A business system encryption method, device, electronic device and storage medium
Through symmetric cryptographic algorithm encryption and generating target passwords based on the current encryption method, the problem of single encryption method of business system is solved, and flexibility and security are improved.
Patent Information
- Application Number
- CN202410331949.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-22
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-03-22
AI Technical Summary
Existing business systems cannot implement the administrator's regular switching of encryption methods, resulting in insufficient flexibility and security, and are vulnerable to attackers' cracking of threats.
The user password is encrypted through a symmetric password algorithm, and then decrypted according to the current encryption method of the business system, generating the target password, and quickly matching the encryption method through the identification code mapping table, supporting regular switching of multiple encryption methods.
It improves the flexibility and security of the business system, prevents attackers from cracking, and enhances the system's protection capabilities.
Smart Images

Figure CN118133269B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a business system encryption method, apparatus, electronic device, and storage medium. Background Art
[0002] Currently, a business system usually only provides an encryption method for a user login password, such as a Message Digest Algorithm MD5 or a Password Hashing Function Standard SM3 algorithm, etc.
[0003] Therefore, the existing business system cannot implement which encryption method to use configured by an administrator, let alone support the administrator to periodically switch which encryption method to use, thus reducing the flexibility of the business system. At the same time, if an attacker successfully cracks the fixed encryption method used by the business system, the security of the entire system will be threatened. Summary of the Invention
[0004] The present invention provides a business system encryption method, apparatus, electronic device, and storage medium, which can improve the flexibility and security of the business system.
[0005] According to one aspect of the present invention, a business system encryption method is provided, and the method includes:
[0006] In response to the business system registration information input by a user, encrypt the user password in the registration information through a symmetric cipher algorithm to obtain a first symmetric cipher;
[0007] Decrypt the first symmetric cipher, and then encrypt the decryption result according to the current encryption method corresponding to the business system to obtain a user encrypted password;
[0008] Wherein, the business system supports multiple encryption methods, and the current encryption method used by the business system is obtained by the administrator's regular configuration;
[0009] Obtain an identification code matching the current encryption method, and generate a target password matching the user according to the identification code and the user encrypted password.
[0010] Optionally, after generating the target password matching the user, it further includes:
[0011] In response to the business system login information input by a user, encrypt the login password in the login information through a symmetric cipher algorithm to obtain a second symmetric cipher;
[0012] According to the login information, obtain the historical encryption method stored in the database and matching the user, and decrypt the second symmetric cipher into a plaintext;
[0013] Encrypt the plain code using the historical encryption method to obtain the database encryption password, and verify the user's identity information based on the target password matched by the user in the database and the database encryption password;
[0014] If the user's identity verification is successful, update the target password matched by the user according to the current encryption method corresponding to the business system.
[0015] Optionally, verifying the user's identity information based on the target password matched by the user in the database and the database encryption password includes:
[0016] Determine whether the target password matched by the user in the database is the same as the database encryption password;
[0017] If so, determine that the user's identity verification is successful;
[0018] If not, determine that the user's login fails.
[0019] Optionally, updating the target password matched by the user according to the current encryption method corresponding to the business system includes:
[0020] Decrypt the second symmetric password to obtain the plain code, encrypt the plain code according to the current encryption method corresponding to the business system to obtain the system encryption password;
[0021] Determine whether the database encryption password is the same as the system encryption password;
[0022] If so, determine that the user's login is successful;
[0023] If not, obtain the identification code matching the current encryption method, and generate an updated target password matched by the user according to the identification code and the system encryption password.
[0024] Optionally, after generating the updated target password matched by the user, it further includes: if it is determined that the update of the target password matched by the user is successful, determine that the user's login is successful.
[0025] Optionally, before obtaining the identification code matching the current encryption method, it further includes:
[0026] Pre-determine the identification codes matching each encryption method, and construct an identification code mapping table according to the mapping relationship between each encryption method and the identification code;
[0027] Obtaining the identification code matching the current encryption method includes:
[0028] Obtain the identification code mapping table, query the identification code mapping table according to the current encryption method, and obtain the identification code matching the current encryption method.
[0029] Optionally, according to the login information, obtain the historical encryption method stored in the database and matching the user, including:
[0030] According to the user name in the login information, obtain the target password matching the user in the database, and obtain the identification code in the target password;
[0031] According to the identification code and the identification code mapping table, determine the historical encryption method matching the user.
