Password setting and verification method, system, equipment and program product

By introducing authorization token verification mechanism and encryption operations into the password encryption component, the problems of lack of authorization verification, insufficient transmission data security and weak database storage protection in the prior art are solved, and higher password setting and verification security and data storage security are achieved.

CN119945797APending Publication Date: 2025-05-06CTRIP FINANCIAL TECH (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510239647.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing password encryption components lack authorization verification mechanisms, insufficient security of transmission data, and weak database storage protection, resulting in an increased risk of user sensitive information leakage.

Method used

By issuing authorization tokens to the client, an authorization verification mechanism is added to the client, and during the password setting and verification process, only the hash value of the plain text password is received for encryption operation and transmission, ensuring the security of data transmission. At the same time, the password information stored in the database is the calculation value obtained by the plain text password after multiple operations to prevent the plain text password from being leaked.

Benefits of technology

Improve the security of password settings and verification, prevent data from being stolen during transmission, enhance the security of password storage, and reduce the risk of user sensitive information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945797A_ABST
    Figure CN119945797A_ABST
Patent Text Reader

Abstract

The invention provides a password setting and verification method, system, device and program product, and the password setting method comprises the steps: responding to a request of a client, and sending an authorization token; in response to the received token and a first hash value of the plaintext password, when the token is an authorized token and is valid, splicing the first hash value with the token to obtain a spliced value, and encrypting the spliced value to obtain a first encrypted value; in response to the received first encryption value, decrypting the first encryption value to obtain a first hash value and a token, and when the token is an authorized token and is valid, encrypting the first hash value to obtain a second encryption value; and in response to the received second encryption value, decrypting to obtain the first hash value, and calculating the first hash value to obtain a second calculation value and sending the second calculation value to the database. According to the invention, the authorization verification security, the password transmission security and the database storage security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the rapid popularization of information technology and Internet applications, user identity authentication and data security have become the focus of attention in all walks of life, especially in the fields of mobile payment and e-commerce. User passwords are the key credentials to ensure account security, and their security is directly related to user privacy and property safety. However, in recent years, criminals have gradually broken through the protection of traditional encryption schemes by using various attack methods such as interception, decryption, and replay, resulting in the leakage of a large amount of user sensitive information. The existing password encryption components have the following main deficiencies:

[0003] First, there is a lack of authorization verification mechanism. Existing password encryption components only perform a single hash or simple encryption on the passwords entered by users, and lack an effective component authorization token verification mechanism. This allows attackers to maliciously exploit the encrypted data by replaying or other reuse attack methods after intercepting the encrypted data, thus rendering the encryption measures ineffective.

[0004] Second, the security of transmitted data is insufficient. In the process of data transmission, the existing password encryption components fail to realize the binding process between data and authorization tokens, resulting in that even if encryption measures are adopted during the data transmission process, it is difficult to prevent the data from being intercepted and replayed or applied to other scenarios, thereby increasing the risk of information leakage.

[0005] Third, the database storage protection is weak. Existing password encryption components often only perform a single encryption process on the password data stored in the database. Once the database is attacked by illegal database dragging, the obtained data often still has a certain possibility of being cracked, making it difficult to completely protect the security of the user's plain text password information. Summary of the invention

[0006] In view of this, the present disclosure provides a password setting and verification method, system, device and program product to at least solve the problems of existing password encryption components lacking an authorization verification mechanism, insufficient transmission data security and weak database storage protection.

[0007] In one aspect, an embodiment of the present disclosure provides a method for setting a password, comprising:

[0008] In response to the client's token acquisition request, send the authorization token to the client;

[0009] In response to receiving the first hash value of the token and the plaintext password from the client, when the token is an authorization token and is valid, concatenating the first hash value with the token to obtain a concatenated value, encrypting the concatenated value to obtain a first encrypted value, and sending the first encrypted value;

[0010] In response to receiving the first encrypted value, decrypting the first encrypted value to obtain a concatenated value, deconcatenating the concatenated value to obtain a first Hash value and a token, and when the token is an authorization token and is valid, encrypting the first Hash value to obtain a second encrypted value, and sending the second encrypted value;

[0011] In response to receiving the second encrypted value, the first encrypted value is decrypted to obtain a first hash value, the first hash value is operated to obtain a second operation value, and the second operation value is sent to the database as the password information of the client.

