Password transmission method and device
The front-end and back-end servers jointly generate random numbers and offsets, and the encryption password is encrypted using XOR operation, the problem that traditional encryption solutions are easily cracked is solved, and the security protection of user information in emergency location services is achieved.
Patent Information
- Application Number
- CN202410030279.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
在紧急位置服务应用中,传统的密码加密、传输技术方案存在固定的规则,容易被捕获并通过破解,无法满足紧急位置服务的安全需求。
Random numbers are generated through the front-end and back-end servers, and the password is encrypted using XOR operation and offset, ensuring the randomness and unpredictability of each encrypted password, avoiding the occurrence of fixed rules.
It improves the complexity of encrypted passwords, reduces the possibility of being cracked after being intercepted, ensures the security of user information, and meets the actual needs of emergency location services.
Smart Images

Figure CN120282134A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a password transmission method and apparatus. Background Art
[0002] This section aims to provide background or context for the embodiments of the present invention described in the claims. The description herein is not admitted to be prior art merely by virtue of its inclusion in this section.
[0003] Currently, with the rapid development of mobile communication technology and the wide popularity of mobile phone users, mobile phones have become the most effective way for emergency calls in current emergency scenarios such as medical first aid and emergency rescue. Emergency location service means that when a person is in an emergency situation, while making an emergency rescue call through a handheld terminal, the terminal automatically sends its location information to a management platform, and the management platform forwards the relevant location information to a rescue agency to provide emergency rescue services for the user.
[0004] In the application of emergency location service, there are security risks for user information, especially the security protection of the user's account password, which is of utmost importance. Traditional password encryption and transmission technical solutions generally have fixed rules and are easily captured during the transmission process and cracked through methods such as brute force testing and repeated verification, which cannot meet the actual requirements of the emergency location service application scenario. Summary of the Invention
[0005] Embodiments of the present invention provide a password transmission method to improve the complexity of the encrypted password during the transmission process, reduce the possibility of the encrypted password being cracked after being intercepted, and protect the security of user information. This method is applied to the foreground and includes:
[0006] Receiving the username and password submitted by the user;
[0007] Sending a verification data acquisition request to the background server for the background server to: generate verification data and send the verification data to the foreground; the verification data includes a first random number;
[0008] Receiving the verification data sent by the background server;
[0009] Generating an offset using the first random number according to the rules agreed upon by the foreground and the background server;
[0010] Generating a second random number;
[0011] Performing an exclusive OR calculation on each byte of the password with the corresponding byte of the second random number to obtain a first series of bytes;
[0012] Subtracting the offset from each byte in the first series of bytes to obtain a second series of bytes;
[0013] Form an array from the second series of bytes to obtain the encrypted password;
[0014] Send the encrypted password, username, verification data, and second random number to the background server.
[0015] An embodiment of the present invention provides a password transmission method for improving the complexity of the encrypted password during the transmission process, reducing the possibility of the encrypted password being cracked after being intercepted, and protecting the security of user information. This method is applied to the background server and includes:
[0016] Receive the encrypted password, username, verification data, and second random number sent by the foreground; the verification data includes a first random number, and this verification data is generated by the background server according to the acquisition request for verification data sent by the foreground after the foreground receives the username and password submitted by the user; the second random number is generated by the foreground after receiving the username and password submitted by the user; the encrypted password is obtained by the foreground encrypting the password submitted by the user using the verification data and the second random number;
[0017] Generate an offset using the first random number according to the rules agreed upon by the foreground and the background server;
[0018] Convert the encrypted password into an array to obtain the second series of bytes;
[0019] Add the offset to each byte in the second series of bytes to obtain the first series of bytes;
[0020] Perform an exclusive OR calculation on each byte of the first series of bytes and the corresponding byte of the second random number to obtain the password.
[0021] An embodiment of the present invention further provides a password transmission device for improving the complexity of the encrypted password during the transmission process, reducing the possibility of the encrypted password being cracked after being intercepted, and protecting the security of user information. This method is applied to the foreground and the device includes:
[0022] A request receiving module for receiving the username and password submitted by the user;
[0023] A verification data acquisition module for sending a request for acquiring verification data to the background server for the background server to: generate verification data and send the verification data to the foreground; the verification data includes a first random number;
[0024] A verification data receiving module for receiving the verification data sent by the background server;
[0025] A password encryption module, which is used to generate an offset using a first random number according to the rules agreed upon by the front-end and back-end servers; generate a second random number; perform an exclusive OR calculation on each byte of the password with the corresponding byte of the second random number to obtain a first series of bytes; subtract the offset from each byte in the first series of bytes to obtain a second series of bytes; form an array from the second series of bytes to obtain an encrypted password.
