System Operation Alarm Method, Device, Electronic Device, and Computer Readable Medium

By decrypting and updating the user's password history operation records, and promptly detecting and alerting unupdated passwords, the problems of high computing resources and users ignore alarms in the prior art are solved, and the security and efficiency of the system are improved.

CN118761054BActive Publication Date: 2025-07-01HUAQING RONGTIAN (BEIJING) SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410853533.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-28
Publication Date
2025-07-01
Estimated Expiration
2044-06-28

AI Technical Summary

Technical Problem

When the existing system operation alarm methods uniformly record and supervise the password modification operations of a large number of users, they occupy too much computing resources and the user ignores the alarm information, resulting in a high risk of system leakage.

Method used

By obtaining the historical operation record of the system user's system password modification from the preset database, decrypting the historical password modification, updating the data table, and establishing a detection thread at the time of the password expiration to detect whether the password is updated. If it is not updated, the password expiration trigger operation and alarm prompt will be triggered.

Benefits of technology

It reduces the consumption of computing resources, improves alarm efficiency, timely releases memory, and reduces the risk of leakage in the user system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118761054B_ABST
    Figure CN118761054B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a system operation warning method, apparatus, electronic device, and computer-readable medium. A specific implementation of the method includes: decrypting the historical modified passwords in each historical operation record in the historical operation record sequence set; updating the historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table; generating a password expiration time point corresponding to each system user in the updated data table; establishing a password expiration detection thread corresponding to the password expiration time point to detect whether the password is updated; triggering a corresponding password expiration trigger operation and recycling the password expiration detection thread to release the occupied memory. This implementation can reduce unnecessary access processes and timely release memory during the regular supervision of a large amount of data, improve the warning efficiency, and reduce the consumption of computing resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technologies, and more particularly, to a system operation warning method, apparatus, electronic device, and computer-readable medium. Background Art

[0002] System operation warning is a technology for warning user systems with potential risks. Currently, when performing system operation warning, the commonly adopted method is to uniformly record password modification operations. If it is detected that the interval duration of a certain operation record is greater than a preset duration (for example, 90 days), then the user corresponding to the operation record is determined from the user list, and finally it is determined that the user has not modified the password within the preset duration, and a system operation warning is issued.

[0003] However, it is found in practice that when the above method is used for system operation warning, the following technical problems often exist:

[0004] First, since there are many users in the system, after uniformly recording password modification operations, it is necessary to simultaneously and regularly monitor a large number of password modification operations to determine whether the interval duration of each password modification operation is greater than the preset duration. At the same time, it is also necessary to match the corresponding users for warning notifications. Therefore, a large amount of computing resources are required.

[0005] Second, if only system operation warning is performed, many users will ignore the warning information and not modify the password, resulting in a relatively high risk of leakage in the user system.

[0006] The above information disclosed in this background art section is only used to enhance the understanding of the background of the inventive concept, and thus, it may include information that does not form the prior art known to those of ordinary skill in the art in this country. Summary of the Invention

[0007] This section of the present disclosure is used to briefly introduce concepts that will be described in detail in the subsequent Detailed Description section. This section of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0008] Some embodiments of the present disclosure propose a system operation warning method, apparatus, electronic device, and computer-readable medium to solve one or more of the technical problems mentioned in the above background art section.

[0009] In a first aspect, some embodiments of the present disclosure provide a system operation warning method, which includes: obtaining historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, where each historical operation record includes an encrypted historical modified password; decrypting the historical modified password in each historical operation record in the above historical operation record sequence set to generate a decrypted historical operation record sequence set; updating the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table; for the decrypted historical operation record corresponding to each system user in the above-recorded data table, perform the following steps: generating a password expiration time point corresponding to each system user in the above updated data table; at the password expiration time point, establishing a password expiration detection thread corresponding to the above password expiration time point to detect whether the password is updated; in response to determining that the decrypted historical operation record is not updated within the corresponding password expiration time point, based on the password expiration time point, triggering a corresponding password expiration trigger operation and recycling the above password expiration detection thread to release the occupied memory, where the password expiration trigger operation is used to send a system password operation warning prompt to the user terminal of the above system user.

