Personal strong password management method, system and electronic device based on PKI

Through the PKI-based personal strong password management method and the use of asymmetric key encryption technology, the problem of users having difficulty managing multiple strong passwords is solved, safe and efficient password management and display are achieved, and information security is improved.

CN115801345BActive Publication Date: 2025-10-10SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211353118.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-31
Publication Date
2025-10-10
Estimated Expiration
2042-10-31

AI Technical Summary

Technical Problem

In the prior art, it is difficult for users to remember multiple complex strong passwords, and existing password management software has information security risks and cannot effectively manage and display pre-stored strong passwords.

Method used

A personal strong password management method based on PKI is adopted. Through asymmetric key encryption technology, strong password data packets are stored in the cloud server and decrypted and displayed through pre-made Ukey devices, avoiding users from remembering passwords and improving security and management efficiency.

Benefits of technology

This eliminates the need for users to remember multiple passwords, improves the security and efficiency of password management, and ensures that strong passwords are only displayed on Ukey devices to prevent data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801345B_ABST
    Figure CN115801345B_ABST
Patent Text Reader

Abstract

The application discloses a PKI-based personal strong password management method, system and electronic equipment, and comprises the following steps: obtaining login request data, wherein the login request data comprises account data and login background information; the login background information is a website name or address to be logged in or a software name to be logged in; according to the login request data, a first password data package associated with the login request data is sent to a prefabricated Ukey device through a second control carrier; the prefabricated Ukey device decrypts the first password data package to obtain a specified password, and the specified password is displayed on the prefabricated Ukey device; and the second control carrier is installed on a second control terminal device. Compared with the prior art, the technical scheme disclosed by the application can avoid user's memory of account passwords on different platforms, can safely display strong passwords pre-stored on a server, and can improve the security of password management and the efficiency of password batch management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of system encryption technology, and in particular to a personal strong password management method based on PKI. The present invention also relates to a system and electronic equipment for running the personal strong password management method based on PKI. Background Art

[0002] my country is paying more and more attention to network security. Cryptography technology, as the most economical, reliable and effective means of protecting data security, can effectively separate and protect data ownership, usage rights and management rights. However, there is also the risk of serious system and data losses due to the loss or theft of confidential information. Currently, many software for confidential information and key management use the public AES algorithm, which is symmetric encryption. Its data transformation details are public, and the security of the algorithm depends only on the algorithm key. Others can analyze or crack the encrypted information if they know some of the algorithm implementation details, which poses a hidden danger to its information security.

[0003] At the same time, due to information security concerns, it is generally recommended to use strong passwords, meaning passwords that are not easily guessed or cracked. Strong passwords are complex and difficult to remember, especially when an individual uses multiple strong passwords, which can easily lead to confusion or forgetfulness.

[0004] Therefore, how to provide a solution to the problem that can avoid users from memorizing account passwords on different platforms, can securely display strong passwords pre-stored on the server, improve the security of password management, and improve the efficiency of batch password management has become a goal that needs to be urgently accomplished by those skilled in the art. Summary of the Invention

[0005] To address the aforementioned technical issues, the present invention primarily aims to provide a PKI-based strong personal password management method. This method eliminates the need for users to memorize their accounts and passwords across different platforms, securely displays strong passwords pre-stored on a server, and improves the security and efficiency of batch password management. Furthermore, the present invention also provides a PKI-based strong personal password management system and electronic device, which also achieve the aforementioned beneficial effects.

[0006] To achieve the above object, the application provides a PKI-based personal strong password management method, which comprises the following steps: obtaining login request data, wherein the login request data comprises account data and login background information, the login background information is a website name or address to be logged in or a software name to be logged in; sending a first password data packet associated with the login request data to a pre-made Ukey device through a second control carrier according to the login request data, the pre-made Ukey device decrypts the first password data packet to obtain a specified password, and the specified password is displayed on the pre-made Ukey device; wherein the second control carrier is installed on a second control terminal device.

