WebSocket-based user login method and device

The WebSocket-based user login method securely processes backspace inputs and encrypts password corrections in Shell terminals, addressing inefficiencies and security risks in root user authentication.

CN120321050AInactive Publication Date: 2025-07-15RONGKE LIANCHUANG (TIANJIN) INFORMATION TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510809291.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-07-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When the existing Shell command line management software terminals process users' input root username and password, the fallback operation cannot be handled correctly, resulting in the input errors that cannot be corrected in time, affecting operation efficiency and security.

Method used

The WebSocket protocol is used to log in to the user, encrypt the password entered by the user through random permutation and XOR operations, and perform special character processing on the client to ensure that the fallback operation is executed normally.

Benefits of technology

It improves the operation efficiency and security of users when entering root username and password, reduces operational inconvenience caused by input errors, and enhances the ease of use and reliability of the terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321050A_ABST
    Figure CN120321050A_ABST
Patent Text Reader

Abstract

The invention provides a user login method and device based on WebSocket, and relates to the technical field of user login, and the method comprises the steps: connecting a server through the WebSocket; obtaining a login password from the user login interface; encrypting the login password according to a key sent by the server, and sending the encrypted login password to the server; wherein the step of encrypting the login password comprises random permutation and XOR operation; and receiving and displaying an execution result returned by the server. According to the invention, the interactive experience is smoother, and the operation inconvenience caused by incapability of backspacing due to input errors is reduced. In addition, when the client sends the password to the terminal on the server, encryption is carried out, and the data security is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In the field of computer system management and operation, the Shell command line management software terminal is an important tool for system administrators and advanced users to interact with the operating system. It is widely used in various Unix, Linux, and Unix-like systems, providing users with an efficient and flexible way to control the system. However, existing Shell command line management software terminals have significant limitations in processing user input, especially in the process of entering the root username and password.

[0003] In daily system management work, users often need to enter the root username and password in the Shell command line terminal to obtain the highest privileges of the system, so as to perform sensitive operations such as system configuration modification, software installation and uninstallation. When users enter the root username and password, it is inevitable that input errors will occur. At this time, users usually hope to be able to use the backspace operation (such as using the Backspace key) to correct the errors.

[0004] However, existing Shell command line management software terminals cannot properly solve this backspace requirement. The terminal is designed to recognize the backspace symbol as a special character, rather than as a normal input correction instruction. This means that when the user presses the Backspace key to try to delete the wrongly entered character, the terminal will not delete the previous character as expected by the user, but will perform special interpretation and processing on the backspace symbol, which may trigger some unexpected operations or display garbled characters, resulting in the user being unable to correct the input error smoothly.

[0005] This defect not only reduces the operation efficiency of users when using the Shell command line management software terminal, increases the operation cost and time cost of users, but also may lead to failure to obtain permissions due to the inability to correct input errors in time, thus affecting the normal execution of system management tasks. In addition, for users who are not familiar with this feature of the terminal, it may cause confusion and misoperations, and even may pose security risks. For example, multiple incorrect password entries may trigger the system's security lock mechanism.

[0006] The existing relevant solutions on the market at present have not effectively solved the above problems. Therefore, there is an urgent need for a new technical solution to improve the Shell command line management software terminal so that it can correctly process the backspace operation when users enter the root username and password, and improve the usability and reliability of the terminal. Summary of the Invention

[0007] In view of the above technical problems, the present application provides a WebSocket-based user login method and device, which at least partially solve the problems existing in the prior art.

[0008] In the first aspect of the present application, a user login method based on WebSocket is provided. The method is applied to a client; the client has a corresponding server; the client is provided with a web version user login interface; the method includes: Connect to the server through WebSocket; Obtain the login password from the user login interface; Encrypt the login password according to the key sent by the server, and send the encrypted login password to the server; wherein, encrypting the login password includes random permutation and exclusive OR operation; Receive and display the execution result returned by the server.

[0009] Optionally, connecting to the server through WebSocket includes: Send a handshake request to the server to establish a WebSocket connection; Obtain the WebSocket connection establishment response sent by the server.

[0010] Optionally, obtaining the login password from the user login interface includes: Obtain the currently input characters of the user; If the currently input character is the character corresponding to the backspace key or the delete key, delete the previous input character of the currently input character; otherwise, determine that the currently input character is the character corresponding to the login password.

