Equipment administrator password maintenance method and system, client, server and equipment

By introducing key pair management technology into device administrator password management, the problems of insufficient security and high complexity of password management in the prior art are solved, and the high security, one-machine, one-security and easy maintenance of device administrator passwords are achieved.

CN120223303APending Publication Date: 2025-06-27西安联乘软件技术有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510448339.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art has problems such as insufficient security, high management complexity, and difficulty in updating passwords after leaks in the management of device administrator passwords, making it difficult to achieve password updates with one machine, one password, high password strength and secure.

Method used

A maintenance method for the device administrator password generation, update, and encryption and decryption based on key pair management is designed. Through the communication between the password management client, key pair management server and managed device, random generation of passwords, periodic updates and key pair updates are realized.

Benefits of technology

It realizes high security, one machine, one password and easy maintenance of the device administrator password, ensures the strength and convenience of updates, and reduces the security risks caused by password leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223303A_ABST
    Figure CN120223303A_ABST
Patent Text Reader

Abstract

The invention relates to a device administrator password maintenance method, a device administrator password maintenance system, a password management client, a server and a device. The method comprises the following steps: a password management client sends a key pair generation request to a server, the server randomly generates a public and private key pair of an asymmetric encryption algorithm, a public key is sent back to the client, and the public and private key pair is stored in the server; the client side randomly generates a device administrator password when storing the public key into the managed device; the public key encrypts the password and sends the password to the client side, the client side sends the encrypted password to the server, the server calls the private key to decrypt the encrypted password and then returns the decrypted password to the client side, and the client side displays the decrypted administrator password to carry out device login verification. The client and the equipment can be remotely connected through a network, and passwords can be updated in real time; the public and private key pair can be updated in real time; the password management client, the server and the managed equipment form the implementation system of the invention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to information security and device management technologies in the field of information technology, and specifically to a maintenance method and system, a client, a server, and a device for generating, updating, encrypting, and decrypting the password of a device administrator. Background Art

[0002] With the rapid development of information technology, various electronic devices such as network devices and intelligent terminals play a crucial role in the operation of all walks of life and personal daily life. The security management of these devices, especially the management of the device administrator password, is directly related to the security and stability of the entire device information system.

[0003] Several common methods for generating and managing the device administrator password in the prior art: One is to set the device administrator password during factory setting after the production line completes the device manufacturing. The password of each device is the same and fixed, and such a password has the worst security and is extremely easy to be cracked and tampered with. The leakage of the password of one device will affect the security of the devices produced in the same batch. Another is based on a fixed algorithm. Each device generates a password according to the inherent ID attributes of the device itself, such as device ID, chip ID, MAC, etc. When manufacturing the device, an information table of the device ID, chip ID, MAC, etc. of each device needs to be recorded to ensure that the corresponding administrator password can be queried according to the relevant ID or the administrator password can be calculated through the ID and the algorithm. Although this method can achieve a unique password for each device, as the number of devices produced increases, the information table will also keep increasing. On the one hand, it will increase the workload of obtaining the administrator password. On the other hand, if the password derivation algorithm is leaked and the device ID is easily obtained, the security of all such devices in the market will be affected. A more serious problem is that in the way of deriving passwords according to a fixed algorithm and fixed ID, when the password is leaked, it is impossible to block the security hole by real-time password update, and it is necessary to rely on software upgrade to solve the security problem, and the timeliness is poor.

[0004] Therefore, developing a maintenance method for generating and updating the device administrator password that is efficient, secure, and easy to maintain, realizing high security with a unique password for each device, high password strength, and secure password storage, and a password maintenance system that can be updated quickly and in real time after the password is leaked has become an urgent problem to be solved in the current device information security field. Summary of the Invention

[0005] The present invention is designed based on password technology and network transmission technology in the field of device information security, and solves the problems existing in the maintenance of the above-mentioned device administrator password. The technical solutions of the invention are as follows:

[0006] I. Glossary Explanation of the Present Invention:

[0007] 1. Managed electronic devices: device 1, device 2, device 3, ... etc. The "managed device", "device", "device 1", "device 1" mentioned in the subsequent text and drawings all refer to "managed electronic devices".

[0008] 2. Password Cloud Proxy Server: Password Cloud Proxy Server. The "cloud server", "cloud proxy server", "remote control server" mentioned in the subsequent text and drawings all refer to "Password Cloud Proxy Server".

