PKI-based enterprise strong password management method, system and electronic device
By adopting a PKI-based enterprise strong password management method, utilizing password vault servers and Ukey devices, and combining asymmetric key encryption technology, the information security threats posed by simple passwords in enterprises are resolved. This achieves secure password management and efficient memorization, improving the security and management efficiency of password protection.
Patent Information
- Application Number
- CN202211367191.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-02
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2042-11-02
AI Technical Summary
The existence of numerous simple passwords in enterprises poses a threat to information security. Furthermore, it is difficult for operators to remember complex passwords, and the password recording files present security risks, affecting the security and efficiency of password management.
The enterprise strong password management method based on PKI is adopted. By combining the password vault server and Ukey device, the storage of non-dynamic passwords and the generation and encryption of dynamic passwords are realized. Asymmetric key encryption technology is used to ensure password security and management efficiency.
It improves password protection security, reduces the risk of password leakage, simplifies the memory burden on operators, and improves the efficiency of batch password management.
Smart Images

Figure CN115913532B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of system encryption technology, in particular to a PKI-based enterprise strong password management method, and further relates to a system and electronic device for running the PKI-based enterprise strong password management method. BACKGROUND
[0002] Information security is a problem that needs to be solved urgently by governments, hospitals and other institutions, and small and medium-sized enterprises. For example, government statistical data, reports, and patient data in hospitals. Statistics show that 80% of information security threats encountered by enterprises come from within.
[0003] There are many important systems in enterprises, such as financial systems, and the simplest way to enter the system is through a password, that is, to obtain the target password. Once the password is obtained, the system can be easily invaded and data can be obtained. In particular, in the enterprise, there are a large number of simple passwords with insufficient strength, and the security risks cannot be ignored.
[0004] However, the passwords used by enterprise personnel in their daily work are more complex, and it is not convenient to remember the passwords, and storing files containing passwords everywhere will cause greater security risks.
[0005] Therefore, how to provide a problem solving scheme that can improve the security of password protection and improve the efficiency of password batch management has become the goal to be completed by the technical personnel in the field. SUMMARY
[0006] To solve the above technical problems, the main purpose of the present application is to provide a PKI-based enterprise strong password management method, which can improve the security of password protection and improve the efficiency of password batch management. In addition, the present application also provides a PKI-based enterprise strong password management system and electronic device, which also has the above-mentioned beneficial effects.
[0007] To achieve the above-mentioned purpose, the present application provides a PKI-based enterprise strong password management method, which comprises: obtaining login request data; performing a first operation or a second operation; performing the first operation comprises: sending the login request data to a password safe server, the password safe server sends a first password data package to a pre-bound Ukey device, the pre-bound Ukey device decrypts the first password data package and displays the first login password data; performing the second operation comprises: the pre-set sandbox module of the login device first generates a dynamic password, and then encrypts the dynamic password to obtain a second password data package, and then sends the second password data package to the pre-bound Ukey device; the pre-bound Ukey device decrypts the second password data package and displays the second login password data.
[0008] Further, in the PKI-based enterprise strong password management method provided by the application, the method further comprises: judging the login device; if the login device is a non-dynamic password login device, performing a first operation; if the login device is a dynamic password login device, performing a second operation.
[0009] Further, in the PKI-based enterprise strong password management method provided by the application, the password safe server is used to store secret files encrypted by an asymmetric key encryption mode, the secret files include non-dynamic passwords associated with user information and login backgrounds, and the non-dynamic passwords are preset strong passwords; the password safe server stores a public key of the asymmetric key encryption mode in the form of ciphertext; and a private key of the asymmetric key encryption mode is stored in the pre-bound Ukey device.
[0010] Further, in the PKI-based enterprise strong password management method provided by the application, the login device downloads and installs a sandbox module from the password safe server to obtain the preset sandbox module; and the preset sandbox module stores the public key of the asymmetric key encryption mode in the form of ciphertext.
[0011] Further, in the PKI-based enterprise strong password management method provided by the application, the method further comprises: downloading control software from the password safe server by a user control terminal, wherein the control software includes PC control software or mobile phone control software; and the user control terminal is a computer or a handheld mobile terminal associated with user information.
