Password authentication method and electronic equipment
By receiving and comparing the encrypted login information of the client in the computing node, the problem of low authentication security in the distributed database is solved, and higher security and reliability are achieved, preventing data leakage and other security threats.
Patent Information
- Application Number
- CN202510400137.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-24
AI Technical Summary
The existing distributed database authentication methods have low security problems, which can easily lead to data leakage, tampering or malicious deletion.
A password authentication method is used in the computing node. By receiving the login request and encryption information sent by the client, and comparing it with the stored ciphertext, the legality of the login request is judged. If passed, login is allowed. This method avoids persisting storage of account password plaintext or decryptable password ciphertext in the compute node, reducing the risk of attackers obtaining passwords.
Improve the security and reliability of password authentication, reduce the risk of attackers obtaining target account passwords by attacking computing nodes, and preventing data breaches and other security threats.
Smart Images

Figure CN120200820A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of database technologies, and in particular, to a password authentication method and an electronic device. Background Art
[0002] In the scenario of a distributed database, authentication security is of crucial importance. A distributed database involves multi-node collaboration and decentralized data storage. Its data often concerns core businesses and sensitive information. Once a vulnerability appears in the authentication process, attackers can easily obtain access rights, resulting in data leakage, being tampered with, or malicious deletion. Due to the wide distribution of nodes in a distributed database, the security boundary expands and the attack surface increases. A reliable authentication mechanism can prevent illegal nodes from accessing, ensuring that only authorized users and nodes can perform data interaction and operations, and maintaining the integrity and availability of the system. However, the current authentication methods for distributed databases have the problem of low security.
[0003] Therefore, how to improve the authentication security of a distributed database is an urgent problem to be solved. Summary of the Invention
[0004] Embodiments of this application provide a password authentication method and an electronic device, so as to achieve the effect of improving the efficiency of account password update in a distributed database environment.
[0005] In a first aspect, an embodiment of this application provides a password authentication method, which is applied to a computing node and includes:
[0006] Receiving a login request sent by a client, where the login request includes an identifier of a target account;
[0007] Receiving first encrypted information sent by the client, where the first encrypted information is generated according to a target encryption field, the identifier of the target account, and an input password of the target account;
[0008] Obtaining second encrypted information, where the second encrypted information is related to the identifier of the target account, a local password of the target account, and the target encryption field;
[0009] Judging whether to pass the login request of the client according to the first encrypted information and the second encrypted information;
[0010] If it passes, allowing the client to log in.
[0011] Optionally, it further includes:
[0012] If the login request is the first time the client logs in through the computing node, sending a first authentication instruction to the client, where the first authentication instruction is used to instruct the client to perform login authentication through a first authentication method;
[0013] Receiving the first encrypted information sent by the client includes:
[0014] Receiving the first encrypted information sent by the client based on the first authentication method.
[0015] Optionally, the method further includes:
[0016] After the client updates the password of the target account, generating the target encryption field;
[0017] Sending the target encryption field to the client;
[0018] Generating the second encrypted information based on the target encryption field, the identifier of the target account, and the updated password;
[0019] Storing the mapping relationship among the second encrypted information, the target encryption field, and the identifier of the target account.
[0020] Optionally, judging whether to pass the login request of the client according to the first encrypted information and the second encrypted information includes:
[0021] Generating the third encrypted information according to the first encrypted information and the target encryption field;
[0022] If the third encrypted information is the same as the second encrypted information, passing the login request of the client.
[0023] Optionally, it further includes:
[0024] Generating the password of the data node corresponding to the client according to the first encrypted information and the target encryption field;
[0025] After allowing the client to log in, enabling the client to log in to the data node according to the password of the data node.
[0026] Optionally, it further includes:
[0027] If the login request is not the first time for the client to log in through the computing node, sending a second authentication instruction to the client, where the second authentication instruction is used to instruct the client to perform login authentication through the second authentication method;
[0028] Receiving the first encrypted information sent by the client includes:
[0029] Receiving the first encrypted information sent by the client based on the second authentication method.
[0030] Optionally, the method further includes:
[0031] After receiving the login request, send the target encryption field to the client.
[0032] Optionally, the obtaining the second encryption information includes:
[0033] Obtain the fourth encryption information generated based on the identifier of the target account and the local password of the target account;
[0034] Obtain the second encryption information according to the target encryption field and the fourth encryption information.
[0035] Optionally, judging whether to pass the login request of the client according to the first encryption information and the second encryption information includes:
[0036] If the first encryption information is the same as the second encryption information, it is determined that the login request of the client is passed.
[0037] In a second aspect, an embodiment of the present application provides a password authentication method, which is applied to a client and includes:
[0038] Send a login request to a computing node, where the login request includes an identifier of a target account;
[0039] Generate first encryption information according to a target encryption field, the identifier of the target account, and the input password of the target account;
[0040] Send the first encryption information to the computing node.
[0041] In a third aspect, an embodiment of the present application provides a password authentication device, which is applied to a computing node and includes:
[0042] A first receiving module, configured to receive a login request sent by a client, where the login request includes an identifier of a target account;
[0043] A second receiving module, configured to receive the first encryption information sent by the client, where the first encryption information is generated according to a target encryption field, the identifier of the target account, and the input password of the target account;
[0044] An obtaining module, configured to obtain second encryption information, where the second encryption information is related to the identifier of the target account, the local password of the target account, and the target encryption field;
[0045] A processing module, configured to judge whether to pass the login request of the client according to the first encryption information and the second encryption information;
[0046] A control module, configured to allow the client to log in if it passes.
[0047] Fourthly, an embodiment of the present application provides a password authentication device, which is applied to a client and includes:
[0048] A first sending module, configured to send a login request to a computing node, where the login request includes an identifier of a target account;
[0049] A processing module, configured to generate first encrypted information according to a target encryption field, the identifier of the target account, and the input password of the target account;
[0050] A second sending module, configured to send the first encrypted information to the computing node.
