A method for secure password entry
By partially scrambling and real-time updating the soft keyboard layout, combined with a multi-digit obfuscated password method that conceals prompts and uses markers for input, the inconvenience and inadequacy of existing secure soft keyboards are solved, achieving higher usability and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FUJIAN NORCA TECH
- Filing Date
- 2022-11-01
- Publication Date
- 2026-06-02
AI Technical Summary
The existing secure soft keyboards use a randomized keyboard layout, which makes them inconvenient to use and cannot effectively defend against attacks such as shoulder spying and filming.
A soft keyboard layout with partial scrambling and real-time updates is adopted. Combined with a multi-digit obfuscated password method that conceals the transmission of prompts and uses marker input, three password input schemes are designed, including a fixed-length obfuscated password that conceals the transmission of prompts, a variable-length obfuscated password that uses marker input, and a combination of the two.
It improves the usability of the secure soft keyboard, enhances password security, effectively resists attacks such as spying and filming, and reduces the cognitive burden on users.
Smart Images

Figure CN115718542B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information security technology, and specifically relates to a method for inputting secure passwords. Background Technology
[0002] Existing secure soft keyboards completely shuffle the keyboard layout to resist mouse logging attacks and improve password security. However, the shuffled keyboard layout contradicts people's usual layout, requiring some time to find the real password, which causes inconvenience and cannot effectively resist attacks such as shoulder spying and camera shooting. Summary of the Invention
[0003] The purpose of this invention is to provide a method for secure password input that can improve the usability of secure soft keyboards while ensuring password security.
[0004] To achieve the above objectives, the solution of the present invention is:
[0005] A method for inputting a secure password includes the following steps:
[0006] Step 1: Set the soft keyboard layout and reset it every time the user clicks any key on the soft keyboard.
[0007] Step two: The user first enters the username on the client device and submits it to the authentication server, and then enters the password data based on the password input scheme selected when registering the account;
[0008] Step 3: The client device uses the preset password security input scheme for the account name returned by the authentication server to extract the real password data;
[0009] Step four: After the client device extracts the real password data, it will use it together with the account name for identity verification.
[0010] By adopting the above solution, the present invention has the following beneficial effects:
[0011] (1) In view of the inconvenience of the method of completely scrambling the keyboard layout of the security soft keyboard, the present invention designs a security soft keyboard based on partial scrambling and real-time updating. The partial scrambling method is used to control the range of randomization and improve the usability of the security soft keyboard. At the same time, the real-time updating mechanism is combined to take into account the security of the password.
[0012] (2) Based on the concept of obfuscated password input, this invention designs two password input methods: one is to input a fixed-length multi-digit obfuscated password by using a method of covertly transmitting prompt information, and the other is to input a variable-length multi-digit obfuscated password by using a marker. This further enhances password security and can effectively resist attacks such as peeping or filming. Attached Figure Description
[0013] Figure 1 This is a flowchart of the present invention;
[0014] Figure 2 This is a schematic diagram of the soft keyboard display after partial scrambling in this invention;
[0015] Among them, (a) is a schematic diagram of letter keys, (b) is a schematic diagram of number keys, and (c) is a schematic diagram of special symbol keys;
[0016] Figure 3 This is a schematic diagram of the password input process in this invention;
[0017] Figure 4 This is a schematic diagram of the password extraction process in this invention. Detailed Implementation
[0018] The technical solution and beneficial effects of the present invention will be described in detail below with reference to the accompanying drawings.
[0019] like Figure 1 As shown, the present invention provides a method for inputting a secure password, comprising the following steps:
[0020] S1 partially scrambles the soft keyboard content and updates it in real time;
[0021] This invention is a secure soft keyboard based on a 26-key layout design, featuring partial scrambling and real-time updates, and only scrambling the letters, numbers, and special symbols:
[0022] The specific process of partial scrambling is as follows: First, the client device generates a pseudo-random number; second, the client device uses the random number to randomly scramble n1 letters, n2 numbers, and n3 special symbols on the soft keyboard; finally, the scrambled characters are highlighted to reduce the cognitive burden on the user.