[0012] On the other hand, an embodiment of the present disclosure further provides a password setting system, comprising:

[0013] The cryptographic component authorization service module sends an authorization token to the client in response to the client's token acquisition request;

[0014] The password component initialization service module, in response to receiving the first hash value of the token and the plain text password from the client, when the token is an authorization token and is valid, concatenates the first hash value with the token to obtain a concatenated value, encrypts the concatenated value to obtain a first encrypted value, and sends the first encrypted value;

[0015] The password pre-service module, in response to receiving the first encrypted value, decrypts the first encrypted value to obtain a spliced ​​value, de-splices the spliced ​​value to obtain a first hash value and a token, and when the token is an authorization token and is valid, encrypts the first hash value to obtain a second encrypted value, and sends the second encrypted value;

[0016] The cryptographic core service module, in response to receiving the second encrypted value, decrypts the first encrypted value to obtain the first hash value, operates the first hash value to obtain the second operation value, and sends the second operation value as the password information of the client to the database.

[0017] On the other hand, an embodiment of the present disclosure further provides a computer program product, including computer-readable instructions, which, when executed by a processor, implement the above-mentioned password setting method.

[0018] The password setting method, system, device and program product disclosed in the present invention increase the authorization verification mechanism for the client by issuing an authorization token to the client, thereby improving the security of password setting; by only receiving the first hash value of the plaintext password and encrypting the first hash value before transmitting, the security of data transmission during the password setting process is improved, and the plaintext password is prevented from being stolen during the transmission process; by storing the password information in the database as the second operation value obtained by multiple operations of the plaintext password, the plaintext password is prevented from being leaked, thereby improving the security of password storage.

[0019] On the other hand, an embodiment of the present disclosure further provides a password verification method, comprising:

[0020] In response to the client's token acquisition request, send the authorization token to the client;

[0021] In response to receiving the first hash value of the token and the plaintext password from the client, when the token is an authorization token and is valid, concatenating the first hash value with the token to obtain a concatenated value, encrypting the concatenated value to obtain a first encrypted value, and sending the first encrypted value;

[0022] In response to receiving the first encrypted value, decrypting the first encrypted value to obtain a concatenated value, deconcatenating the concatenated value to obtain a first Hash value and a token, and when the token is an authorization token and is valid, encrypting the first Hash value to obtain a second encrypted value, and sending the second encrypted value;

[0023] In response to receiving the second encrypted value, the first encrypted value is decrypted to obtain the first hash value, the first hash value is operated to obtain the second operation value, the second operation value is compared and verified with the password information corresponding to the client in the database, and the verification result is sent.

[0024] In some embodiments, the password verification method further includes:

[0025] When the second operation value is compared and verified with the password information, the verification times of the token are increased. In response to receiving a verification result request from the client and the verification times of the token is less than a preset value, the received verification result is returned to the client.

[0026] In some embodiments, the password verification method further includes:

[0027] When receiving the token acquisition request from the client, the first business information from the client is also received at the same time;

[0028] When receiving the verification result request from the client, the second service information from the client is also received simultaneously;

[0029] In response to receiving a verification result request from the client, the number of verifications of the token being less than a preset value, and the first service information and the second service information being the same, the received verification result is returned to the client.

[0030] In some embodiments, a token is determined to be a valid token when the token has not expired and has not been verified.

