Dynamic password generation method and device, equipment and medium
By generating a unique password for the device and dynamically updating it, the problem of weak security protection capabilities of existing video phone devices is solved, and the uniqueness and security of passwords between devices are realized.
Patent Information
- Application Number
- CN202411972828.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-16
AI Technical Summary
The security protection capabilities of existing video phone devices are weak, and the same password can unlock multiple devices, resulting in safety hazards.
Generate a unique password through the device body number and generation date, and determine the verification code based on the current date and generation date, dynamically generate dynamic passwords, and store them in association with the preset valid time, and update periodically.
It significantly enhances the security protection capabilities of the information system, prevents multiple devices from being detached with the same password, and ensures the security and effectiveness of the password.
Smart Images

Figure CN120017253A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security, and in particular to a method, device, equipment and medium for generating a dynamic password. Background Art
[0002] The campus environment needs to restrict students from bringing their personal mobile phones, but the need for students to keep in touch with their parents still exists. The introduction of video phones not only solves the need for students to communicate with their families, but also can avoid the negative effects of students' over-reliance on mobile phones to a certain extent, such as distracting their attention from studying and affecting their eyesight. However, the video phones on the market need to be used with preset applications, have poor association with third-party applications, and have a poor user experience. Summary of the invention
[0003] The present invention provides a dynamic password generation method, which eliminates the possibility that the same password can unlock multiple devices and solves the problem of weak security protection capability of the device.
[0004] In a first aspect, the present invention provides a method for generating a dynamic password, the method comprising:
[0005] Generate a unique password based on the device serial number and generation date;
[0006] Determine the verification code based on the current date and the generation date;
[0007] Generate a dynamic password according to the verification code and the unique dynamic password;
[0008] The dynamic password is associated with a preset validity period and stored; wherein, at each interval of the validity period, a new current date is obtained, and the steps of determining a verification code based on the current date and the generated date, and generating a dynamic password based on the verification code and the unique dynamic password are respectively performed, and the new dynamic password is associated with the validity period and stored.
[0009] In a second aspect, the present invention provides a dynamic password generating device, comprising:
[0010] A first generating unit, used to generate a unique password according to the device body serial number and generation date;
[0011] A second generating unit, used to determine a verification code according to a current date and the generating date;
[0012] A third generating unit, configured to generate a dynamic password according to the verification code and the unique dynamic password;
[0013] An association unit is used to associate and store the dynamic password with a preset effective time; wherein, at each interval of the effective time, a new current date is obtained, and the steps of determining a verification code based on the current date and the generated date, and generating a dynamic password based on the verification code and the unique dynamic password are respectively performed, and the new dynamic password is associated and stored with the effective time.
[0014] In a third aspect, an electronic device is provided, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;
[0015] Memory, used to store computer programs;
[0016] The processor is used to implement the steps of the dynamic password generation method described in any one of the embodiments of the first aspect when executing the program stored in the memory.
[0017] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the dynamic password generation method as described in any embodiment of the first aspect are implemented.
[0018] The above technical solution provided by the embodiment of the present invention has the following advantages compared with the prior art:
[0019] The method generates a unique identifier through device information and timestamp, and generates a dynamic password for the unique identifier. The dynamic password generation has a regular update effect, which significantly enhances the security protection capability of the information system. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0021] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0022] Figure 1 A schematic diagram of a flow chart of a method for generating a dynamic password provided by an embodiment of the present invention;
[0023] Figure 2 A schematic diagram of the structure of a dynamic password generating device provided by an embodiment of the present invention;
[0024] Figure 3A schematic diagram of the structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0025] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0026] Example 1
[0027] Figure 1 The present invention provides a flow chart of a method for generating a dynamic password. The present invention provides a method for generating a dynamic password. Figure 1 , the dynamic password generation method includes the following steps S101-S104.
[0028] S101, generating a unique password according to the device body serial number and generation date.
[0029] In specific implementation, the unique password is a unique password for each device, which ensures the uniqueness of the unlocking password for each device and prevents the phenomenon of using the same password to unlock multiple devices.