[0012] Further, in the PKI-based enterprise strong password management method provided by the application, the pre-bound Ukey device is pre-bound with a handheld mobile terminal, the pre-bound Ukey device and the handheld mobile terminal are connected through a wireless connection mode, the wireless connection mode includes Bluetooth connection and WiFi connection; and the password safe server sends the first password data packet to the pre-bound Ukey device through the handheld mobile terminal.
[0013] Further, in the PKI-based enterprise strong password management method provided by the application, the method for pre-binding the Ukey device comprises the following steps: registering a user account through a handheld mobile terminal, collecting user information associated with the user account, the user information comprising an employee number, a department, a name of the user, and device information of the handheld mobile terminal; uploading the user account and the user information to the password safe server, the password safe server matching the received user account and user information with preset registerable information; if the matching is successful, the user account is successfully registered; logging in to PC terminal control software through the user account, the PC terminal control software downloading the user information from the password safe server, the PC terminal control software writing a digital certificate into the Ukey device based on the user information, and obtaining the pre-bound Ukey device.
[0014] Further, in the PKI-based enterprise strong password management method provided by the application, the "preset sandbox module of the login device first generates a dynamic password, and then encrypts the dynamic password to obtain a second password data packet" specifically comprises the following steps: obtaining login request data; matching the login request data with a dynamic password preset list; after the matching is successful, the preset sandbox module of the login device generates a dynamic password; using a public key of an asymmetric key associated with the user login account to encrypt the dynamic password to obtain a second password data packet; sending the second password data packet to the pre-bound Ukey device of the handheld mobile terminal that has logged in the user login account through the password safe server; using a private key of the asymmetric key to decrypt the second password data packet by the pre-bound Ukey device to obtain the dynamic password of the login device; and displaying the dynamic password on the pre-bound Ukey device.
[0015] In addition, the application further provides a system for running the PKI-based enterprise strong password management method, the system comprising: a first obtaining module for obtaining login request data; a first operation module for performing a first operation, the first operation comprising: sending the login request data to a password safe server, the password safe server sending a first password data packet to a pre-bound Ukey device, the pre-bound Ukey device decrypting the first password data packet and displaying the first login password data; and a second operation module for performing a second operation, the second operation comprising: a preset sandbox module of a login device first generating a dynamic password, then encrypting the dynamic password to obtain a second password data packet, and sending the second password data packet to a pre-bound Ukey device; the pre-bound Ukey device decrypting the second password data packet and displaying the second login password data.
[0016] In addition, the scheme also provides an electronic device, comprising: a memory for storing a computer application program for executing the PKI-based enterprise strong password management method; and a processor for processing the computer application program for the PKI-based enterprise strong password management method.
[0017] The application provides a PKI-based enterprise strong password management method, which specifically comprises the following technical content: obtaining login request data; performing a first operation or a second operation; the first operation comprises: sending the login request data to a password safe server, the password safe server sending a first password data packet to a pre-bound Ukey device, the pre-bound Ukey device decrypting the first password data packet and displaying the first login password data; the second operation comprises: a pre-set sandbox module of the login device first generating a dynamic password, secondly encrypting the dynamic password to obtain a second password data packet, and thirdly sending the second password data packet to the pre-bound Ukey device; the pre-bound Ukey device decrypts the second password data packet and displays the second login password data. Compared with the prior art, the technical scheme disclosed by the application can input login request data on a login device, and after obtaining the login request data, two operations can be performed; when the first operation is performed, the password safe server sends a first password data packet associated with the login request data to the pre-bound Ukey device after receiving the login request data, the pre-bound Ukey device decrypts the first password data packet to obtain a non-dynamic password stored in the first password data packet, and displays the non-dynamic password on the device; the operator can input the non-dynamic password into the login box of the login device to realize login of the login device. When the second operation is performed, the operator performs login operation on the login device that needs to use a dynamic password, obtains login request, and generates a random dynamic password in the sandbox module of the login device; the dynamic password is encrypted by the asymmetric key in the sandbox to obtain a second password data packet; the sandbox module of the login device sends the second password data packet to the pre-bound Ukey device through the password safe server; the pre-bound Ukey device decrypts the second data packet by using the asymmetric key to obtain and display the dynamic password; the operator can input the non-dynamic password into the login box of the login device to realize login of the login device. In summary, in the above operation process, the operator does not need to remember the password of the login device; the non-dynamic password is pre-stored in the password safe server, and the dynamic password is randomly generated by the sandbox module of the login device; the application solves the problem that the operator does not need to remember the non-dynamic password, and further increases the risk of preventing password leakage through the sandbox module. The technical scheme provided by the application can improve the security of password protection and the efficiency of password batch management. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort:
[0019] Fig. 1 This is a flowchart of a PKI-based enterprise strong password management method according to an embodiment of the present invention.
