Terminal security login method and device
By combining user information with encrypted Ukey devices to calculate and verify the second login password, the problem of low security in the prior art of single username and user password login authentication is solved, and higher terminal login security and system security guarantees are achieved.
Patent Information
- Application Number
- CN202211543335.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-02
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-12-02
AI Technical Summary
The existing terminal login method uses a single username and user password for login authentication, which poses security risks and is easily cracked, resulting in data leakage and security risks.
Login authentication is performed by combining user information with encrypted Ukey devices. The second login password is obtained by calculating the first login password entered by the user and verifying its legality to improve the security of login authentication.
By increasing the login factor, the security of identity authentication is improved, the login authentication is prevented from being hacked or cracked, the terminal login security is ensured, illegal intrusion is avoided, and the terminal system is ensured.
Smart Images

Figure CN115913743B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a terminal security login method and device. Background Art
[0002] At present, the country vigorously advocates independent control, among which identity login authentication is a key part. Especially under the domestic platform, the secure login authentication of the terminal is particularly important. The existing terminal login methods, including the existing Ukey device login authentication method, mostly use the system's single user name and user password for login authentication. This method has great security risks, and the authentication data is easy to be cracked, which brings security risks such as data leakage to the terminal system. Therefore, it is necessary to study a more secure terminal login method. Summary of the invention
[0003] In view of this, the present invention provides a terminal security login method and device, which adopts a method of combining user information with a Ukey device for login authentication, and obtains a final login password by calculating a first login password input by the user, thereby making up for the low security of the login authentication method of a single username and user password, and at least partially solving the problems existing in the prior art.
[0004] The specific content of the invention is:
[0005] A terminal security login method, comprising:
[0006] In response to monitoring an operation of a user logging into a terminal device, a user name input by the user is obtained.
[0007] The device information of the encrypted Ukey device that has been connected to the terminal is decrypted according to the user name, and the device unique identifier of the encrypted Ukey device is read.
[0008] The device unique identifier is matched with the login verification information in the Ukey login policy, and if the match is successful, the user is prompted to enter the first login password.
[0009] A first login password input by a user is obtained, and the first login password is calculated using a preset calculation rule to obtain a second login password.
[0010] The second login password is verified, and if the verification is successful, the current user is allowed to log in.
[0011] Furthermore, the method also includes:
[0012] Determine the original Ukey device used to bind to the terminal device, and obtain the device information of the original Ukey device.
[0013] The device information is sent to the server so that the server generates a Ukey login policy for the terminal device; the Ukey login policy includes login verification information that matches the device information of the original Ukey device.
[0014] Receive the Ukey login policy sent by the server and input it into the PAM authentication module.
[0015] Furthermore, the method also includes:
[0016] Determine a target user name for logging into the terminal device, use the target user name to generate an encryption program for configuring the original Ukey device through the PAM authentication module, and send the encryption program to the original Ukey device to obtain the encrypted Ukey device.
[0017] Furthermore, the method further comprises:
[0018] A target first login password for logging into the terminal device is determined, and the target first login password is sent to the PAM authentication module for storage.
[0019] Further, decrypting the device information of the encrypted Ukey device that has been connected to the terminal according to the user name includes:
[0020] The PAM authentication module uses the user name input by the user to decrypt the device information of the encrypted Ukey device that has been connected to the terminal. If the decryption is successful, the device unique identifier of the encrypted Ukey device is read.
[0021] Furthermore, matching the unique device identifier with the login verification information in the Ukey login policy includes:
[0022] The device unique identifier is matched with the login verification information in the Ukey login policy in the PAM authentication module.
[0023] Further, the calculating the first login password by using a preset calculation rule includes:
[0024] The key generation algorithm is used to calculate the user name entered by the user, the device unique identifier of the encryption Ukey device, the first login password entered by the user and the current time to obtain the second login password.
[0025] Further, the verifying the second login password includes:
[0026] The PAM authentication module uses the key generation algorithm to calculate the target user name, target first login password, device unique identifier of the encryption Ukey device and current time corresponding to the current terminal device to obtain a verification password.
[0027] The second login password is matched with the verification password, and if the match is successful, it is determined that the second login password is successfully verified.