[0032] According to another aspect of the present invention, there is provided a business system encryption device, the device includes:
[0033] A registration response module, configured to encrypt the user password in the registration information through a symmetric encryption algorithm in response to the business system registration information input by the user, and obtain a first symmetric password;
[0034] A user password processing module, configured to decrypt the first symmetric password, and then encrypt the decryption result according to the current encryption method corresponding to the business system, and obtain a user encrypted password;
[0035] Wherein, the business system supports multiple encryption methods, and the current encryption method used by the business system is periodically configured by an administrator;
[0036] A target password generation module, configured to obtain the identification code matching the current encryption method, and generate a target password matching the user according to the identification code and the user encrypted password.
[0037] According to another aspect of the present invention, there is provided an electronic device, the electronic device includes:
[0038] At least one processor; and
[0039] A memory communicatively connected to the at least one processor; wherein,
[0040] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the business system encryption method according to any embodiment of the present invention.
[0041] According to another aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the business system encryption method according to any embodiment of the present invention when executed by a processor.
[0042] The technical solution provided by the embodiment of the present invention encrypts the user password in the registration information through a symmetric encryption algorithm in response to the business system registration information input by the user to obtain a first symmetric cipher, decrypts the first symmetric cipher, and then encrypts the decryption result according to the current encryption method corresponding to the business system to obtain a user encrypted password, obtains an identification code matching the current encryption method, and generates a target password matching the user according to the identification code and the user encrypted password, which can improve the flexibility and security of the business system.
[0043] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0045] Figure 1 is a flowchart of a business system encryption method provided by an embodiment of the present invention;
[0046] Figure 2a is a flowchart of another business system encryption method provided by an embodiment of the present invention;
[0047] Figure 2b is a flowchart of a method for a business system to respond to a user login request provided by an embodiment of the present invention;
[0048] Figure 3 is a structural schematic diagram of a business system encryption device provided by an embodiment of the present invention;
[0049] Figure 4 is a structural schematic diagram of an electronic device for implementing the business system encryption method of the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0051] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0052] Figure 1 The following is a flowchart of a business system encryption method provided by an embodiment of the present invention. This embodiment is applicable to the situation where the business system encrypts the password input by the user. This method can be executed by a business system encryption device, which can be implemented in the form of hardware and / or software, and the business system encryption device can be configured in an electronic device. As Figure 1 shown, the method includes:
[0053] Step 110, in response to the business system registration information input by the user, encrypt the user password in the registration information through a symmetric cryptography algorithm to obtain a first symmetric ciphertext.
[0054] In this step, specifically, when the user registers for the business system, the user can open the corresponding registration page of the system and enter information such as the username and password in the registration page. After the front-end of the business system detects the user input registration information, it can encrypt the user password in the registration information through a symmetric encryption algorithm (such as the SM4 algorithm) to obtain a first symmetric ciphertext symmetric_password1, and then transmit the first symmetric ciphertext and registration information such as the username to the system backend together.
[0055] In this embodiment, the service system supports multiple encryption methods, and the current encryption method used by the service system is periodically configured by the administrator. Specifically, the service system can support multiple encryption methods such as MD5, SM3, the cryptographically secure hash function SHA256, and the Password-Based Key Derivation Function 2 (PBKDF2). The administrator can periodically switch the encryption method used by the service system and save the selected current encryption method to the database.
[0056] The advantage of this setting is that since the service system can support multiple encryption methods and the administrator periodically switches the encryption method of the system, on the one hand, it can meet the needs of users for different encryption methods and improve the flexibility of the service system; on the other hand, it can prevent attackers from cracking the fixed encryption method, greatly improving the security of the service system.
[0057] Step 120: Decrypt the first symmetric cipher, and then encrypt the decryption result according to the current encryption method corresponding to the service system to obtain the user-encrypted password.
[0058] In this embodiment, specifically, after the system backend obtains the first symmetric cipher, it can decrypt the first symmetric cipher to obtain the plaintext, and then use the current encryption method login_encrypt_type (such as the SM3 algorithm) corresponding to the service system to encrypt the plaintext to obtain the user-encrypted password encrypt_password1.
[0059] In this step, specifically, after the system backend obtains the user-encrypted password, it can pass the user's registration information, the current encryption method, and the user-encrypted password into the identity authentication end corresponding to the service system.