[0031] In another aspect, an embodiment of the present disclosure further provides a password verification system, comprising:

[0032] The cryptographic component authorization service module sends an authorization token to the client in response to the client's token acquisition request;

[0033] The password component initialization service module, in response to receiving the first hash value of the token and the plain text password from the client, when the token is an authorization token and is valid, concatenates the first hash value with the token to obtain a concatenated value, encrypts the concatenated value to obtain a first encrypted value, and sends the first encrypted value;

[0034] The password pre-service module, in response to receiving the first encrypted value, decrypts the first encrypted value to obtain a spliced ​​value, de-splices the spliced ​​value to obtain a first hash value and a token, and when the token is an authorization token and is valid, encrypts the first hash value to obtain a second encrypted value, and sends the second encrypted value;

[0035] The cryptographic core service module, in response to receiving the second encrypted value, decrypts the first encrypted value to obtain the first hash value, operates the first hash value to obtain the second operation value, compares and verifies the second operation value with the password information corresponding to the client in the database, and sends the verification result.

[0036] In another aspect, an embodiment of the present disclosure further provides a password verification device, comprising:

[0037] processor;

[0038] a memory storing computer-readable instructions;

[0039] The processor is configured to execute the password verification method by executing computer-readable instructions.

[0040] On the other hand, an embodiment of the present disclosure further provides a computer program product, including computer-readable instructions, which, when executed by a processor, implement the above-mentioned password verification method.

[0041] The password verification method, system, device and program product disclosed in the present invention increase the authorization verification mechanism for the client by issuing an authorization token to the client, thereby improving the password verification security; by only receiving the first hash value of the plaintext password and encrypting the first hash value before transmitting, the security of the transmitted data during the password verification process is improved, and the plaintext password is prevented from being stolen during the transmission process; the password information used for comparison is a hash operation value obtained by a series of operations on the plaintext password, thereby preventing the plaintext password from being leaked and improving the security of password storage; by transmitting the first hash value and the token at the same time and verifying the validity of the token, the token is avoided from being reused, the timeliness of the password verification is improved, and it is ensured that the password cannot be repeatedly verified. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0043] Figure 1 is a flowchart of a method for setting a password provided by an embodiment of the present disclosure;

[0044] Figure 2 It is a module structure diagram of a password setting system provided by an embodiment of the present disclosure;

[0045] Figure 3 It is a flowchart of the steps of a password verification method provided by an embodiment of the present disclosure;

[0046] Figure 4 It is a module structure diagram of a password verification system provided by an embodiment of the present disclosure;

[0047] Figure 5 It is a structural diagram of a password verification device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0048] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that the disclosure will be comprehensive and complete and the concepts of the example embodiments will be fully conveyed to those skilled in the art. The same reference numerals in the figures represent the same or similar structures, and thus their repeated description will be omitted.

[0049] The words "first", "second" and similar words used in the specific description do not indicate any order, quantity or importance, but are only used to distinguish different components. In addition, in the description of the present disclosure, the orientation or position relationship indicated by the terms "upper" and "lower" are based on the orientation or position relationship shown in the drawings, which are only for the convenience of description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation, and therefore cannot be understood as a limitation of the present disclosure.

[0050] It should be noted that, in the absence of conflict, the embodiments of the present disclosure and the features in different embodiments may be combined with each other.

[0051] like Figure 1 As shown, in one aspect, an embodiment of the present disclosure provides a method for setting a password, comprising:

[0052] S110, in response to the token acquisition request of the client, sending the authorization token to the client;

[0053] S120, in response to receiving the first hash value of the token and the plaintext password from the client, when the token is an authorization token and is valid, concatenate the first hash value with the token to obtain a concatenated value, encrypt the concatenated value to obtain a first encrypted value, and send the first encrypted value;

[0054] S130, in response to receiving the first encrypted value, decrypting the first encrypted value to obtain a concatenated value, deconcatenating the concatenated value to obtain a first Hash value and a token, and when the token is an authorization token and is valid, encrypting the first Hash value to obtain a second encrypted value, and sending the second encrypted value;

[0055] S140. In response to receiving the second encrypted value, decrypt the first encrypted value to obtain a first hash value, calculate the first hash value to obtain a second calculated value, and send the second calculated value as the password information of the client to the database.