[0030] In one embodiment, the above step S101 includes: obtaining the device body serial number and generation date, and concatenating the two into a string; wherein the generation date is obtained by converting the timestamp; using the SHA-256 hash algorithm to perform a hash operation on the concatenated string to obtain a 256-bit hash value as a unique identifier; performing an XOR operation on the generated unique identifier based on a pre-set key to obtain a unique password.
[0031] In the specific implementation, the device's body serial number and the current system timestamp are obtained, and the two are concatenated into a string. The SHA-256 hash algorithm is used to perform a hash operation on the concatenated string to obtain a 256-bit hash value as a unique identifier. The pre-set key is obtained from the system, and it is XORed with the generated unique identifier to obtain a unique password. The system timestamp when the unique password is generated is recorded as the password generation time. According to the preset unlock password validity time, it is determined whether the difference between the current time and the dynamic password generation time exceeds 24 hours. If it exceeds 24 hours, the dynamic password is invalid and a new dynamic password needs to be regenerated; if it does not exceed 24 hours, the dynamic password is still valid and can continue to be used. The dynamic password, generation timestamp, expiration date and other information are encrypted and stored to ensure the security of the password.
[0032] Specifically, first, the device obtains the body serial number "A2FG7H9J4L" from the system, and obtains the current system timestamp "1684305600", and concatenates the two into a string "A2FG7H9J4L1684305600". The SHA-256 hash algorithm is used to operate the string to obtain a 256-bit hash value "d4a8f2c" as a unique identifier. The system preset key is "Xw2#9Qm!", which is bitwise XORed with the unique identifier and the check code to obtain the dynamic password "Ek8@3Rp#". The timestamp "1684305600" of the generated password is recorded. It is determined that the current time "1684478400" is no more than 24 hours different from the generation time, and the password is still valid. Finally, use the AES encryption algorithm and the MD5 value of the device serial number as the key to encrypt the password "Ek8@3Rp#", timestamp "1684305600" and validity period "24" to obtain the ciphertext "3Xd8Hy" and store it to ensure password security.
[0033] S102, determining a verification code according to the current date and the generation date.
[0034] In a specific implementation, the verification code is the number of days between the current date and the generation date. For example, if the generation date is December 24 and the current date is December 26, the verification code is 2.
[0035] In one embodiment, the above step S102 includes the steps of: evaluating the password strength of the dynamic password, the password strength index including length, complexity, and entropy value, and storing the evaluation result in a log.
[0036] Specifically, extract strength indicator parameters such as password length, complexity and entropy value; input the extracted password strength indicator parameters into a pre-built password strength assessment model, and use a machine learning algorithm to comprehensively score the password strength; divide the password strength level into three levels: weak, medium and strong according to the scoring results output by the password strength assessment model; generate log entries according to a standard format for the indicator parameters, assessment results, strength level and other information generated during the password strength assessment process; and write the generated password strength assessment log entries into a preset log file or log database.
[0037] In the specific implementation, the dynamic password to be evaluated is obtained, and the strength index parameters such as the length, complexity, and entropy value of the password are extracted. The extracted password strength index parameters are input into the pre-built password strength evaluation model, and the machine learning algorithm is used to comprehensively score the password strength. According to the scoring results output by the password strength evaluation model, the password strength level is divided into three levels: weak, medium, and strong. The password strength level is judged. If the password strength level is weak, an early warning prompt of unqualified password strength is triggered. The index parameters, evaluation results, strength level and other information generated during the password strength evaluation process are generated into log entries in a standardized format. The generated password strength evaluation log entries are written into a preset log file or log database to realize persistent storage of the evaluation results. According to the preset log query and display rules, a user-friendly password strength evaluation log query and statistical analysis function is provided to facilitate tracking and optimization of password strength.
