Dynamic password setting method and device, dynamic password verification method and device and electronic equipment
Through the dynamic password setting method based on usage rules, users can customize multiple rules to generate personalized passwords, solving the problems of low static password security and vulnerability to dynamic passwords, and realizing dynamic password management with high security and simple operation.
Patent Information
- Application Number
- CN202510421324.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-22
AI Technical Summary
Existing static passwords are low in security and easy to leak. Dynamic password dependency password generators are vulnerable to attacks and complex operations, making it difficult to meet personalized needs.
Through a dynamic password setting method based on usage rules, users are allowed to select multiple data generation, processing and splicing rules to generate personalized dynamic passwords without the need for a password generator.
It improves information security, simplifies operational processes, enhances attack resistance, adapts to different user needs, and realizes personalized security management.
Smart Images

Figure CN120354402A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a method for setting dynamic passwords, a verification method, a device, and an electronic device. Background Art
[0002] In current information security technologies, there are mainly two types of passwords: static passwords and dynamic passwords. Each of them has its own advantages and disadvantages, but there are significant differences in terms of security and manageability.
[0003] Static passwords have some obvious drawbacks. First of all, their security is relatively low and they are easily vulnerable to attackers' guessing or brute force cracking. Secondly, many people tend to use the same password on multiple platforms, which means that once the password of a certain platform is leaked, the accounts of other platforms will also be at risk. In addition, static passwords lack dynamic protection, resulting in difficulties for users to remember complex passwords, and thus they may choose to use simpler and less secure passwords.
[0004] In contrast, dynamic passwords provide a more flexible security mechanism, and such passwords usually rely on password generators. Although dynamic passwords can improve security to a certain extent, they also bring new challenges. For example, once the password generator fails or is attacked, the entire authentication mechanism will be affected. In addition, users need to input dynamic passwords in real time, which increases the complexity of operations. Dynamic passwords usually also have time limits, and if users fail to use these passwords within the specified time, they may face the risk of expiration. Moreover, if the transmission process between the generator and the terminal is not secure enough, dynamic passwords may still be intercepted, causing potential security hazards. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to address the above-mentioned deficiencies of the prior art and propose a method for setting dynamic passwords, a verification method, a device, and an electronic device based on usage rules. This method for setting dynamic passwords does not require a password generator, can not only improve information security, but also meet the needs of different users and achieve personalized security management.
[0006] In a first aspect, the present invention provides a method for setting dynamic passwords based on usage rules, which is applied to a terminal. The method includes the following steps:
[0007] Respond to a user's password setting request and generate a password setting rule selection interface;
[0008] Obtain the target rule selected by the user in the password setting rule selection interface;
[0009] Among them, the target rule includes a separate first data generation rule, or a rule combining the first data generation rule and the second data generation rule, or a rule combining the first data generation rule, the second data generation rule, and the third data generation rule; the first data generation rule is a rule for directly generating a first dynamic password from a data source, the second data generation rule is a rule for processing or converting the first dynamic password to obtain a second dynamic password, and the third data generation rule is a rule for concatenating the first dynamic password and the second dynamic password to generate a third dynamic password;
[0010] Generate a password setting interface for guiding the user to input according to the target rule;
[0011] Among them, the password setting interface includes a user input box and a verification box. The verification box includes initial data and a verification rule generated according to the target rule. The user input box is used for the user to input a first content, and the first content is the final data formed by the user modifying the initial data according to the verification rule;
[0012] Set the first content as the target dynamic password to complete the dynamic password setting based on the usage rule.
[0013] Further, after setting the first content as the target dynamic password, the method further includes:
[0014] Send the target dynamic password to the server database for storage.
[0015] Further, setting the first content as the target dynamic password specifically includes:
[0016] If the target rule selected by the user in the selection interface is a separate first data generation rule, then use the first password data generated based on the first content according to the first data generation rule as the target dynamic password; or,
[0017] If the target rule selected by the user in the selection interface is a rule combining the first data generation rule and the second data generation rule, then first generate first password data based on the first content according to the first data generation rule, and then process or convert the first password data to obtain the target dynamic password;
[0018] If the target rule selected by the user in the selection interface is a rule combining the first data generation rule, the second data generation rule, and the third data generation rule, then first generate first password data based on the first content according to the first data generation rule, then process or convert the first password data to obtain second password data, and then concatenate the first password data and the second password data to generate the target dynamic password.
