A dynamic password login authentication method for power grid system

By displaying the dynamic password parameter generation interface and QR code in the power grid system, and computing and analysis in a trusted execution environment, the security risks of static password login and the unavailability of mobile phone SMS dynamic password login when the signal is weak is solved, and a high-security dynamic password login authentication is achieved.

CN119397514BActive Publication Date: 2025-05-06HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411974757.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-06
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

There are security risks in existing power grid systems. It takes a long time to enter complex passwords and is easily forgotten. Static passwords are easily stolen; mobile phone SMS dynamic password login cannot be used when the signal is weak or blocked, and dynamic passwords are easily leaked by malware.

Method used

A dynamic password login authentication method of the power grid system is adopted. By displaying the dynamic password parameter generation interface and corresponding QR code in the power grid system, the dynamic password APP on the user's mobile terminal calculates and parses the QR code in a trusted execution environment to generate the first character string, and obtains the dynamic password parameters through the preset password initialization algorithm and the dynamic password information generation algorithm based on the user's personal information.

Benefits of technology

Ensure the security of identity authentication during the first login process of users, avoid the problem of static passwords being easily stolen, and improve the security of login in the power grid system and the reliability of dynamic password generation; through the combination of dynamic password generation algorithm and a trusted execution environment, dynamic passwords are effectively avoided being reused or attacked during multiple login processes, enhancing the uniqueness and real-timeness of dynamic passwords.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119397514B_ABST
    Figure CN119397514B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of power grid system security technology, and in particular to a power grid system dynamic password login authentication method, comprising: when the power grid system obtains first login information input by a user, a first verification method is used to verify the first login information, and after the verification is passed, the power grid system displays a dynamic password parameter generation interface, and further displays a QR code corresponding to the dynamic password parameter on the dynamic password parameter generation interface, so that a dynamic password APP on a user's mobile terminal scans the QR code and calculates and parses it in a trusted execution environment TEE to obtain a first character string; the dynamic password parameter is obtained based on pre-acquired user personal information through a pre-set password initialization algorithm and a dynamic password information generation algorithm; the first login information is the account ID and initialization login password of the power grid system input by the user when logging into the power grid system for the first time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power grid system security, and in particular to a power grid system dynamic password login authentication method. Background Art

[0002] With the rapid development of information technology, the power grid system plays an increasingly important role in ensuring my country's energy security and improving power supply reliability. However, there are certain security risks in the login process of the power grid system. At present, most power grid systems still use static password login, which ensures system security to a certain extent, but also brings the following two problems:

[0003] In order to improve system security, power grid systems generally use long and complex login passwords. This requires users to spend more time and energy entering passwords every time they log in during long-term use; and for users who occasionally use the power grid system, it is easy for them to forget the passwords due to the long and complex passwords, which affects work efficiency.

[0004] Since static passwords remain unchanged for a long time, once they are stolen by criminals, they may cause malicious attacks on the power grid system, posing a serious threat to my country's energy security.

[0005] In order to solve the security risks of static password login, some power grid systems have begun to use dynamic password login via mobile phone text messages. Dynamic password login has improved system security to a certain extent, but there are still the following two problems:

[0006] The current mobile phone text message dynamic password login method requires the user's device to maintain a good communication state. In situations where the signal is weak or blocked, such as unstable mobile phone signals or communication interruptions, users may not be able to obtain dynamic passwords in time, which directly affects the normal login and use of the power grid system. Especially in those power grid systems that only allow internal network communication, the use of mobile phone text message dynamic passwords becomes unfeasible due to the inability to exchange information with the outside world.

[0007] At present, many malwares have the function of monitoring SMS, which may cause the dynamic password to be leaked during the transmission process. Once the password is leaked, criminals can easily log in to the power grid system, posing a threat to the system security. Summary of the invention

[0008] In view of the above-mentioned shortcomings and deficiencies of the prior art, the present invention provides a power grid system dynamic password login authentication method.

[0009] In order to achieve the above object, the main technical solutions adopted by the present invention include:

[0010] An embodiment of the present invention provides a power grid system dynamic password login authentication method, comprising:

[0011] When the power grid system obtains the first login information input by the user, the first verification method is used to verify the first login information, and after the verification is passed, the power grid system displays a dynamic password parameter generation interface, and further displays a QR code corresponding to the dynamic password parameter on the dynamic password parameter generation interface, so that the dynamic password APP on the user's mobile terminal scans the QR code and calculates and parses it in the trusted execution environment TEE to obtain a first character string;

[0012] The dynamic password parameters are obtained based on the pre-acquired user personal information through a pre-set password initialization algorithm and a dynamic password information generation algorithm;

[0013] The first login information is the account ID and initial login password of the power grid system entered by the user when logging into the power grid system for the first time. .

[0014] Preferably,

[0015] When the power grid system obtains the second login information input by the user, the second verification method is used to verify the second login information, and after the verification is passed, the power grid system displays the main page after the successful login;

[0016] The second login information is the account ID and dynamic password of the power grid system entered by the user when logging into the power grid system for the Nth time. ; Where N ≥ 2;

[0017] The dynamic password The dynamic password APP on the user's mobile terminal is generated by using a dynamic password generation algorithm based on the first character string generated in the N-1th login process stored in advance;

[0018] The dynamic password APP on the user's mobile terminal generates the dynamic password using a dynamic password generation algorithm based on a pre-stored first character string. During the N-th login process, the first character string is updated to obtain the first character string corresponding to the N-th login process.

[0019] Preferably,

[0020] The initial login password It is generated by the power grid system according to the pre-acquired user's personal information using a preset generation strategy, and sent to the user through the administrator, specifically including:

[0021] The power grid system converts each information item in the user's personal information into a corresponding binary number, and uses formula (1) to generate a first binary number r1;

[0022] The formula (1) is:

[0023] ;

[0024] in, It is the symbol of XOR operation;

[0025] M n The binary number converted from the nth information item in the user's personal information;

[0026] Hash() is a hash function that can generate 90-bit binary;

[0027] r0 is a second binary number; the second binary number r0 is a 90-bit binary array set by the power grid system, and after randomly filling each bit with 0 or 1, the binary array is converted into a binary number;

[0028] Based on the first binary number r1 and the second binary number r0, a third binary number r2 is generated using formula (2);

[0029] The formula (2) is: ;

[0030] The power grid system converts the third binary number r2 into a second string and uses the second string as the initialization login password. ; The second character string is a character string with a length of 15;

[0031] In the process of converting the third binary number r2 into the second character string, the third binary number r2 is converted into one character from left to right of the second character string corresponding to every 6 bits from high to low.