[0020] Fig. 2 This is a flowchart illustrating the operation of different password login types based on the login device in this embodiment of the invention.
[0021] Fig. 3 This is a system architecture diagram of the enterprise strong password management method based on PKI in an embodiment of the present invention. Detailed Implementation
[0022] To facilitate understanding of the present invention, a more complete description will be given below with reference to the accompanying drawings. Typical embodiments of the invention are shown in the drawings. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete.
[0023] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.
[0024] To better understand the above technical solutions, the following will describe the above technical solutions in detail with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solutions of this application, rather than limitations on the technical solutions of this application. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0025] Specific reference Figs. 1 to 3The application provides a PKI-based enterprise strong password management method, and specifically comprises the following technical contents: obtaining login request data; performing a first operation or a second operation; the first operation comprises: sending the login request data to a password safe server, the password safe server sends a first password data packet to a pre-bound Ukey device, the pre-bound Ukey device decrypts the first password data packet and displays the first login password data; the second operation comprises: a preset sandbox module of the login device first generates a dynamic password, then encrypts the dynamic password to obtain a second password data packet, and then sends the second password data packet to the pre-bound Ukey device; the pre-bound Ukey device decrypts the second password data packet and displays the second login password data. Compared with the prior art, the technical scheme related to the application can input login request data on a login device, and after obtaining the login request data, two operations can be performed; when the first operation is performed, the password safe server sends a first password data packet associated with the login request data to the pre-bound Ukey device after receiving the login request data, the pre-bound Ukey device decrypts the first password data packet to obtain a non-dynamic password stored in the first password data packet, and displays the non-dynamic password on the device; the operator can input the non-dynamic password into the login box of the login device to realize login of the login device. When the second operation is performed, the operator performs login operation on the login device that needs to use a dynamic password, obtains login request, and generates a random dynamic password directly in the sandbox by the sandbox module built in the login device; the dynamic password is encrypted by the asymmetric key to obtain a second password data packet, the sandbox module of the login device sends the second password data packet to the pre-bound Ukey device through the password safe server, the pre-bound Ukey device decrypts the second data packet by using the asymmetric key decryption mode, and the dynamic password is directly displayed after being obtained; the operator can input the non-dynamic password into the login box of the login device to realize login of the login device. In summary, in the above operation process, the operator does not need to remember the password of the login device, the non-dynamic password is pre-stored in the password safe server, and the dynamic password is randomly generated by the sandbox module of the login device; while solving the problem that the operator does not need to remember the non-dynamic password, the sandbox module is further used to increase the risk of preventing password leakage. The technical scheme provided by the application can improve the security of password protection and improve the efficiency of password batch management.
[0026] It should be noted that the login request data comprises: a login account input by an operator / user on a login device, a physical address / model of the login device, and a handheld control terminal (a handheld mobile device / mobile phone) currently logged in the account of the operator / user.
[0027] It needs to be explained that the method further comprises: pre-binding the Ukey device; and identifying whether the operator is the AI password cracking system before decrypting the first password data packet or the second password data packet, and if the operator is not the AI password cracking system, performing the first password data packet or the second password data packet decryption action.
[0028] Further, the pre-binding Ukey device checks and verifies the physiological information of the operator by the pre-binding Ukey device body before displaying the dynamic password or the non-dynamic password, and judges whether the current operator is the owner of the pre-binding Ukey device, and if the operator is the owner, performing the dynamic password or the non-dynamic password display action. The physiological information is one or more of fingerprint, iris, voiceprint and the like.
