Operating System Login Method, Device, Electronic Device, Storage Medium and Program

By using one-to-one corresponding username and Ukey binding methods in the device operating system, the target password is verified to control login permissions, which solves the problem of low security in the existing operating system and significantly reduces the risk of illegal login.

CN114238920BActive Publication Date: 2025-06-27QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010941067.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-09
Publication Date
2025-06-27
Estimated Expiration
2040-09-09

AI Technical Summary

Technical Problem

The operating system of existing devices is very low and is easily logged in illegally.

Method used

Password verification is performed to control whether to allow login to the operating system by obtaining the target username and password in the logged-in device and determining the unique Ukey bound to the target username from the accessed Ukey.

Benefits of technology

Through one-to-one binding methods of username and Ukey, the risk of username and Ukey being stolen is reduced, the security of the operating system is improved, and illegal login is prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238920B_ABST
    Figure CN114238920B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides an operating system login method, device, electronic device, storage medium, and program. The Ukey bound to each username used to log in to the operating system in the device is unique, and the username bound to each Ukey used to log in to the operating system in the device is also unique. When a user logs in to the operating system of the device through a target username, the target password is verified through the Ukey bound to the target username, thereby realizing the control of logging in to the operating system in the device. The username and Ukey used to log in to the operating system in the device adopt a one-to-one binding method, and this one-to-one binding method reduces the risk of illegal login to the operating system caused by the theft of the username or the theft of the Ukey.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to an operating system login method, device, electronic device, storage medium and program. Background Art

[0002] As the risks caused by the leakage of the device password of the terminal are increasing, the significance of device security management for enterprises and individuals is also becoming more and more important. However, in most cases, the operating system of the device is not set with a login password, or the verification method of the login password is simple and single. For example, the login to the operating system is verified by a password set by the user himself. This results in very low security of the operating system of the terminal device and is easily illegally logged in. Summary of the Invention

[0003] Embodiments of the present invention provide an operating system login method, device, electronic device, storage medium and program, which are used to solve the problem that the security of the operating system of the existing device is very low and is easily illegally logged in.

[0004] In view of the above technical problems, in a first aspect, embodiments of the present invention provide an operating system login method, including:

[0005] Obtain a target username and a target password input when obtaining the operating system in the login device;

[0006] Determine a target Ukey bound to the target username from at least one Ukey connected to the device; wherein, the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique;

[0007] Input the target password into the target Ukey, obtain the verification result of the target Ukey for the target password, and control whether to allow logging in to the operating system in the device with the target username according to the verification result.

[0008] Optionally, the determining a target Ukey bound to the target username from at least one Ukey connected to the device includes:

[0009] Obtain the security identifier SID corresponding to the target username from the registry as the target SID;

[0010] Obtain the Ukey storing the target SID from the at least one Ukey as the target Ukey.

[0011] Optionally, after controlling logging in to the operating system in the device with the target username according to the verification result, it further includes:

[0012] After successfully logging in to the operating system in the device with the target username, if it is detected that the target Ukey is removed from the device, the operating system in the device is controlled to be in a disabled state.

[0013] Optionally, before controlling the operating system in the device to be in a disabled state, it further includes:

[0014] Determine whether the currently logged-in username is the target username. If so, proceed to disable; if not, determine whether there is a Ukey bound to the currently logged-in username among the Ukeys currently connected to the device;

[0015] If there is a Ukey bound to the currently logged-in username among the Ukeys currently connected to the device, allow continued login to the operating system in the device; otherwise, proceed to disable.

[0016] Optionally, before determining the target Ukey bound to the target username from at least one Ukey connected to the device, it further includes:

[0017] Obtain the time of the operating system when logging in to the operating system in the device with the target username currently, as the system time at the time of this login;

[0018] Determine whether the system time at the time of this login of the target username is later than the system time at the time of the target username's previous login, where the system time at the time of the target username's previous login is the time of the operating system when logging in to the operating system in the device with the target username for the most recent time;

[0019] If the system time at the time of this login of the target username is later than the system time at the time of the previous login, determine the target Ukey bound to the target username from at least one Ukey connected to the device; otherwise, do not allow logging in to the operating system in the device with the target username.

[0020] Optionally, before obtaining the target username and target password entered when logging in to the operating system in the device, it further includes:

[0021] Authorize at least one administrator Ukey, where when logging in to the operating system in the device with different administrator Ukeys, different permissions for managing the login to the operating system in the device are possessed.