[0007] Further, in the PKI-based personal strong password management method provided by the application, a cloud server obtains login request data; the cloud server sends a first password data packet associated with the login request data to a pre-made Ukey device through a second control carrier according to the login request data.

[0008] Further, in the PKI-based personal strong password management method provided by the application, the method further comprises the following steps: encrypting the specified password through an asymmetric key and storing the encrypted specified password in the cloud server in the form of a first password data packet.

[0009] Further, in the PKI-based personal strong password management method provided by the application, the method further comprises the following steps: registering user information: logging in the second control terminal device through a mobile phone short message verification code, inputting registration information into the second control carrier, the registration information comprising an account name, a device number and associated information of the second control terminal device; the second control carrier uploads the registration information to the cloud server, the cloud server establishes account information after verifying the registration information; installing a first control carrier on a first control terminal device and logging in the account information on the first control carrier; the first control carrier uploads device information of the current first control terminal device to the cloud server, and the device information is bound to the account information.

[0010] Further, in the PKI-based personal strong password management method provided by the application, the method further comprises the following steps: the first control carrier downloads registration information related to the account information from the cloud server.

[0011] Furthermore, in the PKI-based personal strong password management method provided by the present invention, the method also includes a method for prefabricating a Ukey device: connecting the Ukey device to the first control terminal device data; the first control carrier performs a certificate operation on the Ukey device to obtain certificate information, and the certificate information includes the private key password and validity period information of the asymmetric key; the first control carrier uploads the certificate request information to the cloud server, and the certificate request information includes the account information currently logged into the first control carrier and the device information of the first control terminal device where the first control carrier is currently located; after the cloud server verifies that the certificate request information is passed, the first control carrier issues a digital certificate to the Ukey device to obtain a prefabricated Ukey device; the digital certificate includes: the account information, the device information bound to the account information, and the private key password of the asymmetric key.

[0012] Furthermore, in the PKI-based personal strong password management method provided by the present invention, the method also includes a method for entering the designated password: performing a first entry operation or a second entry operation; the first entry operation: entering the designated password and password-related information to be managed in the first control carrier, the password-related information including usage context information, the usage context information being a website / connection external server address; the first control carrier encrypts the designated password using the public key of the asymmetric key to obtain a first password data packet; and saves the encrypted ciphertext for query; the first control carrier synchronizes the password-related information to the second control carrier;

[0013] The second entry operation: enter the specified password and password-related information to be managed in the second control carrier, where the password-related information includes usage context information, which is the URL / connection external server address; the second control carrier encrypts the specified password using the public key of the asymmetric key to obtain a first password data packet; and saves the encrypted ciphertext for future query; the second control carrier synchronizes the password-related information to the first control carrier.

[0014] In addition, this solution also provides a personal strong password management system based on PKI, which includes: a first acquisition module for obtaining login request data, the login request data including: account data, login background information, the login background information being the name or address of the website to be logged in, and the name of the software to be logged in; a first sending module for sending a first password data packet associated with the login request data to a prefabricated Ukey device through a second control carrier according to the login request data, the prefabricated Ukey device decrypts the first password data packet to obtain a specified password, and displays the specified password on the prefabricated Ukey device; wherein, the second control carrier is installed on a second control terminal device.

[0015] In addition, this solution also provides a personal strong password management system based on PKI, which includes: a cloud server for storing data and verifying data; a first control carrier connected to the cloud server for assisting in password management and certificate issuance, and the first control carrier is installed on a first terminal device; a second control software connected to the cloud server for verifying information login and password management, and the second control software is installed on a second terminal device; a Ukey device connected to the first control carrier and the second control software for decrypting passwords and authorizations.

[0016] Furthermore, in the PKI-based personal strong password management method provided by the present invention, the data storage module of the cloud server is used to store the following information: a encrypted file information, pre-stored passwords; b user registration information; c the installation package of the first control carrier, the installation package of the second control software; the data analysis module of the cloud server is used to process the following information: a new user registration information; b certificate verification information; c encrypted file / password acquisition request data information.