[0032] Each character in the second character string is any one of 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters and 2 preset characters.

[0033] Preferably,

[0034] The dynamic password parameters are obtained through a preset password initialization algorithm and a dynamic password information generation algorithm, specifically including:

[0035] The power grid system converts each item of the user's personal information into a one-to-one binary number, and then uses a 256-bit hash function to , map the message into the message space, and get ;

[0036] The message space is a operable number in the range of [0, q); wherein q is a constant, which is a large 256-bit binary prime number set inside the power grid system;

[0037] in, ; ;... ;

[0038] Using the generated , construct the first polynomial;

[0039] Wherein, the first polynomial is:

[0040] ;

[0041] mod is the symbol for the remainder operation;

[0042] Get the password factor M0 entered by the user and pass it through a 256-bit hash function , converting the password factor M0 into the message space to obtain the first power grid parameter;

[0043] Wherein, the value of the first power grid parameter is a0; ;

[0044] The password factor M0 is a character string randomly selected by the user, ranging from 6 to 15 characters; each character in the password factor M0 is any one of the 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters and 2 preset characters;

[0045] The power grid system constructs a second polynomial based on the first polynomial;

[0046] Wherein, the second polynomial is:

[0047] ;

[0048] The coefficients of the second polynomial Convert each of the three strings into a corresponding third string one by one, and use a preset string concatenation function to concatenate all the third strings to obtain a dynamic password parameter; the third string is a hexadecimal string;

[0049] Among them, the dynamic password parameter is s; ;

[0050] Concat() is a string concatenation function;

[0051] The two-dimensional code corresponding to the dynamic password parameter is obtained by converting the dynamic password parameter by the power grid system using a two-dimensional code generation function.

[0052] Preferably, the first login information is verified using a first verification method, specifically including:

[0053] The power grid system will enter the initial login password entered by the user The password is compared with the pre-stored initial login password of the user. If they are the same, the verification is passed and the user's first login is successful.

[0054] Preferably, verifying the first login information using a first verification method further includes:

[0055] If the user enters the initial login password If the initial login password is not consistent with the pre-stored initial login password of the user, the verification fails and the power grid system prompts the user to enter an error message; if the initial login password entered by the user is incorrect for 5 consecutive times If the verification fails, the power grid system will block the user's account, making it impossible for the user to log in.

[0056] Preferably,

[0057] The dynamic password APP on the user's mobile terminal generates the dynamic password using a dynamic password generation algorithm based on the first character string generated during the N-1th login process stored in advance. The process specifically includes:

[0058] The dynamic password APP on the user's mobile terminal uses the pre-set decomposition function UnConcat() in the trusted execution environment TEE to decompose the first string generated in the pre-stored N-1th login process into integers. , and b0 is used as the value of the first APP parameter;

[0059] The dynamic password APP on the user's mobile terminal uses a hash function in the trusted execution environment TEE. Map the account ID entered by the user to the message space to obtain the corresponding integer id;

[0060] in, ;

[0061] Based on the id, the dynamic password APP on the user's mobile terminal calculates in the trusted execution environment TEE ;

[0062] ;

[0063] The dynamic password APP on the user's mobile terminal intercepts the binary number in the trusted execution environment TEE. The last 24 digits of the string are converted into the fourth string t A ;

[0064] Among them, the fourth string t A A 6-digit hexadecimal string;

[0065] The dynamic password APP on the user's mobile terminal converts the fourth string t A Convert it into a binary number t1, and update the first APP parameter so that the value of the first APP parameter is equal to t1;

[0066] The dynamic password APP on the user's mobile terminal is in the trusted execution environment TEE, and the updated first APP parameter value t1 is consistent with the polynomial The coefficients in Convert them into hexadecimal strings respectively, and then use the string concatenation function Concat() to concatenate the converted strings to obtain the first string corresponding to the Nth login process; wherein the strings are separated by half-width commas;

[0067] The dynamic password APP encrypts the first string corresponding to the Nth login process in the TEE and then stores it;

[0068] The dynamic password APP outputs the fourth string t A , as a dynamic password .

[0069] Preferably, the second login information is verified using a second verification method, which specifically includes:

[0070] The power grid system converts each item of the user's personal information into a one-to-one binary number, and then uses a 256-bit hash function to , map the message into the message space, and get ;

[0071] The power grid system obtains the value c of the first power grid parameter stored in the verification of the N-1th login process. N-1 ;

[0072] The power grid system uses a 256-bit hash function to store the account ID. Map it into the message space and get the integer id;

[0073] ;

[0074] Power grid system calculation ;

[0075] ;

[0076] Will The last 24 digits are converted into the fifth string t B ;

[0077] Among them, the fifth string t B A 6-digit hexadecimal string;

[0078] The power grid system will B Converted into a binary number t2, the value of the first power grid parameter stored in the power grid system is updated to t2; that is, the value of the first power grid parameter obtained in the verification of the Nth login process;

[0079] Grid System Verification Fifth String t B Dynamic password entered by the user A comparison is performed. If they are the same, the verification is successful and the user logs in successfully this time.

[0080] Preferably, the second login information is verified by using a second verification method, further comprising:

[0081] If the fifth string t B Dynamic password entered by the user If they are inconsistent, the verification will fail and the power grid system will prompt the user that the input is wrong; if the 5 new dynamic passwords generated by the dynamic password APP entered by the user for 5 consecutive times fail to pass the verification, the power grid system will block the user account, making the user unable to log in.

[0082] Preferably,

[0083] When the user account is blocked in the power grid system, the power grid system obtains the user's account ID and initial login password entered by the administrator. , and use the first verification method or the second verification method for verification. If the verification is successful, the power grid system resets the user's login information to a non-logged-in state, and regenerates a new initialization login password based on the user's personal information using a pre-set generation strategy and returns it to the administrator, so that the administrator can secretly send the user's account ID and the newly generated initialization login password to the user to be unblocked;

[0084] If the power grid system fails to pass the verification, the failure verification information will be returned to the administrator.

