Offline password generation method and device, offline password verification method and device and storage medium

By using encryption algorithms in offline devices to generate and display passwords and extract verification factors, the problem of device security access control in offline scenarios is solved, and the generation and verification of dynamic passwords are realized, which enhances the security of the information system.

CN120034324APending Publication Date: 2025-05-23LOCKE IOT TECHNOLOGY (GUANGZHOU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510177065.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art cannot effectively control the secure access of the device in offline scenarios, and traditional passwords are easily stolen, leaked, and forgotten, and cannot be verified and updated without a network connection.

Method used

By obtaining the current full point timestamp and encryption key, encrypting calculations using preset encryption algorithms (such as AES and FPE), generating display passwords, and extracting the check factor from the original encrypted text for checksum storage.

Benefits of technology

It realizes a simple and reliable dynamic password generation mechanism in offline scenarios, enhances the security of the information system, reduces the security risks caused by password problems, and meets the needs of secure access control of devices or systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034324A_ABST
    Figure CN120034324A_ABST
Patent Text Reader

Abstract

The invention discloses an offline password generation method and device, an offline password verification method and device and a storage medium. The offline password generation method comprises the steps of obtaining a current hourly timestamp and an encryption key; carrying out encryption calculation on the hourpoint timestamp by using the encryption key through a preset encryption algorithm, taking a calculation result as an encrypted original text, and extracting a number at a preset position from the encrypted original text as a verification factor; and performing FPE format reservation encryption on the encrypted original text to generate a display password, and outputting the display password to a user. According to the invention, a simple and reliable dynamic password generation mechanism without network support is provided for a user, the security of an information system and the use convenience of the user are enhanced, the security risk caused by a password problem is reduced, and the requirement of performing security access control on equipment or a system in an offline scene is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of access control system applications, and in particular to an offline password generation and verification method, device and storage medium. Background Art

[0002] In today's digital age, secure authentication is crucial, but traditional passwords are prone to theft, leakage, and forgetting. Especially in offline environments with unstable networks or no network connection, relying on online servers for password verification and updates is often not feasible.

[0003] The above contents are only used to assist in understanding the technical solution of the present application and do not constitute an admission that the above contents are prior art. Summary of the invention

[0004] The main purpose of this application is to provide an offline password generation and verification method, device and storage medium, aiming to solve the technical problem that secure access control to devices cannot be performed in existing offline scenarios.

[0005] To achieve the above purpose, the present application proposes an offline password generation method, the method comprising:

[0006] Get the current hourly timestamp and encryption key;

[0007] The hourly timestamp is encrypted and calculated using the encryption key through a preset encryption algorithm, and the calculation result is used as the encrypted original text, wherein a number at a preset position is extracted from the encrypted original text as a verification factor;

[0008] The encrypted original text is encrypted in an FPE format-preserving manner to generate a display password, and the display password is output to the user.

[0009] In one embodiment, the step of encrypting the hourly timestamp with the encryption key through a preset encryption algorithm and using the calculation result as the encrypted original text includes:

[0010] A timestamp parameter extracted from the hourly timestamp, and the timestamp parameter and the initial setting parameter are concatenated into encrypted plain text;

[0011] The encrypted plaintext is encrypted with the encryption key, and the encryption result is calculated by the AES encryption algorithm to generate the encrypted original text.

[0012] In one embodiment, the steps of performing FPE format-preserving encryption on the encrypted original text to generate a display password, and outputting the display password to the user include:

[0013] Encrypting the encrypted original text with the encryption key to obtain an encryption result;

[0014] A tweak fine-tuning parameter is obtained, and the encryption result is calculated using the tweak fine-tuning parameter as a calculation parameter of the FPE encryption algorithm to obtain the display password.

[0015] In one embodiment, after the step of extracting a number at a preset position from the encrypted original text as a check factor, the method further includes:

[0016] The extracted verification factor is saved in a preset storage area.