[0056] It is worth noting that the above S110 to S140 are merely step numbers, which are used to facilitate reference and avoid text duplication. Unless otherwise specified, the above and subsequent step numbers will not limit the order of implementation of the various steps of the method. In other embodiments, the above steps of the method can also be written and implemented in an interchangeable order, and are not limited thereto.

[0057] For the above step S110, specifically, the client can request to obtain the authorization token in a server-to-server manner. This embodiment ensures the legitimacy of the requesting client by performing signature verification on the requesting client. This embodiment increases the authorization verification mechanism for the client by issuing an authorization token to the client, thereby improving the security of the password setting process.

[0058] For the above step S120, specifically, after receiving the plain text password input by the client, when the token is an authorization token and is valid, a mask display method is used to avoid leakage of the plain text password. When the token is not an authorization token or the token has expired, the password setting process of the client is rejected. The hash algorithm that obtains the first hash value from the plain text password may include MD4, MD5 or SHA-1, etc., but is not limited to this. The encryption algorithm that obtains the first encrypted value from the splicing value may include an asymmetric encryption algorithm such as RSA and DSA, or a symmetric encryption algorithm such as DES, 3DES and AES, but is not limited to this. This embodiment improves the security of data transmission during the password setting process by transmitting the plain text password after performing hash operations and encryption operations, and avoids the plain text password being stolen during the transmission process.

[0059] For the above step S130, specifically, after receiving the first encrypted value, a decryption algorithm corresponding to the encryption algorithm is used to decrypt to obtain a first hash value and a token. When the token is an authorization token and is valid, the client's password setting process continues. At this time, the decrypted first hash value is still an encrypted value, not a plaintext password from the client. The program cannot obtain the client's plaintext password, and the association between the first hash value of the plaintext password and the token is guaranteed to prevent requests for playback or application to other scenarios. When the token is not an authorization token or the token has expired, the client's password setting process is rejected. In addition, the encryption algorithm for obtaining the second encrypted value from the first hash value may include asymmetric encryption algorithms such as RSA and DSA, or symmetric encryption algorithms such as DES, 3DES and AES, but is not limited thereto.

[0060] For the above step S140, specifically, after receiving the second encrypted value, the decryption algorithm corresponding to the encryption algorithm is used to decrypt the first hash value, and then the first hash value is processed according to the random salt algorithm and other algorithms to obtain the second operation value, and sent to the database for storage. In this embodiment, the password information stored in the database is the second operation value after multiple operations of the plain text password, so even in the extreme case of being hacked, the plain text password can still be prevented from being leaked, thereby improving the security of password storage.

[0061] In some embodiments, when the token is not expired and has not been verified, the token is judged to be a valid token. Specifically, when the authorization token is sent to the client, an expiration date is set for the authorization token, and the number of verifications of the authorization token is counted. When the authorization token exceeds the expiration date, it is expired. When the authorization token is verified, the number of verifications increases accordingly. If the number of verifications exceeds, the authorization token becomes invalid. Through the above settings, this embodiment ensures the timeliness of the password setting process and the non-reusability of the authorization token.

[0062] The password setting method disclosed in the present invention increases the security of password setting by issuing an authorization token to the client and adding an authorization verification mechanism to the client; improves the security of data transmission during password setting by only receiving the first hash value of the plaintext password and performing encryption operation on the first hash value before transmission, thereby preventing the plaintext password from being stolen during the transmission process; and prevents the plaintext password from being leaked and improves the security of password storage by storing the password information in the database as the second operation value obtained by multiple operations on the plaintext password.