[0028] Further, after determining that the second login password is successfully verified, the method further includes:
[0029] Generate a login log and send the login log to the server.
[0030] A terminal security login device, comprising:
[0031] The user name acquisition module acquires the user name input by the user in response to monitoring the operation of the user logging into the terminal device.
[0032] The Ukey device information reading module is used to decrypt the device information of the encrypted Ukey device that has been connected to the terminal according to the user name, and read the device unique identifier of the encrypted Ukey device.
[0033] The Ukey login authentication module is used to match the unique identifier of the device with the login verification information in the Ukey login policy, and if the match is successful, prompt the user to enter the first login password.
[0034] The login password generation module is used to obtain a first login password input by a user, and calculate the first login password using a preset calculation rule to obtain a second login password.
[0035] The login password verification module is used to verify the second login password, and if the verification is successful, the current user is allowed to log in.
[0036] A computer device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the aforementioned terminal security login method when executing the computer program.
[0037] A computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the aforementioned terminal security login method.
[0038] The beneficial effects of the present invention are embodied in:
[0039] The present invention adopts the method of combining user information with an encrypted Ukey device for login authentication, and increases the login factor by encrypting the Ukey device to improve the security of identity authentication, which makes up for the low security of the login authentication method of a single user name and user password, solves the problem of being hacked and cracked by the login authentication, and ensures the security of the terminal login while effectively avoiding the risk of illegal intrusion through command escalation, ensuring the security of the terminal system. By calculating the first login password input by the user to obtain the second login password as the final terminal login password, and then verifying the legitimacy of the second login password, the security of the final login password can be improved, the risk of leakage caused by unfavorable password custody can be effectively reduced, and the terminal system security can be further ensured. The applied Ukey device is an encrypted Ukey device, which can effectively ensure the security of the Ukey device, increase the difficulty of cracking the Ukey device, and help ensure the login security of the terminal device. Decrypting the device information of the encrypted Ukey device according to the user name input by the user is a double insurance security login method, which not only verifies the user name input by the user, but also verifies the Ukey device of the access terminal, and improves the security of the login. After decrypting the device information of the encrypted Ukey device, read the device's unique identifier from it and match it with the login verification information in the Ukey login policy to verify the access status of the encrypted Ukey device. This can further ensure the legitimacy of the Ukey device accessing the terminal device, prevent illegal external devices from intruding into the terminal system, and further ensure the security of terminal login and terminal system security. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0041] Figure 1 This is a flow chart of a terminal security login method according to an embodiment of the present invention;
[0042] Figure 2 This is another flow chart of a terminal security login method according to an embodiment of the present invention;
[0043] Figure 3 The present invention is a structural diagram of a terminal security login device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0044] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0045] It should be noted that the following embodiments and features in the embodiments may be combined with each other in the absence of conflict; and, based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making any creative work are within the scope of protection of the present disclosure.
[0046] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.
[0047] The present invention provides a terminal security login method embodiment, such as Figure 1 As shown, including:
[0048] S11: In response to monitoring the operation of a user logging into a terminal device, obtaining a user name input by the user.
[0049] S12: Decrypt the device information of the encrypted Ukey device that has been connected to the terminal according to the user name, and determine whether the decryption is successful. If so, enter S13, otherwise prompt the user that the login failed. The device information includes the device unique identifier and device identity information, and the device identity information includes administrators and ordinary personnel.
[0050] S13: Read the unique device identifier of the encrypted Ukey device.
[0051] S14: Match the unique device identifier with the login verification information in the Ukey login policy to determine whether the match is successful. If so, proceed to S15, otherwise prompt the user that the login failed. The verification information includes the unique device identifier and the device identity information, and the device identity information includes administrators and ordinary personnel. If the match is successful, it is determined that the current encrypted Ukey device is the access device of the terminal.
[0052] S15: Prompt the user to enter the first login password.
[0053] S16: Obtain a first login password input by the user, and calculate the first login password using a preset calculation rule to obtain a second login password. The second login password is used as the final terminal login password.
[0054] S17: Verify the second login password to determine whether the verification is successful. If the verification is successful, the current user is allowed to log in. Otherwise, the user is prompted that the login failed.
