Intelligent password automatic extraction and secure storage method

By dynamically evaluating environmental risk levels and identifying abnormal user behaviors, intelligently adjusting password extraction and storage strategies, the problem of neglecting password security by environmental changes and user behavior patterns in the existing technology is solved, and higher security and adaptability are achieved.

CN120217353AActive Publication Date: 2025-06-27JIANGSU HEGUAN INFORMATION TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510225375.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-27
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

The prior art ignores the impact of environmental changes and user behavior patterns on password security in password extraction and storage processes, resulting in security vulnerabilities and insufficient adaptability.

Method used

By obtaining the current environment parameters, quantifying and weight allocation based on the historical user behavior model, dynamically assessing the environmental risk level, and using the Hidden Markov model to identify abnormal user behavior, intelligently adjusting password extraction and storage strategies.

Benefits of technology

It effectively avoids the security risks ignored due to environmental changes in traditional password management, enhances the overall security and adaptability of password extraction and storage, and improves the intelligence level of the password management system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217353A_ABST
    Figure CN120217353A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent password automatic extraction and secure storage method, which comprises the steps of dynamically evaluating an environmental risk and intelligently adjusting a password extraction and storage strategy according to a risk level by analyzing environmental parameters and historical user behavior data; according to the method, the user behavior is modeled through the hidden Markov model, the abnormal behavior is recognized in real time, and the unsafe password extraction process is stopped, so that the intelligence and safety of password management are effectively improved, the adaptability and safety of the password extraction process are improved, and the user experience is improved. And the reliability of local and cloud storage is guaranteed through a password migration mechanism, and the method has relatively high security, flexibility and operability and is suitable for digital platforms and intelligent equipment with high security requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of password extraction and secure storage processing, and particularly to an intelligent password automatic extraction and secure storage method. Background Art

[0002] With the wide application of information technology, password protection has become one of the important research topics in the field of information security. As the core means of digital identity authentication, passwords are widely used in multiple fields such as network services, electronic payments, and social platforms. However, with the continuous development of network attack technologies, the security and reliability of traditional password management methods face severe challenges. Especially in the process of password storage and extraction, traditional methods often rely too much on users' active operations and memory, and there are significant deficiencies in the dynamic detection of environmental risks and abnormal behaviors. Most of the existing technologies focus on the encrypted storage and access control of passwords, and do not fully consider the impact of environmental changes and behavior patterns during the password extraction process on password security, resulting in certain security vulnerabilities in the password storage process.

[0003] Existing intelligent password management systems mostly manage and store passwords based on static rules, with relatively low security and adaptability. For example, although the device-based storage encryption and user identity authentication mechanisms can prevent external attacks, they ignore the dynamic changes of environmental risk factors, such as the user's location, device network status, and surrounding light, etc. These factors have potential impacts on password security. In addition, most of the existing intelligent password extraction methods only rely on user behavior patterns or device states, and fail to dynamically adjust according to the environmental risk level during the password extraction process. Therefore, in the face of complex usage scenarios and changing security requirements, existing technologies often struggle to provide sufficient security guarantees. Summary of the Invention

[0004] The purpose of this part is to outline some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this part, as well as in the abstract and title of the specification of this application, to avoid obscuring the purpose of this part, the abstract, and the title. However, such simplifications or omissions shall not be used to limit the scope of the present invention.

[0005] In view of the above existing problems, the present invention is proposed. Therefore, the present invention provides an intelligent password automatic extraction and secure storage method to solve the problems raised in the background art.

[0006] To solve the above technical problems, the present invention provides the following technical solution: An intelligent password automatic extraction and secure storage method, comprising:

[0007] Obtain the current environmental parameters, quantify the environmental parameters, and based on the historical user behavior model or historical user behavior data set, assign corresponding weight values to the current environmental parameters to obtain the total risk value of the current environmental parameters;

[0008] According to the total risk value of the current environmental parameters, determine the environmental risk level. Through the environmental risk level, use the user memory benchmark and obtain the current user behavior to extract the user password, and at the same time, according to the current environmental risk level, store the extracted user password;

[0009] Use the hidden Markov model to model the extraction process of the user password, identify whether there is an abnormality in the current user behavior, and based on the identification result of the abnormal user behavior by the hidden Markov model, realize the intelligent extraction and secure storage of the user password.

