Intelligent password key management method and device based on SKF standard
By encapsulating the management interface to unify the management of handles, the problems of cumbersome interfaces and numerous handles in the development of SKF standard USBkeys are solved, improving development efficiency and program stability, and enhancing memory security.
Patent Information
- Application Number
- CN202511445586.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-11
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-10-11
AI Technical Summary
Existing USBkey development solutions based on the SKF standard have cumbersome interface definitions, requiring developers to maintain multiple handles, which leads to program instability and memory insecurity.
This paper provides a smart password key management method based on the SKF standard. It manages handles uniformly by encapsulating the management interface, reducing interface complexity, and uniformly managing the handle lifecycle during connection and disconnection.
It improves development convenience and efficiency, enhances program stability and memory safety, and reduces development difficulty.
Smart Images

Figure CN120910873A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a smart password key management method and device based on SKF standard. BACKGROUND
[0002] The SKF standard is the full name of GM / T 0016 Secure Key Function (SKF) Application Interface Specification in Chinese, which is abbreviated as SKF. The standard defines the application interface of the smart password key (hereinafter referred to as USBkey) based on the PKI password system, covers functions, data types, parameter definitions and device security requirements, and is a C language development interface. In the standard, the USBkey device is divided into three layers vertically: device layer, application layer, and container layer; the core interface function is divided into four categories: device management, application management, container operation, and password operation. Figure 1 It is a schematic diagram of the device level and core interface function of the USBkey.
[0003] The existing USBkey development scheme based on the SKF standard in the industry mainly uses the SKF interface library provided by the manufacturer, develops a deeply customized scheme according to the actual business process through the definition of the SKF standard. However, the SKF standard interface definition is too cumbersome, the interface definition is interlaced with the device level, and the overall level is not obvious, which causes the developer to spend too much time to study how to use the interface; the design of the three-layer vertical device level requires the developer to maintain many handles. For example, at least the following handles need to be maintained for a container-related operation: device handle, application handle, and container handle. The more handles that need to be maintained, the more likely it is to cause instability of the program and insecurity of the memory. SUMMARY
[0004] In view of the above analysis, the embodiments of the present application aim to provide a smart password key management method and device based on the SKF standard, to solve the problems of the existing developer spending too much time to study how to use the interface, low development efficiency, the developer maintaining too many handles, and easily leading to instability of the program and insecurity of the memory.
[0005] In one aspect, the embodiment of the present application provides a smart password key management method based on an SKF standard, which comprises: receiving a first interface call request for a first management interface in a state of successful connection with a first smart password key and successful authentication of the first smart password key; wherein the first interface call request comprises information of a target operation based on the first smart password key; wherein the first smart password key generates a device handle after successful connection; and performing the following operations on the first interface call request through the first management interface: if an operation level of the target operation is a device layer operation, executing the target operation by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, generating an application handle by calling an SKF standard interface for generating the application handle, storing the application handle into a memory, and executing the target operation by calling an SKF standard interface for executing the target operation; and if the operation level of the target operation is a container layer operation, generating an application handle by calling an SKF standard interface for generating the application handle, generating a container handle by calling an SKF standard interface for generating the container handle, storing the application handle and the container handle into the memory, and executing the target operation by calling an SKF standard interface for executing the target operation.
[0006] The above technical solution has the following beneficial effects: the target operation is executed through the encapsulated first management interface, the complexity of the interface is reduced, the handles used therein are uniformly managed, a good development scheme is provided, the development difficulty is reduced, the development convenience and efficiency are improved, and the stability of the program and the safety of the memory are improved.
[0007] Based on the further improvement of the above method, the method further comprises: in response to detecting that the connection of the first smart password key is disconnected, sending a second interface call request to a second management interface; wherein the second interface call request comprises information that the first smart password key is disconnected; for the second interface call request, the following operations are performed through the second management interface: obtaining the current handle generation state; in response to the current generation of the device handle, the application handle and the container handle, releasing the device handle from the memory by calling the SKF standard interface for releasing the device handle, releasing the application handle from the memory by calling the SKF standard interface for releasing the application handle, and releasing the container handle from the memory by calling the SKF standard interface for releasing the container handle; in response to the current generation of the device handle and the application handle, releasing the device handle from the memory by calling the SKF standard interface for releasing the device handle, and releasing the application handle from the memory by calling the SKF standard interface for releasing the application handle; in response to the current generation of the device handle, releasing the device handle from the memory by calling the SKF standard interface for releasing the device handle.
[0008] The beneficial effect of the above further improvement scheme is that the operation after the smart password key is disconnected through the second management interface is realized, the unified management of the handle life cycle is realized, and the stability of the program and the safety of the memory are further improved.
[0009] Based on the further improvement of the above method, before the receiving of the first interface call request for the first management interface, the method further comprises: in response to detecting the insertion operation of the first smart password key, obtaining the device descriptor information of the first smart password key; wherein the device descriptor information comprises a vendor ID and a product ID; receiving a third interface call request for a third management interface; wherein the third interface call request is used to request initialization configuration information; for the third interface call request, the following operations are performed through the third management interface: obtaining a first authentication process configuration file corresponding to the vendor ID and the product ID, reading the first authentication process configuration file and loading an SKF standard library, and initializing a memory context; wherein the SKF standard library comprises information of the SKF standard interface; receiving a fourth interface call request for a fourth management interface; wherein the fourth interface call request is used to request connection and authentication of the first smart password key according to the first authentication process configuration file; for the fourth interface call request, the following operations are performed through the fourth management interface: in response to the device descriptor configuration information in the first authentication process configuration file being consistent with the device descriptor information, connecting the first smart password key by calling an SKF standard interface for device connection, generating a device handle by calling an SKF standard interface for generating a device handle after the first smart password key is successfully connected, and storing the device handle to the memory; according to the first authentication process configuration file, performing device authentication on the first smart password key by calling an SKF standard interface for device authentication.