[0051] Fifthly, an embodiment of the present application provides an electronic device, including: a memory and a processor;
[0052] The memory stores computer-executable instructions;
[0053] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the implementation manner described in any one of the first aspect or the second aspect above.
[0054] Sixthly, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the implementation manner described in any one of the first aspect or the second aspect above.
[0055] Seventhly, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the implementation manner described in any one of the first aspect or the second aspect above.
[0056] For the password authentication method and the electronic device provided in the embodiments of the present application, the computing node receives a login request including an identifier of a target account sent by the client, and receives first encrypted information generated by the client according to a target encryption field, the identifier of the target account, and the input password of the target account. The computing node obtains second encrypted information related to the identifier of the target account, the local password of the target account, and the target encryption field. The computing node determines whether to pass the login request of the client according to the first encrypted information and the second encrypted information. If it passes, the client is allowed to log in. Compared with the prior art in which the computing node directly stores the clear text of the password of the target account or the decryptable cipher text of the password, in this method, the clear text of the password of the target account or the decryptable cipher text of the password is not persistently stored in the computing node, so as to reduce the risk that an attacker obtains the password of the target account by attacking the computing node, thereby improving the security and reliability of password authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0058] Figure 1 It is a schematic structural diagram of a password authentication system provided for this application;
[0059] Figure 2 It is a schematic flowchart of a password authentication method provided for an embodiment of this application;
[0060] Figure 3 It is a schematic flowchart of another password authentication method provided for an embodiment of this application;
[0061] Figure 4 It is a schematic flowchart of yet another password authentication method provided for an embodiment of this application;
[0062] Figure 5 It is a schematic flowchart of still another password authentication method provided for an embodiment of this application;
[0063] Figure 6 It is a schematic flowchart of still another password authentication method provided for an embodiment of this application;
[0064] Figure 7 It is a schematic structural diagram of a password authentication device provided for an embodiment of this application;
[0065] Figure 8 It is a schematic structural diagram of another password authentication device provided for an embodiment of this application;
[0066] Figure 9 It is a schematic structural diagram of an electronic device provided for an embodiment of this application.
[0067] Through the above-mentioned accompanying drawings, specific embodiments of this application have been shown, and there will be more detailed descriptions hereinafter. These accompanying drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed Description of Specific Embodiments
[0068] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.
[0069] First, the professional terms related to the embodiments of this application are introduced:
[0070] Computing node: It is a node in the distributed database that directly serves the client. Its function is to receive client requests and perform corresponding processing, and rely on the data stored in the data node to provide services for the client.
[0071] Data node: It can also be called a storage node. The data node is a node in the distributed database that stores data. The function of the data node is to store data, accept scheduling by the computing node, and provide data support for the computing node.
[0072] Remote repository: It refers to a highly available component that can store data and monitor changes. The remote repository is mainly used to store configurations and ensure the consistency of system configuration data. Currently, common remote repositories can include, for example, zookeeper, ETCD, consul, etc.
[0073] Figure 1 It is a schematic structural diagram of a password authentication system provided by this application. As Figure 1 shown, the system includes: at least one computing node, at least one client (for example, it can be Figure 1 N of them), and at least one data node.
[0074] Among them, the computing node is the server in the distributed database, and it is connected to the data node in the distributed database. The computing node can receive requests from the client and perform corresponding processing, and rely on the data stored in the data node to provide services for the client.
[0075] The client is used to achieve access operations, data management operations, etc. on the distributed database through communication and interaction with the computing node. For example, the client can log in to the data node corresponding to the client by using the computing node through a login request. The user can input relevant request information through the client, such as authentication information such as username and password when making a login request, and specific operation information when making a data management request. After the client processes this information, it sends it to the computing node. The computing node receives the request and processes it based on the data node, and the client then displays the operation result to the user according to the response of the computing node, thus completing a complete interaction process. Among them, the client can, for example, refer to client software (such as an application program), a web client, etc., or the client can also refer to the electronic device where the client is located, such as a computer, a tablet computer, a smart phone, etc. These electronic devices, as hardware carriers, run corresponding software or implement client functions through a browser to meet the needs of different users to operate the distributed database in different scenarios.
[0076] For the login authentication scenario in a distributed database (i.e., the computing node authenticates the login request of the authentication client to enable a user with access rights to access the data nodes in the distributed database through the client), currently, the computing node stores the identifier of the account of the data node (such as username, account name, account number), the plaintext password of the account, or the decryptable ciphertext password in the configuration file system, or stores it in a remote repository (such as zookeeper). When the user authenticates the login to the data node through the client, it depends on the plaintext password of the account stored in the computing node or the decryptable ciphertext password, and the corresponding identifier of the account to authenticate the login request of the client to achieve logging in to the data node.
[0077] However, the current login authentication method for distributed databases has the problem of low security. For example, the plaintext password or the decryptable ciphertext password stored in the computing node is stored on the disk. If attacked, there will be a risk of leakage of the plaintext password or the decryptable ciphertext password. If the plaintext password or the decryptable ciphertext password is leaked, the attacker can illegally log in to the data node through the leaked plaintext password or the decryptable ciphertext password, resulting in problems such as data leakage, being tampered with, or malicious deletion. Due to the wide distribution of the nodes in the distributed database, the security boundary expands, and the attack surface increases, resulting in low security of the current login authentication method for distributed databases.
[0078] In view of this, the present application provides a password authentication method. By storing an undecryptable ciphertext related to the identifier of the target account and the local password of the target account in the computing node, and when the client requests to log in to the target account, receiving the undecryptable first encrypted information sent by the client based on the identifier of the target account, the input password of the target account, and the target encryption field. According to the first encrypted information and the second encrypted information generated from the ciphertext stored in the computing node, it is determined whether to pass the login request of the client. Compared with the existing method in which the computing node directly stores the plaintext password or the decryptable ciphertext password of the target account, this method can reduce the risk of the attacker obtaining the password of the target account by attacking the computing node, thereby improving the security and reliability of password authentication.