[0026] A data sending module, which is used to send the encrypted password, username, verification data, and second random number to the back-end server.
[0027] An embodiment of the present invention further provides a password transmission device, which is used to improve the complexity of the encrypted password during the transmission process, reduce the possibility of the encrypted password being cracked after being intercepted, and protect the security of user information. This method is applied to the back-end server, and the device includes:
[0028] A data receiving module, which is used to receive the encrypted password, username, verification data, and second random number sent by the front-end; the verification data includes a first random number, and this verification data is generated by the back-end server according to a request for obtaining verification data sent by the front-end to the back-end after the front-end receives the username and password submitted by the user; the second random number is generated by the front-end after receiving the username and password submitted by the user; the encrypted password is obtained by the front-end encrypting the password submitted by the user using the verification data and the second random number.
[0029] A password decryption module, which is used to generate an offset using a first random number according to the rules agreed upon by the front-end and back-end servers; convert the encrypted password into an array to obtain a second series of bytes; add the offset to each byte in the second series of bytes to obtain a first series of bytes; perform an exclusive OR calculation on each byte of the first series of bytes with the corresponding byte of the second random number to obtain the password.
[0030] An embodiment of the present invention further provides a computer device, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned password transmission method is implemented.
[0031] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned password transmission method is implemented.
[0032] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the above-mentioned password transmission method is implemented.
[0033] In an embodiment of the present invention, after the front end receives the user name and password submitted by the user, it obtains verification data from the back-end server. The verification data includes a first random number, and a second random number is generated. Each byte of the password is XOR-calculated with the corresponding byte of the second random number to obtain a first series of bytes; each byte in the first series of bytes is subtracted by the offset generated from the first random number to obtain a second series of bytes, and the second series of bytes are combined into an array to obtain the encrypted password. That is, the second random number generated by the front end is used for XOR calculation, and the first random number generated by the back-end server is used for calculating the offset. The front end and the back-end server cooperate to implement the password encryption process. Moreover, since the first random number and the second random number are both random and unpredictable each time the same password is encrypted, even for the same password, the encrypted passwords transmitted each time are different. Such encrypted passwords do not have a fixed composition rule and cannot be cracked by methods such as repeated verification and brute-force testing, improving the complexity of the encrypted password during the transmission process, reducing the possibility of the encrypted password being cracked after being intercepted, ensuring the security of user information, and meeting the actual requirements of the emergency location service application scenario.
[0034] In an embodiment of the present invention, the back-end server receives the encrypted password, user name, verification data, and second random number sent by the front end; the verification data is generated by the back-end server according to the acquisition request of the verification data sent by the front end after the front end receives the user name and password submitted by the user; the second random number is generated by the front end after receiving the user name and password submitted by the user; wherein, the verification data includes a first random number; the encrypted password is obtained by the front end encrypting the password submitted by the user using the verification data and the second random number; according to the rules agreed upon by the front end and the back-end server, an offset is generated using the first random number; the encrypted password is converted into an array to obtain a second series of bytes; each byte in the second series of bytes is added with the offset to obtain a first series of bytes; each byte of the first series of bytes is XOR-calculated with the corresponding byte of the second random number to obtain the password. That is, the second random number generated by the front end is used for XOR calculation, and the first random number generated by the back-end server is used for calculating the offset. The front end and the back-end server cooperate to implement the password encryption process. Moreover, since the first random number and the second random number are both random and unpredictable when encrypting the same password, even for the same password, the encrypted passwords transmitted each time are different. The encrypted password does not have a fixed composition rule and cannot be cracked by methods such as repeated verification and brute-force testing, improving the complexity of the encrypted password during the transmission process, reducing the possibility of the encrypted password being cracked after being intercepted; the back-end server can obtain the first random number and the second random number used by the front end when encrypting the password, and use the rules agreed upon by the front end and the back-end server to crack the encrypted password, ensuring the security of user information and meeting the actual requirements of the emergency location service application scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. In the drawings:
[0036] Figure 1 It is a schematic flowchart of the password transmission method applied to the front desk in the embodiment of the present invention;
[0037] Figure 2 It is a schematic flowchart of the password transmission method applied to the background server in the embodiment of the present invention;
[0038] Figure 3 It is a schematic diagram of the password transmission device applied to the front desk in the embodiment of the present invention;
[0039] Figure 4 It is a schematic diagram of the password transmission device applied to the background server in the embodiment of the present invention;
[0040] Figure 5 It is a schematic diagram of the computer device in the embodiment of the present invention. Detailed implementation manners
[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer and more understandable, the following will further describe the embodiments of the present invention in detail with reference to the drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.
