Password authentication method and system based on geometric algebraic transformation hint

By using a password authentication method that involves users selecting a geometric shape and binding it to a password, followed by a multi-step algebraic arithmetic challenge, the vulnerability of passwords to attack is solved, achieving higher security and attack resistance.

CN121077682AActive Publication Date: 2025-12-05BEIJING ELECTRONICS SCI & TECH INST
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511316300.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-12-05
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

Existing password authentication technologies are vulnerable to keylogging and screen capture attacks, and online and offline password guessing is risky. The small key space also leads to insufficient security.

Method used

By binding the user's selected geometric shape and its state to the password character, and combining multi-step algebraic arithmetic challenges and graphic visual cues, dynamic implicit password verification is achieved. The password authentication method is based on geometric algebraic transformation cues. The user selects a geometric shape to generate a graphic token, and the system dynamically decrypts the password character to perform multi-step arithmetic operations and visual challenges.

Benefits of technology

It effectively resists keylogging and screen capture attacks, significantly increases the trial-and-error cost of online and offline guessing, and improves the security of password authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077682A_ABST
    Figure CN121077682A_ABST
Patent Text Reader

Abstract

The invention discloses a password authentication method and system based on geometric algebraic transformation hints, and relates to the technical field of identity authentication and information security, and the method comprises the steps: S1, inputting basic information by a user, setting graphic information, carrying out registration and graphic binding, and generating a graphic token; s2, checking according to login information input by a user and the graphic token and generating a challenge sequence; and S3, performing visual challenge and arithmetic suggestion according to the challenge sequence, generating an arithmetic prompt, calculating a response value by the user according to the arithmetic prompt, performing comparison verification on the response value, and successfully logging in after the verification is passed. According to the method, dynamic implicit password verification is realized by dynamically binding geometric figures selected by a user and states thereof with password characters and combining multi-step algebraic arithmetic challenges and graphic visual suggestions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of identity authentication and information security technology, and more specifically to a password authentication method and system based on geometric algebraic transformation implications. Background Technology

[0002] Identity authentication is the first line of defense for information system security. In open environments, how to authenticate user identities is a fundamental problem that secure communication must address. Current mainstream identity authentication technologies fall into three categories: those based on user-known information, such as password authentication; those based on user-possessed items, such as smart cards and hardware devices; and those based on user biometrics, such as the widely used fingerprint and iris recognition. Among these, password-based authentication technology has been widely adopted due to its ease of deployment and convenience. However, its limited key space makes it vulnerable to password guessing attacks. To address this issue, dynamic password technology has emerged.

[0003] However, current password authentication solutions still have the following shortcomings:

[0004] 1. Vulnerable to keylogging and screen capture attacks: Traditional password input relies entirely on the keyboard and text boxes. Attackers can use keyloggers or screen capture software to obtain the precise characters entered by the user each time, leading to password leakage. Even with simulated keyboards or scrambled key positions, malware can still combine screenshots to obtain click positions and layouts, and can still reconstruct the actual keystrokes.

[0005] 2. High Risk of Online / Offline Password Guessing: For offline guessing, once the password database is leaked, attackers can perform high-speed hash brute-force attacks offline, which is extremely easy to succeed against short or common passwords. For online guessing: Although servers can be rate-limited and locked, research shows that in reality, rate limits can be bypassed through distributed attacks and large-scale IP spoofing, so the success rate of online guessing should not be underestimated.

[0006] Therefore, how to improve the security of password authentication is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0007] In view of this, the present invention provides a password authentication method and system based on geometric algebraic transformation cues. By dynamically binding the user-selected geometric shape and its state with the password character, and combining multi-step algebraic arithmetic challenges and graphic visual cues, dynamic implicit password verification is achieved.

[0008] To achieve the above objectives, the present invention adopts the following technical solution:

[0009] A password authentication method based on geometric algebraic transformation implications includes the following steps:

[0010] S1: The user inputs basic information and sets graphic information to register and bind the graphic, generating a graphic token;

[0011] S2: Verify the login information and graphical token entered by the user and generate a challenge sequence;

[0012] S3: Based on the challenge sequence, visual challenges and arithmetic cues are provided to generate arithmetic prompts. Users calculate response values ​​based on the arithmetic prompts and compare and verify the response values. Once the verification is successful, the user logs in successfully.

[0013] Preferably, the specific implementation process of S1 is as follows:

[0014] S11: The user inputs basic information and sets graphic information; the basic information includes username and password; the graphic information includes graphic descriptions of N predefined geometric figures, and assigns a unique value v to each predefined figure; the graphic description includes the figure shape and figure state.