[0079] The following takes Figure 1 the system structure of
[0080] Figure 2 as an example, and through specific embodiments, the technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail. The following several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings. Figure 2As shown, the method includes:
[0081] S201. The client sends a login request to the computing node.
[0082] Correspondingly, the computing node receives the login request sent by the client.
[0083] Among them, the login request includes the identifier of the target account, which can be, for example, the username, account name, account number, etc. of the target account. This login request is used for the client to request to log in to the target account to access the data nodes of the distributed database through the target account. The computing node determines the account that the client needs to log in to based on the identifier of the target account carried in the received login request.
[0084] This login request can be sent based on the network protocol between the client and the computing node. For example, it can be sent through the Transmission Control Protocol / Internet Protocol (TCP / IP) protocol, HyperText Transfer Protocol (HTTP) / HyperText Transfer Protocol Secure (HTTPS) protocol, etc. This login request can be in text format (such as JSON or XML format), or in binary format, etc.
[0085] S202. The client generates the first encrypted information according to the target encryption field, the identifier of the target account, and the input password of the target account.
[0086] The client can determine the input password of the user in response to the user input. For example, the user enters a password in the password input box on the interface of the client, and the client determines the input password of the target account according to the password entered by the user.
[0087] The target encryption field can be, for example, a salt, a random salt, a random number seed, and any other field that can be used for encryption, etc. The present application does not limit this. Among them, the target encryption field can be one field or multiple fields.
[0088] This first encrypted information can be obtained by encrypting in any encryption order according to the execution of the target encryption field, the identifier of the target account, and the input password of the target account in sequence.
[0089] For example, the input password can be encrypted first using the username of the target account to obtain an encrypted result, and then the encrypted result can be further encrypted using the target encryption field to generate the first encrypted information. Or, the input password of the target account can be encrypted first using the target encryption field to obtain an encrypted result, and then the encrypted result can be encrypted using the username of the target account to generate the first encrypted information. Or, the username of the target account can be encrypted first using the target encryption field to obtain an encrypted result, and then the encrypted result can be encrypted using the input password of the target account to generate the first encrypted information, etc. This application does not make specific limitations on the encryption order.
[0090] Among them, the encryption method used in the above encryption process can be implemented, for example, through a hash encryption algorithm (such as MD5 hash algorithm, SHA-256 hash algorithm, etc.). This application does not limit the specific encryption algorithm.
[0091] S203. The client sends the first encrypted information to the computing node.
[0092] Correspondingly, the computing node receives the first encrypted information sent by the client.
[0093] After the client generates the first encrypted information, it sends the first encrypted information to the computing node, so that the computing node can subsequently determine whether the login request of the client is a legitimate login request based on the first encrypted information, in order to determine whether to pass the login request of the client.
[0094] The first encrypted information can be sent through the network protocol between the computing node and the client, or in formats such as text or binary.
[0095] S204. The computing node obtains the second encrypted information.
[0096] Among them, the second encrypted information is related to the identifier of the target account, the local password of the target account, and the target encryption field.
[0097] When the target account has not had a password update, the local password of the target account is the password set when the target account was created and temporarily stored in the computing node; when the target account has sent a password update, the local password of the target account is the updated password temporarily stored in the computing node during the last update of the target account. Among them, the local password is not persistently stored in the computing node. After the computing node obtains the local password, it encrypts the local password, generates and persistently stores the encrypted result of the local password, and then deletes the temporarily stored local password to reduce the situation of leaking the local password when under attack.
[0098] A possible implementation is that the second encrypted information is pre-generated according to the identifier of the target account, the local password of the target account, and the target encrypted field. When the computing node needs to obtain the second encrypted information, it can directly obtain the second encrypted information from the storage space.
[0099] Another possible implementation is that the second encrypted information can be generated immediately when the computing node needs to obtain the second encrypted information. For example, when the service segment needs to obtain the second encrypted information, it can be generated immediately according to the encrypted result of the local password stored persistently, and the target encrypted field and / or the identifier of the target account. For example, if the encrypted result of the local password stored persistently is generated according to the local password and the target encrypted field, the second encrypted information can be generated according to the encrypted result of the local password and the identifier of the target account, or the second encrypted information can be generated according to the encrypted result of the local password, the identifier of the target account, and the target encrypted field; or, if the encrypted result of the local password stored persistently is generated according to the local password and the identifier of the target account, the second encrypted information can be generated according to the encrypted result of the local password and the target encrypted field, or the second encrypted information can be generated according to the encrypted result of the local password, the identifier of the target account, and the target encrypted field, etc.
[0100] It should be understood that the encryption method of the second encrypted information (such as the encryption algorithm used for encryption, the order of encryption) is related to the encryption method of the first encrypted information, so that the computing node can subsequently determine whether the login request is a legal login request based on the first encrypted information or the result after processing the first encrypted information, and the second encrypted information.
[0101] S205. The computing node determines whether to pass the login request of the client according to the first encrypted information and the second encrypted information.
[0102] A possible implementation is that the encryption algorithms and the order of encryption used for the first encrypted information and the second encrypted information are exactly the same. At this time, by determining whether the first encrypted information and the second encrypted information are the same, it can be determined whether to pass the login request of the client. Since the encryption algorithms and the order of encryption used for the first encrypted information and the second encrypted information are exactly the same, if the input password is correct (that is, the input password is the same as the local password), the first encrypted information and the second encrypted information are the same, and it can be determined that the login request is legal and the login request of the client is passed. Otherwise, it can be determined that the login request is illegal and the login request of the client is rejected.
[0103] In another possible implementation, after the computing node receives the first encrypted information, it can further encrypt the first encrypted information according to the encryption method of the second encrypted information to obtain encrypted information that can be compared with the second encrypted information (i.e., the result information obtained by further encrypting the first encrypted information). At this time, by determining whether the result information obtained by further encrypting the first encrypted information is the same as the second encrypted information, it can be determined whether to pass the login request of the client.