[0042] The applicant found that in the emergency location service application, there are security risks for user information, especially the security protection of the user's account password, which is of utmost importance. The traditional password encryption and transmission technical solutions generally have fixed rules and are easily captured during the transmission process and cracked through methods such as spoofing tests and repeated verifications, unable to meet the actual needs of the emergency location service application scenario. For this reason, the applicant proposed a password transmission method.
[0043] It should be noted that in the technical solutions of this application, the acquisition, storage, use, processing, etc. of data all comply with the relevant regulations of national laws and regulations.
[0044] Figure 1 It is a schematic flowchart of the password transmission method applied to the front desk in the embodiment of the present invention. As Figure 1 shown, the method includes:
[0045] Step 101, receive the username and password submitted by the user;
[0046] Step 102: Send a request to the background server to obtain verification data for the background server to: generate verification data and send the verification data to the foreground; the verification data includes a first random number.
[0047] Step 103: Receive the verification data sent by the background server.
[0048] Step 104: Generate an offset using the first random number according to the rules agreed upon by the foreground and the background server.
[0049] Step 105: The foreground generates a second random number.
[0050] Step 106: Perform an exclusive OR calculation on each byte of the password with the corresponding byte of the second random number to obtain a first series of bytes.
[0051] Step 107: Subtract the offset from each byte in the first series of bytes to obtain a second series of bytes.
[0052] Step 108: Form an array from the second series of bytes to obtain the encrypted password.
[0053] Step 109: Send the encrypted password, username, verification data, and second random number to the background server.
[0054] From Figure 1 As can be seen from the above process, in the embodiment of the present invention, after the foreground receives the username and password submitted by the user, it obtains verification data from the background server. The verification data includes a first random number, and a second random number is generated. Each byte of the password is subjected to an exclusive OR calculation with the corresponding byte of the second random number to obtain a first series of bytes; each byte in the first series of bytes is subtracted by the offset generated from the first random number to obtain a second series of bytes, and the second series of bytes are formed into an array to obtain the encrypted password. That is, the second random number generated by the foreground is used for exclusive OR calculation, and the first random number generated by the background server is used for calculating the offset. The foreground and the background server cooperate to achieve the password encryption process. Moreover, since for the same password, the first random number and the second random number are random and unpredictable each time encryption is performed, even for the same password, the encrypted passwords transmitted each time are different. Such encrypted passwords do not have a fixed composition rule and cannot be cracked by methods such as repeated verification and brute force testing, improving the complexity of the encrypted password during the transmission process, reducing the possibility of being cracked after the encrypted password is intercepted, ensuring the security of user information, and meeting the actual needs of the emergency location service application scenario.
[0055] The following details the password transmission method applied to the foreground in the embodiment of the present invention.
[0056] In a possible implementation manner, the embodiments of the present invention are mainly directed to the application scenario of emergency rescue, and solve the security problems in the storage and transmission of user passwords in emergency location services. When a user logs in, when the front end receives the user name and password submitted by the user, it needs to submit the user name and password to the back-end server. Among them, the user name can be an identifier such as a user account or a user ID. In such a web application, the user name and password are encrypted and protected during the interaction process or the transmission process between the front end and the back-end server.
[0057] After the front end receives the user name and password submitted by the user, it sends a request for obtaining verification data to the back-end server. The back-end server receives the request for obtaining verification data, generates verification data, and returns the verification data to the front end. Among them, the verification data can include data such as a first random number, a random string, and a unique identification string for the current login, which are used for the back-end server to verify the user name and password sent by the front end later.
[0058] In one embodiment, the verification data further includes a verification code, and the time interval for obtaining the verification code is greater than a first duration threshold. For example, the time interval for obtaining the verification code within a login session cannot be less than 400 milliseconds. If it is less than 400 milliseconds, an error message prompt is displayed on the front end. Since the time interval for obtaining the verification code is restricted, the probability of repeatedly attempting to crack the password is reduced, the situation of forcibly cracking the password through the verification code is avoided, and the security of user information is enhanced.
[0059] After that, the front end encrypts the password.
[0060] In step 104, after the front end receives the verification data sent by the back-end server, according to the rules agreed upon by the front end and the back-end server, an offset is generated using the first random number. For example, an integer is generated using the first random number according to a fixed formula, and then a decimal is generated using the last digit of the integer according to another fixed formula as the offset. In this example, the rules agreed upon by the front end and the back-end server are not limited, and those skilled in the art can customize the generation of the offset.
