] like Figure 5 As shown, after the OS boots, the user can enter a verification password for authentication. Upon receiving the user's verification password, the default password information can be retrieved. A third decryption of the ciphertext field can be performed using the encryption timestamp field. The encryption algorithm used can be determined based on the encryption algorithm identifier field, and the determined encryption algorithm can be used to perform a fourth decryption of the third-decrypted ciphertext field to obtain the default password used for authentication. Consistency verification can be performed on the authentication surface based on the default password used for authentication.
[0129] like Figure 5 As shown, if the consistency verification passes, the user logs in successfully. If the consistency verification fails, an incorrect password message will be displayed. If the number of failed attempts exceeds 5, login will be disabled for half an hour.
[0130] like Figure 5 As shown, after a user successfully logs in, if the user changes the default password, the new password will replace the default password, and the system will load the user-set password for verification the next time the device starts. If the user does not change the default password, the default password will not be regenerated unless the system restarts.
[0131] Figure 6 A structural block diagram of an apparatus for generating a default password according to an embodiment of this application is shown.
[0132] like Figure 6 As shown, the device 600 includes a first determining module 610, a second determining module 620, a first encryption module 630, a second encryption module 640, and an update module 650.
[0133] The first determining module 610 is used to determine the preset default plaintext based on the default password information, which includes an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field.
[0134] The second determining module 620 is used to obtain a default password based on a preset default plaintext and the current date. The default password is used for user verification.
[0135] The first encryption module 630 is used to perform a first encryption on the default password using the encryption algorithm indicated by the encryption algorithm identifier field.
[0136] The second encryption module 640 is used to perform a second encryption on the default password that has been encrypted in the first encryption according to the current timestamp, so as to obtain the target ciphertext.
[0137] Update module 650 is used to update the encryption timestamp field and the ciphertext field based on the current timestamp and the target ciphertext, respectively.
[0138] According to an embodiment of this application, the first determining module 610 includes a first obtaining submodule, a first decryption submodule, and a second decryption submodule.
[0139] The first acquisition submodule is used to acquire default password information in response to a power-on command for starting the target electronic device.
[0140] The first decryption submodule is used to perform the first decryption of the ciphertext field using the historical timestamp indicated by the encryption timestamp field.
[0141] The second decryption submodule is used to perform a second decryption on the ciphertext field that has been decrypted in the first decryption using the encryption algorithm indicated by the encryption algorithm identifier field, so as to obtain the preset default plaintext.
[0142] According to an embodiment of this application, the second determining module 620 includes a first determining submodule and a combining submodule.
[0143] The first determination submodule is used to determine the current date in response to a power-on command for starting the target electronic device. The current date represents the date on which the power-on command was triggered.
[0144] The combination submodule is used to combine the preset default plaintext and the current date to obtain the default password.
[0145] According to embodiments of this application, the apparatus for generating a default password further includes a receiving module, a decoding module, and a third determining module.
[0146] The receiving module is used to receive a standard time signal via a radio wave receiving module in response to a power-on command for starting the target electronic device.
[0147] The decoding module is used to decode the standard time signal and determine the standard time data.
[0148] The third determination module is used to determine the current date and current timestamp based on standard time data.
[0149] According to embodiments of this application, the encryption algorithm identifier field includes an encryption algorithm identifier sequence, which comprises N identifier information arranged in a specified order. Each of the N identifier information indicates one of N different encryption algorithms, where N is a positive integer and N≥3. The apparatus for generating the default password further includes a fourth confirmation module and a fifth confirmation module.
[0150] The fourth confirmation module is used to determine the encryption algorithm used for the second decryption based on the identifier information located at the end of one direction in the encryption algorithm identifier sequence.
[0151] The fifth confirmation module is used to determine the encryption algorithm used for the first encryption based on the identifier information that is first in the encryption algorithm identifier sequence along the direction.