[0104] If the judgment is passed, it indicates that the login request of the client is from a user with access permission, and step S206 is executed; if the judgment is not passed, it indicates that the login request of the client is not from a user with access permission, and step S207 is executed.
[0105] Optionally, after the judgment is completed, the computing node can also return the judgment result to the client to prompt the user whether they can log in or whether there is an incorrect password input, etc.
[0106] S206. The computing node allows the client to log in.
[0107] S207. The computing node rejects the client's login.
[0108] In the method provided by the embodiment of the present application, the computing node receives a login request sent by the client including the identifier of the target account, and receives the first encrypted information sent by the client generated according to the target encryption field, the identifier of the target account, and the input password of the target account. The computing node obtains second encrypted information related to the identifier of the target account, the local password of the target account, and the target encryption field. The computing node determines whether to pass the login request of the client according to the first encrypted information and the second encrypted information. If it passes, the client is allowed to log in. Compared with the prior art in which the computing node directly stores the clear text of the target account password or the decryptable cipher text of the password, this method does not persistently store the clear text of the target account password or the decryptable cipher text of the password in the computing node, thereby reducing the risk that an attacker can obtain the password of the target account by attacking the computing node, and further improving the security and reliability of password authentication.
[0109] Optionally, the client and the computing node can perform login authentication through one or more authentication methods. When the client and the computing node can perform login authentication through multiple authentication methods, the computing node can determine the authentication method for the client's login authentication according to whether the client is logging in through this computing node for the first time. For example, when the client is logging in through this computing node for the first time, it can be determined that the authentication method for the client's login authentication is the first authentication method; when the client is not logging in through this computing node for the first time, it can be determined that the authentication method for the client's login authentication is the second authentication method.
[0110] Next, taking the example where the client and the computing node can perform login authentication through two authentication methods, namely the first authentication method and the second authentication method, as an example. Among them, the first authentication method can be, for example, MD5_REVERSE authentication, or any other authentication method similar to the implementation steps of the MD5_REVERSE authentication, etc.; the second authentication method can be, for example, MD5 authentication.
[0111] Figure 3 It is a schematic flowchart of another password authentication method provided by the embodiments of the present application. As Figure 3 shown, the method may specifically include:
[0112] S301. The client sends a login request to the computing node.
[0113] Correspondingly, the computing node receives the login request sent by the client.
[0114] Among them, the login request includes the identifier of the target account.
[0115] S302. If the computing node determines that the client is logging in through this computing node for the first time according to the login request, it sends a first authentication indication to the client.
[0116] Correspondingly, the client receives the first authentication indication sent by the computing node.
[0117] Among them, the first authentication indication is used to instruct the client to perform login authentication through the first authentication method.
[0118] The first authentication method can be carried in the first authentication indication in the form of an authentication method identifier, for example, "the authentication method is the first authentication method" or "the authentication method is MD5_REVERSE authentication" can be carried in the first authentication indication, etc., or a specific field representing the first authentication method (for example, 0 represents the first authentication method, 1 represents the second authentication method, etc., or it can be other specific fields, and the present application does not limit this) can be carried in the first authentication indication, etc.
[0119] Among them, the first login refers to whether the client has ever successfully logged in through this computing node after each startup or restart of the computing node. If the client has not successfully logged in through this computing node after each startup or restart of the computing node, then the login request is a first login.
[0120] In this step, the computing node can determine whether the client logs in through this computing node for the first time based on the identifier of the target account included in the login request and the historical login information of the computing node. If there is no historical login account corresponding to the identifier of the target account in the historical login information of the computing node, it is determined that the client logs in through this computing node for the first time.
[0121] Alternatively, the computing node can determine whether the client logs in through this computing node for the first time based on whether the storage node password of the target account is stored. If the computing node does not store the storage node password of the target account, it is determined that the client logs in through this computing node for the first time.
[0122] S303. The client generates first encrypted information based on the first authentication method according to the target encryption field, the identifier of the target account, and the input password of the target account.
[0123] Wherein, the target encryption field is the target encryption field generated and stored by the computing node after the password of the target account is updated. For example, each time the password of the target account is updated, a target encryption field can be generated, sent to the client, and stored in the computing node. If there is no subsequent password update of the target account, the target encryption field is used for each subsequent login authentication; if there is a subsequent password update of the target account, the newly generated target encryption field is used to replace the original target encryption field, and the newly generated target encryption field is used for each subsequent login authentication. The target encryption field can be, for example, a salt, or any randomly generated field can be used as the target encryption field, etc.
[0124] Specifically, the client can first encrypt the input password of the target account with the target encryption field, and then use the identifier of the target account to encrypt the input password encrypted by the target encryption field for secondary encryption to generate the first encrypted information.
[0125] Exemplarily, continuing to assume that the identifier of the target account is username, the input password of the target account is password1, and the target encryption field is Salt, and the encryption is implemented using the MD5 hash algorithm as an example, the first encrypted information generated according to the target encryption field, the identifier of the target account, and the input password of the target account can be denoted as
[0126] password1.md5Digest(salt).md5Digest(username).
[0127] Optionally, the encryption order can also be adjusted according to actual needs, and this application does not limit this.
[0128] S304. The client sends the first encrypted information to the computing node based on the first authentication method.
[0129] Correspondingly, the computing node receives the first encrypted information sent by the client based on the first authentication method.
[0130] S305. The computing node obtains the second encrypted information.
[0131] In this implementation, since the target encryption field is persistently stored in the computing node, each time the target encryption field is updated, it can be encrypted according to the target encryption field, the updated password of the target account (i.e., the local password temporarily stored in the computing node), and the identifier of the target account to obtain the second encrypted information, which is then persistently stored, and at the same time, the updated password of the target account is deleted from the storage.