[0061] In one embodiment, in order to increase the difficulty of the encryption password cracking algorithm, generating an offset using the first random number according to the rules agreed upon by the front end and the back-end server may include:
[0062] Dividing one byte of the first random number by the first value and taking the remainder as the offset; the value range of the first value is: [10, 255].
[0063] For example, the 16-byte first random number generated by the background server is: 73 209 63 87 138 222 190 233 77 120 237 200 202 248 127 89. Take the second byte 209, divide it by 10, and the remainder 9 is used as the offset. Or take the second byte 209, divide it by 125, and the remainder 84 is used as the offset. Or take the second byte 209, divide it by 185, and the remainder 24 is used as the offset. Or take the second byte 209, divide it by 255, and the remainder 209 is used as the offset.
[0064] Among them, the foreground and background servers can agree on rules for each login, or can agree on a rule for a period of time and then replace it regularly.
[0065] It can be seen from this example that one of the bytes of the first random number in the rules agreed upon by the foreground and background servers is different each time, so that the amount of downward offset for each byte in the password encryption process is different, and the amount of upward offset for each byte in the decryption process is also different. Therefore, the ciphertext including the encrypted password transmitted each time for the same password is also different. Even in the case of malicious cracking, the ciphertext including the encrypted password captured through the network is also different, reducing the probability of derivation and decryption through regular algorithms.
[0066] In step 105, after the foreground receives the username and password submitted by the user, it needs to generate a second random number by itself. In a preferred embodiment, the second random number is 32 bytes, and the generation order of the second random number and the first random number is not limited.
[0067] In one embodiment, to ensure the stability of the encryption algorithm, the maximum length of the password that the user can set is agreed upon, and it is set that the length of the second random number is greater than the maximum length of the password.
[0068] In step 106, each byte of the password is XOR-calculated with the corresponding byte of the second random number to obtain a first series of bytes. In implementation, the password and the second random number are XOR-calculated byte by byte to obtain a first series of bytes. This step can use a loop algorithm to perform loop calculations on each byte of the password.
[0069] In step 107, each byte in the first series of bytes is subtracted by the offset to obtain a second series of bytes. In implementation, each byte in the first series of bytes is subtracted by the offset to obtain a second series of bytes. This step can use a loop algorithm to perform loop calculations on each byte of the first series of bytes.
[0070] In step 108, the second series of bytes are formed into an array to obtain the encrypted password. In implementation, the second series of bytes are formed into an array, and the text of this array is used as the encrypted password transmitted to the background server.
[0071] Finally, in step 109, the encrypted password, username, verification data, and second random number are sent to the background server. The background server decrypts the encrypted password and performs login checks on the password, username, and verification data, as well as stores the password, etc.
[0072] In one embodiment, sending the encrypted password, username, verification data, and second random number to the background server may include: forming a JSON data packet with the encrypted password, username, verification data, and second random number and sending it to the background server. This can ensure the integrity of the transmitted data and improve the password transmission efficiency.
[0073] Figure 2 It is a schematic flowchart of the password transmission method applied to the background server in the embodiments of the present invention. As Figure 2 shown, the method includes:
[0074] Step 201, receive the encrypted password, username, verification data, and second random number sent by the foreground; the verification data includes a first random number, and the verification data is generated by the background server according to a request for obtaining verification data sent by the foreground to the background server after the foreground receives the username and password submitted by the user; the second random number is generated by the foreground after receiving the username and password submitted by the user; the encrypted password is obtained by the foreground encrypting the password submitted by the user using the verification data and the second random number;
[0075] Step 202, generate an offset using the first random number according to the rules agreed upon by the foreground and the background server;
[0076] Step 203, convert the encrypted password into an array to obtain a second series of bytes;
[0077] Step 204, add the offset to each byte in the second series of bytes to obtain a first series of bytes;
[0078] Step 205, perform an exclusive OR calculation on each byte of the first series of bytes and the corresponding byte of the second random number to obtain the password.