[0009] 3. Key pair management server: Key pair management server. The "server" and "management server" mentioned in the subsequent text and drawings refer to "Key pair management server".

[0010] 4. Password Management Client: Password Management Client. The "device password management client", "management client", "client", "client" etc. mentioned in the subsequent text and drawings all refer to "Password Management Client".

[0011] II. Technical solution of the present invention

[0012] Since the solution of the present invention is a general-purpose password generation and update maintenance solution, the managed electronic device may or may not have network communication capabilities, which depends on the use of the device itself. If the device has network communication capabilities, it supports the Password Management Client to remotely connect to the managed device through wireless or wired networks to generate and update the administrator password of the device (such as Figure 1 the dotted line in the figure); if the device has no network communication capabilities, the client needs to connect to the device through physical connection methods such as "serial port" and "USB" for wired communication to generate and update the administrator password of the device (such as Figure 1 the solid line in the figure).

[0013] 1. Maintenance of the administrator password of the managed device without network communication capabilities ( Figure 1 solid line part)

[0014] (1) Generation of the device administrator password

[0015] 1) Before the managed device leaves the factory, the Password Management Client connects to the Key pair management server through wired (wireless) network and sends a key pair generation request to it. The server randomly generates a public-private key pair of the asymmetric encryption algorithm, sends the public key back to the client, and stores the public-private key pair in the secure storage space of the server.

[0016] 2) The password management client accesses the managed electronic device through physical connections such as USB, serial port, or CAN, and writes the public key sent back by the server into the device. The storage space of the device includes a secure storage space and a general storage space. The public key can be stored in the readable and writable partition of the general storage space. Initially, there is no device administrator password on the device. When the client first writes the public key into the device, the device program starts the true random number generator to randomly generate an administrator password according to the designed algorithm, and stores the generated password in the secure storage space of the device;

[0017] 3) The password management client sends a password acquisition request to the managed device. The device receives the request, reads the password from the secure storage space, reads the public key from the general readable and writable partition, encrypts the read password using the public key, and then returns the encrypted password ciphertext information to the client;

[0018] 4) The password management client sends the received password ciphertext information to the key pair management server to request the server to decrypt it. The server retrieves the private key stored in the secure storage space for decryption, and after decryption, sends the decrypted password plaintext information back to the client. Finally, the client displays the device administrator password in the decrypted information for device login verification.

[0019] In any of the above 3) and 4), between the password management client and the managed device, and between the password management client and the server, the ciphertext protocol for ciphertext information and the plaintext protocol for plaintext information are used for communication inside the device and inside the server. For the communication transformation process of the protocol, see Figure 5 , for details, see the embodiments.

[0020] 5) Figure 4 This is the protocol definition of the password information for password acquisition.

[0021] Such as Figure 4 , the ciphertext protocol contains fields and meanings as follows:

[0022] Protocol version: Indicates the version followed by the password information protocol;

[0023] Encryption algorithm: Indicates which encryption algorithm is used to encrypt the subsequent ciphertext information;

[0024] Key version: Indicates which version of the key is used for encryption by the encryption algorithm.

[0025] 6) Such as Figure 4 , the plaintext protocol contains fields and meanings:

[0026] Protocol version: The same as the ciphertext protocol in 5) above;

[0027] Encryption algorithm: The same as the ciphertext protocol in 5) above;

[0028] Key version: The same as the ciphertext protocol in 5) above;

[0029] Username length: the string length of the administrator username;

[0030] Username: string

[0031] Password length: the length of the administrative password of the administrator user;

[0032] Password: the content of the administrator user password;

[0033] Verification algorithm: specifies the specific algorithm used for CRC / hash verification of all fields of the entire plaintext protocol except the last field "verification result";

[0034] Verification result length: this value is used to confirm the verification result of the algorithm;

[0035] Verification result: the verification result of the verification algorithm for all fields before this field.

[0036] 7) If the device needs to return to the factory for after-sales service, the administrator password of the device needs to be obtained to enter the device for device problem analysis. The device can be connected to the password management client through physical wiring, and the above steps 3) and 4) can be repeated to obtain the administrator password of the device for device login verification.

[0037] After the service personnel log in once and complete the service, the administrator password of the device should be updated once.