[0011] Optionally, encrypting the login password according to the key sent by the server and sending the encrypted login password to the server includes: Obtain the key and the random permutation table sent by the server; wherein, the key is a random key of a fixed length; the random permutation table is generated according to the time stamp corresponding to the establishment of the WebSocket connection and the user behavior corresponding to the login password; the length of the random permutation table is the same as the length of the login password; Group the login password according to the preset data length to obtain a list of login password groups Y = (Y1, Y2,..., Y i ,..., Y n ); i = 1, 2,..., n; where n is the number of login password groups; Y i is the i-th group of password data after grouping the login password; According to the random permutation table corresponding to the current time, perform position permutation on Y to obtain a list of permuted password data D = (D1, D2,..., D i ,..., D n ); where D i is the i-th group of permuted password data; Perform an exclusive OR operation on the secret key and D to obtain the encrypted password data E; Send E to the server according to WebSocket.

[0012] Optionally, encrypt the login password according to the secret key sent by the server and send the encrypted login password to the server, including: Obtain a preset master secret key; Concatenate the master secret key and the current timestamp according to the first hashing algorithm to obtain a primary secret key; Use the primary secret key as a random number seed to obtain a first random permutation table; wherein, the length of the first random permutation table is the same as the length of the login password; Perform a position permutation on the login password according to the first random permutation table to obtain a first permuted login password; Concatenate the primary secret key and partial information of the current timestamp according to the second hashing algorithm to obtain an intermediate secret key; Perform an exclusive OR operation on the intermediate secret key and the first permuted login password to obtain a first encrypted login password; Obtain a high-level secret key according to the first encrypted login password, the intermediate secret key and partial information of the current timestamp; Use the high-level secret key as a random number seed to obtain a second random permutation table; Perform a position permutation on the login password according to the second random permutation table to obtain a second permuted login password; Concatenate the high-level secret key and partial information of the current timestamp according to the third hashing algorithm to obtain a target secret key; Perform an exclusive OR operation on the target secret key and the second permuted login password to obtain the encrypted login password; Send the encrypted login password to the server.

[0013] Optionally, the method further includes: sending the timestamp, the first random permutation table and the second random permutation table to the server.

[0014] Optionally, the method further includes: Send an HTTP upgrade request to the server to upgrade the HTTP connection to a WebSocket connection.

[0015] Optionally, the method further includes: When using WebSocket to establish a connection, perform data transmission in units of data frames.

[0016] Optionally, the method further includes: Send a heartbeat detection message to the server at preset time intervals and receive the heartbeat detection message from the server; wherein, the heartbeat detection message is used to confirm whether the connection with the server is disconnected.

[0017] In a second aspect of the present application, there is provided a user login device based on WebSocket, and the device is applied to a client; the client has a corresponding server; the client is provided with a web version user login interface; the device includes: A connection unit, configured to connect to the server through WebSocket; An acquisition unit, configured to acquire a login password from the user login interface; An encryption unit, configured to encrypt the login password according to the key sent by the server and send the encrypted login password to the server; wherein, encrypting the login password includes random permutation and exclusive-or operation; A receiving unit, configured to receive and display the execution result returned by the server.

[0018] The present application has at least the following beneficial effects: The user login method and device based on WebSocket provided by the present application use the WebSocket protocol control overhead. After the connection is created, when exchanging data with the server, the protocol control packet header is small, and commands and result data can be transmitted more efficiently; it has higher real-time performance. The server can actively push data. Compared with the request waiting of the HTTP protocol to initiate a response, the delay is significantly reduced, and the user can see the execution result faster after entering a command. In the traditional terminal in the root user login scenario, when an input error occurs, the backspace character is misjudged, while the web terminal based on WebSocket can restrict special characters. When the user wants to delete, it avoids treating the backspace and delete characters as ordinary characters, making the interaction experience smoother and reducing the operation inconvenience caused by the inability to backspace due to input errors. In addition, when the password is sent from the client to the terminal on the server, it is encrypted to ensure data security. Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0020] Figure 1 It is a flowchart of the user login method based on WebSocket provided by the embodiment of the present application; Figure 2Block diagram of the user login device based on WebSocket provided by the embodiments of the present application. Detailed implementation manners

[0021] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present application.

[0022] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily need to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0023] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present application, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement a device and / or practice a method. In addition, this device can be implemented and this method can be practiced using other structures and / or functions in addition to one or more of the aspects described herein.

[0024] Please refer to Figure 1 As shown, the embodiments of the present application provide a user login method based on WebSocket. The method is applied to a client; the client has a corresponding server; the client is provided with a web version user login interface; the method includes: S100, connect to the server through WebSocket.