[0010] As a preferred solution of the intelligent password automatic extraction and secure storage method described in the present invention, wherein: the environmental parameters include:

[0011] The current user location, the time period when the current user accesses, the light intensity around the current user, and the network state when the current user accesses.

[0012] As a preferred solution of the intelligent password automatic extraction and secure storage method described in the present invention, wherein: quantifying the environmental parameters and based on the historical user behavior model or historical user behavior data set, assigning corresponding weight values to the current environmental parameters to obtain the total risk value of the current environmental parameters includes:

[0013] Through the fuzzy comprehensive evaluation method, consider the volatility generated by each environmental parameter, and initialize the risk coefficient of each environmental parameter, and the volatility is obtained from the standard deviation of each environmental parameter;

[0014] Call the historical user behavior model or input the historical user behavior data set to obtain the historical weights assigned by the user behavior, and adjust the weight values of each environmental parameter according to the volatility, risk coefficient, and historical weights assigned by the user behavior;

[0015] According to the risk value of each environmental parameter and the weight value assigned to the environmental parameter, establish a risk judgment matrix;

[0016] By means of product summation, calculate the risk judgment matrix to obtain the total risk value of the current environmental parameters.

[0017] As a preferred solution of the intelligent password automatic extraction and secure storage method described in the present invention, wherein: determining the environmental risk level according to the total risk value of the current environmental parameters includes:

[0018] Define the highest risk value and the lowest risk value according to the total risk value of the current environmental parameters;

[0019] When the total risk value of the current environmental parameters exceeds the defined highest risk value, determine that the current environmental risk level is high risk;

[0020] When the total risk value of the current environmental parameters is between the defined lowest risk value and the defined highest risk value, determine that the current environmental risk level is medium risk;

[0021] When the total risk value of the current environmental parameters is lower than the defined lowest risk value, determine that the current environmental risk level is low risk.

[0022] As a preferred scheme of the intelligent password automatic extraction and secure storage method described in the present invention, wherein: through the environmental risk level, utilize the user memory benchmark and obtain the current user behavior to extract the user password, including:

[0023] Take the user memory benchmark as the initial user password and encrypt the initial user password;

[0024] When the environmental risk level is low risk, extract the user password according to the encrypted initial user password and the random number generated by the QRNG;

[0025] When the environmental risk level is high risk, extract the user password according to the combination of the first 8 digits of the encrypted initial user password and the Fourier coefficients of the sliding speed;

[0026] When the environmental risk is medium risk, introduce environmental entropy through environmental parameters according to the encrypted initial user password to extract the user password.

[0027] As a preferred scheme of the intelligent password automatic extraction and secure storage method described in the present invention, wherein: simultaneously store the extracted user password according to the current environmental risk level, including:

[0028] Encrypt the extracted user password and locally store the encrypted user password;

[0029] When the environmental risk level changes from low to high, trigger the migration mechanism of the user password, perform signature verification on the local storage device, decrypt the user password in the local storage device that passes the signature verification, store the decrypted user password in the cloud, and then destroy the user password in the local storage device.

[0030] As a preferred scheme of the intelligent password automatic extraction and secure storage method described in the present invention, wherein: utilize the hidden Markov model to model the extraction process of the user password and identify whether there is an abnormality in the current user behavior, including:

[0031] Define the current user behavior as a state variable of the Hidden Markov Model, and define the environmental parameters as an observation value of the Hidden Markov Model;

[0032] By training the Hidden Markov Model, generate the observation probability of each state variable under the environmental parameters and the transition probability between state variables, and obtain the normal operation chain of the current user behavior;

[0033] Use the Kullback-Leibler divergence to identify the normal operation chain of the current user behavior. When the mean of the Kullback-Leibler divergence identification result plus the standard deviation of this identification result is exactly a multiple of this identification result, it indicates that the current user behavior is abnormal, and the user password extraction process is aborted.