[0085] The beneficial effects of the present invention are as follows: a dynamic password login authentication method for a power grid system of the present invention adopts a first verification method to verify the user's first login information, and displays a dynamic password parameter generation interface and a corresponding QR code after the verification is passed. The dynamic password APP calculates and parses the QR code in a trusted execution environment (TEE) to generate a first character string. Compared with the prior art, it can ensure the security of identity authentication during the user's first login process, avoid the problem of static passwords being easily stolen, and achieve the technical effect of improving the login security of the power grid system and the reliability of dynamic password generation.

[0086] A power grid system dynamic password login authentication method of the present invention adopts a second verification method to verify the second login information input by the user, and generates a dynamic password and updates the first string by using a dynamic password generation algorithm based on a first string generated by the pre-stored N-1th login through a dynamic password APP. Compared with the prior art, it can effectively prevent the dynamic password from being reused or attacked during multiple logins, enhances the uniqueness and real-time nature of the dynamic password, and achieves the technical effect of improving the login security of the power grid system and the dynamic nature of user identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0087] Figure 1 This is a flow chart of a method for dynamic password login authentication in a power grid system in Embodiment 1 of the present invention. DETAILED DESCRIPTION

[0088] In order to better explain the present invention and facilitate understanding, the present invention is described in detail below through specific implementation modes in conjunction with the accompanying drawings.

[0089] In order to better understand the above technical solution, exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided to enable a clearer and more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0090] It should be noted that the account number, login password and other verification data involved in this application have been obtained with full consent and authorization, and the collection, use and processing of relevant information must comply with relevant laws, regulations and standards of relevant countries and regions.

[0091] Embodiment 1

[0092] See also Figure 1 This embodiment provides a power grid system dynamic password login authentication method, including:

[0093] When the power grid system obtains the first login information input by the user, the first verification method is used to verify the first login information, and after the verification is passed, the power grid system displays a dynamic password parameter generation interface, and further displays a QR code corresponding to the dynamic password parameter on the dynamic password parameter generation interface, so that the dynamic password APP on the user's mobile terminal scans the QR code and calculates and parses it in the trusted execution environment TEE to obtain a first character string;

[0094] The dynamic password parameters are obtained based on the pre-acquired user personal information through a pre-set password initialization algorithm and a dynamic password information generation algorithm;

[0095] The first login information is the account ID and initial login password of the power grid system entered by the user when logging into the power grid system for the first time. .

[0096] In this embodiment, the trusted execution environment (TEE) of the dynamic password APP is used to process sensitive data to prevent man-in-the-middle attacks and tampering, thereby improving the security of user identity authentication. The dynamic password parameters are generated based on user personal information and an initialization algorithm to ensure that each user's parameters are unique and to prevent fixed passwords from being stolen or brute-forced. The combination of QR code generation and the dynamic password APP provides a smooth user experience, without the need to manually enter complex dynamic password parameters, and reduces the possibility of input errors. By generating the first character string, basic data is provided for the generation of dynamic passwords in subsequent logins, and chain updates of dynamic passwords are realized, thereby improving the security and efficiency of the login process. The dynamic password parameters are generated based on user information, are unique and cannot be forged, and greatly reduce the risk of impersonation attacks.

[0097] Specifically, when the power grid system obtains the second login information input by the user, the second verification method is used to verify the second login information, and after the verification is passed, the power grid system displays the main page after the successful login;

[0098] The second login information is the account ID and dynamic password of the power grid system entered by the user when logging into the power grid system for the Nth time. ; Where N ≥ 2;

[0099] The dynamic password The dynamic password APP on the user's mobile terminal is generated by using a dynamic password generation algorithm based on the first character string generated in the N-1th login process stored in advance;

[0100] The dynamic password APP on the user's mobile terminal generates the dynamic password using a dynamic password generation algorithm based on a pre-stored first character string. During the N-th login process, the first character string is updated to obtain the first character string corresponding to the N-th login process.

[0101] The dynamic password generation process is based on the first string generated by the last login, and the first string will be updated after each login to ensure that the dynamic password cannot be reused, effectively preventing replay attacks. The generation of dynamic passwords depends on dynamic data (such as the first string and the generation algorithm). Even if an attacker intercepts the dynamic password of a certain login, it cannot be used for the next login. The generation of dynamic passwords and the update of strings are completed in the trusted execution environment (TEE) of the mobile terminal, ensuring that sensitive data is not accessed by external programs and preventing malware attacks. Users do not need to remember complex dynamic password generation rules, but only need to use the dynamic password generated by the dynamic password APP, which is simple and fast. The dynamic password is generated based on the user's unique account information and dynamic string, which is unique and unforgeable, further reducing the possibility of impersonation login. This method is combined with the mobile terminal devices commonly used by users, which not only reduces the complexity of system implementation, but also improves the convenience of user operation.

[0102] The user's personal information in this embodiment includes multiple information items. For example, the user's personal information includes: name, ID number, date of birth, gender, contact information, work unit, marital status, nationality, etc.

[0103] The initial login password It is generated by the power grid system according to the pre-acquired user's personal information using a preset generation strategy, and sent to the user through the administrator, specifically including:

[0104] The power grid system converts each information item in the user's personal information into a corresponding binary number, and uses formula (1) to generate a first binary number r1;

[0105] The formula (1) is:

[0106] ;

[0107] in, It is the symbol of XOR operation;

[0108] M n The binary number converted from the nth information item in the user's personal information;

[0109] Hash() is a hash function that can generate 90-bit binary;

[0110] r0 is a second binary number; the second binary number r0 is a 90-bit binary array set by the power grid system, and after randomly filling each bit with 0 or 1, the binary array is converted into a binary number;

[0111] In this embodiment, the generation of the initial login password relies on the user's personal information (such as name, ID number, etc.) and a random binary number, making each user's password unique and unpredictable. XOR operations and hash functions are used to ensure that the information in the generation process is highly complex, preventing the password from being easily guessed or cracked.