[0060] Step 130: Obtain the identification code matching the current encryption method, and generate a target password matching the user according to the identification code and the user-encrypted password.
[0061] In this embodiment, before responding to the service system registration information input by the user, the identity authentication end can pre-construct the identification codes respectively matching each encryption method, and different encryption methods correspond to different identification codes.
[0062] In this step, the identity authentication end can obtain the identification code matching the current encryption method, then connect the identification code and the user-encrypted password with an underscore to synthesize a final password (i.e., the target password), then bind the target password to the user, and store the target password and information such as the user name in the database.
[0063] In a specific embodiment, after generating a target password that matches the user, the service system may feedback a registration success message to the user.
[0064] The technical solution provided by the embodiments of the present invention encrypts the user password in the registration information through a symmetric encryption algorithm to obtain a first symmetric ciphertext, decrypts the first symmetric ciphertext, and then encrypts the decryption result according to the current encryption method corresponding to the service system to obtain a user encrypted password, obtains an identification code that matches the current encryption method, and generates a target password that matches the user according to the identification code and the user encrypted password, which can improve the flexibility and security of the service system.
[0065] Figure 2a It is a flowchart of another service system encryption method provided by the embodiments of the present invention, as Figure 2a shown, and this method includes:
[0066] Step 210: In response to the service system registration information input by the user, encrypt the user password in the registration information through a symmetric encryption algorithm to obtain a first symmetric ciphertext.
[0067] Step 220: Decrypt the first symmetric ciphertext, and then encrypt the decryption result according to the current encryption method corresponding to the service system to obtain a user encrypted password.
[0068] Step 230: Obtain an identification code that matches the current encryption method, and generate a target password that matches the user according to the identification code and the user encrypted password.
[0069] In an implementation manner of this embodiment, before obtaining the identification code that matches the current encryption method, it further includes: pre-determining the identification code that matches each encryption method, and constructing an identification code mapping table according to the mapping relationship between each encryption method and the identification code.
[0070] In a specific embodiment, Table 1 may be an identification code mapping table in this embodiment. As shown in Table 1, the identification code may be identified by 13 uppercase letters.
[0071] Table 1
[0072] Encryption method Identification code SM3 KUSDSAGBKEDGE MD5 LHDFGHJKJNBVD SHA256 MNBFDWERTYUJN PBKDF2 POIUYTREDXCVB
[0073] In this step, obtaining the identification code that matches the current encryption method includes: obtaining the identification code mapping table, and querying the identification code mapping table according to the current encryption method to obtain the identification code that matches the current encryption method.
[0074] The advantage of this setting is that by constructing an identification code mapping table, the identification code matching the system encryption method can be quickly obtained, thereby improving the encryption efficiency of the system.
[0075] Step 240: In response to the business system login information input by the user, encrypt the login password in the login information through a symmetric encryption algorithm to obtain a second symmetric password.
[0076] In this step, specifically, the user can open the login page corresponding to the business system and enter the login information (such as the username and login password, etc.) in the login page. The front end of the system can encrypt the login password through a symmetric encryption algorithm (such as the SM4 algorithm) to obtain the second symmetric password symmetric_password2, and then pass the second symmetric password and the username to the system back end together.
[0077] Step 250: According to the login information, obtain the historical encryption method stored in the database that matches the user, and decrypt the second symmetric password to obtain the plaintext.
[0078] In this step, after the system back end obtains the second symmetric password, it can decrypt the second symmetric password to obtain the plaintext. The corresponding identity authentication end of the system can obtain the historical encryption method db-login_encrypt_type (such as the SM3 algorithm) stored in the database that matches the user according to the username in the login information.
[0079] In an implementation manner of this embodiment, obtaining the historical encryption method stored in the database that matches the user according to the login information includes: according to the username in the login information, obtaining the target password that matches the user in the database, and obtaining the identification code in the target password; according to the identification code and the identification code mapping table, determining the historical encryption method that matches the user.
[0080] Step 260: Encrypt the plaintext using the historical encryption method to obtain a database encryption password, and verify the user's identity information according to the target password that matches the user in the database and the database encryption password.
[0081] In this step, the system back end can encrypt the above plaintext using the historical encryption method to obtain the database encryption password password1. The identity authentication end can verify the user's identity information according to the database encryption password password1 and the target password password2 that matches the user in the database.