[0034] Compared with the prior art, the beneficial effects of the invention are:

[0035] 1. By introducing the comprehensive analysis of environmental parameters and the user historical behavior model, the present invention can dynamically evaluate the risk level of the current environment, and intelligently adjust the password extraction and storage strategy according to the risk level. This mechanism effectively avoids the security risks caused by ignoring environmental changes in traditional password management, and enhances the overall security of password extraction and storage;

[0036] 2. Using the Hidden Markov Model, it can accurately identify whether the current user behavior is abnormal, and immediately abort the password extraction process when an abnormality is detected, effectively preventing the security risks brought by abnormal user behavior or vulnerabilities in the password extraction process, and improving the intelligence and adaptability of the password management system. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them:

[0038] Figure 1 It is the overall flowchart of the intelligent password automatic extraction and secure storage method according to an embodiment of the present invention;

[0039] Figure 2 It is the dynamic environmental risk assessment level distribution diagram of the intelligent password automatic extraction and secure storage method according to an embodiment of the present invention;

[0040] Figure 3 It is the HMM model anomaly detection ROC curve diagram of the intelligent password automatic extraction and secure storage method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0041] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0042] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0043] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that mutually excludes other embodiments.

[0044] The present invention is described in detail in conjunction with schematic diagrams. When detailing the embodiments of the present invention, for ease of explanation, the cross-sectional views showing the device structure are enlarged locally in a non-general proportion, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention herein. In addition, in actual production, three-dimensional spatial dimensions including length, width, and depth should be included.

[0045] Meanwhile, in the description of the present invention, it should be noted that the orientation or positional relationships indicated by terms such as "upper, lower, inner, and outer" are based on the orientation or positional relationships shown in the drawings, and are only for facilitating the description of the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention. In addition, the terms "first, second, or third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.

[0046] Unless otherwise clearly defined and limited in the present invention, the terms "installed, connected, and coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may also be a mechanical connection, an electrical connection, or a direct connection, or may be indirectly connected through an intermediate medium, or may be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0047] Embodiment 1

[0048] Refer to Figure 1, which is the first embodiment of the present invention. This embodiment provides an intelligent password automatic extraction and secure storage method, including:

[0049] S1. Obtain the current environmental parameters, quantify the environmental parameters, and based on the historical user behavior model or historical user behavior data set, assign corresponding weight values to the current environmental parameters to obtain the total risk value of the current environmental parameters;

[0050] Specifically, the environmental parameters are obtained in real time through a variety of sensors and devices;

[0051] Specifically, the environmental parameters include the current user location (obtain the current coordinates of the user through GPS / base station positioning to get the current user location), the time period when the current user accesses (obtain the time period when the user currently accesses through the current system time), the light intensity around the current user (obtain the light data through a light sensor / environmental light sensor), and the network status when the current user accesses (obtain it by monitoring the network bandwidth, latency, and signal strength of the device, etc.);

[0052] It should be explained that the light intensity around the current user can be used as a potential security indicator. For example, when the light intensity is weak, it means that the user is in a dim environment, and the timing and environment of using the device are not common. Combining the light intensity to evaluate the user's behavior can effectively identify possible abnormal behaviors; for example, when the user performs high-frequency password input operations in a very dark environment, attention should be paid to the potential risks of this behavior;

[0053] Furthermore, the quantization method is through the fuzzy comprehensive evaluation method, considering the volatility generated by each environmental parameter, and initializing the risk coefficient of each environmental parameter;

[0054] It should be noted that the volatility is obtained from the standard deviation of each environmental parameter;

[0055] Even further, call the historical user behavior model or input the historical user behavior data set to obtain the historical weights assigned to user behaviors, and adjust the weight values of each environmental parameter according to the volatility, risk coefficient, and historical weights assigned to user behaviors;

[0056] Specifically, collect the user behavior data set through the log recording module, convert it into a standardized data format (such as JSON, CSV, or database record), and upload the data collected by the log recording module to the database for summarization to obtain the historical user behavior data set;

[0057] Specifically, load the trained historical user behavior model from local storage or cloud storage. During the loading process, use a machine learning framework (such as TensorFlow, PyTorch, Scikit-learn, etc.) to read the historical user behavior model from the database into memory and initialize it to obtain the historical user behavior dataset;