[0025] Specifically, use the WebSocket protocol to send a connection establishment request for a one-time handshake to the server. Among them, the connection establishment request for a one-time handshake includes: sending a connection establishment request to the server and the connection establishment request response replied by the server. After receiving the connection establishment request response replied by the server, it indicates that the connection with the server is established successfully.

[0026] S200, obtain the login password from the user login interface.

[0027] Specifically, the user enters the password on the login interface. The user inputs the password by pressing the keyboard keys. Each keyboard key corresponds to a character. When the character corresponding to the backspace key or delete key pressed by the user is obtained, special processing is performed, and the previous character of the backspace character or delete character is deleted. Finally, the password is converted into password data corresponding to the characters.

[0028] S300, encrypt the login password according to the secret key sent by the server, and send the encrypted login password to the server. Among them, encrypting the login password includes random permutation and exclusive OR operation.

[0029] Specifically, step 300 further includes the following steps: Step a1, obtain the secret key and the random permutation table sent by the server. Among them, the secret key is a random secret key with a fixed length. The random permutation table is generated according to the timestamp corresponding to the establishment of the WebSocket connection and the user behavior corresponding to the login password. The length of the random permutation table is the same as the length of the login password.

[0030] Step a2, group the login password according to the preset data length to obtain the login password grouping list Y=(Y1, Y2,..., Y i ,..., Y n ); i = 1, 2,..., n; where n is the number of login password groups; Y i is the i-th group of password data after the login password is grouped.

[0031] Step a3, perform position permutation on Y according to the random permutation table corresponding to the current time to obtain the permuted password data list D=(D1, D2,..., D i ,..., D n ); where D i is the i-th group of permuted password data.

[0032] Step a4, perform exclusive OR operation on the secret key and D to obtain the encrypted password data E.

[0033] Step a5, send E to the server according to WebSocket.

[0034] This embodiment combines random permutation and XOR operation. While ensuring a certain level of security, it has a relatively small computational load and is suitable for lightweight application scenarios. The dynamic generation of the random permutation table increases the randomness of encryption, and the XOR operation is simple and efficient, without having a significant impact on the real-time interaction performance of the web-based shell terminal. At the same time, the generation of the key and the permutation table is related to the user identification and timestamp, further enhancing the security and uniqueness of encryption.

[0035] In an exemplary embodiment of the present application, step 300 further includes the following steps: Step b1, obtain a preset master key.

[0036] Here, the client and the server pre-share a super master key, and this key does not participate in network transmission. This design greatly reduces the risk of key leakage and constructs a solid security foundation for the entire encryption system. Because once the super master key is leaked, the entire encryption system will face a serious threat. Not transmitting it reduces the possibility of being intercepted, ensuring the initial security of encryption.

[0037] Step b2, splice the master key and the current timestamp according to the first hash algorithm to obtain a primary key.

[0038] Here, the client obtains a timestamp accurate to milliseconds for subsequent key generation. As time is constantly changing, the time factor relied on for each encryption is different, and the generated key also changes dynamically. This effectively prevents replay attacks. An attacker cannot use previously intercepted encrypted data and keys for another attempt because the key has become invalid with the change of time. By splicing the super master key with the timestamp and using a secure hash algorithm (such as SHA-512) to generate the primary key. This method utilizes the security of the super master key and the dynamics of the timestamp, providing a variable and secure basis for further generating more specific encryption keys in the subsequent process, making the initial key for each encryption process unique.

[0039] Step b3, use the primary key as a random number seed to obtain a first random permutation table; wherein, the length of the first random permutation table is the same as the length of the login password.

[0040] Step b4, perform a position permutation on the login password according to the first random permutation table to obtain a first permuted login password.

[0041] Using the primary key as a random number seed to generate a random permutation table and perform the first permutation on the password. This disrupts the original character order of the password. Even if an attacker intercepts the encrypted data, it is difficult to see the true characteristics and patterns of the password on the surface, increasing the confusion degree of the password and improving the cracking difficulty.

[0042] Step b5: Concatenate partial information of the primary key and the current timestamp according to the second hashing algorithm to obtain an intermediate key.

[0043] Generate an intermediate key by combining the primary key and partial information of the current timestamp (the last few digits of the current timestamp, as an example: the last 3 digits of the current timestamp), and then perform the first round of XOR encryption on the password after the first permutation. Generating the intermediate key with multiple factors increases the complexity of the key. The XOR operation itself has the characteristics of simplicity, efficiency, and reversibility. The first round of encryption further hides the password information, making the encrypted result more difficult to crack.