[0063] like Figure 2 As shown, on the other hand, an embodiment of the present disclosure further provides a password setting system, including:

[0064] The cryptographic component authorization service module sends an authorization token to the client in response to the client's token acquisition request;

[0065] The password component initialization service module, in response to receiving the first hash value of the token and the plain text password from the client, when the token is an authorization token and is valid, concatenates the first hash value with the token to obtain a concatenated value, encrypts the concatenated value to obtain a first encrypted value, and sends the first encrypted value;

[0066] The password pre-service module, in response to receiving the first encrypted value, decrypts the first encrypted value to obtain a spliced ​​value, de-splices the spliced ​​value to obtain a first hash value and a token, and when the token is an authorization token and is valid, encrypts the first hash value to obtain a second encrypted value, and sends the second encrypted value;

[0067] The cryptographic core service module, in response to receiving the second encrypted value, decrypts the first encrypted value to obtain the first hash value, operates the first hash value to obtain the second operation value, and sends the second operation value as the password information of the client to the database.

[0068] The specific technical solutions and technical effects of the password setting system disclosed in the present invention can be referred to the aforementioned password setting method embodiments, which will not be described in detail here.

[0069] In another aspect, an embodiment of the present disclosure further provides a computer program product, the computer program product comprising computer-readable instructions, the computer-readable instructions being stored in a computer-readable storage medium. A processor of a computing device can read the computer-readable instructions from the computer-readable storage medium, and the processor executes the computer-readable instructions, so that the computing device executes the password setting method described in the above-mentioned various embodiments.

[0070] The computer-readable storage medium includes computer-readable instructions that can be written in any combination of one or more programming languages. Programming languages ​​include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, as an independent software package, partially on the user computing device and partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).

[0071] The specific technical solutions and technical effects of the computer program product disclosed herein can be referred to the aforementioned password setting method embodiment, which will not be described in detail here.

[0072] like Figure 3 As shown, on the other hand, an embodiment of the present disclosure also provides a password verification method, including:

[0073] S210, in response to the token acquisition request of the client, sending the authorization token to the client;

[0074] S220, in response to receiving the first hash value of the token and the plaintext password from the client, when the token is an authorization token and is valid, concatenate the first hash value with the token to obtain a concatenated value, encrypt the concatenated value to obtain a first encrypted value, and send the first encrypted value;

[0075] S230, in response to receiving the first encrypted value, decrypting the first encrypted value to obtain a concatenated value, deconcatenating the concatenated value to obtain a first Hash value and a token, and when the token is an authorization token and is valid, encrypting the first Hash value to obtain a second encrypted value, and sending the second encrypted value;

[0076] S240. In response to receiving the second encrypted value, decrypt the first encrypted value to obtain a first hash value, perform an operation on the first hash value to obtain a second operation value, compare and verify the second operation value with the password information corresponding to the client in the database, and send the verification result.

[0077] For the above step S210, specifically, the client can request to obtain the authorization token in a server-to-server manner. This embodiment ensures the legitimacy of the requesting client by performing signature verification on the requesting client. This embodiment increases the authorization verification mechanism for the client by issuing an authorization token to the client, thereby improving the security of the password verification process.

[0078] For the above step S220, specifically, the operation from the plaintext password to the first hash value is completed by the user's client, that is, the client adopts a mask display method to avoid the leakage of the plaintext password. The hash algorithm for obtaining the first hash value from the plaintext password may include MD4, MD5 or SHA-1, etc., but is not limited to this. The password verification system disclosed in the present invention only receives the first hash value sent by the client. When the token is not an authorization token or the token has expired, the password verification process of the client is rejected. The encryption algorithm that obtains the first encrypted value from the splicing value may include asymmetric encryption algorithms such as RSA and DSA, or symmetric encryption algorithms such as DES, 3DES and AES, but is not limited to this. This embodiment improves the security of transmitted data during the password verification process by only receiving the first hash value of the plaintext password and performing encryption operation on the first hash value before transmission, thereby avoiding the plaintext password being stolen during the transmission process.

