Password detection method, server side, user side and password detection system

By saving pre-stored passwords on the server and generating the second key using the same encryption algorithm for decryption, the problem of low security in the symmetric PAKE protocol is solved, and weak password detection is implemented in the asymmetric aPAKE protocol, improving the security of password detection.

CN120090813APending Publication Date: 2025-06-03HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311647843.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-01
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

In the symmetric PAKE protocol, the server can obtain plaintext information of the user password, resulting in low security; while in the asymmetric aPAKE protocol, the server cannot obtain plaintext information of the user password, so it cannot detect whether the user password is a weak password.

Method used

By saving the pre-stored password locally on the server, encrypting each pre-stored password using the same encryption algorithm as the user side, generating a second key, and then decrypting the second key with the ciphertext sent by the user side, determining whether the user password belongs to the target password.

Benefits of technology

It realizes that when the server does not have user password plaintext information, it can detect whether the user password belongs to a weak password or other target password, improves the security of password detection, and also has a weak password testing mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090813A_ABST
    Figure CN120090813A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a password detection method, a server side, a user side and a password detection system, which are applied to the technical field of network security and are used for realizing weak password detection. The method comprises the steps that a server side receives a ciphertext from a user side, the ciphertext comprises a first secret key, and the first secret key is obtained by encrypting a user password by the user side; the server encrypts a pre-stored target password to obtain a second key; the server obtains a target result according to the first key and the second key, wherein the target result is used for indicating whether the user password belongs to a target password; and the server side sends a feedback message to the user side according to the target result. According to the embodiment of the invention, whether the user password is the weak password or not can be detected under the condition that the server has no user password plaintext information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of network security technologies, and in particular, to a password detection method, a server, a user terminal, and a password detection system. Background Art

[0002] Currently, in the information and communications technology (ICT) products, it is required that the authentication server system can test whether the password set by the administrator is a weak password. Generally, the symmetric password-authenticated key (PAKE) protocol is adopted in the industry. In the symmetric PAKE protocol, the server has the plaintext information of the user password, and the server can directly compare the user password with the weak passwords in the database one by one to determine whether the user password is a weak password. However, since the server can obtain the plaintext information of the user password in the symmetric PAKE protocol, the security of the symmetric PAEK protocol is not high.

[0003] The server can use the asymmetric password-authenticated key (aPAKE) protocol to transmit the user password. In the aPAKE protocol, the user terminal encrypts the user password to obtain a ciphertext and sends the ciphertext to the server. The server corresponds the ciphertext obtained by encrypting the user password to the user and stores it on the server. Since the server only has the ciphertext sent by the user terminal and the server does not have the secret key of the user terminal, it is impossible to decrypt the ciphertext according to the secret key to obtain the plaintext information of the user password, ensuring the security of the password transmission.

[0004] However, since the server does not have the plaintext information of the user password in the aPAKE protocol, the server cannot test whether the user password is a weak password. Summary of the Invention

[0005] The embodiments of the present application provide a password detection method, a server, a user terminal, and a password detection system for implementing weak password detection, which can detect whether the user password belongs to the target password when the server does not have the plaintext information of the user password.

[0006] In the first aspect of the embodiment of the present application, a password detection method is provided. In this method, the user registers on the user side, and the user inputs a user identifier and a user password. The user side encrypts the user password using a first encryption algorithm to obtain a first key, and then encrypts the first key to obtain a ciphertext. The server receives the ciphertext sent by the user side. The server locally stores one or more pre-stored passwords, and the pre-stored password belongs to the target password. The target password is used to indicate the type of the password. The server encrypts each pre-stored password using the same second encryption algorithm as the user side to obtain a corresponding second key. The server substitutes the second key and the ciphertext into a decryption algorithm to decrypt and obtain a target result. The target result is used to indicate whether the second key generated by the server according to the target password is the same as the first key in the ciphertext. Then, a corresponding feedback message is sent to the user side according to the target result.

[0007] In the embodiment of the present application, the server compares the second key obtained according to the target password with the first key obtained by the user side according to the user password through the same encryption algorithm, so that the server can judge whether the user password belongs to the target password without knowing the plaintext information of the user password, which enables the server to ensure the security of the password detection protocol and have a target password test mechanism.

[0008] In some optional embodiments, the target password is one or more of a weak password, an exposed password, or a sensitive password. Specifically, the sensitive password is used to indicate a password that includes sensitive words.

[0009] In the embodiment of the present application, when the user password belongs to a weak password, an exposed password, or a sensitive password, the server can feedback to the user side, thereby prompting the user to modify the password, improving the security of password detection.

[0010] In some optional embodiments, the target password can be a password that does not meet the preset rules. When the server successfully decrypts the ciphertext sent by the user side using the second key generated by the preset password belonging to the target password, it proves that the user password does not meet the preset rules.

[0011] In some optional embodiments, the target password can be a password with an entropy value lower than a preset value. The entropy value is an index to measure the amount of information in the password distribution. The higher the entropy value, the more random the password distribution and the higher the security.

[0012] In some optional embodiments, the user side encrypts the first key using the second encryption algorithm to obtain a ciphertext, and the server can use the second key to decrypt the ciphertext sent by the user side.

[0013] Specifically, the server substitutes the second key and the ciphertext into the decryption function. The decryption function corresponds to the second encryption algorithm. If the function value obtained is the first value, it means successful decryption. Therefore, the second key is the same as the first key, that is, the user password is the same as one of the preset passwords in the database. Therefore, the type of the user password is the same as the type of the preset password, and both belong to the target password.

[0014] In the embodiments of the present application, by using the second key generated based on the target password to decrypt the ciphertext, the server can determine whether the user password belongs to the target password without the plaintext information of the user password, avoiding the risk of the server exposing the user password and improving the security of password detection.

[0015] In some alternative embodiments, when the ciphertext is successfully decrypted using the second key, the server sends a first message to the client. The first message is used to indicate that the user password belongs to the target password.

[0016] In the embodiments of the present application, when the server decrypts successfully, the user password is the same as the preset password. Therefore, the security level of the user password is not high. The server sends a first message to the client, so that the client prompts the user to modify the password, improving the security of user registration.

[0017] In some alternative embodiments, if the second value is obtained by the server's decryption function, it means decryption failure, that is, the first key is not the same as any of the second keys.

