Full-period password distribution management system for airport information security management

By introducing a full-cycle password distribution management system into the airport information security management system, using the interaction between fingerprint cipher and management software, the problems of easy leakage and inconvenience in passwords in the existing technology are solved, and automatic password input and full life cycle management are realized, and security and operation efficiency are improved.

CN120128340APending Publication Date: 2025-06-10BEIJING JINGHANGAN AIRPORT ENG CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510602751.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing password management system has problems such as password leakage and illegal access during password use, and lacks effective management of the entire life cycle of the password.

Method used

It provides a full-cycle password distribution management system for airport information security management. Through the interaction of fingerprint password and management software, it realizes automatic password input, full life cycle management and secure destruction.

Benefits of technology

It reduces the risk of password leakage and loss, improves password security and operation efficiency, and meets the high standards for password security in airport information security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128340A_ABST
    Figure CN120128340A_ABST
Patent Text Reader

Abstract

The invention provides a full-cycle password distribution management system for airport information security management, which comprises a fingerprint cipherer and a management end, and is characterized in that the management end comprises a password creation and initialization module, a password generation module, an initialization module and an encryption storage module which are connected with one another; the log recording and auditing module is used for inputting and binding user fingerprint information and creating a log record for storing the whole process of password operation; the password distribution module distributes the password to the fingerprint cipherer; the password using module is used for connecting the fingerprint cipherer with a management end through a USB (Universal Serial Bus) interface and automatically inputting a password into the management end by clicking an input key; the password automatic updating module is used for password period management, expiration processing and real-time monitoring; and the password safety destroying module is used for regularly destroying passwords, triggering destroying and carrying out emergency processing operation. According to the method and the device, automatic password input is realized, the risk of password leakage or loss is reduced, full-life-cycle management can be carried out on the password, and the password safety and the operation efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of password management, and particularly to a full-cycle password distribution management system for airport information security management. Background Art

[0002] Airport information security management refers to security protection measures for information systems, networks, and data within the airport area, ensuring the stability of airport operations, the confidentiality, integrity, and availability of data. It mainly focuses on the information security within the airport, including passenger information protection, flight data security, equipment operation monitoring, etc. In airport information security management, the password management system plays a core role. The password management system is an infrastructure for centralized management of keys and password policies. It ensures the security and compliance of passwords through technical means and process specifications to meet information security compliance requirements.

[0003] Existing password management systems mainly generate, store, and manage passwords through software systems or hardware security modules (HSMs). However, there are still problems such as easy password leakage and illegal access to the system in existing password management systems. For example, during the password usage process, it still relies on conventional usage operation processes such as manual password memorization (passwords are easily lost), keyboard password entry (easily stolen), and manual password replacement (prone to human errors). Moreover, when logging in to the system, there is no user authentication, and there is no record during the usage process, resulting in the inability to detect illegal intrusion, information being stolen, and posing security risks. Summary of the Invention

[0004] In order to overcome the deficiencies of the prior art, the purpose of the present invention is to provide a full-cycle password distribution management system for airport information security management. Through the interaction between the management software and the fingerprint password device, it not only realizes the automatic input of passwords, simplifies the manual input link, reduces the risk of password leakage or loss, but also can manage the entire life cycle of passwords, improve the security and operation efficiency of passwords, and meet the high-standard requirements for password security in airport information security management.

[0005] To achieve the above purpose, the present invention provides the following solution: A full-cycle password distribution management system for airport information security management, including a fingerprint password device for automatically inputting, storing, and transmitting passwords and a management terminal connected to the fingerprint password device. The fingerprint password device is connected to the management terminal through a USB interface or a dedicated communication protocol. The management terminal includes: A password creation and initialization module, which is used to generate passwords by combining quantum random number seeds and using a hardware security module or a random number generator, and then write the passwords into the fingerprint password device for password initialization and encrypted storage; A logging and auditing module, which is used to enter and bind user fingerprint information through a secure channel and create a log record of the entire process of storing password operations when the fingerprint password device is used for the first time; A password distribution module, which is used to initiate a password distribution request and distribute the corresponding password to the fingerprint password device in an online or offline manner according to the password distribution request; A password usage module, which is used to connect the fingerprint password device to the management terminal through a USB interface and click the input button on the fingerprint password device to automatically input the password into the password input box of the management terminal; A password automatic update module, which is used to perform periodic management and expiration processing of passwords and monitor the abnormal usage of passwords in real time; A password security destruction module, which is used to build a password regular destruction mechanism, a destruction trigger mechanism and an emergency handling mechanism to complete password security processing; Among them, the password creation and initialization module, the logging and auditing module, the password distribution module, the password usage module, the password automatic update module, and the password security destruction module are interconnected with each other.

