Web login method supporting multiple login password encryption methods and related system
By dynamically loading the verification module in the web login system and selecting the corresponding password verification module based on the algorithm configuration information of the user account, the problem of inconsistency in encryption algorithms between the old system and the new system is solved, seamless import and gradual upgrade of user passwords is realized, and the risk of system migration is reduced.
Patent Information
- Application Number
- CN202510523277.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-06-13
AI Technical Summary
During system upgrade, the hash encryption algorithms used by the old system (such as MD5, SHA, SM3, etc.) cannot be directly imported, and cannot be compatible with the encryption algorithms of the new system.
By providing a web login method and system that supports multiple login password encryption methods, the verification module is dynamically loaded, and the corresponding password verification module is selected based on the algorithm configuration information of the user account, so as to achieve compatibility with different encryption algorithms.
In the case where the password encryption methods between the old system and the new system are inconsistent, the seamless import and gradual upgrade of user passwords reduce the risk of system migration and upgrading, and improve the stability and compatibility of the system.
Smart Images

Figure CN120151099A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of encryption algorithms, and particularly relates to a Web login method and related system that support multiple login password encryption methods. Background Art
[0002] When an information system uses an account password for login authentication, its password encryption algorithms include various types such as hash encryption, symmetric encryption, and asymmetric encryption. The hash encryption algorithm is a one-way algorithm and cannot be decrypted. When the system is upgraded, it is necessary to import existing user data including information such as accounts and passwords. If the old version system uses a symmetric encryption or asymmetric encryption algorithm, the user password can be decrypted first and then re-encrypted using the new algorithm when importing the user password. However, if the old system uses a hash encryption algorithm such as MD5, SHA, SM3, etc., it cannot be imported by decrypting first and then re-encrypting. Summary of the Invention
[0003] The purpose of the present invention is to overcome the problem that passwords cannot be imported directly between the old system and the new system, and to provide a Web login method and related system that support multiple login password encryption methods.
[0004] To achieve the above purpose, the present invention adopts the following technical solutions: In the first aspect, the present invention provides a Web login method that supports multiple login password encryption methods, including the following steps: When a user requests to access the system through a browser, if the current user has not completed the login, then jump to the login interface; Obtain the account information and password information on the login interface, verify the account information and password information, and obtain the algorithm configuration information of the account information and password information; According to the algorithm configuration information of the account information and password information, select the corresponding verification program to verify the account information and password information, and generate a verification result; Perform a corresponding interface jump according to the verification result.
[0005] A further improvement of the present invention is that when a user requests to access the system through a browser, if the current user has not completed the login, the specific method of jumping to the login interface is as follows: Preset a processing chain, continuously obtain the request header information sent by the user through the browser, check all received request header information through the processing chain, and determine whether the user has logged in; If the user has not logged in, then generate a page jump link to make the page jump to the login interface.
[0006] A further improvement of the present invention is that the specific method of obtaining the account information and password information on the login interface, verifying the account information and password information, and obtaining the algorithm configuration information of the account information and password information is as follows: Use form controls to obtain the account information and password information on the login interface, pre-encrypt the account information and password information, and upload the encrypted account information, password information, and pre-encrypted parameters; Verify the legality of the account information and password information based on the encrypted account information, password information, and pre-encrypted parameters; If the verification is passed, obtain the corresponding algorithm configuration and issue it.
[0007] A further improvement of the present invention is that, according to the algorithm configuration information of the account information and password information, select the corresponding verification program to verify the account information and password information, and the specific method for generating the verification result is as follows: Obtain the corresponding verification program according to the algorithm configuration information of the account information and password information; Use the verification program to decrypt the account information and password information to generate a decryption result, and compare and verify the decryption result with the preset password digest; After the verification passes, generate a verification result with attached prompt information.
[0008] A further improvement of the present invention is that the specific method for performing corresponding interface jumps according to the verification result is as follows: If the verification result is successful, perform the page jump after success; If the verification result is failed, issue an error prompt.
[0009] In a second aspect, the present invention provides a Web login system that supports multiple login password encryption methods, including: A login module for, when a user requests to access the system through a browser, if the current user has not completed the login, jump to the login interface; A login authentication module for obtaining the account information and password information on the login interface, verifying the account information and password information, and obtaining the algorithm configuration information of the account information and password information; An encryption algorithm loading module for selecting the corresponding verification program to verify the account information and password information according to the algorithm configuration information of the account information and password information, and generating a verification result; A jump module for performing corresponding interface jumps according to the verification result.