[0017] In addition, the present solution also provides an electronic device, which includes: a memory, the memory being used to store software for executing the PKI-based personal strong password management method; and a processor, the processor being used to process the software.

[0018] The present invention provides a personal strong password management method based on PKI, which specifically includes the following technical contents: obtaining login request data, the login request data including: account data, login background information, the login background information being the name or address of the website to be logged in, and the name of the software to be logged in; according to the login request data, sending the first password data packet associated with the login request data to the prefabricated Ukey device through the second control carrier, the prefabricated Ukey device decrypts the first password data packet to obtain the specified password, and displays the specified password on the prefabricated Ukey device; wherein the second control carrier is installed on the second control terminal device. Compared with the prior art, the technical solution of the present invention, after obtaining the login request data, sends the first password data packet associated with the login request data to the prefabricated Ukey device through the second control carrier according to the login request data. Specifically, the login data includes account data and login context information, and the account data and login context information are bound to a pre-stored strong password to obtain a first password data packet. By matching the account data and login context information, the first password data packet containing the strong password can be quickly identified and filtered from the database. The server sends the first password data packet to the pre-made Ukey device via the second control carrier, and the pre-made Ukey device decrypts the first password data packet. It should be noted here that the first password data packet is the result of encrypting the pre-entered strong password in the form of an asymmetric key. The strong password is encrypted using the associated user's asymmetric public key to facilitate the user to decrypt it using the corresponding asymmetric private key on the Ukey device. After the pre-made Ukey device decrypts the first password data packet, the strong password pre-stored on the server associated with the account data and login context information is obtained. In order to prevent the strong password data from being leaked, the characters of the strong password are only displayed on the pre-made Ukey device. The technical solution provided by this application can avoid users from memorizing account passwords on different platforms, can securely display strong passwords pre-stored on the server, improve the security of password management, and improve the efficiency of batch password management. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only embodiments of the present invention. Those skilled in the art can also derive other drawings based on the provided drawings without inventive work.

[0020] Figure 1 The present invention relates to a method for managing strong personal passwords based on PKI.

[0021] Figure 2A core structure diagram of a PKI-based personal strong password management system in an embodiment of the present application;

[0022] Figure 3 A system connection schematic diagram of a cloud server, a first terminal device, a second terminal device and a Ukey device in the PKI-based personal strong password management system in an embodiment of the present application. DETAILED DESCRIPTION

[0023] In order to facilitate the understanding of the present application, the present application will be described more fully below with reference to the accompanying drawings. The drawings show typical embodiments of the present application. However, the present application can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided for the purpose of making the disclosure of the present application more thorough and comprehensive.

[0024] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used in the specification of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application.

[0025] In order to better understand the above technical solutions, the above technical solutions will be described in detail below in combination with the drawings in the specification and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solutions of the present application, and are not intended to limit the technical solutions of the present application. In the case of no conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other.

[0026] Specifically referring to Figures 1 to 3As shown, the present invention provides a personal strong password management method based on PKI, which specifically includes the following technical contents: obtaining login request data, the login request data including: account data, login background information, the login background information being the name or address of the website to be logged in, and the name of the software to be logged in; according to the login request data, sending the first password data packet associated with the login request data to the prefabricated Ukey device through the second control carrier, the prefabricated Ukey device decrypts the first password data packet to obtain a specified password, and displays the specified password on the prefabricated Ukey device; wherein, the second control carrier is installed on the second control terminal device. Compared with the prior art, the technical solution involved in the present invention, after obtaining the login request data, sends the first password data packet associated with the login request data to the prefabricated Ukey device through the second control carrier according to the login request data. Specifically, the login data includes account data and login context information, and the account data and login context information are bound to a pre-stored strong password to obtain a first password data packet. By matching the account data and login context information, the first password data packet containing the strong password can be quickly identified and filtered from the database. The server sends the first password data packet to the pre-made Ukey device via the second control carrier, and the pre-made Ukey device decrypts the first password data packet. It should be noted here that the first password data packet is the result of encrypting the pre-entered strong password in the form of an asymmetric key. The strong password is encrypted using the associated user's asymmetric public key to facilitate the user to decrypt it using the corresponding asymmetric private key on the Ukey device. After the pre-made Ukey device decrypts the first password data packet, the strong password pre-stored on the server associated with the account data and login context information is obtained. In order to prevent the strong password data from being leaked, the characters of the strong password are only displayed on the pre-made Ukey device. The technical solution provided by this application can avoid users from memorizing account passwords on different platforms, can securely display strong passwords pre-stored on the server, improve the security of password management, and improve the efficiency of batch password management.

