A password changing method and system based on reliable verification
Through a password change method based on reliable verification, the MPC protocol layer is used to segment and block password information, and combined with cloud storage and two-factor verification, the security issues of password transmission and update are solved, and the reliability and security of password management are achieved.
Patent Information
- Application Number
- CN202411822495.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2044-12-11
AI Technical Summary
In the prior art, the distribution and transmission of passwords are at risk of being invaded and theft by hackers, and frequent password updates lead to complex management.
Password change method based on reliable verification is adopted, password information is divided and blocked through the MPC protocol layer and allocated to different password users. Each user generates secondary password information, ultimately ensuring that no one has complete password information, and security is enhanced through cloud storage and two-factor verification.
During the information transmission process, it ensures that no one has complete password information, which improves the security and management reliability of the password change process and reduces the risk of leakage.
Smart Images

Figure CN119519993B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of passwords, and in particular to a password changing method based on reliable verification and a password changing system based on reliable verification. Background Art
[0002] When protecting trade secrets or technical secrets, existing technologies usually require certain permissions to access in order to protect technical secrets or trade secrets. In this case, a certain password needs to be entered before access can be performed.
[0003] However, in most cases, passwords cannot remain unchanged and need to be updated over time. The distribution and transmission of passwords themselves also carry the risk of being hacked and stolen. Summary of the Invention
[0004] The object of the present invention is to provide a password changing method based on reliable verification to at least solve one of the above technical problems.
[0005] One aspect of the present invention provides a password change method based on reliable authentication, the password change method based on reliable authentication comprising:
[0006] The password generator generates new password information;
[0007] The password generator performs segmentation processing based on the new password information, thereby forming the same number of segmented password information as that of the password demander;
[0008] The password generator sends each split password information to the MPC protocol layer;
[0009] The MPC protocol layer distributes the split password information so that each password user is assigned a split password information;
[0010] Each password user generates secondary password information for the split password information obtained by itself through the MPC protocol layer, thereby obtaining the final split password information.
[0011] Optionally, the password generator performs segmentation processing based on the new password information, thereby forming segmented password information having the same number as that of the password requesters, including:
[0012] A masking operation is performed on the password information, so that the formed segmented password information only includes part of the password information and the masking scheme of each segmented password information is stored.
[0013] Optionally, the MPC protocol layer distributes the split password information so that each password user is assigned a split password information including:
[0014] The MPC protocol layer generates a distribution list based on each acquired split password information, wherein the distribution list includes each split password information and the password user corresponding to each split password information;
[0015] The MPC protocol layer sends corresponding split password information to each password user according to the distribution list.
[0016] Optionally, each password user generates secondary password information for the split password information obtained by itself through the MPC protocol layer, thereby obtaining final split password information, including:
[0017] Generate secondary password information through its own historical password information;
[0018] The secondary password information is used to replace the blocked portion in the obtained segmented password information, thereby generating the final segmented password information.
[0019] Optionally, the password changing method based on reliable verification further includes:
[0020] The password generator sends the occlusion solution and new password information to the cloud storage.
[0021] Optionally, the password changing method based on reliable verification further includes:
[0022] The MPC protocol layer sends the allocation list to the cloud storage.
[0023] Optionally, the password changing method based on reliable verification further includes:
[0024] Each of the password users sends the final password information to the cloud storage.
[0025] Optionally, the password changing method based on reliable verification further includes:
[0026] The password user obtains the first password information entered by the user;
[0027] The password user determines whether the first password information is correct based on the final password information he holds. If so,
[0028] The password user generates a second password input prompt;
[0029] The password user obtains the second password information input by the user according to the second password input prompt;
[0030] The password user transmits the second password information to the cloud;
[0031] The cloud determines whether the second password information is correct based on the allocation list, the shielding plan and the new password information. If so, it determines that the user authentication is successful.
[0032] The present application also provides a password change system based on reliable verification, which includes a password generator, an MPC protocol layer, and a password user. The password generator, the MPC protocol layer, and the password user cooperate to implement the password change method based on reliable verification as described above.
[0033] Beneficial effects:
[0034] The password change method based on reliable verification of the present application masks the password information and distributes it to different password users, and the password users then encrypt the password once locally using the secondary password information, so that each password user does not obtain the original new password information, and in the entire information transmission process, no party has the complete new password information. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is a flowchart of a password changing method based on reliable verification according to an embodiment of the present application;
[0036] Figure 2 Schematic diagram of an electronic device for implementing a password changing method based on reliable verification according to an embodiment of the present application. DETAILED DESCRIPTION
[0037] In order to make the purpose, technical solutions and advantages of the implementation of this application clearer, the technical solutions in the embodiments of this application will be described in more detail below in conjunction with the drawings in the embodiments of this application. In the drawings, the same or similar reference numerals throughout represent the same or similar elements or elements with the same or similar functions. The described embodiments are part of the embodiments of this application, not all of the embodiments. The embodiments described below with reference to the drawings are exemplary and are intended to be used to explain this application, and should not be understood as limitations on this application. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. The embodiments of this application are described in detail below in conjunction with the drawings.
