Password String Feature Recognition Method and Device
By performing nonlinear operations on the password plaintext entered in the login service system to generate a ciphertext array and performing feature recognition, the problem of password plaintext access frequency and duration in memory is solved, and the risk of password leakage is reduced.
Patent Information
- Application Number
- CN202211551386.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-12-05
AI Technical Summary
When logging into the business system in the prior art, it is difficult to identify and analyze the entered password in a non-plain text state, resulting in excessive number of password clear texts being stored and retrieved in memory and the time being too long, which increases the risk of password clear text being leaked.
By performing nonlinear operations on the input password plaintext, a ciphertext array is generated, and feature recognition is performed based on the ciphertext array, including identifying whether the password is repeated, continuous, and whether it contains sensitive strings, reducing the access frequency and duration of the password plaintext in memory.
It realizes feature identification and analysis of passwords in non-plain text states, reducing the risk of password clear text leakage. Attackers cannot steal password clear text from memory, and it is difficult to reversely deduce password clear text based on the ciphertext array.
Smart Images

Figure CN116318607B_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to the field of computer technology. More specifically, this disclosure relates to a method and apparatus for identifying password string features. Background Art
[0002] In current Internet usage scenarios, passwords are widely used. Especially when logging in to business systems using the Internet, users are generally required to enter passwords to verify their identities, such as various mobile phone apps, social service websites, life service websites, and government affairs systems.
[0003] However, both mobile phones and PC terminals are at risk of being infected by viruses. If there is a Trojan virus in the operating environment, during the process of a user entering a password to log in to a business system, the Trojan virus can monitor the changes in memory data during the password input process and obtain the clear text of the password entered by the user, thus causing the leakage of the password clear text.
[0004] However, current login business systems often have a need to perform feature analysis on passwords. For example, in account registration services, it is usually necessary to analyze whether the password clear text is repeated, consecutive, and / or contains certain sensitive strings that are prone to leakage and related to personal information. It is difficult to avoid the situation where the password clear text is accessed too many times and stored for too long in memory, which further increases the probability that the exposed position of the password clear text will be stolen by viruses.
[0005] In view of this, there is an urgent need to provide a password string feature recognition solution to perform feature recognition and analysis on the input password in a non-clear text state, and reduce the risk of leakage of the password clear text during the string feature analysis process. Summary of the Invention
[0006] To solve at least one or more of the above-mentioned technical problems, this disclosure proposes a password string feature recognition solution in multiple aspects.
[0007] In a first aspect, this disclosure provides a method for identifying password string features, including: obtaining input characters; the set of input characters constitutes the password clear text; generating a ciphertext array based on the input characters, where the elements in the ciphertext array are the results of non-linear operations corresponding to the input characters; the non-linear operation uses a non-linear monotonic operator; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the password clear text.
[0008] In some embodiments, the feature recognition results include: all passwords are repeated, partial passwords are repeated, and passwords are not repeated; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the password plaintext, including: calculating the number of elements of each type in the ciphertext array; if the maximum value among the number of elements of each type is equal to the total number of input characters, the feature recognition result of the password plaintext is that all passwords are repeated; if the maximum value among the number of elements of each type is within a preset repetition value range, the feature recognition result of the password plaintext is that partial passwords are repeated; if the maximum value among the number of elements of each type is 1, the feature recognition result of the password plaintext is that passwords are not repeated.
[0009] In some embodiments, partial password repetition includes: repeated character combinations; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the password plaintext, further including: if in the ciphertext array, each type of element is adjacent to at least one same-type element, the feature recognition result of the password plaintext is repeated character combinations.
[0010] In some embodiments, the feature recognition results include: all passwords are consecutive; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the password plaintext, including: performing precise matching retrieval in the continuous object set based on the hash value of the ciphertext array; the continuous object set is a hash value set obtained by performing non-linear operations and hash operations on continuous password plaintexts in advance; if there is a precise matching object of the ciphertext array in the continuous object set, the feature recognition result of the password plaintext is that all passwords are consecutive, and the maximum consecutive number of the password plaintext is the initial consecutive number, and the initial consecutive number is the total number of input characters.
[0011] In some embodiments, the feature recognition results further include: partial passwords are consecutive and passwords are not consecutive; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the password plaintext, further including: if there is no precise matching object of the ciphertext array in the continuous object set, perform the following process: subtract one from the initial consecutive number; extract p adjacent elements from the ciphertext array to form the first sub-ciphertext array; where p is the current initial consecutive number; perform precise matching retrieval in the continuous object set based on the hash value of the first sub-ciphertext array, if there is no precise matching object of the first sub-ciphertext array in the continuous object set, return to execute the step of subtracting one from the initial consecutive number until the current initial consecutive number is determined after meeting the continuous retrieval stop condition; if the current initial consecutive number is 1, the feature recognition result of the password plaintext is that passwords are not consecutive, otherwise the feature recognition result of the password plaintext is that partial passwords are consecutive, and the maximum consecutive number of the password plaintext is the current initial consecutive number; the continuous retrieval stop condition includes: there is a precise matching object of the first sub-ciphertext array in the continuous object set or the current initial consecutive number is equal to 1.
[0012] In some embodiments, the continuous password part further includes: concatenating consecutive characters; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the cleartext password, and further includes: after satisfying the retrieval stop condition, if the current initial continuous count is not 1, dividing the ciphertext array into n sub-arrays based on the maximum continuous count N of the cleartext password; where n = L / N, and L is the total number of input characters; if the n sub-arrays are the same, the feature recognition result of the cleartext password is the concatenation of consecutive characters.
[0013] In some embodiments, the feature recognition result includes: the password contains a sensitive string; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the cleartext password, including: performing a precise matching retrieval in the sensitive object set based on the hash value of the ciphertext array; the sensitive object set is a hash value set obtained by performing non-linear operations and hash operations on sensitive strings in advance; if there is a precise matching object of the ciphertext array in the sensitive object set, the feature recognition result of the cleartext password is that the password contains a sensitive string, and the maximum included length of the cleartext password is the initial included length, and the initial included length is the total number of input characters.