[0027] Specifically, in an embodiment of the present invention, the cloud server obtains login request data; the cloud server sends the first password data packet associated with the login request data to the prefabricated Ukey device through the second control carrier based on the login request data.

[0028] It should be noted that in this embodiment, when a user logs in through the login device, the login request data generated by the login device is sent to the cloud server. The cloud server automatically matches the first password data packet of the corresponding strong password (non-dynamic password) based on the information in the login request data, and sends the first password data packet to the pre-made Ukey device. Due to the involvement of the cloud server, the entire password-encrypted data transmission process becomes more reliable. The first password data packet must have the corresponding asymmetric private key to be decrypted, which also ensures the security of the transmission process.

[0029] Specifically, in an embodiment of the present invention, the method further includes: encrypting the designated password by an asymmetric key and storing the encrypted password in the cloud server in the form of a first password data packet.

[0030] It should be noted that the strong password (non-dynamic password) stored externally for input is encrypted by an asymmetric public key that is directly and separately associated with the information; this encryption method can only be decrypted by an asymmetric private key, thereby improving the security of password data management.

[0031] Specifically, in an embodiment of the present invention, the method also includes: registering user information: logging into the second control terminal device through a mobile phone SMS verification code, and entering registration information into the second control carrier, the registration information including: account name, device number and associated information of the second control terminal device; the second control carrier uploads the registration information to the cloud server, and the cloud server establishes account information after verifying the registration information; installing the first control carrier on the first control terminal device, and logging in to the account information on the first control carrier; the first control carrier uploads the device information of the current first control terminal device to the cloud server, and the device information is bound to the account information.

[0032] It should be noted that in this embodiment, the second control terminal device is a handheld mobile terminal (hereinafter referred to as: mobile phone), and the second control carrier is the password management mobile phone software of the present application solution installed on the mobile phone; the first control terminal device is a computer, and the first control carrier is the password management computer software of the present application solution installed on the computer. The mobile phone verification code can be used to safely and reliably verify that after logging into the password management mobile phone software through the mobile phone on the same day, it is equivalent to registering a new account in the password management system; after obtaining the account, it is necessary to complete the registration information, including but not limited to the account name, the device number and associated information of the second control terminal device; upload the registration information to the cloud server, and after the cloud server verifies it, create a new account information for the user in the server. Then the user logs in to the password management computer software with the account information, and the password management computer software uploads the device information of the computer to the server so that the device information is bound to the account information. After that, only the password management computer software on the computer has the authority to adjust the user's strong password data, user information, and account information. Improve the security and convenience of management.

[0033] Specifically, in the embodiment of the present invention, it also includes: the first control carrier downloads registration information related to the account information from the cloud server.

[0034] It should be noted that the first control carrier downloads registration information related to the account information from the cloud server to improve the system's local data processing capability.