[0058] Specifically, the weight value W of each adjusted environmental parameter i (t) can be expressed by the following formula:

[0059]

[0060] where σ i (t) is the standard deviation of each environmental parameter, and C i is the risk coefficient of each environmental parameter (such as location sensitivity coefficient, network risk coefficient, etc.), and H i represents the historical weight (i.e., the weight assigned according to the user's historical behavior);

[0061] Furthermore, based on the risk value of each environmental parameter and the weight value assigned to the environmental parameter, establish a risk judgment matrix;

[0062] Specifically, the risk judgment matrix R is expressed as:

[0063] R = [W1(t), W2(t), …, W i (t)] · [V1, V2, …, V i T

[0064] where V i represents the risk value of each environmental parameter;

[0065] Furthermore, calculate the risk judgment matrix by the method of product summation to obtain the total risk value of the current environmental parameter;

[0066] Specifically, for each environmental parameter i, perform product summation according to the obtained weight value W i (t) and the corresponding risk value V i to further obtain:

[0067]

[0068] It should be noted that combining the light intensity as an environmental parameter with the user's historical behavior can more comprehensively evaluate the overall environmental risk. The purpose is to help the system provide a more accurate judgment basis in the process of multi-dimensional comprehensive evaluation of user behavior and environmental changes, improve system security and reduce potential risks;

[0069] ​S2. Determine the environmental risk level according to the total risk value of the current environmental parameters. Through the environmental risk level, utilize the user memory benchmark and obtain the current user behavior to extract the user password, and at the same time store the extracted user password according to the current environmental risk level;

[0070] It should be noted that since the fuzzy comprehensive evaluation method has been used for the environmental parameters with the greatest impact before defining the environmental risk level, the total risk value of the current environmental parameters obtained here is equivalent to the risk range value. Therefore, there is no need to define rules or thresholds anymore, and it can be obtained through the maximum and minimum values of the risk range value;

[0071] Furthermore, define the highest risk value and the lowest risk value according to the total risk value of the current environmental parameters, and give the rule definition of the environmental risk level as follows:

[0072] Rule 1: When the total risk value of the current environmental parameters exceeds the defined highest risk value, determine that the current environmental risk level is high risk;

[0073] Rule 2: When the total risk value of the current environmental parameters is between the defined lowest risk value and the defined highest risk value, determine that the current environmental risk level is medium risk;

[0074] Rule 3: When the total risk value of the current environmental parameters is lower than the defined lowest risk value, determine that the current environmental risk level is low risk;

[0075] Exemplarily, assume that we have three environmental parameters: location, light, and network status, and their dynamic weights and risk values are as follows:

[0076] Location: W 位置 (t) = 0.6, V 位置 = 0.8 (for example, the user's location appears offset for the first time, that is, in an uncommon place);

[0077] Light: W 光照 (t) = 0.3, V 光照 = 0.5 (for example, the light intensity is weak);

[0078] Network status: W 网络 (t) = 0.1, V 光照 = 0.7 (for example, the current network environment is poor);

[0079] Then R = (0.6 × 0.8) + (0.3 × 0.5) + (0.1 × 0.7) = 0.7;

[0080] If the highest risk value is 0.8 and the lowest risk value is 0.5 at this time, then according to the calculated 0.7, it can be judged that the current environmental risk level is medium risk;

[0081] Furthermore, taking the user memory benchmark as the initial user password and encrypting the initial user password, the method of extracting the user password for each environmental risk level is defined as follows:

[0082] It should be noted that the user memory benchmark refers to a string or phrase that is easy to remember and has personalized characteristics, such as "the upper and lower case of the user's name + the current birth year", "the user's favorite person", "the user's personal experience", etc.; its main function is to provide a reproducible input for generating the system's initial user password, while avoiding the problem that the randomly generated password given by the system is easy to forget;

[0083] When the environmental risk level is at low risk, the user password is extracted according to the encrypted initial user password and the random number generated by QRNG;

[0084] It should be noted that QRNG is quantum random number generation, and the random numbers generated by it are unpredictable;