[0038] (2) Regular update of the device administrator password

[0039] The administrator password of the device may be deliberately or accidentally leaked, so the password needs to be updated regularly. The steps for updating the administrator password are as follows:

[0040] 1) Set the regular password update period of the device. The device program automatically triggers the true random number generator at the set period to randomly generate a new administrator password according to the designed algorithm;

[0041] 2) The device program deletes the old password in the secure storage space and stores the new password;

[0042] 3) The device completes the update of the administrator password.

[0043] The "true random number generator according to the designed algorithm" mentioned in the above (1) and (2) is: using the random number as an index, obtaining password characters from the password character set, and finally splicing them into a valid password. The following embodiments have detailed descriptions.

[0044] (3) Update of the key pair

[0045] If the public-private key pair used for encryption and decryption is leaked or brute-forced, all encrypted messages containing the administrator password sent by the devices to the client can be easily decrypted and obtained. Therefore, it may be necessary to update the public-private key pair to address the potential security risks of the devices caused by the possible leakage. The specific steps are as follows:

[0046] 1) The service personnel connect the password management client to the key pair management server through a wired (wireless) network and send a key pair update request to the server;

[0047] 2) After receiving the request, the server randomly generates a new key pair of the asymmetric encryption algorithm, returns the new public key with version information to the client, and saves the new public-private key pair in the secure storage space of the server; the version information included in the public key: key value, key version, and encryption algorithm to which the key belongs; the key pair management server needs to save all generated public-private key pairs. Each time the server updates the key pair, the key version information is incremented by 1 to ensure that when the password encrypted by any version of the public key of the managed electronic device is returned to the server for decryption, the server can retrieve the private key that matches the public key version and decrypt it normally to obtain the device administrator password;

[0048] 3) The password management client connects to the managed device through physical connections such as USB, serial port, or CAN, writes the received new public key into the device. After receiving the new public key, the device deletes the original old public key and saves the new public key in the normal storage space.

[0049] Preferably, the key length generated by the key pair management server should be secure enough, for example: the key length obtained by the RSA algorithm is greater than or equal to 3072 bit (equivalent to the key length of the ECC algorithm ≧ 256 bit), and the key length of other algorithms is not less than the equivalent of 3072 bit of the RSA algorithm to ensure that it is not easily brute-forced;

[0050] Preferably, the server storage space has a normal storage space and a secure storage space. The public key can be stored in either space, while the private key must be stored in the secure storage space of the server;

[0051] Preferably, the security measures for the key pair server: The server should be preferably deployed in a private network. If public network services need to be provided, access control should be performed by routing devices, and firewalls should be set for the routing devices and the server. It should only respond to requests from the client and limit the request speed to avoid the server being attacked and the entire service being paralyzed and unusable.

[0052] 2. Maintenance of the administrator password of the managed device with network communication capabilities ( Figure 1 dotted part)

[0053] The methods and steps for generating and updating the device administrator password of a managed electronic device with network communication capabilities, and the methods and steps for generating and updating the key pair are basically the same as those of a device without network communication capabilities, as follows:

[0054] (1) Generation of device administrator password

[0055] 1) Before the managed device leaves the factory, the password management client connects to the key pair management server through a wired (or wireless) network and sends a key pair generation request to it. The server randomly generates a public-private key pair of an asymmetric encryption algorithm, sends the public key back to the client, and stores the public-private key pair in the secure storage space of the server;

[0056] 2) The password management client remotely connects to the managed electronic device through the password cloud proxy server using a wireless or wired network, and writes the public key sent back by the server into the device. The storage space of the device includes a secure storage space and a normal storage space. The public key can be stored in the normal readable and writable partition. At the beginning, there is no device administrator password on the device. When the client first writes the public key into the device, the device starts the true random number generator to randomly generate the administrator password according to the designed algorithm, and stores the generated password in the secure storage space of the device;

[0057] The remaining steps are exactly the same as 1.

[0058] (2) Regular update of device administrator password

[0059] The steps are exactly the same as 1.

[0060] (3) Update of key pair

[0061] It is exactly the same as steps 1) and 2) in 1;

[0062] 3) The password management client remotely connects to the managed device through the password cloud proxy server using a wireless or wired network, and writes the received new public key into the device. After the device receives the new public key, it deletes the original old public key and saves the new public key in the normal storage space.

[0063] The remaining steps are exactly the same as 1.