[0022] Optionally, before obtaining the target username and target password entered when logging in to the operating system in the device, it further includes:

[0023] When logging in to the operating system in the device with the system administrator Ukey among the at least one administrator Ukeys, bind the user name that is not currently bound to any Ukey and the Ukey that is not currently bound to any user name; and / or,

[0024] When logging in to the operating system in the device with the security administrator Ukey among the at least one administrator Ukeys, set the login conditions for logging in to the operating system in the device with any user name; wherein, the login conditions include that when logging in to the operating system in the device with the any user name, the system time at the current login is later than the system time at the previous login, and the expiration period for logging in to the operating system in the device with the any user name; and / or,

[0025] When logging in to the operating system in the device with the audit administrator Ukey among the at least one administrator Ukeys, query the login log for logging in to the operating system in the device with any user name; wherein, the login log includes the system time at the previous login of the target user name;

[0026] Wherein, the system time at the current login of the any user name is the time of the operating system when currently logging in to the operating system in the device with the target user name; the system time at the previous login of the target user name is the time of the operating system when last logging in to the operating system in the device with the target user name.

[0027] In a second aspect, an embodiment of the present invention provides an operating system login device, including:

[0028] An acquisition module, configured to acquire a target user name and a target password input when logging in to the operating system in the device;

[0029] A determination module, configured to determine a target Ukey bound to the target user name from at least one Ukey accessing the device; wherein, the Ukey bound to each user name used to log in to the operating system in the device is unique, and the user name bound to each Ukey used to log in to the operating system in the device is unique;

[0030] A control module, configured to input the target password into the target Ukey, obtain the verification result of the target Ukey for the target password, and control whether to allow logging in to the operating system in the device with the target user name according to the verification result.

[0031] In a third aspect, an embodiment of the present invention provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the steps of the above-mentioned operating system login method are implemented.

[0032] In a fourth aspect, an embodiment of the present invention provides a non-transitory readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the operating system login method described in any one of the above are implemented.

[0033] In a fifth aspect, an embodiment of the present invention provides a computer program. When the computer program is executed by a processor, the steps of the operating system login method described in any one of the above are implemented.

[0034] Embodiments of the present invention provide an operating system login method, device, electronic device, storage medium, and program. Each Ukey bound to the user name for logging in to the operating system in the device is unique, and the user name bound to each Ukey for logging in to the operating system in the device is unique. When a user logs in to the operating system of the device through a target user name, the target password is verified through the Ukey bound to the target user name, thereby realizing the control of logging in to the operating system in the device. The user name and Ukey for logging in to the operating system in the device are bound in a one-to-one correspondence. Compared with the situation where multiple user names are bound to one Ukey, the risk of the user name being stolen is reduced. At the same time, compared with the situation where one user name is bound to multiple Ukeys, the risk of the Ukey being stolen is reduced. This one-to-one binding method reduces the risk of the operating system being illegally logged in due to the user name being stolen or the Ukey being stolen.

[0035] Specifically, when multiple user names are bound to one Ukey, after the password in the Ukey is leaked, as long as any one of the multiple user names is leaked, it is possible that the operating system of the device is illegally logged in. When one user name is bound to multiple Ukeys, after the user name is leaked, as long as the password in any one of the Ukeys is cracked, it is possible that the operating system of the device is illegally logged in. It can be seen that when verifying the login to the operating system of the device with the help of the Ukey, both the "one-to-many" or "many-to-one" binding methods have a relatively high risk of the user name and password being leaked. In this application, the user name and Ukey for logging in to the operating system of a certain device are bound in a "one-to-one" manner for the user name and password. If the password in the Ukey is leaked, only when the user name uniquely bound to the Ukey is leaked can it be possible that the operating system of the device is illegally logged in. If the user name is leaked, only when the password in the Ukey uniquely bound to the user name is leaked can it be possible that the operating system of the device is illegally logged in. It can be seen that the "one-to-one" binding method greatly reduces the risk of the user name and password being leaked simultaneously compared with the "one-to-many" or "many-to-one" binding methods, and therefore is also beneficial to reducing the risk of the operating system of the device being illegally logged in. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0037] Figure 1 It is a schematic flowchart of an operating system login method provided by an embodiment of the present invention;

[0038] Figure 2 It is a schematic diagram of the process of binding a username and a Ukey after logging in to the operating system of a device through an authorized administrator Ukey provided by another embodiment of the present invention;

[0039] Figure 3 It is a schematic diagram of the verification process of logging in to the operating system of a device after binding a username and a Ukey provided by another embodiment of the present invention;

[0040] Figure 4 It is a structural block diagram of an operating system login device provided by another embodiment of the present invention;

[0041] Figure 5 It is a schematic diagram of the physical structure of an electronic device provided by another embodiment of the present invention. Detailed implementation manners

[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0043] Figure 1 It is a schematic flowchart of an operating system login method provided for this embodiment. This operating system login method is applicable to the operating system in a device. Refer to Figure 1 This operating system login method includes:

[0044] Step 101: Obtain the target username and target password entered when logging in to the operating system in the device.

