Secret key password processing method, device, equipment and medium
By dynamically splitting and sharing secret key passwords, combined with a double-threshold mechanism and separate management, the security and permission management issues of the static password system are solved, and password access with high security and flexible permission control is achieved.
Patent Information
- Application Number
- CN202410702217.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-01
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2044-06-01
AI Technical Summary
The existing static password system relies on an additional management system to ensure security, lacks external defenses, and is prone to password leakage and malicious sharing. It also lacks fine-grained access control and permission management. The existing secret password splitting method lacks permission expansion and dynamic granting and receiving mechanisms, and security is limited by the number of participants and resource devices.
By dynamically splitting and sharing secret key passwords, using the participants' private keys to generate password shares for user and resource identification, introducing a double threshold mechanism to achieve identity authentication and permission control, adopting separate management of resource device end, resource management center, password distribution center, and user end, using PKI for identity authentication and message encryption, and constructing a method for splitting, distributing, reconstructing and recovering secret passwords.
It improves the security of the static password system and the visitor identity authentication capability, enhances the permission control capability, improves the security of resource access in low-number scenarios through a double-threshold mechanism, prevents illegal copying and leakage of password shares, and realizes flexible permission management.
Smart Images

Figure CN118611926B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network security, and particularly relates to a secret key password processing method and device, equipment and medium. BACKGROUND
[0002] Nowadays, static password systems are common in applications such as data, media, file encryption and decryption, and device and terminal access verification. The main defect of such a system is to rely on an additional management system to ensure the security of the password. In such a system, the resource is only statically matched and verified with the provided password content, which may lead to the fall of the resource due to the lack of external defense. In addition, the password is directly held by the visitor, which may easily lead to malicious sharing and leakage of the password. At the same time, the traditional static password system lacks fine-grained access control and cannot achieve precise permission management.
[0003] In related technologies, a method of splitting and storing secret passwords is proposed, which improves the security of passwords and resources through this way. However, these methods are relatively single in password splitting and recovery, and do not provide effective visitor identity verification and permission control methods. Although the existing technology proposes that participants construct password shares to realize identity traceability, the splitting method still uses one-time generation, lacks permission expansion and dynamic collection and grant mechanism. In addition, the secret recovery threshold of the scheme is limited by the number of participants and resource devices, which may lead to reduced security in some scenarios. SUMMARY
[0004] In order to solve the above technical problems, the present disclosure provides a secret key password processing method, device, equipment and medium, which effectively solves the technical problems proposed in the above content.
[0005] In a first aspect, the embodiments of the present disclosure provide a secret key password processing method, which comprises:
[0006] obtaining a resource identifier of a resource to be accessed and a first password share corresponding to each authorized user;
[0007] using the resource identifier, the pre-stored first password share, and the first password share corresponding to each authorized user, to parse an initial password;
[0008] accessing a resource corresponding to the resource identifier according to the initial password.
[0009] In a possible implementation manner, the method provided by the embodiments of the present disclosure comprises:
[0010] In response to at least a preset number of authorized user-initiated resource access requests, obtaining a resource identifier of a resource corresponding to the resource access request, and a user share corresponding to each of the at least a preset number of authorized users and a user second password share;
[0011] Based on the user share and the user second password share corresponding to each of the authorized users, a user first password share corresponding to each of the authorized users is obtained.
[0012] In a possible implementation, the method provided by the embodiment of the present application comprises the following steps:
[0013] Based on the user share and the user second password share corresponding to each of the authorized users, a user first password share corresponding to each of the authorized users is obtained.
[0014] In a possible implementation, the first password share is generated by the following method:
[0015] In response to a password registration initiated for a resource to be managed, an initial password and a resource identifier corresponding to the resource to be managed are generated;
[0016] Based on the initial password, a second password share is generated;
[0017] According to the second password share and the resource identifier, a first password share is generated and stored in a three-element information table.
[0018] In a possible implementation, the method provided by the embodiment of the present application comprises the following steps:
[0019] A user share is generated by using a user identifier of the user, the resource identifier, and signature information of the user;
[0020] Based on the user share and a random number, a user second password share is generated;
[0021] According to the user second password share and the resource identifier, a user first password share is generated.
[0022] In a possible implementation, the method provided by the embodiment of the present application comprises the following steps:
[0023] According to the user second password share, a resource identifier and a user identifier of the user are obtained;
[0024] An initial password is obtained through the resource identifier, and a user first password share is constructed according to the initial password and the user identifier.