[0079] For the above step S230, specifically, after receiving the first encrypted value, a decryption algorithm corresponding to the encryption algorithm is used to decrypt to obtain a first hash value and a token. When the token is an authorization token and is valid, the password verification process of the client continues. At this time, the decrypted first hash value is still an encrypted value, not a plaintext password from the client. The program cannot obtain the plaintext password of the client, and the association between the first hash value of the plaintext password and the token is guaranteed to prevent requests for playback or application to other scenarios. When the token is not an authorization token or the token has expired, the password verification process of the client is rejected. In addition, the encryption algorithm for obtaining the second encrypted value from the first hash value may include asymmetric encryption algorithms such as RSA and DSA, or symmetric encryption algorithms such as DES, 3DES and AES, but is not limited thereto.

[0080] For the above step S240, specifically, after receiving the second encrypted value, the decryption algorithm corresponding to the encryption algorithm is used to decrypt the first hash value, and then a series of operations are performed on the first hash value according to the random salt algorithm and other operations to obtain the second operation value, and the second operation value is compared and verified with the password information corresponding to the client in the database. Among them, the password information stored in the database is the operation value obtained after a series of operations of the plaintext password obtained in advance from the client through the above password setting method. In this embodiment, the password information stored in the database is the operation value obtained by multiple operations of the plaintext password. Even in the extreme case of being hacked, the database can still prevent the leakage of the plaintext password and improve the security of password storage.

[0081] In some embodiments, the password verification method further includes: when the second operation value is compared and verified with the password information, the number of verification times of the token is increased, and in response to receiving a verification result request from the client and the number of verification times of the token is less than a preset value, the received verification result is returned to the client. Specifically, after completing the password verification process, the client needs to request the verification result again through the previously issued token. At this time, increasing the number of verification times of the token can be used to verify whether the token is verified and the number of verification times. When the token is verified, the token is invalidated, thereby ensuring the timeliness of the password verification process and non-repeatable verification.

[0082] In some embodiments, the password verification method also includes: when receiving a token acquisition request from a client, also simultaneously receiving first business information from the client; when receiving a verification result request from the client, also simultaneously receiving second business information from the client; in response to receiving a verification result request from the client, the number of token verifications is less than a preset value, and the first business information and the second business information are the same, returning the received verification result to the client. Specifically, when receiving a token acquisition request and a verification result request, business information from the client, such as a payment serial number, etc., can also be received at the same time, that is, the token acquisition request interface and the verification result request interface can receive business information at the same time. After the password verification is successful, the risk of tampering with the token can be prevented by comparing the first business information and the second business information for consistency, thereby further improving the security of the password verification process.

[0083] In some embodiments, when the token is not expired and has not been verified, the token is judged to be a valid token. Specifically, when the authorization token is sent to the client, an expiration date is set for the authorization token, and the number of verifications of the authorization token is counted. When the authorization token exceeds the expiration date, it is expired. When the authorization token is verified, the number of verifications increases accordingly. If the authorization token has been verified, it becomes invalid. Through the above-mentioned settings, this embodiment ensures the timeliness of the password verification process and the non-reusability of the authorization token.

[0084] The password verification method disclosed in the present invention increases the authorization verification mechanism for the client by issuing an authorization token to the client, thereby improving the verification security of the password; improves the security of data transmission during the password verification process by only receiving the first hash value of the plaintext password and transmitting it after encrypting the first hash value, thereby preventing the plaintext password from being stolen during the transmission process; prevents the plaintext password from being leaked and improves the security of password storage by using the calculated values ​​obtained by multiple calculations of the plaintext password as the password information used for comparison; avoids the reuse of the token by transmitting the first hash value and the token at the same time and verifying the validity of the token, thereby improving the timeliness of password verification and ensuring that the password cannot be verified repeatedly.

[0085] like Figure 4 As shown, on the other hand, an embodiment of the present disclosure further provides a password verification system, comprising:

[0086] The cryptographic component authorization service module sends an authorization token to the client in response to the client's token acquisition request;

[0087] The password component initialization service module, in response to receiving the first hash value of the token and the plain text password from the client, when the token is an authorization token and is valid, concatenates the first hash value with the token to obtain a concatenated value, encrypts the concatenated value to obtain a first encrypted value, and sends the first encrypted value;

[0088] The password pre-service module, in response to receiving the first encrypted value, decrypts the first encrypted value to obtain a spliced ​​value, de-splices the spliced ​​value to obtain a first hash value and a token, and when the token is an authorization token and is valid, encrypts the first hash value to obtain a second encrypted value, and sends the second encrypted value;

[0089] The cryptographic core service module, in response to receiving the second encrypted value, decrypts the first encrypted value to obtain the first hash value, operates the first hash value to obtain the second operation value, compares and verifies the second operation value with the password information corresponding to the client in the database, and sends the verification result.