[0019] Furthermore, the steps for obtaining the first password data specifically include:
[0020] Obtain the n-digit number corresponding to the current date at a specific longitude and latitude of the user, that is, obtain the first password data, where n is a natural number greater than 1 and less than or equal to 8; or, obtain the corresponding financial data from a financial data provider through the API, that is, obtain the first password data;
[0021] The processing or conversion of the first password data specifically includes:
[0022] Intercept the digit positions in the first password data; or,
[0023] Multiply the numbers in the first password data by a specified number; or,
[0024] Add a specified number to the numbers in the first password data; or,
[0025] Map the numbers in the first password data to lowercase letters in alphabetical order;
[0026] Map the numbers in the first password data to uppercase letters in alphabetical order;
[0027] The splicing of the first password data and the second password data specifically includes:
[0028] Chain-splice the first password data and the second password data through a preset format and delimiter.
[0029] In a second aspect, the present invention provides a dynamic password verification method implemented based on usage rules, which is applied to a terminal. The method includes the following steps:
[0030] Receive the second content input by the user;
[0031] In response to the second content, send the user's password verification request to the server, so that the server feedbacks a preset dynamic password from the server database;
[0032] Wherein, the preset dynamic password is pre-set according to the dynamic password setting method implemented based on usage rules described in the first aspect;
[0033] Convert the preset dynamic password into a corresponding verification password string;
[0034] Compare the verification password string with the second content:
[0035] If the verification password string is different from the second content, it is confirmed that the dynamic password verification fails; if the verification password string is the same as the second content, it is confirmed that the dynamic password verification passes, thus completing the dynamic password verification implemented based on the usage rules.
[0036] In a third aspect, the present invention provides a dynamic password setting device implemented based on usage rules, which is applied to a terminal. The device includes:
[0037] A first generation unit, configured to generate a password setting rule selection interface in response to a user's password setting request;
[0038] An acquisition unit, connected to the first generation unit, configured to acquire a target rule selected by the user in the password setting rule selection interface;
[0039] Wherein, the target rule includes a separate first data generation rule, or a rule combining the first data generation rule and the second data generation rule, or a rule combining the first data generation rule, the second data generation rule, and the third data generation rule; the first data generation rule is a rule for directly generating a first dynamic password from a data source, the second data generation rule is a rule for processing or converting the first dynamic password to obtain a second dynamic password, and the third data generation rule is a rule for splicing the first dynamic password and the second dynamic password to generate a third dynamic password;
[0040] A second generation unit, connected to the acquisition unit, configured to generate a password setting interface for guiding the user to input according to the target rule;
[0041] Wherein, the password setting interface includes a user input box and a verification box. The verification box includes initial data and a verification rule generated according to the target rule. The user input box is used for the user to input a first content, and the first content is the final data formed by the user modifying the initial data according to the verification rule;
[0042] A setting unit, connected to the second generation unit, configured to set the first content as the target dynamic password to complete the dynamic password setting implemented based on the usage rules.
[0043] Further, the device further includes a first sending unit;
[0044] The first sending unit is connected to the setting unit and is configured to send the target dynamic password to the server database for storage.
[0045] Further, the setting unit includes:
[0046] The first setting module, connected to the second generating unit, is configured to use, as the target dynamic password, the first password data generated based on the first content according to the first data generation rule when the target rule selected by the user in the selection interface is a separate first data generation rule;
[0047] The second setting module, connected to the second generating unit, is configured to, when the target rule selected by the user in the selection interface is a rule combining the first data generation rule and the second data generation rule, first generate first password data based on the first content according to the first data generation rule, and then process or transform the first password data to obtain the target dynamic password;
[0048] The third setting module, connected to the second generating unit, is configured to, when the target rule selected by the user in the selection interface is a rule combining the first data generation rule, the second data generation rule, and the third data generation rule, first generate first password data based on the first content according to the first data generation rule, then process or transform the first password data to obtain second password data, and then splice the first password data and the second password data to generate the target dynamic password.
[0049] Fourthly, the present invention provides a dynamic password verification device implemented based on usage rules, which is applied to a terminal. The device includes:
[0050] A receiving unit, configured to receive a second content input by the user;
[0051] A second sending unit, connected to the receiving unit, is configured to, in response to the second content, send the user's password verification request to a server, so that the server feeds back a preset dynamic password from a server database;
[0052] Wherein, the preset dynamic password is obtained by using the dynamic password setting device implemented based on usage rules described in the third aspect;
[0053] A conversion unit, configured to, after receiving the preset dynamic password from the server database, convert the preset dynamic password into a corresponding verification password string;
[0054] A comparison unit, connected to the conversion unit, is configured to compare the verification password string with the second content;
[0055] A verification unit, connected to the comparison unit, is configured to confirm that the dynamic password verification fails when the result of the comparison by the comparison unit is that the verification password string is different from the second content; and is further configured to confirm that the dynamic password verification passes when the result of the comparison by the comparison unit is that the verification password string is the same as the second content, thereby completing the dynamic password verification implemented based on usage rules.