[0038] Figure 1 This is a flowchart of a password changing method based on reliable verification according to an embodiment of the present application.
[0039] like Figure 1 The password change methods shown based on strong authentication include:
[0040] Step 1: The password generator generates new password information;
[0041] Step 2: The password generator performs segmentation processing based on the new password information, thereby forming the same number of segmented password information as that of the password demander;
[0042] Step 3: The password generator sends each split password information to the MPC protocol layer;
[0043] Step 4: The MPC protocol layer distributes the split password information so that each password user is assigned a split password information;
[0044] Step 5: Each password user generates secondary password information for the split password information obtained by itself through the MPC protocol layer, thereby obtaining the final split password information.
[0045] The password change method based on reliable verification of the present application masks the password information and distributes it to different password users, and the password users then encrypt the password once locally using the secondary password information, so that each password user does not obtain the original new password information, and in the entire information transmission process, no party has the complete new password information.
[0046] In this embodiment, the password generator performs segmentation processing based on the new password information, thereby forming the same number of segmented password information as the number of password requesters, including:
[0047] A masking operation is performed on the password information, so that the formed segmented password information only includes part of the password information and the masking scheme of each segmented password information is stored.
[0048] For example, assuming the password information is a string of numbers, such as 123456, then each time the blocking operation is performed, the other numbers in the number can be randomly changed. For example, one split password information can be 12QW56, and another split password information can be WE3456, etc.
[0049] In this embodiment, each shielding scheme needs to be recorded to prevent the user from not knowing how the shielding is performed.
[0050] In this embodiment, the MPC protocol layer distributes the split password information so that each password user is assigned a split password information including:
[0051] The MPC protocol layer generates a distribution list based on each acquired split password information, wherein the distribution list includes each split password information and the password user corresponding to each split password information;
[0052] The MPC protocol layer sends corresponding split password information to each password user according to the distribution list.
[0053] In this embodiment, the allocation list records the password users corresponding to the split password information. For example, 12QW56 is allocated to password user 1, and WE3456 is allocated to password user 2.
[0054] In this embodiment, each password user generates secondary password information for the split password information obtained by itself through the MPC protocol layer, thereby obtaining the final split password information, including:
[0055] Generate secondary password information through its own historical password information;
[0056] The secondary password information is used to replace the blocked portion in the obtained segmented password information, thereby generating the final segmented password information.
[0057] In this embodiment, a time range is set, for example, within one year. Through the historical password information, some secondary password information used within one year can be known. In this case, when generating new secondary password information, these secondary password information will not be used. For example, if the historical password information includes 123, 123 will not be used when generating new secondary password information. In addition, the generated secondary password information does not need to be the same as the masked part in terms of digits. It can be more than or the same as the masked part, or it can be less than the masked part. For example, if the secondary password information is 12345, then after replacing the masked part, the password becomes 121234556. If the secondary password information is 1, one solution for replacing the masked part is 121W56, and another solution is 12Q156. It can be set arbitrarily through the pre-set rules of the secondary password information.
[0058] In this embodiment, the password change method based on reliable verification further includes:
[0059] The password generator sends the occlusion solution and new password information to the cloud storage.
[0060] In this embodiment, the password change method based on reliable verification further includes:
[0061] The MPC protocol layer sends the allocation list to the cloud storage.
[0062] In this embodiment, the password change method based on reliable verification further includes:
[0063] Each of the password users sends the final password information to the cloud storage.
[0064] This approach ensures that neither party has the complete password information. On the other hand, by transmitting the password to the cloud through different transmission channels, it also ensures that the complete password information will not be leaked due to being intercepted during the transmission process to the cloud.
[0065] In this embodiment, the password change method based on reliable verification further includes:
[0066] The password user obtains the first password information entered by the user;
[0067] The password user determines whether the first password information is correct based on the final password information he holds. If so,
[0068] The password user generates a second password input prompt;
[0069] The password user obtains the second password information input by the user according to the second password input prompt;
[0070] The password user transmits the second password information to the cloud;
[0071] The cloud determines whether the second password information is correct based on the allocation list, the shielding plan and the new password information. If so, it determines that the user authentication is successful.
[0072] In this way, the user's security can be further ensured by verifying the password twice. In addition, the first password of this application only needs to be the same as the final password information of the password user, and the second password needs to be the same as the new password information generated by the password generator.
[0073] The present application also provides a password change system based on reliable verification, which includes a password generator, an MPC protocol layer, and a password user. The password generator, MPC protocol layer, and password user cooperate to implement the password change method based on reliable verification as described above.
[0074] It should be noted that the aforementioned explanation of the method embodiment is also applicable to the system of this embodiment and will not be repeated here.
[0075] The present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the computer program, the above-mentioned password changing method based on reliable verification is implemented.
[0076] The present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it can implement the above-mentioned password changing method based on reliable verification.
[0077] Figure 2 This is an exemplary structural diagram of an electronic device that can implement the password changing method based on reliable verification provided according to an embodiment of the present application.