[0018] In some alternative embodiments, when the ciphertext is decrypted unsuccessfully using the second key, the server sends a second message to the client. The second message is used to indicate that the user password does not belong to the target password. The server stores the ciphertext locally for subsequent login and authentication operations of the corresponding user on the client.

[0019] In the embodiments of the present application, by using the second key generated according to the target password to decrypt the ciphertext of the client, it can be determined whether the first key generated according to the user password is the same as the second key, so as to determine whether the user password belongs to the target password, ensuring the security of password detection.

[0020] In some alternative embodiments, before the server receives the ciphertext from the client, the server also receives the first encrypted value and the user identifier from the client. Since the first encrypted value is obtained by the client encrypting the user password using the third encryption algorithm, the first encrypted value includes the user password. The server operates on the first encrypted value and the local long-term key to obtain the second encrypted value, and then sends the second encrypted value and the server identifier to the client. Since the second encrypted value is calculated according to the long-term key of the server, the client can obtain the long-term key of the server according to the second encrypted value.

[0021] In the embodiments of the present application, since the server sends the long-term key implicitly in the second encrypted value to the client, the long-term key serves as a digital certificate, verifying the legal identity of the server and improving the security of password detection.

[0022] In some alternative embodiments, the server uses a third encryption algorithm to encrypt the target password in the database to obtain a third encrypted value, and then encrypts the third encrypted value and the local long-term key together to obtain a first root key. The server obtains a second key based on the first root key, the user identifier, and the server identifier.

[0023] In the embodiments of the present application, both the second key and the first key are obtained based on the long-term key. Therefore, when the server decrypts the ciphertext using the second key, it can determine whether the target password in the second key is consistent with the user password in the first key.

[0024] The second aspect of the embodiments of the present application provides a password detection method. In this method, the client obtains the user identifier and the user password input by the user. The client uses a first encryption algorithm to encrypt the user password to obtain a first key, and then encrypts the first key according to a second encryption algorithm to obtain a ciphertext. The client sends the ciphertext to the server, so that the server can determine whether the user password belongs to the target password based on the ciphertext and the target password in the database. The client receives the feedback message sent by the server, and the feedback message includes the judgment result of the client on the user password, which is used to indicate whether the user password belongs to the target password.

[0025] In some alternative embodiments, the target password is one or more of a weak password, an exposed password, or a sensitive password. Specifically, the sensitive password is used to indicate a password that includes sensitive words.

[0026] In some alternative embodiments, if the user password belongs to the target password, the client will receive a first message from the server, and the first message is used to indicate that the server has successfully decrypted the ciphertext.

[0027] In the embodiments of the present application, when the client receives the first message, it means that the user password belongs to the target password and the security level of the user password is low. The client can prompt the user to modify the password, thereby improving the security of user registration.

[0028] In some alternative embodiments, if the user password belongs to the target password, the client will receive a second message from the server, and the second message is used to indicate that the server has failed to decrypt the ciphertext, the security level of the user password is high, and the client registration is successful, and subsequent login or authentication operations can be performed.

[0029] In some alternative embodiments, before encrypting the user password using the first encryption algorithm at the client side, the client side blinds the user password based on the user password and a randomly generated blinding factor to obtain a first encrypted value. The client side sends the first encrypted value and the user identifier to the server side. The client side receives the second encrypted value and the server identifier sent by the server side, and the second encrypted value includes the long-term key of the server side.

[0030] In the embodiments of the present application, sending the blinded user password to the server side prevents the user password from being exposed to the server side, thus ensuring the security of password detection.

[0031] In some alternative embodiments, the client side substitutes the user password into the third encryption algorithm to obtain a randomized fourth encrypted value, and then calculates the blinding factor with the fourth encrypted value to obtain the first encrypted value.

[0032] In some alternative embodiments, after receiving the second encrypted value, the client side can obtain a fifth encrypted value based on the second encrypted value and the blinding factor. The blinding factor is removed from the fifth encrypted value, and it only includes the user password and the long-term key of the server side. The client side then obtains a second root key based on the fifth encrypted value, and encrypts the second root key, the user identifier, and the server identifier to obtain the first key.

[0033] In some alternative embodiments, the client side performs the inverse operation of blinding on the second encrypted value to remove the blinding factor from the second encrypted value and obtain the fifth encrypted value.

[0034] In the embodiments of the present application, the client side restores the blinded user password by performing the inverse operation of blinding on the second encrypted value, and at the same time retains the long-term key of the server side in the fifth encrypted value. Thus, the client side obtains the long-term key of the server side without exposing the user password to the server side, improving the security of password detection.

[0035] The third aspect of this embodiment provides a server side, including:

[0036] A receiving unit, configured to receive ciphertext from the client side by the server side, where the ciphertext includes the first key, and the first key is obtained by encrypting the user password by the client side;

[0037] An encryption unit, configured to encrypt a pre-stored target password by the server side to obtain a second key;

[0038] A calculation unit, configured to obtain a target result by the server side based on the first key and the second key, where the target result is used to indicate whether the user password belongs to the target password;

[0039] A sending unit, configured to send a feedback message to the client side by the server side according to the target result.

[0040] The fourth aspect of the embodiments of the present application provides a client, including:

[0041] An encryption unit, configured to encrypt a user password by the client to obtain a first key;

[0042] A sending unit, configured to send a ciphertext by the client to a server, where the ciphertext includes the first key;

[0043] A receiving unit, configured to receive a feedback message from the server by the client, where the feedback message is used to indicate whether the user password belongs to a target password.

[0044] The fifth aspect of the embodiments of the present application provides a server, including:

[0045] A processor and a memory, where the processor is coupled to the memory;

[0046] The memory is configured to store a program;

[0047] The processor is configured to execute the program in the memory, so that the server executes the method described in the first aspect as mentioned above.

[0048] The sixth aspect of the embodiments of the present application provides a client, including:

[0049] A processor and a memory, where the processor is coupled to the memory;

[0050] The memory is configured to store a program;

[0051] The processor is configured to execute the program in the memory, so that the client executes the method described in the second aspect as mentioned above.

[0052] The seventh aspect of the embodiments of the present application provides a password detection system, including:

[0053] The server described in the first aspect as mentioned above, and the client described in the second aspect as mentioned above.