[0006] Optionally, the fingerprint password device includes a portable shell, an anti-peeping screen arranged on the front of the portable shell, a USB interface arranged on the side of the portable shell, a fingerprint recognition area arranged on the back of the portable shell, and an embedded microcontroller, a fingerprint sensor, an anti-disassembly sensor and a security chip for password storage and encryption processing arranged inside the portable shell.

[0007] Optionally, the security chip includes a user login key partition, an operation authorization key partition and a system destruction key partition.

[0008] Optionally, the password creation and initialization module includes: A password generation unit, which is used to set password policy configuration options on the management terminal, generate a password by combining a quantum random number seed according to the password policy configuration options by using a hardware security module or a random number generator, and then store the generated password and password metadata in an encrypted database through symmetric encryption; the password policy configuration options include password length, password complexity, password validity period and password usage; A password initialization unit, which is used to select the fingerprint password device that needs to be initialized, connect the selected fingerprint password device to the management terminal, and exchange a temporary session password. The management terminal verifies whether the identity of the selected fingerprint password device is legal. If so, the generated password is transmitted to the selected fingerprint password device through an encrypted channel to complete the password initialization operation; A password writing unit, which is used to bind the generated password with the identification code of the selected fingerprint password device, encrypt and store the password using the security chip built in the selected fingerprint password device, and then return the metadata of the password to the management terminal to complete the password writing operation.

[0009] Optionally, the log recording and auditing module includes: A fingerprint input and binding unit, which is used to input user fingerprint information through a secure channel when the fingerprint password device is used for the first time, bind the user fingerprint information with the identification code of the fingerprint password device, and store it in the built-in security chip; A log recording and auditing unit, which is used to create a log record of the entire process of storing passwords and store the log record in the encrypted database; the log record includes the operation time, operation type, responsible administrator ID, fingerprint password device serial number, password usage, and password policy, and the operation type includes password creation operation, password writing operation, and fingerprint input operation.

[0010] Optionally, the password distribution module includes: A login and verification unit, which is used to log in to the management terminal through multi-factor authentication, verify the administrator's permissions after logging in, and select the password and distribution object to be distributed; the multi-factor authentication includes password, fingerprint, and dynamic verification code; A distribution method selection unit, which is used to perform online password distribution using an encrypted communication channel and offline password distribution using a USB interface; A distribution confirmation unit, which is used to generate a distribution task summary before distribution. After the administrator confirms, it starts the password distribution process and generates a distribution operation log; the distribution operation log includes the distribution time, distribution object, distribution method, fingerprint verification result, and responsible administrator ID.

[0011] Optionally, the password usage module includes: A password automatic input unit, which is used to connect the fingerprint password device to the management terminal through a USB interface. The operator inputs a fingerprint to unlock in the fingerprint recognition area and clicks the input button, and the fingerprint password device automatically transmits the target password to the password input box; An offline viewing unit, which is used to display part of the password content of the fingerprint password device after the first fingerprint unlock in an offline environment, and display the complete password within a short time after the second fingerprint unlock.

[0012] Optionally, the password automatic update module includes: A password cycle management unit, which is used to create a password version number and set a password validity period when generating and updating passwords. Before the password expires, it automatically sends a password expiration reminder to the administrator; A password update and synchronization unit, which is used to initiate a password update request at the management end. According to the password update request, it automatically generates a new password and a new password version number, and marks the old password as to-be-deleted status to regularly and automatically clean up the to-be-deleted passwords; A usage monitoring unit, which is used to monitor the password usage situation in real time according to the password version number and detect abnormal usage behaviors.