[0112] Based on the first binary number r1 and the second binary number r0, a third binary number r2 is generated using formula (2);

[0113] The formula (2) is: ;

[0114] The power grid system converts the third binary number r2 into a second string and uses the second string as the initialization login password. ; The second character string is a character string with a length of 15;

[0115] In the process of converting the third binary number r2 into the second character string, the third binary number r2 is converted into one character from left to right of the second character string corresponding to every 6 bits from high to low.

[0116] In this embodiment, the final generated initialization login password is a string of 15 characters, including Arabic numerals, uppercase letters, lowercase letters and preset characters, which is moderately complex but controllable, easy for users to remember and input. When converted into the second string, every 6 binary digits correspond to one character, ensuring that the generated string has a fixed length and rules, which is convenient for users to operate.

[0117] Each character in the second character string is any one of 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters, and 2 preset characters (in this embodiment, the two preset characters are "@" and "!"). The initialization login password contains a variety of characters (numbers, uppercase and lowercase letters, special characters), meets common password strength requirements, and can effectively resist simple password cracking tools.

[0118] In the actual application of this embodiment, the dynamic password parameters are obtained through a preset password initialization algorithm and a dynamic password information generation algorithm, which specifically include:

[0119] The power grid system converts each item of the user's personal information into a one-to-one binary number, and then uses a 256-bit hash function to , map the message into the message space, and get ;

[0120] The message space is operable numbers in the range of [0, q); wherein q is a constant, which is a large 256-bit binary prime number set inside the power grid system; the selection of this large prime number ensures the randomness and unpredictability of the numerical value.

[0121] in, ; ;... ;

[0122] Using the generated , construct the first polynomial;

[0123] Wherein, the first polynomial is:

[0124] ;

[0125] mod is the symbol for the remainder operation;

[0126] Among them, x represents the independent variable in the polynomial, which is used to determine the output results of the polynomial f(x) under different inputs.

[0127] Get the password factor M0 entered by the user and pass it through a 256-bit hash function , converting the password factor M0 into the message space to obtain the first power grid parameter;

[0128] Wherein, the value of the first power grid parameter is a0; ;

[0129] The password factor M0 is a character string randomly selected by the user, ranging from 6 to 15 characters; each character in the password factor M0 is any one of the 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters and 2 preset characters;

[0130] The password factor M0 is randomly selected by the user and ranges from a 6-15-digit string containing Arabic numerals, uppercase and lowercase letters, and preset characters, which enhances user participation and security.

[0131] The power grid system constructs a second polynomial based on the first polynomial; the construction of this polynomial increases the security and complexity of the data.

[0132] Wherein, the second polynomial is:

[0133] ;

[0134] The coefficients of the second polynomial The third strings are converted into corresponding third strings one by one, and all the third strings are concatenated using a preset string concatenation function to obtain a dynamic password parameter; the third string is a hexadecimal string; the coefficients in the second polynomial are converted into corresponding hexadecimal strings, and all the strings are concatenated using a preset string concatenation function to form a final dynamic password parameter (s). This conversion method makes the final password parameter compact and easy to handle.

[0135] Among them, the dynamic password parameter is s; ;

[0136] Concat() is a string concatenation function;

[0137] The two-dimensional code corresponding to the dynamic password parameter is obtained by the power grid system by converting the dynamic password parameter using a two-dimensional code generation function. Finally, the dynamic password parameter is converted into a two-dimensional code using the two-dimensional code generation function so that the user can scan and use it. The form of the two-dimensional code is not only convenient for user operation, but also convenient for verification on mobile devices.

[0138] In this embodiment, the high security of the dynamic password parameters is ensured by multi-layer encryption means such as hash functions, polynomial construction, and string concatenation. Even if one link is cracked, other links can still provide effective protection. Using a 256-bit binary prime number as the modulus greatly increases the difficulty of calculation and prevents brute force cracking. The final dynamic password parameters are presented in the form of a QR code. Users only need to scan the QR code with a mobile phone or other device to complete the verification, which simplifies the operation process.

[0139] Specifically, the first login information is verified using a first verification method, which specifically includes:

[0140] The power grid system will enter the initial login password entered by the user The password is compared with the pre-stored initial login password of the user. If they are the same, the verification is passed and the user's first login is successful.

[0141] In this embodiment, only a simple string comparison is performed between the password input by the user and the pre-stored password. This method is easy to implement and does not require a complex encryption algorithm. The system will only pass the verification if the password input by the user is completely consistent with the password stored in the system, which effectively prevents illegal users from impersonating real users to log in to the system.

[0142] Specifically, verifying the first login information using a first verification method also includes:

[0143] If the user enters the initial login password If the initial login password is not consistent with the pre-stored initial login password of the user, the verification fails and the power grid system prompts the user to enter an error message; if the initial login password entered by the user is incorrect for 5 consecutive times If the verification fails, the power grid system will block the user's account, making it impossible for the user to log in.

[0144] For example, after receiving the initial login password entered by Mr. Li, the power grid system first checks whether the input matches the pre-stored password. Since the password entered by Mr. Li does not match the pre-stored password, it is considered that the verification failed. The power grid system issues a prompt to tell Mr. Li that the password he entered is incorrect and needs to re-enter. The error message displayed may be: "The initial login password entered is incorrect, please re-enter." Mr. Li tried four more times, and each time he entered the wrong password, he failed to pass the verification. On the fifth attempt, he still entered the wrong password. The power grid system recorded these five incorrect attempts and blocked the account according to regulations. The power grid system locked Mr. Li's account and prompted him to contact the administrator to unlock or reset the password. The administrator may need to verify Mr. Li's identity and manually reset the password to ensure login security.

[0145] In this embodiment, the number of times a user enters an incorrect password continuously is limited to prevent brute force attacks. Once an incorrect password is entered five times in a row, the system automatically blocks the account to reduce account security risks caused by guesswork or probing. Through the blocking mechanism, user accounts can be effectively protected from speculative attacks and brute force attempts, thereby improving the overall security of the system. If a user's multiple incorrect login attempts are not restricted, the system may be overloaded and the access experience of normal users may be affected. The blocking mechanism avoids system anomalies and performance issues caused by frequent incorrect login attempts.