[0054] The eighth aspect of the embodiments of the present application provides a computer-readable storage medium, including instructions, when the instructions run on a computer, enabling the computer to execute the method described in the first aspect as mentioned above, or enabling the computer to execute the method described in the second aspect as mentioned above. Description of the Drawings

[0055] Figure 1 It is a network architecture diagram in the embodiments of the present application;

[0056] Figure 2 It is a schematic diagram of an embodiment of the password detection method in the embodiments of the present application;

[0057] Figure 3Schematic diagram of an embodiment of user authentication and login in the embodiments of the present application;

[0058] Figure 4 Schematic diagram of an embodiment of user data encryption in the embodiments of the present application;

[0059] Figure 5 Schematic diagram of an embodiment of the server in the embodiments of the present application;

[0060] Figure 6 Schematic diagram of an embodiment of the user terminal in the embodiments of the present application;

[0061] Figure 7 Schematic diagram of another embodiment of the server in the embodiments of the present application;

[0062] Figure 8 Schematic diagram of another embodiment of the user terminal in the embodiments of the present application. Detailed implementation manners

[0063] The embodiments of the present application provide a password detection method, a server, a user terminal, and a password detection system, which are applied to the field of network security technology and are used to implement weak password detection.

[0064] Next, the embodiments of the present application will be described with reference to the accompanying drawings. Those skilled in the art know that with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0065] Terms such as "first" and "second" in the specification, claims, and drawings of the present application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing the embodiments of the present application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product, or device including a series of units does not necessarily have to be limited to those units, but may include other units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0066] First, some terms and related technologies involved in the present application will be explained with reference to the accompanying drawings to facilitate understanding by those skilled in the art.

[0067] A key agreement protocol refers to the negotiation among two or more participating parties to jointly establish a session key. Any participant can influence the result without the need for any trusted third party. The two communicating parties can jointly establish a secure shared secret key by transmitting some messages to each other over an open channel. In key agreement, the secret key jointly established by both parties is usually a function of the input messages of both parties.

[0068] Private set intersection (PSI) is a cryptographic technique in secure multi-party computation that allows two parties participating in the computation to calculate the intersection of their data without obtaining additional information about the other party (other information except the intersection).

[0069] Please refer to Figure 1 , and the network architecture on which the password detection method in the embodiments of the present application is based will be briefly described below:

[0070] This network architecture is a "client-server" structure. Multiple clients 101 are connected to the server 102. Users perform registration and login operations through the client 101. Among them, registration means that the client sends user information to the server, and the legal identity and user information of the user are recorded in the server to obtain the qualification to use the services provided by the server on the server. Login means that the user enters the server through the client to use the services provided by the server. The server 102 performs password detection on the registered users and authenticates the logged-in users.

[0071] The client can be a terminal device, such as a mobile phone, a tablet (Pad), a computer with transceiver functions, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a wearable device, a vehicle-mounted device; and a network device, such as a three-layer switch, a router, a broadband gateway, a firewall, a load balancer and other network devices.

[0072] The server, which can also be referred to as a server, can serve the client. For example, the server can provide resources to the client and / or save the client data. The resources can be at least one of text, images, and videos. The server can be a single server or a server cluster, which is not limited in the embodiments of this application. The server can be an application server, that is, an application server that provides services for the user side.

[0073] Based on the standard aPAKE protocol and key negotiation protocol, the embodiments of this application enable the server to detect whether the user password is a weak password without disclosing the clear text information of the user password.

[0074] When registering, the user inputs the user identifier and the user password. The user terminal 101 uses an encryption algorithm to encrypt the user password into the first key, and then constructs a ciphertext with this key. The user terminal 101 sends the ciphertext and the user identifier to the server 102 together. The server 102 uses the same encryption algorithm as the user terminal 101 to generate the corresponding second key according to each preset password, and tries to decrypt the ciphertext with each second key one by one. If the decryption is successful, it means that the user password is the same as one of the preset passwords saved by the server 102. The server 102 sends a message to the user terminal 101 to prompt the user to modify the user password. If the decryption fails, it means that the user password is not the same as any of the preset passwords saved by the server 102, and the user registration is successful. The server saves the user's registration information. When the user corresponding to the user terminal logs in to the server, the server can authenticate the user terminal according to this registration information. Among them, the preset password belongs to the target password, and the target password is one or more of a weak password, an exposed password, or a sensitive password.

[0075] When the user performs a login operation, the server 102 authenticates the user to determine whether the user terminal 101 is a legitimate user. After successful login, the user terminal 101 encrypts the data generated by the user and sends it to the server 102, and then the server 102 decrypts and saves it.

[0076] The server has a long - term key (LTK), a long - term public key (PK), and a long - term secret key (SK). The LTK is used as a digital certificate to prove the identity of the server and at the same time to verify the legitimate identity of the user terminal. PK and SK are a key pair. The server sends PK to the user terminal so that the user terminal uses PK for encryption and the server uses SK for decryption, thus ensuring the security of information transmission.

[0077] When the user registers, the user terminal also generates a long-term public key and a long-term private key. In the embodiments of the present application, x is used to represent the long-term private key of the user terminal, and X is used to represent the long-term public key of the user terminal. When the user logs in, the server authenticates the user terminal. At this time, both the user terminal and the server generate a temporary public key and a temporary private key. In the embodiments of the present application, y1 is used to represent the temporary private key of the user terminal, y2 is used to represent the temporary private key of the server, Y1 is used to represent the temporary public key of the user terminal, and Y2 is used to represent the temporary public key of the server.

[0078] Both the first key and the second key are key encryption keys (KEKs), and the KEKs are generated by the user terminal or the server according to the root key (RK). In the embodiments of the present application, Ke is used to represent the first key, and Ke* is used to represent the second key.

[0079] It can be understood that in the embodiments of the present application, the above representation methods of the keys are only examples. In actual applications, there can be various representation methods for the keys of the user terminal and the server, and specific details are not limited here.

[0080] Based on the above architecture, in the embodiments of the present application, the server 102 can determine whether the user password is the same as the preset password saved by the server 102 without the plaintext information of the user password, so as to detect whether the user password is a weak password. The following separately describes the steps of the user terminal and the server in registration, authentication, login, and encryption:

[0081] I. Registration;

[0082] Please refer to Figure 2 , Figure 2 which is a schematic diagram of an embodiment for password detection during user registration in the embodiments of the present application.