[0010] A further improvement of the present invention is that the function of the login authentication module is implemented by the following method: Use form controls to obtain the account information and password information on the login interface, pre-encrypt the account information and password information, and upload the encrypted account information, password information, and pre-encrypted parameters; Verify the legality of the account information and password information according to the encrypted account information, password information, and pre-encrypted parameters; If the verification is passed, obtain the corresponding algorithm configuration and issue it.
[0011] A further improvement of the present invention lies in that the function of the encryption algorithm loading module is implemented by the following method: Obtain the corresponding verification program according to the algorithm configuration information of the account information and password information; Use the verification program to decrypt the account information and password information to generate a decryption result, and compare and verify the decryption result with the preset password digest; After the verification passes, generate a verification result with an attached prompt message.
[0012] In a third aspect, the present invention provides an electronic device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of a Web login method that supports multiple login password encryption methods.
[0013] In a fourth aspect, the present invention provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of a Web login method that supports multiple login password encryption methods.
[0014] Compared with the prior art, the present invention has the following beneficial effects: The present invention can select the corresponding password verification module according to the algorithm configuration information of different user accounts, so that even if the old system uses one encryption method and the new system uses another method, two or more encryption methods can still be compatible under the same login entry. When the present invention obtains the account and password, it dynamically loads the corresponding verification module through configuration, allowing the system to support both the old encryption algorithm and the new algorithm during the migration process, ensuring that the user password verification does not fail due to inconsistent encryption algorithms. The present invention adopts a multi-encryption method verification mechanism, enabling users to achieve a smooth transition without being forced to modify passwords, thereby reducing the usage barriers brought by password updates for users and the risks of system migration. After the user successfully logs in, the present invention can re-encrypt and store the old password with the new encryption algorithm according to the current configuration, realizing progressive password upgrade without requiring all users to change passwords at once. Through the dynamic loading and algorithm mapping mechanism, the present invention can specify different password encryption policies for different users or user groups respectively, which not only solves the problem of password import between the old system and the new system, but also can adjust the strength or parameters of the encryption algorithm in real time according to security requirements. The present invention records in detail the exceptions or errors in password verification during the verification process, which helps to timely discover and correct problems with password encryption policies during the migration process and ensure the overall security of the system. During the use of the present invention by users, the system automatically selects the appropriate verification program according to the configuration of the account, and will not cause login failures due to differences in encryption methods, which improves the overall stability and compatibility of the system. In summary, the present invention can, in the case of inconsistent password encryption methods between the old system and the new system, through flexible algorithm mapping and dynamic verification processes, achieve seamless import of old passwords, gradual upgrade, and ensure security and user experience. This solution not only reduces the risks of system migration and upgrade, but also provides expansion space and flexibility for future possible updates of encryption algorithms. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a flowchart of the present invention; Figure 2 is a system diagram of the present invention; Figure 3 is a system diagram of Embodiment 7. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] To further understand the content of the present invention, the following describes the present invention in detail with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments are only for explaining the present invention and not for limiting it.
[0017] Embodiment 1: Refer to Figure 1 , a Web login method supporting multiple login password encryption methods, including the following steps: S1. When a user requests to access the system through a browser, if the current user has not completed the login, then redirect to the login page.
[0018] S2. Obtain the account information and password information on the login page, verify the account information and password information, and obtain the algorithm configuration information of the account information and password information.
[0019] S3. According to the algorithm configuration information of the account information and password information, select the corresponding verification program to verify the account information and password information, and generate a verification result.
[0020] S4. Perform a corresponding page redirect according to the verification result.
[0021] Example 2: See Figure 2 , a Web login system that supports multiple login password encryption methods, including: A login module, which is used to redirect to the login page when a user requests to access the system through a browser and the current user has not completed the login; A login authentication module, which is used to obtain the account information and password information on the login page, verify the account information and password information, and obtain the algorithm configuration information of the account information and password information; An encryption algorithm loading module, which is used to select the corresponding verification program to verify the account information and password information according to the algorithm configuration information of the account information and password information, and generate a verification result; A jump module, which is used to perform a corresponding page redirect according to the verification result.
[0022] Example 3: This example further limits the specific method of S1 on the basis of the above example, as follows: S11. Configure an interceptor or filter in the Web server to detect whether there is valid session information for the user in each HTTP request. By checking whether there is an authenticated Token or Session ID in the request header, confirm whether the current user has logged in, and record the URL, IP address, and time of the user's request in the log system to provide a basis for subsequent security audits.
[0023] S12. If the user has not logged in, which means the session does not exist or has expired, then determine the current status as the unlogged status, generate the URL of the login page, and at the same time, the parameters of the original request page can be attached to facilitate page redirection after successful login. Use the HTTP 302 or front-end redirection mechanism to direct the user's request to the login page.