[0014] In some embodiments, the feature recognition result further includes: the password does not contain a sensitive string; performing feature recognition based on the ciphertext array to obtain the feature recognition result of the cleartext password, and further includes:
[0015] If there is no precise matching object of the ciphertext array in the sensitive object set, the following process is executed: subtracting one from the initial included length; extracting q adjacent elements from the ciphertext array to form a second sub-ciphertext array; where q is the current initial included length; performing a precise matching retrieval in the sensitive object set based on the second sub-ciphertext array, if there is no precise matching object of the second sub-ciphertext array in the sensitive object set, return to execute the step of subtracting one from the initial included length until the current initial included length is determined after satisfying the sensitive retrieval stop condition; if the current initial included length is less than the minimum length of the sensitive string, the feature recognition result of the cleartext password is that the password does not contain a sensitive string, otherwise the feature recognition result of the cleartext password is that the password contains a sensitive string, and the maximum included length of the cleartext password is the current initial included length; the sensitive retrieval stop condition includes: there is a precise matching object of the second sub-ciphertext array in the continuous object set or the current initial included length is less than the minimum length of the sensitive string.
[0016] In a second aspect, the present disclosure provides a password string feature recognition device, including: a password input module, configured to obtain input characters and generate a ciphertext array based on the input characters; where the set of input characters constitutes the cleartext password; the elements in the ciphertext array are the results of non-linear operations on the corresponding input characters; the non-linear operation uses a non-linear monotonic operator; a feature extraction module, performing feature recognition based on the ciphertext array to obtain the feature recognition result of the cleartext password.
[0017] In some embodiments, the password string feature recognition device further includes: an initialization module, configured to perform non-linear operations and hash operations on the continuous password plaintext to obtain a continuous object set, and generate a sensitive string and perform non-linear operations and hash operations on the sensitive string to obtain a sensitive object set.
[0018] Through the password string feature recognition method provided above, the embodiments of the present disclosure use a non-linear monotonic operator to perform a function operation on the input characters to obtain a non-linear operation result, thereby obtaining a ciphertext array corresponding to the password plaintext, so that the password stored in the memory is in a non-plaintext state. During the password string feature recognition process, the accessed data objects are all mapping values without a linear relationship, and there is no need for the password plaintext to directly participate in the feature recognition process, so that an attacker cannot steal the password plaintext from the memory; moreover, due to the use of a non-linear monotonic operator, the relationship between the password plaintext and the ciphertext array is a non-linear mapping relationship, and it is also difficult for an attacker to reverse the password plaintext based on the ciphertext array, thereby greatly reducing the risk of password plaintext leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] By reading the following detailed description with reference to the accompanying drawings, the above and other objects, features, and advantages of the exemplary embodiments of the present disclosure will become readily understood. In the drawings, several embodiments of the present disclosure are shown in an exemplary and non-limiting manner, and the same or corresponding reference numerals represent the same or corresponding parts, wherein:
[0020] Figure 1 An exemplary flowchart of the password string feature recognition method according to some embodiments of the present disclosure is shown;
[0021] Figure 2 An exemplary flowchart of the repeated feature recognition method according to some embodiments of the present disclosure is shown;
[0022] Figure 3 An exemplary flowchart of the continuous feature recognition method according to some embodiments of the present disclosure is shown;
[0023] Figure 4 An exemplary flowchart of the sensitive string feature recognition method according to some embodiments of the present disclosure is shown;
[0024] Figure 5 An exemplary structural block diagram of the password string feature recognition device according to the embodiments of the present disclosure is shown;
[0025] Figure 6 An exemplary structural block diagram of the electronic device according to the embodiments of the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
[0027] It should be understood that the terms "including" and "comprising" used in the specification and claims of the present disclosure indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0028] It should also be understood that the terms used in the specification of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure. As used in the specification and claims of the present disclosure, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms. It should be further understood that the term "and / or" used in the specification and claims of the present disclosure refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0029] As used in this specification and the claims, the term "if" may be construed as "when", "once", "in response to determining", or "in response to detecting" depending on the context. Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be construed as meaning "once determined", "in response to determining", "once detected [the described condition or event]", or "in response to detecting [the described condition or event]" depending on the context.
[0030] The specific embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0031] Exemplary application scenario
[0032] When using the Internet to log in to a business system, users generally need to enter a password to verify their identity. To ensure password security and reduce the risk of password theft, some websites or APPs with higher security requirements will require that the complete password plaintext should not appear as much as possible during the password input process.
[0033] However, in the current password usage scenarios, there is still a large demand for password feature analysis. For example, it is necessary to know the types of characters in the password, whether the input password is repeated or consecutive, the maximum number of repetitions or the maximum number of consecutive occurrences in the input password, and whether the password contains strings of personal information that are easily leaked, etc. During the process of performing password feature analysis, the password plaintext is frequently accessed and stored in memory, and some Trojan viruses can obtain the password plaintext entered by the user by monitoring the changes in memory data during the password input process. The more times and the longer the password plaintext exists in memory, the more likely it is to expose its location and be stolen.
[0034] Exemplary password string feature recognition scheme
[0035] In view of this, the embodiments of the present disclosure provide a password string feature recognition scheme. After performing non-linear operations on each character of the password plaintext, a mapping value of the password plaintext is formed, that is, a ciphertext array corresponding to the password plaintext, so that the password stored in memory is in a non-plaintext state. String feature recognition is performed on the non-plaintext state ciphertext array, reducing the access frequency and existence duration of the password plaintext in memory, so that the attacker can neither steal the password plaintext from memory nor easily reverse deduce the password plaintext from the ciphertext array, thereby greatly reducing the risk of password plaintext leakage.
