Password management method and device

Through technical means such as Chrome Extension API and AES encryption algorithm, the problems of poor user experience and insufficient security of traditional password management methods are solved, efficient and secure password management is achieved, cross-platform adaptation is supported and log audit functions are provided.

CN120030571APending Publication Date: 2025-05-23SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510155185.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Traditional password management methods have problems such as poor user experience and insufficient security, especially when multiple accounts and passwords are needed to manage, which can easily lead to operational errors and security risks.

Method used

Register a keyboard event listener through Chrome Extension API, capture user keyboard input, automatically copy passwords, and use AES encryption algorithm to add salt values ​​to encrypt passwords, support multi-factor authentication and permission control, and integrate a secure transmission protocol.

Benefits of technology

Improves user experience, reduces the complexity and error rate of manual operations, enhances password security, supports cross-platform adaptation, and provides auditability through log auditing capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030571A_ABST
    Figure CN120030571A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer software, in particular to a password management method and device.A Chrome Extension API is used for registering a keyboard event monitor, capturing keyboard input of a user interacting with a webpage, conducting targeted processing on a specific keyboard event, obtaining text content associated with the event through the API, and using a naviator.clipboard.writeText () method to manage a password. And writing the extracted text content into a system clipboard to realize automatic copying operation. Compared with the prior art, the password management can be more efficiently carried out, manual copying and pasting are not needed, and the working efficiency is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer software, and specifically provides a password management method and device. Background Art

[0002] Traditional password management methods have a series of problems, mainly in terms of user experience and security. First, traditional password management usually requires users to manually copy and paste password information, which is not only prone to operational errors, but also significantly reduces user work efficiency. Users need to frequently enter passwords in different pages and systems, which increases the complexity of operations, especially when multiple accounts and passwords need to be managed at the same time.

[0003] Secondly, there are potential security risks in the process of manual password operation. Users may copy the wrong password due to negligence or other reasons, resulting in login failure or information leakage. In addition, since people tend to use simple and easy-to-remember passwords, traditional manual password management methods are also vulnerable to attacks such as password cracking.

[0004] With the development of the Internet, people use more and more online services, and the number of accounts and passwords that need to be managed is also on the rise. Traditional manual password management methods can no longer meet users' needs for security and convenience, so it is necessary to propose a more advanced and intelligent password management method to meet the growing password management challenges. Summary of the invention

[0005] The present invention aims at solving the above-mentioned deficiencies of the prior art and provides a password management method with strong practicability.

[0006] A further technical task of the present invention is to provide a password management device that is rationally designed, safe and applicable.

[0007] The technical solution adopted by the present invention to solve its technical problem is:

[0008] A password management method uses the Chrome Extension API to register a keyboard event listener, captures the keyboard input of the user interacting with the web page, performs targeted processing on specific keyboard events, uses the API to obtain the text content associated with the event, and uses the navigator.clipboard.writeText() method to write the extracted text content to the system clipboard to achieve automatic copying operation.

[0009] Furthermore, the user exports the password template, maintains the password book, and sets the shortcut key for the corresponding password after importing the password book. A maximum of three shortcut keys are supported, a minimum of two keys are supported, and the ctrl key must be included. Press the corresponding shortcut key on the page where the password is required, and the password will be written to the clipboard. The user can use the password by pressing ctrl+v or right-clicking to paste.

[0010] Furthermore, users need to log in to the plugin through a valid authentication method, and different permission levels are set according to the user's identity. Only authorized users can access and manage the password list;

[0011] Supports multi-factor authentication. Users can set the password change cycle and enable or disable multi-factor authentication in the plugin's settings.

[0012] Furthermore, the password stored in the password book is encrypted using the AES encryption algorithm plus the salt value. The steps are as follows:

[0013] (1) Generate a random salt value (32 bits): Use the randomUUID method in UUID to generate a 32-bit random salt value. Use the toString method to convert the generated random salt value into a string. Finally, use the replaceAll method to replace the "-" in the string with an empty string.

[0014] (2) Plain text encryption: According to the agreed format, use the "32-bit salt value + $ + password plain text" method to encrypt and obtain the final password.

[0015] Furthermore, a secure transmission protocol is adopted, a secure transmission protocol is integrated, and symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms are used to ensure the security and integrity of data.

[0016] Furthermore, plug-ins are used in different operating systems and browser environments, and common Web standards and a cross-platform browser plug-in development framework are used to ensure that the application can run normally in various environments.