[0013] Optionally, the password security destruction module includes: A regular destruction unit, which is used to generate a destruction task. According to the destruction task, it calls the destruction interface of the encrypted database, uses the multiple write-over technique to delete the password records and generate a destruction log to complete the password destruction of the database. Then, it sends a destruction instruction to the fingerprint password device through the management end, uses the security chip and the multiple write-over technique to delete the password records, and sends a password destruction confirmation message to the management end to complete the password destruction of the fingerprint password device; the destruction task includes the password version number, the password storage location, the destruction time and the administrator ID; A trigger destruction unit, which is used to set a fingerprint verification failure counter in the fingerprint password device. When the fingerprint failure counter reaches the set threshold, it triggers the self-destruction mechanism of the fingerprint password device, deletes all password records in the fingerprint password device and locks the device, and then generates a self-destruction event report and sends the self-destruction event report to the management end; among them, before the self-destruction mechanism is triggered, the self-destruction is stopped by inputting the administrator password or the dynamic verification code to complete the additional verification. When the additional verification cannot be passed, the self-destruction mechanism is automatically executed; An emergency destruction unit, which is used to set a one-key destruction function to delete all password records of the management end and the fingerprint password device, and mark the lost or stolen fingerprint password device as an abandoned status. When it detects that the abandoned status fingerprint password device is connected to the management end or the fingerprint password device is illegally disassembled, it automatically triggers the self-destruction mechanism of the abandoned status fingerprint password device.

[0014] Optionally, the roles of the management end include an administrator responsible for password creation, distribution, update and destruction, an auditor responsible for viewing logs and audit records, and a security officer responsible for formulating password policies and handling security incidents.

[0015] The present invention discloses the following technical effects by providing a full-cycle password distribution management system for airport information security management: 1. Automatic password input: The present invention realizes automatic password input by setting a fingerprint password device. The fingerprint password device verifies fingerprints. Only after the legal fingerprint is verified can the password be viewed or corresponding operations be performed. At the same time, the fingerprint data is encrypted and stored in the fingerprint password device, without relying on an external network. For occasions without a network environment or with high confidentiality requirements, the fingerprint password device stores the password locally, and the user can unlock it with a fingerprint to view it offline locally. The fingerprint password device does not rely on manual password memorization, not only realizing automatic password input, but also greatly increasing the security and convenience of password use, and minimizing the risks of password leakage, being peeked at, or brute force cracking.

[0016] 2. Efficient password management: The present invention realizes unified management of the entire password life cycle by setting up management software. The management software can realize functions such as automatic password creation, password distribution, password storage, and secure password destruction, meeting the high standards of password security requirements for airport information security management and improving operation efficiency.

[0017] The technical solutions of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a schematic diagram of the overall system architecture provided by the embodiment of the present invention; Figure 2 It is a schematic diagram of the structure of the fingerprint password device provided by the embodiment of the present invention; Figure 3 It is a schematic diagram of the architecture of the management terminal provided by the embodiment of the present invention; Description of the reference numerals in the drawings: 1. Portable housing; 2. Anti-peeping screen; 3. USB interface; 4. Fingerprint recognition area. Detailed Embodiments

[0020] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0021] To make the above objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0022] As Figure 1 shown, the present invention provides a full-cycle password distribution management system for airport information security management, including a fingerprint password device for automatically inputting, storing, and transmitting passwords, and a management terminal connected to the fingerprint password device. The fingerprint password device is connected to the management terminal through a USB interface or a dedicated communication protocol.

[0023] As Figure 2 shown, the fingerprint password device includes a portable housing 1, an anti-peeping screen 2 (adopting anti-peeping technology to limit the viewing angle and prevent others from peeping) provided on the front of the portable housing 1, a USB interface 3 provided on the side of the portable housing 1, a fingerprint recognition area 4 provided on the back of the portable housing 1, and an embedded microcontroller (MCU, responsible for coordinating all functional modules), a fingerprint sensor (collecting fingerprint data and performing encryption and matching), an anti-disassembly sensor, and a security chip for password storage and encryption processing provided inside the portable housing 1. The security chip includes a user login key partition, an operation authorization key partition, and a system destruction key partition.