[0010] In a second aspect, some embodiments of the present disclosure provide a system operation warning device, which includes: an acquisition unit configured to obtain historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, where each historical operation record includes an encrypted historical modified password; a decryption unit configured to decrypt the historical modified password in each historical operation record in the above historical operation record sequence set to generate a decrypted historical operation record sequence set; an update unit configured to update the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table; an operation warning unit configured to, for the decrypted historical operation record corresponding to each system user in the above-recorded data table, perform the following steps: generating a password expiration time point corresponding to each system user in the above updated data table; at the password expiration time point, establishing a password expiration detection thread corresponding to the above password expiration time point to detect whether the password is updated; in response to determining that the decrypted historical operation record is not updated within the corresponding password expiration time point, based on the password expiration time point, triggering a corresponding password expiration trigger operation and recycling the above password expiration detection thread to release the occupied memory, where the password expiration trigger operation is used to send a system password operation warning prompt to the user terminal of the above system user.

[0011] In a third aspect, some embodiments of the present disclosure provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the above first aspect.

[0012] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium storing a computer program thereon, wherein the program, when executed by a processor, implements the method described in any implementation manner of the above first aspect.

[0013] The above various embodiments of the present disclosure have the following beneficial effects: Through the system operation alarm method of some embodiments of the present disclosure, the consumption of computing resources can be reduced. Specifically, the reason for the relatively large consumption of computing resources is that: since there are many users in the system, after uniformly recording password modification operations, it is necessary to simultaneously and regularly monitor a large number of password modification operations to determine whether the interval duration of each password modification operation is greater than a preset duration, and at the same time, it is also necessary to match the corresponding users for alarm notification. Based on this, in the system operation alarm method of some embodiments of the present disclosure, first, obtain the historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, where each historical operation record includes an encrypted historical modified password. Decrypt the historical modified password in each historical operation record in the above historical operation record sequence set to generate a decrypted historical operation record sequence set. Encrypted passwords occupy more bytes, and by decrypting, the byte bits of the password can be reduced, thereby reducing the data volume of the decrypted historical operation record sequence set. Then, update the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table. Then, for each decrypted historical operation record corresponding to each system user in the above-recorded data table, perform the following steps: Generate the password expiration time point corresponding to each system user in the above updated data table. By setting the password expiration time point, it is convenient to quickly determine whether the user password corresponding to the historical operation record is at risk. At the password expiration time point, establish a password expiration detection thread corresponding to the above password expiration time point to detect whether the password is updated. Finally, in response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, based on the password expiration time point, trigger the corresponding password expiration trigger operation and recycle the above password expiration detection thread to release the occupied memory, where the password expiration trigger operation is used to send a system password operation alarm prompt to the user terminal of the above system user. Thus, during the process of regularly monitoring a large amount of data, unnecessary access processes can be reduced, and the alarm efficiency can be improved. At the same time, the memory can be released in a timely manner, and the occupation and consumption of computing resources can be reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and that the elements and elements are not necessarily drawn to scale.

[0015] Figure 1 is a flowchart of some embodiments of a system operation warning method according to the present disclosure;

[0016] Figure 2 is a schematic structural diagram of some embodiments of a system operation warning device according to the present disclosure;

[0017] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0019] In addition, it should be noted that, for the sake of convenience of description, only the parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.

[0020] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or the interdependence relationship.

[0021] It should be noted that the modifications of "one" and "plural" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".

[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0023] For operations such as the collection, storage, and use of the user's personal information (such as the user's historical system operation behavior) involved in the present disclosure, before performing the corresponding operations, relevant organizations or individuals shall fulfill obligations including conducting a personal information security impact assessment, fulfilling the obligation of notification to the personal information subject, and obtaining the prior authorization and consent of the personal information subject.

[0024] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0025] Figure 1 Flow 100 of some embodiments of the system operation warning method according to the present disclosure is shown. The system operation warning method includes the following steps:

[0026] Step 101, obtain the historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set.