[0083] 201. The user terminal calculates the first encrypted value;

[0084] When the user registers on the user terminal, the user terminal obtains the user password and username input by the user, and the user terminal generates the user identification ID_client according to the username. The user terminal can also generate ID_client according to the encoding of the user terminal device, and specific details are not limited here. The user terminal substitutes the user password into the third encryption algorithm. In actual applications, the third encryption algorithm belongs to the HashToGroup function, and the function value is expressed as:

[0085] HashToG(user password)

[0086] The client generates a random number as a blinding factor to blind the function value, that is, the client performs an operation on the function value and the blinding factor to obtain a first encrypted value. In this embodiment, r is used to represent the blinding factor, and R is used to represent the first encrypted value. There are different mathematical systems corresponding to the HashToGroup function, and the client has different blinding methods according to the constructed mathematical system. For example, R is expressed as:

[0087] R = HashToG(user password)^r

[0088] Or

[0089] R = HashToG(user password)*r

[0090] Specifically, no limitation is made here.

[0091] In this embodiment, since the HashToGroup function makes it difficult to restore the obtained function value to the input value, reducing the risk of the plaintext information of the user password being exposed to the server, the security of password detection is improved.

[0092] 202. The client sends the first encrypted value and the user identifier to the server;

[0093] The server saves ID_client from the client and saves R corresponding to ID_client.

[0094] In this embodiment, since the server cannot obtain r, the server cannot restore R to obtain the plaintext information of the user password, thereby improving the security of password detection.

[0095] 203. The server calculates a second encrypted value;

[0096] The server calculates the second encrypted value by calculating the locally saved LTK and R. This calculation method corresponds to the calculation method of R in step 201. In this embodiment, Y is used to represent the second encrypted value, and Y can be expressed as:

[0097] Y = R^LTK

[0098] Or

[0099] Y = R*LTK

[0100] In this embodiment, LTK has the function of a digital certificate, which is used to prove that the server has the permission to perform registration, authentication, or login. At the same time, the server needs to send LTK to the client so that the client can encrypt the user password according to LTK. The server calculates Y by calculating LTK and R, ensuring the secrecy of the long-term key and improving the security level of password detection.

[0101] 204. The server sends the second encrypted value, the server's long-term public key, and the server identifier to the client;

[0102] Since Y includes the LTK, the server's authority can be proven. The PK is used for subsequent user authentication and login operations. At the same time, in the asymmetric encryption algorithm, the client needs to use the PK for encryption, and the server uses the SK for decryption. Therefore, the server sends the PK to the client so that the client can use the PK for the asymmetric encryption algorithm to encrypt the plaintext information.

[0103] In this embodiment, the client needs to confirm that the server has the registration authority and is not a phishing website, and at the same time, the server needs to confirm that the client is a legitimate user. Therefore, the server includes the LTK in Y and sends it to the client, thus proving the server's identity. After receiving Y, since Y includes the LTK, the client will be recognized as a legitimate user by the server in subsequent authentication and login operations, improving the security of password detection.

[0104] 205. The client calculates the fifth encrypted value;

[0105] After receiving Y, the client calculates the fifth encrypted value according to r. In this embodiment, T is used to represent the fifth encrypted value. The client performs deblinding on Y, that is, the inverse operation of blinding Y, to obtain T. If R is:

[0106] R = HashToG(user password)^r

[0107] Then T is:

[0108] T = Y^(1 / r) = HashToG(user password)^LTK

[0109] If R is:

[0110] R = HashToG(user password)*r

[0111] Then T is:

[0112] T = Y*(1 / r) = HashToG(user password)*LTK

[0113] In this embodiment, the client needs to use the server's LTK to verify the server's identity. Through the blinding operation, the client enables the server to obtain the server's LTK without being able to obtain the plaintext information of the user password, improving the security of password detection.

[0114] 206. Generate the first key Ke;

[0115] The client generates RK based on T. In this embodiment, RK1 represents the RK generated by the client, and RK2 represents the RK generated by the server. The client generates Ke based on RK1.

[0116] Specifically, the client can substitute T and the hash value of the user password Hash(user password) into a pseudo-random function (PRF) to generate RK1:

[0117] RK1 = PRF(T, Hash(user password))

[0118] In practical applications, T can also be substituted into the PRF together with other random numbers generated based on the user password. Specifically, it is not limited here.

[0119] The client derives Ke from RK1 through a key derivation function (KDF). Among them, the client substitutes ID_client, ID_server, and a fixed string as a salt value into the KDF. Ke is expressed as:

[0120] Ke = KDF(RK1, ID-client || ID_server || REGENC)

[0121] In practical applications, the fixed string can be set by the server. The fixed string in the above formula is only an example, and the form of the fixed string is not limited in the embodiments of this application.

[0122] In this embodiment, the client encrypts T using PRF and then derives the first Ke from the second root key RK using KDF, which increases the computing resources required to crack the key, prevents brute-force cracking, and improves the security of the first key Ke.

[0123] 207. The client generates a first ciphertext and a second ciphertext;

[0124] The client generates x, and then operates x with the generator to obtain X. The generator is represented by g. The calculation method of X corresponds to the calculation method of R in step 201. In a possible implementation manner, X is expressed as:

[0125] X = g^x

[0126] Or

[0127] X = g * x

[0128] The client uses Ke as the key for the first ciphertext, and uses x, X, ID_client, and PK as the first plaintext information of the first ciphertext, and encrypts them using a symmetric encryption algorithm. In this embodiment, the first ciphertext is denoted as C1. In practical applications, the client can use the Galois / Counter Mode (GCM) in the Advanced Encryption Standard (AES) algorithm to encrypt the first plaintext information, and C1 is expressed as

[0129] C1 = AES-GCM(Ke, x||X||ID_client||PK)

[0130] It can be understood that the client can also use the Data Encryption Standard (DES) algorithm to encrypt the first plaintext information, or use the Triple Data Encryption Algorithm (3DES) to encrypt the first plaintext information, and the specific method is not limited here.