[0017] In one embodiment, the offline password generation method further includes:

[0018] According to the detected device initialization settings, set password generation parameters based on the device, the password generation parameters including initial setting parameters, encryption keys and tweak parameters;

[0019] Synchronize the device's system time.

[0020] In one embodiment, the offline password generation method further includes:

[0021] Obtain a preset encryption algorithm from a cloud server, wherein the preset encryption algorithm includes an AES encryption algorithm and an FPE encryption algorithm;

[0022] The preset encryption algorithm is written into the device.

[0023] The present application also proposes an offline password verification method, which includes:

[0024] Receiving a password input by a user, and performing reverse decryption on the input password to obtain an encrypted original text;

[0025] Obtain the current hourly timestamp, and encrypt the hourly timestamp and the initial setting parameters to obtain the decrypted original text;

[0026] Comparing the check factors of the encrypted original text and the decrypted original text to determine whether the check factors are consistent;

[0027] If the verification factors are inconsistent, regenerate the decrypted original text using another hourly timestamp and the initial verification factor;

[0028] The regenerated decrypted original text is compared with the encrypted original text until the check factors are consistent.

[0029] In one embodiment, the offline password verification method further includes:

[0030] Counting the number of comparisons of the check factor;

[0031] When it is determined that the number of comparisons is equal to the preset number of verifications, a password verification failure message is output.

[0032] In addition, to achieve the above-mentioned purpose, the present application also proposes an offline password generation device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the offline password generation method and the offline password verification method as described above.

[0033] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the offline password generation method and the offline password verification method described above are implemented.

[0034] One or more technical solutions proposed in this application have at least the following technical effects:

[0035] The technical solution of the present application is to obtain the current hourly timestamp and encryption key by building an encryption processing algorithm in the device; encrypt the hourly timestamp with the encryption key through a preset encryption algorithm, and use the calculation result as the encrypted original text, wherein the number at the preset position is extracted from the encrypted original text as a verification factor; perform FPE format-preserving encryption on the encrypted original text to generate a display password, and output the display password to the user for the user to use. The present invention provides users with a simple, reliable, and network-free dynamic password generation mechanism, enhances the security of information systems and the convenience of user use, reduces security risks caused by password problems, and meets the needs of secure access control of devices or systems in offline scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0038] Figure 1 A flowchart of the first embodiment of the offline password generation method of the present application is provided;

[0039] Figure 2 A flowchart of the first embodiment of the offline password verification method of the present application is provided.

[0040] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0041] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0042] Based on this, the present application embodiment provides an offline password generation method, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the offline password generation method of the present application. In this embodiment, the offline password generation method includes steps S10 to S30:

[0043] Step S10, obtaining the current hourly timestamp and encryption key;

[0044] Step S20, encrypting the hourly time stamp with the encryption key through a preset encryption algorithm, and using the calculation result as the encrypted original text, wherein a number at a preset position is extracted from the encrypted original text as a verification factor;

[0045] Step S30, performing FPE format-preserving encryption on the encrypted original text to generate a display password, and outputting the display password to the user.

[0046] In this embodiment, the user can issue a password generation instruction through the device-related function to generate a password to be applied by the device, and the device is a smart electronic lock or an electronic device that can apply a password. When the device function of the device is used to initiate the password generation instruction, it can be implemented based on the function of the device itself, or issued based on the corresponding function button of the device.

[0047] When executing the password generation instruction, the preset encryption algorithm is called for implementation. The current hourly timestamp and encryption key are obtained, the hourly timestamp and the encryption key are used as calculation parameters of the AES encryption algorithm, and the input password of the device is generated by the AES encryption algorithm. The calculation process based on the AES encryption algorithm can be understood as the step of encrypting the hourly timestamp with the encryption key through the preset encryption algorithm and using the calculation result as the encrypted original text, including:

[0048] A timestamp parameter extracted from the hourly timestamp, and the timestamp parameter and the initial setting parameter are concatenated into encrypted plaintext;

[0049] The encrypted plaintext is encrypted with the encryption key, and the encryption result is calculated by the AES encryption algorithm to generate the encrypted original text.