[0152] According to embodiments of this application, the apparatus for generating a default password further includes an update module.
[0153] The update module is used to move the first identifier in the encryption algorithm identifier sequence along the direction to the last position along the direction after the user verification is successful, and to move the remaining sequence consisting of the remaining N-1 identifiers one position in the opposite direction of the direction in the encryption algorithm identifier sequence to obtain the updated encryption algorithm identifier sequence.
[0154] According to embodiments of this application, any plurality of modules among the first determining module 610, the second determining module 620, the first encryption module 630, the second encryption module 640, and the updating module 650 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this application, at least one of the first determining module 610, the second determining module 620, the first encryption module 630, the second encryption module 640, and the updating module 650 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the first determining module 610, the second determining module 620, the first encryption module 630, the second encryption module 640, and the update module 650 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0155] Figure 7 A structural block diagram of a user authentication apparatus according to an embodiment of this application is shown.
[0156] like Figure 7 As shown, the device 700 includes a second acquisition module 710, a third decryption module 720, a fourth decryption module 730, and a verification module 740.
[0157] The second acquisition module 710 is used to acquire default password information in response to receiving a verification password from the user. The default password information includes an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field.
[0158] The third decryption module 720 is used to perform a third decryption on the ciphertext field using the timestamp indicated by the encryption timestamp field.
[0159] The fourth decryption module 730 is used to perform a fourth decryption on the ciphertext field that has been decrypted in the third step, using the encryption algorithm indicated by the encryption algorithm identifier field, to obtain the default password used for verification.
[0160] The verification module 740 is used to perform consistency verification on the verification password based on the default password used for verification, so as to obtain the verification result.
[0161] According to embodiments of this application, the encryption algorithm identifier field includes an encryption algorithm identifier sequence, which comprises N identifier information arranged in a specified order. Each of the N identifier information indicates one of N different encryption algorithms, where N is a positive integer and N≥3. The user verification device further includes a sixth confirmation module.
[0162] The sixth confirmation module is used to determine the encryption algorithm used for the fourth decryption based on the identifier information that is the first one in one direction in the encryption algorithm identifier sequence.
[0163] According to embodiments of this application, the device for user verification further includes a first processing module and a second processing module.
[0164] The first processing module is used to log in to the target account when the verification result indicates that the consistency verification is successful. The target account has control permissions over the target electronic device.
[0165] The second processing module is used to refuse login to the target account within a preset time period if the number of verification failures in the consistency verification of the verification results is greater than or equal to a preset threshold.
[0166] According to embodiments of this application, any plurality of modules among the second acquisition module 710, the third decryption module 720, the fourth decryption module 730, and the verification module 740 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this application, at least one of the second acquisition module 710, the third decryption module 720, the fourth decryption module 730, and the verification module 740 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the second acquisition module 710, the third decryption module 720, the fourth decryption module 730, and the verification module 740 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0167] Figure 8 A block diagram of an electronic device suitable for implementing a method for generating a default password and / or performing a method for user authentication, according to embodiments of this application, is shown.
[0168] like Figure 8As shown, an electronic device 800 according to an embodiment of this application includes a processor 801, which can perform various appropriate actions and processes according to a program stored in a ROM (Read-Only Memory) 802 or a program loaded from a storage portion 808 into a RAM (Random Access Memory) 803. The processor 801 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 801 may also include onboard memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.
[0169] RAM 803 stores various programs and data required for the operation of electronic device 800. Processor 801, ROM 802, and RAM 803 are interconnected via bus 804. Processor 801 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 802 and / or RAM 803. It should be noted that the programs may also be stored in one or more memories other than ROM 802 and RAM 803. Processor 801 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in said one or more memories.
[0170] According to embodiments of this application, the electronic device 800 may further include an input / output (I / O) interface 805, which is also connected to a bus 804. The electronic device 800 may also include one or more of the following components connected to the input / output (I / O) interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the input / output (I / O) interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 810 as needed so that computer programs read from it can be installed into the storage section 808 as needed.