[0146] The dynamic password APP on the user's mobile terminal generates the dynamic password using a dynamic password generation algorithm based on the first character string generated during the N-1th login process stored in advance. The process specifically includes:

[0147] The dynamic password APP on the user's mobile terminal uses the pre-set decomposition function UnConcat() in the trusted execution environment TEE to decompose the first string generated in the pre-stored N-1th login process into integers. , and b0 is used as the value of the first APP parameter;

[0148] The dynamic password APP on the user's mobile terminal uses a hash function in the trusted execution environment TEE. Map the account ID entered by the user to the message space to obtain the corresponding integer id;

[0149] in, ;

[0150] Based on the id, the dynamic password APP on the user's mobile terminal calculates in the trusted execution environment TEE ;

[0151] ;

[0152] The dynamic password APP on the user's mobile terminal intercepts the binary number in the trusted execution environment TEE. The last 24 digits of the string are converted into the fourth string t A ;

[0153] Among them, the fourth string t A A 6-digit hexadecimal string;

[0154] The dynamic password APP on the user's mobile terminal converts the fourth string t A Convert it into a binary number t1, and update the first APP parameter so that the value of the first APP parameter is equal to t1;

[0155] The dynamic password APP on the user's mobile terminal is in the trusted execution environment TEE, and the updated first APP parameter value t1 is consistent with the polynomial The coefficients in Convert them into hexadecimal strings respectively, and then use the string concatenation function Concat() to concatenate the converted strings to obtain the first string corresponding to the Nth login process; wherein the strings are separated by half-width commas;

[0156] The dynamic password APP encrypts the first string corresponding to the Nth login process in the TEE and then stores it;

[0157] The dynamic password APP outputs the fourth string t A , as a dynamic password .

[0158] In this embodiment, the first string generated during the previous login process is used as the basis to dynamically adjust the subsequent passwords to ensure that the password for each login is not repeated with the previous password, thereby enhancing the uniqueness of the password. By updating the numerical value of the first APP parameter and converting the binary number into a hexadecimal string, the password generation process is ensured to be real-time and unpredictable, preventing hackers from using historical data to crack passwords. The complex calculation process is decomposed into a disassembly function (UnConcat()) and a string concatenation (Concat()), making the password generation process more concise and clear, and reducing the complexity of implementation. The generated dynamic password is encrypted and stored to further protect the security of the password and prevent data leakage.

[0159] In this embodiment, the second verification method is adopted to verify the second login information, which specifically includes:

[0160] The power grid system converts each item of the user's personal information into a one-to-one binary number, and then uses a 256-bit hash function to , map the message into the message space, and get ;

[0161] The power grid system obtains the value c of the first power grid parameter stored in the verification of the N-1th login process. N-1 ;

[0162] The power grid system uses a 256-bit hash function to store the account ID. Map it into the message space and get the integer id;

[0163] ;

[0164] Power grid system calculation ;

[0165] ;

[0166] Will The last 24 digits are converted into the fifth string t B ;

[0167] Among them, the fifth string t B A 6-digit hexadecimal string;

[0168] The power grid system will B Converted into a binary number t2, the value of the first power grid parameter stored in the power grid system is updated to t2; that is, the value of the first power grid parameter obtained in the verification of the Nth login process;

[0169] Grid System Verification Fifth String t B Dynamic password entered by the user A comparison is performed. If they are the same, the verification is successful and the user logs in successfully this time.

[0170] Preferably, the second login information is verified by using a second verification method, further comprising:

[0171] If the fifth string t B Dynamic password entered by the user If they are inconsistent, the verification will fail and the power grid system will prompt the user that the input is wrong; if the 5 new dynamic passwords generated by the dynamic password APP entered by the user for 5 consecutive times fail to pass the verification, the power grid system will block the user account, making the user unable to log in.

[0172] When the user account is blocked in the power grid system, the power grid system obtains the user's account ID and initial login password entered by the administrator. , and use the first verification method or the second verification method for verification. If the verification is successful, the power grid system resets the user's login information to a non-logged-in state, and regenerates a new initialization login password based on the user's personal information using a pre-set generation strategy and returns it to the administrator, so that the administrator can secretly send the user's account ID and the newly generated initialization login password to the user to be unblocked;

[0173] If the power grid system fails to pass the verification, the failure verification information will be returned to the administrator.

[0174] Embodiment 2

[0175] This embodiment aims to reduce the risk of key leakage caused by long-term fixed passwords and solve the user memory burden caused by long and complex login passwords, thereby improving the overall security of the power grid system and user convenience. In addition, this embodiment also solves the problem of not being able to generate dynamic passwords through mobile phone text messages in an intranet environment.

[0176] This embodiment provides a power grid system dynamic password login authentication algorithm method, which not only provides a dynamic password generation and verification algorithm, but also provides other supporting function algorithms for the corresponding power grid system dynamic password login authentication on this basis. The methods involved are as follows:

[0177] User registration algorithm: The administrator enters user information into the power grid system in batches, and secretly sends the account number and initial login password returned by the power grid system to the user.

[0178] User unblocking algorithm: The administrator applies for account unblocking for the user through the power grid system and issues the account ID and a new initial login password to the user.

[0179] User login algorithm: The power grid system handles the first login of a user and the normal login of a user (that is, the Nth login, N≥2) accordingly.

[0180] Password initialization algorithm: The power grid system performs a mandatory password update operation on users who log in to the system for the first time, and first performs an initialization algorithm.

[0181] Dynamic password parameter generation algorithm: The power grid system calculates and returns the relevant parameters for generating dynamic passwords for mobile APPs, which are used to generate new dynamic login passwords.

[0182] Dynamic password verification algorithm: The power grid system verifies the passwords entered by the user during the first login and normal login, and returns the login status.

[0183] Dynamic password APP initialization algorithm: The dynamic password APP provides a dynamic password APP initialization function for users who log in to the power grid system for the first time.

[0184] Dynamic password generation algorithm: The dynamic password APP generates and returns a new dynamic password of appropriate length for users who log in to the power grid system normally.