[0050] According to the acquired hourly timestamp of the current device system, the hourly time is extracted from the hourly timestamp as the timestamp parameter. The definition of the hourly timestamp comes from the numerical representation of the timestamp. In practical applications, the timestamp is understood as being calculated based on a fixed starting time point, which is called the Unix epoch or Epoch time. Different systems or applications have different time bases. Therefore, the timestamp is essentially represented by an integer or floating point number, which represents the number of seconds or milliseconds that have passed since the time base. For example, if the current time is 1633072800 after the Unix epoch or Epoch time, the timestamp of the current time is 1633072800. In this embodiment, only the hourly timestamp of the current device system is applied. For example, if the current time is 12:01 on December 30, 2020, the hourly timestamp is 12:00 on December 30, 2020. That is, the hourly time of the current time is converted into the hourly timestamp, that is, the timestamp of 12:00 on December 30, 2020 is 1609300800, which is expressed in hexadecimal as 5FEBFB40.

[0051] According to the limitation of the hourly timestamp, a 4-byte timestamp is selected from the hourly timestamp as the timestamp parameter, and the timestamp parameter is concatenated with the initial setting parameter into a fixed-byte encrypted plaintext, wherein the initial setting parameter is a fixed-byte value set after the system of the device is initialized, for example, 12 bytes. Therefore, the concatenated encrypted plaintext is a 16-byte value of the 4-byte timestamp parameter concatenated with the 12-byte initial setting parameter.

[0052] Furthermore, the device system configuration parameters in different application scenarios are different, so the number of bytes of the timestamp parameter and the number of bytes of the initial setting parameter can be set accordingly based on the system configuration parameters of the device, so as to achieve the purpose of changing the number of bytes of the encrypted plaintext. For example, the system configuration parameters of the smart electronic locks used in confidential places and the smart electronic locks used in private residences are very different. Specifically, it can be implemented based on the functions provided by the system configuration parameters of the device.

[0053] According to the encrypted plaintext that has been spliced, the encrypted plaintext is converted into an encrypted original text by using an encryption key and passing through the calculation process of the AES encryption algorithm. The encryption key is a fixed byte parameter value set when the device is initialized. The encryption key can be 16 bytes, or the number of bytes based on the encryption key can be set according to the system configuration parameters of the device. The AES encryption algorithm (Advanced Encryption Standard) is a symmetric encryption algorithm widely used in the field of data encryption. The specific encryption process of the encrypted original text can be as follows:

[0054] The spliced ​​16-byte encrypted plaintext is used as the calculation object, and the encrypted ciphertext is generated after encryption with the encryption key. The generated encrypted ciphertext is: 12866FCA348A8265B6752A1270397B26. The encrypted ciphertext is split, S1=12866FCA, S2=348A8265, S3=B6752A12, S4=70397B26. The split sum SUM=S1+S2+S3+S4=16EBF9767=6153017191.

[0055] Among them, it is also necessary to extract the preset number of preset positions from the calculation result as a check factor, and use the calculation result after extracting the check factor as the encrypted original text. In this embodiment, the last three digits of the calculation result are used as the check factor, that is, the check factor is 191, and the encryption generated based on the check factor is 101191. The encrypted original text consists of three parts: password type + password interval + check factor, where the password type occupies 1 bit, the password interval occupies 2 bits, and the check factor occupies 3 bits. In the encrypted original text 101191, the first digit 1 of the password indicates that it is a time-limited password and the password interval is in hours. 01 means that the time interval is 1 hour. If the hourly time obtained after comparison is 12:00, then the end time of this time-limited password is 13:00. The last three digits are the check factor, and the splicing is 101191. Considering the use of the check factor, the extracted check factor can also be saved to the preset storage area of ​​the device to verify the input password, that is, after the step of extracting the digits at the preset position from the encrypted original text as the check factor, it also includes:

[0056] The extracted verification factor is saved in a preset storage area.