[0036] Figure 1 An exemplary flowchart of a password string feature recognition method according to some embodiments of the present disclosure is shown.
[0037] As Figure 1 shown, in step 101, input characters are obtained.
[0038] In practical applications, the password input process is a process of inputting characters one by one, and the set of input characters of the user constitutes the password plaintext.
[0039] It should be noted that in the embodiments of the present disclosure, the input characters are not directly stored in memory to form a password string, but are processed to form password-related data in a non-plaintext state.
[0040] In step 102, a ciphertext array is generated based on the input characters.
[0041] In the embodiments of the present disclosure, after each input character is obtained, a non-linear monotonic operator is selected to perform non-linear operations on the input character until all input characters are operated, and a ciphertext array corresponding to the password plaintext is obtained.
[0042] Taking the password plaintext "ab" as an example, its ASCII code values correspond to 97 and 98, and the logarithmic function ln is used xPerform a non - linear operation as a non - linear monotonic operator. After inputting "a", the array P = [4.574710978503383]. Then input "b", and the array P is updated to P = [4.574710978503383, 4.584967478670572], obtaining the ciphertext array [4.574710978503383, 4.584967478670572] corresponding to the plaintext password "ab".
[0043] In practical applications, the password string feature recognition scheme disclosed herein is applicable to a variety of non - linear monotonic operators. For example: the power function x 3 and the logarithmic function ln x etc., which is not uniquely limited here.
[0044] Since the correlation between the result of the logarithmic function and the input characters is very low, based on the discrete logarithm problem, it is difficult to deduce the password plaintext from the non - linear operation result of the logarithmic function. Therefore, in order to improve password security, the disclosed scheme can select the logarithmic function ln x as the non - linear monotonic operator.
[0045] It should be noted that in the embodiments of the present disclosure, in one password string feature recognition process, the non - linear operation uses the same non - linear monotonic operator, that is, a non - linear monotonic operator is fixedly used for a password plaintext.
[0046] In step 103, based on the ciphertext array, feature recognition is performed to obtain the feature recognition result of the password plaintext.
[0047] In the embodiments of the present disclosure, performing feature recognition on the ciphertext array may include one or more of the following recognition tasks: identifying whether the password is repeated, identifying whether the password is continuous, and identifying whether the password contains sensitive strings. Further, the recognition task may also include: identifying the character types of the password.
[0048] Through the mapping relationship between the ciphertext array and the password plaintext, the feature recognition result of the ciphertext array can reflect the feature recognition result of its corresponding password plaintext.
[0049] Since in step 103, feature recognition is based on the ciphertext array, that is, the data stored in the memory is the mapped value of the password plaintext, rather than the password plaintext itself. Therefore, even if an attacker monitors the change of the memory data during the password input process, only the ciphertext array can be obtained. Also, because the calculation process of the ciphertext array uses a non - linear monotonic operator and the relationship between the password plaintext and the ciphertext array is a non - linear mapping relationship, it is difficult for the attacker to reverse - deduce the password plaintext from the ciphertext array, thus greatly reducing the risk of password plaintext leakage.
[0050] The recognition process of repeated features will be described below with reference to the accompanying drawings.
[0051] Figure 2 An exemplary flowchart of the repeated feature recognition method according to some embodiments of the present disclosure is shown. It can be understood that the repeated feature recognition method is a specific implementation of the foregoing step 103. Therefore, the features described above in conjunction with Figure 1 can be similarly applied herein.
[0052] As Figure 2 shown, in step 201, the number of elements of each type in the ciphertext array is calculated.
[0053] Since the ciphertext array is calculated using a non-linear monotonic operator, for the same input character, the result of its non-linear operation is the same. For different input characters, the results of their non-linear operations are also different. Therefore, the same elements in the ciphertext array can be regarded as the same input characters. According to the number of elements of each type in the ciphertext array, the repetition count of repeated characters in the password plaintext can be reflected.
[0054] In step 202, the numerical range to which the maximum value among the number of elements of each type belongs is determined.
[0055] If it is equal to the total number of input characters, step 203 is executed;
[0056] If it is within the preset repetition numerical range, step 204 is executed;
[0057] If it is equal to 1, step 205 is executed.
[0058] In step 203, the feature recognition result of the password plaintext is output as all passwords repeated.
[0059] In step 204, the feature recognition result of the password plaintext is output as part of the passwords repeated.
[0060] In step 205, the feature recognition result of the password plaintext is output as no passwords repeated.
[0061] When the maximum value among the number of elements of each type is equal to the total number of input characters, it means that all input characters belong to the same character. That is to say, the password plaintext is composed of one input character repeated. The password plaintext has the feature of all passwords repeated.
[0062] Furthermore, according to the output result that the feature recognition result of the password plaintext is all passwords repeated, the system can prompt the user that the security of the password plaintext is weak to remind the user to change or modify the password.
[0063] In some embodiments, the preset repetition value range can be set to [2, Max), where Max is the total number of input characters. It can be understood that in actual application, the preset repetition value range can also be adjusted according to actual needs, for example, the preset repetition value range can be set to [4, Max), etc., which is not a unique limitation here.
[0064] Furthermore, a repetition number threshold can be set based on the number of elements of each category in the ciphertext array. When the maximum value of the number of elements of each category is greater than or equal to the repetition number threshold, it means that the number of repeated characters in the password plaintext is too many and the security of the password plaintext is poor, then a prompt is issued to remind the user to change or modify the password.
[0065] When the maximum value of the number of elements of each type is 1, it means that there is only one element of each type in the ciphertext array, that is, there are no repeated input characters in the password plaintext, and the password plaintext has the characteristic of non-repetitive password.
[0066] On the basis of the corresponding embodiment of the above-mentioned repeated feature recognition method, further, the present disclosure can also identify whether the password plaintext is a repeated character combination based on the ciphertext array.