[0085] Specifically, by using the AES encryption algorithm and using the random number randomly generated by QRNG as the salt value to encrypt the password for storage; when extracting the password, it can be decrypted by using the encrypted user password and the salt value;

[0086] When the environmental risk level is at high risk, the user password is extracted according to the first 8 digits of the encrypted initial user password and the combination of the Fourier coefficients of the sliding speed;

[0087] Specifically, the encryption method is similar to the above encryption method. Through the AES encryption algorithm, the role of the Fourier coefficients of the sliding speed is to increase the encryption security when encrypting the user password in a high-risk environment level; when extracting the password, it can be decrypted by using the key generated by the AES encryption algorithm and the initial user password;

[0088] When the environmental risk is at medium risk, the user password is extracted by introducing environmental entropy according to the encrypted initial user password;

[0089] Specifically, through the AES encryption algorithm, retaining the key of the initial user password, splicing the environmental parameters into a string, and hashing the spliced environmental parameters into a string to obtain the environmental entropy, combining the initial user password and the environmental entropy to obtain the encrypted password; when the password needs to be extracted, it can be decrypted by using the key of the initial user password and the initial user password;

[0090] Furthermore, if the extracted user password is encrypted, the encrypted user password needs to be stored locally;

[0091] Furthermore, when the environmental risk level changes from low to high, the user password migration mechanism is triggered to perform signature verification on the local storage device. Decrypt the user password in the local storage device that passes the signature verification (each decryption operation is as described above), store the decrypted user password in the cloud, and then destroy the user password in the local storage device;

[0092] It should be noted that signature verification ensures that only verified devices can decrypt the password, which not only protects the security of local storage but also avoids security issues caused by device loss or damage by migrating the password to the cloud. By storing the password in the cloud, the system can further improve the reliability and recoverability of data, ensuring that user data can be securely accessed in any device environment. In addition, during the password migration process, the locally stored password will be destroyed, which greatly reduces the risk of password leakage when the local device is stolen;

[0093] S3. Use the hidden Markov model to model the extraction process of the user password, identify whether there is any abnormality in the current user behavior, and realize the intelligent extraction and secure storage of the user password according to the recognition result of the hidden Markov model for abnormal user behavior;

[0094] It should be explained that the hidden Markov model (Hidden Markov Model, HMM) is a statistical model used to describe an observation sequence generated by a hidden state sequence;

[0095] Furthermore, define the current user behavior as a state variable of the hidden Markov model and define the environmental parameter as an observation value of the hidden Markov model;

[0096] Furthermore, by training the hidden Markov model, generate the observation probability of each state variable under the environmental parameter and the transition probability between state variables to obtain the normal operation chain of the current user behavior;

[0097] Specifically, the observation probability of the state variable, for example, the user is currently at home, and the probability that the observed user location data is a location frequently appearing near home; and the transition probability between state variables, for example, the probability that the user transfers from home to the office. The generated normal operation chain of user behavior, for example, the user often transfers from home to the office in the past few days, but suddenly jumps to a strange area today (such as a strange location, that is, the user location in the environmental parameter that has never appeared);

[0098] Furthermore, use the K-L divergence to identify the normal operation chain of the current user behavior. When the mean of the K-L divergence recognition result plus the standard deviation of this recognition result is exactly a multiple of this recognition result, it indicates that there is an abnormality in the current user behavior, and the user password extraction process is aborted;

[0099] It should be explained that the Kullback-Leibler Divergence is an index used to measure the difference between two probability distributions. If the transition probability of the current state differs significantly from that of the user's normal behavior, the value of the Kullback-Leibler Divergence will be relatively high, indicating abnormal behavior.

[0100] Specifically, according to the 68-95-99.7 rule (characteristics of the normal distribution), approximately 68% of the data points will fall within the range of the mean plus or minus 1 standard deviation, 95% of the data points will fall within the range of the mean plus or minus 2 standard deviations, and 99.7% of the data points will fall within the range of the mean plus or minus 3 standard deviations. Therefore, setting the threshold as a multiple of the mean plus the standard deviation can effectively identify abnormal behavior when the user extracts the password, especially when the distribution of the Kullback-Leibler Divergence is close to the normal distribution.