[0055] Figure 1 The embodiment adopts a method of combining user information with a Ukey device for login authentication, which makes up for the low security of the login authentication method with a single username and user password, and solves the problem of login authentication being hacked and cracked. The login factor is increased by an external Ukey device to improve the security of identity authentication, and while ensuring the security of terminal login, it effectively avoids the risk of illegal intrusion through command escalation, ensures the security of the terminal system, and calculates the first login password entered by the user to obtain the second login password as the final terminal login password, and then verifies the legitimacy of the second login password, which can improve the security of the final login password, effectively reduce the risk of leakage caused by improper password storage, and further ensure the security of the terminal system. Figure 1 The Ukey device used in the embodiment is an encrypted Ukey device, which can effectively ensure the security of the Ukey device, increase the difficulty of cracking the Ukey device, and help ensure the login security of the terminal device. Decrypting the device information of the encrypted Ukey device according to the user name entered by the user is a double-insurance security login method, which not only verifies the user name entered by the user, but also verifies the Ukey device accessed to the terminal, thereby improving the security of the login. After decrypting the device information of the encrypted Ukey device, read the device unique identifier from it, and match it with the login verification information in the Ukey login policy to verify the access status of the encrypted Ukey device, which can further ensure the legitimacy of the Ukey device accessing the terminal device, prevent illegal external devices from intruding into the terminal system, and further ensure the security of the terminal login and the security of the terminal system.
[0056] Preferably, the method further comprises:
[0057] Determine the original Ukey device used to bind to the terminal device, and obtain the device information of the original Ukey device.
[0058] The device information is sent to the server so that the server generates a Ukey login policy for the terminal device; the Ukey login policy includes login verification information that matches the device information of the original Ukey device.
[0059] Receive the Ukey login policy sent by the server and input it into the PAM authentication module.
[0060] The above preferred scheme gives the generation process of the Ukey login policy and the information contained in the login verification information in the Ukey login policy. Using server-side computing resources to generate Ukey login policies is conducive to the management of Ukey login policies for each terminal device. At the same time, compared with the terminal device formulating its own Ukey login policy, it can effectively reduce the memory consumption of the terminal device and improve the performance of the terminal device. The PAM authentication module is a lightweight security authentication module that can securely manage the login authentication method of the terminal. Inputting the Ukey login policy into the PAM authentication module of the terminal device is conducive to the management of Ukey device access to the terminal device.
[0061] Preferably, the method further comprises:
[0062] Determine the target user name for logging into the terminal device, generate an encryption program for configuring the original Ukey device using the target user name through the PAM authentication module, and send the encryption program to the original Ukey device to obtain the encrypted Ukey device. The encryption program includes an encryption algorithm that can encrypt the device information of the original Ukey device. The encryption algorithm can be set by the administrator according to specific needs, such as encryption algorithms such as DES and AES, or an encryption algorithm based on the public key corresponding to the user.
[0063] Preferably, the method further comprises:
[0064] A target first login password for logging into the terminal device is determined, and the target first login password is sent to the PAM authentication module for storage. The target first login password is used to obtain a verification password through calculation to verify the legitimacy of the second login password.
[0065] Preferably, decrypting the device information of the encrypted Ukey device that has been connected to the terminal according to the user name includes:
[0066] The PAM authentication module uses the user name input by the user to decrypt the device information of the encrypted Ukey device that has been connected to the terminal. If the decryption is successful, the device unique identifier of the encrypted Ukey device is read. The encrypted Ukey device that can pass the access verification and is legal is encrypted using the target user name used to log in to the terminal device, so it must be decrypted using the user name input by the user. If the decryption is successful, it is considered that the user name entered by the user is correct, and then the device unique identifier in the device information of the encrypted Ukey device is further read for the next verification. If the decryption fails, at least one of the user name entered by the user and the encrypted Ukey device connected to the terminal device is problematic and cannot pass the login authentication.
[0067] Preferably, matching the device unique identifier with the login verification information in the Ukey login policy includes:
[0068] The unique identifier of the device is matched with the login verification information in the Ukey login policy in the PAM authentication module. If the match is successful, the encrypted Ukey device is determined as an access device, otherwise the encrypted Ukey device is determined as an external unknown device, login is refused, and no reading operation is performed on the device information to ensure the security of the terminal system.