[0079] From Figure 2As can be seen from the process shown, in the embodiment of the present invention, the background server receives the encrypted password, username, verification data, and second random number sent by the foreground; the verification data is generated by the background server according to the acquisition request for the verification data sent by the foreground after the foreground receives the username and password submitted by the user; the second random number is generated by the foreground after receiving the username and password submitted by the user; wherein, the verification data includes a first random number; the encrypted password is obtained by the foreground encrypting the password submitted by the user by using the verification data and the second random number; according to the rules agreed upon by the foreground and the background server, an offset is generated by using the first random number; the encrypted password is converted into an array to obtain a second series of bytes; each byte in the second series of bytes is added with the offset to obtain a first series of bytes; each byte of the first series of bytes is subjected to an exclusive OR calculation with the corresponding byte of the second random number to obtain the password; that is, the second random number generated by the foreground is used for the exclusive OR calculation, and the first random number generated by the background server is used for calculating the offset. The foreground and the background server cooperate to implement the password encryption process. Moreover, since the first random number and the second random number are both random and unpredictable when encrypting the same password, therefore, even for the same password, the encrypted passwords transmitted each time are different, and there is no fixed composition rule for the encrypted password, and it cannot be cracked by methods such as repeated verification and brute force testing, which improves the complexity of the encrypted password during the transmission process and reduces the possibility of the encrypted password being cracked after being intercepted; the background server can obtain the first random number and the second random number used by the foreground when encrypting the password, and use the rules agreed upon by the foreground and the background server to crack the encrypted password, ensuring the security of user information and meeting the actual requirements of the emergency location service application scenario.
[0080] The password transmission method applied to the background server in the embodiment of the present invention will be explained in detail below.
[0081] In a possible implementation manner, the embodiment of the present invention mainly aims at the application scenario of emergency rescue and solves the security problems in the storage and transmission of user passwords in the emergency location service. When the user logs in, after the background server receives the password-related data sent by the foreground, it is necessary to store and decrypt the password-related data. In this web application, the password-related data is protected and decrypted during the interaction process or the transmission process between the background server and the foreground. Among them, the password-related data includes the encrypted password, username, verification data, and second random number; the verification data is generated by the background server according to the acquisition request for the verification data sent by the foreground after the foreground receives the username and password submitted by the user. The verification data may include data such as a first random number, a random string, and a unique identification string for the current login, etc.; the second random number is generated by the foreground after receiving the username and password submitted by the user; the encrypted password is obtained by the foreground encrypting the password submitted by the user by using the verification data and the second random number.
[0082] In one embodiment, the verification data further includes a verification code, and the acquisition time interval of the verification code is greater than a first duration threshold. For example, within a login session, the time interval for the foreground to obtain the verification code from the background server cannot be less than 400 milliseconds. If it is less than 400 milliseconds, an error message is returned to the foreground. Since the time interval for obtaining the verification code is restricted, the probability of repeatedly attempting to crack the encrypted password is reduced, the situation of forcibly cracking the password through the verification code is avoided, and the security of user information is enhanced.
[0083] In one embodiment, in order to ensure the stability of the encryption algorithm, it is agreed that the maximum length of the password that the user can set is determined, and it is set that the length of the second random number is greater than the maximum length of the password.
[0084] In one embodiment, the background server receives a JSON data packet sent by the foreground, which consists of an encrypted password, a username, verification data, and a second random number. This can ensure the integrity of the transmitted data and improve the password transmission efficiency.
[0085] After that, the background server decrypts the password.
[0086] In step 202, according to the rules agreed upon by the foreground and the background server, an offset is generated using the first random number. For example, an integer is generated using the first random number according to a fixed formula, and then a decimal number is generated using the last digit of the integer according to another fixed formula as the offset. In this example, the rules agreed upon by the foreground and the background server are not limited, and those skilled in the art can customize the generation of the offset.
[0087] In one embodiment, in order to increase the difficulty of the encrypted password cracking algorithm, generating an offset using the first random number according to the rules agreed upon by the foreground and the background server may include:
[0088] Dividing one byte of the first random number by a first value and taking the remainder as the offset; the value range of the first value is: [10, 255].
[0089] For example, the 16-byte first random number returned by the foreground is: 94 24 91 214 23 20 98 179 194 240 207 195 151 146 26 210. Taking the second byte 24 and dividing it by 10, the remainder 4 is used as the offset, or taking the fourth byte 214 and dividing it by 125, the remainder 89 is used as the offset, or taking the fourth byte 214 and dividing it by 185, the remainder 29 is used as the offset, or taking the fourth byte 214 and dividing it by 255, the remainder 214 is used as the offset.
[0090] Among them, the front-end and back-end servers can agree on rules for each login, or they can agree on a rule for a period of time and then replace it regularly.
[0091] As can be seen from this example, one of the bytes of the first random number in the rules agreed upon by the front-end and back-end servers is different each time, so that the amount of downward offset for each byte during the password encryption process is different, and the amount of upward offset for each byte during the decryption process is also different. Therefore, the ciphertext including the encrypted password transmitted each time for the same password is also different. Even in the case of malicious cracking, the ciphertext including the encrypted password captured through the network is also different, reducing the probability of derivation and decryption through regular algorithms.
[0092] In step 203, the encrypted password is converted into an array to obtain a second series of bytes. In implementation, the encrypted password can be in a text form, and it is converted into an array to obtain a second series of bytes.