[0131] The client then uses the PK of the server as the key for the second ciphertext, and uses ID_client, ID_server, and X as the second plaintext information, and encrypts them using an asymmetric encryption algorithm. In the embodiment of this application, the second ciphertext is denoted as C2. In practical applications, the client can use the Elliptic Curve Integrated Encryption Scheme (ECIES) algorithm to encrypt the second plaintext information, and C2 is expressed as

[0132] C2 = ECIES(PK, ID_client||ID_server||X)

[0133] It can be understood that the client can also use the RSA encryption algorithm to encrypt the second plaintext information, or use the Digital Signature Algorithm (DSA) to encrypt the second plaintext information, and the specific method is not limited here.

[0134] In this embodiment, the client uses a symmetric encryption algorithm to encrypt the first plaintext information, so that when the server and the client have the same key, the server can decrypt C1. Based on this, the server can determine whether the user password is a weak password without knowing the plaintext information of the user password, improving the security of password detection.

[0135] In this embodiment, x and X are only examples. In actual applications, the long-term private key and long-term public key of the client can have various representation forms. For example, a is used to represent the long-term private key of the client, A is used to represent the long-term public key of the client, or SA is used to represent the long-term private key of the client, and PA is used to represent the long-term public key of the client. Specifically, it is not limited here.

[0136] 208. The client sends the user identifier, the first ciphertext, and the second ciphertext to the server.

[0137] The client sends ID_client to the server to prove the user's identity. C1 is used for the server to detect whether the user password is a weak password, and C2 is used for the server to authenticate the subsequent login operation of the client.

[0138] 209. The server generates the second key.

[0139] The server locally stores multiple preset passwords. In actual applications, the server substitutes each preset password into the third encryption algorithm, and the function value is expressed as:

[0140] HashToG(target password)

[0141] The server then performs an operation on each function value and K to obtain multiple third encryption values. In this embodiment, the third encryption value is represented by T * represented as, T * is represented as:

[0142] T * = HashToG(target password)^LTK

[0143] Or

[0144] T * = HashToG(target password)*LTK

[0145] The server substitutes each T * and the hash value Hash(target password) of the corresponding preset password into the PRF to obtain multiple RK2, and RK2 is represented as:

[0146] RK2 = PRF(T * , Hash(target password))

[0147] The server derives Ke * from each RK * through KDF. Among them, the server substitutes ID_client, ID_server, and a string of fixed strings as salt values into the KDF, and Ke * is represented as:

[0148] Ke *= KDF(RK2, ID_client||ID_server||REGENC)

[0149] In this embodiment, step 209 may be executed after step 208, or may be executed before step 208 and after step 202. Specifically, there is no limitation here.

[0150] 210. The server decrypts the first ciphertext using the second key;

[0151] The server substitutes different Ke * into the decryption function to decrypt C1, and obtains:

[0152] Dec(Ke * , C1)

[0153] where Dec represents the decryption function, Ke * is the key used for decryption, and C1 is the ciphertext to be decrypted.

[0154] Since the client encrypts C1 using the symmetric encryption algorithm, when Ke * is the same as Ke, the decryption function obtains the first value, indicating successful decryption, that is, the user password belongs to one or more of weak keys, exposed keys, or sensitive passwords including sensitive words, and step 211 is executed. When Ke * is different from Ke, the decryption function obtains the second value, indicating decryption failure, that is, the user password is different from any of the preset passwords, and step 212 is executed.

[0155] In practical applications, the first value and the second value can have various representation methods. For example, the first value is 1 indicating successful decryption, the second value is 0 indicating decryption failure, or the first value is success indicating successful decryption, and the second value is fail indicating decryption failure. Specifically, there is no limitation here.

[0156] 211. The server sends a first message to the client;

[0157] The decryption function obtains the first value, the server terminates the program, saves ID_client and C1, deletes C2, and sends a first message to the client. The first message is used to indicate that the user registration fails. After receiving the first message, the client prompts the user to modify the user password.

[0158] 212. The server sends a second message to the client;

[0159] The server substitutes all Ke * into the decryption function and all obtain the second value. The server saves the ID_client, C1, and C2 sent by the client and sends a second message to the client. The second message is used to indicate that the user registration is successful.

[0160] In this embodiment, the server detects whether the user password is a weak password by using Ke * to decrypt C1, which avoids exposing the plaintext information of the user password to the server and improves the security of password detection.

[0161] It can be understood that in this embodiment, the target password can be a password that does not meet the preset rules. For example, if the preset rule is that the password should include at least 4 characters, then the preset passwords include all passwords with the number of characters from 0 to 3. When the server uses Ke * to successfully decrypt C1, it proves that the user password belongs to the target password and the user password does not meet the preset rules. If the server cannot use Ke * to decrypt C1, it proves that the user password meets the preset rules. Therefore, this embodiment can detect whether the user password meets the preset rules without exposing the plaintext information of the user password.

[0162] In practical applications, the target password can also be a password with an entropy value lower than the preset value, an exposed password, or a password including sensitive words, which is not specifically limited here.

[0163] In the embodiment of the present application, the aPAKE protocol and PSI are combined to achieve high-security asymmetric password two-way authentication and session key negotiation. At the same time, the server can achieve the business goal of testing the user's weak password without knowing the plaintext information of the user password, thereby avoiding the security risks brought by the traditional PAKE protocol, improving security, and filling the functional gap of the standard aPAKE protocol in this regard.

[0164] II. Authentication and login;

[0165] Please refer to Figure 3 , Figure 3 which is a schematic diagram of the embodiment of the server authenticating the user login in the embodiment of the present application.

[0166] 301. The client calculates the sixth encrypted value and the temporary public key of the client;

[0167] The client obtains the user password and username input by the user and generates ID_client. The client substitutes ID_client and the user password into the third encryption algorithm to obtain a function value:

[0168] HashToG(user password || ID_client)

[0169] The client generates a random number and y1, and uses the random number as a blinding factor to blind the function value to obtain the sixth encrypted value. In this embodiment, r1 represents the blinding factor and R1 represents the sixth encrypted value. According to the mathematical system used by the HashToG function, R1 is expressed as:

[0170] R1 = HashToG(user password || ID_client) ^ r1

[0171] or

[0172] R1 = HashToG(user password || ID_client) * r1

[0173] The client then calculates Y1 based on y1 and the generator. In this embodiment, the generator is denoted as g, and Y1 is expressed as:

[0174] Y1 = g ^ y1

[0175] or

[0176] Y1 = g * y1

[0177] 302. The client sends the user identifier, the sixth encrypted value, and the client's temporary public key to the server;

[0178] The server receives ID_client, R1, and Y1 from the client, and retrieves the corresponding C1 and C2 from the database according to ID_client.