[0069] Preferably, calculating the first login password using a preset calculation rule includes:
[0070] The key generation algorithm is used to calculate the user name entered by the user, the unique device identifier of the encrypted Ukey device, the first login password entered by the user and the current time to obtain the second login password. This preferred solution adds consideration of the current time, so that the second login password used for the final login terminal device changes dynamically according to different login times, increasing the unpredictability of the second login password, effectively avoiding the problem of password leakage caused by improper password management, and increasing the difficulty of cracking the second login password, further ensuring the security of the final login password and the security of the terminal system.
[0071] Preferably, the verifying the second login password includes:
[0072] The PAM authentication module uses the key generation algorithm to calculate the target user name, target first login password, device unique identifier of the encryption Ukey device and current time corresponding to the current terminal device to obtain a verification password.
[0073] The second login password is matched with the verification password, and if the match is successful, it is determined that the second login password is successfully verified.
[0074] The above preferred scheme provides a method for verifying the second login password. As long as the user name, the first login password, and the device unique identifier of the encrypted Ukey device entered by the user, one of which does not match the corresponding terminal device stored in the PAM authentication module, the calculated second login password cannot pass the verification, that is, the current login operation is not allowed.
[0075] Preferably, after determining that the second login password is successfully verified, the method further includes:
[0076] Generate a login log and send the login log to the server. The information in the login log includes at least one of the following: login time, login user name, login identity, login Ukey device information, login terminal device information.
[0077] To further illustrate the present invention, another terminal security login method embodiment is provided in combination with the above preferred solution. Figure 2 As shown, including:
[0078] S21: In response to monitoring the operation of a user logging into a terminal device, obtaining a user name input by the user.
[0079] S22: The device information of the encrypted Ukey device that has been connected to the terminal is decrypted using the user name input by the user through the PAM authentication module to determine whether the decryption is successful. If so, enter S23, otherwise prompt the user that the login failed.
[0080] The encrypted Ukey device is obtained by encrypting the original Ukey device bound to the terminal device according to the target user name used to log in to the terminal device, including: determining the target user name used to log in to the terminal device, using the target user name to generate an encryption program for configuring the original Ukey device through the PAM authentication module, and sending the encryption program to the original Ukey device to obtain the encrypted Ukey device. The encryption program contains an encryption algorithm that can encrypt the device information of the original Ukey device. The encryption algorithm can be set by the administrator according to specific needs, such as encryption algorithms such as DES and AES, or an algorithm based on the public key corresponding to the user. The device information includes a unique device identifier and device identity information. The device identity information includes administrators and ordinary personnel.
[0081] S23: Read the unique device identifier in the device information of the encrypted Ukey device.
[0082] S24: Match the unique identifier of the device with the login verification information in the Ukey login policy in the PAM authentication module to determine whether the match is successful. If so, proceed to S25; otherwise, prompt the user that the login failed.
[0083] The Ukey login policy is generated and obtained on the server side, including: determining the original Ukey device used to bind to the terminal device, and obtaining the device information of the original Ukey device; sending the device information to the server side, so that the server side generates a Ukey login policy for the terminal device, and the Ukey login policy contains login verification information that matches the device information of the original Ukey device; receiving the Ukey login policy sent by the server side, and inputting it into the PAM authentication module.
[0084] S25: Prompt the user to enter the first login password.
[0085] The PAM authentication module also needs to write the target first login password in advance, including: determining the target first login password for logging into the terminal device, and sending the target first login password to the PAM authentication module for storage. The target first login password is used to obtain the verification password by calculation in S27 to verify the legitimacy of the second login password.
[0086] S26: Obtain the first login password input by the user, and use the key generation algorithm to calculate the user name input by the user, the device information of the encrypted Ukey device, the first login password input by the user and the current time to obtain the second login password.
[0087] S27: The PAM authentication module uses the key generation algorithm to calculate the target user name, the target first login password, the device unique identifier of the encryption Ukey device and the current time corresponding to the current terminal device to obtain a verification password.