[0023] The specific content of the real-time update is as follows: after each click of any key on the software keyboard, the software keyboard will repeat the above steps to update the keyboard in real time, and randomly shuffle the aforementioned n1 letters, n2 numbers and n3 special symbols again in a localized manner.
[0024] Among them, n1, n2 and n3 can be set by the user, and can usually be set to 26≥n1≥5, 10≥n2≥3, 26≥n3≥5; Figure 2 The image shows the soft keyboard layout for n1=5, n2=3, n3=5, where the letters dgtqu, the numbers 795, and the special symbols \《^.? are highlighted.
[0025] S2, Enter password data according to the password security input scheme;
[0026] Cooperate Figure 3 As shown, the user needs to enter their username on the client device and click submit. The client device sends the username to the authentication server through a secure transmission channel, requesting the password security input scheme serial number and related settings parameters selected during account registration, so as to extract the real password data later. The user then enters the password using a partially scrambled soft keyboard, relying on the password input scheme selected during account registration from memory.
[0027] This invention designs three password input schemes, assuming the actual password is PW = {pw1, pw2, ..., pw...} i ,...,pw m}, i∈[1,m], the three password input schemes will be explained below.
[0028] If the password input method set during user registration is Scheme 1, and the password is input by means of a fixed-length, multi-digit obfuscated password through a hidden message, the specific steps for password input are as follows:
[0029] Step 1: The user enters a real password, pw. i (pw i After entering ∈PW, i∈[1,m-1]), observe whether the client device vibrates. If so, enter k obfuscated characters, and then enter the next real password pw. i+1 Meanwhile, the client device records the phenomenon and its position in the password; if not, proceed to the next step (k is set by the user during account registration, and k≥0 is required);
[0030] Step 2: The user chooses whether to activate the method of constructing a prompt message to input the obfuscated password. If so, pause and double-click (instead of quickly double-clicking) the uppercase toggle key as the prompt message, then input 1 obfuscated character, and finally input the next real password, pw. i+1 Simultaneously, the client device records this phenomenon and its position in the password; otherwise, it directly enters the next real password, pw. i+1 (l can be customized by the user during account registration, and l≥0 is required);
[0031] Step 3: Determine if the password input is complete. If yes, stop password input and click "Login". If not, repeat steps 1 and 2.
[0032] The client device will monitor the password input status in real time. If the user constructs a prompt message, it will wait for the user to input l obfuscated characters before automatically determining whether to emit vibration. If a vibration is triggered, it will wait for the user to input k obfuscated characters before automatically determining whether to emit vibration. To prevent attackers from obtaining the vibration sound, the client device will emit simulated vibration noise to hide the vibration sound or disrupt the attacker's judgment of the sound, regardless of whether vibration is actually present. Simultaneously, to prevent vibration interference from other notifications on the client device, the vibration of other notifications will be masked during the password input process.
[0033] The method described in this password input scheme, which uses vibration of the client device to convey concealed information and pauses to double-click the Caps Lock key to construct prompts, can be replaced with other suitable methods as needed, such as sound or clicking on a blank area of the screen.