[0017] Furthermore, the plug-in will record all password access and modification operations and perform security audits. The log collection method is as follows:

[0018] (1) Page injection: Inject JavaScript code into the page to monitor and record user behavior;

[0019] (2)) Browser API: Use the API provided by the browser to obtain data;

[0020] Log storage uses encryption algorithms and has a regular backup mechanism. Strict access permissions are set for log access, and only authorized personnel can access log data.

[0021] A password management device, comprising: at least one memory and at least one processor;

[0022] The at least one memory is used to store a machine-readable program;

[0023] The at least one processor is used to call the machine-readable program to execute a password management method.

[0024] Compared with the prior art, the password management method and device of the present invention have the following outstanding beneficial effects:

[0025] The browser plug-in of the present invention allows users to manage passwords more efficiently without the need for manual copying and pasting, thereby greatly improving work efficiency.

[0026] (1) User experience upgrade: The plug-in monitors keyboard events, allowing users to operate passwords more conveniently when using the browser, thereby improving the user experience.

[0027] (2) Password security: Multiple security measures such as identity authentication, permission control, and password encryption are introduced to effectively ensure the security of user passwords.

[0028] (3) Cross-platform adaptation: By adopting a cross-platform adaptation technical solution, the present invention can run flexibly in different operating systems and browsers, providing a wider range of applicability.

[0029] (4) Log audit function: The operation log and audit function help users track and understand the historical operations of password management, increasing the auditability and transparency of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0031] Attached Figure 1 It is a flowchart diagram of a password management method;

[0032] Attached Figure 2 It is a diagram of password encryption steps in a password management method. DETAILED DESCRIPTION

[0033] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention is further described in detail below in conjunction with specific implementation methods. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0034] A best embodiment is given below:

[0035] like Figure 1 As shown, in this embodiment, a password management method uses the Chrome Extension API to register a keyboard event listener, which can capture the keyboard input of the user interacting with the web page. Specific keyboard events are processed in a targeted manner, and the API is used to obtain the text content associated with the event, including but not limited to the input box, text area, etc. With the help of the navigator.clipboard.writeText() method, the extracted text content is written to the system clipboard to realize the automatic copy operation. This technology ensures the efficient acquisition and secure transmission of passwords.

[0036] Users can export password templates to maintain password books and set shortcut keys for corresponding passwords after importing password books. By monitoring user key operations, the shortcut keys corresponding to passwords can be read. The detailed process can be seen in Figure 1 This process supports up to three shortcut keys, at least two keys, and must include the ctrl key. Press the corresponding shortcut key on the page where the password is required, and the password will be written to the clipboard. Users can use ctrl+v or right-click to paste the password.

[0037] In the present invention, in order to ensure the security of the password, the system can implement user identity authentication and permission control. Users need to log in to the plug-in through a valid identity authentication method, and different permission levels can be set according to the user's identity. Only authorized users can access and manage the password list. In addition to traditional username and password verification, the present invention also supports multiple identity authentication. Users can set the password change cycle in the settings of the plug-in, and enable or disable multiple identity authentication. When multiple identity authentication is enabled, in addition to the username and password, additional verification steps (such as mobile phone verification code, fingerprint recognition, mobile phone token, etc., using FreeOTP as soft token authentication) are required, thereby greatly improving the security of the password.

[0038] In order to further enhance the security of passwords, this patent uses the AES encryption algorithm plus salt values ​​to encrypt passwords stored in the password book. When all users' password information is stored locally, it is processed by the AES encryption algorithm plus salt values, which means that even if two users use the same password, their encrypted forms are different. The AES encryption algorithm combined with the use of salt values ​​improves the security of password storage and transmission by adding an additional random factor to prevent direct matching attacks on passwords. This means that even if the device is stolen or the data is illegally accessed, it is difficult for attackers to decrypt and obtain the real password information.

[0039] like Figure 2 As shown, the encryption steps are as follows:

[0040] (1) Generate a random salt value (32 bits): Use the randomUUID method in UUID to generate a 32-bit random salt value (the format is xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx (8-4-4-4-12)). However, the format we agreed on (completely defined by ourselves) does not require "-". Therefore, the generated random salt value is first converted into a string using the toString method, and then the replaceAll method is used to replace the "-" in the string with an empty string.

[0041] (2) Plain text encryption: According to the agreed format, use the "32-bit salt value + $ + password plain text" method to encrypt and obtain the final password. This agreed format is to make it easier to obtain the salt value (split by $ as the separator, the part before the first $ symbol is the salt value), so that we can decrypt.