[0132] When the computing node needs to obtain the second encrypted information, it can obtain the pre-generated and stored second encrypted information from the storage space.
[0133] Specifically, the method by which the computing node pre-encrypts according to the target encryption field, the updated password of the target account (i.e., the local password temporarily stored in the computing node), and the identifier of the target account includes the method by which the client generates the first encrypted information according to the target encryption field, the identifier of the target account, and the input password of the target account.
[0134] Exemplarily, continuing to assume that the identifier of the target account is username, the input password of the target account is password1, the local password of the target account is password2, and the target encryption field is Salt, and the encryption is implemented using the MD5 hash algorithm as an example, the second encrypted information pre-generated and stored by the computing node according to the target encryption field, the updated password of the target account (i.e., the local password temporarily stored in the computing node), and the identifier of the target account can be recorded as:
[0135] password2.md5Digest(salt).md5Digest(username).md5Digest(salt).md5Digest(salt).
[0136] Among them, password2.md5Digest(salt).md5Digest(username) is the part with the same generation method when the client generates the first encrypted information according to the target encryption field, the identifier of the target account, and the input password of the target account. The only difference is that the client uses the input password password1, while the computing node uses the local password password2.
[0137] It should be understood that the above is only for easy understanding and is introduced by taking an example, rather than limiting the implementation method. Among them, the specific encryption order can be restricted according to the corresponding rules configured according to actual needs (for example, configured in the authentication method), and the specific number of times of encrypting through the target encryption field to obtain the second encrypted information can also be determined according to actual needs, rather than being limited to the two times in the above example (that is, md5Digest(salt).md5Digest(salt)).
[0138] S306. The computing node generates a third encrypted information according to the first encrypted information and the target encryption field.
[0139] In this step, after receiving the first encrypted information, the computing node can use the target encryption field to encrypt the first encrypted information according to the encryption method corresponding to the second authentication method to generate the third encrypted information.
[0140] Continuing with the examples in steps S303 and S305 above, assume that the second encrypted information is:
[0141] password2.md5Digest(salt).md5Digest(username).md5Digest(salt).md5Digest(salt).
[0142] The first encrypted information is password1.md5Digest(salt).md5Digest(username). The target encryption field is Salt.
[0143] Then the computing node can use the target encryption field to encrypt the first encrypted information twice based on the MD5 hash algorithm to generate the third encrypted information:
[0144] password1.md5Digest(salt).md5Digest(username).md5Digest(salt).md5Digest(salt).
[0145] S307. The computing node determines whether the third encrypted information is the same as the second encrypted information.
[0146] Since the encryption algorithms and encryption orders of the third encrypted information and the second encrypted information are exactly the same, if the input password is correct (that is, the input password is the same as the local password), the third encrypted information is the same as the second encrypted information, and it can be determined that the login request is legal and the login request of the client is passed. Otherwise, it can be determined that the login request is illegal and the login request of the client is rejected.
[0147] Therefore, if the third encrypted information is the same as the second encrypted information, it indicates that the input password is correct, and the login request of the client is from a user with access permission, and step S308 is executed; if the third encrypted information is different from the second encrypted information, it indicates that the input password is incorrect, and the login request of the client is not from a user with access permission, and step S309 is executed.
[0148] S308. The computing node allows the client to log in.
[0149] S309. The computing node rejects the client's login.
[0150] In the method provided by the embodiment of the present application, the computing node receives the login request sent by the client. If the computing node determines that the client is logging in through this computing node for the first time according to the login request, it sends a first authentication indication to the client, instructing the client to perform login authentication through the first authentication method. The client generates the first encrypted information based on the first authentication method according to the target encryption field, the identifier of the target account, and the input password of the target account. The computing node receives the first encrypted information sent by the client based on the first authentication method and obtains the second encrypted information. The computing node generates the third encrypted information according to the first encrypted information and the target encryption field. If the third encrypted information is the same as the second encrypted information system, the computing node allows the client to log in. Compared with the existing method in which the computing node directly stores the clear text of the password of the target account or the decryptable cipher text of the password, this method does not persistently store the clear text of the password of the target account or the decryptable cipher text of the password in the computing node, thereby reducing the risk that an attacker can obtain the password of the target account by attacking the computing node, and further improving the security and reliability of password authentication.
[0151] Next, the aforementioned Figure 3 target encryption field and the second encrypted information of the computing node are introduced in detail. Figure 4 It is a schematic flowchart of another password authentication method provided by the embodiment of the present application. As Figure 4 shown, the method may further include:
[0152] S401. After the client updates the password of the target account, the computing node generates a target encryption field.
[0153] After each password update of the target account is completed, the operation of generating the target encryption field by the computing node can be triggered to generate the target encryption field corresponding to the target account before the next password update, that is, the encryption for login authentication is performed using the same target encryption field before the next password update.
[0154] Among them, the target encryption field can be any randomly generated field. For example, it can be a salt, or it can be other fields that can be used to encrypt data, etc. When the target encryption field is randomly generated, the target encryption field can be generated by a random number generation method. Among them, the specific random number generation method can refer to the prior art, and this application does not limit it.
[0155] S402. The computing node sends the target encryption field to the client.
[0156] The client receives the target encryption field sent by the computing node.
[0157] S403. The computing node generates second encrypted information based on the target encryption field, the identifier of the target account, and the updated password.
[0158] Since the password of the target account has just been updated, the updated password can be temporarily stored. And based on the target encryption field, the identifier of the target account, and the updated password, the second encrypted information is generated through multiple encryptions. Among them, for the specific encryption method, reference can be made to the foregoing step S305, which will not be elaborated here.
[0159] S404. The computing node stores the mapping relationship among the second encrypted information, the target encryption field, and the identifier of the target account.
[0160] After the second encrypted information is generated, the second encrypted information, the target encryption field, and the identifier of the target account, as well as the mapping relationship among them, can be stored, so that the subsequent computing node can extract the target encryption field and the second encrypted information corresponding to the identifier of the target account according to the identifier of the target account carried in the received login request.