[0025] In a possible implementation, the method provided by the embodiment of the present application adds an authorized user by the following method:
[0026] In response to the password authorization application of the target user, a user share of the target user is generated;
[0027] The user share of the target user is sent to all authorized users;
[0028] After the approval of all authorized users, a user first password share corresponding to the target user is generated based on the user share of the target user and a random number;
[0029] According to the user first password share corresponding to the target user and the resource identifier, a user second password share corresponding to the target user is generated.
[0030] In a second aspect, the embodiment of the present application provides a secret key password processing device, and the device comprises:
[0031] The acquisition unit is configured to acquire a resource identifier of a resource to be accessed and a user first password share corresponding to each authorized user;
[0032] The analysis unit is configured to analyze an initial password by using the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user;
[0033] The processing unit is configured to access a resource corresponding to the resource identifier according to the initial password.
[0034] In a possible implementation, the acquisition unit in the device provided by the embodiment of the present application is specifically configured to:
[0035] In response to a resource access request initiated by at least a preset number of authorized users, the acquisition unit is configured to acquire a resource identifier of a resource corresponding to the resource access request, and a user share and a user second password share corresponding to each authorized user in the at least preset number of authorized users;
[0036] The acquisition unit is configured to obtain a user first password share corresponding to each authorized user based on the user share and the user second password share corresponding to each authorized user.
[0037] In a possible implementation, the acquisition unit in the device provided by the embodiment of the present application is specifically configured to:
[0038] The acquisition unit is configured to obtain a user first password share corresponding to each initial authorized user in a pre-stored three-element information table based on the user share and the user second password share corresponding to each authorized user.
[0039] In a possible implementation, the processing unit generates the first password share in the apparatus provided by the embodiment of the present application by the following method:
[0040] In response to a password registration initiated by the to-be-managed resource, an initial password and a resource identifier corresponding to the to-be-managed resource are generated;
[0041] A second password share is generated based on the initial password;
[0042] The first password share is generated according to the second password share and the resource identifier, and is stored in the ternary information table.
[0043] In a possible implementation, the processing unit generates the first password share corresponding to each authorized user in the apparatus provided by the embodiment of the present application by the following method:
[0044] A user share is generated by using a user identifier of the user, the resource identifier, and signature information of the user;
[0045] A second password share of the user is generated based on the user share and a random number;
[0046] The first password share of the user is generated according to the second password share of the user and the resource identifier.
[0047] In a possible implementation, the processing unit is specifically further configured to:
[0048] The resource identifier and the user identifier of the user are obtained according to the second password share of the user;
[0049] The initial password is obtained through the resource identifier, and the first password share of the user is constructed according to the initial password and the user identifier.
[0050] In a possible implementation, the processing unit adds an authorized user in the apparatus provided by the embodiment of the present application by the following method:
[0051] In response to a password authorization application of a target user, a user share of the target user is generated;
[0052] The user share of the target user is sent to all authorized users;
[0053] After the user share of the target user is audited and passed by all authorized users, a first password share of the target user is generated based on the user share of the target user and a random number;
[0054] A second password share of the target user is generated according to the first password share of the target user and the resource identifier.
[0055] In a third aspect, an electronic device is provided, including:
[0056] a memory;
[0057] a processor; and
[0058] a computer program;
[0059] The computer program is stored in the memory and is configured to be executed by the processor to implement the secret key password processing method as described above.
[0060] In a fourth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of the secret key password processing method as described above.
[0061] The embodiments of the present disclosure provide a secret key password processing method, comprising:
[0062] First, the resource identifier of the resource to be accessed and the user first password share corresponding to each authorized user are obtained, and then the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user are used to parse out an initial password. Finally, the resource corresponding to the resource identifier is accessed according to the initial password. The secret key password processing method provided by the present disclosure uses the user first password share of the authorized user and the pre-stored first password share to jointly parse out the initial password for obtaining the resource. By setting a double threshold, a higher password recovery share number threshold value is applied in a scenario where the number of people required for joint access is small, and the security of resource access is improved. BRIEF DESCRIPTION OF DRAWINGS
[0063] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the present disclosure.
[0064] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without creative labor.
[0065] Figure 1 A flowchart of a secret key password processing method provided by the embodiments of the present disclosure;
[0066] Figure 2 A flowchart of an initial password generation method provided by the embodiments of the present disclosure;
[0067] Figure 3 An interaction flowchart of an initial password generation method provided by the embodiments of the present disclosure;
[0068] Figure 4A principle schematic diagram of a first password share and a user first password share generation method provided by an embodiment of the present disclosure is shown in FIG. 1.
[0069] Figure 5 A flow schematic diagram of a first password share generation method provided by an embodiment of the present disclosure is shown in FIG. 2.
[0070] Figure 6 A flow schematic diagram of a user second password share generation method provided by an embodiment of the present disclosure is shown in FIG. 3.