[0082] In an implementation manner of this embodiment, verifying the identity information of the user according to the target password matched by the user in the database and the encrypted password of the database includes: determining whether the target password matched by the user in the database is the same as the encrypted password of the database; if so, determining that the identity verification of the user is successful; if not, determining that the user login fails.
[0083] Step 270, if the identity verification of the user is successful, update the target password matched by the user according to the current encryption method corresponding to the service system.
[0084] In an implementation manner of this embodiment, updating the target password matched by the user according to the current encryption method corresponding to the service system includes: decrypting the second symmetric password into plaintext, encrypting the plaintext according to the current encryption method corresponding to the service system to obtain a system encrypted password; determining whether the encrypted password of the database is the same as the system encrypted password; if so, determining that the user login is successful; if not, obtaining an identification code matched by the current encryption method, and generating an updated target password matched by the user according to the identification code and the system encrypted password.
[0085] In a specific embodiment, if the identity verification of the user is successful, the system backend can obtain the current encryption method login_encrypt_type of the service system (such as the SM3 algorithm), decrypt the second symmetric password into plaintext, and then encrypt the plaintext using the current encryption method to obtain a system encrypted password encrypt_password2.
[0086] The system backend can transmit the username, the current encryption method, the system encrypted password, and the above-mentioned encrypted password of the database to the identity authentication end. The identity authentication end can compare the encrypted password of the database with the system encrypted password. If they are the same, it means that the encryption method of the service system has not changed, and it is determined that the user login is successful; if they are different, the identity authentication end can query the identification code mapping table according to the current encryption method to obtain the matched identification code, and then connect the identification code and the system encrypted password with an underscore to synthesize a final password, obtaining an updated target password matched by the user.
[0087] In a specific embodiment, after generating the updated target password matched by the user, it further includes: if it is determined that the update of the target password matched by the user is successful, determining that the user login is successful.
[0088] Figure 2b This is a flowchart of a response method of a service system for a user login request in this embodiment. To better introduce the technical solution provided by the embodiment of the present invention, as Figure 2bAs shown, the embodiments of the present invention can refer to the following implementation manners:
[0089] Step 1: In response to the business system login information input by the user, encrypt the login password in the login information through a symmetric encryption algorithm to obtain a second symmetric cipher.
[0090] Step 2: According to the login information, obtain the historical encryption method stored in the database that matches the user, and decrypt the second symmetric cipher to obtain the plaintext.
[0091] Step 3: Encrypt the plaintext using the historical encryption method to obtain a database encryption password, and determine whether the target password that matches the user in the database is the same as the database encryption password. If so, execute Step 4; if not, execute Step 8.
[0092] Step 4: Decrypt the second symmetric cipher to obtain the plaintext, and encrypt the plaintext according to the current encryption method corresponding to the business system to obtain a system encryption password.
[0093] Step 5: Determine whether the database encryption password is the same as the system encryption password. If so, execute Step 7; if not, execute Step 6.
[0094] Step 6: Obtain the identification code that matches the current encryption method, and generate an updated target password that matches the user according to the identification code and the system encryption password.
[0095] Step 7: Determine that the user has logged in successfully.
[0096] Step 8: Determine that the user has logged in failed.
[0097] The technical solution provided by the embodiments of the present invention can improve the flexibility and security of the business system by, in response to the business system registration information input by the user, encrypting the user password in the registration information through a symmetric encryption algorithm to obtain a first symmetric cipher, decrypting the first symmetric cipher, encrypting the decryption result according to the current encryption method to obtain a user encryption password, obtaining the identification code that matches the current encryption method, generating a target password according to the identification code and the user encryption password, in response to the business system login information input by the user, encrypting the login password through a symmetric encryption algorithm to obtain a second symmetric cipher, obtaining the historical encryption method stored in the database that matches the user, decrypting the second symmetric cipher to obtain the plaintext, encrypting the plaintext using the historical encryption method to obtain a database encryption password, and verifying the user's identity information according to the target password that matches the user in the database and the database encryption password. If the user's identity verification is successful, the target password that matches the user is updated according to the current encryption method corresponding to the business system.
[0098] Figure 3 The structural schematic diagram of a service system encryption device provided by an embodiment of the present invention, the device is applied to an electronic device, such as Figure 3 As shown, the device includes: a registration response module 310, a user password processing module 320, and a target password generation module 330.