[0057] In the device, a preset storage area is provided as the storage location of the check factor, and the preset storage area is only used to store a check factor, that is, when a new check factor is detected, the new check factor overwrites the check factor in the preset storage area. Alternatively, after the device is initialized, the check factor in the preset storage area is cleared.

[0058] In another embodiment, based on the check factor obtained from the encrypted text, the check factor and the encrypted text can be associated and saved, so as to verify the encrypted text directly through the check factor. This operation can be implemented when the device only has one encrypted text for confidentiality operations. Therefore, after the encrypted text and the check factor are associated and saved, when the encrypted text is regenerated, the check factor extracted from the new encrypted text needs to overwrite the historically stored check factor. It should be clear that the check factor and the encrypted text have a one-to-one data relationship.

[0059] In addition, in order to improve the confidentiality of the encrypted original text, the encrypted original text can be fine-tuned by tweaking the fine-tuning parameters and displayed to the user, that is, the encrypted original text is encrypted in FPE format to generate a display password, and the display password is output to the user, including:

[0060] Encrypting the encrypted original text with the encryption key to obtain an encryption result;

[0061] A tweak fine-tuning parameter is obtained, and the encryption result is calculated using the tweak fine-tuning parameter as a calculation parameter of the FPE encryption algorithm to obtain the display password.

[0062] According to the above, after obtaining the encrypted original text through the preset encryption algorithm, the encrypted original text is encrypted again through the encryption key to obtain the encryption result, and the preset tweak fine-tuning parameters are used as the adjustment parameters of the FPE encryption algorithm to adjust the encryption result to obtain the display password, which is the usage password output to the user. The tweak fine-tuning parameters are the usage parameters of the FPE encryption algorithm. When the tweak fine-tuning parameters are applied to the FPE encryption algorithm, different adjustments can be made based on the same encrypted original text using the same encryption key to generate different display passwords, thereby increasing the diversity and complexity of encryption and improving the security of encryption. The value range of the tweak fine-tuning parameters is usually determined by the specific FPE algorithm and application scenario. In general, the tweak fine-tuning parameters can be represented as an integer, a string or other specific data type. In some algorithms, tweak may be limited to a certain numerical range, for example, between 0 and (2 to the power of N - 1), where N is a certain integer. Its specific setting can be customized according to the application scenario and algorithm scenario of the device. In this embodiment, the process after fine-tuning based on the encrypted original text can be as follows:

[0063] Among them, the encrypted original text: 101191; the encryption key: 16 bytes setting parameters when the device is initialized: 65544332655443326554433265544332; the tweak fine-tuning parameters: 1717171717171717;

[0064] Encryption process: The encryption algorithm of the encrypted original text is retained in the FPE format, and the encrypted original text is processed with the encryption key and the tweak parameter to obtain 123998, that is, 123998 is the display password output to the user. The user can use the processing result as the input password for security verification based on the display password.

[0065] Furthermore, the offline password generation method further includes:

[0066] According to the detected device initialization settings, set password generation parameters based on the device, the password generation parameters including initial setting parameters, encryption keys and tweak parameters;

[0067] Synchronize the device's system time.

[0068] Based on the current device application requirements, after the device is initialized before the device is applied, the relevant parameter information based on the offline password generation is set, that is, after the device initialization is detected, the password generation parameters based on the offline password are set through the relevant functions provided by the device. In this embodiment, the generation set includes initial setting parameters for splicing encrypted plaintext, encryption keys applied to encrypted plaintext and encrypted original text, and tweak fine-tuning parameters. It should be clear that when setting the parameters, the parameters must comply with the setting requirements of the system setting parameters of the device, and the setting requirements include the number of bytes and the calculation requirements of the corresponding encryption algorithm, such as the fixed number of bytes required by the system setting parameters of devices in different application scenarios and the calculation scenario requirements of the encryption algorithm. Since the password generation parameters are fixed values, the password generation parameters can also be reset based on the settings of the application scenario when the device is initialized.