[0035] Specifically, in an embodiment of the present invention, the method also includes a method for prefabricating a Ukey device: connecting the Ukey device to the data of the first control terminal device; the first control carrier performs a certificate operation on the Ukey device to obtain certificate information, and the certificate information includes the private key password and validity period information of the asymmetric key; the first control carrier uploads the certificate request information to the cloud server, and the certificate request information includes the account information currently logged into the first control carrier and the device information of the first control terminal device where the first control carrier is currently located; after the cloud server verifies that the certificate request information is passed, the first control carrier issues a digital certificate to the Ukey device to obtain a prefabricated Ukey device; the digital certificate includes: the account information, the device information bound to the account information, and the private key password of the asymmetric key.

[0036] It should be noted that, in this embodiment, the production process of the prefabricated Ukey device is completed jointly by the mobile phone, computer, server, and the Ukey device in the initial state; the prefabricated Ukey device decrypts and displays the received password data packet.

[0037] Specifically, in an embodiment of the present invention, the method further includes a method for entering the designated password: performing a first entry operation or a second entry operation; the first entry operation: entering the designated password and password-related information to be managed in the first control carrier, the password-related information including usage context information, the usage context information being a website / connection external server address; the first control carrier encrypting the designated password using a public key of an asymmetric key to obtain a first password data packet; and saving the encrypted ciphertext for query; the first control carrier synchronizing the password-related information to the second control carrier;

[0038] The second entry operation: enter the specified password and password-related information to be managed in the second control carrier, where the password-related information includes usage context information, which is the URL / connection external server address; the second control carrier encrypts the specified password using the public key of the asymmetric key to obtain a first password data packet; and saves the encrypted ciphertext for future query; the second control carrier synchronizes the password-related information to the first control carrier.

[0039] It should be noted that the designated password is the strong password (non-dynamic password) mentioned above, which itself must meet certain rules, such as the complexity of the password. The first or second entry operation enables the user password to be securely and reliably stored on the cloud server.

[0040] In addition, this solution also provides a personal strong password management system based on PKI, which includes: a first acquisition module for obtaining login request data, the login request data including: account data, login background information, the login background information being the name or address of the website to be logged in, and the name of the software to be logged in; a first sending module for sending a first password data packet associated with the login request data to a prefabricated Ukey device through a second control carrier according to the login request data, the prefabricated Ukey device decrypting the first password data packet to obtain a specified password, and displaying the specified password on the prefabricated Ukey device; wherein the second control carrier is installed on a second control terminal device. The personal strong password management system based on PKI provided by this application also has the above-mentioned technical effects.

[0041] In addition, this solution also provides a personal strong password management system based on PKI, which includes: a cloud server for storing data and verifying data; a first control carrier connected to the cloud server for assisting in password management and certificate issuance, the first control carrier being installed on a first terminal device; a second control software connected to the cloud server for verifying information login and password management, the second control software being installed on a second terminal device; and a Ukey device connected to the first control carrier and the second control software for decrypting passwords and authorizations. The personal strong password management system based on PKI provided in this application also has the above-mentioned technical effects.

[0042] Specifically, in an embodiment of the present invention, the data storage module of the cloud server is used to store the following information: a encrypted file information, pre-stored passwords; b user registration information; c installation package of the first control carrier, installation package of the second control software; the data analysis module of the cloud server is used to process the following information: a new user registration information; b certificate verification information; c encrypted file / password acquisition request data information.

[0043] In addition, the present solution also provides an electronic device, which includes: a memory, the memory being used to store software for executing the PKI-based personal strong password management method; and a processor, the processor being used to process the software.

[0044] The following is a more detailed description of the background and overall solution of the embodiments of the present invention:

[0045] This method is based on the public key infrastructure (PKI) knowledge system and integrates the CA function into the strong password management software of the personal PC. It uses an asymmetric encryption method combining public and private keys to encrypt strong password information. The encrypted information can only be displayed in the Ukey with a digital certificate, which greatly ensures the security of the information.

[0046] like Figure 3 This is a structural diagram of a personal strong password management system based on PKI; the system consists of four parts: cloud server, personal PC software (first control carrier), personal App software (second control carrier), and personal Ukey (prefabricated Ukey device).