[0010] The beneficial effect of the above further improvement scheme is that the initialization of configuration information through the encapsulated second management interface and the connection and authentication of the smart password key through the third management interface are realized, the complexity of the interface is reduced, the handle used therein is uniformly managed, the development convenience and efficiency are further improved, and the stability of the program and the security of the memory are improved.
[0011] Based on the further improvement of the above method, before the obtaining of the first authentication process configuration file corresponding to the vendor ID and the product ID, the method further comprises: generating the first authentication process configuration file according to a second authentication process configuration file of at least one second smart password key that has been successfully authenticated.
[0012] The beneficial effect of the above further improvement scheme is that by generating the first authentication process configuration file according to the second authentication process configuration file of at least one second smart password key that has been successfully authenticated, the automatic generation of the first authentication process configuration file is realized, and the difficulty of adaptation to new devices is reduced.
[0013] Based on the further improvement of the above method, the generating the first authentication process configuration file according to the second authentication process configuration file of the at least one second smart password key which has been successfully authenticated comprises: obtaining configuration enumeration values in the second authentication process configuration file of the at least one second smart password key; repeatedly performing the action of arranging and combining the configuration enumeration values in the second authentication process configuration file of the at least one second smart password key to obtain a third authentication process configuration file until the first smart password key is successfully authenticated according to the third authentication process configuration file; and taking the third authentication process configuration file which is successfully authenticated as the first authentication process configuration file.
[0014] The beneficial effect of the above further improvement is that by obtaining configuration enumeration values in the second authentication process configuration file of the at least one second smart password key, repeatedly performing the action of arranging and combining the configuration enumeration values in the second authentication process configuration file of the at least one second smart password key to obtain a third authentication process configuration file until the first smart password key is successfully authenticated according to the third authentication process configuration file, and taking the third authentication process configuration file which is successfully authenticated as the first authentication process configuration file, the generation efficiency of the first authentication process configuration file is improved and the adaptability of the first authentication process configuration file is ensured.
[0015] Based on the further improvement of the above method, after the first smart password key is authenticated according to the third authentication process configuration file, the method further comprises: in response to the number of authentication test failures exceeding a preset number, modifying the third authentication process configuration file.
[0016] The beneficial effect of the above further improvement is that by modifying the third authentication process configuration file in response to the number of authentication test failures exceeding a preset number, the generation efficiency of the first authentication process configuration file is further improved.
[0017] Based on the further improvement of the above method, before the first authentication process configuration file is generated according to the second authentication process configuration file of the at least one second smart password key which has been successfully authenticated, the method further comprises: determining the at least one second smart password key according to a preset device priority; wherein the priority of the device priority from high to low comprises: the manufacturer ID is the same, but the product ID is different; the manufacturer ID is different, and the product ID is different.
[0018] The beneficial effect of the above further improvement is that by determining the at least one second smart password key according to a preset device priority, the generation efficiency of the first authentication process configuration file is further improved.
[0019] In another aspect, the embodiment of the present application provides an intelligent cryptographic key management device based on the SKF standard, which comprises: a receiving module, configured to receive a first interface call request for a first management interface in a state of successful connection with a first intelligent cryptographic key and successful authentication of the first intelligent cryptographic key; wherein the first interface call request comprises information of a target operation based on the first intelligent cryptographic key; wherein the first intelligent cryptographic key generates a device handle after successful connection; and a processing module, configured to execute the following operations on the first interface call request through the first management interface: if an operation level of the target operation is a device layer operation, executing the target operation by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, generating an application handle by calling an SKF standard interface for generating the application handle, storing the application handle into a memory, and executing the target operation by calling an SKF standard interface for executing the target operation; and if the operation level of the target operation is a container layer operation, generating an application handle by calling an SKF standard interface for generating the application handle, generating a container handle by calling an SKF standard interface for generating the container handle, storing the application handle and the container handle into the memory, and executing the target operation by calling an SKF standard interface for executing the target operation.
[0020] The intelligent cryptographic key management device based on the SKF standard provided by the present application realizes execution of a target operation through a packaged first management interface, reduces the complexity of an interface, uniformly manages handles used therein, provides a good development scheme, reduces development difficulty, improves development convenience and development efficiency, and improves the stability of a program and the security of a memory.
[0021] The present application further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the intelligent cryptographic key management method based on the SKF standard according to any one of the above embodiments when executing the computer program.
[0022] The present application further provides a non-transitory computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the intelligent cryptographic key management method based on the SKF standard according to any one of the above embodiments.
[0023] The present application further provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the intelligent cryptographic key management method based on the SKF standard according to any one of the above embodiments.
[0024] The technical solutions in the present application can be combined with each other to achieve more preferred combination solutions. Other features and advantages of the present application will be described in the following description, and some advantages will become apparent from the description, or will be understood by those skilled in the art through implementation of the present application. The objects and other advantages of the present application can be achieved and obtained through the contents particularly pointed out in the description and the drawings. BRIEF DESCRIPTION OF DRAWINGS
[0025] The drawings are only for the purpose of illustrating specific embodiments and are not considered as limiting the present application, and in the whole drawings, the same reference signs represent the same parts; Figure 1 is a device level and core interface function schematic diagram of the USB key; Figure 2 is one of the flow schematic diagrams of the intelligent password key management method based on the SKF standard provided by the present application; Figure 3 is a generation process schematic diagram of the authentication flow configuration file in the intelligent password key management method based on the SKF standard provided by the present application; Figure 4 is another of the flow schematic diagrams of the intelligent password key management method based on the SKF standard provided by the present application; Figure 5 is a third of the flow schematic diagrams of the intelligent password key management method based on the SKF standard provided by the present application; Figure 6 is a comparison diagram of the intelligent password key management method based on the SKF standard provided by the present application and the standard SKF flow; Figure 7 is a structure schematic diagram of the intelligent password key management device based on the SKF standard provided by the present application; Figure 8 An example of an electronic device is shown in the physical structure schematic diagram. DETAILED DESCRIPTION
[0026] The preferred embodiments of the present application will be specifically described below in combination with the drawings, wherein the drawings constitute a part of the present application, and are used to explain the principles of the embodiments of the present application, and are not used to limit the scope of the present application.