[0056] In a fifth aspect, the present invention provides an electronic device, which includes a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the dynamic password setting method implemented based on the usage rules according to the first aspect, or executes the dynamic password verification method implemented based on the usage rules according to the second aspect.
[0057] Through flexible dynamic password generation rules and diverse setting methods, the present invention can improve information security and meet the needs of different users to achieve personalized security management without a password generator. The specific beneficial effects are as follows:
[0058] 1. High flexibility and personalized customization:
[0059] The present invention allows users to freely select a suitable dynamic password generation method from multiple rule combinations according to their own needs, preferences, and usage habits. Whether using a single data generation rule alone or combining multiple rules, personalized customization of dynamic passwords can be achieved to meet diverse security needs.
[0060] 2. Multi-level security and anti-attack ability:
[0061] The present invention combines different data generation, processing conversion, and splicing rules to generate complex and unpredictable dynamic passwords, thereby significantly enhancing the confidentiality and anti-attack ability of passwords.
[0062] 3. Simplified operation and improved user experience:
[0063] The present invention provides an intuitive password setting rule selection interface and a password setting interface, enabling users to easily understand and operate the dynamic password setting process. Users can quickly complete the setting without going through complex steps or having professional knowledge, significantly reducing the complexity during use and improving the overall user experience.
[0064] 4. Wide adaptability and efficient management:
[0065] The present invention is applicable to various terminal devices and operating systems. Whether it is a mobile phone, tablet, or computer, the dynamic password setting and use can be efficiently achieved. In addition, clear rule definitions and operation processes are provided for system administrators and developers, making the management and maintenance of dynamic passwords simpler and more efficient.
[0066] 5. Real-time generation, verification, and intelligent processing:
[0067] The real-time generation and processing function of the dynamic password in the present invention enhances security. Users only need to input the latest generated password during actual operations, effectively reducing the risks of theft and replay attacks. At the same time, combined with intelligent data processing, it reduces human intervention and improves the automation degree of password generation.
[0068] 6. Powerful audit monitoring and user participation:
[0069] The present invention allows for the detailed recording and analysis of the entire process of dynamic password generation and use, facilitating subsequent audits and anomaly monitoring to promptly identify potential security threats. In addition, by enabling users to participate in the selection of password setting rules, it enhances their proactive awareness of their own security management and improves the overall security prevention ability. Description of the Drawings
[0070] Figure 1 Schematic diagram of the dynamic password setting method implemented based on usage rules in the embodiment of the present invention;
[0071] Figure 2 Flowchart of the dynamic password setting implemented based on usage rules in the embodiment of the present invention;
[0072] Figure 3 Flowchart of the dynamic password verification implemented based on usage rules in the embodiment of the present invention;
[0073] Figure 4 Schematic diagram of the dynamic password setting device implemented based on usage rules in the embodiment of the present invention;
[0074] Figure 5 Schematic diagram of the dynamic password verification device implemented based on usage rules in the embodiment of the present invention;
[0075] Figure 6 Architecture diagram of the electronic device in the embodiment of the present invention.
[0076] Reference numerals: 10, first generation unit; 20, acquisition unit; 30, second generation unit; 40, setting unit; 50, receiving unit; 60, second sending unit; 70, conversion unit; 80, comparison unit; 90, verification unit; 100, processor; 200, memory. Detailed Embodiments
[0077] To enable those skilled in the art to better understand the technical solutions of the present invention, the embodiments of the present invention will be further described in detail below in conjunction with the accompanying drawings.
[0078] It can be understood that the specific embodiments and drawings described herein are only for explaining the present invention and are not intended to limit the present invention.
[0079] It is understood that, without conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.
[0080] It is understood that, for ease of description, only the parts related to the present invention are shown in the drawings of the present invention, and the parts unrelated to the present invention are not shown in the drawings.
[0081] It is understood that each unit and module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures. Alternatively, multiple units and modules may also be integrated into one entity structure.
[0082] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in an order different from that marked in the drawings.
[0083] It is understood that in the flowcharts and block diagrams of the present invention, the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the embodiments of the present invention are shown. Among them, each block in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified function. Moreover, each block or combination of blocks in the block diagram and flowchart may be implemented by a hardware-based system for implementing the specified function, or may be implemented by a combination of hardware and computer instructions.
[0084] It is understood that the units and modules involved in the embodiments of the present invention may be implemented in software or in hardware. For example, the units and modules may be located in the processor.