[0024] As Figure 3 shown, the management terminal includes the following connected to each other: 1. A password creation and initialization module For combining a quantum random number seed, using a hardware security module or a random number generator to generate a password, and then writing the password into the fingerprint password device for password initialization and encrypted storage; the password creation and initialization module includes: 1.1 A password generation unit For setting password policy configuration options on the management terminal, and according to the password policy configuration options, combining a quantum random number seed, using a hardware security module or a random number generator to generate a password, and then storing the generated password and password metadata in an encrypted database through symmetric encryption.

[0025] Among them, the quantum random number seed refers to the initial parameter used in the process of generating quantum random numbers, which is used to initialize quantum devices or quantum algorithms to generate random numbers. The quantum random number seed is different from traditional random number seeds. It is based on quantum physical phenomena, such as the uncertainty of quantum measurement results and the characteristics of quantum entanglement. The random number generator combined with the quantum random number seed is the quantum random number generator (Quantum Random Number Generator, QRNG). The quantum random number generator uses quantum physical processes to quickly and massively generate true random numbers guaranteed by quantum randomness principles such as the theory of the collapse of quantum superposition states. QRNG has the characteristics of high physical integration, unpredictability, inaudibility by a third party, meeting the requirements of OTP, and process monitoring and verification.

[0026] The password policy configuration options include: Password length, such as 12 - 32 bits; Password complexity, such as it must contain uppercase letters, lowercase letters, numbers, and special characters; Password validity period, such as 30 days, 90 days; Password usage, such as system access, device authentication, etc.

[0027] 1.2 Password Initialization Unit It is used to select the fingerprint password device that needs to be initialized, connect the selected fingerprint password device to the management terminal, and exchange a temporary session password (used to protect subsequent data transmission). The management terminal verifies whether the identity of the selected fingerprint password device is legal through digital signature or device certificate. If so, the generated password is transmitted to the selected fingerprint password device through an encrypted channel to complete the password initialization operation.

[0028] 1.3 Password Writing Unit It is used to bind the generated password to the identification code of the selected fingerprint password device, encrypt and store the password using the security chip built in the selected fingerprint password device, and then return the metadata of the password (writing time, password usage, etc.) to the management terminal to complete the password writing operation.

[0029] 2. Log Recording and Auditing Module It is used to enter and bind the user's fingerprint information through a secure channel and create a log record of the entire process of storing the password when the fingerprint password device is used for the first time. The log recording and auditing module includes: 2.1 Fingerprint Entry and Binding Unit It is used to enter the user's fingerprint information through a secure channel when the fingerprint password device is used for the first time, bind the user's fingerprint information to the identification code of the fingerprint password device, and store it in the built-in security chip.

[0030] 2.2 Log Record and Audit Unit Used to create a log record of the entire process of storing password operations, and store the log record in the encrypted database; the log record includes the operation time, operation type, responsible administrator ID, fingerprint password device serial number, password usage, and password policy, and the operation type includes password creation operation, password writing operation, and fingerprint entry operation.

[0031] 3. Password Distribution Module Used to initiate a password distribution request, and according to the password distribution request, distribute the corresponding password to the fingerprint password device in an online or offline manner; the password distribution module includes: 3.1 Login and Verification Unit Used to log in to the management terminal through multi-factor authentication (such as password + fingerprint + dynamic verification code) to ensure that only authorized personnel can initiate a password distribution request. After logging in, verify the administrator's permissions and select the password and distribution objects (such as operators, servers, devices, etc.) that need to be distributed.

[0032] 3.2 Distribution Method Selection Unit Used to perform online password distribution using an encrypted communication channel (such as TLS 1.3), and perform offline password distribution using USB interface 3.

[0033] 3.3 Distribution Confirmation Unit Used to generate a distribution task summary before distribution. After the administrator confirms, start the password distribution process and generate a distribution operation log; the distribution operation log includes the distribution time, distribution object, distribution method, fingerprint verification result, and responsible administrator ID.