[0027] Figure 2 is one of the flow schematic diagrams of the intelligent password key management method based on the SKF standard provided by the present application. As shown in Figure 2 , the method comprises: Step S1, receiving a first interface call request for a first management interface in a state that a first smart password key is successfully connected and authenticated; wherein the first interface call request comprises information of a target operation based on the first smart password key; wherein the device handle is generated after the first smart password key is successfully connected.
[0028] The smart password key management method based on the SKF standard provided by the application can be applied to various devices capable of connecting a smart password key (USBKey) and having data processing capability, such as servers, personal computers, mobile terminals and other terminal devices. For the convenience of description, the device running the smart password key management method based on the SKF standard is referred to as a smart password key management device based on the SKF standard, which is hereinafter referred to as a smart password key management device.
[0029] The application encapsulates a new management interface according to the actual use scene based on the SKF standard interface, reduces the complexity of the interface, and uniformly manages the handle used therein, thereby providing a good development scheme. In addition, the method minimizes the USBkey call demand of different manufacturers (the USBkey device supports the SKF standard interface by default), and can complete device management through the SKF interface library provided by the manufacturer and the corresponding USBkey device, without the need for additional development support of the manufacturer, thereby providing a good manufacturer scheme.
[0030] After the smart password key management device and the first smart password key are successfully connected and authenticated, one or more target operations can be executed according to different program settings. The first management interface request can be automatically sent to the first management interface according to the program setting, or the first interface call request can be sent to the first management interface by triggering a pre-set operation, such as clicking a menu, so as to execute the target operation. In a state that the smart password key management device and the first smart password key are successfully connected and authenticated, the first interface call request for the first management interface is received. The first interface call request comprises information of a target operation to be executed. Since the device handle is generated after the smart password key management device and the first smart password key are successfully connected, the device handle has been generated in the state that the smart password key management device and the first smart password key are successfully connected and authenticated.
[0031] Step S2, for the first interface call request, the following operations are executed through the first management interface: If the operation level of the target operation is a device layer operation, the target operation is executed by calling the SKF standard interface for executing the target operation. If the operation level of the target operation is an application layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, the application handle is stored in memory, and the target operation is executed by calling an SKF standard interface for executing the target operation; If the operation level of the target operation is a container layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, a container handle is generated by calling an SKF standard interface for generating a container handle, the application handle and the container handle are stored in memory, and the target operation is executed by calling an SKF standard interface for executing the target operation.
[0032] As shown in Figure 1 The operation level of the target operation can be determined according to information of the target operation based on the first smart password key. The operation level of the target operation can be a device layer operation, an application layer operation, or a container layer operation.
[0033] If the operation level of the target operation is a device layer operation, the target operation is executed by calling an SKF standard interface corresponding to the target operation. If the operation level of the target operation is an application layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, the application handle is stored in memory, and the target operation is executed by calling an SKF standard interface corresponding to the target operation. If the operation level of the target operation is a container layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, a container handle is generated by calling an SKF standard interface for generating a container handle, the application handle and the container handle are stored in memory, and the target operation is executed by calling an SKF standard interface for executing the target operation.
[0034] The application provides an intelligent password key management method based on an SKF standard, which comprises the following steps: in a state of successful connection with a first intelligent password key and successful authentication of the first intelligent password key, a first interface call request for a first management interface is received, the first interface call request comprises information of a target operation based on the first intelligent password key, and the following operations are performed on the first interface call request through the first management interface: if the operation level of the target operation is a device layer operation, the target operation is executed by calling an SKF standard interface for executing the target operation, if the operation level of the target operation is an application layer operation, an application handle is generated by calling an SKF standard interface for generating the application handle, the application handle is stored in a memory, and the target operation is executed by calling an SKF standard interface for executing the target operation, and if the operation level of the target operation is a container layer operation, an application handle is generated by calling an SKF standard interface for generating the application handle, a container handle is generated by calling an SKF standard interface for generating the container handle, the application handle and the container handle are stored in the memory, and the target operation is executed by calling an SKF standard interface for executing the target operation, so that the target operation is executed through the encapsulated first management interface, the complexity of the interface is reduced, the handles used are uniformly managed, a good development scheme is provided, the development difficulty is reduced, the development convenience and efficiency are improved, and the stability of the program and the safety of the memory are improved.
[0035] According to the application, the method further comprises the following steps: in response to detecting that the connection of the first intelligent password key is disconnected, a second interface call request is sent to a second management interface; the second interface call request comprises information that the first intelligent password key is disconnected; and the following operations are performed on the second interface call request through the second management interface: a current handle generation state is acquired; in response to that the device handle, the application handle and the container handle are currently generated, the device handle is released from the memory by calling an SKF standard interface for releasing the device handle, the application handle is released from the memory by calling an SKF standard interface for releasing the application handle, and the container handle is released from the memory by calling an SKF standard interface for releasing the container handle; in response to that the device handle and the application handle are currently generated, the device handle is released from the memory by calling an SKF standard interface for releasing the device handle, and the application handle is released from the memory by calling an SKF standard interface for releasing the application handle; and in response to that the device handle is currently generated, the device handle is released from the memory by calling an SKF standard interface for releasing the device handle.
[0036] If the connection between the first smart password key and the terminal device is detected to be disconnected, all handles are automatically released from the memory by sending a second interface call request to the second management interface. Since the handles generated under different target operations are different, the current handle generation state is obtained. If there are device handles, application handles and container handles generated at present, it indicates that the container layer target operation is executed, then the device handles are released from the memory by calling the SKF standard interface for releasing the device handles, the application handles are released from the memory by calling the SKF standard interface for releasing the application handles, and the container handles are released from the memory by calling the SKF standard interface for releasing the container handles; if there are device handles and application handles generated at present, it indicates that the application layer target operation is executed, then the device handles are released from the memory by calling the SKF standard interface for releasing the device handles, and the application handles are released from the memory by calling the SKF standard interface for releasing the application handles; if there is a device handle generated at present, it indicates that the device layer target operation is executed, then the device handles are released from the memory by calling the SKF standard interface for releasing the device handles.