[0045] The device can be a terminal device, such as a computer. The operating system in the device is a system used to support the operation of the device, such as the Window operating system.

[0046] When the device is turned on, an interface for inputting a username and a password is displayed, and the target username and target password input by the user are obtained through this interface.

[0047] Step 102: Determine the target Ukey bound to the target username from at least one Ukey accessing the device; wherein, the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique.

[0048] Multiple interfaces for accessing Ukeys are provided in the device. When multiple Ukeys are accessed in the device, each Ukey can be traversed according to the target username to determine the Ukey bound to the target username.

[0049] The username and Ukey for logging in to the operating system in the device are bound in a one-to-one manner. The Ukey bound to the target username can be uniquely determined through the target username, and the verification of the target password is achieved through this Ukey. Compared with the one-to-many or many-to-one binding methods, the risk of the passwords in the username and Ukey being leaked simultaneously can be reduced.

[0050] Specifically, when multiple usernames are bound to one Ukey, after the password in the Ukey is leaked, as long as any one of the multiple usernames is leaked, it is possible to cause the illegal login of the operating system of the device. When one username is bound to multiple Ukeys, after the username is leaked, as long as the password in any one of the Ukeys is cracked, it is possible to cause the illegal login of the operating system of the device. It can be seen that when verifying the login of the operating system of the device with the help of the Ukey, both the "one-to-many" and "many-to-one" binding methods have a relatively high risk of the username and password being leaked. In this application, for the username and Ukey for logging in to the operating system of a certain device, the username and password are bound in a "one-to-one" manner. If the password in the Ukey is leaked, only when the username uniquely bound to this Ukey is leaked can it possibly cause the illegal login of the operating system of the device. If the username is leaked, only when the password in the Ukey uniquely bound to this username is leaked can it possibly cause the illegal login of the operating system of the device. It can be seen that compared with the "one-to-many" or "many-to-one" binding methods, the "one-to-one" binding method greatly reduces the risk of the username and password being leaked simultaneously, and therefore is also beneficial to reducing the risk of the illegal login of the operating system of the device.

[0051] In addition, when multiple Ukeys are bound to a single username, if there is a problem with the username (for example, forgetting the username and being unable to retrieve it), all Ukeys bound to that username will become invalid, thereby affecting the operating systems of the devices held by multiple holders of these Ukeys, and none of them can log in. When multiple usernames are bound to a single Ukey, if the Ukey is lost or damaged, each username bound to it will be unable to log in to the operating system of the device. It can be seen that the one-to-many or many-to-one binding methods are very likely to result in the situation where multiple users are unable to log in to the operating system of the device, and the risk resistance ability is relatively low. However, the one-to-one binding method of the device and the Ukey adopted in this embodiment can only affect one user's login to the operating system of the device whether there is a problem with the username or the Ukey, and will not affect other users, greatly improving the risk resistance ability.

[0052] Step 103: Input the target password into the target Ukey, obtain the verification result of the target Ukey for the target password, and control whether to allow logging in to the operating system in the device with the target username according to the verification result.

[0053] Specifically, input the target password into the target Ukey, and the target Ukey compares the target password with the password stored in the target Ukey. When the target password is the same as the password stored in the target Ukey, output a verification result indicating that the verification of the target password is passed; otherwise, input a verification result indicating that the verification of the target password fails.

[0054] Obtain the verification result. If the verification result is that the verification is passed, allow logging in to the operating system in the device with the target username; otherwise, do not allow logging in to the operating system in the device with the target username, and send a prompt message indicating that the verification of the target password is unsuccessful.

[0055] This embodiment provides a method for logging in to an operating system. The Ukey bound to each username used to log in to the operating system in the device is unique, and the username bound to each Ukey used to log in to the operating system in the device is unique. When a user logs in to the operating system of the device with a target username, the target Ukey bound to the target username verifies the target password, thereby realizing the control of logging in to the operating system in the device. The usernames and Ukeys used to log in to the operating system in the device adopt a one-to-one binding method, which reduces the risk of the username being stolen compared to the situation where multiple usernames are bound to a single Ukey. At the same time, compared to the situation where a single username is bound to multiple Ukeys, it reduces the risk of the Ukey being stolen. This one-to-one binding method reduces the risk of the operating system being illegally logged in due to the username being stolen or the Ukey being stolen.