[0067] Repeated character combination refers to the characteristics of a string formed by combining several single-type character strings, where a single-type character string is a string formed by the same character being repeated continuously. For example, "aaabbbccc", "aabbaacc" and "aabbbbccddd" all have the characteristics of repeated character combination.
[0068] Exemplarily, after obtaining the ciphertext array corresponding to the password plaintext, if in the ciphertext array, each type of element is adjacent to at least one element of the same type, then the feature recognition result of the password plaintext is a repeated character combination.
[0069] The above describes an application scenario of using the password string feature recognition scheme for password repetition feature recognition tasks. The following describes an application scenario of using the password string feature recognition scheme for password continuous feature recognition in conjunction with the accompanying drawings.
[0070] Figure 3 FIG. 1 shows an exemplary flow chart of a continuous feature recognition method according to some embodiments of the present disclosure. It can be understood that the continuous feature recognition method is a specific implementation of the aforementioned step 103, so the aforementioned method is combined with the continuous feature recognition method. Figure 1 The features described can analogously apply here.
[0071] like Figure 3 As shown, in step 301, an exact match search is performed in a continuous object set based on the hash value of the ciphertext array.
[0072] Among them, the hash value of the ciphertext array is obtained by concatenating the elements in the ciphertext array in sequence to form a ciphertext field and then processing the ciphertext field through a hash function; the continuous object set is an array hash value set obtained by performing non-linear operations and hash operations on continuous plaintext passwords in advance.
[0073] Exemplarily, taking the plaintext password "abce" as an example, its ASCII code values correspond to 97, 98, 99, and 100. After performing the logarithmic function ln x operation, four floating-point numbers 4.574710978503383, 4.584967478670572, 4.59511985013459, and 4.605170185988092 are obtained. The memory values of these four floating-point numbers are obtained and converted into hexadecimal, resulting in 40926408, 4092b80e, 40930b39, and 40935d8e. Then, these four hexadecimal strings are concatenated together and their hash value is calculated, that is, the hash value corresponding to the non-linear mapping of the plaintext password "abcd" is obtained. For example, if the md5 hash algorithm is used, the hash value "501d94de43dc896a744349f6581e72ac" is obtained.
[0074] Before performing step 301, the system pre-generates a continuous object set, which contains the hash values corresponding to the non-linear mapping values of all possible continuous strings. Since this hash value is obtained by concatenating the ciphertext array and then calculating, due to the one-way nature of the hash function, even if the continuous object set is exposed, the attacker cannot reverse the ciphertext array based on the hash value, let alone obtain the characteristics of the plaintext password corresponding to the hash value in the continuous object set.
[0075] Exemplarily, assuming that the maximum password length set by the system is 8, there are 25 + 24 + 23 + 22 + 21 + 20 + 19 = 154 possible strings of increasing consecutive lowercase letters, including cases of 2-character consecutive to 8-character consecutive, such as: "ab", "bc", "cdef", and "abcdefgh", etc. Similarly, there are 154 possible strings of increasing consecutive uppercase letters, such as: "ABCDEFGH", "STUV", and "XY", etc. By analogy, there are 9 + 8 + 7 + 6 + 5 + 4 + 3 = 42 possible strings of increasing consecutive numbers. Thus, there are a total of 350 possible strings of increasing consecutive strings, and there are also a total of 350 possible strings of decreasing consecutive strings. Calculate the hash values of the ciphertext arrays corresponding to a total of 700 possible strings to form the above-mentioned continuous object set.
[0076] Exact match retrieval refers to a retrieval method where the retrieval term is exactly the same as a certain field in the resource library. Only when there is a hash value in the continuous object set that is exactly the same as the hash value of the ciphertext array can the match be successful.
[0077] In step 302, it is determined whether there is an exact match object for the ciphertext array.
[0078] If so, step 303 is executed.
[0079] In step 303, the feature recognition result of the plaintext password is output as all passwords being continuous, and the maximum continuous number of the plaintext password is output as the initial continuous number.
[0080] Among them, the initial continuous number is the total number of input characters.
[0081] A successful match indicates that the plaintext password used to construct the continuous object set contains the plaintext password corresponding to the ciphertext array. Since the plaintext passwords used in the continuous object set all have the characteristic of password continuity, after a successful match, it can be determined that the plaintext password has the characteristic of password continuity.
[0082] Since step 301 is an exact match retrieval based on the entire ciphertext array, a successful match at this time indicates that the entire ciphertext array is continuous, that is, the feature recognition result of the plaintext password is that all passwords are continuous, and the maximum continuous number of the plaintext password is equal to the total number of input characters.
[0083] Furthermore, based on the output result that the feature recognition result of the plaintext password is that all passwords are continuous, the system can prompt the user that the security of this plaintext password is weak to remind the user to change or modify the password.
[0084] Furthermore, the feature recognition result can also include: partial password continuity and non - continuity of the password.
[0085] In step 302, if there is no exact match object for the ciphertext array in the continuous object set, steps 304 to 308 can be executed to determine the feature recognition result of the plaintext password and the maximum continuous number of the plaintext password.
[0086] In step 304, subtract one from the initial continuous number.
[0087] In step 305, p adjacent elements are extracted from the ciphertext array to form the first sub - ciphertext array.
[0088] Among them, p is the current initial continuous number.
[0089] In practical applications, the plaintext password may contain some consecutive characters. After identifying that the plaintext password does not have the feature of all consecutive characters of the password, several consecutive elements can be extracted from the ciphertext array to form a first sub-ciphertext array. Among them, the number of elements in the first sub-ciphertext array extracted in each round decreases round by round.
[0090] Exemplarily, assume that the plaintext password is "abc12345". Then, through the above steps 301 to 302, it can be identified that the 8-bit plaintext password does not have the feature of all consecutive characters of the password. Then, 7 consecutive characters in the plaintext password are extracted to form a first sub-ciphertext array, including: "abc1234" and "bc12345". If it still does not have the feature of all consecutive characters of the password, then in the next round, 6 consecutive characters are extracted, for example: "abc123", "bc1234", and "c12345".