[0024] S13, Initialize security measures such as verification codes and CSRF Tokens to prevent brute-force cracking and cross-site attacks. Display a prompt like "Please log in first" or "Session has expired, please log in again" on the login page, and provide help documents or FAQ links related to logging in to facilitate users in quickly finding solutions.
[0025] Example 4: In this example, based on the above example, the specific method of S2 is further defined as follows: S21, In the login page design, collect the account and password entered by the user through form controls, use the HTTPS protocol to ensure the encryption of the data transmission process, or pre-encrypt the password using a client-side encryption algorithm (such as RSA encryption) before submission. In addition to the account and password, also submit parameters indicating the currently used encryption algorithm (such as encryption version, encryption strength, etc.).
[0026] S22, Check the account format (such as the legality of email, mobile phone number or username) and password format (length, character requirements, etc.), ensure that the required items are not missing in the submitted data, perform basic anti-injection processing on the data, record the abnormal situations during the verification process, and promptly feedback to the administrator system.
[0027] S23, Query the database or configuration center according to the account identifier (such as user ID, account type) to obtain the password encryption and verification algorithm information corresponding to the user, load or initialize the corresponding encryption algorithm instance (such as MD5, SHA-256, BCrypt, PBKDF2, etc.) from the system's algorithm library, and dynamically adjust the subsequent verification strategy according to the configuration, such as selecting different iteration times or salt value generation mechanisms to ensure security and flexibility.
[0028] Example 5: In this example, based on the above example, the specific method of S3 is further defined as follows: S31, According to the algorithm configuration information, select the corresponding password verification module through the mapping relationship. If the system supports plug-in extension, dynamically load or activate the specified verification program, and set the necessary parameters (such as salt value, key, iteration times, etc.) for the selected verification program to ensure the consistency of the verification environment.
[0029] S32, Obtain the password digest and additional information (such as salt value, algorithm version) stored for the corresponding account from the database, use the selected verification program to decrypt the password submitted by the user, and compare it with the password digest stored in the database. Record detailed logs for successful and failed attempts during the verification process to facilitate security analysis and anomaly detection.
[0030] S33. Generate verification results (success, failure, error codes, etc.), along with necessary prompt messages or error descriptions, and pass the verification results to the business logic processing module to provide a basis for subsequent interface jumps. For successfully verified users, update the session information (such as generating a new Token, refreshing the Session) to prepare for the next access.
[0031] Embodiment 6: Based on the above embodiment, this embodiment further defines the specific method of S4 as follows: S41. If the verification is successful, mark the user as authenticated and perform a page jump after success (such as the user homepage or the original request page). If the verification fails, determine whether it is a password error, account does not exist, or encryption algorithm mismatch based on the error code, and generate corresponding prompt messages. For system exceptions or unknown errors during the verification process, give a unified error prompt and record the exception log.
[0032] S42. Use HTTP redirection (302 / 303) or front-end route jump to ensure that necessary parameters (such as error prompt messages) are carried during the page jump. Preload or dynamically render the page before the jump to ensure a smooth user experience. Pass necessary security identifiers (such as CSRF Token or two-factor authentication parameters) during the jump to ensure the security of subsequent operations.
[0033] S43. Display a customized welcome page for successfully logged-in users, providing account information, login logs, or personalized settings. When the verification fails, allow the user to try logging in again and provide auxiliary measures such as retrieving the password and refreshing the verification code. In a multi-system environment, synchronize the session status; and notify the user of abnormal login attempts or account status changes via email or text message when necessary.
[0034] Embodiment 7: Please refer to Figure 3 As shown, the present invention also provides an electronic device 100 for a Web login method that supports multiple login password encryption methods; the electronic device 100 includes a memory 101, at least one processor 102, a computer program 103 stored in the memory 101 and executable on the at least one processor 102, and at least one communication bus 104.
[0035] The memory 101 can be used to store the computer program 103. By running or executing the computer program stored in the memory 101 and calling the data stored in the memory 101, the processor 102 implements the steps of the Web login method supporting multiple login password encryption methods described in Embodiment 1. The memory 101 may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area can store data created according to the use of the electronic device 100 (such as audio data), etc. In addition, the memory 101 may include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices.
[0036] The at least one processor 102 may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 102 may be a microprocessor or the processor 102 may also be any conventional processor, etc. The processor 102 is the control center of the electronic device 100, and connects various parts of the entire electronic device 100 through various interfaces and lines.