[0034] 4. Password Usage Module Used to connect the fingerprint password device to the management terminal through USB interface 3, and click the input button on the fingerprint password device to automatically input the password into the password input box of the management terminal; the password usage module includes: 4.1 Password Automatic Input Unit Used to connect the fingerprint password device to the management terminal through USB interface 3. The operator inputs a fingerprint to unlock in the fingerprint recognition area 4 and clicks the input button, and the fingerprint password device automatically transmits the target password into the password input box.

[0035] 4.2 Offline Viewing Unit Used in an offline environment. After the first fingerprint unlock of the fingerprint password device, display part of the password content, such as the first 4 digits and the last 4 digits, and hide the rest with "*" to prevent the password from being fully peeked. If the operator needs to view the complete password, they need to input the fingerprint again for secondary verification. After the second fingerprint unlock, the complete password will be displayed for a short time.

[0036] The operator connects the fingerprint password device to the target system and automatically inputs the password into the target system through the "Input" button. The automatic input process is the same as in the online scenario, ensuring that the password cannot be peeked at or recorded.

[0037] 5. Password Automatic Update Module Used for periodic management and expiration processing of passwords, and real-time monitoring of abnormal password usage; the password automatic update module includes: 5.1 Password Period Management Unit Used to create a unique password version number when generating and updating passwords, and set the password expiration period (such as 30 days, 90 days). Before the password expires (such as 3 days before expiration), automatically send a password expiration reminder to the administrator to prompt password update.

[0038] 5.2 Password Update and Synchronization Unit Used to initiate a password update request at the management end. According to the password update request, automatically generate a new password and a new password version number, and mark the old password as pending deletion to regularly and automatically clean up the passwords to be deleted.

[0039] 5.3 Usage Monitoring Unit Used to monitor the password usage situation in real time according to the password version number, including usage time, usage object, usage method (such as online distribution, offline input), and detect abnormal usage behaviors. When an anomaly is detected, the system will automatically lock the relevant password and notify the administrator.

[0040] 6. Password Security Destruction Module Used to build a password regular destruction mechanism, a destruction trigger mechanism, and an emergency handling mechanism to complete password security processing; the password security destruction module includes: 6.1 Regular Destruction Unit Used to generate a destruction task. According to the destruction task, call the destruction interface of the encrypted database, use the multiple write-overwrite technology to delete the password records and generate a destruction log to complete the password destruction in the database, and then send a destruction instruction to the fingerprint password device through the management end, use the security chip and the multiple write-overwrite technology to delete the password records, and send a password destruction confirmation message to the management end to complete the password destruction of the fingerprint password device; the destruction task includes the password version number, password storage location, destruction time, and administrator ID.

[0041] Among them, the multiple write - overwrite technology is a data destruction method. By writing random data or fixed data to each data sector in the storage device multiple times, the original data is completely overwritten, thus ensuring that the data cannot be recovered. This technology is widely used in fields such as enterprise - discarded hard drives and personal privacy protection, and is regarded as an "excellent tool" in the field of data destruction. 6.2 Trigger the destruction unit A fingerprint verification failure counter is built into the fingerprint password device. Each time fingerprint verification fails, the counter is incremented by 1. When the fingerprint failure counter reaches a set threshold (such as 5 times), the self - destruction mechanism of the fingerprint password device is triggered (before the self - destruction mechanism is triggered, the self - destruction can be stopped by entering the administrator password or dynamic verification code to complete additional verification. When the additional verification cannot be passed, the self - destruction mechanism is automatically executed). The self - destruction mechanism can delete all password records in the fingerprint password device and lock the device (subsequent operations are prohibited until the administrator re - activates the device through the management software), and then generate a self - destruction event report and send the self - destruction event report to the management end.

[0042] 6.3 Emergency destruction unit It is used to set a one - key destruction function to delete all password records of the management end and the fingerprint password device. The administrator can trigger the password batch destruction operation in an emergency. The one - key destruction operation requires multiple confirmations (such as joint confirmation by the system administrator and the security officer) to prevent misoperation.

[0043] Mark the lost or stolen fingerprint password device as in the discarded state. When it is detected that a fingerprint password device in the discarded state is connected to the management end or the fingerprint password device is illegally disassembled, the self - destruction mechanism of the fingerprint password device in the discarded state is automatically triggered to clear all locally stored password files.