[0091] It should be noted that in the above description process, the first sub-ciphertext array should actually be the mapping value obtained after non-linear operation. However, for the convenience of understanding by those skilled in the art, it is described in the form of the plaintext state in the previous description process. It can be understood that in the system processing process, the first sub-ciphertext array does not present in the data form similar to "abc1234".
[0092] In step 306, it is determined whether there is an exact matching object of the first sub-ciphertext array in the continuous object set.
[0093] If so, step 307 is executed;
[0094] If not, return to execute step 304 until the continuous retrieval stop condition is satisfied, and then execute step 307.
[0095] Among them, the continuous retrieval stop condition includes the following two:
[0096] One is that there is an exact matching object of the first sub-ciphertext array in the continuous object set. Meeting this condition indicates that the continuous feature has been identified in the plaintext password.
[0097] The other is that the current initial continuous number is equal to 1. When the current initial continuous number is equal to 1, the first sub-ciphertext array extracted is a single character, which is not sufficient to determine the continuous feature.
[0098] Meeting any of the above continuous retrieval stop conditions, the retrieval is stopped and step 307 is executed.
[0099] In step 307, the current initial continuous number is determined.
[0100] In step 308, the feature recognition result and the maximum continuous number of the plaintext password are determined according to the current initial continuous number.
[0101] Specifically:
[0102] If the current initial consecutive count is 1, the feature recognition result of the password plaintext is that the password is not consecutive, and the maximum consecutive count of the password plaintext is 1;
[0103] If the current initial consecutive count is not 1, the feature recognition result of the password plaintext is that the password is partially consecutive, and the maximum consecutive count of the password plaintext is the current initial consecutive count.
[0104] Still taking the password plaintext "abc12345" as an example, after extracting 6 consecutive characters in position, the following first sub-ciphertext arrays are obtained: "abc123", "bc1234", and "c12345". At this time, the initial consecutive count is 6. It is judged that there is no exact matching object of the first sub-ciphertext array in the consecutive object set. Then, after subtracting 1 from the initial consecutive count, the initial consecutive count is 5 at this time. Extract 5 characters from the ciphertext array to obtain the following first ciphertext arrays: "abc12", "bc123", "c1234", and "12345". Among them, it is found that "12345" has an exact matching object in the consecutive object set, and the initial consecutive count is 5 at this time. It can be known that the feature recognition result of the password plaintext is that the password is partially consecutive, and the maximum consecutive count of the password plaintext is 5.
[0105] Suppose the password plaintext is "2431". This 4-bit password plaintext does not have the feature of all consecutive passwords. Extract 3 consecutive characters in position to get "243" and "431", and it is found that they are not consecutive. Then extract 2 consecutive characters in position to get "24", "43", and "31", and it is found that they are not consecutive. Then, after subtracting 1 from the initial consecutive count, the current initial consecutive count is equal to 1. At this time, the consecutive retrieval stop condition is triggered. Since the current initial consecutive count is 1, the feature recognition result of the password plaintext is that the password is not consecutive, and the maximum consecutive count of the password plaintext is 1.
[0106] It should be noted that in the above description process, the first sub-ciphertext array should actually be the mapping value obtained after non-linear operation. However, for the convenience of those skilled in the art to understand, the presentation form in the plaintext state is used in the above description process. It can be understood that in the system processing process, the first sub-ciphertext array does not present in data forms such as "abc12" and "243".
[0107] On the basis of the corresponding embodiment of the above consecutive feature recognition method, further, this disclosure can also identify whether the password plaintext with the feature of partially consecutive passwords is composed of consecutive characters based on the ciphertext array.
[0108] Exemplarily, after the retrieval stop condition is met, if the current initial consecutive count is not 1, the ciphertext array is divided into n sub-arrays based on the maximum consecutive count N of the plaintext password; if these n sub-arrays are identical, the feature recognition result of the plaintext password is consecutive character concatenation. Herein, n = L / N, where L is the total number of characters of the input characters.
[0109] Consecutive character concatenation refers to the feature of a string formed by concatenating several consecutive strings, such as: "abcabcabc" and "123123", etc.
[0110] Taking the plaintext password "123123" as an example, through the above steps 301 to 308, it can be known that the maximum consecutive count N of this plaintext password is 3. Then, the elements consecutive at every three positions in the ciphertext array are divided into one sub-array, forming the following two sub-arrays "123" and "123". Since these two sub-arrays are identical, the feature recognition result of this plaintext password is output as consecutive character concatenation.
[0111] Furthermore, the above-mentioned division method with non-repeating sub-array positions is adopted to identify whether the plaintext password has the feature of consecutive character concatenation. In some other embodiments, a division method with repeating sub-array positions can also be adopted to identify the feature of a password string such as the plaintext password "1123123".
[0112] The application scenario of applying the password string feature recognition scheme to sensitive string feature recognition is introduced below with reference to the accompanying drawings.
[0113] Figure 4 An exemplary flowchart of the sensitive string feature recognition method according to some embodiments of the present disclosure is shown. It can be understood that the sensitive string feature recognition method is a specific implementation in the foregoing step 103. Therefore, the features described above in conjunction with Figure 1 can be similarly applied herein.
[0114] As Figure 4 shown, in step 401, a precise matching search is performed in the sensitive object set based on the hash value of the ciphertext array.
[0115] In step 402, it is determined whether there is a precise matching object for the ciphertext array.
[0116] If so, step 403 is executed.
[0117] In step 403, the feature recognition result of the plaintext password is output as the password containing the sensitive string, and the maximum inclusion length of the plaintext password is output as the initial inclusion length.
[0118] Herein, the initial inclusion length is the total number of characters of the input characters.