[0044] Step b6: Perform an XOR operation on the intermediate key and the first permuted login password to obtain the first encrypted login password.

[0045] Step b7: Obtain a high-level key based on the first encrypted login password, the intermediate key, and partial information of the current timestamp.

[0046] Derive a high-level key by combining the result of the first round of encryption, the intermediate key, and the first few digits of the timestamp, and then generate a new permutation table with the high-level key for the second round of permutation. Multiple rounds of permutation and generating the key with multiple factors make the structure of the encrypted data more complex, making it more difficult for attackers to analyze the encryption rules and the original password information.

[0047] Step b8: Use the high-level key as a random number seed to obtain a second random permutation table.

[0048] Step b9: Perform a position permutation on the login password according to the second random permutation table to obtain the second permuted login password.

[0049] Step b10: Concatenate the high-level key and partial information of the current timestamp according to the third hashing algorithm to obtain the target key.

[0050] Combine the high-level key and a new timestamp segment to generate the final key, and perform the second round of XOR encryption on the result after the second round of permutation. The generation of the final key takes more dynamic factors into account. Using XOR encryption again further enhances the encryption strength, making the finally encrypted password highly secure.

[0051] Step b11: Perform an XOR operation on the target key and the second permuted login password to obtain the encrypted login password; Step b12: Send the encrypted login password to the server.

[0052] Here, the timestamp, the first random permutation table, and the second random permutation table are also sent to the server.

[0053] The client encapsulates and sends the finally encrypted password, timestamp, and all permutation tables (after encoding). The timestamp can be used by the server to verify the timeliness of the data, and the permutation table can be inversely permuted on the server side to restore the password, ensuring the integrity and traceability of the data during transmission, which is convenient for the server to correctly decrypt and verify the password.

[0054] S400 receives and displays the execution result returned by the server.

[0055] In an exemplary embodiment of the present application, the webSocket connection is upgraded from an HTTP connection.

[0056] Specifically, the WebSocket connection is upgraded from the HTTP protocol. The client first sends a request with specific HTTP headers to the server, including the "Upgrade: websocket" and "Connection: Upgrade" header fields. This request informs the server that the client wishes to upgrade the connection from a normal HTTP connection to a WebSocket connection.

[0057] In an exemplary embodiment of the present application, when using WebSocket to establish a connection, data is transmitted in units of data frames.

[0058] Specifically, each frame has a fixed format, including a frame header and a frame data part. The frame header contains various information about the frame, such as the opcode (Opcode), whether it is the last frame, the mask bit, etc. The opcode is used to distinguish the type of message. For example, 0x01 represents a text message, and 0x02 represents a binary message. The mask bit is used to indicate whether the data sent by the client is masked.

[0059] When sending data, the data will be split into one or more frames for transmission. For small messages, only one frame may be needed. But for large messages, they will be divided into multiple frames, and the receiving party will reassemble these frames into a complete message according to the information in the frame header. For example, a simple text message may be sent in one frame, with the opcode in the frame header being 0x01, followed by the text content. While a larger binary data file will be divided into multiple frames, each frame with an opcode of 0x02, and the receiving party will splice these frames according to the information in the frame header to restore the original binary data.

[0060] In an exemplary embodiment of the present application, after connecting to the server through WebSocket, the method further includes: Sending a heartbeat detection message to the server at preset intervals and receiving the heartbeat detection message from the server; wherein, the heartbeat detection message is used to confirm whether the connection to the server is disconnected.

[0061] Specifically, in order to keep the WebSocket connection active and prevent the connection from being accidentally interrupted due to factors such as network fluctuations and firewalls, a heartbeat mechanism is usually adopted. The heartbeat mechanism means that the client and the server regularly send a very small message to each other to confirm that the connection is still valid.

[0062] It can be implemented through a scheduled task. For example, the client sends a heartbeat message every certain period (such as 30 seconds), and the server replies after receiving the heartbeat message. If the client does not receive a reply from the server within a certain period (such as 60 seconds), it is considered that there is a problem with the connection, and the client can try to reconnect.

[0063] In an exemplary embodiment of the present application, the above steps of identifying and processing the password input by the user further include the following steps: Obtain the key and the random permutation table sent by the server.