[0027] In some embodiments, the execution subject of the system operation warning method may obtain the historical operation records of modifying the system password corresponding to each system user from a preset database in a wired or wireless manner to obtain a historical operation record sequence set. Among them, each historical operation record includes an encrypted historical modified password. Among them, the system user is an account registered to use the system. Modifying the system password may be modifying the login password of the account, etc. The historical operation record may be a record of the historical password modification operation. In practice, the historical operation record may be stored as data after encrypting the password before recording.

[0028] It should be noted that the above wireless connection methods may include but are not limited to 3G / 4G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future-developed wireless connection methods.

[0029] Step 102, decrypt the historical modified password in each historical operation record in the historical operation record sequence set to generate a decrypted historical operation record sequence set.

[0030] In some embodiments, the above execution subject may decrypt the historical modified password in each historical operation record in the historical operation record sequence set to generate a decrypted historical operation record sequence set. Among them, decryption may be performed through a preset decryption algorithm.

[0031] As an example, the decryption algorithm may include but is not limited to at least one of the following: symmetric encryption algorithm, elliptic curve encryption algorithm, hash encryption algorithm, etc.

[0032] Step 103: Update the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table.

[0033] In some embodiments, the above-mentioned execution entity may update the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table.

[0034] Among them, the data table may include three fields. For example, username, host address, and operation time point. Thus, the data table may include the password modification situations of each system user (a set of field values of the corresponding three fields is a table record, corresponding to one user). When updating the historical operation record to the data table, first, it can be detected that the historical operation record is a newly added historical record. Then, the username corresponding to the historical operation record in the data table can be indexed. After that, the host address and operation time point of the historical operation record can be replaced with the field values of the host address and operation time point in the data table to obtain an updated data table. Thus, the updated data table may include the latest time point of each user's password modification operation.

[0035] Step 104: For the decrypted historical operation records corresponding to each system user in the recorded data table, perform the following steps:

[0036] Step 1041: Generate the password expiration time point corresponding to each system user in the updated data table.

[0037] In some embodiments, the above-mentioned execution entity may generate the password expiration time point corresponding to each system user in the above-mentioned updated data table. Among them, the operation time point corresponding to each user in the updated data table may be added with a preset time period threshold (for example, 3 months) to obtain the expiration time point corresponding to each system user.

[0038] In some alternative implementation manners of some embodiments, the above-mentioned execution entity generating the password expiration time point corresponding to each system user in the above-mentioned updated data table may include the following steps:

[0039] Step 1: Detect the abnormal status of each historical operation record in the above updated data table to generate a set of abnormal operation probability values. Among them, for each historical operation record (i.e., each table record in the updated data table), first, the number of host address changes corresponding to the historical operation record can be determined. Here, the host addresses of the corresponding user can be compared, and the number of different host addresses can be used as the number of host address changes. Then, the number of password modifications and the number of off-site logins of the user can be obtained. Finally, according to the preset weights, the number of host address changes and the number of off-site logins can be weighted and summed, and the normalized number of password modifications can be subtracted to obtain the abnormal operation probability value. Here, the normalized number of password modifications can be a floating-point number between 0 and 1, for example, a decimal number with one digit after the decimal point such as 0.1, 0.2, 0.5, etc. Each abnormal operation probability value can represent the risk degree of the corresponding user's account leakage.

[0040] Step 2: Based on the above set of abnormal operation probability values, establish the expiration time point for each system user in the above updated data table. Among them, for each abnormal operation probability value in the set of abnormal operation probability values, the expiration time point can be determined by multiplying the complementary number of the abnormal operation probability value and 1 by a preset time period threshold. Thus, an account with a higher abnormal risk degree can be set with a shorter warning time to facilitate increasing the user's password modification frequency and reducing the risk of password cracking and leakage.

[0041] Step 1042: At the password expiration time point, establish a password expiration detection thread corresponding to the password expiration time point to detect whether the password is updated.

[0042] In some embodiments, the above execution subject can establish a password expiration detection thread corresponding to the above password expiration time point at the password expiration time point to detect whether the password is updated. Among them, a preset creation script can be called, and a password expiration detection thread corresponding to the above password expiration time point can be established by using the pre-set memory to detect whether the password is updated.