[0085] Embodiment 1:
[0086] As Figure 1 shown, this embodiment provides a dynamic password setting method implemented based on usage rules. This method is applicable to user authentication scenarios that require high security, such as online banking, e-commerce platforms, enterprise internal systems, and cloud services. In these scenarios, users can select and customize dynamic password generation rules according to their own needs, so as to find the best balance between convenience and security and effectively prevent account theft or information leakage. When this method is applied to a terminal, it specifically includes the following steps:
[0087] 1. Respond to the user's password setting request and generate a password setting rule selection interface.
[0088] When the terminal receives the user's password setting request, it will quickly respond and pop up a carefully designed password setting rule selection interface. This interface clearly shows a variety of different password setting rule options.
[0089] 2. Obtain the target rule selected by the user in the password setting rule selection interface. The target rule includes a separate first data generation rule, or a rule combining the first data generation rule and the second data generation rule, or a rule combining the first data generation rule, the second data generation rule, and the third data generation rule; the first data generation rule is a rule for directly generating a first dynamic password from a data source, the second data generation rule is a rule for processing or converting the first dynamic password to obtain a second dynamic password, and the third data generation rule is a rule for concatenating the first dynamic password and the second dynamic password to generate a third dynamic password.
[0090] 3. Generate a password setting interface for guiding the user to input according to the target rule; the password setting interface includes a user input box and a verification box, and the verification box includes initial data and verification rules generated according to the target rule. The user input box is used for the user to input a first content, and the first content is the final data formed by the user modifying the initial data according to the verification rules.
[0091] Generate a password setting interface according to the target rule to guide the user to complete the input and setting of the password. The interface design is intuitive and fully functional, mainly including a user input box and a verification box. In the verification box, initial data is pre-generated according to the target rule, and the corresponding verification rules are clarified. The user input box is specifically set for the user to input the first content, which needs to be formed by the user modifying the initial data according to the verification rules. It represents the password data finally set by the user, which not only reflects the user's personalized needs but also meets the system's requirements for password security.
[0092] 4. Obtain the first content of the user in the password setting interface, and set the first content of the user in the password setting interface as the target dynamic password to complete the dynamic password setting based on the usage rule.
[0093] The setting of the first content as the target dynamic password specifically includes:
[0094] If the target rule selected by the user in the selection interface is a separate first data generation rule, then use the first password data generated based on the first content according to the first data generation rule as the target dynamic password; or,
[0095] If the target rule selected by the user in the selection interface is a rule combining the first data generation rule and the second data generation rule, then first generate the first password data based on the first content according to the first data generation rule, and then process or convert the first password data to obtain the target dynamic password;
[0096] If the target rule selected by the user in the selection interface is a rule that combines the first data generation rule, the second data generation rule, and the third data generation rule, then first, based on the first content, generate the first password data according to the first data generation rule, and then process or transform the first password data to obtain the second password data, and then splice the first password data and the second password data to generate the target dynamic password.
[0097] As a specific implementation manner, the step of obtaining the first password data includes:
[0098] Obtain the n-digit number corresponding to the current date of a specific longitude and latitude of the user, that is, obtain the first password data, where n is a natural number greater than 1 and less than or equal to 8; or, obtain the corresponding financial data from a financial data provider through the API, that is, obtain the first password data;
[0099] The processing or transformation of the first password data specifically includes:
[0100] Intercept the digital digits in the first password data; or,
[0101] Multiply the numbers in the first password data by a specified number; or,
[0102] Add a specified number to the numbers in the first password data; or,
[0103] Map the numbers in the first password data to lowercase letters in alphabetical order;
[0104] Map the numbers in the first password data to uppercase letters in alphabetical order;
[0105] The splicing of the first password data and the second password data specifically includes:
[0106] Chain-splice the first password data and the second password data through a preset format and delimiter.
[0107] 5. Send the target dynamic password to the server database for storage.