[0064] 3. Password management client, which is specifically an electronic device, and its structure includes but is not limited to: a processor, a memory, and a communicator. It installs a password acquisition / update local client program, a password acquisition / update network client program, etc. The processor can access the memory, and the memory stores programs and instructions. The communicator interface ensures that the processor's processing results and instructions are remotely communicated through wired communication between the processor and the managed device or through a wireless (wired) network of the password cloud proxy server between the managed devices, and also ensures wired communication or wireless (wired) network communication between the processor's processing results and instructions and the key pair management server. When the programs and instructions are executed by the processor, the processor executes the method steps related to the password management client described in any one of the above 1 and 2.

[0065] The above client electronic device can be a fixed client or a mobile client.

[0066] 4. Key pair management server, whose structure includes but is not limited to: a processor, a memory, and a communication interface. It installs an asymmetric public-private key pair management program, etc. The processor can access the memory, and the memory stores programs and instructions. The communicator interface ensures wired communication or wired (wireless) network communication between the processor's processing results and instructions and the password management client. When the programs and instructions are executed by the processor, the processor executes the method steps related to the server described in any one of the above 1 and 2.

[0067] The above server memory (storage space) includes: a hardware security module HSM.

[0068] 5. Managed electronic device, in addition to the device having its own attribute functional components, its structure also includes but is not limited to: a processor, a memory, a true random number generator, and a communicator. It installs a device password management service program, etc. The processor can access the memory, and the memory stores programs and instructions. The communicator interface ensures wired communication between the processor's processing results and instructions and the password management client or wireless (wired) network communication with the password management client through the password cloud proxy server. When the programs and instructions are executed by the processor, the processor executes the method steps related to the managed electronic device described in any one of the above 1 to 2.

[0069] The device memory (storage space) includes: a hardware security module SE chip and a general read-write partition.

[0070] 6. A device administrator password maintenance system includes but is not limited to: the password management client described in any one of the above 3, the key pair management server described in any one of the above 4, and the managed device described in any one of the above 5.

[0071] Beneficial effects:

[0072] The present invention aims to improve the complexity and unpredictability of the passwords of equipment administrators through a convenient, easy-to-operate, and highly flexible maintenance strategy, while simplifying the password update and management processes, reducing security risks caused by password leakage or improper management, ensuring the security and controllability of equipment access permissions, and achieving high security and easy maintenance of the passwords of equipment administrators.

[0073] The present invention is not only applicable to the password management of equipment administrators in traditional IT environments, but also has broad application prospects and important practical values in password security management in emerging technology fields such as the Internet of Things. Its beneficial effects are as follows:

[0074] 1. One password per device: The password is randomly generated by each device, eliminating the problem of one device's password leakage affecting other devices.

[0075] 2. High password strength, secure storage, rigorous encryption, and easy to use: The password is generated by a true random number generator in the device according to a designed algorithm and stored in its own secure storage space. Subsequently, the final password is obtained through public key encryption and private key decryption. The entire process does not require manual memorization or recording of the password, reducing the risks of password leakage and being forgotten.

[0076] 3. Easy to update: Since the password management client, the managed device, and the server form a maintenance system and communicate remotely through wired or wireless networks, without being restricted by space and time, the password can be updated at any time if it is found to be insecure, avoiding the risks caused by password leakage and remaining unchanged for a long time. Brief Description of the Drawings

[0077] Figure 1 Object topology diagram related to equipment password acquisition and update

[0078] Figure 2 Communication between the password management client and the device - direct communication through a wired connection

[0079] Figure 3 Communication between the password management client and the device - indirect communication through a cloud proxy

[0080] Figure 4 Protocol definition of password information for password acquisition

[0081] Figure 5 Example of protocol transformation of password information during the password acquisition process

[0082] Figure 6 Components and general process involved in the generation of equipment administrator passwords

[0083] Figure 7 LT8215GTCAM vehicle-mounted intelligent terminal

[0084] Figure 8Schematic diagram of the structure of the password management client electronic device

[0085] Figure 9 Schematic diagram of the structure of the key pair management server

[0086] Figure 10 Schematic diagram of the structure of the device under management

[0087] Figure 11 Schematic diagram of the device administrator password maintenance system

[0088] Figure 12 Schematic diagram of the interactive communication of the device administrator password maintenance system Specific embodiments

[0089] The technical solution of the present invention will be further described in detail below in conjunction with the specific implementation manners:

[0090] Embodiment 1

[0091] As Figure 1 As shown by the solid line is the flowchart for the device under management without network communication ability to generate the administrator password. The specific steps are as follows:

[0092] 101. The password management client connects to the key pair management server through wired or wireless Internet methods such as Ethernet network, WLAN network, and dial-up network. The "password get / update local client" of the client sends a request to generate a key pair to the server;

[0093] Upon receiving the request instruction, the server uses the "asymmetric public and private key pair management program" and randomly generates an asymmetric public and private key pair using an asymmetric encryption algorithm such as the RSA security algorithm. Tools such as openssl can be used to generate it;

[0094] 102. The "asymmetric public and private key pair management program" returns the public key including version information to the client, and at the same time saves the public and private key pair. The private key is saved to the server's secure memory HSM;

[0095] 103. As Figure 2As shown, the client accesses the device through physical connection methods such as USB, serial port, and CAN on the production line. The client writes the public key carrying version information into the device through "password get / update local client". The device storage space includes: a secure space such as an SE chip and a normal space such as a normal readable and writable partition. The "Device Password ManagerService" of the device stores the public key in the normal readable and writable partition; when a new device on the production line initially has no administrator password, when the client first writes the public key into the device, the "Device Password ManagerService" in the device enables the true random number generator to automatically generate a random device administrator password according to the designed algorithm and stores the password in the secure storage space SE chip; as Figure 6 shown, the true random number generator presets password rules such as including: numbers, uppercase and lowercase letters, special characters, and the length cannot be less than 12, etc. The password generation steps are shown as follows:

[0096] B1. For password generation, first determine the password length len, and then request the true random number generator to generate len random numbers based on this length;

[0097] B2. Take the remainder of each digit of the random number with 80, and use it as the index of the password character set list to obtain len characters, and then the actual password can be concatenated;

[0098] B3. Write the generated password into the secure storage space SE chip.

[0099] Figure 6 The character set here is only an example, mainly expressing the password generation and storage method, rather than the selection of the character set.

[0100] Using the true random number generator of the device to randomly generate passwords with configurable length and complexity ensures that each device has a unique password and the password has high strength.

[0101] 104. Such as Figure 2 shown, the password management client sends a password acquisition request to the device through "password get / update local client program". After the "Device Password ManagerService" on the device receives the request, it retrieves the password from the SE chip into the memory and reads the public key from the normal read / write partition;

[0102] 105. Such as Figure 5The "Device Password Management Service Program" encrypts the retrieved password using the public key and then replies with the encrypted password ciphertext carrying the password and including the key version information to the client. The client program then sends the obtained encrypted ciphertext information to the management server and requests the server to decrypt it. The server uses the "Asymmetric Public-Private Key Pair Management Program" to compare the version information carried by the public key with the private key backed up in the HSM and decrypts it using the private key that matches the public key version. The server sends the decrypted plaintext information containing the administrator password back to the client;

[0103] As Figure 4 shown, the plaintext protocol and the ciphertext protocol contain fields and meanings as follows:

[0104] Plaintext protocol:

[0105] D1. Protocol version, encryption algorithm, and key version are as follows C1, C2, C3 in the ciphertext protocol, and the three fields are the same;

[0106] D2. User name length: The string length of the administrator user name. For example, when the administrator user name is "root", the length is 4, and when the administrator user name is "admin", the user name length is 5, etc. It is used to determine the actual length of the subsequent variable-length user name and confirm the start position of the subsequent fields;

[0107] D3. User name: Such as "root", "admin", etc.;

[0108] D4. Password length: The length of the administrator user's management password. For example, when the administrator password is "passwd123@", the password length is 10, and when the password is "uxA8@!aaTm4", the password length is 11. It is used to determine the actual length of the subsequent variable-length password and confirm the start position of the subsequent fields;

[0109] D5. Password: The content of the administrator user password, such as "passwd123@", "uxA8@!aaTm4", etc.;

[0110] D6. Check algorithm: Specifies the specific algorithm used for CRC / hash check of all fields of the entire protocol plaintext except the last field "Check result"; The check algorithm is defined as follows in C / C++ implementation. This field is 2 bytes, so a maximum of 65535 algorithms can be defined:

[0111] typedef enum:uint16_t{ / *CRC* /

[0112] devPwMgrPktChkAlg_CRC8 = 0x0001,

[0113] devPwMgrPktChkAlg_CRC16 = 0x0002,

[0114] devPwMgrPktChkAlg_CRC32 = 0x0003,

[0115] / *MD5* /

[0116] devPwMgrPktChkAlg_MD5 = 0x0101,

[0117] / *SHA1* /

[0118] devPwMgrPktChkAlg_SHA1 = 0x0201,

[0119] / *SHA2* /

[0120] devPwMgrPktChkAlg_SHA2_224 = 0x0301,

[0121] devPwMgrPktChkAlg_SHA2_256 = 0x0302, devPwMgrPktChkAlg_SHA2_384 = 0x0303, devPwMgrPktChkAlg_SHA2_512 = 0x0304,