[0119] In this embodiment, the calculation process of the hash value of the ciphertext array and the process of accurate matching retrieval can refer to the description content of step 301 in the foregoing embodiment, which will not be elaborated here.
[0120] In this embodiment, the sensitive object set is a set of hash values obtained by performing non-linear operations and hash operations on sensitive strings in advance. Before executing step 401, the system pre-generates a sensitive object set, which contains the hash values corresponding to the non-linear mapping values of all possible sensitive strings. Since this hash value is calculated after concatenating the ciphertext arrays, due to the one-way nature of the hash function, even if the sensitive object set is exposed, an attacker cannot reverse the ciphertext array based on the hash value, let alone obtain the characteristics of the plaintext password corresponding to the hash value in the sensitive object set.
[0121] Furthermore, the feature recognition result may also include: the password does not contain sensitive strings.
[0122] It should be noted that in practical applications, sensitive strings can be divided into general sensitive strings and specific sensitive strings. Among them, specific sensitive strings are related to the information of the user who enters the password, such as: the user's birthday information, ID number, and so on.
[0123] In step 402, if there is no exact matching object of the ciphertext array in the sensitive object set, steps 404 to 408 can be executed to determine the feature recognition result of the plaintext password and the maximum inclusion length of the plaintext password.
[0124] In step 404, subtract one from the initial inclusion length.
[0125] In step 405, extract q adjacent elements from the ciphertext array to form a second sub-ciphertext array.
[0126] Where q is the current initial inclusion length.
[0127] In practical applications, there may be a situation where the plaintext password partially contains sensitive strings. After it is recognized that the complete plaintext password does not contain sensitive strings, several consecutive elements can be extracted from the ciphertext array to form a second sub-ciphertext array, where the number of elements in the second sub-ciphertext array extracted in each round decreases round by round.
[0128] In this embodiment, the extraction process of extracting q adjacent elements from the ciphertext array to form a second sub-ciphertext array can refer to the content in step 305 of the foregoing embodiment, which will not be elaborated here.
[0129] In step 406, determine whether there is an exact matching object of the second sub-ciphertext array in the sensitive object set.
[0130] If so, execute step 407;
[0131] If not, return to execute step 404 until the sensitive retrieval stop condition is satisfied, and then execute step 407.
[0132] Among them, the sensitive retrieval stop conditions include the following two:
[0133] One is that there is an exact match object of the second sub-ciphertext array in the continuous object set. Meeting this condition indicates that the sensitive string has been identified in the ciphertext.
[0134] The other is that the current initial inclusion length is less than the minimum length of the sensitive string. Meeting this condition indicates that the second sub-ciphertext array obtained by the next extraction cannot form a sensitive string.
[0135] If any of the above continuous retrieval stop conditions is met, stop the retrieval and execute step 407.
[0136] In step 407, determine the current initial inclusion length.
[0137] In step 408, determine the feature recognition result and the maximum inclusion length of the ciphertext according to the current initial inclusion length.
[0138] Specifically:
[0139] If the current initial inclusion length is less than the minimum length of the sensitive string, the feature recognition result of the ciphertext is that the ciphertext does not contain the sensitive string, and the maximum inclusion length of the ciphertext is 0;
[0140] If the current initial inclusion length is greater than or equal to the minimum length of the sensitive string, the feature recognition result of the ciphertext is that the ciphertext contains the sensitive string, and the maximum inclusion length of the ciphertext is the current initial inclusion length.
[0141] Furthermore, according to the output result that the feature recognition result of the ciphertext is that the ciphertext contains the sensitive string, the system can prompt the user that the security of the ciphertext is weak to remind the user to change or modify the password.
[0142] In some other embodiments of the present disclosure, an alphabet object set and / or a number object set can also be formed. Among them, the alphabet object set is a set of hash values of non-linear operation results of all alphabetic characters, and the number object set is a set of hash values of non-linear operation results of all numeric characters.
[0143] Perform an exact match search for each input character in the alphabet object set and / or the number object set, so as to identify the character type of each input character, and then determine whether the ciphertext is composed of pure letters or pure numbers.
[0144] It should be noted that the foregoing methods for identifying repeated features, continuous features, sensitive string features, and character type features can be selected one or more and combined and applied in the password string feature recognition solution disclosed in this disclosure.
[0145] That is, the multiple features described in combination with Figures 2 to 4 above can be combined and applied to Figure 1 the password string feature recognition solution shown.
[0146] The password string feature recognition solution disclosed in this disclosure makes the data stored in the memory a ciphertext array in a non-plaintext state through non-linear operations. It is very difficult to deduce the original data through the data after using non-linear mapping, thereby improving the security of the data in the memory and effectively reducing the probability of password plaintext leakage.
[0147] Furthermore, the password string feature recognition process uses a hash function, and the entire recognition process only requires mapping values without linear relationships to participate, greatly reducing the risk of password plaintext leakage.
[0148] Moreover, the password string features that can be extracted in this disclosure are very rich. Based on the correspondence between the constituent elements of the ciphertext array and the input characters of the password plaintext, the features related to the password plaintext can all be obtained through the data of non-linear mapping.
[0149] The embodiments of this disclosure also provide a password string feature recognition device.
[0150] Figure 5 The exemplary structural block diagram of the password string feature recognition device of the embodiments of this disclosure is shown.
[0151] As Figure 5 shown, the password string feature recognition device of the embodiments of this disclosure includes the following modules:
[0152] A password input module 501, configured to obtain input characters and generate a ciphertext array based on the input characters. Among them, the set of the input characters constitutes the password plaintext; the elements in the ciphertext array are the hash values of the results of non-linear operations of the corresponding input characters; the non-linear operation uses a non-linear monotonic operator.