[0034] If the password input method set during user registration is scheme 2, a variable-length, multi-digit obfuscated password is input using markers. This method inputs a p-digit obfuscated password cpw before the password PW. st After PW, enter the q-digit obfuscated password cpw ed When p > 2, the first two characters of the obfuscated password can be set as identifiers, used to input obfuscated characters in any interval within the password. Considering that the identifiers may be similar to the real password characters, causing conflicts, this embodiment provides two anti-competition mechanism schemes to handle the conflict problem, and users can customize the settings (where p and q are customized by the user during account registration):
[0035] The specific implementation steps for password input based on anti-contention scheme 1 are as follows:
[0036] Step 1: The user first enters the obfuscated password CPW st ={cpw st,1 ,...,cpw st,i ,...,cpw st,p}, p≥0, i∈[1,p]; the user determines whether p satisfies p>2 and cpw st,1 and cpw st,2 Does it satisfy: cpw st,1 ≠cpw st,2 ≠cpw st,i ≠cpw i (where: cpw) st,1 ,cpw st,2 ,cpw st,i ∈CPW st ,i∈[3,p],cpw i∈PW, i∈[1,m], and case-sensitive), if both are true, then record flag=1, otherwise record flag=0, and continue to the next step;
[0037] Step 2: The user enters a real password, pw. i (pw i After ∈PW, i∈[1,m-1]), if flag=1 and the user wants to input a multi-digit obfuscated password, the user can use the identifier cpw st,1 and cpw st,2 Set the obfuscated password range, enter the obfuscated password: CPW rd ={cpw st,1 ,cpw rd,1 ,...,cpw rd,i ,...,cpw rd,u ,cpw st,2}, u≥1, i∈[1,u],cpw rd,i ≠cpw st,1 ≠cpw st,2 Finally, enter the next real password, pw. i+1 If flag=0, or flag=1 and the user does not want to enter a multi-digit obfuscated password, then directly enter the next real password pw. i+1 Proceed to the next step;
[0038] Step 3: Check if the password input has ended. If not, repeat steps 1 and 2; if yes, enter the obfuscated password CPW. ed ={cpw ed,1 ,...,cpw ed,i ,...,cpw ed,q}, q≥0, i∈[1,q], then click login.
[0039] The specific steps for implementing password input based on anti-contention scheme 2 are as follows:
[0040] Step 1: The user first enters the obfuscated password CPW st ={cpw st,1 ,...,cpw st,i ,...,cpw st,p}, p≥0, i∈[1,p];
[0041] Step 2: Enter a real password pw i (pw i After ∈PW, i∈[1,m-1]), if the user wants to enter a multi-digit obfuscated password, the user can use the identifier cpw st,1 and cpw st,2 Randomly select a range of obfuscated passwords, and enter the obfuscated password: CPWrd ={cpw st,1 ,cpw rd,1 ,...,cpw rd,i ,...,cpw rd,u ,cpw st,2}, u≥1, i∈[1,u]. (where, in the input cpw st,1 and cpw st,2 Beforehand, the user needs to construct a prompt message by clicking the keyboard to collapse and reopen the input field, informing the system that the character is an identifier (this prompt message needs to be different from the prompt message in password input scheme 1)). Finally, the user enters the next digit of the real password, pw. i+1 Meanwhile, the client device will record this phenomenon and its position in the password; otherwise, it will directly enter the next real password, pw. i+1 .
[0042] Step 3: Check if the password input is complete. If not, repeat steps 1 and 2; if yes, enter the obfuscated password CPW. ed ={cpw ed,1 ,...,cpw ed,i ,...,cpw ed,q}, q≥0, i∈[1,q], then click login.
[0043] The method of constructing prompt information by clicking the keyboard collapse and reopen button in the password input scheme based on anti-competition scheme 2 can be replaced with other suitable methods as needed, such as clicking on a blank area of the screen.
[0044] If the password input method set during user registration is scheme 3, then the password input is based on a combination of schemes 1 and 2 mentioned above. The specific implementation steps are as follows:
[0045] Step 1: The user first randomly inputs p characters as the obfuscation password CPW according to their needs. st If the user chooses to randomly enter multiple variable-length obfuscated passwords during subsequent password input, then CPW st If p≥2 is satisfied, and flag=1 is recorded, proceed to the next step; otherwise, any character can be entered as the obfuscated password, and flag=0 is recorded, proceed to the next step.