[0044] 7. Role definitions Administrator: Responsible for password creation, distribution, update, and destruction.

[0045] Auditor: Responsible for viewing logs and audit records and has no right to view password content.

[0046] Security officer: Responsible for formulating password policies and handling security incidents.

[0047] Therefore, the present invention provides a full - cycle password distribution management system for airport information security management. Through the interaction between the management software and the fingerprint password device, it not only realizes the automatic input of passwords, simplifies the manual input link, reduces the risk of password leakage or loss, but also can manage the entire life cycle of passwords, improve the security and operation efficiency of passwords, and meet the high - standard requirements for password security in airport information security management.

[0048] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other.

[0049] In this article, specific examples are used to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present invention. At the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the present invention.

Claims

1. A full-cycle password distribution and management system for airport information security management, characterized in that: It includes a fingerprint cipher for automatically inputting, storing and transmitting passwords and a management terminal connected to the fingerprint cipher, the fingerprint cipher is connected to the management terminal via a USB interface or a dedicated communication protocol, and the management terminal includes: A password creation and initialization module is used to generate a password using a hardware security module or a random number generator in combination with a quantum random number seed, and then write the password into the fingerprint cipher for password initialization and encrypted storage; The logging and auditing module is used to input and bind the user's fingerprint information through a secure channel when the fingerprint password device is used for the first time, and to create a log record of the entire process of storing password operations; A password distribution module, used to initiate a password distribution request, and distribute the corresponding password to the fingerprint password device in an online or offline manner according to the password distribution request; A password using module, used to connect the fingerprint password device to the management terminal through a USB interface, and click the input button on the fingerprint password device to automatically input the password into the password input box of the management terminal; The automatic password update module is used to manage the password periodically and handle its expiration, and monitor abnormal password usage in real time; The password security destruction module is used to build a password periodic destruction mechanism, a destruction trigger mechanism, and an emergency processing mechanism to complete password security processing; Among them, the password creation and initialization module, the log recording and auditing module, the password distribution module, the password use module, the password automatic update module, and the password security destruction module are interconnected.

2. A full-cycle password distribution and management system for airport information security management according to claim 1, characterized in that: The fingerprint cipher comprises a portable housing, an anti-peeping screen arranged on the front of the portable housing, a USB interface arranged on the side of the portable housing, a fingerprint recognition area arranged on the back of the portable housing, and an embedded microcontroller, a fingerprint sensor, an anti-disassembly sensor and a security chip for password storage and encryption processing arranged inside the portable housing.

3. A full-cycle password distribution and management system for airport information security management according to claim 2, characterized in that: The security chip includes a user login key partition, an operation authorization key partition and a system destruction key partition.

4. A full-cycle password distribution and management system for airport information security management according to claim 3, characterized in that: The password creation and initialization module includes: A password generation unit, used to set password policy configuration options on the management end, generate a password using a hardware security module or a random number generator according to the password policy configuration options and in combination with a quantum random number seed, and then store the generated password and password metadata in an encrypted database by symmetric encryption; the password policy configuration options include password length, password complexity, password validity period, and password purpose; A password initialization unit, used to select the fingerprint encryptor that needs to be initialized, connect the selected fingerprint encryptor to the management end, and exchange a temporary session password. The management end verifies whether the identity of the selected fingerprint encryptor is legal. If so, the generated password is transmitted to the selected fingerprint encryptor through an encrypted channel to complete the password initialization operation; The password writing unit is used to bind the generated password with the identification code of the selected fingerprint encryptor, encrypt and store the password using the built-in security chip of the selected fingerprint encryptor, and then return the metadata of the password to the management end to complete the password writing operation.

5. A full-cycle password distribution and management system for airport information security management according to claim 4, characterized in that: The logging and auditing module includes: A fingerprint entry and binding unit, used to enter the user's fingerprint information through a secure channel when the fingerprint encryptor is used for the first time, bind the user's fingerprint information with the identification code of the fingerprint encryptor, and store it in a built-in security chip; The log record and audit unit is used to create a log record of the entire process of password operation, and the log record is stored in the encrypted database; the log record includes the operation time, operation type, responsible administrator ID, fingerprint password device serial number, password purpose and password policy, and the operation type includes password creation operation, password writing operation and fingerprint entry operation.