[0047] 1. The cloud server has the following functions: (1) It can provide users with downloads of personal PC software and App software; (2) It can back up user registration information; (3) It can provide certificate information verification function.

[0048] 2. Personal PC software (PC password management software) has the following functions: (1) certificate creation and management; (2) registered user management; (3) password information maintenance.

[0049] 3. The personal App software (strong password manager App) has the following functions: (1) mobile phone verification code login; (2) password information maintenance; (3) Ukey management.

[0050] 4. Personal Ukey has the following functions: (1) Password decryption display; (2) Digital certificate authorization confirmation.

[0051] Furthermore, the use embodiment of the system includes the following four major process steps: 1. Preparation, 2. Issuance of certificate, 3. Entry of secret and strong password, 4. Viewing of secret and strong password.

[0052] 1. The specific process of "preparation" is as follows:

[0053] (1) Download and install software from the cloud server: Download strong password management software (including CA function) on the PC, and download the strong password manager app on your mobile phone;

[0054] (2) The user completes device registration and binding according to the following process:

[0055] a. Log in to the mobile app via SMS verification code and enter the registration information; (Example: Registration information may include account name, device ID (mobile phone IMEI code automatically collected by the app), and other personal identity information (filled in by the user));

[0056] b. The information entered by the user is uploaded to the cloud server (in this embodiment, it is uploaded through the Nigx reverse proxy method. The reverse proxy method refers to using a proxy server (i.e., a cloud server) to accept user requests, and then forward the requests to other servers in the cloud server's internal network, and return the results obtained from the server to the user. At this time, the proxy server (i.e., a cloud server) appears to the outside world as a server. This method can protect the security of the cloud server's internal network because any request from the Internet must first pass through the proxy cloud server. In addition, by caching static resources, it can speed up the response to Web requests and achieve load balancing). After obtaining approval from the cloud service, the user account is established and the account is bound to the mobile phone.

[0057] c. The user uses their phone to scan the QR code to log in to the PC-based password management software. After logging in, the PC-based password management software downloads the user information entered by the mobile app from the cloud server, eliminating the need to re-enter it. Simultaneously, the PC-based password management software collects the current PC information (such as the PC's MAC address) and uploads it to the cloud server, thus completing the binding between the PC and the user account.

[0058] 2. The specific process of "issuing a certificate" is as follows:

[0059] (1) Open the strong password management software on your mobile phone and PC, and connect your personal UKey to your personal PC via USB;

[0060] (2) The user performs a personal UKey certificate creation operation in the strong password management software on the PC. The user enters the certificate creation information (private key password, validity period, etc.), where the private key password is 8-16 characters long;

[0061] (3) The user sends a request for a certificate, and the strong password management software on the PC connects to the cloud server to authenticate the user's identity to ensure that the request is indeed sent by the user. The authentication process includes the following steps:

[0062] a. The user's PC software actively initiates a challenge response to the cloud server and sends user verification information (such as user ID, MAC address of the PC sending the information, etc.);

[0063] b. Cloud server backend response verification (verification is performed by comparing existing information. If the verification passes (the user ID and the MAC address of the PC sending the information are the same as the existing information), the information is confirmed; otherwise, the verification fails and the confirmation is rejected);

[0064] c. PC software receives verification message from cloud server

[0065] (4) After the authentication is passed, the strong password management software on the PC issues a digital certificate to the UKey. The certificate contains the user identity, the PC bound to the user account, mobile phone information, asymmetric private key information, etc., and is written to the UKey via USB.

[0066] (5) After the certificate is issued, Ukey displays the digital certificate authorization confirmation information, completing the issuance of Ukey's digital certificate and device binding.

[0067] Example: The national secret SM2 algorithm, or RSA algorithm, etc. are used as the asymmetric encryption algorithm of Ukey. The private key is given by the user and is only stored in Ukey. The public key is calculated by the above-mentioned asymmetric encryption algorithm. In this embodiment, after the public key is obtained by calculation, it is saved in the mobile app and PC.