[0071] Figure 7 A principle schematic diagram of a secret key password processing method provided by an embodiment of the present disclosure is shown in FIG. 4.
[0072] Figure 8 A flow schematic diagram of a secret key password processing method provided by an embodiment of the present disclosure is shown in FIG. 5.
[0073] Figure 9 A principle schematic diagram of an authorized user adding method provided by an embodiment of the present disclosure is shown in FIG. 6.
[0074] Figure 10 A flow schematic diagram of an authorized user adding method provided by an embodiment of the present disclosure is shown in FIG. 7.
[0075] Figure 11 A structure schematic diagram of a secret key password processing device provided by an embodiment of the present disclosure is shown in FIG. 8.
[0076] Figure 12 A structure schematic diagram of an electronic device provided by an embodiment of the present disclosure is shown in FIG. 9. DETAILED DESCRIPTION
[0077] In order to more clearly understand the above-mentioned purposes, features and advantages of the present disclosure, the schemes of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.
[0078] In the following description, many specific details are set forth in order to provide a thorough understanding of the present disclosure, but the present disclosure can also be implemented in other ways different from those described herein; obviously, the embodiments in the description are only some embodiments of the present disclosure, not all embodiments.
[0079] Nowadays, static password systems are common in applications such as data, media, file encryption and decryption, and device and terminal access verification. The main defect of such a system is to rely on an additional management system to ensure the security of the password. In such a system, resources are only statically matched and verified for the provided password content, which may lead to the fall of resources due to the lack of external defense. In addition, the password is directly held by the visitor, which is easy to cause malicious sharing and leakage of the password. At the same time, the traditional static password system lacks fine-grained access control and cannot realize accurate permission management.
[0080] In the related art, a method of splitting and storing secret passwords is proposed, which improves the security of passwords and resources. However, these methods are relatively single in password splitting and recovery, and do not provide effective visitor identity verification and permission control methods. Although the existing technical scheme proposes that participants construct password shares to realize identity traceability, the splitting method still uses one-time generation, lacks permission expansion and dynamic collection mechanism. In addition, the secret recovery threshold of the scheme is limited by the number of participants and resource devices, which may lead to reduced security in some scenarios.
[0081] To solve these problems, the present scheme proposes a secret key password processing and management method independent of the resource management system. This method uses the private key of the participant to dynamically split and share the password, and provides a mechanism to quickly dynamically expand or reduce authorized users after initialization. This not only improves the security of the static password system, but also enhances the ability of visitor identity verification and permission control.
[0082] Figure 1 A flowchart of a secret key password processing method provided by an embodiment of the present disclosure is shown, which specifically includes the following steps S101-S103 as shown in Figure 1
[0083] S101, obtaining the resource identifier of the resource to be accessed and the user first password share corresponding to each authorized user.
[0084] In specific implementation, first, in response to a resource access request initiated by at least a preset number of authorized users, the resource identifier of the resource corresponding to the resource access request is obtained, and the user share and the user second password share corresponding to each authorized user in the at least preset number of authorized users are obtained. Then, based on the user share and the user second password share corresponding to each authorized user, the user first password share corresponding to each initial authorized user is queried in the pre-stored three-element information table.
[0085] S102, using the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user to parse the initial password.
[0086] In specific implementation, based on the held first password share and the received at least preset number of user first password shares, the initial password is reconstructed.
[0087] S103, accessing the resource corresponding to the resource identifier according to the initial password.
[0088] In specific implementation, the reconstructed initial password is used to access the resource corresponding to the resource identifier, and the reconstructed initial password is destroyed immediately after the access is completed.
[0089] This solution consists of four units: resource device end, resource control center, password distribution center, and user end. The units perform identity authentication, message encryption and verification based on PKI. Figures 2-10 , a key password generation and processing method and operating environment provided by the disclosed embodiment are explained in detail.
[0090] Figure 2 A flowchart of a method for generating an initial password provided by an embodiment of the present disclosure, specifically including the following steps: Figure 2 The following steps S201 to S203 are shown:
[0091] Step S201: Determine the security level.
[0092] In the specific implementation, during the initialization phase of the solution, the password distribution center is used as the Certificate Authority (CA). All resource terminals and all user terminals generate public and private keys based on a trusted public key algorithm and exchange public keys with the password distribution center and the resource control center. The interaction process is as follows: Figure 3 As shown, in this step, after the resource end registers the resource identifier RID with the resource management and control center, it sets the resource common authorization security level M, the common access security level N, and initializes the authorized user list, where N≤M.
[0093] Step S202: Initiate password registration based on the resource identifier.