[0043] Step 1043: In response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, trigger the corresponding password expiration trigger operation based on the password expiration time point and recycle the above password expiration detection thread to release the occupied memory.

[0044] In some embodiments, the above-mentioned execution entity may, in response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, trigger a corresponding password expiration trigger operation based on the password expiration time point and recycle the above-mentioned password expiration detection thread to release the occupied memory. Among them, the host address corresponding to each user can be bound to a preset trigger warning operation to obtain an expiration trigger operation, which is used to send a warning message to the corresponding host address at the expiration time point.

[0045] Optionally, the above-mentioned execution entity may also perform the following steps:

[0046] First step, in response to receiving a password modification operation of a system user within the above-mentioned expiration time point, store the above-mentioned password modification operation in the historical operation record, and perform a secondary update on the above-mentioned updated data table to obtain a secondarily updated data table. Among them, the above-mentioned secondary update is to update the operation time point of the password modification operation of the corresponding system user. Here, the update can be to replace the operation time point in the updated data table corresponding to the above-mentioned password modification operation with the operation time point.

[0047] Second step, use the operation time point of the above-mentioned password modification operation to reset the expiration time point corresponding to the above-mentioned password modification operation. Here, a preset time period threshold can be added to the operation time point as the modified expiration time point.

[0048] Optionally, the above-mentioned execution entity may also perform the following steps:

[0049] First step, in response to determining that a system operation warning prompt is sent to the user terminal of the above-mentioned system user, use the time point when the system operation warning prompt is sent to reset the expiration time point corresponding to the above-mentioned system user as the first warning reset time point. Among them, the time point when the system operation warning prompt is sent can be added with a preset second duration threshold (for example, 2 months) to obtain the first warning reset time point.

[0050] Second step, for the historical operation record corresponding to each system user in the above-mentioned recorded data table, in response to determining that the historical operation record has not been updated within the first warning reset time point, perform a preset strong reminder operation on the above-mentioned system user to prompt the user to modify the password regularly.

[0051] As an example, the strong reminder operation may include but is not limited to at least one of the following: SMS reminder, page pop-up reminder, password re-entry reminder, etc.

[0052] Optionally, the above-mentioned execution entity may also perform the following steps:

[0053] First step, in response to determining to perform a strong reminder operation on the user terminal of the above-mentioned system user, use the time point when the strong reminder operation is performed to reset the above-mentioned first alarm reset time point as the second alarm reset time point. Among them, the time point when the strong reminder operation is performed can be added with a preset third duration threshold (for example, 1 month) to obtain the second alarm reset time point.

[0054] Second step, for the historical operation records corresponding to each system user in the above-mentioned recorded data table, in response to determining that the historical operation records have not been updated within the second alarm reset time point, determine whether the above-mentioned user terminal is in an idle state. Among them, the system terminal can be called to obtain the program process. Secondly, in response to detecting that the program process does not include a preset working process, it is determined that the user terminal is in an idle state.

[0055] In practice, the working process can be a process generated when the user logs in to the system for system operations.

[0056] Third step, in response to determining that the above-mentioned user terminal is in an idle state, based on the historical operation records of the above-mentioned system user, perform an active password modification operation to obtain a modified password and store the modified password.

[0057] Optionally, the above-mentioned execution subject performs an active password modification operation based on the historical operation records of the above-mentioned system user to obtain a modified password, and may further include the following steps:

[0058] First step, obtain the personal registration information of the above-mentioned system user. Among them, the personal registration information may include but is not limited to at least one of the following: username, user's own name, user ID number, user mobile phone number, etc.

[0059] Second step, perform password text extraction on each historical operation record of the above-mentioned system user to obtain an extracted password group. Among them, the password text in the historical operation record can be indexed according to a preset position as the extracted password.