[0093] In step 204, each byte in the second series of bytes is added with an offset to obtain a first series of bytes. In implementation, each byte in the second series of bytes is added with the offset byte by byte to obtain a first series of bytes. This step can use a loop algorithm to perform loop calculations on each byte in the second series of bytes.
[0094] In step 205, each byte in the first series of bytes is subjected to an exclusive OR calculation with the corresponding byte of the second random number to obtain the password. In implementation, each byte in the first series of bytes is subjected to an exclusive OR calculation with the second random number byte by byte to obtain the password. This password is the original password submitted by the user. This step can use a loop algorithm to perform loop calculations on each byte in the first series of bytes.
[0095] After that, login checks can be performed on the username, password, and verification code in the verification data. If the check passes, login is successful and a success message is returned. If the check fails, a failure message is returned. Possible reasons for the check failure can include key error messages such as incorrect verification code, non-existent username, and incorrect password.
[0096] In an embodiment of the present invention, a password transmission device is also provided, as described in the following embodiment. Since the principle of this device for solving problems is similar to that of the password transmission method, the implementation of this device can refer to the implementation of the password transmission method, and the repeated parts will not be described again.
[0097] Figure 3 It is a schematic diagram of the password transmission device applied to the front-end in an embodiment of the present invention, as Figure 3 shown. This device includes:
[0098] A request receiving module 301, configured to receive the username and password submitted by the user;
[0099] The verification data acquisition module 302 is configured to send a request for acquiring verification data to the background server for the background server to: generate verification data and send the verification data to the foreground; the verification data includes a first random number.
[0100] The verification data receiving module 303 is configured to receive the verification data sent by the background server.
[0101] The password encryption module 304 is configured to generate an offset using the first random number according to the rules agreed upon by the foreground and the background server; generate a second random number; perform an exclusive OR calculation on each byte of the password with the corresponding byte of the second random number to obtain a first series of bytes; subtract the offset from each byte in the first series of bytes to obtain a second series of bytes; form an array with the second series of bytes to obtain the encrypted password.
[0102] The ciphertext sending module 305 is configured to send the encrypted password, the username, the verification data, and the second random number to the background server.
[0103] In one embodiment, the verification data further includes a verification code, and the acquisition time interval of the verification code is greater than a first duration threshold.
[0104] In one embodiment, the password encryption module 304 is specifically configured to:
[0105] Divide one byte of the first random number by a first value and take the remainder as the offset; the value range of the first value is: [10, 255].
[0106] In one embodiment, the first value is 10;
[0107] The password encryption module 304 is specifically configured to:
[0108] Divide the second byte of the first random number by 10 and take the remainder as the offset.
[0109] In one embodiment, the length of the second random number is greater than the maximum length of the password.
[0110] In one embodiment, the ciphertext sending module 305 is specifically configured to:
[0111] Form a JSON data packet with the encrypted password, the username, the first random number, and the second random number, and send it to the background server.
[0112] Figure 4 It is a schematic diagram of a password transmission device applied to a background server in an embodiment of the present invention. As Figure 4 shown, the device includes:
[0113] A data receiving module 401 is configured to receive an encrypted password, a username, verification data, and a second random number sent by the front end; the verification data includes a first random number, which is generated by the back-end server according to a request for obtaining verification data sent by the front end after the front end receives the username and password submitted by the user; the second random number is generated by the front end after receiving the username and password submitted by the user; the encrypted password is obtained by the front end encrypting the password submitted by the user by using the verification data and the second random number.
[0114] A password decryption module 402 is configured to generate an offset by using the first random number according to a rule agreed upon by the front end and the back-end server; convert the encrypted password into an array to obtain a second series of bytes; add the offset to each byte in the second series of bytes to obtain a first series of bytes; perform an exclusive OR calculation on each byte in the first series of bytes and the corresponding byte of the second random number to obtain the password.
[0115] In one embodiment, the verification data further includes a verification code, and the time interval for obtaining the verification code is greater than a first duration threshold.
[0116] In one embodiment, the password decryption module 402 is specifically configured to:
[0117] Divide one byte of the first random number by a first value, and take the remainder as the offset; the value range of the first value is: [10, 255].
[0118] In one embodiment, the first value is 10;
[0119] The password decryption module 402 is specifically configured to:
[0120] Divide the second byte of the first random number by 10, and take the remainder as the offset.
[0121] In one embodiment, the length of the second random number is greater than the maximum length of the password.