[0094] During specific implementation, the resource control center sends RID and M to the password distribution center to initiate password registration.
[0095] Step S203: register an initial password.
[0096] In specific implementation, after receiving the registration information, the password distribution center initiates a password exchange with the resource end corresponding to the ID. The two parties negotiate an encrypted transmission channel based on the preset PKI. The resource end sends the real static secret password K to the password distribution center through the encrypted channel. After receiving the initial password K, the password distribution center randomly constructs M password coefficients a1, a2...a M , making And a1~a M Persistent storage.
[0097] This solution divides password and share management into three units: the resource side, the password distribution center, the resource control center, and the user side. This allows data with different confidentiality requirements to be confined to different units. Actual passwords are stored on the resource side and the password distribution center, encrypted using negotiated secrets for transmission, and temporarily restored and destroyed in real time on the resource control side. User password shares are partially stored and temporarily collected on the resource control side. This management process adheres to the hierarchical and domain-based principles of security design.
[0098] Figure 4 The schematic diagram of the principle of the method for generating the first password share and the user's first password share provided in the embodiment of the present disclosure is as follows: the pre-authorized user submits the user share to the resource control center, the resource control center uniformly submits the user's first password share and second password share to the password distribution center, the password distribution center distributes the first password share to the resource control center, and distributes the user's second password share to the authorized user. The flowchart of the method for generating the first password share is as follows: Figure 5 As shown, the process includes the following steps S501:
[0099] S501: Generate a second password share based on the initial password.
[0100] In the specific implementation, the resource control center first randomly constructs MN integers r1, r2…r M-N , encrypt the self-identifier MID and resource identifier RID with the private key to generate the signature MSign, and concatenate them with the random number to generate the second password share Xm i =Concat(MSign,r i ), respectively sent to the password distribution center, where 1≤i≤MN. Of course, in this step, the second password share can also be constructed by other means, such as obtaining MN integers with a regular pattern through a certain calculation method, which is not limited in the embodiment of the present disclosure.
[0101] It should be noted that the method for generating the user's first password share is the same as the method for generating the second password share, which will not be repeated here.
[0102] S502: Generate a first password share according to the second password share and the resource identifier, and store the first password share in a ternary information table.
[0103] In specific implementation, the password distribution center receives Xm1~Xm M-N After that, the first password share Ym1~Ym M-N , and then returns it to the resource management center.
[0104] The detailed steps of the first password generation method are as follows: First, take the signature part of Xm, decrypt it using the public key of the resource control center, and obtain (MID, RID). Based on RID, restore a1~a M ; Then based on a1~a M Construct an M-1 password generating polynomial:
[0105] F(x)=a1x M-1 +a2x M-2 +…+a M
[0106] Let x=Xm, obtain the value of the polynomial as the first password share Ym; finally, Ym is sent to the resource management center based on the MID. In the resource management center, the triple (RID, Xm i , Ym i ) is persisted, where 1≤i≤M-N.
[0107] It should be noted that the generation method of the second password share of the user is consistent with the generation method of the first password share, which will not be repeated here.
[0108] The scheme minimizes the storage and transmission scenarios of the static password K by constructing a splitting distribution and reconstruction recovery method of the secret password K. For the password shares used for sharing and transmission, there is a threshold value M at the mathematical level, so that under the condition that less than M different shares are cracked, the relevant information of the secret password cannot be obtained. Compared with the original static password system, the concealment of the password itself is improved, and the security of the password sharing scenario is also improved.
[0109] Figure 6 The flowchart of the method for generating the second password share of the user provided by the embodiment of the present disclosure includes steps S601-S603:
[0110] S601, generating a user share using the user identifier, resource identifier, and signature information of the user.
[0111] In specific implementation, the user encrypts and signs the user identifier UID and the resource identifier RID using a private key to generate a user share USign, and sends the user share USign to the resource management center.
[0112] S602, generating a first password share of the user based on the user share and a random number.
[0113] In specific implementation, the resource management center decrypts USign using the public key of the user, and verifies the initial authority of UID to RID; the resource management center constructs a random number Ru, concatenates USign and the random number to generate a first password share Xu=Concat(MSign,Ru) of the user, persists (UID, RID, Xu), and sends Xu to the password distribution center. By introducing a one-time random number to construct the first password share of the user, the management end can manage the user password share authority through the management of the random number, thereby realizing higher security and applicability of the authority management scenario.
[0114] S603, generating a second password share of the user according to the first password share of the user and the resource identifier.
[0115] In specific implementation, after the password distribution center receives Xu, a second password share Yu of the user is generated and returned to the authorized user.