[0060] Third step, perform user habit feature extraction on each extracted password in the above-mentioned extracted password group to generate a password personal feature group. Among them, the user habit features of each extracted password in the above-mentioned extracted password group can be extracted through a preset feature extraction algorithm to generate a password personal feature group. Here, the user habit feature extraction can be to extract the frequency (for example, it can be statistically analyzed through the term frequency-inverse document frequency algorithm) and corresponding meanings of single characters or combined characters (for example, at least two characters composed of numbers and / or letters) appearing in each password. Then, each character or combined character and the corresponding word frequency and meaning identifier can be determined as password personal features to obtain a password personal feature group.

[0061] In addition, the meaning corresponding to a single character or a combined character can be extracted through a rule-based method. For example, a dictionary can be preset in advance to compare the meaning identifiers of characters or combined characters. The corresponding meaning identifier can also be determined through models such as Hidden Markov Model and Conditional Random Field.

[0062] In practice, by analyzing the word frequency and meaning corresponding to each character or combined character, the personality characteristics of the user-set password can be extracted. Thus, during the password modification process, in order to reduce the possibility of leakage, these personality characteristics can be greatly avoided to improve the confidentiality of the password.

[0063] Step 4: Perform a fusion process on each password personal characteristic in the above personal registration information and the above password personal characteristic group to generate the fused user password characteristic information. Among them, the fusion process can be to compare the meaning identifier corresponding to the password personal characteristic with each piece of information in the personal registration information, delete the password personal characteristics corresponding to the non-matching meaning identifiers, and determine the password personal characteristics corresponding to the matching meaning identifiers as the fused user password characteristic information.

[0064] In practice, non-matching can be that the meaning represented by the meaning identifier is different from each piece of information in the personal registration information. For example, if the meaning identifier is 1 and the corresponding meaning is the year of birth, and the user ID number in the personal registration information is different from the year of birth, it is determined as non-matching.

[0065] Step 5: Perform information association on each extracted password in the above extracted password group and the above fused user password characteristic information to generate a password association feature set. Among them, the information association can be to determine the index position where the single character or combined character corresponding to each password personal characteristic in the fused user password characteristic information appears in the extracted password, and then, the index position with the highest frequency corresponding to each fused user password characteristic information can be selected. Finally, the password personal characteristic in the fused user password characteristic information and the corresponding index position can be determined as the password association feature to obtain the password association feature set.

[0066] Step 6: Modify the system password of the above system user based on the above password association feature set to obtain the modified password. Among them, the single character or combined character and the corresponding index position in each password association feature can be used as the restriction conditions for modifying the password, so as to avoid these single characters or combined characters at the corresponding index positions and perform random password modification to obtain the modified password. Optionally, the above execution entity can also perform the following steps:

[0067] First step, in response to detecting that the user terminal of the above-mentioned system user fails to log in, send a password verification question to the above-mentioned user terminal. Among them, the user terminal fails to log in due to an incorrect password. Among them, the password verification question can be the verification question filled in by the user during account registration.

[0068] Second step, in response to determining that the password verification question of the above-mentioned user terminal passes, send the modified password to the user terminal of the above-mentioned system user.

[0069] The above steps 102 - 104 and their respective optional implementation manners are an inventive point of the embodiments of the present disclosure, which solve the second technical problem mentioned in the background art, "If only system operation warnings are given, there are many users who ignore the warning information and do not modify their passwords, thus resulting in a relatively high risk of leakage of the user system." The factors that lead to a relatively high risk of leakage of the user system are often as follows: If only system operation warnings are given, there are many users who ignore the warning information and do not modify their passwords. If the above factors are solved, the risk of leakage of the user system can be reduced. To achieve this effect, first, through two reset operations, it can be used to timely adjust the expiration time point for warnings. Therefore, it can be used to remind users to modify their passwords multiple times. Then, considering the situation where the user still has not modified their password, by introducing the user's personal registration information and the passwords used in the past, it can be used to extract the user's personal password characteristics. And through feature extraction and feature fusion, the correlation characteristics between password characters and personal information can be associated. At the same time, the characteristics of the user's setting of personal information in the password are also considered, so that the password correlation characteristics include the common password characters and the common position characteristics of personal information. Thus, by avoiding these characteristics when modifying the password, the risk of password leakage caused by the user's personal habit characteristics can be further reduced.