[0099] The registration response module 310 is configured to encrypt the user password in the registration information by using a symmetric encryption algorithm in response to the service system registration information input by the user, so as to obtain a first symmetric password;
[0100] The user password processing module 320 is configured to decrypt the first symmetric password, and then encrypt the decryption result according to the current encryption method corresponding to the service system, so as to obtain a user encrypted password;
[0101] Wherein, the service system supports multiple encryption methods, and the current encryption method used by the service system is regularly configured by an administrator;
[0102] The target password generation module 330 is configured to obtain an identification code matching the current encryption method, and generate a target password matching the user according to the identification code and the user encrypted password.
[0103] The technical solution provided by the embodiment of the present invention can improve the flexibility and security of the service system by encrypting the user password in the registration information by using a symmetric encryption algorithm in response to the service system registration information input by the user to obtain a first symmetric password, decrypting the first symmetric password, and then encrypting the decryption result according to the current encryption method corresponding to the service system to obtain a user encrypted password, obtaining an identification code matching the current encryption method, and generating a target password matching the user according to the identification code and the user encrypted password.
[0104] Based on the above embodiment, the device further includes:
[0105] A login response module, configured to encrypt the login password in the login information by using a symmetric encryption algorithm in response to the service system login information input by the user, so as to obtain a second symmetric password;
[0106] An encryption method acquisition module, configured to obtain a historical encryption method stored in the database and matching the user according to the login information, and decrypt the second symmetric password to obtain a clear code;
[0107] An identity authentication module, configured to encrypt the clear code by using the historical encryption method to obtain a database encrypted password, and authenticate the user's identity information according to the target password matching the user in the database and the database encrypted password;
[0108] A password update module, configured to update the target password matched by the user according to the current encryption method corresponding to the business system if the authentication of the user is successful;
[0109] A mapping table construction module, configured to pre-determine the identification codes matched by each encryption method, and construct an identification code mapping table according to the mapping relationship between each encryption method and the identification code.
[0110] The target password generation module 330 includes:
[0111] A mapping table query unit, configured to obtain the identification code mapping table, query the identification code mapping table according to the current encryption method, and obtain the identification code matched by the current encryption method.
[0112] The authentication module includes:
[0113] A password judgment unit, configured to judge whether the target password matched by the user in the database is the same as the database encrypted password; if so, determine that the authentication of the user is successful; if not, determine that the user login fails.
[0114] The password update module includes:
[0115] An encryption unit, configured to decrypt the second symmetric password into a plain code, encrypt the plain code according to the current encryption method corresponding to the business system, and obtain a system encrypted password;
[0116] A password comparison unit, configured to judge whether the database encrypted password is the same as the system encrypted password; if so, determine that the user login is successful; if not, obtain the identification code matched by the current encryption method, and generate an updated target password matched by the user according to the identification code and the system encrypted password;
[0117] An update detection unit, configured to determine that the user login is successful if it is determined that the update of the target password matched by the user is successful.
[0118] The encryption method acquisition module includes:
[0119] A target password acquisition unit, configured to obtain the target password matched by the user in the database according to the user name in the login information, and obtain the identification code in the target password;
[0120] A historical encryption method determination unit, configured to determine the historical encryption method matched by the user according to the identification code and the identification code mapping table.
[0121] The above device can execute the methods provided in all the foregoing embodiments of the present invention, and has corresponding functional modules and beneficial effects for executing the above methods. For technical details not described in detail in the embodiments of the present invention, reference may be made to the methods provided in all the foregoing embodiments of the present invention.
[0122] Figure 4 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0123] As Figure 4 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0124] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0125] The processor 11 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the business system encryption method.
[0126] In some embodiments, the business system encryption method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the business system encryption method described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute the business system encryption method by any other suitable means (e.g., by means of firmware).