[0122] / *SHA3* /

[0123] devPwMgrPktChkAlg_SHA3_224 = 0x0401,

[0124] devPwMgrPktChkAlg_SHA3_256 = 0x0402, devPwMgrPktChkAlg_SHA3_384 = 0x0403, devPwMgrPktChkAlg_SHA3_512 = 0x0404,

[0125] / *SM3* /

[0126] devPwMgrPktChkAlg_SM3 = 0x0501,

[0127] / *...* /

[0128] }devPwMgrPktCAlg_e;

[0129] D7. Check result length: The check result length varies according to the selected algorithm. This value is used to confirm the check result of the algorithm to ensure that the result length generated by the check algorithm is the expected length.

[0130] D8. Check result: The check result of the check algorithm for all fields before this field.

[0131] Ciphertext Protocol

[0132] C1. Protocol Version: Indicates the version followed by the cryptographic information protocol. The current version is fixed at 0x0001 and is used for the compatibility design of possible protocol version updates;

[0133] C2. Encryption Algorithm: Indicates which encryption algorithm is used to encrypt the subsequent ciphertext information and is used in conjunction with the key version in C3 below. The encryption algorithm is defined as follows in C / C++ implementation. This field is 2 bytes, so up to 65535 algorithms can be defined:

[0134] / *Device Password Management Algorithm* / typedef enum:uint16_t{

[0135] / *RSA* /

[0136] devPwMgrAlg_RSA = 0x0001,

[0137] / *ECC* /

[0138] devPwMgrAlg_ECC = 0x0101,

[0139] / *SM2* /

[0140] devPwMgrAlg_SM2 = 0x0201,

[0141] / *...* /

[0142] }devPwMgrAlg_e;

[0143] C3. Key Version: Indicates which version of the key is used for the encryption of the encryption algorithm in C2 above. (This version information is written into the device together with the public key when the key is updated);

[0144] C4. Ciphertext Information: The encrypted information content is the same as the content from D2 to D8 above.

[0145] 106. The client displays the decrypted administrator password for device login verification.

[0146] The ciphertext information in the above ciphertext protocol is obtained by encrypting the remaining fields in the plaintext protocol except the first three fields. The encryption method is jointly determined by the "encryption algorithm" and the "key version";

[0147] The key pair management server and the managed device need to ensure consistency in the specific definition and parsing method of the fields.

[0148] Embodiment 2

[0149] Regularly update the administrator password of managed devices without network communication capabilities

[0150] 201. Set a periodic password update cycle for the device. For example, the device is set to 1 week, 1 month or other period when it is due. The password is automatically updated once when it expires (the specific period can be determined based on whether the administrator password of the device is frequently used). The "device password management service program" automatically triggers the true random number generator to randomly generate a new administrator password according to the designed algorithm in the set period (the method is the same as B1 and B2 in the above embodiment 1);

[0151] 202. The "device password management service program" deletes the old password stored in the SE chip, and then stores the new password in the SE chip again, thereby completing the administrator password update.

[0152] Embodiment 3

[0153] Update of public and private key pairs for devices without network communication capabilities

[0154] If a private key leak occurs, the service personnel will contact the device user to request a device security upgrade, such as Figure 1 The solid line shows:

[0155] 301. The password management client connects to the key pair management server via a wired or wireless method such as an Ethernet network, a WLAN network, a dial-up network, etc., and the "password acquisition / update local client program" sends a key pair update request to the key pair management server;

[0156] 302. The server generates a new public-private key pair of an asymmetric encryption algorithm using the "asymmetric public-private key pair management program" (the method is the same as 101 and any step A1-A6 in the first embodiment above). The "asymmetric public-private key pair management program" returns the new public key carrying the version information to the client, and backs up the new public-private key pair and saves the private key to the server's secure storage HSM. The server stores all previously updated key pairs on the server, which ensures that all devices do not need to use the same version of the encryption algorithm and key.