[0070] The above embodiments of the present disclosure have the following beneficial effects: Through the system operation warning method of some embodiments of the present disclosure, the consumption of computing resources can be reduced. Specifically, the reason for the relatively large consumption of computing resources is that: since there are many users in the system, after uniformly recording password modification operations, it is necessary to simultaneously and regularly monitor a large number of recorded password modification operations to determine whether the interval duration of each password modification operation is greater than a preset duration. At the same time, it is also necessary to match the corresponding users for warning notifications. Based on this, in the system operation warning method of some embodiments of the present disclosure, first, obtain the historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, where each historical operation record includes an encrypted historical modified password. Decrypt the historical modified password in each historical operation record in the above historical operation record sequence set to generate a decrypted historical operation record sequence set. The encrypted password occupies more bytes. By decrypting, the byte bits of the password can be reduced, thereby reducing the data volume of the decrypted historical operation record sequence set. Then, update the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table. Then, for each decrypted historical operation record corresponding to each system user in the above-recorded data table, perform the following steps: Generate the password expiration time point corresponding to each system user in the above updated data table. By setting the password expiration time point, it is convenient to quickly determine whether the user password corresponding to the historical operation record is at risk. At the password expiration time point, establish a password term detection thread corresponding to the above password expiration time point to detect whether the password is updated. Finally, in response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, based on the password expiration time point, trigger the corresponding password expiration trigger operation and recycle the above password term detection thread to release the occupied memory, where the password expiration trigger operation is used to send a system password operation warning prompt to the user terminal of the above system user. Thus, during the process of regularly monitoring a large amount of data, unnecessary access processes can be reduced, and the warning efficiency can be improved. At the same time, the memory can be released in a timely manner, and the occupation and consumption of computing resources can be reduced.

[0071] Further referring to Figure 2 , as an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a system operation warning device. These device embodiments correspond to Figure 1 the method embodiments shown, and the device can be specifically applied to various electronic devices.

[0072] As Figure 2As shown, the system operation warning device 200 of some embodiments includes: an acquisition unit 201, a decryption unit 202, an update unit 203, and an operation warning unit 204. Among them, the acquisition unit 201 is configured to obtain the historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, where each historical operation record includes an encrypted historical modified password; the decryption unit 202 is configured to decrypt the historical modified password in each historical operation record in the above historical operation record sequence set to generate a decrypted historical operation record sequence set; the update unit 203 is configured to update the decrypted historical operation record with the largest timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table; the operation warning unit 204 is configured to perform the following steps for the decrypted historical operation record corresponding to each system user in the above-recorded data table: generate the password expiration time point corresponding to each system user in the above updated data table; at the password expiration time point, establish a password expiration detection thread corresponding to the password expiration time point to detect whether the password is updated; in response to determining that the decrypted historical operation record is not updated within the corresponding password expiration time point, based on the password expiration time point, trigger the corresponding password expiration trigger operation and recycle the above password expiration detection thread to release the occupied memory, where the password expiration trigger operation is used to send a system password operation warning prompt to the user terminal of the above system user.

[0073] It can be understood that the various units described in the device 200 correspond to the respective steps in the method described with reference to Figure 1 Therefore, the operations, features, and beneficial effects described above for the method also apply to the device 200 and the units included therein, and will not be elaborated here.

[0074] Next, with reference to Figure 3 , which shows a schematic structural diagram of an electronic device (for example, a computing device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present disclosure.

[0075] As Figure 3As shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to a program stored in the read-only memory 302 or a program loaded from the storage device 308 into the random access memory 303. In the random access memory 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the read-only memory 302, and the random access memory 303 are connected to each other through a bus 304. The input / output interface 305 is also connected to the bus 304.

[0076] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 the electronic device 300 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had. Figure 3 Each block shown in may represent one device or, as needed, multiple devices.

[0077] Specifically, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such some embodiments, the computer program may be downloaded and installed from a network through the communication device 309, or installed from the storage device 308, or installed from the read-only memory 302. When the computer program is executed by the processing device 301, the above functions defined in the methods of some embodiments of the present disclosure are executed.