[0037] The smart password key management method based on the SKF standard provided by the application, by responding to the detection of the disconnection of the first smart password key, sending a second interface call request to the second management interface, the second interface call request including the information of the disconnection of the first smart password key, for the second interface call request, the following operations are executed by the second management interface: obtaining the current handle generation state; in response to the generation of device handles, application handles and container handles at present, the device handles are released from the memory by calling the SKF standard interface for releasing the device handles, the application handles are released from the memory by calling the SKF standard interface for releasing the application handles, and the container handles are released from the memory by calling the SKF standard interface for releasing the container handles; in response to the generation of device handles and application handles at present, the device handles are released from the memory by calling the SKF standard interface for releasing the device handles, and the application handles are released from the memory by calling the SKF standard interface for releasing the application handles; in response to the generation of device handles at present, the device handles are released from the memory by calling the SKF standard interface for releasing the device handles, which realizes the operation after the disconnection of the smart password key through the second management interface, realizes the unified management of the handle life cycle, and further improves the stability of the program and the safety of the memory.
[0038] According to the method for managing the intelligent password key based on the SKF standard, before receiving the first interface calling request for the first management interface, the method further comprises: in response to detecting the insertion operation of the first intelligent password key, obtaining the device descriptor information of the first intelligent password key; wherein the device descriptor information comprises a vendor ID and a product ID; receiving a third interface calling request for a third management interface; wherein the third interface calling request is used to request initialization configuration information; for the third interface calling request, the following operations are performed through the third management interface: obtaining a first authentication process configuration file corresponding to the vendor ID and the product ID, reading the first authentication process configuration file and loading an SKF standard library, and initializing a memory context; wherein the SKF standard library comprises information of the SKF standard interface; receiving a fourth interface calling request for a fourth management interface; wherein the fourth interface calling request is used to request connection and authentication of the first intelligent password key according to the first authentication process configuration file; for the fourth interface calling request, the following operations are performed through the fourth management interface: in response to the device descriptor configuration information in the first authentication process configuration file being consistent with the device descriptor information, connecting the first intelligent password key by calling an SKF standard interface for device connection, generating a device handle by calling an SKF standard interface for generating a device handle after the first intelligent password key is successfully connected, and storing the device handle to the memory; and performing device authentication on the first intelligent password key by calling an SKF standard interface for device authentication according to the first authentication process configuration file.
[0039] Before receiving the first interface calling request for the first management interface, the connection with the first intelligent password key needs to be established and the first intelligent password key needs to be successfully authenticated in advance.
[0040] To establish the connection with the first intelligent password key and successfully authenticate the first intelligent password key, the first intelligent password key needs to be inserted into the intelligent password key management device first. If the intelligent password key management device detects the insertion operation of the first intelligent password key, the device descriptor information of the first intelligent password key is obtained, the device descriptor information comprises the information of each field of the device descriptor, and the device descriptor information comprises a vendor ID and a product ID. The combination of the vendor ID and the product ID uniquely identifies a specific USB device model in theory.
[0041] A third interface call request for the third management interface is received. The sequence of the interface call requests can be set in the smart password key management program or triggered according to user operation. In response to the third interface call request, the following operations are performed through the third management interface: obtaining a first authentication flow configuration file corresponding to the vendor ID and the product ID, reading and loading the SKF standard library from the first authentication flow configuration file, and initializing the memory context. The SKF standard library includes information of SKF standard interfaces.
[0042] A fourth interface call request for the fourth management interface is received. The fourth interface call request is used to request connection and authentication of the first smart password key according to the first authentication flow configuration file. In response to the fourth interface call request, the following operations are performed through the fourth management interface: if it is determined that the device descriptor configuration information in the first authentication flow configuration file is consistent with the device descriptor information, connection and authentication operations for the first smart password key are performed. The connection and authentication operations for the first smart password key include connecting the first smart password key by calling the SKF standard interface for device connection, generating a device handle by calling the SKF standard interface for generating a device handle after the first smart password key is successfully connected, storing the device handle in the memory, and performing device authentication on the first smart password key by calling the SKF standard interface for device authentication according to the first authentication flow configuration file. If it is determined that the device descriptor configuration information in the first authentication flow configuration file is inconsistent with the device descriptor information, the connection and authentication operations for the smart password key are not performed, that is, the fourth interface call request is rejected.
[0043] The application provides an intelligent password key management method based on an SKF standard, which comprises the following steps: in response to detecting a first intelligent password key insertion operation, acquiring device descriptor information of the first intelligent password key, the device descriptor information comprising a manufacturer ID and a product ID; receiving a third interface call request for a third management interface, the third interface call request being used to request initialization configuration information; for the third interface call request, performing the following operations through the third management interface: acquiring a first authentication process configuration file corresponding to the manufacturer ID and the product ID, reading the first authentication process configuration file and loading an SKF standard library, initializing a memory context, and the SKF standard library comprising information of an SKF standard interface; receiving a fourth interface call request for a fourth management interface, the fourth interface call request being used to request connection and authentication of the first intelligent password key according to the first authentication process configuration file; for the fourth interface call request, performing the following operations through the fourth management interface: in response to the device descriptor configuration information in the first authentication process configuration file being consistent with the device descriptor information, connecting the first intelligent password key by calling an SKF standard interface for device connection, generating a device handle by calling an SKF standard interface for generating a device handle after the first intelligent password key is successfully connected, storing the device handle in the memory, and performing device authentication on the first intelligent password key by calling an SKF standard interface for device authentication according to the first authentication process configuration file. The method realizes initialization of configuration information through a second management interface, and realizes connection and authentication of the intelligent password key through the third management interface, reduces the complexity of the interfaces, uniformly manages the handles used in the method, and further improves the development convenience and efficiency, and the stability of the program and the safety of the memory.