[0116] Figure 7 The schematic diagram of the principle of the secret key password processing method provided by the embodiment of the present disclosure is as follows: a number of authorized users who meet the common access security level N jointly initiate resource access, and submit the user shares and user second password shares held to the resource management center respectively. The resource management center reconstructs the resource password based on the MN shares of the first and second password shares held, and the N shares of the user shares and user second password shares received, and accesses the resource. The flow diagram of the method is as follows Figure 8 As shown, the following steps S801 to S803 are included:
[0117] S801: Obtain the resource identifier of the resource to be accessed and the first password share of each authorized user.
[0118] In the specific implementation, first obtain the resource identifier of the resource to be accessed and the user's second password share corresponding to each authorized user, and then obtain the user's first password share based on the user's second password share. Specifically, according to the common security access level, N authorized users who jointly access the resource will encrypt and sign their own identifier UID and resource identifier RID using their own private key to reconstruct their own user shares Usign1~Usign N , together with the user's second password share, is sent to the resource control center, where 1≤i≤N. The resource control center receives the authorized user share and the user's second password share (Usign i ,Yu i ) and then use the corresponding user public key to decrypt Usign i , query the corresponding user's first password share Xu according to the obtained (UID, RID) i , until it is fully received (Xu i ,Yu i ), where 1≤i≤N.
[0119] S802: Analyze the initial password using the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user.
[0120] In specific implementation, the resource control center recovers the persistent storage based on RID (Xm i ,Ym i ), where 1≤i≤MN. Construct (X i ,Y i )where 1≤i≤M, let:
[0121]
[0122] Based on the preset method, the basis function L can be constructed according to the following formula i (x):
[0123]
[0124] And the password generation polynomial can be recovered:
[0125]
[0126] According to The resource management center can calculate the resource real static password, that is, the initial password K, by reconstruction.
[0127] S803, according to the initial password, access the corresponding resource of the resource identifier.
[0128] In specific implementation, the resource management center holds the recovered password K, establishes access with the resource, and destroys K immediately after the access is completed.
[0129] Figure 9 The principle diagram of the method for adding authorized users provided by the embodiment of the present disclosure is shown in the figure. The new user initiates a resource password authorization request to the authorized users meeting the number of common authorization security level M, the authorized users submit authorization confirmation to the resource management center, and the resource management center submits the user first password share to the password distribution center, and the password distribution center distributes the corresponding user second password share to the new user. The flowchart of the method is shown in Figure 10 The method includes the following steps S1001 to S1004:
[0130] S1001, in response to the password authorization application of the target user, generating the user share of the target user.
[0131] In specific implementation, when any unauthorized new user UID0 applies for the authority of a specific resource RID with a common authorization security level of M, the user share is generated by encrypting and signing the private key of the user (UID0, RID) of the user.
[0132] S1002, sending the user share of the target user to all authorized users.
[0133] In specific implementation, the user share is sent to M authorized users UID i , where 1≤i≤M.
[0134] S1003, after the approval of all authorized users, generating the user first password share corresponding to the target user based on the user share of the target user and the random number.
[0135] In specific implementation, after receiving the USign, the authorized user UID i decrypts the USign using the public key of the application user, checks UID0 and RID, performs the approval operation, and after the approval, the authorized user uses the private key to encrypt (UID i,RID,UID0) encrypted signature generates user authorization share AUSign i , sent to the resource control center for authorization confirmation, and the resource control center receives AUSign i Then, use the public key of the corresponding authorized user to decrypt according to (UID i ,RID) retrieval Xu i The password authority of the authorized user is verified. After the verification is passed, a triplet (UID0, RID, C=i) is set, where C is the count of the authorization confirmations of the user UID0 regarding the resource RID password by the authorized users who have passed the verification; when C=M, the applicant user submits his own user share to the resource management center through the authorized user password share distribution method, and then uses the user share to generate the user's first password share. The specific generation method is the same as the above step S801 and will not be repeated here.
[0136] S1004: Generate a second user password share corresponding to the target user according to the first user password share corresponding to the target user and the resource identifier.
[0137] During specific implementation, the resource management center sends the user's first password share to the password distribution center. The password distribution center generates the user's second password share based on the user's first password share and sends it to the user. The specific method of generating the user's second password share is the same as the above step S801 and will not be repeated here. When it comes to canceling the authorization of an authorized user, the resource management center destroys the password authorization by destroying the persistently stored (UID, RID, Xu).
[0138] This solution introduces dual thresholds for shared authorization and shared access within the password share threshold construction method. The shared authorization threshold corresponds to the actual password recovery threshold. By holding local shares on the resource management side, the security of high threshold settings can be applied even when the authorized user or shared access threshold requirements are low. At the same time, the difficulty of unauthorized authorization is equal to the difficulty of completely cracking the shared authorization threshold, thus mitigating the security risk of password escalation through authorization penetration.