[0171] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.
[0172] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 802 and / or RAM 803 and / or one or more memories other than ROM 802 and RAM 803 described above.
[0173] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the methods for generating default passwords and performing user authentication provided in the embodiments of this application.
[0174] When the computer program is executed by the processor 801, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0175] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 809, and / or installed from a removable medium 811. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0176] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 809, and / or installed from the removable medium 811. When the computer program is executed by the processor 801, it performs the functions defined in the system of this application embodiment. According to the embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0177] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0178] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0179] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.
[0180] The embodiments of this application have been described above. However, these embodiments are merely illustrative and not intended to limit the scope of this application. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of this application, those skilled in the art can make various substitutions and modifications, all of which should fall within the scope of this application.
Claims
1. A method of generating a default password, characterized by, The method comprises: determining a preset default plaintext based on default password information, the default password information comprising an encryption timestamp field, an encryption algorithm identifier field and a ciphertext field; obtaining a default password based on the preset default plaintext and a current date, the default password being used for user authentication; performing first encryption on the default password using an encryption algorithm indicated by the encryption algorithm identifier field; performing second encryption on the default password subjected to the first encryption based on a current timestamp to obtain target ciphertext; and updating the encryption timestamp field and the ciphertext field based on the current timestamp and the target ciphertext, respectively; wherein the determining of the preset default plaintext based on the default password information comprises: obtaining the default password information in response to a boot-up starting instruction for starting a target electronic device; performing first decryption on the ciphertext field using a historical timestamp indicated by the encryption timestamp field; performing second decryption on the ciphertext field subjected to the first decryption using an encryption algorithm indicated by the encryption algorithm identifier field to obtain the preset default plaintext; wherein the encryption algorithm identifier field comprises an encryption algorithm identifier sequence, the encryption algorithm identifier sequence comprising N pieces of identifier information arranged in a specified order, the N pieces of identifier information respectively indicating N different encryption algorithms, N being a positive integer and N≥3; the method further comprises: determining the encryption algorithm used for the second decryption based on the identifier information located at the end of the encryption algorithm identifier sequence in a direction; determining the encryption algorithm used for the first encryption based on the identifier information located at the beginning of the encryption algorithm identifier sequence in the direction; and after the user authentication is passed, moving the identifier information located at the beginning of the encryption algorithm identifier sequence in the direction to the end of the encryption algorithm identifier sequence in the direction, and moving the remaining sequence composed of the remaining N-1 pieces of identifier information by one position in the opposite direction of the direction in the encryption algorithm identifier sequence to obtain an updated encryption algorithm identifier sequence.
2. The method of claim 1, wherein, The obtaining of the default password based on the preset default plaintext and the current date comprises: determining the current date in response to a boot-up starting instruction for starting a target electronic device, the current date representing a date when the boot-up starting instruction is triggered; and combining the preset default plaintext and the current date to obtain the default password.
3. The method of claim 1, wherein, The method further comprises: receiving a standard time signal through a wireless wave receiving module in response to a boot-up starting instruction for starting a target electronic device; decoding the standard time signal to determine standard time data; and determining the current date and the current timestamp based on the standard time data.
4. The method according to any one of claims 1 to 3, characterized in that, The default password information is part of device configuration information, and the device configuration information is stored in a preset non-volatile memory of the target electronic device.
5. A method of performing user authentication, characterized by, The method comprises: obtaining default password information in response to receiving an authentication password from a user, the default password information comprising an encryption timestamp field, an encryption algorithm identifier field and a ciphertext field; The ciphertext field is decrypted a third time using the timestamp indicated by the encryption timestamp field. Using the encryption algorithm indicated by the encryption algorithm identifier field, the ciphertext field, which has been decrypted in the third step, is decrypted in the fourth step to obtain the default password used for verification; and The verification password is validated for consistency based on the default password used for verification to obtain the verification result; The encryption algorithm identifier field includes an encryption algorithm identifier sequence, which comprises N identifier information arranged in a specified order. Each of the N identifier information indicates one of N different encryption algorithms, where N is a positive integer and N≥3. The method further includes: The encryption algorithm used for the fourth decryption is determined based on the identifier information that is first in one direction in the encryption algorithm identifier sequence.