[0046] Step 2: The user enters the first real password, pw. i (i=1);
[0047] Step 3: If the user receives a vibration prompt from the client device before entering the next real password, then enter k arbitrary characters as obfuscation characters and proceed to Step 6. If there is no prompt, proceed to the next step.
[0048] Step 4: If flag = 0, the user can choose whether to construct a prompt message. If yes, pause, double-click the uppercase key, enter 1 arbitrary character as the obfuscation character, and jump to Step 6. If no such character is found, jump to Step 6. If flag = 1, proceed to the next step.
[0049] Step 5: User-defined password input scheme: Scheme 1: Construct a prompt message to input a coded password; Scheme 2: Set a coded password range; Scheme 3: Do not input a coded password. If 1 is selected, pause, double-click the Caps Lock key, and then input 1 arbitrary character as the coded character before proceeding to the next step; if 2 is selected, use the identifier cpw. st,1 and cpw st,2 Set the obfuscated password range, enter any random character within the range, and proceed to the next step; if you select 3, proceed directly to the next step.
[0050] Step 6: Enter the next password pw i+1 Check if i+1 is equal to m. If not, go to step 3; if equal, proceed to the next step.
[0051] Step 7: Enter any character in position q as the obfuscation password CPW ed Then enter the number 'q' to end the password input and click 'Login'.
[0052] Note: The vibration trigger is randomly selected by the client device. To distinguish between the real password and the obfuscated password, the client device will monitor the password input status in real time. If the current user selects password input scheme 1, the device's vibration trigger mechanism will only trigger again after the user inputs 1 or k digits of obfuscated password. If the current user selects password input scheme 2, the device's vibration trigger mechanism will only trigger again after the user inputs the prompt message and the identifier cpw. st,2 Only after that can it be triggered again; if the current user selects password input scheme 3, the device can directly and randomly decide whether to trigger the vibration mechanism.
[0053] S3, extract the password based on the password security input scheme used when entering the password;
[0054] Cooperate Figure 4 Assume the user's final password input according to the password security input scheme is PW last (PW last ={pw lt,1 ,....,pw lt,i ,...,pw lt,h), i∈[1,h], the client device will use the password input scheme number and related parameter settings set by the user as fed back by the authentication server to eliminate obfuscated passwords and extract the real password.
[0055] If the password input set during user registration is scheme 1, the specific steps for password retrieval scheme 1 are as follows:
[0056] Step 1: Determine if the client device has a record of triggering vibration. If so, find the obfuscated password data entered according to the prompt message issued by the client device based on the vibration location, vibration frequency, and k value recorded by the client device, and delete it; if not, proceed to the next step.
[0057] Step 2: Determine if the client device has a record of user-constructed prompt messages. If so, find the obfuscated password data used to construct the prompt messages based on the location, frequency, and l value recorded on the client device and delete it. If not, proceed to the next step.
[0058] Step 3: At this point, the password PW has been entered. last The obfuscated passwords have been removed.
[0059] If the password input set during user registration is scheme 2, the specific steps for password retrieval scheme 2 are as follows:
[0060] Step 1: Determine if p is greater than or equal to 2. If so, extract pw. lt,1 (that is, p) and pw lt,h (that is, q), PW last The second and third characters of the password are denoted as the identifier cpw. st,2 and cpw st,3 and PW last Delete the password data in the first p position and proceed to the next step. Otherwise, delete the PW. last Deleting the first p and last q bits of the password data will give you the actual password data.
[0061] Step 2: Relying on the identifier cpw st,1 and cpw st,2 The obfuscated password range is found by comparing it with the prompts recorded by the client device and then deleted. The password data obtained at this point is recorded as the real password data.
[0062] If the password input set during user registration is scheme 3, the specific steps for password retrieval scheme 3 are as follows:
[0063] Step 1: Determine if p is greater than or equal to 2. If so, extract pw. lt,1 (that is, p) and pwlt,h (that is, q), PW last The second and third characters of the password are denoted as the identifier cpw. st,2 and cpw st,3 If yes, proceed to the next step; otherwise, proceed directly to the next step.