[0044] According to the intelligent password key management method based on the SKF standard, before the first authentication process configuration file corresponding to the manufacturer ID and the product ID is acquired, the method further comprises the following step: generating the first authentication process configuration file according to a second authentication process configuration file of at least one second intelligent password key which has been successfully authenticated.
[0045] For the device authentication process, the authentication algorithms and authentication data used by various manufacturers are quite different, so that the code results adapted to one manufacturer's device cannot be directly applied to other manufacturers' devices, and therefore, in the existing development practice, it is difficult to avoid making changes to the device authentication process related code, which wastes a large amount of human and time costs. In the device authentication, the device authentication is performed based on an authentication process configuration file, and the authentication process configuration file comprises device authentication keys, device authentication data, device authentication algorithms and other key information.
[0046] It can be understood that if the first authentication process configuration file corresponding to the manufacturer ID and product ID of the first smart password key has been stored, the first authentication process configuration file is directly obtained, and the first smart password key is authenticated by using the first authentication process configuration file. If there is no first authentication process configuration file corresponding to the manufacturer ID and product ID of the first smart password key, the first process configuration file needs to be generated in advance.
[0047] The application generates the first authentication process configuration file based on the second authentication process configuration file of at least one second smart password key which has been successfully authenticated, and reduces the difficulty of adapting to new equipment. The second smart password key is used to distinguish from the first smart password key, the second smart password key is an adapted smart password key, and the first smart password key is a smart password key to be adapted. The at least one second smart password key can include a plurality of different smart password keys.
[0048] The application provides an SKF standard-based smart password key management method, which generates a first authentication process configuration file according to a second authentication process configuration file of at least one second smart password key which has been successfully authenticated, realizes automatic generation of the first authentication process configuration file, and reduces the difficulty of adapting to new equipment.
[0049] According to the SKF standard-based smart password key management method provided by the application, the first authentication process configuration file is generated according to the second authentication process configuration file of at least one second smart password key which has been successfully authenticated, and the method comprises the following steps: obtaining a configuration enumeration value in the second authentication process configuration file of the at least one second smart password key; repeatedly performing the action of arranging and combining the configuration enumeration value in the second authentication process configuration file of the at least one second smart password key to obtain a third authentication process configuration file until the first smart password key is successfully authenticated according to the third authentication process configuration file; and taking the third authentication process configuration file which is successfully authenticated as the first authentication process configuration file.
[0050] In generating the first authentication procedure configuration file according to the second authentication procedure configuration file of the at least one second smart password key which has been successfully authenticated, the configuration enumeration values in the second authentication procedure configuration file of the at least one second smart password key are acquired, the configuration enumeration values in the second authentication procedure configuration file of the at least one second smart password key are arranged and combined to obtain a third authentication procedure configuration file, the first smart password key is authenticated according to the third authentication procedure configuration file, if the authentication test is successful, the third authentication procedure configuration file of which the authentication test is successful is taken as the first authentication procedure configuration file; if the test fails, the action of arranging and combining the configuration enumeration values in the second authentication procedure configuration file of the at least one second smart password key to obtain the third authentication procedure configuration file is repeatedly performed until the authentication test of the first smart password key according to the third authentication procedure configuration file is successful. The second authentication procedure configuration file is only used to distinguish from the first authentication procedure configuration file, and the second authentication procedure configuration files corresponding to the respective second smart password keys are different.
[0051] For example, the authentication procedure configuration file ConfigA adapted to the USBkeyA, the USBkeyB and the USBkeyC is acquired, the ConfigA includes the content of the authentication procedure configuration file corresponding to the USBkeyA, the USBkeyB and the USBkeyC respectively, and is a file integrated from the authentication procedure configuration file corresponding to the USBkeyA, the USBkeyB and the USBkeyC respectively.
[0052] The three smart password keys to be adapted include the USBkeyD, the USBkeyE and the USBkeyF (it is considered that the corresponding SKF interface library has been provided by three manufacturers, and the device can be successfully called through the interface library).
[0053] The authentication procedure configuration file of the new device is generated according to the following process: The configuration enumeration values in the authentication procedure configuration files of the USBkeyA, the USBkeyB and the USBkeyC are acquired, and the configuration enumeration values in the authentication procedure configuration files of the USBkeyA, the USBkeyB and the USBkeyC are arranged and combined to obtain a third authentication procedure configuration file. It can be understood that the same configuration enumeration value can be selected from the authentication procedure configuration files of the USBkeyA, the USBkeyB and the USBkeyC, but the same configuration enumeration value is only selected once.
[0054] The USBkey D is authenticated by using the third authentication procedure configuration file, if the authentication test is successful, the third authentication procedure configuration file is used as the authentication procedure configuration file of the USBkey D. If the authentication test fails, the configuration enumeration value in the authentication procedure configuration file of the USBkey A, the USBkey B and the USBkey C is repeatedly acquired, the configuration enumeration value in the authentication procedure configuration file of the USBkey A, the USBkey B and the USBkey C is arranged and combined, the action of obtaining the third authentication procedure configuration file is performed until the USBkey D is authenticated by using the third authentication procedure configuration file successfully.
[0055] The authentication procedure configuration file of the USBkey E and the USBkey F is acquired in the same way as the USBkey D, and details are not repeated. The authentication procedure configuration file of the USBkey D, the USBkey E and the USBkey F can be written in the ConfigB, and of course, the authentication procedure configuration file of different smart password keys can also be independently formed into a file, only the difference is in the storage form.
[0056] The authentication procedure configuration file of the test success can be permanently saved, so as to generate the authentication procedure configuration file of the new device subsequently.
[0057] Figure 3 The application provides a generation process schematic diagram of an authentication procedure configuration file in a smart password key management method based on a SKF standard, and the method comprises the following steps of: An adapted (already successfully authenticated) configuration file is used as a template to generate an authentication procedure configuration file for a device to be adapted; A vendor's USBKey is inserted, and the authentication procedure configuration file is tested; If the test result is failure, the authentication procedure configuration file is regenerated, the number of times of the procedure can be controlled, and the configuration file can be manually modified after exceeding a threshold value; The correct authentication procedure configuration file is output.