[0122] Figure 5 The following is a schematic diagram of a computer device in an embodiment of the present invention. As Figure 5 shown, an embodiment of the present invention further provides a computer device 500, including a processor 501, a memory 502, and a computer program 503 stored in the memory 502 and executable on the processor 501. When the processor 501 executes the computer program 503, the above password transmission method is implemented.
[0123] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above password transmission method is implemented.
[0124] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the above password transmission method is implemented.
[0125] In an embodiment of the present invention, after the front end receives the user name and password submitted by the user, it obtains verification data from the back-end server. The verification data includes a first random number, and a second random number is generated. Each byte of the password is XOR-calculated with the corresponding byte of the second random number to obtain a first series of bytes; each byte in the first series of bytes is subtracted by an offset generated from the first random number to obtain a second series of bytes, and the second series of bytes are combined into an array to obtain an encrypted password; that is, the second random number generated by the front end is used for XOR calculation, and the first random number generated by the back-end server is used for calculating the offset. The front end and the back-end server cooperate to implement the password encryption process. Moreover, since the first random number and the second random number are random and unpredictable each time the same password is encrypted, even for the same password, the encrypted passwords transmitted each time are different. Such encrypted passwords do not have a fixed composition rule and cannot be cracked by methods such as repeated verification and brute-force testing, which improves the complexity of the encrypted password during the transmission process, reduces the possibility of the encrypted password being cracked after being intercepted, ensures the security of user information, and meets the actual requirements of the emergency location service application scenario.
[0126] In the embodiments of the present invention, the background server receives the encrypted password, username, verification data, and second random number sent by the foreground; the verification data is generated by the background server according to the acquisition request of the verification data sent by the foreground to the background server after the foreground receives the username and password submitted by the user; the second random number is generated by the foreground after receiving the username and password submitted by the user; wherein, the verification data includes a first random number; the encrypted password is obtained by the foreground encrypting the password submitted by the user by using the verification data and the second random number; according to the rules agreed upon by the foreground and the background server, an offset is generated by using the first random number; the encrypted password is converted into an array to obtain a second series of bytes; each byte in the second series of bytes is added with the offset to obtain a first series of bytes; each byte of the first series of bytes is subjected to an exclusive OR calculation with the byte corresponding to the second random number to obtain the password; that is, the second random number generated by the foreground is used for the exclusive OR calculation, and the first random number generated by the background server is used for calculating the offset. The foreground and the background server cooperate to implement the password encryption process. Moreover, since the first random number and the second random number are both random and unpredictable when encrypting the same password, even for the same password, the encrypted passwords transmitted each time are different, and there is no fixed composition rule for the encrypted password, and it cannot be cracked by methods such as repeated verification and brute force testing, which improves the complexity of the encrypted password during the transmission process and reduces the possibility of the encrypted password being cracked after being intercepted; the background server can obtain the first random number and the second random number used by the foreground when encrypting the password, and use the rules agreed upon by the foreground and the background server to crack the encrypted password, ensuring the security of user information and meeting the actual requirements of the emergency location service application scenario.
[0127] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, system, or computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0128] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocksFigure 1 means for the functions specified in one or more blocks.
[0129] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 1 process or a plurality of processes and / or blocks Figure 1 or more blocks.
[0130] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 process or a plurality of processes and / or blocks Figure 1 or more blocks.
[0131] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A password transmission method, characterized in that, Applied to the foreground, including: Receive the username and password submitted by the user; Send a request to obtain verification data to the background server for the background server to: generate verification data and send the verification data to the foreground; the verification data includes a first random number; Receive the verification data sent by the background server; Generate an offset using the first random number according to the rules agreed upon by the foreground and the background server; Generate a second random number; Perform an exclusive OR calculation on each byte of the password with the corresponding byte of the second random number to obtain a first series of bytes; Subtract the offset from each byte in the first series of bytes to obtain a second series of bytes; Form an array with the second series of bytes to obtain the encrypted password; Send the encrypted password, username, verification data, and second random number to the background server.
2. The method according to claim 1, wherein The verification data further includes a verification code, and the time interval for obtaining the verification code is greater than the first duration threshold.
3. The method according to claim 1, characterized in that Generating an offset using the first random number according to the rules agreed upon by the foreground and the background server includes: Divide one byte of the first random number by the first value and take the remainder as the offset; the value range of the first value is: [10, 255].
4. The method according to claim 3, characterized in that, The first value is 10; Dividing one byte of the first random number by the first value and taking the remainder as the offset includes: Divide the second byte of the first random number by 10 and take the remainder as the offset.
5. The method according to claim 1, characterized in that, The length of the second random number is greater than the maximum length of the password.