[0101] It should be noted that, in addition, the magnitude of the multiple determines the sensitivity of detecting abnormal behavior. The smaller the multiple, the stricter the system is in judging abnormal behavior, that is, when the Kullback-Leibler Divergence slightly deviates from the mean, an abnormal behavior warning will be triggered. The larger the multiple, the more lenient the system is in judging abnormal behavior.

[0102] Embodiment 2

[0103] Referring to Figure 2 and Figure 3 , this is the second embodiment of the present invention. This embodiment provides an intelligent password automatic extraction and secure storage method, including: To verify the effectiveness of the intelligent password automatic extraction and secure storage method proposed by the present invention, a set of experimental comparison schemes were designed to compare the performance differences between the present invention and the prior art under different environmental conditions. The experiments selected three typical environmental risk levels (low risk, medium risk, high risk), and simulated the user password extraction process under each risk level.

[0104] Experimental equipment and environmental settings: The experiment used a smartphone branded "SecureTech" (model: STX2025) as the user device, equipped with environmental parameter sensors (including GPS, light intensity sensors, network status monitors, etc.) and an encryption algorithm module. An encryption application based on the Android operating system was used, and the AES encryption algorithm and QRNG (quantum random number generator) were used to generate random numbers. The system has integrated a Hidden Markov Model (HMM) for abnormal behavior detection, and dynamically adjusts the password extraction strategy according to environmental parameters (location, light, network status, etc.).

[0105] Experimental environment: Low-risk environment: The user is in the office, with a stable network status, moderate light intensity, and located at a known position; Medium-risk environment: The user is in a public place, with large network fluctuations, rapid light changes, and located at a relatively unfamiliar position; High-risk environment: The user is in an area with insufficient light, unstable network signal, and located at an unknown or abnormal position;

[0106] Experimental steps: Real-time obtain environmental parameters through sensors and record the user's behavior data; then the system quantifies each environmental parameter using the fuzzy comprehensive evaluation method, calculates the total risk value of the current environment, and determines the risk level (low, medium, high); according to the change of the environmental risk level, the system respectively adopts QRNG random number encryption, Fourier coefficient encryption, and environmental entropy encryption methods to extract the user's password and store it. The password storage locations are the local device and the cloud to ensure the security of the experimental data; analyze the user's behavior through the hidden Markov model to detect whether there is any abnormality. If there is an abnormality, the password extraction process is aborted; Some test data results are shown in Table 1:

[0107]

[0108] From the test data results in Table 1, it can be seen that the proposed solution of the present invention is superior to the prior art in terms of password security comparison, password storage security comparison, and the detection effect of user abnormal behavior, and through Figure 2 , the joint influence of light intensity and network delay in environmental parameters on the risk level is shown using a grayscale heat map and contour lines. Among them, the weaker the light, the higher the risk, and the higher the network delay, the higher the risk. Combined with dynamic weight allocation, the high-risk area (dark color) is more in line with the actual scenario, which is superior to the traditional fixed threshold method; In addition, Figure 3 it can be seen that the ROC curve shows that the AUC of the HMM model of the present invention is close to 1, which is significantly better than the traditional threshold method. When the threshold is set to the mean + 3σ, (K-L divergence = 1.2), TPR = 95% and FPR < 5%, verifying the high sensitivity and specificity of the HMM model in abnormal behavior detection;

[0109] In summary, through the comparative experiment method, the feasibility and beneficial effects of the proposed solution of the present invention are fully demonstrated.

[0110] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present application can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript, etc.

[0111] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0112] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction means that implements the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0113] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, so that the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0114] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application.

[0115] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to cover these changes and modifications.

Claims

1. An intelligent password automatic extraction and secure storage method, characterized in that: include: Acquire current environmental parameters, quantify the environmental parameters, and assign corresponding weight values ​​to the current environmental parameters based on a historical user behavior model or a historical user behavior data set to obtain a total risk value of the current environmental parameters; Determine the environmental risk level according to the total risk value of the current environmental parameters, extract the user password by using the environmental risk level, using the user memory benchmark and obtaining the current user behavior, and store the extracted user password according to the current environmental risk level; The hidden Markov model is used to model the user password extraction process and identify whether the current user behavior is abnormal. Based on the hidden Markov model's identification results of abnormal user behavior, the user password is intelligently extracted and securely stored.