[0078] like Figure 2 As shown, the electronic device includes an input device 501, an input interface 502, a central processing unit 503, a memory 504, an output interface 505, and an output device 506. The input interface 502, the central processing unit 503, the memory 504, and the output interface 505 are interconnected via a bus 507. The input device 501 and the output device 506 are connected to the bus 507 via the input interface 502 and the output interface 505, respectively, and are then connected to other components of the electronic device. Specifically, the input device 501 receives input information from the outside and transmits the input information to the central processing unit 503 via the input interface 502; the central processing unit 503 processes the input information based on the computer-executable instructions stored in the memory 504 to generate output information, temporarily or permanently stores the output information in the memory 504, and then transmits the output information to the output device 506 via the output interface 505; the output device 506 outputs the output information to the outside of the electronic device for use by the user.
[0079] That is to say, Figure 2 The electronic device shown may also be implemented as comprising: a memory storing computer executable instructions; and one or more processors, which can implement the combination of the computer executable instructions when executing the computer executable instructions. Figure 1 Describes a password change method based on reliable authentication.
[0080] In one embodiment, Figure 2 The electronic device shown may be implemented to include: a memory 504 configured to store executable program code; and one or more processors configured to run the executable program code stored in the memory 504 to execute the password changing method based on reliable authentication in the above embodiment.
[0081] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0082] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0083] Computer-readable media include permanent and non-permanent, removable and non-removable media, and media can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), data versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0084] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and a part of the module, program segment or code includes one or more executable instructions for realizing the prescribed logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes identified in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or overall flow chart can be implemented using a dedicated hardware-based system that performs the prescribed function or operation, or can be implemented using a combination of dedicated hardware and computer instructions.
[0085] The processor referred to in this embodiment may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0086] The memory can be used to store computer programs and / or modules. The processor implements various functions of the system / terminal device by running or executing the computer programs and / or modules stored in the memory and accessing the data stored in the memory. The memory may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application required for a function (such as sound playback or image playback); the data storage area may store data generated based on the use of the mobile phone (such as audio data and a phone book). Furthermore, the memory may include high-speed random access memory (RAM) and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0087] In this embodiment, if the modules / units integrated into the system / terminal device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the process steps in the above-mentioned method embodiments by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. Computer-readable media can include: any entity or system capable of carrying computer program code, recording media, USB flash drives, removable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunications signals, and software distribution media. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased based on the requirements of legislation and patent practice within a jurisdiction. Although the present application is disclosed as above with reference to preferred embodiments, it is not intended to limit the present application. Any person skilled in the art may make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims of the present application.
[0088] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0089] In addition, it is obvious that the word "comprising" does not exclude other units or steps. The multiple units, modules or systems stated in the system claims can also be implemented by one unit or the overall system through software or hardware.
[0090] Although the present invention has been described in detail above using general descriptions and specific embodiments, it will be apparent to those skilled in the art that modifications and improvements may be made based on the present invention. Therefore, such modifications and improvements, which do not depart from the spirit of the present invention, are intended to be within the scope of protection claimed herein.
Claims
1. A password changing method based on reliable verification, characterized in that: The password changing method based on reliable verification includes: The password generator generates new password information; The password generator performs segmentation processing based on the new password information, thereby forming the same number of segmented password information as that of the password demander; The password generator sends each split password information to the MPC protocol layer; The MPC protocol layer distributes the split password information so that each password user is assigned a split password information; The password generator performs segmentation processing based on the new password information, thereby forming the same number of segmented password information as that of the password requester, including: Performing a masking operation on the password information so that the formed segmented password information only includes part of the password information and storing a masking scheme for each segmented password information; The MPC protocol layer distributes the split password information so that each password user is assigned a split password information including: The MPC protocol layer generates a distribution list based on each acquired split password information, wherein the distribution list includes each split password information and the password user corresponding to each split password information; The MPC protocol layer sends corresponding split password information to each password user according to the distribution list; Each password user generates secondary password information for the split password information obtained by itself through the MPC protocol layer, thereby obtaining the final split password information, including: Generate secondary password information through its own historical password information; Replacing the blocked portion of the acquired segmented password information with the secondary password information, thereby generating the final segmented password information; The password changing method based on reliable verification further includes: The password generator sends the occlusion plan and new password information to the cloud storage; The password changing method based on reliable verification further includes: The MPC protocol layer sends the allocation list to the cloud storage; The password changing method based on reliable verification further includes: Each of the password users sends the final password information to the cloud storage; The password changing method based on reliable verification further includes: The password user obtains the first password information entered by the user; The password user determines whether the first password information is correct based on the final password information he holds. If so, The password user generates a second password input prompt; The password user obtains the second password information input by the user according to the second password input prompt; The password user transmits the second password information to the cloud; The cloud determines whether the second password information is correct based on the allocation list, the shielding plan and the new password information. If so, it determines that the user authentication is successful.
2. A password changing system based on reliable authentication, characterized in that: The password change system based on reliable verification includes a password generator, an MPC protocol layer and a password user, and the password generator, MPC protocol layer and password user cooperate to implement the password change method based on reliable verification as claimed in claim 1.
Citation Information
Patent Citations
Password verification method and device, electronic equipment and storage medium
CN111371563A
Information storage device and authentication method and system of information storage device
CN117879900A