[0153] During the password input process, every time the user inputs a character, the password input module 501 calculates the result of its non-linear operation and saves the non-linear operation result in the array P. For example, if the input is "a", then P = [4.574710978503383]. Then, if the input is "b", then P = [4.574710978503383, 4.584967478670572]. Since the non-linear monotonic operator remains unchanged during one input process, the characteristics of the non-linear mapping value are the same as those of the original data. That is, the characteristics of the password plaintext can be identified by analyzing the characteristics of the ciphertext array.
[0154] Since the repeated feature recognition is an identification task performed on the ciphertext array itself, the initialization step can be skipped when performing the repeated feature recognition.
[0155] The feature extraction module 502 is used to perform feature recognition based on the ciphertext array generated by the password input module 501 to obtain the feature recognition result of the password plaintext. Among them, the feature recognition can include one or more of the following recognition tasks: identifying whether the password is repeated, identifying whether the password is continuous, and identifying whether the password contains sensitive strings. Further, the recognition task can also include: identifying the character types of the password.
[0156] Further, the password string feature recognition device further includes: an initialization module 503, which is used to perform non-linear operation and hash operation on the continuous password plaintext to obtain a continuous object set, and generate sensitive strings and perform non-linear operation and hash operation on the sensitive strings to obtain a sensitive object set.
[0157] In this embodiment, when the initialization module 503 executes the initialization step, a non-linear monotonic operator and a hash function are randomly selected. During the current password string feature recognition process, the selected non-linear monotonic operator and hash function will not be changed until the next password string feature recognition starts, and the initialization step can be selected to be executed again to replace the non-linear monotonic operator and the hash function.
[0158] It should be noted that in practical applications, the feature recognition performed on the same password plaintext belongs to the same password string feature recognition process, regardless of whether the password string feature recognition is for repeated features, continuous features, or sensitive string features.
[0159] Corresponding to the foregoing functional embodiments, an electronic device as shown in Figure 6 is also provided in the embodiments of the present invention. Figure 6 shows an exemplary structural block diagram of the electronic device according to the embodiment of the present invention.
[0160] Figure 6The electronic device 600 shown includes: a processor 610; and a memory 620, on which executable program instructions are stored. When the program instructions are executed by the processor 610, the electronic device implements any of the methods described above.
[0161] In Figure 6 the electronic device 600, only the constituent elements related to this embodiment are shown. Therefore, it is obvious to those of ordinary skill in the art that: the electronic device 600 may further include common constituent elements different from those shown in Figure 6 it.
[0162] The processor 610 can control the operation of the electronic device 600. For example, the processor 610 controls the operation of the electronic device 600 by executing the programs stored in the memory 620 of the electronic device 600. The processor 610 can be implemented by a central processing unit (CPU), an application processor (AP), an artificial intelligence processor chip (IPU), etc. provided in the electronic device 600. However, this disclosure is not limited thereto. In this embodiment, the processor 610 can be implemented in any suitable manner. For example, the processor 610 can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, etc.
[0163] The memory 620 can be hardware for storing various data and instructions processed in the electronic device 600. For example, the memory 620 can store the processed data and the data to be processed in the electronic device 600. The memory 620 can store data sets that have been processed or are to be processed by the processor 610. In addition, the memory 620 can store applications, drivers, etc. to be driven by the electronic device 600. The memory 620 can be DRAM, but the present disclosure is not limited thereto. The memory 620 can include at least one of volatile memory or non-volatile memory. The non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, phase change RAM (PRAM), magnetic RAM (MRAM), resistive RAM (RRAM), ferroelectric RAM (FRAM), etc. The volatile memory can include dynamic RAM (DRAM), static RAM (SRAM), synchronous DRAM (SDRAM), PRAM, MRAM, RRAM, ferroelectric RAM (FeRAM), etc. In an embodiment, the memory 620 can include at least one of a hard disk drive (HDD), a solid state drive (SSD), a high density flash (CF) card, a secure digital (SD) card, a micro secure digital (Micro-SD) card, a mini secure digital (Mini-SD) card, an extreme digital (xD) card, caches, or a memory stick.
[0164] In summary, the specific functions implemented by the memory 620 and the processor 610 of the electronic device 600 provided in the embodiments of this specification can be explained in contrast to the foregoing embodiments in this specification, and can achieve the technical effects of the foregoing embodiments, and will not be elaborated here.
[0165] Alternatively, the present disclosure can also be implemented as a non-transitory machine-readable storage medium (or computer-readable storage medium, or machine-readable storage medium) having computer program instructions (or computer programs, or computer instruction codes) stored thereon. When the computer program instructions (or computer programs, or computer instruction codes) are executed by a processor of an electronic device (or an electronic device, a server, etc.), the processor is caused to execute some or all of the steps of the above method according to the present disclosure.
[0166] Although several embodiments of the present disclosure have been shown and described herein, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Many variations, changes, and alternative ways will occur to those skilled in the art without departing from the spirit and scope of the present disclosure. It should be understood that various alternatives to the embodiments of the present disclosure described herein may be employed in practicing the present disclosure. The appended claims are intended to define the scope of the present disclosure and thus cover equivalents or alternatives within the scope of these claims.
Claims
1. A method for identifying characteristics of a password string, characterized in that, it includes: Obtain input characters; The set of the input characters constitutes the password plaintext; Generate a ciphertext array based on the input characters, wherein the elements in the ciphertext array are the results of non-linear operations corresponding to the input characters; the non-linear operation uses a non-linear monotonic operator; Perform feature identification based on the ciphertext array to obtain the feature identification result of the password plaintext, wherein the feature identification result includes: all characters of the password are repeated, some characters of the password are repeated, and the password is not repeated; The performing feature identification based on the ciphertext array to obtain the feature identification result of the password plaintext includes: Calculate the number of elements of each type in the ciphertext array; If the maximum value among the number of elements of each type is equal to the total number of input characters, the feature identification result of the password plaintext is that all characters of the password are repeated; If the maximum value among the number of elements of each type is within a preset repetition value range, the feature identification result of the password plaintext is that some characters of the password are repeated; If the maximum value among the number of elements of each type is 1, the feature identification result of the password plaintext is that the password is not repeated.