[0185] Based on the power grid system dynamic password login authentication algorithm method provided in this embodiment, it is possible to establish a one-way connection between the power grid system and the dynamic password APP only by scanning the code during the initialization phase, and then the two operate independently without any interaction process. This effectively avoids the risk of eavesdropping that may be suffered when generating dynamic passwords through communication interaction. If the user enters an incorrect password during the normal login process, the power grid system will dynamically change the password required for the next login, thereby reducing the risk of illegal users invading the system by guessing the password. Neither the power grid system nor the dynamic password APP stores any login passwords. The login password is generated in real time through a specific calculation formula, thereby preventing hackers from stealing login passwords by directly accessing hard disk data, thereby enhancing the security of the system.

[0186] The power grid system dynamic password of this embodiment is divided into two parts, namely the power grid system and the dynamic password APP. The password login in the power grid system is operated by two roles: administrator and user. Among them, the administrator performs user registration and the user performs password login.

[0187] The dynamic password APP is dynamically operated by the user role, and its function is to protect the security of the user password and generate a password for the user to log in to the power grid system. The power grid dynamic password login algorithm of this embodiment can be divided into three aspects according to the two parts of the power grid system and the dynamic password APP and the two roles of the administrator and the user, namely, the administrator's operation of the power grid system, the user's operation of the power grid system, and the user's operation of the dynamic password APP.

[0188] In this embodiment, the algorithms for the administrator to operate the power grid system are mainly user registration algorithm and user unblocking algorithm, and the steps are as follows:

[0189] User registration algorithm:

[0190] The administrator collects the personal information of the prospective users of the power grid system, including personal name, ID number, date of birth, gender, etc. Then, the administrator enters the user information into the power grid system in batches. After that, the power grid system returns the personal account ID and initial login password of the user who successfully entered the system to the administrator. Finally, the administrator will enter the account ID and initial login password. Sent confidentially to individual users.

[0191] The account ID here is the work number set by the power grid system according to the user's entry order.

[0192] Here, The character string is randomly selected for the power grid system. The specific steps are as follows:

[0193] The power grid system sets a 90-bit binary array and randomly fills each bit with 0 or 1, and then converts the array into a binary number r0.

[0194] The power grid system converts users' personal information into binary numbers , and then use the hash function Hash() that can generate 90-bit binary to calculate and generate a new binary number r1, ;

[0195] in, M is the symbol for the XOR operation; n The binary number converted from the nth information item in the user's personal information;

[0196] The grid system calculates the new binary number r2, ;

[0197] The power grid system converts the binary number r2 into a string of length 15, which is the initial login password. .

[0198] The conversion process is as follows: 2地从 Every 6 bits from high to low correspond to a string Each character has 64 possibilities, corresponding to 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters and 2 pre-set characters.

[0199] User login algorithm

[0200] It is divided into two situations: the user's first login and the user's normal login.

[0201] When a user logs in for the first time, the user enters the account ID and initial login password received from the administrator. After that, after the password is verified by the power grid system, the power grid system triggers the password initialization algorithm and the dynamic password information generation algorithm.

[0202] If the verification fails, the power grid system triggers the counting function. If the dynamic password information entered fails to pass the verification for 5 consecutive times, the user account lock function is triggered. After the user account lock function is triggered, the user cannot log in, and the administrator needs to perform the unblocking algorithm operation on the power grid system.

[0203] When the user logs in normally, the user enters the account ID and the dynamic password provided by the dynamic password APP After that, after the password is verified by the power grid system, the power grid system returns the login information;

[0204] If the verification fails, the power grid system triggers the counting function. At the same time, the dynamic password for login has changed. You need to re-enter it and open the dynamic password APP to generate a new dynamic password. In addition, if the dynamic password information entered for five consecutive times fails to pass verification, the user account lock function is triggered. After the user account lock function is triggered, the user cannot log in, and the administrator needs to perform an unblocking algorithm operation on the power grid system.

[0205] Password initialization algorithm:

[0206] When a user logs into the system for the first time, the power grid system forces the user to update the password and first perform an initialization algorithm.

[0207] The power grid system converts users' personal information into binary numbers , and then through a 256-bit hash function , map the message into the message space, and get .

[0208] ;

[0209] ; ...

[0210] ;

[0211] The power grid system uses the generated , construct the first polynomial. The first polynomial is: ;

[0212] q is a constant, a large 256-bit binary prime number set inside the power grid system.

[0213] Dynamic password parameter generation algorithm:

[0214] After the user enters the password factor M0, the power grid system calculates and returns the relevant parameters for generating a dynamic password for the mobile phone APP, which is used to generate a new dynamic login password.

[0215] The specific steps are as follows:

[0216] The user enters a password factor M0. The password factor here is a string of 6-15 characters randomly selected by the user. Each character can be any one of the 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters, and 2 preset characters.

[0217] Power grid system using hash functions The password factor is converted into the message space to obtain the first power grid parameter. The value of the first power grid parameter is a0, .

[0218] The power grid system stores the first power grid parameter at this time.

[0219] The power grid system constructs the second polynomial, which is:

[0220] ;

[0221] The power grid system converts the coefficients of the binary polynomial Convert them into hexadecimal strings respectively, and then use the string concatenation function Concat() to concatenate these strings to get the dynamic password parameters that need to be returned. Among them, half-width commas are used to separate the strings.

[0222] Among them, the dynamic password parameter is s; ;

[0223] The power grid system uses a QR code generation function to convert the dynamic password parameter s into a QR code and displays it on the screen so that the user can scan the code using the dynamic password APP to enter the dynamic password parameter s.

[0224] Dynamic password verification algorithm:

[0225] The power grid system verifies the password entered by the user and returns the login status.

[0226] The dynamic password verification algorithm is divided into two cases: the user's first login and normal login.

[0227] First time user logs in:

[0228] The power grid system obtains the user's initial login password from the database Compare it with the password entered by the user. If they match, the user's first login is successful and the process jumps to the initialization algorithm.

[0229] If they are inconsistent, the user is prompted that the input is wrong and the counting function is triggered. If the dynamic password information entered for 5 consecutive times fails to pass the verification, the user account lock function is triggered. After the user account lock function is triggered, the user cannot log in and the administrator needs to perform the unblocking algorithm operation on the power grid system.

[0230] User logs in normally:

[0231] The power grid system converts the pre-stored user's personal information into binary numbers and then uses a 256-bit hash function to , map the message into the message space, and get .