6. A full-cycle password distribution and management system for airport information security management according to claim 5, characterized in that: The password distribution module includes: A login and verification unit, used to log in to the management terminal through multi-factor authentication, verify the administrator's authority after logging in, and select the password and distribution object to be distributed; the multi-factor authentication includes password, fingerprint and dynamic verification code; A distribution mode selection unit is used to distribute the password online by using an encrypted communication channel and to distribute the password offline by using a USB interface; The distribution confirmation unit is used to generate a distribution task summary before distribution. After the administrator confirms, the password distribution process is started and a distribution operation log is generated; the distribution operation log includes the distribution time, distribution object, distribution method, fingerprint verification result and responsible administrator ID.

7. A full-cycle password distribution and management system for airport information security management according to claim 6, characterized in that: The password usage module includes: The automatic password input unit is used to connect the fingerprint password device to the management terminal through a USB interface. The operator inputs the fingerprint in the fingerprint recognition area to unlock and clicks the input button. The fingerprint password device automatically transmits the target password to the password input box; The offline viewing unit is used in an offline environment, wherein the fingerprint cipher displays part of the password after the first fingerprint unlocking, and displays the complete password in a short time after the second fingerprint unlocking.

8. A full-cycle password distribution and management system for airport information security management according to claim 7, characterized in that: The automatic password update module includes: The password cycle management unit is used to create a password version number and set the password validity period when the password is generated and updated. Before the password expires, it automatically sends a password expiration reminder to the administrator; A password update and synchronization unit, used to initiate a password update request at the management end, automatically generate a new password and a new password version number according to the password update request, and mark the old password as a pending deletion state, so as to automatically clean up the pending deletion passwords regularly; The usage monitoring unit is used to monitor the password usage in real time according to the password version number and detect abnormal usage behavior.

9. A full-cycle password distribution and management system for airport information security management according to claim 8, characterized in that: The password security destruction module includes: The periodic destruction unit is used to generate a destruction task, call the destruction interface of the encrypted database according to the destruction task, use the multiple write-over technology to delete the password record and generate a destruction log, complete the password destruction of the database, and then send a destruction instruction to the fingerprint cipher through the management end, use the security chip and the multiple write-over technology to delete the password record, and send the password destruction confirmation information to the management end to complete the password destruction of the fingerprint cipher; the destruction task includes the password version number, password storage location, destruction time and administrator ID; A triggering and destroying unit is used to build a fingerprint verification failure counter in the fingerprint cipher. When the fingerprint failure counter reaches a set threshold, the self-destruction mechanism of the fingerprint cipher is triggered, all password records in the fingerprint cipher are deleted and the device is locked, and a self-destruction event report is generated, and the self-destruction event report is sent to the management end; wherein, before the self-destruction mechanism is triggered, the self-destruction is stopped by inputting the administrator password or the dynamic verification code, and the additional verification is completed. When the additional verification fails, the self-destruction mechanism is automatically executed; The emergency destruction unit is used to set a one-key destruction function to delete all password records of the management terminal and the fingerprint encryptor, and mark the lost or stolen fingerprint encryptor as abandoned. When it is detected that the fingerprint encryptor in the abandoned state is connected to the management terminal or the fingerprint encryptor is illegally disassembled, the self-destruction mechanism of the fingerprint encryptor in the abandoned state is automatically triggered.

10. A full-cycle password distribution and management system for airport information security management according to claim 9, characterized in that: The roles of the management end include administrators who are responsible for password creation, distribution, updating and destruction, auditors who are responsible for viewing logs and audit records, and security officers who are responsible for formulating password policies and handling security incidents.

Citation Information

Patent Citations

  • Fingerprint identification cipher device

    CN101521573A

  • Device capable of carrying out fingerprint identification login and replacing password of operating system in fixed time and use method

    CN104899492A

  • Information filling method and electronic equipment

    CN105808132A

  • Method and device for generating signature

    CN106603236A

  • Virtualized password service management platform

    CN118094523A