[0056] Further, based on the above embodiments, determining the target Ukey bound to the target username from at least one Ukey accessing the device includes:

[0057] Obtaining the security identifier SID corresponding to the target username from the registry as the target SID;

[0058] Obtaining the Ukey storing the target SID from the at least one Ukey as the target Ukey.

[0059] It should be noted that the same username can be set between the operating systems of different devices (for example, the usernames for logging in to the operating systems of device A and device B both include the username a). To avoid the cross - use of usernames between the operating systems of different devices (for example, using the username a for logging in to the operating system of device B to log in to the operating system of device A), in this embodiment, the Ukey bound to the target username is queried through the security identifier SID generated by the operating system for the target username (the SIDs corresponding to the username a for logging in to the operating system of device B and the username a for logging in to the operating system of device A are different).

[0060] The SID is a unique identifier generated by the operating system for each username, and the SIDs corresponding to the same username in different devices are also different. Therefore, when the SID corresponding to the target username is stored in the Ukey bound to the target username, it can be distinguished whether it is the Ukey bound to the target username through the SID.

[0061] In this embodiment, by querying the SID corresponding to the target username in the registry, since the SID can uniquely identify each username (for example, the same username in different devices), the Ukey bound to the target username can be located through the SID corresponding to the target username and the SIDs stored in each Ukey, avoiding the cross - abuse between the same usernames for logging in to different devices and improving the security of logging in to the operating system of the device.

[0062] Further, based on the above embodiments, after controlling to log in to the operating system of the device with the target username according to the verification result, it further includes:

[0063] After successfully logging in to the operating system of the device with the target username, if it is detected that the target Ukey is removed from the device, then control the operating system of the device to be in a disabled state.

[0064] To improve security, after detecting that the target Ukey bound to the target username is removed from the device, the operating system in the control device is disabled, avoiding continued execution of relevant operations on the operating system of the device after the target Ukey is removed and improving the security of the operating system.

[0065] Further, on the basis of the above embodiments, before controlling the operating system in the device to be in a disabled state, it further includes:

[0066] Determine whether the currently logged-in username is the target username. If so, transfer to the disabled state. If not, determine whether there is a Ukey bound to the currently logged-in username among the Ukeys currently accessing the device;

[0067] If there is a Ukey bound to the currently logged-in username among the Ukeys currently accessing the device, allow continued login to the operating system in the device. Otherwise, transfer to the disabled state.

[0068] It can be understood that after multiple usernames have successfully logged in to the operating system in the device, the username currently logged in to the operating system in the device can be switched through the account switching function. For example, after the target Ukey is removed from the device and the currently logged-in username is the target username, the operating system in the device is in a disabled state. However, after switching to another successfully logged-in username through the account switching function, if it is detected that the Ukey bound to the successfully logged-in username exists (i.e., has not been removed), then continued login to the operating system in the device with the successfully logged-in username is allowed, such that the operating system in the device is in an available state under the successfully logged-in username.

[0069] In this embodiment, when it is detected that the target Ukey is removed from the device, such that the operating system of the device is in a disabled state when the logged-in username is the target username, it avoids non-target username corresponding users from operating the operating system of the device after the target Ukey is removed. At the same time, when the username logged in to the operating system is switched from the target username to another successfully logged-in username, if the Ukey bound to the successfully logged-in username is connected to the device, then the operating system is available under the successfully logged-in username. On the one hand, it avoids operations on the operating system by non-normal logged-in users and improves the security of the operating system. On the other hand, it does not interfere with the use of the operating system by other normally logged-in users and ensures the availability of the operating system.

[0070] Further, on the basis of the above embodiments, before determining the target Ukey bound to the target username from at least one Ukey accessing the device, it further includes:

[0071] Obtain the time of the operating system when logging in to the operating system of the device with the target user name currently, as the system time at the time of this login;

[0072] Judge whether the system time at the time of this login of the target user name is later than the system time at the time of the previous login of the target user name, where the system time at the time of the previous login of the target user name is the time of the operating system when logging in to the operating system of the device with the target user name for the last time;

[0073] If the system time at the time of this login of the target user name is later than the system time at the time of the previous login, determine the target Ukey bound to the target user name from at least one Ukey connected to the device, otherwise, do not allow logging in to the operating system of the device with the target user name.

[0074] Among them, it may also include:

[0075] Judge whether the system time at the time of this login of the target user name is within the valid period set for logging in to the operating system of the device with the target user name. If so, determine the target Ukey bound to the target user name from at least one Ukey connected to the device, otherwise, do not allow logging in to the operating system of the device with the target user name.