[0038] Specifically, first, the system obtains the dynamic password entered by the user, such as "Pwd@1234", and then extracts the password length of 8 characters, the complexity includes four types of characters: uppercase and lowercase letters, numbers and special characters, and the entropy value is 22. Then, the extracted password length, complexity, entropy value and other parameters are input into the password strength assessment model trained based on the random forest algorithm. The model comprehensively considers various parameters and outputs a score between 0 and 100, such as 75 points. According to the preset strength level classification rules, the password strength level corresponding to 75 points is "medium". Since the password strength level is not "weak", it will not trigger an early warning prompt. The information generated during the assessment process, such as password length 8, complexity 4, entropy 22, assessment score 75, and strength level "Medium", will be generated as a log entry in the format of "timestamp|password|length|complexity|entropy|score|level", for example, "2023-06-01 10:30:00|Pwd@1234|8|4|22|75|Medium", and this log entry will be written to the password_log table of the MySQL database to achieve persistent storage of the assessment results. Users can use the log query function provided on the web page to filter and view the assessment log according to conditions such as time range and password strength level, and can perform statistical analysis on the assessment results and generate chart reports to intuitively display the overall distribution of user password strength over a period of time, providing decision-making basis for security managers and continuously improving and optimizing password strength strategies.
[0039] S103, generating a dynamic password according to the verification code and the unique dynamic password.
[0040] In the specific implementation, the unique password and the check code are converted to Base64 encoding, the device type identification and the valid time period information are obtained, and the encoded unique password is encrypted using the AES-256-GCM encryption algorithm to obtain a dynamic password. The dynamic password is a string of characters encrypted by encoding to prevent the password from being maliciously obtained and cracked. In this embodiment, the dynamic password is updated periodically to further enhance the security of the password.
[0041] In one embodiment, the above step S103 includes: evaluating the password strength of the dynamic password, the password strength index includes length, complexity, and entropy value, and storing the evaluation result in a log.
[0042] Specifically, extract strength indicator parameters such as password length, complexity and entropy value; input the extracted password strength indicator parameters into a pre-built password strength assessment model, and use a machine learning algorithm to comprehensively score the password strength; divide the password strength level into three levels: weak, medium and strong according to the scoring results output by the password strength assessment model; generate log entries according to a standard format for the indicator parameters, assessment results, strength level and other information generated during the password strength assessment process; and write the generated password strength assessment log entries into a preset log file or log database.
[0043] In the specific implementation, first, the system will obtain the dynamic password entered by the user, such as "Pwd@1234", and then extract the length of the password to be 8 characters, the complexity includes four types of characters: uppercase and lowercase letters, numbers and special characters, and the entropy value is 22. Then, the extracted password length, complexity, entropy value and other parameters are input into the password strength assessment model trained based on the random forest algorithm. The model comprehensively considers various parameters and outputs a score between 0 and 100, such as 75 points. According to the preset strength level classification rules, the password strength level corresponding to 75 points is "medium". Since the password strength level is not "weak", it will not trigger an early warning prompt. The information generated during the assessment process, such as password length 8, complexity 4, entropy 22, assessment score 75, and strength level "Medium", will be generated as a log entry in the format of "timestamp|password|length|complexity|entropy|score|level", for example, "2023-06-01 10:30:00|Pwd@1234|8|4|22|75|Medium", and this log entry will be written to the password_log table of the MySQL database to achieve persistent storage of the assessment results. Users can use the log query function provided on the web page to filter and view the assessment log according to conditions such as time range and password strength level, and can perform statistical analysis on the assessment results and generate chart reports to intuitively display the overall distribution of user password strength over a period of time, providing decision-making basis for security managers and continuously improving and optimizing password strength strategies.
[0044] S104, storing the dynamic password in association with a preset validity period; wherein, at each interval of the validity period, a new current date is obtained, and the steps of determining a verification code based on the current date and the generation date, and generating a dynamic password based on the verification code and the unique dynamic password are respectively performed, and the new dynamic password is stored in association with the validity period.
[0045] Specifically, the validity period is set to 24 hours, and steps S102-S104 are executed every 24 hours to achieve periodic updating of the dynamic password and ensure the security of the password.
[0046] In one embodiment, the dynamic password generation method further comprises the steps of:
[0047] The password backup mechanism is executed regularly to encrypt the currently valid unlock password information and store it in an independent secure storage device.