[0179] 303. Calculate the seventh encrypted value and the server's temporary public key;

[0180] The server performs an operation on the R1 sent by the client and the LTK to obtain the seventh encrypted value. The seventh encrypted value is denoted as W1, and W1 is expressed as:

[0181] W1 = R1 ^ K

[0182] or

[0183] W1 = R1 * K

[0184] The server generates a random y2, and obtains Y2 based on y2 and the generator. The generator is denoted as g, and Y2 is expressed as:

[0185] Y2 = g ^ y2

[0186] or

[0187] Y2 = g * y2

[0188] 304. The server sends the server identifier, the seventh encrypted value, the first ciphertext, and the server's temporary public key to the client;

[0189] The client de - blinds W1 to obtain the seventh encrypted value. The seventh encrypted value is denoted as T1, and T1 is expressed as:

[0190] T1 = W1 ^ (1 / r1)

[0191] or

[0192] T1 = W1 * (1 / r1)

[0193] The client generates the third key RK3 through PRF according to T1, and RK3 is:

[0194] RK3 = PRF(T1, Hash(user password))

[0195] The client derives the third key from RK3 through KDF. The third key is represented by Kel. Among them, the client substitutes ID_client, ID_server, and a fixed string as the salt value into KDF, and Kel is expressed as:

[0196] Ke1 = KDF(RK3, ID_client || ID_server || REGENC)

[0197] The client substitutes Ke1 into the AES algorithm to decrypt C1 to obtain the first plaintext information. If the user password entered by the user is the same as the user password in C1 saved by the server, the decryption is successful. If the user password entered by the user is different from the user password in the first ciphertext C1, the decryption fails, which is specifically expressed as:

[0198] AES - GCM(Ke1, C1) = x || X || ID_client || PK

[0199] When the decryption of C1 fails, the client prompts that the user password input is incorrect and re - executes step 301 until the decryption of C1 is successful.

[0200] 305. The server calculates the first authentication parameter;

[0201] The SK and PK of the server are a key pair, and the key of C2 is the PK of the server. Therefore, the server can use SK to decrypt C2 to obtain the second plaintext information, and the second plaintext information includes X of the client.

[0202] The server calculates the master key according to SK, y2, X, and Y1. The master key of the server is represented by mk1, and mk1 is expressed as:

[0203] mk1 = X ^ SK || Y1 ^ SK || X ^ y2 || Y1 ^ y2

[0204] Or

[0205] mk1 = X * SK || Y1 * SK || X * y2 || Y1 * y2

[0206] Among them, mk1 consists of four parts. The first part is X and SK, the second part is Y1 and SK, the third part is X and y2, and the fourth part is Y1 and y2. When mk1 is obtained by power operation, the public key is the base and the private key is the exponent.

[0207] In the embodiments of the present application, by using four keys to form mk1 for authentication, it can be detected whether the user has all the keys, improving the security of user authentication.

[0208] The server generates a message authentication code key (K_MAC) according to mk1. K_MAC is used to protect the data security during the communication process and is obtained by PRF according to mk1, R1, W1, Y1, Y2, ID_client, ID_server and a fixed string. The K_MAC of the server is specifically expressed as:

[0209] K_MAC = PRF(mk1, R1||W1||Y1||Y2||ID_client||ID_server||″MAC″)

[0210] The server generates an authentication parameter (authentication, Auth) according to K_MAC. This authentication parameter is the first authentication parameter and is represented by Auth1. The server uses a symmetric encryption algorithm and encrypts using the K_MAC of the server as the key. Auth1 is expressed as:

[0211] Auth1 = AES - GCM(K_MAC, R1||W1||Y1||Y2||ID_client||ID_server||″server″)

[0212] In this embodiment, the timing sequence of step 305 and step 304 is not limited. Step 305 can be executed before step 304 or after step 304, and it is not specifically limited here.

[0213] 306. The server sends the first authentication parameter to the client;

[0214] The server sends Auth1 to the client, enabling the client to authenticate the server.

[0215] 307. The client compares the first authentication parameter with the second authentication parameter;

[0216] The client calculates MK according to PK, x, y1 and Y2. The MK of the client is represented by mk2, and mk2 is expressed as:

[0217] mk2 = PK^x||PK^y1||Y2^x||Y2^y1

[0218] or

[0219] mk2 = PK * x || PK * y1 || Y2 * x || Y2 * y1

[0220] The client calculates K_MAC based on mk2. The K_MAC of the client is expressed as:

[0221] K_MAC = PRF(mk2, R1 || W1 || Y1 || Y2 || ID_client || ID_server || "MAC")

[0222] The client uses the symmetric encryption algorithm to encrypt with the K_MAC of the client as the key to obtain the second authentication parameter. The second authentication parameter is represented by Auth1 * represented by, Auth1 * is expressed as:

[0223] Auth1 * = AES - GCM(K_MAC, R1 || W1 || Y1 || Y2 || ID_client || ID_server || "server")

[0224] If the Auth1 generated by the client * is the same as the Auth1 from the server, the client's authentication of the server is successful; if Auth1 * is different from Auth1, the client's authentication of the server fails, and the identity of this server is illegal.

[0225] 308. The client calculates the third authentication parameter;

[0226] The client uses the symmetric encryption algorithm to encrypt with the K_MAC of the client as the key to obtain the third authentication parameter. The third authentication parameter is represented by Auth2, and Auth2 is expressed as:

[0227] Auth2 = AES - GCM(K_MAC, R1 || W1 || Y1 || Y2 || ID_client || ID_server || "client")

[0228] Auth2 is used for the server to authenticate the client.

[0229] 309. The client sends the third authentication parameter to the server;

[0230] The client sends the third authentication parameter to the server to enable the server to authenticate the client.

[0231] 310. The server compares the third authentication parameter with the fourth authentication parameter;

[0232] The server generates a fourth authentication parameter based on K_MAC, denoted as Auth2*. The server uses a symmetric encryption algorithm and encrypts using the server's K_MAC as the key, and Auth2 * is expressed as:

[0233] Auth2 * = AES-GCM(K_MAC, R1||W1||Y1||Y2||ID_client||ID_server||″client″)

[0234] If the Auth2 generated by the client is the same as the Auth2 from the server * the server successfully authenticates the client and executes step 311; if Auth2 and Auth2 * are different, the server fails to authenticate the client, the identity of the client is illegal, and step 312 is executed.