[0042] Before the plugin writes the password to the clipboard, it needs to decrypt it first to ensure that the protected password information is transmitted in the system. The decrypted information needs to remove the salt value, remove the first $ sign and the preceding part, and the corresponding password is obtained.

[0043] Considering the transmission process of passwords within the system, it is crucial to use a secure transmission protocol. The present invention can integrate a secure transmission protocol, such as HTTPS, to ensure that the user password is not intercepted and tampered with by malicious attackers during the transmission process within the plug-in. Symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms are used to ensure the security and integrity of data, thereby ensuring the identity and data security of both parties in the communication.

[0044] Considering that users may use plug-ins in different operating systems and browser environments, the technical solution should have good cross-platform adaptability. By using common Web standards and a cross-platform browser plug-in development framework, it can be ensured that it can run normally in various environments.

[0045] The plugin will log all password access and modification operations and perform security audits, which means that if there is any abnormal behavior or unauthorized access, administrators or users can quickly discover and take action.

[0046] Log collection method:

[0047] (1) Page injection: Inject JavaScript code into the page to monitor and record user behavior.

[0048] (2) Browser API: Use the API provided by the browser (such as webRequest, history, etc.) to obtain data.

[0049] Log collection complies with relevant laws, regulations and privacy policies. Log storage uses encryption algorithms and has a regular backup mechanism. Strict access rights are set for log access, and only authorized personnel can access log data.

[0050] Based on the above method, a password management device in this embodiment includes: at least one memory and at least one processor;

[0051] The at least one memory is used to store a machine-readable program;

[0052] The at least one processor is used to call the machine-readable program to execute a password management method.

[0053] The above-mentioned specific implementations are only specific cases of the present invention. The patent protection scope of the present invention includes but is not limited to the above-mentioned specific implementations. Any technical solutions that conform to the above-mentioned specific implementations of the present invention and any appropriate changes or substitutions made by ordinary technicians in the relevant technical field shall fall within the patent protection scope of the present invention.

[0054] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A password management method, characterized in that: Use the Chrome Extension API to register a keyboard event listener to capture keyboard input from users interacting with web pages, perform targeted processing on specific keyboard events, use the API to obtain the text content associated with the event, and use the navigator.clipboard.writeText() method to write the extracted text content to the system clipboard to implement automatic copy operations.

2. A password management method according to claim 1, characterized in that: The user exports the password template, maintains the password book, and sets the shortcut key for the corresponding password after importing the password book. A maximum of three shortcut keys are supported, and a minimum of two keys are supported, and the ctrl key must be included. Press the corresponding shortcut key on the page where the password is required, and the password will be written to the clipboard. The user can use the password by pressing ctrl+v or right-clicking to paste.

3. A password management method according to claim 1, characterized in that: Users need to log in to the plugin through a valid authentication method, and different permission levels are set according to the user's identity. Only authorized users can access and manage the password list; Supports multi-factor authentication. Users can set the password change cycle and enable or disable multi-factor authentication in the plugin's settings.

4. A password management method according to claim 3, characterized in that: Use the AES encryption algorithm and salt value to encrypt the password stored in the password book. The steps are as follows: (1) Generate a random salt value (32 bits): Use the randomUUID method in UUID to generate a 32-bit random salt value. Use the toString method to convert the generated random salt value into a string. Finally, use the replaceAll method to replace the "-" in the string with an empty string. (2) Plain text encryption: According to the agreed format, use the "32-bit salt value + $ + password plain text" method to encrypt and obtain the final password.

5. A password management method according to claim 4, characterized in that: Adopt secure transmission protocols, integrate secure transmission protocols, and use symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms to ensure data security and integrity.

6. A password management method according to claim 5, characterized in that: Use plug-ins in different operating systems and browser environments, using common web standards and a cross-platform browser plug-in development framework to run normally in a variety of environments.

7. A password management method according to claim 6, characterized in that: The plug-in will record all password access and modification operations and perform security audits. The log collection method is: (1) Page injection: Inject JavaScript code into the page to monitor and record user behavior; (2)) Browser API: Use the API provided by the browser to obtain data; Log storage uses encryption algorithms and has a regular backup mechanism. Strict access permissions are set for log access, and only authorized personnel can access log data.

8. A password management device, characterized in that: include: at least one memory and at least one processor; The at least one memory is used to store a machine-readable program; The at least one processor is configured to call the machine-readable program to execute the method according to any one of claims 1 to 7.