[0048] In the specific implementation, according to the preset time interval, the password backup mechanism is triggered to obtain the currently valid unlocking password information; an asymmetric encryption algorithm is used to encrypt the obtained password information using a pre-generated public key to obtain encrypted password data; the encrypted password data is transmitted to an independent secure storage device and written to the storage through the device interface to complete the password backup; if the main system fails or data is lost, the encrypted password backup data is read from the secure storage device; the read encrypted password data is decrypted using the private key paired with the encryption to obtain unique password information; the decrypted password information is applied to the unlocking authentication process of the main system to restore normal access to the system; the operating status and data integrity of the main system are continuously monitored, and the password recovery process is automatically triggered when an abnormality is found to ensure the availability of the system.
[0049] Specifically, the system is set to automatically trigger the password backup mechanism every 24 hours, and obtain the current valid unlock password by calling the GetCurrentPassword() function. The RSA asymmetric encryption algorithm is used to encrypt the password using a 2048-bit pre-generated public key, and the encrypted password data is obtained using the public key encryption function Encrypt(password, publicKey). The encrypted data is transmitted to an independent hardware security module (HSM) through a secure transmission protocol such as SSL / TLS, and the WriteSecureData(encryptedPassword) interface provided by the HSM is called to write the data to a dedicated secure storage area. When the main system fails, the encrypted password backup data is read by calling the ReadSecureData() interface of the HSM. Using the 2048-bit RSA private key paired with the encryption, the decryption function Decrypt(encryptedPassword, privateKey) is called to decrypt the password data to obtain the original password. The decrypted password is passed to the authentication module of the main system.
[0050] AuthenticateUser(password), restore normal access to the system through password verification. The system calls the CheckSystemI ntegr ity() function every 5 minutes to check the operating status of the main system and the hash value of key data. If an abnormality is found, the password recovery process RestorePassword() is immediately triggered to ensure that the system can automatically resume operation after a failure occurs.
[0051] In one embodiment, the dynamic password generation method further comprises the steps of:
[0052] Determine whether the current time is within the valid time associated with the dynamic password; if so, obtain the key according to the device type identifier and the unlocking character, decrypt the dynamic password with the key, and obtain the unique password for unlocking operation.
[0053] In one embodiment, obtaining a key according to the device type identifier and the unlocking character and using the key to decrypt the dynamic password includes: determining whether the verification code of the unlocking character is the same as the verification code of the dynamic password; if so, obtaining a key according to the device type identifier and using the key to decrypt the dynamic password.
[0054] Specifically, first obtain a unique password, such as "Un lock123", and perform Base64 encoding conversion on it to obtain the encoded unique password "VW5sb2NrMTI z". Extract the device type identifier (such as "TypeA") and valid time period information (such as "2023-05-01 00:00:00 to 2023-05-31 23:59:59") from the encoded unique password. According to the device type identifier "TypeA", determine the corresponding AES key (such as "abcdef0123456789") from the pre-configured mapping relationship. Use the AES-256-GCM encryption algorithm and use the AES key to encrypt the encoded unique password "VW5sb2NrMTI z" to obtain an encrypted dynamic password (such as "Xf7as8x9"). The dynamic password "Xf7as8x9" is associated with the device type identifier "TypeA" and the valid time period information "2023-05-01 00:00:00 to 2023-05-31 23:59:59" and stored. If an unlock request is received, the dynamic password "Xf7as8x9", the device type identifier "TypeA" and the current time "2023-05-15 12:30:00" in the request are obtained, and it is determined that the current time is within the valid time period. Then, according to the device type identifier "TypeA", the corresponding AES key "abcdef0123456789" is obtained, and the dynamic password "Xf7as8x9" is decrypted using the key to obtain the unique password "Un lock123" and perform the unlock operation; otherwise, the unlock request is rejected. In this way, the security of the unlock password can be effectively improved to prevent the password from being maliciously obtained and cracked. .
[0055] The embodiments of the present invention can achieve the following advantages:
[0056] The method generates a unique identifier through device information and timestamp, and generates a dynamic password for the unique identifier. The dynamic password generation has a regular update effect, which significantly enhances the security protection capability of the information system.