[0068] 3. The specific process of "Secret and Strong Password Entry" is as follows:

[0069] You can choose to enter strong passwords or secret information on PC or mobile app.

[0070] (1) PC

[0071] a. The user enters the strong password they need to manage in the PC software and can choose to complete the relevant information (for example, enter the usage scenario at the same time, such as a related website that uses a strong password, etc.).

[0072] b. The strong password entered by the user is encrypted using the Ukey public key on the PC and the encrypted ciphertext is saved for future reference. Therefore, the specific information of the strong password cannot be seen after entry. Only its background information can be queried.

[0073] c. Synchronize the strong password information on the PC to the mobile app (information synchronization does not go through the cloud server and can be performed via Bluetooth, WiFi, etc.)

[0074] (2) Mobile App

[0075] a. The user enters the strong password they need to manage in the mobile app and can choose to complete the relevant information (for example, enter the usage scenario at the same time, such as a related website that uses a strong password, etc.).

[0076] b. The strong password entered by the user is encrypted on the mobile phone using the Ukey public key and the encrypted ciphertext is saved for future reference. Therefore, the specific information of the strong password cannot be seen after entry. Only its background information can be queried.

[0077] c. Synchronize the strong password information on the PC to the PC (information synchronization does not go through the cloud server and can be done via Bluetooth, WiFi, etc.)

[0078] 4. The specific process of "Secret and Strong Password View" is as follows:

[0079] When a user attempts to view a strong password or secret

[0080] (1) Search and select the entry containing the password or secret by background information (such as the name or URL of a website)

[0081] (2) Send the password or secret ciphertext (encrypted by public key) to the Ukey terminal via Bluetooth on the mobile phone.

[0082] (3) After the Ukey end decrypts the ciphertext using the private key, it displays the strong password or secret required by the user to the customer.

[0083] Furthermore, those skilled in the art will appreciate that although some embodiments described herein include certain features included in other embodiments but not other features, combinations of features from different embodiments are intended to be within the scope of the present invention and to form different embodiments. For example, in the claims below, any of the claimed embodiments may be used in any combination.

[0084] It should be noted that the above embodiments illustrate rather than limit the invention, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between brackets should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising several different elements and by means of appropriately programmed computers. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.

Claims

1. A personal strong password management method based on PKI, characterized in that: The method includes: The cloud server obtains login request data, wherein the login request data includes: account data and login background information, wherein the login background information is the name or address of the website to be logged in, or the name of the software to be logged in; The cloud server sends a first password data packet associated with the login request data to the prefabricated Ukey device via a second control carrier according to the login request data. The prefabricated Ukey device decrypts the first password data packet to obtain a specified password, and displays the specified password on the prefabricated Ukey device. Wherein, the second control carrier is installed on the second control terminal device; Before sending the first password data packet associated with the login request data to the prefabricated Ukey device via the second control carrier, the method further includes: The first control carrier issues a digital certificate to the Ukey device to obtain a prefabricated Ukey device; the digital certificate includes: account information, device information bound to the account information, and a private key password of an asymmetric key; the first control carrier is installed on a first control terminal device; the first control carrier and the second control carrier use the same account information; the device information includes device information of the first control terminal device and device information of the second control terminal device.

2. The PKI-based personal strong password management method according to claim 1, characterized in that: The method further includes: After the designated password is encrypted by an asymmetric key, it is stored in the cloud server in the form of a first password data packet.

3. The PKI-based personal strong password management method according to claim 1, characterized in that: The method further includes: Registered user information: Log in to the second control terminal device via a mobile phone SMS verification code, and enter registration information into the second control carrier, the registration information including: account name and device number and associated information of the second control terminal device; The second control carrier uploads the registration information to the cloud server, and the cloud server establishes account information after verifying that the registration information is qualified; A first control carrier is installed on the first control terminal device, and the account information is logged in on the first control carrier; the first control carrier uploads the device information of the current first control terminal device to the cloud server, and the device information is bound to the account information.