[0139] The scheme is in the construction method of password share, first, the first and second password share separate management method is adopted, which is mastered by the resource management and control end and the user end, so that neither party continuously holds the complete information of the user share, and the difficulty of cracking the password share is improved; secondly, the user private key signature information (i.e. user share) is introduced to construct the first password share of the user, so that the leaked password share has traceability and non-repudiation, can prevent illegal copying, borrowing and using of the share, and realizes higher security; in addition, a one-time random number is introduced in the process of constructing the first password share of the user, which is held by the resource management and control end as the condition for restoring the first password share, so that the user's right can be flexibly granted and deprived by retaining and destroying the random number.
[0140] Figure 11 The structure diagram of the secret key password processing device provided by the embodiment of the present disclosure is provided. The secret key password processing device 1100 provided by the embodiment of the present disclosure can execute the processing flow provided by the secret key password processing method embodiment. As shown in the figure, the secret key password processing device 1100 includes an acquisition unit 1101, an analysis unit 1102 and a processing unit 1103, wherein: Figure 11
[0141] The acquisition unit 1101 is used to acquire the resource identifier of the resource to be accessed and the user first password share corresponding to each authorized user.
[0142] The analysis unit 1102 is used to analyze the initial password by using the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user.
[0143] The processing unit 1103 is used to access the resource corresponding to the resource identifier according to the initial password.
[0144] In a possible implementation manner, in the device provided by the embodiment of the present disclosure, the acquisition unit 1101 is specifically used for:
[0145] In response to the resource access request initiated by at least a preset number of authorized users, acquiring the resource identifier of the resource corresponding to the resource access request, and the user share and the user second password share corresponding to each authorized user in the at least preset number of authorized users;
[0146] Based on the user share and the user second password share corresponding to each authorized user, the user first password share corresponding to each authorized user is obtained.
[0147] In a possible implementation manner, in the device provided by the embodiment of the present disclosure, the acquisition unit 1101 is specifically used for:
[0148] Based on the user share corresponding to each authorized user and the user second password share, the user first password share corresponding to each initial authorized user is obtained by querying a pre-stored three-element information table.
[0149] In a possible implementation, the processing unit 1103 generates the first password share in the apparatus provided by the embodiment of the application by the following method:
[0150] In response to a password registration initiated by a to-be-managed resource, an initial password and a resource identifier corresponding to the to-be-managed resource are generated;
[0151] A second password share is generated based on the initial password;
[0152] A first password share is generated according to the second password share and the resource identifier, and is stored in the three-element information table.
[0153] In a possible implementation, the processing unit 1103 generates the user first password share corresponding to each authorized user in the apparatus provided by the embodiment of the application by the following method:
[0154] A user share is generated by using a user identifier of the user, the resource identifier, and signature information of the user;
[0155] A user second password share is generated based on the user share and a random number;
[0156] A user first password share is generated according to the user second password share and the resource identifier.
[0157] In a possible implementation, the processing unit 1103 is specifically further configured to:
[0158] The resource identifier and the user identifier of the user are obtained according to the user second password share;
[0159] An initial password is obtained through the resource identifier, and a user first password share is constructed according to the initial password and the user identifier.
[0160] In a possible implementation, the processing unit 1103 adds an authorized user in the apparatus provided by the embodiment of the application by the following method:
[0161] In response to a password authorization application of a target user, a user share of the target user is generated;
[0162] The user share of the target user is sent to all authorized users;
[0163] After the user share of the target user is audited and passed by all authorized users, a user first password share corresponding to the target user is generated based on the user share of the target user and a random number;
[0164] The user second password share corresponding to the target user is generated according to the user first password share corresponding to the target user and the resource identifier.
[0165] Figure 11 The key password processing apparatus of the illustrated embodiment can be used to execute the technical solutions of the method embodiments described above, and has similar implementation principles and technical effects, which will not be described here again.
[0166] In addition, in combination with Figures 1-11 The key password processing method and apparatus of the embodiments of the present application described above can be implemented by an electronic device. Figure 12 A hardware structure schematic diagram of an electronic device provided by the embodiments of the present application is shown.
[0167] As Figure 12 As shown, the electronic device 1200 can include a processing apparatus (such as a central processor, a graphics processor, etc.) 1201, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1202 or loaded from a storage apparatus 1208 into a random access memory (RAM) 1203 to implement the key password processing method of the embodiments as described in the present disclosure. In the RAM 1203, various programs and data required for the operation of the electronic device 1200 are also stored. The processing apparatus 1201, the ROM 1202, and the RAM 1203 are connected to each other through a bus 1204. An input / output (I / O) interface 1205 is also connected to the bus 1204.