[0057] See also Figure 2 The embodiment of the present invention further provides a dynamic password generating device 400 , which includes a first generating unit 401 , a second generating unit 402 , a third generating unit 403 and an associating unit 404 .
[0058] The first generating unit 401 is used to generate a unique password according to the device body serial number and generation date.
[0059] In one embodiment, generating a unique password according to the device body serial number and generation date includes:
[0060] Obtain the device body serial number and generation date, and concatenate the two into a string; wherein the generation date is obtained by converting the timestamp;
[0061] Use the SHA-256 hash algorithm to perform a hash operation on the concatenated string to obtain a 256-bit hash value as a unique identifier;
[0062] A unique password is obtained by performing an XOR operation on the preset key and the generated unique identifier.
[0063] The second generating unit 402 is used to determine the verification code according to the current date and the generating date.
[0064] The third generating unit 403 is configured to generate a dynamic password according to the verification code and the unique dynamic password.
[0065] In one embodiment, the generating a dynamic password according to the verification code and the unique dynamic password includes:
[0066] Evaluate the password strength of the dynamic password, the password strength indicators include length, complexity, and entropy value, and store the evaluation results in a log.
[0067] In one embodiment, the step of evaluating the password strength of the dynamic password, wherein the password strength index includes length, complexity, and entropy value, and storing the evaluation result in a log, includes:
[0068] Extract password strength indicator parameters such as length, complexity and entropy value;
[0069] The extracted password strength index parameters are input into the pre-built password strength assessment model, and a machine learning algorithm is used to comprehensively score the password strength;
[0070] According to the scoring results output by the password strength assessment model, the password strength level is divided into three levels: weak, medium and strong;
[0071] Generate log entries in a standardized format using the indicator parameters, evaluation results, and strength levels generated during the password strength evaluation process;
[0072] Write the generated password strength assessment log entries to the preset log file or log database.
[0073] The association unit 404 is used to store the dynamic password in association with a preset validity period; wherein, at each interval of the validity period, a new current date is obtained, and the steps of determining the verification code based on the current date and the generation date, and generating a dynamic password based on the verification code and the unique dynamic password are respectively performed, and the new dynamic password is stored in association with the validity period.
[0074] In one embodiment, the dynamic password generating device 400 further includes a backup unit for periodically executing a password backup mechanism to encrypt the currently valid unlocking password information and store it in an independent secure storage device.
[0075] In one embodiment, the dynamic password generating device 400 also includes an unlocking unit, which is used to receive an unlocking request, obtain an unlocking character, a device type identifier and a current time in the unlocking request; determine whether the current time is within the valid time associated with the dynamic password; if so, obtain a key based on the device type identifier and the unlocking character, decrypt the dynamic password with the key, and obtain a unique password to perform an unlocking operation.
[0076] In one embodiment, the step of obtaining a key according to the device type identifier and the unlocking character, and decrypting the dynamic password using the key includes:
[0077] Determining whether the verification code of the unlocking character is the same as the verification code of the dynamic password;
[0078] If so, a key is obtained according to the device type identifier, and the key is used to decrypt the dynamic password.
[0079] like Figure 3 As shown, Figure 3 5 is a schematic block diagram of a computer device provided in an embodiment of the present application. The computer device 500 may be a terminal or a server, wherein the terminal may be an electronic device with communication functions such as a smart phone, a tablet computer, a laptop computer, a desktop computer, a personal digital assistant, and a wearable device. The server may be an independent server or a server cluster composed of multiple servers.
[0080] The computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a system bus 501 , wherein the memory may include a non-volatile storage medium 503 and an internal memory 504 .
[0081] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. When the computer program 5032 is executed, the processor 502 can execute a dynamic password generation method.
[0082] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500 .
[0083] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a dynamic password generation method.
[0084] The network interface 505 is used to communicate with other devices over the network. Those skilled in the art will appreciate that the above structure is only a block diagram of a portion of the structure related to the present application solution, and does not constitute a limitation on the computer device 500 to which the present application solution is applied. The specific computer device 500 may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0085] It should be understood that in the embodiment of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0086] It is understood by those skilled in the art that all or part of the processes in the method for implementing the above embodiment can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a storage medium, which is a computer-readable storage medium. The computer program is executed by at least one processor in the computer system to implement the process steps of the embodiment of the above method.