[0108] When the terminal receives a password setting request from the user, it will quickly pop up a well-designed password setting rule selection interface, displaying multiple password setting rule options, including a separate first data generation rule or options combined with other rules. After the user selects the target rule, a password setting interface that guides the user to input will be generated, including a user input box and a verification box, and the verification box will display the verification value generated according to the target rule. After the user enters content in the password setting interface, the system will use this input as the target dynamic password and generate the final password according to the rule selected by the user; if the selected is the separate first data generation rule, the first password data will be directly generated through the data source; if the combined rule is selected, the first password data will be generated first, and then processed or spliced to form the target dynamic password. Finally, the generated dynamic password will be sent to the server database for storage. The following details the detailed process and related examples of this implementation:
[0109] The basic principle of this embodiment is that the dynamic password consists of a static string and a rule part. The static string refers to the fixed content composed of numbers, letters, punctuation marks, etc.; the rule part is further divided into a data source rule and a conversion rule. The data source rule determines numbers according to the system or external data at any time, such as the current date in the East Eighth District (generating 8 digits, such as 20241025), the current time (generating 4 digits, such as 1421), or external data (such as the closing value of the Shanghai Composite Index yesterday, 3280.26, converted to 328026); the conversion rule further processes the numbers generated by the data source, such as intercepting the last few digits (for example, rule4-2 intercepts 1234 as 34), multiplying the number by a specified value (for example, rule5-2 multiplies 1234 by 2 to become 2468), adding a specified value to the number (for example, rule6-3 adds 3 to 1234 to get 1237), and mapping the number to a letter (rule7 maps the number to a lowercase letter, such as 13 mapped to m, while rule8 maps to an uppercase letter, such as 13 mapped to M). When the user registers or modifies the password, the dynamic password is defined by freely combining the static string with the rule (in the format of "${rule}" or "${rule1|rule4-2}", etc.). What the system saves is the dynamic password expression, and when verifying, it will calculate the verification password in combination with the current real-time data and then compare it with the verification password entered by the user.
[0110] Such as Figure 2As shown in the figure, this method mainly includes three links: rule presetting, password setting, and password saving. First, various rules are preset on the server side. Data source rules such as rule1 (8-digit number of the current date in the East Eighth Time Zone), rule2 (4-digit number of the current time in the East Eighth Time Zone), rule3 (converting the closing index of the Shanghai Composite Index yesterday into a number); conversion rules such as rule4 (intercepting the last few digits, e.g., rule4-2 intercepts the last two digits), rule5 (multiplying the number by a specified value, e.g., rule5-2 multiplies by 2), rule6 (adding a specified value to the number, e.g., rule6-3 adds 3), rule7 (mapping the number to lowercase letters), and rule8 (mapping the number to uppercase letters). When implementing, developers can write corresponding code in programming languages. The data source rules directly obtain the system time or external data, and the conversion rules process the incoming values. Secondly, when a user registers or modifies the password on the client side, the system displays all the rules and usage instructions through the page. The user can either enter pure static text or embed rules in it. For example, enter "ds${rule2}wz23te?@". If the current time is 14:21, then rule2 returns 1421, generating the verification password "ds1421wz23te?@"; another example is to enter "ds${rule1|rule4-2}wz23te?@". When the date is October 25, 2024, rule1 returns 20241025, and after being intercepted by rule4-2 for the last two digits, it gets 25, generating "ds25wz23te?@"; another example is to enter "ds${rule2|rule6-3|rule4-2|rule7}wz23te?@". When the current time is 14:21, rule2 returns 1421, adding 3 by rule6-3 to get 1424, intercepting the last two digits by rule4-2 to get 24, and assuming mapping by rule7 to get the lowercase letter x, generating "dsxwz23te?@". The system provides a real-time preview function to facilitate the user to confirm the setting effect. Finally, after the user confirms the password setting, the system saves the dynamic password expression (such as "ds${rule2}wz23te?@") to the database for subsequent verification.
[0111] Figure 2 Describes the setting process of the dynamic password, specifically including the following steps:
[0112] S1, Obtain the preset rules:
[0113] The user or the system obtains the preset rules from the server, and these rules define how to generate a part of the dynamic password. The rules include data source rules and conversion rules, such as time, date, specific events (such as stock index), etc.
[0114] S2, Display the rules and the dynamic password splicing specification:
[0115] On the account registration and password modification pages, display the available rules to users and show them how to use these rules to concatenate dynamic passwords. Users can directly enter static text or insert data source rules by inserting specific formats (such as "${}").
[0116] S3. Set the dynamic password:
[0117] Based on the displayed rules, users set their own dynamic passwords in the input box. If rules are used, the system will preview the converted verification password in real time.
[0118] S4. Save the dynamic password to the database:
[0119] After the user sets and saves the dynamic password, the system stores the corresponding string of the dynamic password in the database for use during password verification.
[0120] As Figure 3 shown, the verification process occurs when the user logs in or performs sensitive operations. First, the client recalculates the verification password based on the saved dynamic password expression and the current real-time data. For example, if the user sets "ds${rule2}wz23te?@" and logs in at 14:21, the client converts it to "ds1421wz23te?@" and enters it. Then, the verification password entered by the user is sent to the server via the network. The server reads the dynamic password expression saved for this user and, based on the current time, date, or other external data, gradually converts and concatenates it according to the set rules to generate the expected verification password string. Finally, the server compares the calculated result with the password sent by the client. If they are the same, the verification is successful; otherwise, it fails, and the verification result is fed back to the client.