[0029] Specifically, in the embodiment of the application, the method further comprises: judging the login device; a performing the first operation if the login device is a non-dynamic password login device; and b performing the second operation if the login device is a dynamic password login device.
[0030] It needs to be explained that the first operation or the second operation is pre-determined by the judgment instruction; and the efficiency of password batch management is improved.
[0031] Specifically, in the embodiment of the application, the password safe server is used to store confidential files encrypted in an asymmetric key encryption mode, the confidential files include non-dynamic passwords associated with user information and login backgrounds, and the non-dynamic passwords are preset strong passwords; the password safe server stores a public key of the asymmetric key encryption mode in the form of ciphertext; and a private key of the asymmetric key encryption mode is stored in the pre-binding Ukey device.
[0032] It needs to be explained that the password safe server is used to store non-dynamic passwords in an asymmetric key encryption mode; and the security of password associated data storage is improved.
[0033] Specifically, in the embodiment of the application, the login device downloads and installs a sandbox module from the password safe server to obtain the preset sandbox module; and the preset sandbox module stores a public key of the asymmetric key encryption mode in the form of ciphertext.
[0034] It needs to be explained that the preset sandbox module is associated with the login device, and the password safe server can only obtain the encrypted dynamic password data packet transmitted by the sandbox module, so that even if the password safe server is cracked, the dynamic password data cannot be leaked, and the security of password management is improved.
[0035] Specifically, in the embodiment of the present application, the method further comprises: downloading control software by the user control terminal through the password safe server, wherein the control software comprises: PC terminal control software or mobile phone terminal control software; and the user control terminal is a computer or a handheld mobile terminal associated with the user information.
[0036] It should be noted that the password safe server stores control software for PC terminal or handheld mobile terminal, and when the relevant device is connected to the password safe server, the relevant data can be downloaded quickly, thereby improving the convenience of password management; meanwhile, the relevant device can also avoid downloading non-official and genuine control software through other channels, thereby improving the security of password management.
[0037] Specifically, in the embodiment of the present application, the pre-binding Ukey device and the handheld mobile terminal are pre-bound, the pre-binding Ukey device and the handheld mobile terminal are connected through a wireless connection mode, and the wireless connection mode comprises Bluetooth connection and WiFi connection; and the password safe server sends the first password data packet to the pre-binding Ukey device.
[0038] It should be noted that the communication channel of the password safe server and the pre-binding Ukey device can be established conveniently and quickly through the handheld control terminal.
[0039] It should be noted that the handheld control terminal is a mobile phone.
[0040] Specifically, in the embodiment of the present application, the pre-binding method of the Ukey device comprises: registering a user account through a handheld mobile terminal, collecting user information associated with the user account, wherein the user information comprises the employee number, department, name of the user and device information of the handheld mobile terminal; uploading the user account and the user information to the password safe server, matching the received user account and user information with preset registerable information by the password safe server; if the matching is successful, the user account is registered successfully; logging in the PC terminal control software through the user account, downloading the user information from the password safe server by the PC terminal control software, writing a digital certificate for the Ukey device based on the user information by the PC terminal control software, and obtaining the pre-binding Ukey device.
[0041] It should be noted that in the method, the password safe server can simultaneously manage a plurality of login devices, a plurality of handheld control terminals, a plurality of PC control terminals, and a plurality of pre-bound Ukey terminals. The plurality of login devices, the plurality of handheld control terminals, the plurality of PC control terminals, and the plurality of pre-bound Ukey terminals are pre-associated and bound through login authentication and binding of digital certificates, thereby improving the efficiency of password batch management.
[0042] Specifically, in the embodiment of the present application, the "preset sandbox module of the login device first generates a dynamic password, and then encrypts the dynamic password to obtain a second password data packet" specifically includes: obtaining login request data; matching the login request data with a dynamic password preset list; after successful matching, the preset sandbox of the login device generates a dynamic password; using a public key of an asymmetric key associated with the user login account to encrypt the dynamic password to obtain a second password data packet; sending the second password data packet to the pre-bound Ukey device of the handheld mobile terminal that has logged into the user login account through the password safe server; the pre-bound Ukey device decrypts the second password data packet using a private key of the asymmetric key to obtain the dynamic password of the login device; and displaying the dynamic password on the pre-bound Ukey device.