[0127] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0128] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0129] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0130] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0131] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0132] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0133] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0134] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A business system encryption method, characterized in that, The method includes: In response to the business system registration information input by the user, encrypt the user password in the registration information through a symmetric encryption algorithm to obtain a first symmetric cipher; Decrypt the first symmetric cipher, and then encrypt the decryption result according to the current encryption method corresponding to the business system to obtain a user encrypted password; Wherein, the business system supports multiple encryption methods, and the current encryption method used by the business system is periodically configured by the administrator; Obtain an identification code matching the current encryption method, and generate a target password matching the user according to the identification code and the user encrypted password; After generating the target password matching the user, it further includes: In response to the business system login information input by the user, encrypt the login password in the login information through a symmetric encryption algorithm to obtain a second symmetric cipher; According to the login information, obtain the historical encryption method stored in the database that matches the user, and decrypt the second symmetric cipher to obtain the plaintext; Encrypt the plaintext using the historical encryption method to obtain a database encrypted password, and verify the user's identity information according to the target password matching the user in the database and the database encrypted password; If the user's identity verification is successful, update the target password matching the user according to the current encryption method corresponding to the business system; The updating the target password matching the user according to the current encryption method corresponding to the business system includes: Decrypt the second symmetric cipher to obtain the plaintext, and encrypt the plaintext according to the current encryption method corresponding to the business system to obtain a system encrypted password; Determine whether the database encrypted password is the same as the system encrypted password; If so, determine that the user has logged in successfully; If not, obtain an identification code matching the current encryption method, and generate an updated target password matching the user according to the identification code and the system encrypted password; Before obtaining the identification code matching the current encryption method, it further includes: Pre-determine the identification code matching each encryption method, and construct an identification code mapping table according to the mapping relationship between each encryption method and the identification code; Obtaining the identification code matching the current encryption method includes: Obtain the identification code mapping table, query the identification code mapping table according to the current encryption method, and obtain the identification code matching the current encryption method; Wherein, the identification code is a capital letter identifier.
2. The method according to claim 1, wherein Verifying the user's identity information according to the target password matching the user in the database and the database encrypted password includes: Determine whether the target password matching the user in the database is the same as the database encrypted password; If so, determine that the user's identity verification is successful; If not, determine that the user's login fails.
3. The method according to claim 1, wherein After generating the updated target password matching the user, it further includes: If it is determined that the update of the target password matching the user is successful, determine that the user has logged in successfully.
4. The method according to claim 1, wherein Obtaining the historical encryption method stored in the database that matches the user according to the login information includes: Obtain the target password matching the user in the database according to the username in the login information, and obtain the identification code in the target password; Determine the historical encryption method matching the user according to the identification code and the identification code mapping table.
5. A business system encryption device, characterized in that, The device includes: A registration response module, configured to encrypt the user password in the registration information by using a symmetric cryptography algorithm in response to the business system registration information input by the user, to obtain a first symmetric password; A user password processing module, configured to decrypt the first symmetric password, and then encrypt the decryption result according to the current encryption method corresponding to the business system, to obtain a user encrypted password; Wherein, the business system supports multiple encryption methods, and the current encryption method used by the business system is regularly configured by an administrator; A target password generation module, configured to obtain the identification code matching the current encryption method, and generate a target password matching the user according to the identification code and the user encrypted password; A login response module, configured to encrypt the login password in the login information by using a symmetric cryptography algorithm in response to the business system login information input by the user, to obtain a second symmetric password; An encryption method acquisition module, configured to obtain the historical encryption method matching the user stored in the database according to the login information, and decrypt the second symmetric password to obtain the plaintext; An identity authentication module, configured to encrypt the plaintext by using the historical encryption method to obtain a database encrypted password, and authenticate the identity information of the user according to the target password matching the user in the database and the database encrypted password; A password update module, configured to, if the identity authentication of the user is successful, update the target password matching the user according to the current encryption method corresponding to the business system; The password update module further includes: An encryption unit, configured to decrypt the second symmetric password to obtain the plaintext, and encrypt the plaintext according to the current encryption method corresponding to the business system, to obtain a system encrypted password; A password comparison unit, configured to determine whether the database encrypted password is the same as the system encrypted password; if so, determine that the user logs in successfully; if not, obtain the identification code matching the current encryption method, and generate an updated target password matching the user according to the identification code and the system encrypted password; A mapping table construction module, configured to pre-determine the identification code matching each encryption method, and construct an identification code mapping table according to the mapping relationship between each encryption method and the identification code; The target password generation module further includes: a mapping table query unit; The mapping table query unit is configured to obtain the identification code mapping table, and query the identification code mapping table according to the current encryption method, to obtain the identification code matching the current encryption method; Wherein, the identification code is a capital letter identifier.
6. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, enables the at least one processor to execute the business system encryption method according to any one of claims 1-4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for implementing the business system encryption method according to any one of claims 1-4 when the computer instructions are executed by a processor.
Citation Information
Patent Citations
Account migration method and device, terminal equipment and storage medium
CN108471403A
User password management method, computer device and storage medium
CN117034309A