[0078] It should be noted that the computer-readable media described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0079] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (Hyper Text Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed network.

[0080] The above computer-readable medium may be included in the above electronic device; or it may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is caused to: obtain historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, where each historical operation record includes an encrypted historical modified password; decrypt the historical modified password in each historical operation record in the historical operation record sequence set to generate a decrypted historical operation record sequence set; update the decrypted historical operation record with the largest timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table; for each decrypted historical operation record corresponding to each system user in the recorded data table, perform the following steps: generate a password expiration time point corresponding to each system user in the updated data table; at the password expiration time point, establish a password expiration detection thread corresponding to the password expiration time point to detect whether the password is updated; in response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, based on the password expiration time point, trigger a corresponding password expiration trigger operation and recycle the password expiration detection thread to release the occupied memory, where the password expiration trigger operation is used to send a system password operation warning prompt to the user terminal of the system user.

[0081] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages - such as Java, Smalltalk, C++; and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or may be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).

[0082] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0083] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes an acquisition unit, a decryption unit, an update unit, and an operation warning unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the acquisition unit can also be described as "the unit for acquiring historical operation records".

[0084] The functions described above can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0085] The above description is only some preferred embodiments of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A system operation alarm method, comprising: Obtaining historical operation records of modifying system passwords corresponding to each system user from a preset database to obtain a historical operation record sequence set, wherein each historical operation record includes an encrypted historical modification password; Decrypting the history modification password in each history operation record in the history operation record sequence set to generate a decrypted history operation record sequence set; Update the decrypted historical operation record with the largest time stamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set to a preset data table to obtain an updated data table; For the decrypted historical operation records corresponding to each system user in the updated data table, perform the following steps: Generate a password expiration time point corresponding to each system user in the updated data table; At the password expiration time point, a password period detection thread corresponding to the password expiration time point is established to detect whether the password is updated; In response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, based on the password expiration time point, triggering a corresponding password expiration trigger operation and reclaiming the password period detection thread to release the occupied memory, wherein the password expiration trigger operation is used to issue a system password operation alarm prompt to the user terminal of the system user; In response to determining to issue a password operation alarm prompt to a user terminal of the system user, resetting the expiration time point corresponding to the system user by using the time point of issuing the password operation alarm prompt as a first alarm reset time point; For the historical operation record corresponding to each system user in the post-record data table, in response to determining that the historical operation record has not been updated within the first alarm reset time point, performing a preset strong reminder operation on the system user to prompt the user to change the password regularly; In response to determining to perform a strong reminder operation on the user terminal of the system user, resetting the first alarm reset time point by using the time point of performing the strong reminder operation as the second alarm reset time point; For the historical operation record corresponding to each system user in the post-record data table, in response to determining that the historical operation record is not updated within the second alarm reset time point, determining whether the user terminal is in an idle state; In response to determining that the user terminal is in an idle state, based on the historical operation record of the system user, performing an active password modification operation, obtaining a modified password, and storing the modified password; The step of performing an active password modification operation based on the historical operation record of the system user to obtain a modified password includes: Obtaining personal registration information of the system user; Extracting password text from each historical operation record of the system user to obtain an extracted password group; Extracting user habit features from each extracted password in the extracted password group to generate a password personal feature group; fusing the personal registration information and each password personal feature in the password personal feature group to generate fused user password feature information; The fused user password feature information is informationally associated with each extracted password in the extracted password group to generate a password associated feature set, wherein the information association is to determine the index position where a single character or a combination of characters of each password personal feature in the fused user password feature information corresponds to in the extracted password, select an index position with the highest frequency corresponding to the index position where each fused user password feature information is located, determine the password personal feature in the fused user password feature information and the corresponding index position as the password associated feature, and obtain the password associated feature set; Based on the password-associated feature set, the system password of the system user is modified to obtain a modified password, wherein the single characters or combined characters in each password-associated feature and the corresponding index positions are used as restriction conditions for modifying the password, so as to avoid these single characters or combined characters at the corresponding index positions, perform random password modification, and obtain the modified password.