[0058] Figure 4 The application provides a flow schematic diagram two of a smart password key management method based on a SKF standard. As shown in the figure, Figure 4 The method comprises the following steps of: The generated configuration file ConfigB is correctly placed in a specified position of a server ServerA; Suppose that a binary program of "creating a container of an ECC key pair" is written, and an interface provided by the method is called; Three vendors' USBkeys are inserted and the program is run, and the operation of creating an ECC key pair is performed on the USBkey device of a specified vendor and a serial number; After the USBkey management of any one manufacturer is completed, the device can be directly pulled out, and after the interface detects that the device is pulled out, all handles related to the device generated in the memory are uniformly cleaned up.
[0059] The intelligent password key management method based on the SKF standard provided by the application comprises the following steps: obtaining configuration enumeration values in a second authentication process configuration file of at least one second intelligent password key; repeatedly performing arrangement and combination of the configuration enumeration values in the second authentication process configuration file of the at least one second intelligent password key to obtain a third authentication process configuration file; and performing authentication test on the first intelligent password key according to the third authentication process configuration file until the authentication test succeeds, and taking the third authentication process configuration file with which the authentication test succeeds as the first authentication process configuration file, thereby improving the generation efficiency of the first authentication process configuration file and ensuring the adaptability of the first authentication process configuration file.
[0060] According to the intelligent password key management method based on the SKF standard provided by the application, after the authentication test on the first intelligent password key according to the third authentication process configuration file, the method further comprises the following steps: in response to the number of times of authentication test failure exceeding a preset number of times, modifying the third authentication process configuration file.
[0061] The intelligent password key management method based on the SKF standard provided by the application comprises the following steps: obtaining configuration enumeration values in a second authentication process configuration file of at least one second intelligent password key; repeatedly performing arrangement and combination of the configuration enumeration values in the second authentication process configuration file of the at least one second intelligent password key to obtain a third authentication process configuration file; and performing authentication test on the first intelligent password key according to the third authentication process configuration file.
[0062] The intelligent password key management method based on the SKF standard provided by the application comprises the following steps: obtaining configuration enumeration values in a second authentication process configuration file of at least one second intelligent password key; repeatedly performing arrangement and combination of the configuration enumeration values in the second authentication process configuration file of the at least one second intelligent password key to obtain a third authentication process configuration file; and performing authentication test on the first intelligent password key according to the third authentication process configuration file.
[0063] According to the intelligent password key management method based on the SKF standard provided by the application, before the first authentication process configuration file is generated according to the second authentication process configuration file of the at least one second intelligent password key that has passed the authentication, the method further comprises the following steps: determining the at least one second intelligent password key according to a preset device priority; and wherein the priority of the device priority comprises, from high to low, the same manufacturer ID but different product IDs, and different manufacturer IDs and different product IDs.
[0064] Before generating the first authentication procedure configuration file according to the second authentication procedure configuration file of the at least one second smart password key, the at least one second smart password key is determined according to preset device priorities.
[0065] It should be noted that the at least one second smart password key does not necessarily include all the smart password keys that have been successfully authenticated, and the at least one second smart password key can be determined according to part of the smart password keys that have been successfully authenticated.
[0066] When the at least one second smart password key is determined, the priorities of the devices from high to low include: the same manufacturer ID but different product IDs, and different manufacturer IDs and different product IDs. For example, all or part of the smart password keys with the same manufacturer ID but different product IDs as the first smart password key can be selected to construct the at least one second smart password key.
[0067] If the first authentication procedure configuration file of the first smart password key cannot be obtained according to the smart password key with the same manufacturer ID but different product ID as the first smart password key, the smart password key with different manufacturer ID and different product ID as the first smart password key can be gradually added to construct the at least one second smart password key, and when the configuration enumeration values in the second authentication procedure configuration file of the at least one second smart password key are arranged and combined, the arrangement and combination of the configuration enumeration values that include more information of the second smart password key with high device priority can be tried first.
[0068] The smart password key management method based on the SKF standard provided by the application further improves the generation efficiency of the first authentication procedure configuration file by determining the at least one second smart password key according to preset device priorities.
[0069] Figure 5 is a third flowchart of the smart password key management method based on the SKF standard provided by the application. As shown in Figure 5 the method comprises: After the smart password key management program starts running, the authentication procedure configuration file is read and the SKF standard library is loaded, and the memory context is initialized; The USBKey is connected and the device is authenticated, and the device handle is stored in the memory; The operation of generating the ECC key pair is performed, and the generated application handle and container handle are stored in the memory; After detecting that the smart password key is pulled out, the memory space of the device handle, the application handle and the container handle in the memory is released.
[0070] The three types of handles in the SKF standard do not need to be managed explicitly in the management program code, because they are uniformly stored in the memory for management, and are uniformly released and destroyed when needed, thereby avoiding the problem of memory leakage that can be caused.
[0071] Figure 6 is a comparison chart of the intelligent password key management method based on the SKF standard and the standard SKF process provided by the application. As shown in Figure 6 the right side is a flow chart of the intelligent password key management method based on the SKF standard provided by the application, and each flow block can be implemented as a packaged management interface, and the left side is the standard SKF process. The application is based on the SKF standard interface, and encapsulates the management interface according to the actual business, wherein the device connection authentication, target operation execution and device pulling out post-processing are encapsulated, the complexity of the interface is reduced, and the handles used therein are uniformly managed, thereby providing a good development scheme.
[0072] The intelligent password key management device based on the SKF standard provided by the application is described below, and the intelligent password key management device based on the SKF standard described below can be correspondingly referred to the intelligent password key management method based on the SKF standard described above.