[0168] Generally, the following apparatuses can be connected to the I / O interface 1205: input apparatuses 1206 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output apparatuses 1207 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage apparatuses 1208 including, for example, a magnetic tape, a hard disk, etc.; and communication apparatuses 1209. The communication apparatuses 1209 can allow the electronic device 1200 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 12 The electronic device 1200 with various apparatuses is shown, but it should be understood that it is not required to implement or have all the shown apparatuses. More or fewer apparatuses can be alternatively implemented or possessed.
[0169] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for executing the methods illustrated by the flowcharts, thereby implementing the voice control method as described above. In such embodiments, the computer program can be downloaded and installed from a network by the communication device 1209, or installed from the storage device 1208, or installed from the ROM 1202. When the computer program is executed by the processing device 1201, the above-described functions defined in the methods of the embodiments of the present disclosure are performed.
[0170] It should be noted that the computer-readable medium described above in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination thereof. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program used or used in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take on many forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium that can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained in the computer-readable medium can be transmitted by any suitable medium, including but not limited to a wire, cable, optical fiber, RF (radio frequency), or the like, or any suitable combination thereof.
[0171] In some embodiments, the client, server, or both can communicate using any known or later developed end-to-end protocol, such as the HyperText Transfer Protocol (HTTP), and can be interconnected with any form or medium of digital data communication (for example, a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), the Internet, and peer-to-peer networks (for example, ad hoc peer-to-peer networks), as well as any then-current or later developed networks.
[0172] The computer-readable medium described above can be included in the electronic device described above; alternatively, it can exist separately from the electronic device and be loaded into the electronic device at a later time.
[0173] The computer-readable medium described above carries one or more programs which, when executed by the electronic device, cause the electronic device to perform at least the following steps:
[0174] Obtain a resource identifier of a resource to be accessed and a user first password share corresponding to each authorized user;
[0175] Use the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user to resolve an initial password;
[0176] Access the resource corresponding to the resource identifier according to the initial password.
[0177] Optionally, when the one or more programs are executed by the electronic device, the electronic device can further perform other steps described in the above embodiments.
[0178] Computer program code for carrying out operations of the present disclosure can be written in any one or more programming languages, including object oriented programming languages such as Java, Smalltalk, C++, or conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network ("LAN"), a wide area network ("WAN"), or the Internet, or the connection can be made to an external computer (for example, through an Internet service provider, through your ISP) via the Internet.
[0179] The flow and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow and block diagrams can represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations thereof, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or combinations of hardware and software.
[0180] The units described in the embodiments of the present disclosure can be implemented by software, or by hardware. In some cases, the name of the unit does not constitute a limitation on the unit itself.
[0181] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, non-limiting examples of exemplary types of hardware logic components that can be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SOCs), complex programmable logic devices (CPLDs), etc.
[0182] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more of: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0183] The embodiments of the present disclosure provide a secret key password processing method, comprising:
[0184] First, the resource identifier of the resource to be accessed and the user first password share corresponding to each authorized user are acquired, then the initial password is parsed by using the resource identifier, the pre-stored first password share, and the user first password share corresponding to each authorized user, and finally the resource corresponding to the resource identifier is accessed according to the initial password. The secret key password processing method provided by the present disclosure parses the initial password used for acquiring the resource by using the user first password share of the authorized user and the pre-stored first password share, and realizes the application of a higher password recovery share quantity threshold value in the scenario where the number of persons required for joint access is small by setting a double threshold, thereby improving the security of resource access.
[0185] Those skilled in the art will appreciate that embodiments of the present application can be provided as methods, systems, or computer program products. Accordingly, the present application can be embodied in the form of complete hardware embodiments, complete software embodiments, or embodiments combining software and hardware aspects. Moreover, the present application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) having computer-usable program code embodied thereon.
[0186] The present application is described with reference to flowcharts and / or block diagrams according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The functions specified in one or more flows and / or blocks.
[0187] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction devices that implement the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The functions specified in one or more flows and / or blocks.
[0188] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a process for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1one or more processes and / or blocks Figure 1 the steps of the functions specified in the one or more blocks.