[0043] It should be noted that the dynamic password is generated by the preset sandbox module of the login device, and after the dynamic password is encrypted to obtain a second password data packet, the second password data packet is sent to the pre-bound Ukey device through the password safe server. Although the password safe server is involved in the process, the password safe server cannot decrypt the second password data packet because it does not have the private key of the asymmetric encryption associated with the user. Even if the password safe server is hacked, the dynamic password cannot be obtained, thereby improving the security of the password management system.
[0044] It should be noted that further, the method of the preset sandbox module on the dynamic password includes:
[0045] After the login request data and the dynamic password are integrated under the preset rules, the second password data packet is obtained by encrypting the dynamic password using an asymmetric key. This embodiment further improves the encryption strength of the second password data packet to prevent decryption.
[0046] Further, the present application also provides a system for running the PKI-based enterprise strong password management method, which comprises: a first acquisition module for acquiring login request data; a first operation module for performing a first operation, wherein the first operation comprises: sending the login request data to a password safe server, the password safe server sending a first password data package to a pre-bound Ukey device, the pre-bound Ukey device decrypting the first password data package and displaying the first login password data; a second operation module for performing a second operation, wherein the second operation comprises: a pre-set sandbox module of a device logging in first generating a dynamic password, secondly encrypting the dynamic password to obtain a second password data package, and thirdly sending the second password data package to the pre-bound Ukey device; and the pre-bound Ukey device decrypting the second password data package and displaying the second login password data. The system for running the PKI-based enterprise strong password management method provided by the present application also has the above technical effects.
[0047] Further, the present application also provides an electronic device, which comprises: a memory for storing a computer application program for executing the PKI-based enterprise strong password management method; and a processor for processing the computer application program of the PKI-based enterprise strong password management method. The electronic device provided by the present application also has the above technical effects.
[0048] The background and the overall scheme of the present application are described in more detail as follows:
[0049] The present method is based on a public key infrastructure (PKI), and an employee device can be issued with an asymmetrically encrypted digital certificate by an enterprise PC. On the server side, a password safe server mechanism is used for storage and information verification, and a sandbox is used to ensure dynamic updating of the password, thereby greatly ensuring the security of enterprise information.
[0050] As shown in Fig. 3 the whole system comprises: a password safe server, a computer control end software, a mobile phone control end software, a Ukey device and a sandbox module.
[0051] 1. Password safe server:
[0052] (1) providing storage and reading services for confidential data:
[0053] (a) when storing, storing various confidential files and passwords in the form of ciphertext in the safe,
[0054] encrypting various files by using an asymmetric key (public key),
[0055] Asymmetric key is also stored in the form of ciphertext in the safe, and the decryption key of the asymmetric key ciphertext is in the employee's personal Ukey.
[0056] (b) When reading, the data content ciphertext in the safe, the data encryption key ciphertext is transmitted to the data display mobile terminal (such as a personal mobile phone) through SSL VPN, and the mobile terminal sends it to the Ukey device through another channel (such as through Bluetooth) to decrypt the data ciphertext and display it to the user.
[0057] (2) Personal PC software and App software can be downloaded for users: Before registration, users can download PC software and mobile phone App through the password safe server, and install the sandbox on the device using the dynamic password.
[0058] (3) Registered user and device information management: including but not limited to user (user ID, user binding device number) and device (PC (MAC address, etc.), mobile phone (IMEI code, etc.) information input, query, edit and delete, etc.
[0059] (4) Provide certificate information verification function: provide information verification for user registration (account establishment).