[0090] The specific technical solutions and technical effects of the password verification system disclosed in the present invention can be referred to the aforementioned password verification method embodiment, which will not be repeated here.

[0091] like Figure 5 As shown, in another aspect, an embodiment of the present disclosure further provides a password verification device, comprising: a processor; a memory storing computer-readable instructions, wherein the processor is configured to execute a password verification method by executing the computer-readable instructions.

[0092] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which may be collectively referred to herein as "circuits", "modules" or "platforms".

[0093] Refer to the following Figure 5 The electronic device 600 according to this embodiment of the present disclosure is described. Figure 5 The electronic device 600 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0094] like Figure 5 As shown, the electronic device 600 is in the form of a general computing device. The components of the electronic device 600 may include, but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different platform components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.

[0095] The storage unit 620 stores computer-readable instructions, which can be executed by the processing unit 610, so that the processing unit 610 performs the steps described in the above method section of this specification according to various exemplary embodiments of the present disclosure. For example, the processing unit 610 can perform the following steps: Figure 3 Follow the steps shown in .

[0096] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202 , and may further include a read-only storage unit (ROM) 6203 .

[0097] The storage unit 620 may also include a program / utility 6204 having a set (at least one) of program modules 6205, such program modules 6205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0098] Bus 630 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0099] The electronic device 600 may also communicate with one or more external devices 700 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 600, and / or communicate with any device that enables the electronic device 600 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 650. Furthermore, the electronic device 600 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 660. The network adapter 660 may communicate with other modules of the electronic device 600 via a bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage platforms, etc.

[0100] The specific technical solutions and technical effects of the password verification device disclosed in the present invention can be referred to the aforementioned password verification method embodiment, which will not be repeated here.

[0101] In another aspect, an embodiment of the present disclosure further provides a computer program product, which includes computer-readable instructions, which are stored in a computer-readable storage medium. A processor of a computing device can read the computer-readable instructions from the computer-readable storage medium, and the processor executes the computer-readable instructions, so that the computing device executes the password verification method described in the above embodiments.

[0102] The computer-readable storage medium includes computer-readable instructions that can be written in any combination of one or more programming languages. Programming languages ​​include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, as an independent software package, partially on the user computing device and partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).

[0103] The specific technical solutions and technical effects of the computer program product disclosed in the present invention can be referred to the aforementioned password verification method embodiment, which will not be repeated here.

[0104] The above contents are further detailed descriptions of the present disclosure in combination with specific optional implementation methods, and it cannot be determined that the specific implementation of the present disclosure is limited to these descriptions. For ordinary technicians in the technical field to which the present disclosure belongs, several simple deductions or substitutions can be made without departing from the concept of the present disclosure, which should be regarded as falling within the scope of protection of the present disclosure.

Claims

1. A method for setting a password, characterized in that: include: In response to a token acquisition request from a client, sending an authorization token to the client; In response to receiving the first hash value of the token and the plaintext password of the client, when the token is the authorization token and is valid, concatenating the first hash value with the token to obtain a concatenated value, encrypting the concatenated value to obtain a first encrypted value, and sending the first encrypted value; In response to receiving the first encrypted value, decrypting the first encrypted value to obtain the concatenated value, deconcatenating the concatenated value to obtain the first Hash value and the token, and when the token is the authorization token and is valid, encrypting the first Hash value to obtain a second encrypted value, and sending the second encrypted value; In response to receiving the second encrypted value, the first encrypted value is decrypted to obtain the first Hash value, the first Hash value is operated to obtain a second operation value, and the second operation value is sent to the database as the password information of the client.