[0161] After the computing node completes storing the mapping relationship among the second encrypted information, the target encryption field, and the identifier of the target account, it can delete the temporarily stored updated password of the target account to prevent the attacker from obtaining the updated password of the target account from the storage when the computing node is attacked.
[0162] Figure 5 It is a schematic flowchart of another password authentication method provided by the embodiments of this application. As Figure 5 shown, the method may further include:
[0163] S501. The computing node generates the password of the data node corresponding to the client according to the first encrypted information and the target encryption field.
[0164] Among them, the client may correspond to one or more data nodes, and the passwords of the multiple data nodes corresponding to the client are the same.
[0165] In this step, the first encrypted information can be encrypted by the target encryption field to obtain the password of the data node corresponding to the client. For example, continuing with the example in the foregoing step S305, the first encrypted information is password1.md5Digest(salt).md5Digest(username). The target encryption field is Salt. Then, the first encrypted information can be encrypted by the target encryption field to obtain the password of the data node corresponding to the client as follows:
[0166] password1.md5Digest(salt).md5Digest(username).md5Digest(salt).
[0167] Optionally, the first encrypted information can be encrypted multiple times by the target encryption field. For example, it can be encrypted two or three times, etc., to obtain the data node password. It should be noted that to improve security, the number of times the first encrypted information is encrypted by the target encryption field in the encryption rule for obtaining the data node password should be less than the number of times the first encrypted information is encrypted multiple times by the target encryption field to generate the third encrypted information. That is, assuming that the foregoing third encrypted information is obtained by encrypting the first encrypted information twice by the target encryption field, the number of times the first encrypted information is encrypted by the target encryption field in the generation rule of the data node password should not exceed two times.
[0168] S502. After the computing node allows the client to log in, it enables the client to log in to the data node according to the password of the data node.
[0169] After the computing node allows the login, it can allow the client to log in to and access the data node through the password of the data node.
[0170] In the method provided by the embodiment of the present application, the computing node generates the password of the data node corresponding to the client according to the first encrypted information and the target encryption field, and after allowing the client to log in, enables the client to log in to the data node according to the password of the data node. Among them, since only the target encryption field and the third encrypted information are stored in the computing node, and the hash encryption is irreversible, even if the target encryption field and the third encrypted information stored in the computing node are leaked, the user password and the data node password cannot be deduced, thereby improving the security of the login authentication.
[0171] Next, the case where the client logs in to the computing node for the non-first time is introduced.
[0172] Figure 6 It is a schematic flowchart of another password authentication method provided by the embodiment of the present application. As Figure 6 shown, the method may specifically include:
[0173] S601. The client sends a login request to the computing node.
[0174] Correspondingly, the computing node receives the login request sent by the client.
[0175] Wherein, the login request includes the identifier of the target account.
[0176] S602. If the computing node determines, based on the login request, that the client is not logging in for the first time through this computing node, it sends a second authentication instruction to the client.
[0177] Correspondingly, the client receives the second authentication instruction sent by the computing node.
[0178] Wherein, the second authentication instruction is used to instruct the client to perform login authentication through the second authentication method.
[0179] This second authentication method can be carried in the form of an authentication method identifier in the second authentication instruction. For example, it can carry "the authentication method is the second authentication method" or "the authentication method is MD5 authentication" etc. in the second authentication instruction, or carry a specific field representing the second authentication method (for example, 0 represents the first authentication method, 1 represents the second authentication method, etc., and it can also be other specific fields, and this application does not limit this) etc. in the second authentication instruction.
[0180] Wherein, this first login refers to whether the client has ever successfully logged in through this computing node after each startup or restart of the computing node. If the client has not successfully logged in through this computing node after each startup or restart of the computing node, then this login request is a first login.
[0181] In this step, the computing node can determine whether the client is logging in for the first time through this computing node based on the identifier of the target account included in the login request and the historical login information of the computing node. If there is a historical login account corresponding to the identifier of the target account in the historical login information of the computing node, it is determined that the client is not logging in for the first time through this computing node.
[0182] Alternatively, the computing node can determine whether the client is logging in for the first time through this computing node based on whether it stores the storage node password of the target account. If the computing node stores the storage node password of the target account, it is determined that the client is not logging in for the first time through this computing node.
[0183] S603. The computing node sends a target encryption field to the client.
[0184] Correspondingly, the client receives the target encryption field sent by the computing node.
[0185] Among them, the target encrypted field is a target encrypted field instantaneously generated by the computing node for the current login authentication behavior of the target account after receiving the login request. For example, it can be a randomly generated salt (randomSalt) instantaneously, or a randomly generated field can be used as the target encrypted field, etc.
[0186] S604. The client generates first encrypted information based on the target encrypted field, the identifier of the target account, and the input password of the target account.
[0187] Specifically, the client can first encrypt the input password of the target account using the identifier of the target account. This encryption can be implemented using, for example, the MD5 hashing algorithm to obtain the initial first encrypted information. Exemplarily, assume that the identifier of the target account is username and the input password of the target account is password1. Then the initial first encrypted information can be denoted as username.md5Digest(password1), indicating that based on the MD5 hashing algorithm, i.e., md5Digest(), the input password of the target account is encrypted using the identifier of the target account.
[0188] After obtaining the initial first encrypted information, the target encrypted field can be further used to encrypt the initial first encrypted information to generate the first encrypted information. Continuing with the example where the initial first encrypted information is denoted as username.md5Digest(password1) and the target encrypted field is the random salt (randomSalt), the first encrypted information can be denoted as:
[0189] username.md5Digest(password).md5Digest(randomSalt).
[0190] Optionally, the client can also first encrypt the identifier of the target account using the input password of the target account to obtain the initial first encrypted information. Continuing with the example where the identifier of the target account is username and the input password of the target account is password1, the initial first encrypted information can be denoted as password.md5Digest(username). Correspondingly, the first encrypted information generated based on the initial first encrypted information can be denoted as:
[0191] password.md5Digest(username).md5Digest(randomSalt).