4. The PKI-based personal strong password management method according to claim 3, characterized in that: The method also includes prefabricating the Ukey device: Connect the Ukey device to the first control terminal device; The first control carrier performs a certificate-making operation on the Ukey device to obtain certificate-making information, where the certificate-making information includes a private key password and validity period information of the asymmetric key; The first control carrier uploads the certificate request information to the cloud server, wherein the certificate request information includes the account information currently logged into the first control carrier and the device information of the first control terminal device where the first control carrier is currently located; After the cloud server verifies that the certificate request information is passed, the first control carrier issues a digital certificate to the Ukey device to obtain a prefabricated Ukey device.

5. The PKI-based personal strong password management method according to claim 4, characterized in that: The method also includes a method for entering the specified password: Performing a first entry operation or a second entry operation; First entry operation: Entering the designated password and password-related information required for management into the first control carrier, wherein the password-related information includes usage context information, which is a website or an address for connecting to an external server; The first control carrier encrypts the specified password using the public key of the asymmetric key to obtain a first password data packet; and saves the encrypted ciphertext for query; The first control carrier synchronizes the password-related information to the second control carrier; Second entry operation: Entering the designated password and password-related information required for management into the second control carrier, wherein the password-related information includes usage context information, which is a website or an address for connecting to an external server; The second control carrier encrypts the specified password using the public key of the asymmetric key to obtain a first password data packet; and saves the encrypted ciphertext for query; The second control carrier synchronizes the password-related information to the first control carrier.

6. Personal strong password management system based on PKI, characterized by: The system includes: A first acquisition module for acquiring login request data, wherein the login request data includes: account data and login background information, wherein the login background information is the name or address of the website to be logged in, or the name of the software to be logged in; Used to send, according to the login request data, a first password data packet associated with the login request data to the first sending module on the prefabricated Ukey device through the second control carrier, so that the prefabricated Ukey device decrypts the first password data packet to obtain a specified password, and displays the specified password on the prefabricated Ukey device; Wherein, the first acquisition module and the first sending module are on the cloud server, and the second control carrier is installed on the second control terminal device; The system further comprises: A first control carrier, the first control carrier issues a digital certificate to the Ukey device to obtain a prefabricated Ukey device; the digital certificate includes: account information, device information bound to the account information, and a private key password of an asymmetric key; the first control carrier is installed on a first control terminal device; the first control carrier and the second control carrier use the same account information; the device information includes device information of the first control terminal device and device information of the second control terminal device.

7. Personal strong password management system based on PKI, characterized by: The system includes: Cloud servers for storing and verifying data; A first control carrier connected to the cloud server for assisting with password management and certificate issuance, the first control carrier being installed on a first control terminal device; A second control carrier connected to the cloud server for verifying information login and password management, the second control carrier being installed on a second control terminal device; A Ukey device that is data-connected to the first control carrier and the second control carrier and is used to decrypt passwords and authorizations; The cloud server sends a first password data packet associated with the login request data to the prefabricated Ukey device via a second control carrier according to the login request data. The prefabricated Ukey device decrypts the first password data packet to obtain a specified password, and displays the specified password on the prefabricated Ukey device. The first control carrier issues a digital certificate to the Ukey device to obtain a prefabricated Ukey device; the digital certificate includes: account information, device information bound to the account information, and a private key password of an asymmetric key; the first control carrier and the second control carrier use the same account information; the device information includes the device information of the first control terminal device and the device information of the second control terminal device.

8. An electronic device, characterized in that: The device includes: A computer program for executing the PKI-based personal strong password management method according to any one of claims 1 to 5; a memory, the memory being used to store the computer program; A processor is configured to execute the computer program.

Citation Information

Patent Citations

  • Password input method, intelligent secret key device and client device

    CN103929307A

  • Password management method based on security hardware

    CN112383914A