2. The method for identifying characteristics of a password string according to claim 1, characterized in that, The situation that some characters of the password are repeated includes: repeated character combinations; The performing feature identification based on the ciphertext array to obtain the feature identification result of the password plaintext further includes: If in the ciphertext array, each type of element is adjacent to at least one same-type element, the feature identification result of the password plaintext is a repeated character combination.
3. The method for identifying characteristics of a password string according to claim 1, characterized in that, The feature identification result includes: all characters of the password are consecutive; The performing feature identification based on the ciphertext array to obtain the feature identification result of the password plaintext includes: Perform precise matching retrieval in the continuous object set based on the hash value of the ciphertext array; the continuous object set is a hash value set obtained in advance by performing non-linear operations and hash operations on continuous password plaintexts; If there is a precise matching object of the ciphertext array in the continuous object set, the feature identification result of the password plaintext is that all characters of the password are consecutive, and the maximum consecutive number of the password plaintext is the initial consecutive number, and the initial consecutive number is the total number of input characters.
4. The method for identifying characteristics of a password string according to claim 3, characterized in that, The feature identification result further includes: some characters of the password are consecutive and the password is not consecutive; The performing feature identification based on the ciphertext array to obtain the feature identification result of the password plaintext further includes: If there is no precise matching object of the ciphertext array in the continuous object set, then perform the following process: Decrease the initial consecutive number by one; Extract p adjacent elements from the ciphertext array to form a first sub-ciphertext array; where p is the current initial consecutive number; Precisely match and retrieve based on the hash value of the first sub-ciphertext array in the continuous object set. If there is no precisely matching object of the first sub-ciphertext array in the continuous object set, return to execute the step of subtracting one from the initial continuous count until the current initial continuous count is determined after meeting the continuous retrieval stop condition; If the current initial continuous count is 1, the feature recognition result of the password plaintext is that the password is discontinuous. Otherwise, the feature recognition result of the password plaintext is that the password is partially continuous, and the maximum continuous count of the password plaintext is the current initial continuous count; The continuous retrieval stop condition includes: there is a precisely matching object of the first sub-ciphertext array in the continuous object set or the current initial continuous count is equal to 1.
5. The password string feature recognition method according to claim 4, characterized in that, further comprising: The password being partially continuous further includes: continuous character splicing; The step of obtaining the feature recognition result of the password plaintext based on the ciphertext array further includes: After meeting the retrieval stop condition, if the current initial continuous count is not 1, divide the ciphertext array into n sub-arrays based on the maximum continuous count N of the password plaintext; where n = L / N, and L is the total number of input characters; If the n sub-arrays are the same, the feature recognition result of the password plaintext is continuous character splicing.
6. The password string feature recognition method according to claim 1, characterized in that, The feature recognition result includes: the password contains a sensitive string; The step of obtaining the feature recognition result of the password plaintext based on the ciphertext array includes: Precisely match and retrieve based on the hash value of the ciphertext array in the sensitive object set; the sensitive object set is a hash value set obtained by performing non-linear operations and hash operations on sensitive strings in advance; If there is a precisely matching object of the ciphertext array in the sensitive object set, the feature recognition result of the password plaintext is that the password contains a sensitive string, and the maximum included length of the password plaintext is the initial included length, and the initial included length is the total number of input characters.
7. The password string feature recognition method according to claim 6, characterized in that, The feature recognition result further includes: the password does not contain a sensitive string; The step of obtaining the feature recognition result of the password plaintext based on the ciphertext array further includes: If there is no precisely matching object of the ciphertext array in the sensitive object set, perform the following process: Subtract one from the initial included length; Extract q adjacent elements from the ciphertext array to form a second sub-ciphertext array; where q is the current initial included length; Precisely match and retrieve based on the second sub-ciphertext array in the sensitive object set. If there is no precisely matching object of the second sub-ciphertext array in the sensitive object set, return to execute the step of subtracting one from the initial included length until the current initial included length is determined after meeting the sensitive retrieval stop condition; If the current initial inclusion length is less than the minimum length of the sensitive string, the feature recognition result of the cleartext password is that the password does not contain the sensitive string; otherwise, the feature recognition result of the cleartext password is that the password contains the sensitive string, and the maximum inclusion length of the cleartext password is the current initial inclusion length. The sensitive retrieval stop condition includes: there is an exact match object of the second sub-ciphertext array in the continuous object set or the current initial inclusion length is less than the minimum length of the sensitive string.
8. A password string feature recognition device Characterized in that It includes: A password input module, configured to obtain input characters and generate a ciphertext array based on the input characters; wherein, the set of the input characters constitutes the cleartext password; the elements in the ciphertext array are the results of non-linear operations on the corresponding input characters; the non-linear operation uses a non-linear monotonic operator. A feature extraction module, which performs feature recognition based on the ciphertext array to obtain the feature recognition result of the cleartext password, wherein the feature recognition result includes: all repeated passwords, partially repeated passwords, and non-repeated passwords; The feature extraction module is further configured to: Calculate the number of elements of each type in the ciphertext array; If the maximum value among the number of elements of each type is equal to the total number of input characters, the feature recognition result of the cleartext password is that all passwords are repeated; If the maximum value among the number of elements of each type is within a preset repetition value range, the feature recognition result of the cleartext password is that the password is partially repeated; If the maximum value among the number of elements of each type is 1, the feature recognition result of the cleartext password is that the password is not repeated.
9. The password string feature recognition device according to claim 8, Characterized in that It further includes: An initialization module, configured to perform non-linear operations and hash operations on continuous cleartext passwords to obtain a continuous object set, and generate a sensitive string and perform non-linear operations and hash operations on the sensitive string to obtain a sensitive object set.
Citation Information
Patent Citations
Ciphertext voice retrieval method and system based on deep perceptual hash
CN111897909A