[0076] The system time at the time of this login of the target user name being later than the system time at the time of the previous login of the target user name means that on the time axis from the past to the future, the system time at the time of this login of the target user name is closer to the future than the system time at the time of the previous login of the target user name.

[0077] By judging whether the system time at the time of this login of the target user name is later than the system time at the time of the previous login of the target user name, it is to prevent the user corresponding to the target user name from continuing to use the operating system outside the valid period of the operating system by modifying the time of the operating system.

[0078] For example, when the valid period for allowing logging in to the operating system of the device with the target user name is approaching the deadline, the user may modify the time of the operating system to an earlier time. For example, if the valid period expires on 20191012 and the current time is 20191101, the user may modify the time of the operating system to 20191001 so that the current login to the operating system is within the valid period.

[0079] In this embodiment, by determining whether the system time at the current login of the target username is later than the system time at the previous login of the target username, illegal operations of avoiding the expiration date by modifying the operating system time are avoided, which is beneficial to improving the security of logging in to the operating system of the device.

[0080] Further, on the basis of the above embodiments, before obtaining the target username and target password input when logging in to the operating system in the device, it further includes:

[0081] Authorize at least one administrator Ukey, wherein when logging in to the operating system in the device with different administrator Ukeys, different permissions for managing the operating system logged in to the device are owned.

[0082] At least one administrator Ukey may include a system administrator Ukey for binding the username and Ukey, a security administrator Ukey for setting login conditions, an audit administrator Ukey for querying logs and other information, and so on.

[0083] Each administrator Ukey can be authorized through an authorization tool, or a UKey authorization certificate can be applied for, and then the certificate information is imported into each administrator Ukey to achieve the authorization of the administrator Ukey.

[0084] In this embodiment, different permissions for managing the operating system logged in to the device are assigned to different administrator Ukeys. Compared with assigning all permissions for managing the operating system logged in to the device to the same administrator Ukey, the permissions of each administrator Ukey holder are weakened, and the security is improved.

[0085] Further, on the basis of the above embodiments, before obtaining the target username and target password input when logging in to the operating system in the device, it further includes:

[0086] When logging in to the operating system in the device with the system administrator Ukey among the at least one administrator Ukey, bind the username that is not currently bound to any Ukey and the Ukey that is not currently bound to any username; and / or,

[0087] When logging in to the operating system in the device with the security administrator Ukey among the at least one administrator Ukey, set the login conditions for logging in to the operating system in the device with any username; wherein, the login conditions include that when logging in to the operating system in the device with the any username, the system time at the current login is later than the system time at the previous login, and the expiration date for logging in to the operating system in the device with the any username; and / or,

[0088] When logging in to the operating system in the device with the audit administrator Ukey among the at least one administrator Ukey, query the login logs of logging in to the operating system in the device with any user name; wherein, the login logs include the system time when the target user name logged in last time.

[0089] Wherein, the system time when any user name logs in this time is the time of the operating system when currently logging in to the operating system in the device with the target user name; the system time when the target user name logged in last time is the time of the operating system when last logging in to the operating system in the device with the target user name.

[0090] Further, the binding of the user name that is not currently bound to any Ukey and the Ukey that is not currently bound to any user name includes:

[0091] Obtain the hardware key information of any Ukey from the Ukeys accessed to the device, and judge whether the any Ukey is bound to any user name according to the preset corresponding relationship and the hardware key information of the any Ukey. If so, continue to obtain the hardware key information of any un-traversed Ukey from the Ukeys accessed to the device. Otherwise, the any Ukey is not currently bound to any user name, and bind the user name that is not currently bound to any Ukey and the any Ukey.

[0092] Wherein, the hardware key information of the Ukey is the information used to identify the Ukey. For example, the hardware key information of a certain Ukey is the hardware identification code that uniquely identifies the Ukey.

[0093] For example, after opening the operating system, select to log in as an administrator, and access the system administrator Ukey, security administrator Ukey and audit administrator Ukey in the device. Then enter the user name and password corresponding to the system administrator Ukey. After passing the verification by the system administrator Ukey, you can select the Ukey that is not bound to any user name and the user name that is not bound to any Ukey through the interface to bind the two. Enter the user name and password corresponding to the security administrator Ukey. After passing the verification by the security administrator Ukey, you can set login conditions such as the validity period for each user name successfully bound to the Ukey through the interface. Enter the user name and password corresponding to the audit administrator Ukey. After passing the verification by the audit administrator Ukey, you can read the login logs of logging in to the operating system in the device through each successfully bound user name.