[0189] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the preferred embodiments by those of skill in the art once they have the benefit of the present disclosure. Therefore, the appended claims are intended to encompass within their scope all possible variations and modifications of the preferred embodiments. The preferred embodiments of the application are described above in detail. The preferred embodiments of the application are not limited to what has been described in the above content. The preferred embodiments of the application are only suitable for explaining the preferred embodiments of the application. The above content is intended to describe and define the preferred embodiments of the application. The scope of the preferred embodiments of the application is indicated by the appended claims rather than by the foregoing description. All changes and modifications that come within the meaning and range of equivalents of the claims are intended to be embraced by the claims as supplemented to the foregoing description. The claims are further indicated by the appended claims.
[0190] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A method for processing a secret key password, characterized in that: The method comprises: Obtain the resource identifier of the resource to be accessed and the first password share and the second password share corresponding to each authorized user, wherein the first password share is generated based on the user share and a random number, and the user share is obtained by encrypting and signing with a private key based on the user identifier and the resource identifier; Parsing the initial password using the resource identifier, the first password share and the second password share pre-stored by the resource management center, and the first password share corresponding to each authorized user and the obtained second password share; Access the resource corresponding to the resource identifier according to the initial password.
2. The method according to claim 1, characterized in that The step of obtaining the resource identifier of the resource to be accessed and the user second password share and the user first password share corresponding to each initially authorized user includes: In response to resource access requests initiated by at least a preset number of the authorized users, obtaining a resource identifier of a resource corresponding to the resource access request, and a user share and a user second password share corresponding to each of the at least a preset number of the authorized users; Based on the user share corresponding to each authorized user, the user first password share corresponding to each authorized user is obtained.
3. The method according to claim 2, characterized in that The obtaining, based on the user share corresponding to each authorized user, the user first password share corresponding to each authorized user, includes: Determining a user identifier and a resource identifier based on a user share corresponding to each of the authorized users; Based on the user identifier and the resource identifier, the user first password share corresponding to each of the initially authorized users is obtained by querying in a pre-stored ternary information table.
4. The method according to claim 3, characterized in that The first password share is generated by the following method: The password distribution center generates an initial password and resource identifier corresponding to the resource to be managed in response to the password registration initiated for the resource to be managed; The password distribution center constructs M password coefficients a based on the initial password 1、 a2...a M , making , and the M password coefficients a 1、 a2...a M Persistent storage; The resource management and control center generates a signature MSign based on its own identity and resource identity using a private key encryption; The resource management center generates a second password share based on the signature MSign and the random number, and sends it to the password distribution center; The password distribution center obtains the signature MSign based on the second password share, and decrypts the signature MSign to obtain the self-identity and resource identification of the resource management and control center; The password distribution center determines the password coefficient a according to the resource identifier 1、 a2...a M , then based on the password coefficient a 1、 a2...a M Construct an M-1 password generating polynomial: Substituting the second password share into the polynomial to obtain the value of the polynomial as the first password share, and sending the first password share to the resource management center; The resource management and control center stores the resource identifier, the second password share and the first password share in the ternary information table.
5. The method according to claim 4, characterized in that The first password share corresponding to each authorized user is generated by the following method: Generating a user share using the user identifier of the user, the resource identifier, and the signature information of the user; Generate a user's first password share based on the user share and the random number; A second password share for the user is generated according to the first password share for the user and the resource identifier.
6. The method according to claim 5, characterized in that Generating the user's second password share according to the user's first password share and the resource identifier includes: Obtaining the resource identifier and the user identifier of the user according to the user's first password share; The initial password is obtained through the resource identifier, and the user's second password share is constructed according to the initial password and the user identifier.
7. The method according to claim 6, characterized in that Use the following method to add the authorized user: In response to a password authorization request from a target user, generating a user share of the target user; Sending the user share of the target user to all the authorized users; After all the authorized users have passed the review, a first password share corresponding to the target user is generated based on the user share of the target user and a random number; A second user password share corresponding to the target user is generated according to the first user password share corresponding to the target user and the resource identifier.
8. A key password processing device, characterized in that: The device comprises: an acquisition unit, configured to acquire a resource identifier of a resource to be accessed and a first password share and a second password share corresponding to each authorized user, wherein the first password share is generated based on the user share and a random number, and the user share is obtained by cryptographically signing the user identifier and the resource identifier using a private key; A parsing unit, configured to parse an initial password using the resource identifier, the first password share and the second password share pre-stored by the resource management center, and the first password share corresponding to each authorized user and the acquired second password share; A processing unit is configured to access the resource corresponding to the resource identifier according to the initial password.
9. An electronic device, characterized in that: include: Memory; processor; as well as computer programs; The computer program is stored in the memory and is configured to be executed by the processor to implement the key password processing method according to any one of claims 1 to 7.
10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the key password processing method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Threshold-variable secret image sharing method
CN111953485A
SM9 user key generation method and device, equipment and storage medium
CN113381850A