[0088] S28: Match the second login password with the verification password to determine whether they match successfully. If so, proceed to S29; otherwise, prompt the user that the login failed.
[0089] S29: Allow the current user to log in, generate a login log, and send the login log to the server.
[0090] Figure 2The embodiment adopts a method of combining user information with an encrypted Ukey device for login authentication. The login factor is increased by encrypting the Ukey device to improve the security of identity authentication, which makes up for the low security of the login authentication method of a single username and user password, solves the problem of login authentication being hacked and cracked, and ensures the security of terminal login while effectively avoiding the risk of illegal intrusion through command privilege escalation, ensuring the security of the terminal system, and calculating the second login password as the final terminal login password by the first login password entered by the user, and then verifying the legitimacy of the second login password, which can improve the security of the final login password, effectively reduce the risk of leakage caused by poor password storage, and further ensure the security of the terminal system. The applied Ukey device is an encrypted Ukey device, which can effectively ensure the security of the Ukey device, increase the difficulty of cracking the Ukey device, and help ensure the login security of the terminal device. Decrypting the device information of the encrypted Ukey device according to the username entered by the user is a double-insurance security login method, which not only verifies the username entered by the user, but also verifies the Ukey device accessing the terminal, thereby improving the security of the login. After decrypting the device information of the encrypted Ukey device, read the device's unique identifier from it and match it with the login verification information in the Ukey login policy to verify the access status of the encrypted Ukey device. This can further ensure the legitimacy of the Ukey device accessing the terminal device, prevent illegal external devices from intruding into the terminal system, and further ensure the security of terminal login and terminal system security. Figure 2 The embodiment described utilizes server-side computing resources to generate Ukey login policies, which is beneficial for managing the Ukey login policies of each terminal device. At the same time, compared with the terminal device formulating its own Ukey login policy, it can effectively reduce the memory consumption of the terminal device and improve the performance of the terminal device. The PAM authentication module is a lightweight security authentication module that can securely manage the login authentication method of the terminal. Inputting the Ukey login policy into the PAM authentication module of the terminal device is beneficial for managing the access of the Ukey device to the terminal device. The second login password used for the final login of the terminal device adds consideration of the current time, so that the second login password changes dynamically according to different login times, increases the unpredictability of the second login password, effectively avoids the problem of password leakage caused by improper password management, and increases the difficulty of cracking the second login password, further ensuring the security of the final login password and the security of the terminal system.
[0091] Figure 2 The embodiment is based on Figure 1 The preferred solution of the embodiment is obtained, therefore, Figure 2 The description of the above embodiment is relatively simple. Please refer to Figure 1 The embodiment described.
[0092] The present invention also provides an embodiment of a terminal security login device, such as Figure 3 As shown, including:
[0093] The user name acquisition module 31 acquires the user name input by the user in response to monitoring the operation of the user logging into the terminal device.
[0094] The Ukey device information reading module 32 is used to decrypt the device information of the encrypted Ukey device that has been connected to the terminal according to the user name, and read the device unique identifier of the encrypted Ukey device.
[0095] The Ukey login authentication module 33 is used to match the unique identifier of the device with the login verification information in the Ukey login policy, and if the match is successful, prompt the user to enter the first login password.
[0096] The login password generating module 34 is used to obtain a first login password input by a user, and calculate the first login password using a preset calculation rule to obtain a second login password.
[0097] The login password verification module 35 is used to verify the second login password, and if the verification is successful, the current user is allowed to log in.
[0098] Preferably, it also includes a Ukey login policy generation module, which is used to:
[0099] Determine the original Ukey device used to bind to the terminal device, and obtain the device information of the original Ukey device.
[0100] The device information is sent to the server so that the server generates a Ukey login policy for the terminal device; the Ukey login policy includes login verification information that matches the device information of the original Ukey device.
[0101] Receive the Ukey login policy sent by the server and input it into the PAM authentication module.
[0102] Preferably, it also includes a Ukey device encryption module for:
[0103] Determine a target user name for logging into the terminal device, use the target user name to generate an encryption program for configuring the original Ukey device through the PAM authentication module, and send the encryption program to the original Ukey device to obtain the encrypted Ukey device.