[0069] Furthermore, the offline password generation method further comprises:

[0070] Obtain a preset encryption algorithm from a cloud server, wherein the preset encryption algorithm includes an AES encryption algorithm and an FPE encryption algorithm;

[0071] The preset encryption algorithm is written into the device.

[0072] According to the encryption requirements of the current device, after the device is initialized and the password generation parameters based on the offline password generation are set, the preset encryption algorithm is obtained from the cloud server and written to the device, so that when the device detects the password generation instruction, the preset encryption algorithm is called to generate the encrypted original text and the display password, and the preset encryption algorithm includes the AES encryption algorithm and the FPE encryption algorithm. Since the preset encryption algorithm has been written to the device and is available for use, the preset encryption algorithm is not limited by the communication status of the device, that is, when the device is offline, the preset encryption algorithm can still be called to perform encryption operations in combination with the preset parameters based on the offline password generation.

[0073] In addition, the device has a communication connection with the cloud server, and after the device is initialized, the parameter information of the device can be reported to the cloud server so that the cloud server can manage the device. In another embodiment, when the device fails to disconnect the communication with the cloud server, that is, when the device is not in an offline state, it can also obtain a preset encryption algorithm from the cloud server to perform encryption operations on the current device, wherein, when the preset encryption algorithm obtained based on the cloud server is used, the data involved in the encryption operation can be stored in the device and the cloud server, so that the password verification operation can be performed based on the device and the cloud server.

[0074] In this embodiment, by writing an encryption algorithm into the device and setting encryption parameters, a usable dynamic password can be generated by calculating parameters even when the device is offline, providing users with a simple, reliable dynamic password generation mechanism that does not require network support, enhancing the security of the information system and the convenience of user use, reducing security risks caused by password issues, and meeting the needs of secure access control to devices or systems in offline scenarios.

[0075] The present application embodiment provides an offline password verification method, referring to Figure 2 , Figure 2 This is a flow chart of an embodiment of an offline password verification method of the present application. In this embodiment, the offline password verification method includes the following steps:

[0076] Step S40, receiving the password input by the user, and performing reverse decryption with the initial setting parameters to obtain the encrypted original text;

[0077] Step S50, obtaining the current hourly timestamp, and encrypting the hourly timestamp and the initial setting parameters to obtain a decrypted original text;

[0078] Step S60, comparing the check factors of the encrypted original text and the decrypted original text to determine whether the check factors are consistent;

[0079] Step S70, if the verification factors are inconsistent, regenerate the decrypted original text with another hourly timestamp and the initial verification factor;

[0080] Step S80, comparing the regenerated decrypted text with the encrypted text until the check factors are consistent.

[0081] In this embodiment, when receiving the password input by the user, the input password is reversely decrypted by the encryption key to obtain the encrypted original text. According to the definition of the previous embodiment, the input password is the display password, that is, the user enters the display password on the password input page provided by the device, which is the user input password. It can be understood that the display password is obtained by adjusting the tweak parameters after being processed by the encryption key, so the encrypted original text corresponding to the display password can be obtained by reverse deduction of the encryption key.

[0082] Extract the hourly timestamp at the current time node, extract the four-byte timestamp parameter from the hourly timestamp, concatenate the timestamp parameter and the initial setting parameter into decrypted plaintext, and then encrypt the decrypted plaintext using the encryption key through AES to obtain the decrypted plaintext. Extract the check factor from the decrypted plaintext, and compare the check factor with the check factor of the encrypted original text obtained by reverse deduction to verify whether the input password is correct.