[0232] The power grid system obtains first power grid parameters stored in a database.

[0233] The power grid system uses a 256-bit hash function to store user IDs. Map it to the message space and get the id. ;

[0234] Power grid system calculation ,

[0235] ;

[0236] Power grid system intercepts binary numbers The last 24 digits of the string are converted into a 6-digit hexadecimal string t B , t B This is the login password at this time.

[0237] The power grid system will B After conversion into binary t2, the value of the first grid parameter stored in the grid system is updated to t2.

[0238] The power grid system verifies the string at this time and the dynamic password entered by the user t If they are inconsistent, the user is prompted with an input error and the counting function is triggered. At the same time, the dynamic password used for login has changed. You need to re-enter it and open the dynamic password APP to generate a new dynamic password. t In addition, if the dynamic password information entered for five consecutive times fails to pass verification, the user account lock function is triggered. After the user account lock function is triggered, the user cannot log in, and the administrator needs to perform an unblocking algorithm operation on the power grid system.

[0239] The algorithms for the user's operation of the dynamic password APP in this embodiment are mainly the dynamic password APP initialization algorithm and the dynamic password generation algorithm. The steps of each algorithm are as follows:

[0240] Dynamic password APP initialization algorithm: For users who log in to the power grid system for the first time, a dynamic password APP initialization function is provided.

[0241] The user enters the account ID and the initial login password , and then the dynamic password APP uses the mobile phone's TEE (Trusted Execution Environment) to encrypt and save it.

[0242] The dynamic password APP calls the camera function of the mobile phone, scans the dynamic password parameter QR code generated by the power grid system, and calculates and resolves it into the first string in TEE.

[0243] The dynamic password APP encrypts the first character string in TEE and stores it securely.

[0244] Dynamic password generation algorithm: For users who log in to the power grid system normally, a new dynamic password p is generated and returned t .

[0245] The dynamic password APP obtains the stored encrypted first character string, and decrypts it in the TEE to obtain the first character string.

[0246] The dynamic password APP uses the disassembly function UnConcat() in TEE to split the first string into .

[0247] The dynamic password APP obtains the stored encrypted account ID, decrypts it in TEE, and uses the hash function Map it to the message space and get the id. ;

[0248] Based on the id, the dynamic password APP on the user's mobile terminal calculates in the trusted execution environment TEE ; ;

[0249] Dynamic password APP intercepts binary numbers in TEE The last 24 digits of the string are converted into a 6-digit hexadecimal string t A .

[0250] The dynamic password APP on the user's mobile terminal converts the fourth string t A Convert it into a binary number t1, and update the first APP parameter so that the value of the first APP parameter is equal to t1.

[0251] The dynamic password APP on the user's mobile terminal is in the trusted execution environment TEE, and the updated first APP parameter value t1 is consistent with the polynomial The coefficients in Convert them into hexadecimal strings respectively, and then use the string concatenation function Concat() to concatenate the converted strings to obtain the first string corresponding to the Nth login process; wherein the strings are separated by half-width commas;

[0252] The dynamic password APP encrypts the first string corresponding to the Nth login process in the TEE and then stores it;

[0253] The dynamic password APP outputs the fourth string t A , as a dynamic password p t .

[0254] In the description of the present invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0255] In the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", "connected", "fixed" and the like should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be the internal connection of two elements or the interaction relationship between two elements. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0256] In the present invention, unless otherwise clearly specified and limited, when a first feature is “on” or “below” a second feature, it may be that the first and second features are in direct contact, or that the first and second features are in indirect contact through an intermediate medium. Moreover, when a first feature is “above”, “above” or “above” a second feature, it may be that the first feature is directly above or obliquely above the second feature, or it may simply mean that the first feature is higher in level than the second feature. When a first feature is “below”, “below” or “below” a second feature, it may be that the first feature is directly below or obliquely below the second feature, or it may simply mean that the first feature is lower in level than the second feature.

[0257] In the description of this specification, the description of the terms "one embodiment", "some embodiments", "embodiment", "example", "specific example" or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are contradictory.

[0258] Although the embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and are not to be construed as limitations of the present invention. A person skilled in the art may alter, modify, replace and modify the above embodiments within the scope of the present invention.

Claims

1. A power grid system dynamic password login authentication method, characterized in that: include: When the power grid system obtains the first login information input by the user, the first verification method is used to verify the first login information, and after the verification is passed, the power grid system displays a dynamic password parameter generation interface, and further displays a QR code corresponding to the dynamic password parameter on the dynamic password parameter generation interface, so that the dynamic password APP on the user's mobile terminal scans the QR code and calculates and parses it in the trusted execution environment TEE to obtain a first character string; The dynamic password parameters are obtained based on the pre-acquired user personal information through a pre-set password initialization algorithm and a dynamic password information generation algorithm; The first login information is the account ID and initial login password of the power grid system entered by the user when logging into the power grid system for the first time. ; When the power grid system obtains the second login information input by the user, the second verification method is used to verify the second login information, and after the verification is passed, the power grid system displays the main page after the successful login; The second login information is the account ID and dynamic password of the power grid system entered by the user when logging into the power grid system for the Nth time. ; Where N ≥ 2; The dynamic password The dynamic password APP on the user's mobile terminal is generated by using a dynamic password generation algorithm based on the first character string generated in the N-1th login process stored in advance; The dynamic password APP on the user's mobile terminal generates the dynamic password using a dynamic password generation algorithm based on a pre-stored first character string. In the process of, updating the first character string to obtain the first character string corresponding to the Nth login process; The initial login password It is generated by the power grid system according to the pre-acquired user's personal information using a preset generation strategy, and sent to the user through the administrator, specifically including: The power grid system converts each information item in the user's personal information into a corresponding binary number, and uses formula (1) to generate a first binary number r1; The formula (1) is: ; in, It is the symbol of XOR operation; M n The binary number converted from the nth information item in the user's personal information; Hash() is a hash function that can generate 90-bit binary; r0 is a second binary number; the second binary number r0 is a 90-bit binary array set by the power grid system, and after randomly filling each bit with 0 or 1, the binary array is converted into a binary number; Based on the first binary number r1 and the second binary number r0, a third binary number r2 is generated using formula (2); The formula (2) is: ; The power grid system converts the third binary number r2 into a second string and uses the second string as the initialization login password. ; The second character string is a character string with a length of 15; In the process of converting the third binary number r2 into the second character string, the third binary number r2 is converted into one character from left to right of the second character string corresponding to every 6 bits from high to low. Each character in the second character string is any one of 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters and 2 preset characters; The dynamic password parameters are obtained through a preset password initialization algorithm and a dynamic password information generation algorithm, specifically including: The power grid system converts each item of the user's personal information into a one-to-one binary number, and then uses a 256-bit hash function to , map the message into the message space, and get ; The message space is a operable number in the range of [0, q); wherein q is a constant, which is a large 256-bit binary prime number set inside the power grid system; in, ; ;... ; Using the generated , construct the first polynomial; Wherein, the first polynomial is: ; mod is the symbol for the remainder operation; Get the password factor M0 entered by the user and pass it through a 256-bit hash function , converting the password factor M0 into the message space to obtain the first power grid parameter; Wherein, the value of the first power grid parameter is a0; ; The password factor M0 is a string of 6 to 15 characters randomly selected by the user; each character in the password factor M0 is any one of the 10 Arabic numerals, 26 uppercase letters, 26 lowercase letters and 2 preset characters; The power grid system constructs a second polynomial based on the first polynomial; Wherein, the second polynomial is: ; The coefficients of the second polynomial Convert each of the three strings into a corresponding third string one by one, and use a preset string concatenation function to concatenate all the third strings to obtain a dynamic password parameter; the third string is a hexadecimal string; Among them, the dynamic password parameter is s; ; Concat() is a string concatenation function; The two-dimensional code corresponding to the dynamic password parameter is obtained by converting the dynamic password parameter by the power grid system using a two-dimensional code generation function.