[0121] Specific example: Assume that the following three dynamic passwords are set when the user registers. Example 1: Dynamic password expression "ds${rule2}wz23te?@". When the user logs in, if the current time is 14:21, rule2 returns 1421, and generates the verification password "ds1421wz23te?@"; the client calculates and transmits this password, and the server also uses the current time to calculate "ds1421wz23te?@", and the verification is passed after the comparison is consistent. Example 2: Dynamic password expression "ds${rule1|rule4-2}wz23te?@". When the date is October 25, 2024, rule1 returns 20241025, and the last two digits "25" are processed by rule4-2, generating "ds25wz23te?@"; both parties use the current date to generate the verification password and successfully verify. Example 3: Dynamic password expression "ds${rule2|rule6-3|rule4-2|rule7}wz23te?@". The parsing process is: rule2 returns the current time "1421", rule6-3 adds 3 to get "1424", rule4-2 intercepts the last two digits to get "24", and rule7 maps (assuming the mapping result is x) to generate "dsxwz23te?@". The client and server both generate the same verification password and the verification is successful.
[0122] The dynamic password setting method presets data source rules and conversion rules, allowing users to customize a set of password expressions that combine static strings and dynamic real-time data when registering or modifying passwords; while the verification method uses current real-time data to convert the saved dynamic password during login or key operations, generates an instant verification password, and determines the verification result after comparing it with the client input result. This method is suitable for scenarios that require high security and do not want passwords to remain static for a long time, such as online banking, e-commerce platforms, and key enterprise systems. Even if an attacker obtains the password expression, it is difficult to forge the correct verification password, which can greatly improve security.
[0123] Embodiment 2:
[0124] This embodiment provides a dynamic password verification method based on usage rules, which is applied to a terminal. The method includes the following steps:
[0125] receiving second content input by a user;
[0126] In response to the second content, a password verification request for the user is sent to the server, so that the server feeds back a preset dynamic password from a server database;
[0127] The preset dynamic password is preset according to the dynamic password setting method based on the usage rule described in Example 1;
[0128] Convert the preset dynamic password into a corresponding verification password string;
[0129] Compare the verification password string with the second content:
[0130] If the verification password string is different from the second content, it is confirmed that the dynamic password verification fails; if the verification password string is the same as the second content, it is confirmed that the dynamic password verification passes, thus completing the dynamic password verification based on the usage rules.
[0131] Figure 3 Describes the verification process of the dynamic password, and the specific steps are as follows:
[0132] K1, Input password:
[0133] The user calculates the verification password string corresponding to the current moment according to the rules defined during password setting on the client and enters it into the input box.
[0134] K2, Send to the server:
[0135] When the user clicks the login or verify password operation, the entered verification password string is sent to the server.
[0136] K3, Read the corresponding dynamic password:
[0137] The server reads the dynamic password saved by the user in the database according to the user information.
[0138] K4, Verify the password:
[0139] The server converts the dynamic password saved by the user into the verification password string corresponding to the current moment according to the rules and compares it with the verification password string entered by the user. If they are the same, the password is verified as correct; if they are different, the password is verified as incorrect.
[0140] K5, Return the verification result:
[0141] The server returns the verification result to the client.
[0142] Embodiment 3:
[0143] As Figure 4 shown, this embodiment provides a dynamic password setting device based on usage rules, which is applied to a terminal. The device includes:
[0144] The first generation unit 10 is used to generate a password setting rule selection interface in response to the user's password setting request;
[0145] An obtaining unit 20, connected to the first generating unit 10, is configured to obtain a target rule selected by a user in a password setting rule selection interface;
[0146] Wherein, the target rule includes a separate first data generation rule, or a rule combining the first data generation rule and the second data generation rule, or a rule combining the first data generation rule, the second data generation rule, and the third data generation rule; the first data generation rule is a rule for directly generating a first dynamic password from a data source, the second data generation rule is a rule for processing or converting the first dynamic password to obtain a second dynamic password, and the third data generation rule is a rule for splicing the first dynamic password and the second dynamic password to generate a third dynamic password;
[0147] A second generating unit 30, connected to the obtaining unit 20, is configured to generate a password setting interface for guiding a user to input according to the target rule;
[0148] Wherein, the password setting interface includes a user input box and a verification box, the user input box is configured to display a user input value, and the verification box is configured to display a verification value generated according to the user input value and the target rule;
[0149] A setting unit 40, connected to the second generating unit 30, is configured to set the first content as a target dynamic password to complete the dynamic password setting implemented based on a usage rule.
[0150] As a specific implementation manner, the device further includes a first sending unit;
[0151] The first sending unit is connected to the setting unit and is configured to send the target dynamic password to a server database for storage.