[0235] 311. The server sends a login success message to the client;

[0236] If the client successfully verifies the server and the server successfully verifies the client, the server sends a login success message to the client, indicating that the username and user password entered by the user are the same as the data saved by the server, and the user logs in successfully.

[0237] 312. The server sends a login failure message to the client;

[0238] If the client fails to verify the server or the server fails to verify the client, the server sends a login failure message to the client, indicating that the username or user password entered by the user is incorrect, and prompts the user to re-enter.

[0239] III. Encryption

[0240] Please refer to Figure 4 , Figure 4 which is a schematic diagram of an embodiment of user data encryption in the embodiment of the present application.

[0241] 401. The client generates an encryption key;

[0242] The client generates an encryption key (encryption key, K_ENC) through PRF based on mk2 generated during authentication, and K_ENC is expressed as:

[0243] K_ENC = PRF(mk2, R1||W1||Y1||Y2||ID_client||ID_server||″ENC″)

[0244] 402. The client encrypts the data generated by the user using an encryption key;

[0245] The client obtains the data generated by the user and encrypts the data through a symmetric encryption algorithm, specifically expressed as:

[0246] AES_GCM(K_ENC, m)

[0247] Where m represents the data that the client needs to encrypt. In practical applications, the client can also use K_ENC and K_MAC to encrypt the user data, and specific details are not limited here.

[0248] 403. The client sends the encrypted data to the server;

[0249] Since the client uses a symmetric encryption algorithm to encrypt the user data, the encrypted data can only be decrypted by K_ENC to obtain the user data, and terminals without K_ENC cannot obtain the user data, ensuring the security of the user data.

[0250] 404. The server generates an encryption key;

[0251] The server generates K_ENC through PRF based on mk1 generated during authentication. K_ENC is expressed as:

[0252] K_ENC = PRF(mk1, R1||W1||Y1||Y2||ID_client||ID_server||″ENC″)

[0253] Since the mutual authentication between the client and the server is successful, mk1 and mk2 are the same, and the K_ENC generated by the client is the same as the K_ENC generated by the server.

[0254] 405. The server decrypts the encrypted data using the encryption key.

[0255] The server can use K_ENC to decrypt the encrypted data, obtain the user data therein, and save the user data locally on the server.

[0256] In this embodiment, the client and the server construct a secure transmission channel by generating K_ENC, enabling the user data to be securely transmitted from the client to the server and ensuring the security of data transmission.

[0257] The above describes the password detection method in the embodiments of the present application. Next, the server and the client in the embodiments of the present application are described.

[0258] Please refer to Figure 5 , an embodiment of the server in the embodiments of the present application includes:

[0259] A receiving unit 501, configured to receive a ciphertext from a client. The ciphertext is obtained by encrypting based on a first key, and the first key is obtained by encrypting a user password based on a first encryption algorithm.

[0260] An encryption unit 502, configured to encrypt a pre-stored target password using the first encryption algorithm to obtain a second key.

[0261] A calculation unit 503, configured to determine whether the user password belongs to the target password according to the ciphertext and the second key.

[0262] A sending unit 504, configured to send a feedback message to the client, where the feedback message is used to indicate whether the user password belongs to the target password.

[0263] Please refer to Figure 6 , an embodiment of the client in the embodiments of the present application includes:

[0264] An encryption unit 601, configured to encrypt a user password using the first encryption algorithm to obtain a first key.

[0265] A sending unit 602, configured to send a ciphertext to a server. The ciphertext is obtained by the client encrypting the first key using a second encryption algorithm.

[0266] A receiving unit 603, configured to receive a feedback message from the server. The feedback message is used to indicate whether the user password belongs to a target password, and the target password is used to indicate the type of the password.

[0267] Please refer to Figure 7 , another embodiment of the server in the embodiments of the present application includes:

[0268] Figure 7 FIG. is a schematic structural diagram of a server provided by an embodiment of the present application. The server 700 may include one or more central processing units (CPUs) 701 and a memory 705. One or more application programs or data are stored in the memory 705.

[0269] Among them, the memory 705 may be volatile storage or persistent storage. The program stored in the memory 705 may include one or more modules, and each module may include a series of instruction operations on the server. Further, the central processor 701 may be set to communicate with the memory 705 and execute a series of instruction operations in the memory 705 on the server 700.

[0270] The server 700 may also include one or more power supplies 702, one or more wired or wireless network interfaces 703, one or more input / output interfaces 704, and / or one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0271] The central processing unit 701 may perform the operations executed by the server in the foregoing embodiments, which will not be elaborated herein.

[0272] Please refer to Figure 8 , another embodiment of the client in the embodiments of the present application includes:

[0273] Figure 8 FIG. is a schematic structural diagram of a client provided by an embodiment of the present application. The client 800 may include one or more central processing units (CPUs) 801 and a memory 805, and one or more applications or data are stored in the memory 805.

[0274] Among them, the memory 805 may be volatile storage or persistent storage. The programs stored in the memory 805 may include one or more modules, and each module may include a series of instruction operations on the server. Further, the central processing unit 801 may be configured to communicate with the memory 805 and execute a series of instruction operations in the memory 805 on the client 800.

[0275] The client 800 may also include one or more power supplies 802, one or more wired or wireless network interfaces 803, one or more input / output interfaces 804, and / or one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0276] The central processing unit 801 may perform the operations executed by the client in the foregoing embodiments, which will not be elaborated herein.

[0277] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above may refer to the corresponding processes in the foregoing method embodiments, which will not be elaborated herein.

[0278] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical, or other forms.

[0279] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0280] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0281] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

Claims

1. A password detection method, characterized in that, the method includes: The server receives a ciphertext from the client, the ciphertext is encrypted based on a first key, and the first key is obtained by encrypting the user password using a first encryption algorithm; The server uses the first encryption algorithm to encrypt a pre-stored target password to obtain a second key; The server determines whether the user password belongs to the target password according to the ciphertext and the second key; The server sends a feedback message to the client, and the feedback message is used to indicate whether the user password belongs to the target password.