[0192] S605. The client sends the first encrypted information to the computing node based on the second authentication method.
[0193] Correspondingly, the computing node receives the first encrypted information sent by the client based on the second authentication method.
[0194] S606. The computing node obtains the second encrypted information.
[0195] In this implementation, the computing node can pre-store the fourth encrypted information generated based on the identifier of the target account and the local password of the target account, where the fourth encrypted information is generated in the same way as the client generates the initial first encrypted information. For example, if the initial first encrypted information is username.md5Digest(password1), then the fourth encrypted information is username.md5Digest(password2), where password2 is the local password of the target account. The ways of generating the initial first encrypted information and pre-generating the fourth encrypted information can be predefined by rules.
[0196] The computing node generates the second encrypted information based on the pre-stored fourth encrypted information and the target encrypted field instantaneously generated for the current login authentication behavior of the target account. Taking the fourth encrypted information as username.md5Digest(password2) and the target encrypted field as the random salt randomSalt, the fourth encrypted information can be hashed with the random salt randomSalt to obtain the second encrypted information username.md5Digest(password).md5Digest(randomSalt).
[0197] S607. The computing node determines whether the first encrypted information is the same as the second encrypted information.
[0198] Since the encryption algorithms and encryption orders used for the first encrypted information and the second encrypted information are exactly the same, if the input password is correct (i.e., the input password is the same as the local password), then the first encrypted information and the second encrypted information are the same, and it can be determined that the login request is legal, and the login request of the client is passed. Otherwise, it can be determined that the login request is illegal, and the login request of the client is rejected.
[0199] Therefore, if the first encrypted information is the same as the second encrypted information, it indicates that the input password is correct, and the login request of the client is from a user with access rights, and step S608 is executed; if the first encrypted information is different from the second encrypted information, it indicates that the input password is incorrect, and the login request of the client is not from a user with access rights, and step S609 is executed.
[0200] S608. The computing node allows the client to log in.
[0201] S609. The computing node rejects the client's login.
[0202] In the method provided by the embodiment of the present application, the computing node receives a login request sent by the client. If the computing node determines according to the login request that the client is not logging in through this computing node for the first time, it sends a second authentication indication to the client, instructing the client to perform login authentication through the second authentication method. Then, the computing node sends a target encryption field to the client. The client generates first encrypted information based on the target encryption field, the identifier of the target account, and the input password of the target account, and sends the first encrypted information to the computing node based on the second authentication method. The computing node determines whether to allow the client to log in by judging whether the first encrypted information is the same as the second encrypted information generated by itself. Compared with the prior art in which the computing node directly stores the cleartext password of the target account or the decryptable ciphertext password, this method does not persistently store the cleartext password of the target account or the decryptable ciphertext password in the computing node, thereby reducing the risk of an attacker obtaining the password of the target account by attacking the computing node, and further improving the security and reliability of password authentication.
[0203] Figure 7 It is a schematic structural diagram of a password authentication device provided by an embodiment of the present application. As Figure 7 shown, this password authentication device is used for a computing node, and the device may include: a first receiving module 11, a second receiving module 12, an obtaining module 13, a processing module 14, and a control module 15. In a possible implementation manner, a sending module 16 may further be included.
[0204] The first receiving module 11 is configured to receive a login request sent by the client, and the login request includes the identifier of the target account.
[0205] The second receiving module 12 is configured to receive the first encrypted information sent by the client, and the first encrypted information is generated based on the target encryption field, the identifier of the target account, and the input password of the target account.
[0206] The obtaining module 13 is configured to obtain second encrypted information, and the second encrypted information is related to the identifier of the target account, the local password of the target account, and the target encryption field.
[0207] The processing module 14 is configured to determine whether to pass the login request of the client according to the first encrypted information and the second encrypted information.
[0208] The control module 15 is configured to, if it passes, allow the client to log in.
[0209] Optionally, when the login request is the first time the client logs in through the computing node, the sending module 16 is configured to send a first authentication indication to the client, and the first authentication indication is used to instruct the client to perform login authentication through the first authentication method. The second receiving module 12 is specifically configured to receive the first encrypted information sent by the client based on the first authentication method.
[0210] Optionally, the processing module 14 is specifically configured to generate a target encrypted field after the client updates the password of the target account. The sending module 16 is specifically configured to send the target encrypted field to the client. The processing module 14 is specifically configured to generate second encrypted information based on the target encrypted field, the identifier of the target account, and the updated password. Store the mapping relationship among the second encrypted information, the target encrypted field, and the identifier of the target account.
[0211] Optionally, the processing module 14 is specifically configured to generate third encrypted information according to the first encrypted information and the target encrypted field. If the third encrypted information is the same as the second encrypted information, the login request of the client is passed.
[0212] Optionally, the processing module 14 is further configured to generate the password of the data node corresponding to the client according to the first encrypted information and the target encrypted field. The control module 15 is further configured to, after allowing the client to log in, enable the client to log in to the data node according to the password of the data node.
[0213] Optionally, when the login request is not the first time the client logs in through the computing node, the sending module 16 is further configured to send a second authentication indication to the client, and the second authentication indication is used to instruct the client to perform login authentication through the second authentication method. The second receiving module 12 is specifically configured to receive the first encrypted information sent by the client based on the second authentication method.
[0214] Optionally, the sending module 16 is further configured to send the target encrypted field to the client after receiving the login request.
[0215] Optionally, the obtaining module 13 is specifically configured to obtain fourth encrypted information generated based on the identifier of the target account and the local password of the target account. Obtain the second encrypted information according to the target encrypted field and the fourth encrypted information.
[0216] Optionally, the processing module 14 is specifically configured to determine that the login request of the client is passed if the first encrypted information is the same as the second encrypted information.