[0152] As a specific implementation manner, the setting unit 40 includes:
[0153] A first setting module, connected to the second generating unit, is configured to, when the target rule selected by the user in the selection interface is a separate first data generation rule, use first password data generated based on the first content according to the first data generation rule as the target dynamic password;
[0154] A second setting module, connected to the second generating unit, is configured to, when the target rule selected by the user in the selection interface is a rule combining the first data generation rule and the second data generation rule, first generate first password data based on the first content according to the first data generation rule, and then process or convert the first password data to obtain the target dynamic password;
[0155] The third setting module, connected to the second generating unit, is configured to, when the target rule selected by the user in the selection interface is a rule that combines the first data generation rule, the second data generation rule, and the third data generation rule, first generate first password data based on the first content according to the first data generation rule, then process or transform the first password data to obtain second password data, and then splice the first password data and the second password data to generate the target dynamic password.
[0156] The device in this embodiment can execute the method in Embodiment 1.
[0157] Embodiment 4:
[0158] As Figure 5 shown, this embodiment provides a dynamic password verification device implemented based on usage rules, which is applied to a terminal. The device includes:
[0159] A receiving unit 50, configured to receive a second content input by a user;
[0160] A second sending unit 60, connected to the receiving unit 50, is configured to, in response to the second content, send the user's password verification request to a server, so that the server feeds back a preset dynamic password from a server database;
[0161] Wherein, the preset dynamic password is obtained by using the dynamic password setting device implemented based on usage rules described in Embodiment 3;
[0162] A conversion unit 70, configured to, after receiving the preset dynamic password in the server database, convert the preset dynamic password into a corresponding verification password string;
[0163] A comparison unit 80, connected to the conversion unit 70, is configured to compare the verification password string with the second content;
[0164] A verification unit 90, connected to the comparison unit 80, is configured to confirm that the dynamic password verification fails when the result of the comparison by the comparison unit is that the verification password string is different from the second content; and is also configured to confirm that the dynamic password verification passes when the result of the comparison by the comparison unit is that the verification password string is the same as the second content, thereby completing the dynamic password verification implemented based on usage rules.
[0165] Embodiment 5:
[0166] As Figure 6As shown in the figure, the present invention provides an electronic device, which includes a memory 200 and a processor 100. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the dynamic password setting method implemented based on the usage rules according to Embodiment 1, or executes the dynamic password verification method implemented based on the usage rules according to Embodiment 2.
[0167] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principle of the present invention. However, the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.
Claims
1. A dynamic password setting method implemented based on usage rules, applied to a terminal, characterized in that The method includes the following steps: Respond to the user's password setting request and generate a password setting rule selection interface; Obtain the target rule selected by the user in the password setting rule selection interface; Wherein, the target rule includes a separate first data generation rule, or a rule combining the first data generation rule and the second data generation rule, or a rule combining the first data generation rule, the second data generation rule, and the third data generation rule; the first data generation rule is a rule for directly generating a first dynamic password from a data source, the second data generation rule is a rule for processing or converting the first dynamic password to obtain a second dynamic password, and the third data generation rule is a rule for splicing the first dynamic password and the second dynamic password to generate a third dynamic password; Generate a password setting interface for guiding the user to input according to the target rule; Wherein, the password setting interface includes a user input box and a verification box, the verification box includes initial data and a verification rule generated according to the target rule, and the user input box is used for the user to input a first content, and the first content is the final data formed by the user modifying the initial data according to the verification rule; Set the first content as the target dynamic password to complete the dynamic password setting based on the usage rule.
2. The method for implementing dynamic password setting based on usage rules according to claim 1, characterized in that, After setting the first content as the target dynamic password, the method further includes: Send the target dynamic password to the server database for storage.
3. The method for implementing dynamic password setting based on usage rules according to claim 1, characterized in that, Setting the first content as the target dynamic password specifically includes: If the target rule selected by the user in the selection interface is a separate first data generation rule, then use the first password data generated based on the first content according to the first data generation rule as the target dynamic password; or, If the target rule selected by the user in the selection interface is a rule combining the first data generation rule and the second data generation rule, then first generate the first password data based on the first content according to the first data generation rule, and then process or convert the first password data to obtain the target dynamic password; If the target rule selected by the user in the selection interface is a rule combining the first data generation rule, the second data generation rule, and the third data generation rule, then first generate the first password data based on the first content according to the first data generation rule, then process or convert the first password data to obtain the second password data, and then splice the first password data and the second password data to generate the target dynamic password.