[0064] Step 2: Delete PW last The first p-digit password is pw lt,1 ,...,pw lt,p , and the password pw after q lt,h-q ,....,pw lt,h ;
[0065] Step 3: Determine if the client device has a record of triggering vibration. If so, find the obfuscated password data entered according to the prompt message issued by the client device based on the vibration location, vibration frequency, and k value recorded by the client device, and delete it; if not, proceed to the next step.
[0066] Step 4: Determine if the client device has a record of user-constructed prompt messages. If so, find the obfuscated password data used to construct the prompt messages based on the location, frequency, and l value recorded on the client device and delete it. If not, proceed to the next step.
[0067] Step 5: Relying on the identifier cpw st,1 and cpw st,2 The obfuscated password range is found by comparing it with the prompts recorded by the client device and then deleted. The password data obtained at this point is recorded as the real password data.
[0068] S4 uses the extracted password for identity authentication.
[0069] After the client device extracts the real password data, it will use it together with the account name for identity authentication.
[0070] In summary, this invention designs a secure soft keyboard based on local scrambling and real-time updates, controlling the randomization range and improving ease of use. Furthermore, based on the concept of obfuscated password input, it proposes a method for secure password input. This method includes two password input methods: inputting fixed-length multi-digit obfuscated passwords using covertly transmitted prompts and inputting variable-length multi-digit obfuscated passwords using markers. These three password security schemes further enhance password security, ensuring that even under attacks such as peeping or photography, attackers cannot obtain the true password data.
[0071] The above embodiments are merely illustrative of the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made to the technical solutions based on the technical concept proposed in this invention shall fall within the scope of protection of this invention.
Claims
1. A method for inputting secure passwords, characterized in that... Includes the following steps: Step 1: Set the soft keyboard layout and reset it every time the user clicks any key on the soft keyboard. Step two: The user first enters the username on the client device and submits it to the authentication server, and then enters the password data based on the password input scheme selected when registering the account; Step 3: The client device uses the preset password security input scheme for the account name returned by the authentication server to extract the real password data; Step 4: After the client device extracts the real password data, it will use it together with the account name for identity verification. In step two, it is assumed that the actual password is The specific steps for the password input scheme are as follows: Step 11, the user enters a real password. Afterwards, observe whether the client device vibrates. If it does, input... Obfuscation characters, then enter the next real password. Meanwhile, the client device records this phenomenon and its position in the password; If not, proceed to the next step; Step 12: The user chooses whether to activate the method of constructing a prompt message to input an obfuscated password. If so, the user pauses, double-clicks the uppercase toggle key as a prompt message, and then enters the password. After obfuscating the password, enter the next real password digit. Simultaneously, the client device records this phenomenon and its position within the password; otherwise, it directly enters the next digit of the real password. ; Step 13: Determine if the password input is complete. If yes, stop password input and click "Login". If not, repeat steps 11 and 12.
2. The method as described in claim 1, characterized in that: In step one, when setting the soft keyboard layout, only the keys corresponding to letters, numbers, and special symbols are partially shuffled. First, the client device generates pseudo-random numbers; then, the client device uses the random numbers to shuffle the keys in the soft keyboard. Letters Numbers and The special symbols are randomly shuffled; finally, the shuffled characters are highlighted.
3. The method as described in claim 2, characterized in that: In step one, after each time the user clicks any key on the soft keyboard, the [key / function] is re-evaluated. Letters Numbers and A special symbol is randomly shuffled.