[0094] It should be noted that the login log can either include only the system time at the last login or the system time at each login for each username. When logging in to the operating system with the target username, the system time at the last login with the target username can be obtained from the login log, and then compared with the system time at the current login with the target username to determine whether the current login to the operating system of the device with the target username meets the login conditions set when logging in through the security administrator Ukey.

[0095] In this embodiment, one-to-one binding of usernames and Ukeys, setting of login conditions, and querying of log information are achieved through three administrator Ukeys (system administrator Ukey, security administrator Ukey, and audit administrator Ukey), ensuring secure login to the operating system of the device by username.

[0096] Figure 2 This is a schematic diagram of the process of binding a username and a Ukey after logging in to the operating system of the device through an authorized administrator Ukey provided in this embodiment. Figure 3 This is a schematic diagram of the verification process for logging in to the operating system of the device after binding a username and a Ukey provided in this embodiment. Refer to Figure 2 and Figure 3 , and the processes of binding and logging in include the following:

[0097] (1) Use the authorization tool to authorize the three administrator Ukeys or apply for a Ukey authorization certificate, and then import the certificate information into the three administrator Ukeys.

[0098] (2) Insert the authorized system administrator Ukey and install and register the secure login module. When installing, it will traverse the accounts and modify the passwords.

[0099] (3) Insert the authorized system administrator Ukey and use the system administrator account (sysadmin) to log in to the secure login configuration interface.

[0100] (4) Insert an unauthorized ordinary Ukey, and then select a local account for binding. If the inserted Ukey has been bound to a user, it will prompt to unbind it first before binding. If the selected user has been bound to a Ukey, it will prompt that user XXX has been bound to a Ukey, please unbind it before binding. (One user can only be bound to one Ukey, and one Ukey can only be bound to one user)

[0101] (5) Restart the computer. After entering the login interface, insert the UKEY that was just bound to the user, enter the username and PIN code (i.e., the entered password), click OK for PIN code authentication, and after successful authentication, log in to the system normally with the modified password.

[0102] In this embodiment, when logging in to the operating system, the hardware key information, the binding relationship between the local system account and the key, and the PIN code in the key are verified to ensure that only authorized personnel can log in to the safe mode.

[0103] Figure 4 The following is the structural block diagram of the operating system login device provided in this embodiment. Refer to Figure 4 , the operating system login device includes an acquisition module 401, a determination module 402, and a control module 403, where

[0104] The acquisition module 401 is configured to acquire a target username and a target password input when logging in to the operating system in the login device;

[0105] The determination module 402 is configured to determine a target Ukey bound to the target username from at least one Ukey connected to the device; where the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique;

[0106] The control module 403 is configured to input the target password into the target Ukey, obtain the verification result of the target Ukey for the target password, and control whether to allow logging in to the operating system in the device with the target username according to the verification result.

[0107] The operating system login device provided in this embodiment is applicable to the operating system login management method provided in each of the above embodiments, and will not be elaborated here.

[0108] This embodiment provides an operating system login device. The Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique. When a user logs in to the operating system of the device with a target username, the target Ukey bound to the target username verifies the target password, thereby realizing the control of logging in to the operating system in the device. The usernames and Ukeys for logging in to the operating system in the device adopt a one-to-one binding method. Compared with the situation where multiple usernames are bound to one Ukey, the risk of username theft is reduced. At the same time, compared with the situation where one username is bound to multiple Ukeys, the risk of Ukey theft is reduced. This one-to-one binding method reduces the risk of illegal login to the operating system due to username theft or Ukey theft.

[0109] Specifically, when multiple user names are bound to one Ukey, if the password in the Ukey is leaked, as long as any one of the multiple user names is leaked, it is possible for the operating system of the device to be illegally logged in. When one user name is bound to multiple Ukeys, after the user name is leaked, as long as the password in any one of the Ukeys is cracked, it is possible for the operating system of the device to be illegally logged in. It can be seen that when verifying the operating system of the logged-in device with the help of the Ukey, both the "one-to-many" or "many-to-one" binding methods have a relatively high risk of leakage of user names and passwords. In this application, for the user name and Ukey for logging in to the operating system of a certain device, the user name and password are bound in a "one-to-one" manner. If the password in the Ukey is leaked, only when the user name uniquely bound to the Ukey is leaked can it be possible for the operating system of the device to be illegally logged in. If the user name is leaked, only when the password in the Ukey uniquely bound to the user name is leaked can it be possible for the operating system of the device to be illegally logged in. It can be seen that the "one-to-one" binding method greatly reduces the risk of simultaneous leakage of user names and passwords compared with the "one-to-many" or "many-to-one" binding methods, and therefore is also beneficial to reducing the risk of illegal login to the operating system of the device.