[0087] Therefore, the present invention also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program.
[0088] The storage medium is a physical, non-transient storage medium, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk, etc., which can store program codes. The computer-readable storage medium can be non-volatile or volatile.
[0089] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0090] In the several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of each unit is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0091] The steps in the method of the embodiment of the present invention can be adjusted in order, combined and deleted according to actual needs. The units in the device of the embodiment of the present invention can be combined, divided and deleted according to actual needs. In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0092] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, terminal, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention.
[0093] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0094] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
[0095] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present invention, and these modifications or replacements should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.
Claims
1. A method for generating a dynamic password, characterized in that: The method comprises: Generate a unique password based on the device serial number and generation date; Determine the verification code based on the current date and the generation date; Generate a dynamic password according to the verification code and the unique dynamic password; The dynamic password is associated with a preset validity period and stored; wherein, at each interval of the validity period, a new current date is obtained, and the steps of determining a verification code based on the current date and the generated date, and generating a dynamic password based on the verification code and the unique dynamic password are respectively performed, and the new dynamic password is associated with the validity period and stored.
2. The method according to claim 1, characterized in that The method of generating a unique password according to the device body serial number and generation date includes: Obtain the device body serial number and generation date, and concatenate the two into a string; wherein the generation date is obtained by converting the timestamp; Use the SHA-256 hash algorithm to perform a hash operation on the concatenated string to obtain a 256-bit hash value as a unique identifier; A unique password is obtained by performing an XOR operation on the preset key and the generated unique identifier.
3. The method according to claim 1, characterized in that: The generating a dynamic password according to the verification code and the unique dynamic password comprises: Evaluate the password strength of the dynamic password, the password strength indicators include length, complexity, and entropy value, and store the evaluation results in a log.
4. The method according to claim 3, characterized in that The step of evaluating the password strength of the dynamic password, wherein the password strength index includes length, complexity, and entropy value, and storing the evaluation result in a log, includes: Extract password strength indicator parameters such as length, complexity and entropy value; The extracted password strength index parameters are input into the pre-built password strength assessment model, and a machine learning algorithm is used to comprehensively score the password strength; According to the scoring results output by the password strength assessment model, the password strength level is divided into three levels: weak, medium and strong; Generate log entries in a standardized format using the indicator parameters, evaluation results, and strength levels generated during the password strength evaluation process; Write the generated password strength assessment log entries to the preset log file or log database.
5. The method according to claim 1, characterized in that Also includes: The password backup mechanism is executed regularly to encrypt the currently valid unlock password information and store it in an independent secure storage device.
6. The method according to claim 1, characterized in that Also includes: Upon receiving an unlock request, obtaining the unlock character, device type identifier, and current time in the unlock request; Determine whether the current time is within the validity period associated with the dynamic password; If so, a key is obtained according to the device type identifier and the unlocking character, and the key is used to decrypt the dynamic password to obtain a unique password for unlocking.
7. The method according to claim 6, characterized in that The step of obtaining a key according to the device type identifier and the unlocking character and decrypting the dynamic password with the key includes: Determining whether the verification code of the unlocking character is the same as the verification code of the dynamic password; If so, a key is obtained according to the device type identifier, and the key is used to decrypt the dynamic password.
8. A dynamic password generating device, characterized in that: include: A first generating unit, used to generate a unique password according to the device body serial number and generation date; A second generating unit, used to determine a verification code according to a current date and the generating date; A third generating unit, configured to generate a dynamic password according to the verification code and the unique dynamic password; An association unit is used to associate and store the dynamic password with a preset effective time; wherein, at each interval of the effective time, a new current date is obtained, and the steps of determining a verification code based on the current date and the generated date, and generating a dynamic password based on the verification code and the unique dynamic password are respectively performed, and the new dynamic password is associated and stored with the effective time.
9. A computer device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing the steps of the method described in any one of claims 1 to 7 when executing a program stored in a memory.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.