4. The method as described in claim 1, characterized in that: In step three, the specific steps for extracting the real password are as follows: Step 14: Determine if the client device has a record of triggering vibration. If so, determine the vibration location, number of vibrations, and... Find the obfuscated password data entered based on the prompt message from the client device and delete it; If not, proceed to the next step; Step 15: Determine if the client device has a record of user-constructed prompts. If so, determine the location, frequency, and other details of the prompts recorded on the client device. Find the obfuscated password data entered in the construct prompt message and delete it; If not, proceed to the next step; Step 16: At this point, the password has been passed. The obfuscated passwords have been removed.
5. The method as described in claim 1, characterized in that: In step two, it is assumed that the actual password is The password input scheme is then set as follows: a variable-length, multi-digit obfuscated password is input via a marker, and the password... Previous input Obfuscated password and Enter after Obfuscated password ,when When the password is obfuscated, the first two characters of the obfuscated password are set as identifiers, which are used to input obfuscated characters in any interval in the middle of the password.
6. The method as described in claim 5, characterized in that: In step three, the specific steps for extracting the real password are as follows: Step 21, Determine Is it greater than or equal to 2? If so, extract. and ,in, That is , That is ;Will The second and third characters of the password are recorded as identifiers. and and will Center front Delete the password data and proceed to the next step. Otherwise, proceed to the next step. Center front Position and after Deleting the password data will give you the real password data. Step 21, relying on identifiers and The obfuscated password range is found by comparing it with the prompts recorded by the client device and then deleted. The password data obtained at this point is recorded as the real password data.
7. The method as described in claim 1, characterized in that: In step two, it is assumed that the actual password is The specific steps for the password input scheme are as follows: Step 31: The user first inputs randomly according to their needs. Any character used as a decryption password If the user chooses to randomly enter multiple variable-length obfuscated passwords during the subsequent password input process, then Must meet And record Proceed to the next step; If none is available, enter any characters as a password to obfuscate the password, and record them. Proceed to the next step; Step 32, the user enters the first real password. ; Step 33: If the user receives a vibration notification from the client device before entering the next digit of the real password, then enter... If any character is used as the obfuscation character, proceed to step 36. If there is no prompt, proceed to the next step. Step 34, if If the user chooses whether to construct a prompt message, then after pausing and double-clicking the capitalization toggle key, the user can enter the message. If any character is used as an obfuscation character, proceed to step 36; if none is found, proceed to step 36. Proceed to the next step; Step 35: The user selects a password input scheme: Scheme 1: Construct a prompt message to input a cryptic password; Scheme 2: Set a cryptic password range; Scheme 3: Do not input a cryptic password. If option 1 is selected, the user will pause, double-click the Caps Lock key, and then input the password. Use any character as an obfuscation character and proceed to the next step; If option 2 is selected, use the identifier. and Set a password obfuscation range, randomly enter any characters within the range, and proceed to the next step; If you choose option 3, proceed directly to the next step; Step 36, enter the next password ,judge Is it equal to If it is not equal, proceed to step 3; if it is equal, proceed to the next step. Step 37, Input Any character used as a decryption password Enter the numbers again. To end the password input, click Login.
8. The method as described in claim 7, characterized in that: In step three, the specific steps for extracting the real password are as follows: Step 38, Determine Is it greater than or equal to 2? If so, extract. and ,in, That is , That is ;Will The second and third characters of the password are recorded as identifiers. and If yes, proceed to the next step; otherwise, proceed directly to the next step. Step 39, Delete forward password , and after password ; Step 310: Determine if the client device has a record of triggering vibration. If so, determine the vibration location, number of vibrations, and... If the value is not found, locate the obfuscated password data entered according to the prompt message issued by the client device and delete it; if not, proceed to the next step. Step 311: Determine if the client device has a record of user-constructed prompt messages. If so, determine the location, frequency, and other information of the prompt messages recorded on the client device. If the value is not found, locate the obfuscated password data entered in the construction prompt message and delete it; if not, proceed to the next step. Step 312, relying on identifiers and The obfuscated password range is found by comparing it with the prompts recorded by the client device and then deleted. The password data obtained at this point is recorded as the real password data.