2. The intelligent password automatic extraction and safe storage method as claimed in claim 1, characterized in that: The environmental parameters include: The current user location, the time period of the current user's visit, the light intensity around the current user, and the network status when the current user visits.

3. The intelligent password automatic extraction and safe storage method as claimed in claim 2, characterized in that: The environmental parameters are quantified, and based on the historical user behavior model or the historical user behavior data set, corresponding weight values ​​are assigned to the current environmental parameters to obtain the total risk value of the current environmental parameters, including: By using the fuzzy comprehensive evaluation method, the volatility generated by each environmental parameter is considered and the risk coefficient of each environmental parameter is initialized, wherein the volatility is obtained by the standard deviation of each environmental parameter; Calling a historical user behavior model or inputting a historical user behavior data set to obtain a historical weight assigned to the user behavior, and adjusting a weight value of each environmental parameter according to the volatility, risk factor, and the historical weight assigned to the user behavior; Establishing a risk determination matrix according to the risk value of each environmental parameter and the weight value assigned to the environmental parameter; The risk determination matrix is ​​calculated by a product-sum method to obtain a total risk value of the current environmental parameters.

4. The intelligent password automatic extraction and safe storage method as claimed in claim 3, characterized in that: Determine the environmental risk level based on the total risk value of the current environmental parameters, including: According to the total risk value of the current environmental parameters, define the highest risk value and the lowest risk value; When the total risk value of the current environmental parameters exceeds the defined maximum risk value, the current environmental risk level is determined to be high risk; When the total risk value of the current environmental parameters is between the defined minimum risk value and the defined maximum risk value, the current environmental risk level is determined to be medium risk; When the total risk value of the current environmental parameters is lower than the defined minimum risk value, the current environmental risk level is determined to be low risk.

5. The intelligent password automatic extraction and safe storage method as claimed in claim 2 or 4, characterized in that: According to the environmental risk level, the user password is extracted by using the user memory benchmark and obtaining the current user behavior, including: Using the user memory reference as the initial user password, and encrypting the initial user password; When the environmental risk level is low, the user password is extracted based on the encrypted initial user password and the random number generated by QRNG; When the environmental risk level is high, the user password is extracted based on the first 8 bits of the encrypted initial user password and the Fourier coefficient combination of the sliding speed; When the environmental risk is at medium risk, the environmental entropy is introduced through environmental parameters based on the encrypted initial user password to extract the user password.

6. The intelligent password automatic extraction and safe storage method as claimed in claim 5, characterized in that: At the same time, according to the current environmental risk level, the extracted user password is stored, including: Encrypt the extracted user password and store the encrypted user password locally; When the environmental risk level changes from low to high, the user password migration mechanism is triggered, the signature verification is performed on the local storage device, the user password in the local storage device that passes the signature verification is decrypted, the decrypted user password is stored in the cloud, and then the user password in the local storage device is destroyed.

7. The intelligent password automatic extraction and safe storage method as claimed in claim 2 or 5, characterized in that: The hidden Markov model is used to model the process of extracting user passwords and identify whether the current user behavior is abnormal, including: Define the current user behavior as a state variable of the hidden Markov model, and define the environmental parameter as an observation value of the hidden Markov model; By training the hidden Markov model, the observation probability of each state variable under the environmental parameters and the transition probability between state variables are generated, and the normal operation chain of the current user behavior is obtained; The normal operation chain of the current user behavior is identified by KL divergence. When the mean of the KL divergence identification result plus the standard deviation of the identification result is exactly a multiple of the identification result, it means that the current user behavior is abnormal, and the user password extraction process is terminated.

Citation Information

Patent Citations

  • Payment data security protection method and device, electronic equipment and storage medium

    CN115001683A

  • Management method and system of password device

    CN115473782A

  • Privacy information protection method and device

    CN118153109A

  • Industrial network security protection method and system, terminal and storage medium

    CN118827247A

  • Password security enhancement method based on secret communication

    CN119210901A