6. The method according to claim 1, characterized in that Sending the encrypted password, username, verification data, and second random number to the background server includes: Form a JSON data packet with the encrypted password, username, verification data, and second random number and send it to the background server.
7. A password transmission method, characterized in that, Applied to the background server, including: Receive the encrypted password, username, verification data, and second random number sent by the foreground; the verification data includes a first random number, which is generated by the background server according to the request for obtaining verification data sent by the foreground after the foreground receives the username and password submitted by the user; the second random number is generated by the foreground after receiving the username and password submitted by the user; the encrypted password is obtained by the foreground encrypting the password submitted by the user using the verification data and the second random number; Generate an offset using the first random number according to the rules agreed upon by the foreground and the background server; Convert the encrypted password into an array to obtain a second series of bytes; Add the offset to each byte in the second series of bytes to obtain a first series of bytes; Perform an exclusive OR calculation on each byte of the first series of bytes with the corresponding byte of the second random number to obtain the password.
8. The method according to claim 7, wherein The verification data further includes a verification code, and the time interval for obtaining the verification code is greater than the first duration threshold.
9. The method according to claim 7, wherein Generating an offset using the first random number according to the rules agreed upon by the foreground and the background server includes: Divide one byte of the first random number by the first value and take the remainder as the offset; the value range of the first value is: [10, 255].
10. The method according to claim 9, wherein The first value is 10; Dividing one byte of the first random number by the first value and taking the remainder as the offset includes: Divide the second byte of the first random number by 10 and take the remainder as the offset.
11. The method according to claim 7, wherein The length of the second random number is greater than the maximum length of the password.
12. A password transmission device, characterized in that, Applied to the foreground, it includes: A request receiving module, used to receive the username and password submitted by the user; A verification data acquisition module, used to send a request for acquiring verification data to the background server for the background server to: generate verification data and send the verification data to the foreground; the verification data includes a first random number; A verification data receiving module, used to receive the verification data sent by the background server; A password encryption module, used to generate an offset using the first random number according to the rules agreed upon by the foreground and the background server; generate a second random number; perform exclusive OR calculation on each byte of the password with the corresponding byte of the second random number to obtain a first series of bytes; subtract the offset from each byte in the first series of bytes to obtain a second series of bytes; form an array from the second series of bytes to obtain an encrypted password; A ciphertext sending module, used to send the encrypted password, username, verification data, and second random number to the background server.
13. The device according to claim 12, characterized in that, The verification data further includes a verification code, and the acquisition time interval of the verification code is greater than a first duration threshold.
14. The device according to claim 12, wherein Specifically, the password encryption module is used for: Dividing one byte of the first random number by a first value and taking the remainder as the offset; the value range of the first value is: [10, 255].
15. The device according to claim 14, wherein, The first value is 10; Specifically, the password encryption module is used for: Dividing the second byte of the first random number by 10 and taking the remainder as the offset.
16. The device according to claim 12, characterized in that, The length of the second random number is greater than the maximum length of the password.
17. The device according to claim 12, characterized in that, Specifically, the ciphertext sending module is used for: Forming a JSON data packet from the encrypted password, username, first random number, and second random number and sending it to the background server.
18. A password transmission device, characterized in that, Applied to the background server, it includes: A data receiving module, used to receive the encrypted password, username, verification data, and second random number sent by the foreground; the verification data includes a first random number, and this verification data is generated by the background server according to the request for acquiring verification data sent by the foreground after the foreground receives the username and password submitted by the user; the second random number is generated by the foreground after receiving the username and password submitted by the user; the encrypted password is obtained by the foreground encrypting the password submitted by the user using the verification data and the second random number; A password decryption module, used to generate an offset using the first random number according to the rules agreed upon by the foreground and the background server; convert the encrypted password into an array to obtain a second series of bytes; add the offset to each byte in the second series of bytes to obtain a first series of bytes; perform exclusive OR calculation on each byte of the first series of bytes with the corresponding byte of the second random number to obtain the password.
19. The device according to claim 18, characterized in that, The verification data further includes a verification code, and the acquisition time interval of the verification code is greater than a first duration threshold.
20. The device according to claim 18, characterized in that Specifically, the password decryption module is used for: Dividing one byte of the first random number by a first value and taking the remainder as the offset; the value range of the first value is: [10, 255].
21. The device according to claim 20, characterized in that, The first value is 10; Specifically, the password decryption module is used for: Dividing the second byte of the first random number by 10 and taking the remainder as the offset.
22. The device according to claim 18, wherein, The length of the second random number is greater than the maximum length of the password.
23. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 11 is implemented.
24. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 11 is implemented.
25. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 11 is implemented.