2. The method according to claim 1, wherein: The method further comprises: In response to receiving a password modification operation of a system user within the password expiration time point, storing the password modification operation in a historical operation record, and performing a secondary update on the updated data table to obtain a secondary updated data table, wherein the secondary update is to update the operation time point of the password modification operation of the corresponding system user; The expiration time point corresponding to the password modification operation is reset using the operation time point of the password modification operation.

3. The method according to claim 1, wherein: The generating of the password expiration time point corresponding to each system user in the updated data table includes: Performing abnormal state detection on each historical operation record in the updated data table to generate an abnormal operation probability value set; Based on the abnormal operation probability value set, an expiration time point corresponding to each system user in the updated data table is established.

4. A system operation alarm device, comprising: The acquisition unit is configured to acquire the historical operation records of modifying the system password corresponding to each system user from a preset database to obtain a historical operation record sequence set, wherein each historical operation record includes an encrypted historical modification password; a decryption unit configured to decrypt the history modification password in each history operation record in the history operation record sequence set to generate a decrypted history operation record sequence set; An updating unit is configured to update the decrypted historical operation record with the largest corresponding timestamp in each decrypted historical operation record sequence in the decrypted historical operation record sequence set into a preset data table to obtain an updated data table; The operation alarm unit is configured to perform the following steps for the decrypted historical operation record corresponding to each system user in the recorded data table: Generate a password expiration time point corresponding to each system user in the updated data table; At the password expiration time point, a password period detection thread corresponding to the password expiration time point is established to detect whether the password is updated; In response to determining that the decrypted historical operation record has not been updated within the corresponding password expiration time point, based on the password expiration time point, triggering a corresponding password expiration trigger operation and reclaiming the password period detection thread to release the occupied memory, wherein the password expiration trigger operation is used to issue a system password operation alarm prompt to the user terminal of the system user; A first resetting unit is configured to, in response to determining to issue a password operation alarm prompt to a user terminal of the system user, reset the expiration time point corresponding to the system user by using the time point of issuing the password operation alarm prompt as a first alarm reset time point; A strong reminder operation unit is configured to, for each system user's historical operation record in the post-record data table, in response to determining that the historical operation record has not been updated within the first alarm reset time point, perform a preset strong reminder operation on the system user to prompt the user to change the password regularly; A second resetting unit is configured to, in response to determining to perform a strong reminder operation on a user terminal of the system user, reset the first alarm reset time point by using the time point of performing the strong reminder operation as the second alarm reset time point; A determination unit is configured to determine, for each system user's historical operation record in the post-record data table, whether the user terminal is in an idle state in response to determining that the historical operation record is not updated within the second alarm reset time point; a storage unit configured to, in response to determining that the user terminal is in an idle state, perform an active password modification operation based on a historical operation record of the system user, obtain a modified password, and store the modified password; The step of performing an active password modification operation based on the historical operation record of the system user to obtain a modified password includes: Obtaining personal registration information of the system user; Extracting password text from each historical operation record of the system user to obtain an extracted password group; Extracting user habit features from each extracted password in the extracted password group to generate a password personal feature group; fusing the personal registration information and each password personal feature in the password personal feature group to generate fused user password feature information; The fused user password feature information is informationally associated with each extracted password in the extracted password group to generate a password associated feature set, wherein the information association is to determine the index position where a single character or a combination of characters of each password personal feature in the fused user password feature information corresponds to in the extracted password, select an index position with the highest frequency corresponding to the index position where each fused user password feature information is located, determine the password personal feature in the fused user password feature information and the corresponding index position as the password associated feature, and obtain the password associated feature set; Based on the password-associated feature set, the system password of the system user is modified to obtain a modified password, wherein the single characters or combined characters in each password-associated feature and the corresponding index positions are used as restriction conditions for modifying the password, so as to avoid these single characters or combined characters at the corresponding index positions, perform random password modification, and obtain the modified password.

5. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 3.

6. A computer readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.

Citation Information

Patent Citations

  • Application system user password expiration reminding design method capable of being flexibly set

    CN112651016A

  • Apparatus and method for multi-threaded password management

    US20030018919A1