[0073] Figure 7 is a structural schematic diagram of the intelligent password key management device based on the SKF standard provided by the application. As shown in Figure 7 the device includes a receiving module 10 and a processing module 20, wherein: The receiving 10 is configured to: in a state of successfully connecting with a first intelligent password key and successfully authenticating the first intelligent password key, receive a first interface call request for a first management interface; wherein the first interface call request includes information of a target operation based on the first intelligent password key; wherein the first intelligent password key generates a device handle after successfully connecting; The processing module 20 is configured to: for the first interface call request, execute the following operations through the first management interface: if the operation level of the target operation is a device layer operation, execute the target operation by calling the SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, generate an application handle by calling the SKF standard interface for generating an application handle, store the application handle in the memory, and execute the target operation by calling the SKF standard interface for executing the target operation; and if the operation level of the target operation is a container layer operation, generate an application handle by calling the SKF standard interface for generating an application handle, generate a container handle by calling the SKF standard interface for generating a container handle, store the application handle and the container handle in the memory, and execute the target operation by calling the SKF standard interface for executing the target operation.
[0074] The SKF standard-based intelligent password key management device provided by the application can receive a first interface call request for a first management interface in a state of successful connection with a first intelligent password key and successful authentication of the first intelligent password key, the first interface call request comprising information of a target operation based on the first intelligent password key, the device handle being generated after the successful connection of the first intelligent password key, and for the first interface call request, the following operations are executed through the first management interface: if the operation level of the target operation is a device layer operation, the target operation is executed by calling the SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, an application handle is generated by calling the SKF standard interface for generating an application handle, the application handle is stored in the memory, and the target operation is executed by calling the SKF standard interface for executing the target operation; and if the operation level of the target operation is a container layer operation, an application handle is generated by calling the SKF standard interface for generating an application handle, a container handle is generated by calling the SKF standard interface for generating a container handle, the application handle and the container handle are stored in the memory, and the target operation is executed by calling the SKF standard interface for executing the target operation, so that the target operation is executed through the encapsulated first management interface, the complexity of the interface is reduced, the handles used are uniformly managed, a good development scheme is provided, the development difficulty is reduced, the development convenience and efficiency are improved, and the stability of the program and the safety of the memory are improved.
[0075] Figure 8 An example of a schematic diagram of the physical structure of an electronic device is shown in FIG. 1. Figure 8As shown, the electronic device can include a processor 810, a communications interface 820, a memory 830, and a communications bus 840, wherein the processor 810, the communications interface 820, and the memory 830 complete mutual communication through the communications bus 840. The processor 810 can invoke a logic instruction in the memory 830 to execute an intelligent password key management method based on the SKF standard, which includes: in a state of successful connection with a first intelligent password key and successful authentication of the first intelligent password key, receiving a first interface call request for a first management interface; wherein the first interface call request includes information of a target operation based on the first intelligent password key; wherein a device handle is generated after the first intelligent password key is successfully connected; for the first interface call request, the following operations are performed through the first management interface: if the operation level of the target operation is a device layer operation, the target operation is executed by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, the application handle is stored to the memory, and the target operation is executed by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is a container layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, a container handle is generated by calling an SKF standard interface for generating a container handle, the application handle and the container handle are stored to the memory, and the target operation is executed by calling an SKF standard interface for executing the target operation.
[0076] In addition, the logic instruction in the memory 830 described above can be implemented in the form of a software functional unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0077] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program being stored on a non-transitory computer readable storage medium, and the computer program being executable by a processor to cause a computer to execute the method for managing an intelligent cryptographic key based on the SKF standard, the method comprising: receiving a first interface call request for a first management interface in a state that a first intelligent cryptographic key is successfully connected and authenticated; wherein the first interface call request comprises information of a target operation based on the first intelligent cryptographic key; wherein the first intelligent cryptographic key generates a device handle after being successfully connected; and for the first interface call request, executing the following operations through the first management interface: if an operation level of the target operation is a device layer operation, executing the target operation by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, generating an application handle by calling an SKF standard interface for generating the application handle, storing the application handle into a memory, and executing the target operation by calling an SKF standard interface for executing the target operation; and if the operation level of the target operation is a container layer operation, generating an application handle by calling an SKF standard interface for generating the application handle, generating a container handle by calling an SKF standard interface for generating the container handle, storing the application handle and the container handle into a memory, and executing the target operation by calling an SKF standard interface for executing the target operation.
[0078] In yet another aspect, the present application also provides a non-transitory computer readable storage medium having stored thereon a computer program, which, when executed by a processor, implements the method for managing an intelligent cryptographic key based on the SKF standard as described above, which comprises: receiving a first interface call request for a first management interface in a state of successful connection with a first intelligent cryptographic key and successful authentication of the first intelligent cryptographic key; wherein the first interface call request comprises information of a target operation based on the first intelligent cryptographic key; wherein a device handle is generated after the first intelligent cryptographic key is successfully connected; for the first interface call request, the following operations are performed through the first management interface: if the operation level of the target operation is a device layer operation, the target operation is executed by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, the application handle is stored in a memory, and the target operation is executed by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is a container layer operation, an application handle is generated by calling an SKF standard interface for generating an application handle, a container handle is generated by calling an SKF standard interface for generating a container handle, the application handle and the container handle are stored in a memory, and the target operation is executed by calling an SKF standard interface for executing the target operation.
[0079] Those skilled in the art can understand that all or part of the processes of the above-mentioned embodiments can be completed by a computer program instructing related hardware, and the program can be stored in a computer readable storage medium. The computer readable storage medium includes a magnetic disk, an optical disk, a read-only memory, a random access memory, etc.
[0080] The device embodiments described above are merely illustrative, and the units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e., they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the present embodiment according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0081] Those skilled in the art can clearly understand the implementation of the various embodiments by means of software and necessary general hardware platforms through the description of the above embodiments, and of course, the embodiments can also be implemented by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, and the computer software product can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in the various embodiments or some parts of the embodiments.
[0082] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
[0083] The above is only the preferred specific implementation of the present application, but the protection scope of the present application is not limited to this, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application.