[0064] Specifically, when establishing a WebSocket connection, the server generates a random key K with a fixed length. At the same time, a random permutation table is generated according to the current time and the user identifier, and this permutation table is used to perform position permutation on the data. The generation rule of the permutation table is: randomly sort the numbers from 0 to the data length - 1. As an example: if the key data length is 8, the generated permutation table may be [3, 1, 7, 4, 0, 6, 2, 5].

[0065] According to a preset data length, group the password data to obtain a list of password data Y=(Y1, Y2,..., Y i ,..., Y n ); i = 1, 2,..., n; where n is the number of groups of password data; Y i is the i-th group of password data.

[0066] Specifically, the preset data length is determined according to the length of the frame data part in the sent data frame, and the maximum value of the preset data length cannot exceed the length of the frame data part; group the password data, and divide the password data into several groups according to the preset data length, where the last group of password data can be less than the preset data length; as an example: if the length of the frame data part is 8 bytes, the maximum value of the preset data length is 8 bytes; if the password data is 10, the password data is divided into two groups, the length of the first group of password data is 8 bytes, and the length of the second group of password data is 2 bytes.

[0067] In an exemplary embodiment of the present application, after sending a handshake request to the server once to establish a WebSocket connection, the method further includes: After establishing a connection using WebSocket, after a preset time, a heartbeat detection message is sent to the server, and a heartbeat message from the server is received to confirm that the connection to the server has not been disconnected; among them, sending the heartbeat detection message to the server is periodic.

[0068] Specifically, the heartbeat detection message is an empty message without data content, used to check whether the connection to the server is disconnected. Receiving the heartbeat detection information from the server means that the connection to the server has not been disconnected, and there is no need to process specific data content; the heartbeat detection message is sent periodically, and the sending period is the preset time; as an example: if the preset time is 3 seconds, the heartbeat detection message is sent every three seconds.

[0069] As Figure 2 shown, an embodiment of the present application provides a WebSocket-based user login device 100, and the device is applied to the client; the client has a corresponding server; the client is provided with a web version user login interface; the device includes: A connection unit 110, configured to connect to the server through WebSocket.

[0070] An acquisition unit 120, configured to acquire the login password from the user login interface.

[0071] An encryption unit 130, configured to encrypt the login password according to the key sent by the server and send the encrypted login password to the server; wherein, encrypting the login password includes random permutation and exclusive-or operation.

[0072] A receiving unit 140, configured to receive and display the execution result returned by the server.

[0073] In an exemplary embodiment of the present application, an electronic device capable of implementing the above method is also provided.

[0074] Those skilled in the art of the present application can understand that various aspects of the present application can be implemented as a system, a method, or a program product. Therefore, various aspects of the present application can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "system" here.

[0075] The electronic device according to this embodiment of the present application. The electronic device is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present application.

[0076] The electronic device is presented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: the at least one processor described above, the at least one memory described above, and a bus connecting different system components (including the memory and the processor).

[0077] Among them, the memory stores program code, and the program code can be executed by the processor, so that the processor executes the steps according to various exemplary embodiments of the present application described in the "Exemplary Method" section of this specification above.

[0078] The memory may include a readable medium in the form of a volatile memory, such as a random access memory (RAM) and / or a cache memory, and may further include a read-only memory (ROM).

[0079] The memory may also include a program / utility with a set (at least one) of program modules. Such program modules include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0080] The bus may represent one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any bus structure in a variety of bus structures.

[0081] The electronic device can also communicate with one or more external devices (such as a keyboard, a pointing device, a Bluetooth device, etc.), can also communicate with one or more devices that enable a user to interact with the electronic device, and / or communicate with any device that enables the electronic device to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface. And, the electronic device can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter. As shown in the figure, the network adapter communicates with other modules of the electronic device through the bus. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0082] Those skilled in the art can easily understand from the description of the above embodiments that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present application.

[0083] In an exemplary embodiment of the present application, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above method of this specification is stored. In some possible implementation manners, various aspects of the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary embodiments of the present application described in the above "Exemplary Method" section of this specification.

[0084] The program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0085] The computer-readable signal medium can include a data signal propagated in a baseband or as a part of a carrier wave, which carries the readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program used by or in combination with an instruction execution system, apparatus, or device.

[0086] The program code contained on the readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0087] The program code for performing the operations of the present application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or, alternatively, can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0088] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, rather than for restrictive purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.