[0110] Optionally, determining the target Ukey bound to the target user name from at least one Ukey accessing the device includes:

[0111] Obtaining the security identifier SID corresponding to the target user name from the registry as the target SID;

[0112] Obtaining the Ukey storing the target SID from the at least one Ukey as the target Ukey.

[0113] Optionally, after controlling to log in to the operating system in the device with the target user name according to the verification result, it further includes:

[0114] After successfully logging in to the operating system in the device with the target user name, if it is detected that the target Ukey is removed from the device, then control the operating system in the device to be in a disabled state.

[0115] Optionally, before controlling the operating system in the device to be in a disabled state, it further includes:

[0116] Judging whether the currently logged-in user name is the target user name. If so, transfer to the disabled state. If not, determine whether there is a Ukey bound to the currently logged-in user name among the Ukeys currently accessing the device;

[0117] If there is a Ukey bound to the currently logged-in username in the Ukey currently accessing the device, then continue to log in to the operating system of the device is allowed; otherwise, transfer to disabled.

[0118] Optionally, before determining the target Ukey bound to the target username from at least one Ukey accessing the device, it further includes:

[0119] Obtain the time of the operating system when currently logging in to the operating system of the device with the target username, as the system time at the time of this login;

[0120] Judge whether the system time at the time of this login of the target username is later than the system time at the time of the target username's previous login, where the system time at the time of the target username's previous login is the time of the operating system when last logging in to the operating system of the device with the target username;

[0121] If the system time at the time of this login of the target username is later than the system time at the time of the previous login, then determine the target Ukey bound to the target username from at least one Ukey accessing the device; otherwise, do not allow logging in to the operating system of the device with the target username.

[0122] Optionally, before obtaining the target username and target password input when logging in to the operating system of the device, it further includes:

[0123] Authorize at least one administrator Ukey, where when logging in to the operating system of the device with different administrator Ukeys, different permissions for managing the login to the operating system of the device are possessed.

[0124] Optionally, before obtaining the target username and target password input when logging in to the operating system of the device, it further includes:

[0125] When logging in to the operating system of the device with the system administrator Ukey among the at least one administrator Ukeys, bind the username that is not currently bound to any Ukey and the Ukey that is not currently bound to any username; and / or,

[0126] When logging in to the operating system of the device with the security administrator Ukey among the at least one administrator Ukeys, set the login conditions for logging in to the operating system of the device with any username; where the login conditions include that when logging in to the operating system of the device with any username, the system time at the time of this login is later than the system time at the time of the previous login, the expiration period for logging in to the operating system of the device with any username; and / or,

[0127] When logging in to the operating system in the device with the audit administrator Ukey among the at least one administrator Ukeys, query the login logs of logging in to the operating system in the device with any user name; wherein, the login logs include the system time when the target user name logged in last time.

[0128] Wherein, the system time when any user name logs in this time is the time of the operating system when currently logging in to the operating system in the device with the target user name; the system time when the target user name logged in last time is the time of the operating system when last logging in to the operating system in the device with the target user name.

[0129] Figure 5 An example of the entity structure diagram of an electronic device is as Figure 5 shown. The electronic device may include: a processor 501, a communication interface 502, a memory 503, and a communication bus 504. Among them, the processor 501, the communication interface 502, and the memory 503 complete mutual communication through the communication bus 504. The processor 501 can call the logical instructions in the memory 503 to execute the following method: obtain the target user name and target password input when logging in to the operating system in the device; determine the target Ukey bound to the target user name from at least one Ukey accessing the device; wherein, the Ukey bound to each user name for logging in to the operating system in the device is unique, and the user name bound to each Ukey for logging in to the operating system in the device is unique; input the target password into the target Ukey, obtain the verification result of the target Ukey for the target password, and control whether to allow logging in to the operating system in the device with the target user name according to the verification result.

[0130] In addition, when the logical instructions in the above-mentioned memory 503 are implemented in the form of a software functional unit and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. And the aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical disks and other various media that can store program codes.

[0131] Furthermore, an embodiment of the present invention discloses a computer program product, which includes a computer program stored on a non-transitory readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the methods provided in the above method embodiments, for example, including: obtaining a target username and a target password input when logging in to the operating system in the device; determining a target Ukey bound to the target username from at least one Ukey connected to the device; wherein, the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique; inputting the target password into the target Ukey, obtaining the verification result of the target Ukey for the target password, and controlling whether to allow logging in to the operating system in the device with the target username according to the verification result.