Claims
1. A method for managing an intelligent cipher key based on an SKF standard, characterized by, Comprise: In the state of successful connection with the first smart password key and successful authentication of the first smart password key, a first interface call request for a first management interface is received; wherein the first interface call request comprises information of a target operation based on the first smart password key; wherein the device handle is generated after the successful connection of the first smart password key; For the first interface call request, the following operations are performed through the first management interface: If the operation level of the target operation is a device layer operation, the target operation is executed by calling the SKF standard interface for executing the target operation; If the operation level of the target operation is an application layer operation, an application handle is generated by calling the SKF standard interface for generating an application handle, the application handle is stored in the memory, and the target operation is executed by calling the SKF standard interface for executing the target operation; If the operation level of the target operation is a container layer operation, an application handle is generated by calling the SKF standard interface for generating an application handle, a container handle is generated by calling the SKF standard interface for generating a container handle, the application handle and the container handle are stored in the memory, and the target operation is executed by calling the SKF standard interface for executing the target operation.
2. The intelligent key management method based on the SKF standard according to claim 1, characterized in that, The method further comprises: In response to detecting that the connection of the first smart password key is disconnected, a second interface call request is sent to a second management interface; wherein the second interface call request comprises information that the first smart password key is disconnected; For the second interface call request, the following operations are performed through the second management interface: Get the current handle generation state; In response to the generation of the device handle, the application handle and the container handle, the device handle is released from the memory by calling the SKF standard interface for releasing the device handle, the application handle is released from the memory by calling the SKF standard interface for releasing the application handle, and the container handle is released from the memory by calling the SKF standard interface for releasing the container handle; In response to the generation of the device handle and the application handle, the device handle is released from the memory by calling the SKF standard interface for releasing the device handle, and the application handle is released from the memory by calling the SKF standard interface for releasing the application handle; In response to the generation of the device handle, the device handle is released from the memory by calling the SKF standard interface for releasing the device handle.
3. The method of claim 1, wherein the method is based on the SKF standard, and Before the receiving of the first interface call request for the first management interface, the method further comprises: In response to detecting the insertion operation of the first smart password key, the device descriptor information of the first smart password key is obtained; wherein the device descriptor information comprises the vendor ID and the product ID; A third interface call request for a third management interface is received; wherein the third interface call request is used to request initialization configuration information; For the third interface call request, the following operations are performed through the third management interface: obtaining a first authentication process configuration file corresponding to the vendor ID and the product ID, reading the first authentication process configuration file and loading an SKF standard library, and initializing a memory context; wherein the SKF standard library includes information of the SKF standard interface; receiving a fourth interface call request for a fourth management interface; wherein the fourth interface call request is used to request connection and authentication of the first smart password key according to the first authentication process configuration file; For the fourth interface call request, the following operations are performed through the fourth management interface: in response to the device descriptor configuration information in the first authentication process configuration file being consistent with the device descriptor information, connecting the first smart password key by calling an SKF standard interface for device connection, generating a device handle by calling an SKF standard interface for generating a device handle after the first smart password key is successfully connected, and storing the device handle to the memory; according to the first authentication process configuration file, performing device authentication on the first smart password key by calling an SKF standard interface for device authentication.
4. The method of claim 3, wherein the method is based on the SKF standard, and Before the first authentication process configuration file corresponding to the vendor ID and the product ID is obtained, the method further comprises: generating the first authentication process configuration file according to a second authentication process configuration file of at least one second smart password key that has been successfully authenticated.
5. The method of claim 4, wherein the method is based on the SKF standard, and The generating of the first authentication process configuration file according to the second authentication process configuration file of the at least one second smart password key that has been successfully authenticated comprises: obtaining a configuration enumeration value in the second authentication process configuration file of the at least one second smart password key; repeatedly performing the action of arranging and combining the configuration enumeration value in the second authentication process configuration file of the at least one second smart password key to obtain a third authentication process configuration file until the authentication test on the first smart password key according to the third authentication process configuration file is successful; taking the third authentication process configuration file for which the authentication test is successful as the first authentication process configuration file.
6. The method of claim 5, wherein the method further comprises: After the authentication test on the first smart password key according to the third authentication process configuration file, the method further comprises: in response to the number of times of authentication test failure exceeding a preset number of times, modifying the third authentication process configuration file.
7. The method of claim 4, wherein the method further comprises: receiving a request for a key from a user; and providing the key to the user. Before the first authentication process configuration file is generated according to the second authentication process configuration file of the at least one second smart password key that has been successfully authenticated, the method further comprises: determining the at least one second smart password key according to a preset device priority; wherein the priority of the device priority from high to low comprises: the vendor ID is the same, but the product ID is different; the vendor ID is different, and the product ID is different.
8. An intelligent cryptographic key management device based on SKF standards, characterized by, comprises: The receiving module is configured to: receive a first interface call request for a first management interface in a state where the first smart password key is successfully connected and the first smart password key is successfully authenticated; the first interface call request comprises information of a target operation based on the first smart password key; and the device handle is generated after the first smart password key is successfully connected; The processing module is configured to: execute the following operations on the first interface call request through the first management interface: if the operation level of the target operation is a device layer operation, execute the target operation by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is an application layer operation, generate an application handle by calling an SKF standard interface for generating the application handle, store the application handle into the memory, and execute the target operation by calling an SKF standard interface for executing the target operation; if the operation level of the target operation is a container layer operation, generate an application handle by calling an SKF standard interface for generating the application handle, generate a container handle by calling an SKF standard interface for generating the container handle, store the application handle and the container handle into the memory, and execute the target operation by calling an SKF standard interface for executing the target operation.
9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, The processor executes the computer program to implement the smart password key management method based on the SKF standard according to any one of claims 1 to 7.
10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the smart password key management method based on the SKF standard according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for realizing password application interface of intelligent password key based on TPM (Trusted Platform Module)
CN115062330A
Cross-browser application and identity authentication method and system based on intelligent password key
CN116647361A
Password authentication using cryptographic key handle-based authentication records
CN120150979A
Password authentication using cryptographic key handle-based authentication records
US20250192999A1
Cited By
Unified cryptographic interface management system and method based on hardware feature automatic identification
CN121644083A
A unified national secret interface management system and method based on automatic recognition of hardware features
CN121644083B