[0104] Preferably, it also includes a password storage module for:
[0105] A target first login password for logging into the terminal device is determined, and the target first login password is sent to the PAM authentication module for storage.
[0106] Preferably, decrypting the device information of the encrypted Ukey device that has been connected to the terminal according to the user name includes:
[0107] The PAM authentication module uses the user name input by the user to decrypt the device information of the encrypted Ukey device that has been connected to the terminal. If the decryption is successful, the device unique identifier of the encrypted Ukey device is read.
[0108] Preferably, matching the device unique identifier with the login verification information in the Ukey login policy includes:
[0109] The device unique identifier is matched with the login verification information in the Ukey login policy in the PAM authentication module.
[0110] Preferably, calculating the first login password using a preset calculation rule includes:
[0111] The key generation algorithm is used to calculate the user name entered by the user, the device unique identifier of the encryption Ukey device, the first login password entered by the user and the current time to obtain the second login password.
[0112] Preferably, the verifying the second login password includes:
[0113] The PAM authentication module uses the key generation algorithm to calculate the target user name, target first login password, device unique identifier of the encryption Ukey device and current time corresponding to the current terminal device to obtain a verification password.
[0114] The second login password is matched with the verification password, and if the match is successful, it is determined that the second login password is successfully verified.
[0115] Preferably, after determining that the second login password is successfully verified, the login password verification module 35 is further used to:
[0116] Generate a login log and send the login log to the server.
[0117] Figure 3The embodiment adopts a method of combining user information with a Ukey device for login authentication, which makes up for the low security of the login authentication method with a single username and user password, and solves the problem of login authentication being hacked and cracked. The login factor is increased by an external Ukey device to improve the security of identity authentication, and while ensuring the security of terminal login, it effectively avoids the risk of illegal intrusion through command escalation, ensures the security of the terminal system, and calculates the first login password entered by the user to obtain the second login password as the final terminal login password, and then verifies the legitimacy of the second login password, which can improve the security of the final login password, effectively reduce the risk of leakage caused by improper password storage, and further ensure the security of the terminal system. Figure 3 The Ukey device used in the embodiment is an encrypted Ukey device, which can effectively ensure the security of the Ukey device, increase the difficulty of cracking the Ukey device, and help ensure the login security of the terminal device. Decrypting the device information of the encrypted Ukey device according to the user name entered by the user is a double-insurance security login method, which not only verifies the user name entered by the user, but also verifies the Ukey device accessed to the terminal, thereby improving the security of the login. After decrypting the device information of the encrypted Ukey device, read the device unique identifier from it, and match it with the login verification information in the Ukey login policy to verify the access status of the encrypted Ukey device, which can further ensure the legitimacy of the Ukey device accessing the terminal device, prevent illegal external devices from intruding into the terminal system, and further ensure the security of the terminal login and the security of the terminal system.
[0118] Figure 3 The embodiment is Figure 1 , Figure 2 The device embodiment corresponding to the method embodiment, Figure 3 Part of the implementation process of the embodiment is Figure 1 , Figure 2 The embodiments are similar, therefore, Figure 3 The description of the above embodiment is relatively simple. Please refer to Figure 1 , Figure 2 The embodiment described.
[0119] The present invention also provides an embodiment of a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in the above embodiment is implemented. The method can be found in Figure 1 , Figure 2 The description of the embodiment will not be repeated here.
[0120] An embodiment of the present invention further provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the method described in the above embodiment.
[0121] The present invention adopts the method of combining user information with an encrypted Ukey device for login authentication, and increases the login factor by encrypting the Ukey device to improve the security of identity authentication, which makes up for the low security of the login authentication method of a single user name and user password, solves the problem of being hacked and cracked by the login authentication, and ensures the security of the terminal login while effectively avoiding the risk of illegal intrusion through command escalation, ensuring the security of the terminal system. By calculating the first login password input by the user to obtain the second login password as the final terminal login password, and then verifying the legitimacy of the second login password, the security of the final login password can be improved, the risk of leakage caused by unfavorable password custody can be effectively reduced, and the terminal system security can be further ensured. The applied Ukey device is an encrypted Ukey device, which can effectively ensure the security of the Ukey device, increase the difficulty of cracking the Ukey device, and help ensure the login security of the terminal device. Decrypting the device information of the encrypted Ukey device according to the user name input by the user is a double insurance security login method, which not only verifies the user name input by the user, but also verifies the Ukey device of the access terminal, and improves the security of the login. After decrypting the device information of the encrypted Ukey device, read the device's unique identifier from it and match it with the login verification information in the Ukey login policy to verify the access status of the encrypted Ukey device. This can further ensure the legitimacy of the Ukey device accessing the terminal device, prevent illegal external devices from intruding into the terminal system, and further ensure the security of terminal login and terminal system security.