2. A password setting system, characterized in that: include: The cryptographic component authorization service module sends an authorization token to the client in response to a token acquisition request from the client; The password component initialization service module, in response to receiving the first hash value of the token and the plain text password of the client, when the token is the authorization token and is valid, concatenates the first hash value with the token to obtain a concatenated value, encrypts the concatenated value to obtain a first encrypted value, and sends the first encrypted value; The password pre-service module, in response to receiving the first encrypted value, decrypts the first encrypted value to obtain the spliced ​​value, deconcatenates the spliced ​​value to obtain the first Hash value and the token, and when the token is the authorization token and is valid, encrypts the first Hash value to obtain a second encrypted value, and sends the second encrypted value; The cryptographic core service module, in response to receiving the second encrypted value, decrypts the first encrypted value to obtain the first hash value, operates the first hash value to obtain a second operation value, and sends the second operation value as the password information of the client to the database.

3. A computer program product comprising computer readable instructions, characterized in that: When the computer readable instructions are executed by a processor, the method according to claim 1 is implemented.

4. A password verification method, characterized in that: include: In response to a token acquisition request from a client, sending an authorization token to the client; In response to receiving the first hash value of the token and the plaintext password of the client, when the token is the authorization token and is valid, concatenating the first hash value with the token to obtain a concatenated value, encrypting the concatenated value to obtain a first encrypted value, and sending the first encrypted value; In response to receiving the first encrypted value, decrypting the first encrypted value to obtain the concatenated value, deconcatenating the concatenated value to obtain the first Hash value and the token, and when the token is the authorization token and is valid, encrypting the first Hash value to obtain a second encrypted value, and sending the second encrypted value; In response to receiving the second encrypted value, the first encrypted value is decrypted to obtain the first hash value, the first hash value is operated to obtain a second operation value, the second operation value is compared and verified with the password information corresponding to the client in the database, and the verification result is sent.

5. The password verification method according to claim 4, characterized in that: Also includes: When the second operation value is compared and verified with the password information, the verification times of the token are increased. In response to receiving a verification result request from the client and the verification times of the token being less than a preset value, the received verification result is returned to the client.

6. The password verification method according to claim 5, characterized in that: Also includes: When receiving the token acquisition request from the client, also receiving first business information from the client; When receiving the verification result request from the client, also receiving second service information from the client; In response to receiving a verification result request from the client, the number of verifications of the token being less than a preset value, and the first service information and the second service information being the same, the received verification result is returned to the client.

7. The password verification method according to claim 4, characterized in that: When the token is not expired and has not been verified, the token is determined to be a valid token.

8. A password verification system, characterized in that: include: The cryptographic component authorization service module sends an authorization token to the client in response to a token acquisition request from the client; The password component initialization service module, in response to receiving the first hash value of the token and the plain text password of the client, when the token is the authorization token and is valid, concatenates the first hash value with the token to obtain a concatenated value, encrypts the concatenated value to obtain a first encrypted value, and sends the first encrypted value; The password pre-service module, in response to receiving the first encrypted value, decrypts the first encrypted value to obtain the spliced ​​value, deconcatenates the spliced ​​value to obtain the first Hash value and the token, and when the token is the authorization token and is valid, encrypts the first Hash value to obtain a second encrypted value, and sends the second encrypted value; The cryptographic core service module, in response to receiving the second encrypted value, decrypts the first encrypted value to obtain the first hash value, operates the first hash value to obtain a second operation value, compares and verifies the second operation value with the password information corresponding to the client in the database, and sends the verification result.

9. A password verification device, characterized in that: include: processor; a memory storing computer-readable instructions; The processor is configured to perform the method according to any one of claims 4 to 7 by executing the computer readable instructions.

10. A computer program product comprising computer readable instructions, characterized in that: When the computer-readable instructions are executed by a processor, the method according to any one of claims 4 to 7 is implemented.