[0157] 303. The password management client is connected to the managed device through physical connections such as USB, serial port, CAN, etc. The client uses the "password acquisition / update local client program" to write the new public key to the device. After the device receives the new public key, the "device password management service program" deletes the original old public key and saves the new public key to the general storage partition to complete the update of the key pair.

[0158] Through the above operation steps, the flexibility of the operation method for updating the key pair is ensured. Specifically, when implemented, the key can be updated, and the encryption algorithm can also be updated. Both the algorithm and the key can be updated as part of the key information to the managed device.

[0159] Embodiment 4

[0160] Currently, most managed electronic devices have both network communication ports and traditional USB, serial, CAN ports, etc. For example, Figure 7 For the LT8215GTCAM vehicle-mounted intelligent terminal, the implementation examples using traditional wired communication interfaces are as shown in the above Embodiments 1, 2, and 3, and will not be elaborated here.

[0161] Such as Figure 1 As shown by the dashed line part, the vehicle-mounted intelligent terminal with network communication capabilities uses the network communication port to connect wirelessly (wired) between the cloud proxy server and the password management client. Except for the connection communication method between the password management client and the managed device and the different application programs used by the client, the specific steps for generating the administrator password are completely the same as those in Embodiment 1 above. The same parts will not be elaborated here. The differences from "103 and 104 in Embodiment 1" are as follows:

[0162] "The connection between the device and the client is as Figure 3 shown. The client connects to the vehicle-mounted intelligent terminal through the password cloud proxy server in a wired or wireless manner such as through the Ethernet network, WLAN network, dial-up network, etc. The client writes the public key carrying the version information into the device through the "password get / update net client". Other steps are completely the same as those in Embodiment 1.

[0163] "Such as Figure 3 shown. The password management client sends a password request to the device through the "password get / update net client". Other steps are completely the same as those in Embodiment 1.

[0164] Embodiment 5

[0165] The administrator password of the vehicle-mounted intelligent terminal is updated regularly. The specific steps are completely the same as those in Embodiment 2 above and will not be elaborated here.

[0166] Embodiment 6

[0167] Such as Figure 1As shown by the dashed line, the in-vehicle intelligent terminal with network communication capabilities is wirelessly (or wired) connected to the password management client through the cloud proxy server using the network communication port. The specific steps for key update are exactly the same as those in the above-mentioned Embodiment 3, except for the connection method between the password management client and the device to be managed and the application used by the client. The same parts will not be elaborated again. The differences from "303 in Embodiment 3" are as follows:

[0168] "As Figure 3 shown, the service staff connects the password management client to the in-vehicle intelligent terminal through the password cloud proxy server by wired or wireless means such as Ethernet network, WLAN network, or dial-up network. The client writes the new public key into the device using the "Password Acquisition / Update Remote Client Program". Other steps are exactly the same as those in Embodiment 3.

[0169] In the above Embodiments 1 to 6, the connection method between the password management client and the server, and the connection method between the password management client and the device to be managed are as Figure 12 shown.

[0170] Embodiment 7

[0171] Figure 8 It is a schematic diagram of the structure of the password management client electronic device. The electronic device includes: 701 processor, 702 memory, 703 communicator, software "Password Acquisition / Update Local Client Program" and "Password Acquisition / Update Remote Client Program". The processor 701 can access the memory 702 and process the information and instructions received and sent by the communicator 703 from the device to be managed, the key pair management server, the password cloud proxy server, and the client itself, so that the processor 701 executes the method steps performed by the password management client described in any one of the above Embodiments 1, 3, 4, and 6.

[0172] This electronic device is a fixed client or a mobile client.

[0173] Embodiment 8

[0174] Figure 9 It is a schematic diagram of the structure of the key pair management server. The server includes: 801 processor, 802 memory, 803 communicator, and software "Asymmetric Public-Private Key Pair Management Program". The processor 801 can access the memory 802 and process the information and instructions received and sent by the communicator 803 from the password management client and the server itself, so that the processor 801 executes the method steps performed by the key pair management server described in any one of the above Embodiments 1, 3, 4, and 6.

[0175] Embodiment 9

[0176] Figure 10It is a schematic structural diagram of a device to be managed. In addition to the functional modules necessary for its own functions, the device also includes: a 901 processor, a 902 storage module, a 903 true random number generator, a 904 communicator, and the "device password management service program" software. The processor 901 can access the memory 902 and control the true random number generator 903 and process the information and instructions received and sent by the communicator 904 from the password management client, the password cloud proxy server, and the client itself, so that the processor 901 executes the method steps performed by the device to be managed described in any one of the first to sixth embodiments as described above.