6. The method of claim 5, wherein, The method further includes: If the verification result indicates that the consistency verification is successful, log in to the target account, which has control permissions over the target electronic device. If the number of verification failures indicating consistency is greater than or equal to a preset threshold, the target account will be refused login for a preset period of time.
7. An apparatus for generating a default password, the apparatus comprising: The device includes: The first determining module is used to determine a preset default plaintext based on default password information, wherein the default password information includes an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field. The second determining module is used to obtain a default password based on the preset default plaintext and the current date, and the default password is used for user verification; The first encryption module is used to perform a first encryption on the default password using the encryption algorithm indicated by the encryption algorithm identification field; The second encryption module is used to perform a second encryption on the default password, which has been encrypted in the first encryption, based on the current timestamp, to obtain the target ciphertext; and The update module is used to update the encryption timestamp field and the ciphertext field based on the current timestamp and the target ciphertext, respectively. The first determining module includes: The first acquisition submodule is used to acquire default password information in response to a power-on command for starting the target electronic device; The first decryption submodule is used to perform the first decryption of the ciphertext field using the historical timestamp indicated by the encryption timestamp field. The second decryption submodule is used to perform a second decryption on the ciphertext field that has been decrypted in the first decryption using the encryption algorithm indicated by the encryption algorithm identifier field, so as to obtain the preset default plaintext. The encryption algorithm identifier field includes an encryption algorithm identifier sequence, which comprises N identifier information arranged in a specified order. Each of the N identifier information indicates one of N different encryption algorithms, where N is a positive integer and N≥3. The device for generating the default password also includes: The fourth confirmation module is used to determine the encryption algorithm used for the second decryption based on the identifier information located at the end of one direction in the encryption algorithm identifier sequence. The fifth confirmation module is used to determine the encryption algorithm used for the first encryption based on the identifier information located at the first position along the direction in the encryption algorithm identifier sequence. The update module is further configured to: after user verification, move the first identifier in the encryption algorithm identifier sequence along the direction to the last identifier in the encryption algorithm identifier sequence along the direction, and move the remaining N-1 identifiers in the encryption algorithm identifier sequence one position in the opposite direction to the direction, thereby obtaining the updated encryption algorithm identifier sequence.
8. An apparatus for performing user authentication, the apparatus comprising: The device includes: The second acquisition module is used to acquire default password information in response to receiving a verification password from the user. The default password information includes an encryption timestamp field, an encryption algorithm identifier field, and a ciphertext field. The third decryption module is used to perform a third decryption on the ciphertext field using the timestamp indicated by the encryption timestamp field. The fourth decryption module is used to perform a fourth decryption on the ciphertext field that has been decrypted in the third step, using the encryption algorithm indicated by the encryption algorithm identifier field, to obtain a default password for verification; and The verification module is used to perform consistency verification on the verification password based on the default password used for verification, so as to obtain the verification result; The encryption algorithm identifier field includes an encryption algorithm identifier sequence, which comprises N identifier information arranged in a specified order. Each of the N identifier information indicates one of N different encryption algorithms, where N is a positive integer and N≥3. The user verification device further includes: The sixth confirmation module is used to determine the encryption algorithm used for the fourth decryption based on the identifier information that is the first one in one direction in the encryption algorithm identifier sequence.
9. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 6.
10. A computer readable storage medium having stored thereon a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 6.
11. A computer program product comprising computer programs or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Vehicle FlexRay bus data communication method and device and vehicle
CN118900174A