[0060] 2. Computer control end software:
[0061] (1) Certificate and certificate management: PC software contains CA function, which can apply for certificate for users or devices that have not applied for certificate (details see later process), and can manage existing digital certificate, including but not limited to adding, querying and modifying digital certificate production operation (such as supporting to query digital certificate meeting the conditions according to device or personnel name, or revoking existing digital certificate)
[0062] (2) Password information maintenance and inspection: users can input strong password and related information (related information refers to the use scene of strong password, such as the name of financial software, the computer number and use page website of the software login password, etc.) through PC software.
[0063] The password is divided into dynamic password and non-dynamic password. Dynamic password is the password important to the enterprise or employee, which needs to be changed regularly, and adopts one-time one-key principle (such as the boot password of some important computers of the company); Non-dynamic password is the password that does not need to be updated in real time (such as employee's personal ERP account password)
[0064] (a) For dynamic password (such as the boot password of some important computers of the company), (use instruction and process are described later).
[0065] (b) For passwords or keys that use non-dynamic password protection mechanisms, the software automatically checks the password strength and naming rules when the user registers and enters a strong password or key.
[0066] The rules for strong passwords or keys are as follows:
[0067] More than 10 characters in length, the longer the better;
[0068] Contains at least one special symbol;
[0069] It is best not to contain any pinyin or English letters;
[0070] Does not contain mobile phone numbers, QQ numbers, names, etc.
[0071] Different from other passwords in the system
[0072] 3. Mobile control software:
[0073] (1) Mobile phone verification code login: can log in to the software through the form of mobile phone short message verification code.
[0074] (2) Password information maintenance and inspection: this function is the same as the PC software
[0075] (3) Ukey management: when the mobile terminal App receives the ciphertext state password or secret from the password safe server, it will be issued to the Ukey through Bluetooth.
[0076] 4. Ukey device:
[0077] (1) Password decryption display
[0078] (2) Digital certificate authorization confirmation
[0079] 5. System using dynamic password (sandbox module)
[0080] (1) Dynamic password generation function;
[0081] (2) Dynamic password encryption function.
[0082] I. Prepare to use the example:
[0083] (1) The use scenario is a certain enterprise, and the enterprise has installed a password safe server and computer control software (the PC is used to issue and install electronic digital certificates to the Ukey device).
[0084] (2) Employees use mobile phones to download and install mobile control software from the password safe server through SSL VPN;
[0085] (3) Employees complete device registration and binding according to the following process:
[0086] a. Employee prepares a mobile phone with an installed App and connects his own Ukey device to the issuing PC (computer) via a USB interface;
[0087] b. The employee creates a new account on the mobile phone and completes the first login through SMS verification (subsequent logins can be through scanning a code, manually entering a username, etc.),
[0088] enters the information for registration (example: enters the employee's work number, department, name, etc. information, and the system collects the mobile phone's hardware information for binding the user);
[0089] c. The system uploads the employee's entered information to the password safe server through SSL VPN, and after obtaining approval from the password safe server (the password safe server compares the company's existing employee information in the system with the employee's application information, and only if the two are consistent can it be approved, otherwise it cannot be approved), the employee's account is established, and the binding of the account and the employee's mobile phone is completed;
[0090] d. The username and password registered using the mobile phone App are used to log in to the PC-side software for issuance, and after logging in, the PC-side software downloads the existing user information from the password safe server.
[0091] e. The PC-side software generates a digital certificate for the personal UKey, and the steps are as follows:
[0092] The employee enters the relevant certificate information (asymmetric private key password, validity period, etc. information), and the private key should meet the strong password rules (the PC checks the private key password entered by the employee, and if it does not meet the strong password rules, the employee needs to revise it until it meets the regulations to pass);
[0093] The user sends a certificate issuance request, and the PC-side software sends the certificate issuance request, employee information, and employee Ukey hardware information (device number, etc.) to the password safe server through SSL VPN, and the safe box confirms the employee information (example: confirms that the employee's mobile phone is bound to the user, and whether the account has a Ukey bound, if there is a Ukey bound, the confirmation fails, if there is no Ukey bound, the safe box sends a certificate issuance notification to the mobile phone App (notifies the preparation of the certificate issuance operation on the Ukey, and asks the employee if he agrees), after the password safe server obtains the employee's mobile phone App confirmation agreement information, the password safe server confirms that the PC-side certificate issuance request is legal and passes), and after the confirmation passes, the certificate issuance operation can be performed.