[0083] Among them, the process of splicing the hourly timestamp and the initial setting parameters to obtain the decrypted plaintext, and encrypting the decrypted plaintext using the encryption key through the AES encryption algorithm to generate the decrypted original text is essentially the process of splicing the encrypted plaintext and generating the encrypted original text recorded in the first embodiment of the offline password generation method, which will not be elaborated here.

[0084] Then, according to the preset verification factor extraction rules, the verification factors are extracted from the decrypted original text and the encrypted original text derived in reverse, the two extracted verification factors are compared, and it is determined whether the input password is successfully verified according to the comparison result.

[0085] The preset verification factor extraction rule is the one set in the previous embodiment, and the last three digits are used as the verification factor. It is clear from the above that since the verification factor extraction rule is consistent, and the calculation parameters and generation rules used to generate the decrypted original text and the encrypted original text are the same, the verification factors to be compared should also be consistent, so the verification of the input password can be achieved by comparing the verification factors.

[0086] In addition, considering that one of the generation parameters of the encrypted text and the decrypted text is a four-byte timestamp parameter extracted from the current hourly timestamp, if the hourly timestamps of the encrypted text and the decrypted text are inconsistent, the verification factor comparison will be inconsistent. To this end, when the comparison of the current verification factor is inconsistent, the timestamp parameter can be re-extracted based on another hourly timestamp, wherein the other hourly timestamp is the previous hourly timestamp or the next hourly timestamp of the current time, and the re-extracted timestamp parameter and the initial setting parameter are re-joined into a decrypted plaintext, and the decrypted plaintext is regenerated into a decrypted text using the decryption key through the AES algorithm, and the verification factor is extracted based on the regenerated decrypted text, and re-compared with the verification factor of the encrypted text derived by reverse deduction to verify the input password. The next hourly timestamp is a new hourly timestamp based on the current hourly time pushed forward or backward by one hour. A four-byte timestamp parameter is extracted from the new hourly timestamp. It can be understood that the process of regenerating the decrypted original text and extracting the check factor for comparison is defined as the second round of check factor comparison process. Since there are 24 hourly timestamps, the upper limit of the number of comparisons based on the check factor should be 24 times, that is, when the second round of check factor comparison is still inconsistent, continue to extract the four-byte timestamp parameter from the next hourly timestamp to regenerate the decrypted original text for the third round of check factor comparison. It should be clear that the timestamp parameters are different for each round of check factor comparison.

[0087] According to the comparison based on the verification factor shown above, multiple rounds of verification factor comparison processes can be performed based on the changes in the hourly timestamp, until the verification factors are compared consistently, then it is determined that the input password verification is successful.

[0088] In addition, the check factor comparison can be performed on the encrypted text reversely derived from the input password based on the check factor stored in the preset storage area, the preset storage area is used to store the check factor, and the check factor is the last three digits of the value extracted from the pre-generated encrypted text.

[0089] In the comparison process of the verification factors, when the verification factors are consistent, it is determined that the input password verification is successful. Since the timestamp parameter is extracted from the hourly timestamp, the hourly timestamp is 24 times, so the offline password verification method also includes:

[0090] Counting the number of comparisons of the check factor;

[0091] When it is determined that the number of comparisons is equal to the preset number of verifications, a password verification failure message is output.

[0092] Due to the characteristics of the hourly timestamp, the number of comparisons based on the verification factor can be set, that is, the hourly timestamp is a fixed number of values. Taking 24 hours a day as an example, the value of the hourly timestamp has only 24 different values. According to the comparison of the current verification factor, the number of comparisons of the verification factor is counted for security determination. Among them, according to the characteristics of the hourly timestamp, a preset number of comparisons based on the verification factor is pre-set, and the preset number can be set to 24, or, based on the computing power of the device, it can be set to any number less than 24. Specifically, it can be set based on the upper limit of the computing power of the device, or based on the security verification rules of the device, and the details will not be repeated. Based on this, when the number of comparisons of the verification factor is counted to be equal to the preset verification number, the password verification failure information is output.