[0089] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more of the above-described modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0090] The above are only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A user login method based on WebSocket, characterized in that The method is applied to a client; the client has a corresponding server; the client is provided with a web version user login interface; the method includes: Connect to the server via WebSocket; Obtain the login password from the user login interface; Encrypt the login password according to the key sent by the server, and send the encrypted login password to the server; wherein, encrypting the login password includes random permutation and exclusive-or operation; Receive and display the execution result returned by the server.

2. The WebSocket-based user login method according to claim 1, wherein Connecting to the server via WebSocket includes: Send a handshake request to the server once to establish a WebSocket connection; Obtain the WebSocket connection establishment response sent by the server.

3. The WebSocket-based user login method according to claim 1, wherein Obtaining the login password from the user login interface includes: Obtain the currently input characters of the user; If the currently input character is the character corresponding to the backspace key or the delete key, delete the previous input character of the currently input character; otherwise, determine that the currently input character is the character corresponding to the login password.

4. The WebSocket-based user login method according to claim 1, wherein Encrypting the login password according to the key sent by the server and sending the encrypted login password to the server includes: Obtain the key and the random permutation table sent by the server; wherein, the key is a random key of a fixed length; the random permutation table is generated according to the time stamp corresponding to the establishment of the WebSocket connection and the user behavior corresponding to the login password; the length of the random permutation table is the same as the length of the login password; Group the login password according to the preset data length to obtain a list of grouped login passwords Y = (Y1, Y2,..., Y i ,..., Y n ); i = 1, 2,..., n; where n is the number of groups of the grouped login password; Y i is the i-th group of password data corresponding to the grouped login password; According to the random permutation table corresponding to the current time, perform a position permutation on Y to obtain the permuted password data list D = (D1, D2, …, D i , …, D n ); where D i is the password data after the i-th group of permutations; Perform an exclusive-or operation on the key and D to obtain the encrypted password data E; Send E to the server according to WebSocket.

5. The WebSocket-based user login method according to claim 1, characterized in that, Encrypting the login password according to the key sent by the server and sending the encrypted login password to the server includes: Obtain the preset master key; Concatenate the master key and the current time stamp according to the first hash algorithm to obtain the primary key; Use the primary key as the random number seed to obtain the first random permutation table; wherein, the length of the first random permutation table is the same as the length of the login password; Perform position permutation on the login password according to the first random permutation table to obtain the first permuted login password; Concatenate the primary key and partial information of the current time stamp according to the second hash algorithm to obtain the intermediate key; Perform an exclusive-or operation on the intermediate key and the first permuted login password to obtain the first encrypted login password; Obtain the high-level key according to the first encrypted login password, the intermediate key and partial information of the current time stamp; Use the high-level key as the random number seed to obtain the second random permutation table; Perform position permutation on the login password according to the second random permutation table to obtain the second permuted login password; Concatenate the high-level key and partial information of the current time stamp according to the third hash algorithm to obtain the target key; Perform an exclusive-or operation on the target key and the second permuted login password to obtain the encrypted login password; Send the encrypted login password to the server.

6. The WebSocket-based user login method according to claim 5, wherein The method further includes: sending the time stamp, the first random permutation table and the second random permutation table to the server.

7. The WebSocket-based user login method according to claim 2, wherein The method further includes: Send an HTTP upgrade request to the server to upgrade the HTTP connection to a WebSocket connection.

8. The WebSocket-based user login method according to claim 2, characterized in that, The method further includes: When establishing a connection using WebSocket, data is transmitted in units of data frames.

9. The WebSocket-based user login method according to claim 2, characterized in that After connecting to the server via WebSocket, the method further includes: Sending a heartbeat detection message to the server at preset time intervals and receiving a heartbeat detection message from the server; wherein, the heartbeat detection message is used to confirm whether the connection to the server is disconnected.

10. A user login device based on WebSocket, characterized in that, The device is applied to a client; the client has a corresponding server; the client is provided with a web version user login interface; the device includes: A connection unit for connecting to the server via WebSocket; An acquisition unit for acquiring the login password from the user login interface; An encryption unit for encrypting the login password according to the key sent by the server and sending the encrypted login password to the server; wherein, encrypting the login password includes random permutation and exclusive OR operation; A receiving unit for receiving and displaying the execution result returned by the server.

Citation Information

Patent Citations

  • System for encrypting and decrypting a plaintext message with authentication

    CN102687457A

  • Information transmission method and device based on WEB simulation terminal system

    CN105812406A

  • Data encryption method and device

    CN106921486A

  • Data processing method and system based on Websocket long connection

    CN109561159A

  • Method and device for establishing long connection between client and server and communication method and device

    CN112202792A