[0094] The PC-side software issues a digital certificate to the UKey, which includes the user's identity, the PC-side information bound to the user's account (issuing computer network card number, port number, etc. information), mobile phone information (employee's personal mobile phone hardware information), asymmetric private key, etc., and writes it into the UKey through USB.
[0095] Certificate issuance, Ukey display digital certificate authorization confirmation information, PC software to read the connected Ukey hardware information, information saved to the employee user account, and upload the password safe server for saving, from the password safe server to the mobile phone end App for saving. Thus complete the issuance of digital certificate of Ukey and equipment binding.
[0096] Example: Ukey key uses asymmetric encryption algorithm, such as SM2 algorithm, RSA algorithm, etc., the private key is given by the employee, only saved in Ukey, the public key is calculated by the above asymmetric encryption algorithm, and saved in mobile phone App, PC and password safe server.
[0097] Two, non-dynamic password entry example:
[0098] For non-dynamic password, employees can use PC or mobile phone App to enter, and need to improve its use background information for query (such as the name and number of the software or system using the password, etc.), strong password entry, only its background information can be seen, strong password itself will be encrypted by public key of asymmetric algorithm, neither in mobile phone nor in PC.
[0099] Note: In the process of entering strong password, you can choose whether it can be seen.
[0100] Three, non-dynamic password viewing example:
[0101] When the user intends to view a non-dynamic strong password, the ciphertext encrypted by the public key needs to be sent to the Ukey side (through Bluetooth, etc.), the Ukey uses the private key to decrypt the ciphertext, and the decrypted information can be displayed to the user.
[0102] Four, dynamic password use example:
[0103] After the enterprise sets a device to use dynamic password, the use process is as follows:
[0104] (1) Install sandbox on the device that needs to use dynamic password (such as computer installed with financial software, hereinafter referred to as device a),
[0105] (2) The enterprise administrator preexists the list of employees with the use permission of device a (the list includes the asymmetric public key of the employee's Ukey) in the sandbox of device a.
[0106] (3) When the user logs in device a, first enter his ID (employee number) in the login interface, and click the "dynamic password application" button
[0107] (4) The sandbox of the device a detects the login authentication information, and first verifies whether the user ID has the use right. If not, no operation is performed;
[0108] If the user ID has the use right, the sandbox immediately changes the boot password, and encrypts the changed password using the asymmetric public key of the employee
[0109] (5) The sandbox of the device a sends the boot password in the cipher text state to the password safe server through the SSL VPN, and the password safe server forwards it to the employee's mobile phone App. The mobile phone App sends the cipher text to the Ukey through Bluetooth, the Ukey decrypts the cipher text through the private key, and displays the strong password to the user (obtains the dynamic password).
[0110] Furthermore, those skilled in the art will appreciate that the features of the different embodiments can be combined in any combination, meaning that the combinations of features of different embodiments are within the scope of the application and form different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.
[0111] It should be noted that the above-mentioned embodiments illustrate rather than limit the application, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps other than those listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In a unit claim, several devices can be listed, comprising means for performing a certain function. The means recited in the claim can be either hardware or software, or a combination thereof. The use of the word at the beginning of the claim does not limit the scope of the claim to a single article, but rather allows the claim to cover both a single article and a plurality of articles. The application can be implemented by means of both hardware and software, and any combination thereof. In a unit claim, several devices can be listed, comprising means for performing a certain function. The means recited in the claim can be either hardware or software, or a combination thereof. The use of the word at the beginning of the claim does not limit the scope of the claim to a single article, but rather allows the claim to cover both a single article and a plurality of articles. The word 'first','second', 'third', etc. do not necessarily indicate any order, but rather are used for naming.