[0037] The memory 101 in the electronic device 100 stores multiple instructions to implement the Web login method supporting multiple login password encryption methods. The processor 102 can execute the multiple instructions to implement: When the user requests to access the system through a browser, if the current user has not completed the login, then jump to the login interface; Obtain the account information and password information on the login interface, and verify the account information and password information to obtain the algorithm configuration information of the account information and password information; According to the algorithm configuration information of the account information and password information, select the corresponding verification program to verify the account information and password information, and generate a verification result; Perform corresponding interface jumps according to the verification result.
[0038] Example 8: If the modules / units integrated in the electronic device 100 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above method embodiments of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory and read-only memory (ROM, Read-Only Memory).
[0039] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, system, or computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0040] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0041] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the processes in Figure 1 one process or multiple processes and / or blocks Figure 1The functions specified in one or more boxes.
[0042] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in one Figure 1 One process or more processes and / or boxes Figure 1 The steps of the functions specified in one or more boxes.
[0043] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A Web login method that supports multiple login password encryption methods, characterized in that: The following steps are involved: When a user requests to access the system through a browser, if the current user has not completed the login, the user will be redirected to the login interface; Obtain the account information and password information of the login interface, verify the account information and password information, and obtain the algorithm configuration information of the account information and password information; According to the algorithm configuration information of the account information and password information, select the corresponding verification program to verify the account information and password information and generate a verification result; Jump to the corresponding interface based on the verification result.
2. The Web login method supporting multiple login password encryption methods according to claim 1, characterized in that: When a user requests to access the system through a browser, if the current user has not completed the login, the specific method of jumping to the login interface is as follows: The preset processing chain continues the request header information sent by the user through the browser, and checks all received request header information through the processing chain to determine whether the user is logged in; If the user is not logged in, a page jump link is generated to jump the page to the login interface.
3. The Web login method supporting multiple login password encryption methods according to claim 1, characterized in that: Get the account information and password information of the login interface, and verify the account information and password information. The specific method for obtaining the algorithm configuration information of the account information and password information is as follows: Use form controls to obtain the account information and password information of the login interface, pre-encrypt the account information and password information, and upload the encrypted account information and password information and pre-encrypted parameters; Verify the legitimacy of the account information and password information based on the encrypted account information and password information and the pre-encrypted parameters; If the verification is passed, the corresponding algorithm configuration is obtained and issued.
4. The Web login method supporting multiple login password encryption methods according to claim 1, characterized in that: According to the algorithm configuration information of the account information and password information, select the corresponding verification program to verify the account information and password information. The specific method of generating the verification result is as follows: Obtain the corresponding verification program according to the algorithm configuration information of the account information and password information; Use the verification program to decrypt the account information and password information, generate a decryption result, and compare and verify the decryption result with the preset password summary; After the verification is passed, a verification result with accompanying prompt information is generated.
5. The Web login method supporting multiple login password encryption methods according to claim 1, characterized in that: The specific method of jumping to the corresponding interface according to the verification result is as follows: If the verification result is successful, the page jump will be executed successfully; If the verification result is failed, an error prompt will be issued.
6. A web login system that supports multiple login password encryption methods, characterized in that: include: The login module is used to jump to the login interface when the user requests to access the system through the browser if the current user has not completed the login; The login authentication module is used to obtain the account information and password information of the login interface, verify the account information and password information, and obtain the algorithm configuration information of the account information and password information; The encryption algorithm loading module is used to select a corresponding verification program to verify the account information and password information according to the algorithm configuration information of the account information and password information, and generate a verification result; The jump module is used to jump to the corresponding interface according to the verification result.
7. The Web login system supporting multiple login password encryption methods according to claim 6, characterized in that: The functions of the login authentication module are implemented through the following methods: Use form controls to obtain the account information and password information of the login interface, pre-encrypt the account information and password information, and upload the encrypted account information and password information and pre-encrypted parameters; Verify the legitimacy of the account information and password information based on the encrypted account information and password information and the pre-encrypted parameters; If the verification is passed, the corresponding algorithm configuration is obtained and issued.
8. The Web login system supporting multiple login password encryption methods according to claim 6, characterized in that: The encryption algorithm loading module is implemented by the following methods: Obtain the corresponding verification program according to the algorithm configuration information of the account information and password information; Use the verification program to decrypt the account information and password information, generate a decryption result, and compare and verify the decryption result with the preset password summary; After the verification is passed, a verification result with accompanying prompt information is generated.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the Web login method supporting multiple login password encryption methods described in any one of claims 1 to 5 are implemented.
10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the Web login method supporting multiple login password encryption methods described in any one of claims 1 to 5 are implemented.