[0132] On the other hand, an embodiment of the present invention also provides a non-transitory readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the transmission methods provided in the above embodiments, for example, including: obtaining a target username and a target password input when logging in to the operating system in the device; determining a target Ukey bound to the target username from at least one Ukey connected to the device; wherein, the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique; inputting the target password into the target Ukey, obtaining the verification result of the target Ukey for the target password, and controlling whether to allow logging in to the operating system in the device with the target username according to the verification result.

[0133] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.

[0134] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for logging in to an operating system, characterized in that Including: Obtaining a target username and a target password input when acquiring the operating system in the logged-in device; Determining a target Ukey bound to the target username from at least one Ukey accessing the device; wherein, the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique; Inputting the target password into the target Ukey, obtaining the verification result of the target Ukey for the target password, and controlling whether to allow logging in to the operating system in the device with the target username according to the verification result.

2. The operating system login method according to claim 1, wherein The determining a target Ukey bound to the target username from at least one Ukey accessing the device includes: Obtaining a security identifier SID corresponding to the target username from the registry as the target SID; Obtaining the Ukey storing the target SID from the at least one Ukey as the target Ukey.

3. The operating system login method according to claim 1, wherein, After controlling to log in to the operating system in the device with the target username according to the verification result, further including: After successfully logging in to the operating system in the device with the target username, if it is detected that the target Ukey is removed from the device, controlling the operating system in the device to be in a disabled state.

4. The operating system login method according to claim 3, wherein Before controlling the operating system in the device to be in a disabled state, further including: Judging whether the currently logged-in username is the target username, if so, turning to disable, if not, determining whether there is a Ukey bound to the currently logged-in username among the Ukeys currently accessing the device; If there is a Ukey bound to the currently logged-in username among the Ukeys currently accessing the device, allowing to continue logging in to the operating system in the device, otherwise turning to disable.

5. The operating system login method according to claim 1, wherein Before determining a target Ukey bound to the target username from at least one Ukey accessing the device, further including: Obtaining the time of the operating system when currently logging in to the operating system in the device with the target username as the system time at the time of this login; Judging whether the system time at the time of this login of the target username is later than the system time at the time of the previous login of the target username, wherein the system time at the time of the previous login of the target username is the time of the operating system when last logging in to the operating system in the device with the target username; If the system time at the time of this login of the target username is later than the system time at the time of the previous login, determining a target Ukey bound to the target username from at least one Ukey accessing the device, otherwise, not allowing to log in to the operating system in the device with the target username.

6. The operating system login method according to claim 1, wherein, Before obtaining the target username and the target password input when acquiring the operating system in the logged-in device, further including: Authorizing at least one administrator Ukey, wherein when logging in to the operating system in the device with different administrator Ukeys, different permissions for managing the login to the operating system in the device are possessed.

7. The operating system login method according to claim 6, characterized in that, Before obtaining the target username and target password input when logging in to the operating system in the logged-in device, it further includes: When logging in to the operating system in the device with the system administrator Ukey among the at least one administrator Ukeys, binding the username that is not currently bound to any Ukey and the Ukey that is not currently bound to any username; and / or, When logging in to the operating system in the device with the security administrator Ukey among the at least one administrator Ukeys, setting the login conditions for logging in to the operating system in the device with any username; wherein, the login conditions include that when logging in to the operating system in the device with any username, the system time of this login is later than the system time of the previous login, and the validity period for logging in to the operating system in the device with any username; and / or, When logging in to the operating system in the device with the audit administrator Ukey among the at least one administrator Ukeys, querying the login log of logging in to the operating system in the device with any username; wherein, the login log includes the system time of the previous login of the target username; Wherein, the system time of this login of any username is the time of the operating system when currently logging in to the operating system in the device with the target username; the system time of the previous login of the target username is the time of the operating system when last logging in to the operating system in the device with the target username.

8. An operating system login device, characterized in that, It includes: An acquisition module, configured to acquire the target username and target password input when logging in to the operating system in the logged-in device; A determination module, configured to determine the target Ukey bound to the target username from at least one Ukey accessing the device; wherein, the Ukey bound to each username for logging in to the operating system in the device is unique, and the username bound to each Ukey for logging in to the operating system in the device is unique; A control module, configured to input the target password into the target Ukey, obtain the verification result of the target Ukey for the target password, and control whether to allow logging in to the operating system in the device with the target username according to the verification result.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the operating system login method according to any one of claims 1 to 7.

10. A non-transitory readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, it implements the steps of the operating system login method according to any one of claims 1 to 7.

11. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory readable storage medium, the computer program includes program instructions, and when the program instructions are executed by a computer, the computer can execute the steps of the operating system login method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Computer system, and user identity recognition method implemented by system

    CN107864145A

  • User authentication method and device and storage medium

    CN110661784A