Claims
1. A PKI-based enterprise strong password management method, characterized by, The method includes: Retrieve login request data; Identify the login device; a. If the login device is a non-dynamic password login device, then perform the first operation; b. If the login device is a dynamic password login device, then perform the second operation; The execution of the first operation includes: sending the login request data to the password vault server; the password vault server sending the first password data packet to the pre-bound Ukey device; the pre-bound Ukey device decrypting the first password data packet to obtain the non-dynamic password stored in the first password data packet; and displaying the non-dynamic password on the pre-bound Ukey device. The second operation includes: sending the login request data to a preset sandbox module built into the login device; the preset sandbox module first generates a random dynamic password, which is then directly encrypted in the sandbox using the public key of an asymmetric key to obtain a second password data packet; the sandbox module sends the second password data packet to a pre-bound Ukey device through a password vault server; the pre-bound Ukey device decrypts the second password data packet using the private key of an asymmetric key to obtain the dynamic password, and displays the dynamic password on the pre-bound Ukey device.
2. The enterprise strong password management method based on PKI according to claim 1, characterized in that, The password vault server is used to store confidential files encrypted using asymmetric key encryption. The confidential files include non-dynamic passwords associated with user information and login background. The non-dynamic passwords are preset strong passwords. The password vault server stores the public key of the asymmetric key encryption method, which is encrypted in ciphertext form. The private key for the asymmetric key encryption method is stored in the pre-bound Ukey device.
3. The enterprise strong password management method based on PKI according to claim 2, characterized in that, The login device downloads and installs the sandbox module through the password safe server to obtain the preset sandbox module; The preset sandbox module stores the public key of the asymmetric key encryption method, which is encrypted in ciphertext.
4. The PKI-based enterprise strong password management method of claim 1, wherein, The method also includes: The user control terminal downloads control software through the password vault server. The control software includes PC-based control software or mobile-based control software. The user control terminal is a computer or handheld mobile terminal associated with user information.
5. The enterprise strong password management method based on PKI according to claim 4, characterized in that, The pre-bound Ukey device is pre-bound to the handheld mobile terminal, and the pre-bound Ukey device and the handheld mobile terminal are connected wirelessly, including Bluetooth connection and WiFi connection. The step "the password vault server sends the first password data packet to the pre-bound Ukey device" specifically refers to: The password safe server sends the first password data packet to the pre-bound Ukey device via a handheld mobile terminal.
6. The PKI-based enterprise strong password management method of claim 5, wherein, The method for pre-binding the Ukey device includes: Register a user account through a handheld mobile terminal and collect user information associated with the user account. The user information includes the user's employee number, department, name, and device information of the handheld mobile terminal. The user account and user information are uploaded to the password vault server, and the password vault server matches the received user account and user information with preset registration information; If the match is successful, the user account registration is successful. The user logs into the PC control software using the user account. The PC control software downloads the user information from the password vault server. Based on the user information, the PC control software writes a digital certificate to the Ukey device, thus obtaining the pre-bound Ukey device.
7. A system for running the PKI-based enterprise strong password management method according to any one of claims 1 to 6, characterized in that, The system includes: The first acquisition module used to obtain login request data; Used to determine the login device; a. If the login device is a non-dynamic password login device, then perform the first operation; b. If the login device is a dynamic password login device, then perform the second operation; A first operation module for performing a first operation includes: sending the login request data to a password vault server; the password vault server sending a first password data packet to a pre-bound Ukey device; the pre-bound Ukey device decrypting the first password data packet to obtain a non-dynamic password stored in the first password data packet; and displaying the non-dynamic password on the pre-bound Ukey device. A second operation module for performing a second operation includes: sending the login request data to a preset sandbox module built into the login device; the preset sandbox module first randomly generates a dynamic password, which is then directly encrypted in the sandbox using the public key of an asymmetric key to obtain a second password data packet; the sandbox module sends the second password data packet to a pre-bound Ukey device through a password vault server; the pre-bound Ukey device decrypts the second password data packet using the private key of an asymmetric key to obtain the dynamic password, and displays the dynamic password on the pre-bound Ukey device.
8. An electronic device, characterized in that, include: A computer program, the computer program being used to execute the PKI-based enterprise strong password management method according to any one of claims 1 to 6; A memory for storing the computer program; A processor for executing the computer program.
Citation Information
Patent Citations
Password safe box system based on hardware encryption and application method
CN113014393A
Operating system login method and device and electronic equipment
CN114139131A