4. The method for implementing dynamic password setting based on usage rules according to claim 3, characterized in that, The specific steps for obtaining the first password data include: Obtain the n - digit number corresponding to the current date at a specific longitude and latitude of the user, that is, obtain the first password data, where n is a natural number greater than 1 and less than or equal to 8; or, obtain the corresponding financial data from a financial data provider through an API, that is, obtain the first password data; The processing or conversion of the first password data specifically includes: Intercepting the digital digits in the first password data; or, Multiplying the numbers in the first password data by a specified number; or, Adding a specified number to the numbers in the first password data; or, Mapping the numbers in the first password data to lowercase letters in alphabetical order; Mapping the numbers in the first password data to uppercase letters in alphabetical order; The splicing of the first password data and the second password data specifically includes: Chain - splicing the first password data and the second password data through a preset format and delimiter.
5. A dynamic password verification method implemented based on usage rules, applied to a terminal, characterized in that, The method includes the following steps: Receive the second content input by the user; In response to the second content, send the user's password verification request to the server, so that the server feedbacks a preset dynamic password from the server database; Among them, the preset dynamic password is preset according to the dynamic password setting method based on usage rules described in any one of claims 1 to 4; Convert the preset dynamic password into a corresponding verification password string; Compare the verification password string with the second content: If the verification password string is different from the second content, it is confirmed that the dynamic password verification fails; if the verification password string is the same as the second content, it is confirmed that the dynamic password verification passes, thus completing the dynamic password verification based on usage rules.
6. A dynamic password setting device implemented based on usage rules, applied to a terminal, characterized in that, It includes: A first generation unit, configured to generate a password setting rule selection interface in response to the user's password setting request; An acquisition unit, connected to the first generation unit, configured to acquire the target rule selected by the user in the password setting rule selection interface; Among them, the target rule includes a separate first data generation rule, or a rule combining the first data generation rule and the second data generation rule, or a rule combining the first data generation rule, the second data generation rule, and the third data generation rule; the first data generation rule is a rule for directly generating the first dynamic password from a data source, the second data generation rule is a rule for processing or converting the first dynamic password to obtain the second dynamic password, and the third data generation rule is a rule for splicing the first dynamic password and the second dynamic password to generate the third dynamic password; A second generation unit, connected to the acquisition unit, configured to generate a password setting interface for guiding the user to input according to the target rule; Among them, the password setting interface includes a user input box and a verification box, the verification box includes initial data and a verification rule generated according to the target rule, and the user input box is used for the user to input the first content, and the first content is the final data formed by the user modifying the initial data according to the verification rule; A setting unit, connected to the second generating unit, for setting the first content as a target dynamic password to complete the dynamic password setting implemented based on the usage rule.
7. The dynamic password setting device implemented based on the usage rule according to claim 6, wherein The device further includes a first sending unit; The first sending unit is connected to the setting unit, and is used for sending the target dynamic password to the server database for storage.
8. The dynamic password setting device implemented based on the usage rule according to claim 6, wherein The setting unit includes: A first setting module, connected to the second generating unit, for using the first password data generated based on the first content according to the first data generation rule as the target dynamic password when the target rule selected by the user in the selection interface is a separate first data generation rule; A second setting module, connected to the second generating unit, for first generating the first password data based on the first content according to the first data generation rule, and then processing or converting the first password data to obtain the target dynamic password when the target rule selected by the user in the selection interface is a rule combining the first data generation rule and the second data generation rule; A third setting module, connected to the second generating unit, for first generating the first password data based on the first content according to the first data generation rule, then processing or converting the first password data to obtain the second password data, and then splicing the first password data and the second password data to generate the target dynamic password when the target rule selected by the user in the selection interface is a rule combining the first data generation rule, the second data generation rule, and the third data generation rule.
9. A dynamic password verification device implemented based on usage rules, applied to a terminal, characterized in that, Including: A receiving unit, for receiving the second content input by the user; A second sending unit, connected to the receiving unit, for sending the password verification request of the user to the server in response to the second content, so that the server feeds back a preset dynamic password from the server database; Wherein, the preset dynamic password is obtained by using the dynamic password setting device implemented based on any one of claims 6 to 8; A conversion unit, for converting the preset dynamic password received from the server database into a corresponding verification password string after receiving it; A comparison unit, connected to the conversion unit, for comparing the verification password string with the second content; A verification unit, connected to the comparison unit, for confirming that the dynamic password verification fails when the result of the comparison by the comparison unit is that the verification password string is different from the second content; and is also used for confirming that the dynamic password verification passes when the result of the comparison by the comparison unit is that the verification password string is the same as the second content, thereby completing the dynamic password verification implemented based on the usage rule.
10. An electronic device, characterized in that, It includes a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the dynamic password setting method implemented based on the usage rules according to any one of claims 1 to 4, or executes the dynamic password verification method implemented based on the usage rules according to claim 5.