2. The power grid system dynamic password login authentication method according to claim 1, characterized in that: The first login information is verified using a first verification method, specifically including: The power grid system will enter the initial login password entered by the user The password is compared with the pre-stored initial login password of the user. If they are the same, the verification is passed and the user's first login is successful.

3. The power grid system dynamic password login authentication method according to claim 2, characterized in that: Verifying the first login information using a first verification method also includes: If the user enters the initial login password If the initial login password is not consistent with the pre-stored initial login password of the user, the verification fails and the power grid system prompts the user to enter an error message; if the initial login password entered by the user is incorrect for 5 consecutive times If the verification fails, the power grid system will block the user's account, making it impossible for the user to log in.

4. The power grid system dynamic password login authentication method according to claim 3, It is characterized in that in, The dynamic password APP on the user's mobile terminal generates the dynamic password using a dynamic password generation algorithm based on the first character string generated during the N-1th login process stored in advance. The process specifically includes: The dynamic password APP on the user's mobile terminal uses the pre-set decomposition function UnConcat() in the trusted execution environment TEE to decompose the first string generated in the pre-stored N-1th login process into integers. , and b0 is used as the value of the first APP parameter; The dynamic password APP on the user's mobile terminal uses a hash function in the trusted execution environment TEE. Map the account ID entered by the user to the message space to obtain the corresponding integer id; in, ; Based on the id, the dynamic password APP on the user's mobile terminal calculates in the trusted execution environment TEE ; ; The dynamic password APP on the user's mobile terminal intercepts the binary number in the trusted execution environment TEE. The last 24 digits of the string are converted into the fourth string t A ; Among them, the fourth string t A A 6-digit hexadecimal string; The dynamic password APP on the user's mobile terminal converts the fourth string t A Convert it into a binary number t1, and update the first APP parameter so that the value of the first APP parameter is equal to t1; The dynamic password APP on the user's mobile terminal is in the trusted execution environment TEE, and the updated first APP parameter value t1 is consistent with the polynomial The coefficients in Convert them into hexadecimal strings respectively, and then use the string concatenation function Concat() to concatenate the converted strings to obtain the first string corresponding to the Nth login process; wherein the strings are separated by half-width commas; The dynamic password APP encrypts the first string corresponding to the Nth login process in the TEE and then stores it; The dynamic password APP outputs the fourth string t A , as a dynamic password .

5. The power grid system dynamic password login authentication method according to claim 3, characterized in that: The second login information is verified using a second verification method, specifically including: The power grid system converts each item of the user's personal information into a one-to-one binary number, and then uses a 256-bit hash function to , map the message into the message space, and get ; The power grid system obtains the value c of the first power grid parameter stored in the verification of the N-1th login process. N-1 ; The power grid system uses a 256-bit hash function to store the account ID. Map it into the message space and get the integer id; ; Power grid system calculation ; ; Will The last 24 digits are converted into the fifth string t B ; Among them, the fifth string t B A 6-digit hexadecimal string; The power grid system will B Converting into a binary number t2, updating the value of the first power grid parameter stored in the power grid system to t2; Grid System Verification Fifth String t B Dynamic password entered by the user A comparison is performed. If they are the same, the verification is successful and the user logs in successfully this time.

6. The power grid system dynamic password login authentication method according to claim 5, characterized in that: Using a second verification method to verify the second login information also includes: If the fifth string t B Dynamic password entered by the user If they are inconsistent, the verification will fail and the power grid system will prompt the user that the input is wrong; if the 5 new dynamic passwords generated by the dynamic password APP entered by the user for 5 consecutive times fail to pass the verification, the power grid system will block the user account, making the user unable to log in.

7. The power grid system dynamic password login authentication method according to claim 6, characterized in that: When the user account is blocked in the power grid system, the power grid system obtains the user's account ID and initial login password entered by the administrator. , and use the first verification method or the second verification method for verification. If the verification is successful, the power grid system resets the user's login information to a non-logged-in state, and regenerates a new initialization login password based on the user's personal information using a pre-set generation strategy and returns it to the administrator, so that the administrator can secretly send the user's account ID and the newly generated initialization login password to the user to be unblocked; If the power grid system fails to pass the verification, the failure verification information will be returned to the administrator.

Citation Information

Patent Citations

  • Method and system for identity authentication based on dynamic password

    CN101582763A

  • Online banking transaction method

    CN105809441A