[0177] Embodiment Ten

[0178] Figure 11 It is a schematic structural diagram of a device administrator password maintenance system, which includes: the password management client electronic device, the key pair management server, and the device to be managed as described above.

[0179] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for maintaining a device administrator password, characterized in that: The method includes: The password management client sends a key generation request to the key pair management server. The server randomly generates a public and private key pair of an asymmetric encryption algorithm, sends the public key back to the client, and stores the public and private key pair in the server storage space. The client writes the received public key to the managed device. When the public key is first written to the device, the device's true random number generator randomly generates a device administrator password according to the designed algorithm and stores it in the device's secure storage space, while the public key is stored in the device's normal storage space. The client sends a request to the device to obtain the password. The device retrieves the password from the secure storage space and reads the public key from the common storage space, encrypts the password with the public key, and then sends the encrypted information back to the client. The client sends the encrypted information to the server and requests decryption. The server retrieves the private key from the secure storage space to decrypt the encrypted information and then sends the decrypted information back to the client. The client displays the device administrator password in the decrypted information for device login verification.

2. The method according to claim 1, characterized in that The managed device automatically starts the true random number generator according to the set update cycle and randomly generates a new device administrator password according to the designed algorithm. The device deletes the old password stored in the secure storage space and stores the new password in the secure storage space. The managed device completes the device administrator password update.

3. The method according to claim 1, characterized in that The password management client sends a key pair update request to the server, the server randomly generates a new key pair of an asymmetric encryption algorithm, returns the new public key to the client, and saves the new public and private key pair to the server storage space; The client writes the new public key to the device. After the device receives the new public key, it deletes the old public key from the ordinary storage space and stores the new public key. The server completes the key pair update.

4. The method according to claim 1, characterized in that The device administrator password is randomly generated by the device's true random number generator according to a designed algorithm, including: using a random number as an index, obtaining password characters from a password character set, and finally splicing them into a valid password.

5. The method according to claim 1, characterized in that The device secure storage space includes: an SE chip; the common storage space includes: a common readable and writable partition.

6. The method according to claim 1, characterized in that The communication mode between the password management client and the server includes: wired communication or wireless network communication or wired network communication; the communication mode between the password management client and the managed device includes: wired communication or wireless network remote communication or wired network remote communication.

7. The method according to claim 1, characterized in that The encrypted information is transmitted between the password management client and the server, and between the password management client and the managed device using the ciphertext protocol, and the decrypted information is transmitted using the plaintext protocol.

8. As claimed in claim 7, characterized in that The ciphertext protocol encryption method is determined by the encryption algorithm and key version.

9. As claimed in claim 8, characterized in that The ciphertext information of the ciphertext protocol includes: username length, username, password length, password, verification algorithm, verification result length, and verification result.

10. The method according to claim 1, characterized in that The server includes: a private network server or a public network server, and the public network server adopts routing equipment and firewall security measures.

11. The method according to any one of claims 1 or 3, characterized in that: Each time the server generates a key, the key version information is +1; the public key sent back to the client includes the version information; the server stores all generated public and private key pairs, and the private key is stored in a secure storage space, which includes: a hardware security module HSM.

12. A password management client electronic device, characterized in that include: The processor can access the memory, the memory stores programs and instructions, and the communicator transmits instructions. When the instructions are executed by the processor, the processor executes the method steps described in any one of claims 1, 3, 6, 7, 8, and 9.

13. The method according to claim 12, wherein: The client electronic device is a fixed client or a mobile client.

14. A server, characterized in that include: The processor can access the memory, the memory stores programs and instructions, and the communicator transmits instructions. When the instructions are executed by the processor, the processor executes the method steps described in any one of claims 1, 3, 6, 7, 8, 9, 10, and 11.

15. A device, in addition to its own functional components, characterized in that include: The processor can access the memory, the memory stores programs and instructions, and the communicator transmits instructions. When the instructions are executed by the processor, the processor executes the method steps described in any one of claims 1, 2, 3, 4, 5, 6, 7, 8, and 9.

16. A device administrator password maintenance system, characterized in that: include: The client electronic device as described in claim 12 or 13 is connected to the server as described in claim 14 via a network, and the client electronic device as described in claim 12 or 13 is connected to the device as described in claim 15 via a direct wired connection or a remote network connection.