[0122] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A terminal security login method, It is characterized in that include: In response to monitoring an operation of a user logging into a terminal device, obtaining a user name input by the user; Decrypt the device information of the encrypted Ukey device that has been connected to the terminal according to the user name, and read the device unique identifier of the encrypted Ukey device; Match the unique device identifier with the login verification information in the Ukey login policy, and if the match is successful, prompt the user to enter the first login password; Obtaining a first login password input by a user, and calculating the first login password using a preset calculation rule to obtain a second login password; The second login password is verified, and if the verification is successful, the current user is allowed to log in.
2. The method according to claim 1, It is characterized in that The method also includes: Determine the original Ukey device used to bind to the terminal device, and obtain device information of the original Ukey device; Send the device information to the server, so that the server generates a Ukey login policy for the terminal device; the Ukey login policy contains login verification information that matches the device information of the original Ukey device; Receive the Ukey login policy sent by the server and input it into the PAM authentication module.
3. The method according to claim 2, It is characterized in that The method also includes: Determine a target user name for logging into the terminal device, use the target user name to generate an encryption program for configuring the original Ukey device through the PAM authentication module, and send the encryption program to the original Ukey device to obtain the encrypted Ukey device.
4. The method according to claim 2, It is characterized in that The method further comprises: A target first login password for logging into the terminal device is determined, and the target first login password is sent to the PAM authentication module for storage.
5. The method according to claim 3, It is characterized in that The decrypting the device information of the encrypted Ukey device that has been connected to the terminal according to the user name includes: The PAM authentication module uses the user name input by the user to decrypt the device information of the encrypted Ukey device that has been connected to the terminal. If the decryption is successful, the device unique identifier of the encrypted Ukey device is read.
6. The method according to claim 2, It is characterized in that The matching of the unique device identifier with the login verification information in the Ukey login policy includes: The device unique identifier is matched with the login verification information in the Ukey login policy in the PAM authentication module.
7. The method according to any one of claims 1 to 6, It is characterized in that The calculating the first login password by using a preset calculation rule includes: The key generation algorithm is used to calculate the user name entered by the user, the device unique identifier of the encryption Ukey device, the first login password entered by the user and the current time to obtain the second login password.
8. The method according to claim 7, It is characterized in that The verifying the second login password includes: The PAM authentication module uses the key generation algorithm to calculate the target user name, the target first login password, the device unique identifier of the encryption Ukey device and the current time corresponding to the current terminal device to obtain a verification password; The second login password is matched with the verification password, and if the match is successful, it is determined that the second login password is successfully verified.
9. The method according to claim 8, It is characterized in that After the determination that the second login password is successfully verified, the method further includes: Generate a login log and send it to the server.
10. A terminal security login device, It is characterized in that include: A user name acquisition module, in response to monitoring the operation of the user logging into the terminal device, acquires the user name input by the user; A Ukey device information reading module, used to decrypt the device information of the encrypted Ukey device that has been connected to the terminal according to the user name, and read the device unique identifier of the encrypted Ukey device; A Ukey login authentication module, used to match the unique identifier of the device with the login verification information in the Ukey login policy, and if the match is successful, prompt the user to enter the first login password; A login password generation module, used to obtain a first login password input by a user, and calculate the first login password using a preset calculation rule to obtain a second login password; The login password verification module is used to verify the second login password, and if the verification is successful, the current user is allowed to log in.
Citation Information
Patent Citations
Dynamic digital right management method and system based on identification password
CN105553662A
Multi-factor authentication method and system based on encryption card and UsbKey, and security gateway
CN109462572A