[0093] In this embodiment, the time-based dynamic password generation method makes the password time-effective and one-time. Even if the password is stolen by others, due to its extremely short validity period (only valid at the current hour), the next password will be regenerated according to the new time and parameters, which greatly reduces the risk of password cracking and abuse, thereby achieving the technical effect of improving device security.

[0094] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the offline password generation method of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0095] The present application provides an offline password generation device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the offline password generation method and the offline password verification method in the above-mentioned embodiment.

[0096] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0097] The present application provides a storage medium, which is a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, and the computer-readable program instructions are used to execute the steps of the offline password generation method and the offline password verification method in the above-mentioned embodiments.

[0098] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0099] The computer-readable storage medium may be included in the offline password generating device; or may exist independently without being assembled into the offline password generating device.

[0100] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the offline password generating device, the offline password generating device implements the technical content of the offline password generating method and offline password verifying method embodiments shown above.

Claims

1. An offline password generation method, characterized in that: The offline password generation method comprises: Get the current hourly timestamp and encryption key; The hourly timestamp is encrypted and calculated using the encryption key through a preset encryption algorithm, and the calculation result is used as the encrypted original text, wherein a number at a preset position is extracted from the encrypted original text as a verification factor; The encrypted original text is encrypted in an FPE format-preserving manner to generate a display password, and the display password is output to the user.

2. The offline password generation method according to claim 1, characterized in that: The step of encrypting and calculating the hourly timestamp using the encryption key through a preset encryption algorithm and taking the calculation result as the encrypted original text comprises: A timestamp parameter extracted from the hourly timestamp, and the timestamp parameter and the initial setting parameter are concatenated into encrypted plaintext; The encrypted plaintext is encrypted with the encryption key, and the encryption result is calculated by the AES encryption algorithm to generate the encrypted original text.

3. The offline password generation method according to claim 1, characterized in that: The steps of performing FPE format-preserving encryption on the encrypted original text to generate a display password, and outputting the display password to the user include: Encrypting the encrypted original text with the encryption key to obtain an encryption result; A tweak fine-tuning parameter is obtained, and the encryption result is calculated using the tweak fine-tuning parameter as a calculation parameter of the FPE encryption algorithm to obtain the display password.

4. The offline password generation method according to claim 1, characterized in that: After the step of extracting a number at a preset position from the encrypted original text as a check factor, the method further includes: The extracted verification factor is saved in a preset storage area.

5. The offline password generation method according to any one of claims 1 to 4, characterized in that: The offline password generation method further comprises: According to the detected device initialization settings, set password generation parameters based on the device, the password generation parameters including initial setting parameters, encryption keys and tweak parameters; Synchronize the device's system time.

6. The offline password generation method according to claim 5, characterized in that: The offline password generation method further comprises: Obtain a preset encryption algorithm from a cloud server, wherein the preset encryption algorithm includes an AES encryption algorithm and an FPE encryption algorithm; The preset encryption algorithm is written into the device.

7. An offline password verification method, characterized in that: The following steps are involved: Receiving a password input by a user, and performing reverse decryption on the input password to obtain an encrypted original text; Obtain the current hourly timestamp, and encrypt the hourly timestamp and the initial setting parameters to obtain the decrypted original text; Comparing the check factors of the encrypted original text and the decrypted original text to determine whether the check factors are consistent; If the verification factors are inconsistent, regenerate the decrypted original text using another hourly timestamp and the initial verification factor; The regenerated decrypted original text is compared with the encrypted original text until the check factors are consistent.

8. The off-line password verification method according to claim 7, characterized in that: The offline password verification method also includes: Counting the number of comparisons of the check factor; When it is determined that the number of comparisons is equal to the preset number of verifications, a password verification failure message is output.

9. An offline password generation device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the offline password generation method according to any one of claims 1 to 6 and the offline password verification method according to any one of claims 7 to 8.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the offline password generation method according to any one of claims 1 to 6 and the offline password verification method according to any one of claims 7-8 are implemented.