[0217] The password authentication device provided in the embodiments of the present application can execute the password authentication method applied to the computing node in the above method embodiments, and its implementation principle and technical effects are similar and will not be described in detail here.
[0218] Figure 8This is a schematic structural diagram of another password authentication device provided by an embodiment of the present application. As Figure 8 shown, this password authentication device is applied to a client, and the device includes: a first sending module 21, a processing module 22, and a second sending module 23. In a possible implementation manner, a receiving module 24 may further be included.
[0219] The first sending module 21 is configured to send a login request to a computing node, where the login request includes an identifier of a target account.
[0220] The processing module 22 is configured to generate first encrypted information according to a target encryption field, the identifier of the target account, and the input password of the target account.
[0221] The second sending module 23 is configured to send the first encrypted information to the computing node
[0222] Optionally, when the authentication method is a first authentication method, the receiving module 24 is configured to receive the target encryption field sent by the computing node after the password of the target account is updated on the client.
[0223] Optionally, when the authentication method is a second authentication method, the receiving module 24 is further configured to receive the target encryption field sent by the computing node after sending the login request to the computing node.
[0224] The password authentication device provided by the embodiment of the present application can execute the password authentication method applied to the client in the foregoing method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated herein.
[0225] Figure 9 This is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Among them, the electronic device is used to execute the foregoing password authentication method, and may be, for example, the foregoing computing node or client. As Figure 9 shown, the electronic device 900 may include: at least one processor 901, a memory 902, and a communication interface 903.
[0226] The memory 902 is used to store a program. Specifically, the program may include program code, and the program code includes computer operation instructions.
[0227] The memory 902 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory.
[0228] The processor 901 is used to execute the computer-executable instructions stored in the memory 902 to implement the method described in the foregoing method embodiments. Among them, the processor 901 may be a CPU, or a specific integrated circuit (Application Specific Integrated Circuit, abbreviated as ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0229] The processor 901 can communicate with external devices through the communication interface 903. When the electronic device is a computing node, the external device may be, for example, the foregoing client; when the electronic device is a client, the external device may be, for example, the foregoing computing node, etc. In specific implementation, if the communication interface 903, the memory 902, and the processor 901 are independently implemented, the communication interface 903, the memory 902, and the processor 901 can be interconnected through a bus and complete communication with each other. The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc., but it does not mean that there is only one bus or one type of bus.
[0230] Optionally, in specific implementation, if the communication interface 903, the memory 902, and the processor 901 are integrated on a chip, the communication interface 903, the memory 902, and the processor 901 can complete communication through an internal interface.
[0231] This application also provides a password authentication system as described above Figure 1 shown, and the password authentication system is used to implement the above password authentication method.
[0232] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above method is implemented.
[0233] This application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the processor executes the computer-executable instructions, the above method is implemented.
[0234] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0235] An exemplary readable storage medium is coupled to the processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0236] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be an indirect coupling or communication connection through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0237] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0238] In addition, each functional unit in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0239] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, and other various media that can store program codes.
[0240] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When this program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: ROMs, RAMs, magnetic disks, or optical discs, and other various media that can store program codes.
[0241] Finally, it should be noted that: After considering the specification and practicing the invention disclosed herein, those skilled in the art will easily think of other implementation manners of the present invention. The present invention is intended to cover any variations, uses, or adaptive changes of the present invention. These variations, uses, or adaptive changes follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed in the present invention. It is not limited to the exact structure described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A password authentication method, characterized in that: Applied to compute nodes, including: Receiving a login request sent by a client, wherein the login request includes an identifier of a target account; Receiving first encrypted information sent by the client, where the first encrypted information is generated according to a target encryption field, an identifier of the target account, and an input password of the target account; Obtaining second encrypted information, the second encrypted information being associated with an identifier of the target account, a local password of the target account, and the target encrypted field; determining whether the login request of the client is approved according to the first encrypted information and the second encrypted information; If passed, the client is allowed to log in.
2. The method according to claim 1, characterized in that Also includes: If the login request is the first login of the client through the computing node, sending a first authentication instruction to the client, where the first authentication instruction is used to instruct the client to perform login authentication through a first authentication method; The receiving the first encrypted information sent by the client includes: Receive first encrypted information sent by the client based on a first authentication method.
3. The method according to claim 2, characterized in that The method further comprises: After the client updates the password of the target account, generating the target encrypted field; Sending the target encrypted field to the client; generating the second encrypted information based on the target encrypted field, the identifier of the target account, and the updated password; A mapping relationship between the second encrypted information, the target encrypted field, and the identifier of the target account is stored.
4. The method according to claim 3, characterized in that Determining whether the login request of the client is passed according to the first encrypted information and the second encrypted information includes: Generate third encrypted information according to the first encrypted information and the target encrypted field; If the third encrypted information is the same as the second encrypted information, the login request of the client is approved.
5. The method according to any one of claims 2 to 4, characterized in that: Also includes: Generate a password of the data node corresponding to the client according to the first encryption information and the target encryption field; After the client is allowed to log in, the client is allowed to log in to the data node according to the password of the data node.
6. The method according to claim 1, characterized in that Also includes: If the login request is not the first login of the client through the computing node, sending a second authentication instruction to the client, where the second authentication instruction is used to instruct the client to perform login authentication through a second authentication method; The receiving the first encrypted information sent by the client includes: Receive first encrypted information sent by the client based on the second authentication method.
7. The method according to claim 6, characterized in that The method further comprises: After receiving the login request, the target encrypted field is sent to the client.
8. The method according to claim 7, characterized in that The obtaining of the second encrypted information comprises: Obtain fourth encrypted information generated based on the identifier of the target account and the local password of the target account; The second encrypted information is acquired according to the target encrypted field and the fourth encrypted information.
9. The method according to claim 8, characterized in that Determining whether the login request of the client is passed according to the first encrypted information and the second encrypted information includes: If the first encryption information is the same as the second encryption information, it is determined that the login request of the client is passed.
10. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 9.