2. The password detection method according to claim 1, characterized in that, The target password is one or more of a weak password, an exposed password, or a sensitive password, and the sensitive password is a password including sensitive words.

3. The password detection method according to claim 1 or 2, characterized in that, The ciphertext is calculated by the first key based on a second encryption algorithm; The server determines whether the user password belongs to the target password according to the ciphertext and the second key, including: The server substitutes the second key and the ciphertext into a decryption algorithm, and uses the second key to decrypt the ciphertext, and the decryption algorithm corresponds to the second encryption algorithm; If the decryption is successful, the second key is the same as the first key, and the user password belongs to the target password.

4. The password detection method according to claim 3, characterized in that, The server sends a feedback message to the client according to the target result, including: The server sends a first message to the client, and the first message is used to indicate that the user password belongs to the target password.

5. The password detection method according to claim 3, characterized in that, After the server substitutes the second key and the ciphertext into a decryption algorithm and uses the second key to decrypt the ciphertext, the method further includes: If the decryption fails, the second key is different from the first key, and the user password does not belong to the target password.

6. The password detection method according to claim 5, characterized in that, The server sends a feedback message to the client according to the target result, including: The server sends a second message to the client, and the second message is used to indicate that the user password does not belong to the target password; The server stores the ciphertext, and the ciphertext is used for the server to authenticate the client when the client logs in.

7. The password detection method according to any one of claims 1 to 6, characterized in that, Before the server receives the ciphertext from the client, the method further includes: The server receives a first encrypted value and a user identifier from the client, the first encrypted value is encrypted by the user password using a third encryption algorithm, and the user identifier is used to identify the user corresponding to the user password; The server obtains a second encrypted value based on the long-term key of the server and the first encrypted value, and the long-term key of the server is used by the client to encrypt the user password; The server sends the second encrypted value and the server identifier to the client.

8. The password detection method according to claim 7, wherein, The server encrypts the pre-stored target password using the first encryption algorithm to obtain a second key, including: The server encrypts the pre-stored target password using the third encryption algorithm to obtain a third encrypted value; The server obtains a first root key according to the third encrypted value and the long-term key of the server; The server substitutes the first root key, the user identifier, and the server identifier into the first encryption algorithm to obtain the second key.

9. A password detection method, wherein, The method includes: The client encrypts the user password using the first encryption algorithm to obtain a first key; The client sends a ciphertext to the server, and the ciphertext is obtained by the client encrypting the first key using the second encryption algorithm; The client receives a feedback message from the server, and the feedback message is used to indicate whether the user password belongs to the target password.

10. The password detection method according to claim 9, wherein, The target password is one or more of a weak password, an exposed password, or a sensitive password, and the sensitive password is a password including sensitive words.

11. The password detection method according to claim 9 or 10, wherein, The client receives a feedback message from the server, including: The client receives a first message from the server, and the first message is used to indicate that the user password belongs to the target password.

12. The password detection method according to claim 9 or 10, wherein, The client receives a feedback message from the server, including: The client receives a second message from the server, and the second message is used to indicate that the user password does not belong to the target password.

13. The password detection method according to any one of claims 9 to 12, wherein, Before encrypting the user password using the first encryption algorithm to obtain the first key, the method further includes: The client calculates a first encrypted value according to the user password and a blinding factor; The client sends the first encrypted value and the user identifier to the server; The client receives a second encrypted value and a server identifier from the server, and the second encrypted value includes the long-term key of the server.

14. The password detection method according to claim 13, wherein, The client calculates a first encrypted value according to the user password and a blinding factor, including: The client substitutes the user password into the third encryption algorithm to obtain a fourth encrypted value; The client blinds the fourth encrypted value using the blinding factor to obtain the first encrypted value.

15. The password detection method according to claim 13 or 14, wherein, The client encrypts the user password to obtain a first key, including: The client obtains a fifth encrypted value according to the second encrypted value and the blinding factor; The client obtains a second root key according to the fourth encrypted value; The client obtains the first key according to the second root key, the user identifier, and the server identifier.

16. The password detection method according to claim 15, wherein, The client obtains a fifth encrypted value according to the second encrypted value and the blinding factor, including: The client removes the blinding factor from the second encrypted value to obtain the fifth encrypted value.

17. A server, wherein, including: A receiving unit, configured to receive a ciphertext from a client, the ciphertext being encrypted based on a first key, and the first key being obtained by encrypting a user password using a first encryption algorithm; An encryption unit, configured to encrypt a pre-stored target password using the first encryption algorithm to obtain a second key; A judgment unit, configured to judge whether the user password belongs to the target password according to the ciphertext and the second key; A sending unit, configured to send a feedback message to the client, the feedback message being used to indicate whether the user password belongs to the target password.

18. A client, wherein, including: An encryption unit, configured to encrypt a user password using a first encryption algorithm to obtain a first key; A sending unit, configured to send a ciphertext to a server, the ciphertext being encrypted by the client using a second encryption algorithm for the first key; A receiving unit, configured to receive a feedback message from the server, the feedback message being used to indicate whether the user password belongs to a target password.

19. A server, wherein, including: A processor and a memory, the processor being coupled to the memory; The memory is used for storing programs; The processor is configured to execute the programs in the memory, so that the server executes the method according to any one of claims 1 to 8.

20. A client, wherein, including: A processor and a memory, the processor being coupled to the memory; The memory is used for storing programs; The processor is configured to execute the programs in the memory, so that the client executes the method according to any one of claims 9 to 16.

21. A password detection system, wherein, including a client and a server, wherein, The client is configured to encrypt a user password using a first encryption algorithm to obtain a first key; The client is further configured to send a ciphertext to the server, the ciphertext being encrypted by the client using a second encryption algorithm for the first key; The server is configured to receive the ciphertext from the client; The server is further configured to encrypt a pre-stored target password using the first encryption algorithm to obtain a second key; The server is further configured to judge whether the user password belongs to the target password according to the ciphertext and the second key; The server is further configured to send a feedback message to the client, where the feedback message is used to indicate whether the user password belongs to the target password; The client is further configured to receive the feedback message from the server.

22. A computer-readable storage medium, comprising instructions that, when run on a computer, cause the computer to execute the method according to any one of claims 1 to 8, or cause the computer to execute the method according to any one of claims 9 to 16.