[0015] S12: Generate a unique salt value and master key for the user based on the password and store them. Generate a secret master key using a key derivation function based on the master key. Add a salt value to the password and encrypt it using the master key and a key derivation function to obtain an encrypted password. Perform a hash calculation on the password to obtain the password HMAC value.

[0016] S13: Using the master key and salt value, combined with the graphic description, derive the predefined unique graphic key corresponding to each graphic through key derivation functions such as HKDF;

[0017] S14: Locate the (v-1)%L password character in the password according to the value v corresponding to each graphic, where L represents the password length. Replace the located password character with the corresponding graphic and encrypt the located password character using the authentication encryption algorithm according to the corresponding graphic key to obtain the encrypted password character.

[0018] S15: Store the user's username, salt value, encrypted master key, encrypted password, password length, password HMAC value, and all encrypted password characters and their corresponding graphic descriptions, numerical values ​​v, and graphic keys as a graphic token, and associate it with the graphic predefined during user registration.

[0019] Preferably, the key derivation function includes PBKDF2-HMAC, etc.; the authentication encryption algorithm includes AES-GCM, etc.

[0020] Preferably, the specific implementation process of S2 is as follows:

[0021] S21: The login information entered by the user includes the username and M login images selected from the predefined image information during user registration for this login;

[0022] S22: Verify the username, login image, and login time based on the username. Verify whether the user exists, whether the account is locked, and check whether the login attempt frequency is within the allowed range. If the session verification passes, proceed to S23; otherwise, login fails.

[0023] S23: Based on the M login graphs selected by the user and the associated graph tokens, a challenge sequence is dynamically generated in combination with predefined multi-step operation rules.

[0024] Preferably, the multi-step operation rules in S23 include initial operation, intermediate operation and final operation; the initial operation is to calculate the base value based on the value in the graphic token associated with the login graphic and the corresponding encrypted password character; the intermediate operation is to randomly select several arithmetic operations and operands, perform arithmetic operations and modulo operations on the base value to generate an intermediate value; a random perturbation value is introduced into the modulo of the modulo operation in the intermediate operation to obtain the adjustment modulo, and the intermediate value is subjected to modulo operation based on the adjustment modulo to obtain the challenge sequence.

[0025] Preferably, the arithmetic operations include addition, subtraction, multiplication, and modular arithmetic; the operands are values ​​in the range of 0-10.

[0026] Preferably, the specific implementation process of S3 is as follows:

[0027] S31: Retrieve the corresponding graphic based on the graphic description of the graphic token corresponding to the challenge sequence, retrieve the corresponding value v based on the random perturbation value and adjustment modulus corresponding to the challenge sequence, and find the corresponding graphic based on the retrieved value v, and combine all the retrieved graphics into a graphical arithmetic prompt.

[0028] S32: The user maps the arithmetic prompt to the password in the basic information entered during registration, and then maps it to a response value.

[0029] S33: Based on the graphic description corresponding to the first login graphic, and in combination with the salt value and the master key, derive the corresponding login graphic key; decrypt the encrypted password characters associated with the first login graphic based on the login graphic key to obtain the decrypted characters, and convert them into decrypted values;

[0030] S34: Calculate the base value based on the value v assigned during registration corresponding to the remaining login images, combined with the decrypted value;

[0031] S35: Dynamically generate the expected result value based on the base value through intermediate and final operations;

[0032] S36: Compare and verify the response value and the expected result value. If they are the same, the verification is successful and login is successful; otherwise, the verification fails and login fails.

[0033] Preferably, a multi-round or multiple-attempt mechanism is adopted in the comparison verification process of S2-S3. If the verification passes, it is determined whether the number of successful verifications has reached a preset success threshold. If the success threshold is reached, the login is successful. If the success threshold is not reached, it is determined whether the number of calculations in this round has reached a calculation threshold. If the calculation threshold is reached, the authentication round judgment is performed. If the calculation threshold is not reached, the process returns to S23. If the verification fails, it is determined whether the number of failed verifications has reached a preset failure threshold. If the failure threshold is reached, the authentication round judgment is performed. If the failure threshold is not reached, the process proceeds to the next round of comparison verification. The authentication round judgment is to determine whether the number of current comparison authentications has reached a preset authentication threshold. If the authentication threshold is reached, the authentication fails and the login fails. If the authentication threshold is not reached, the process returns to S23.

[0034] A password authentication system based on geometric algebraic transformation cues, comprising:

[0035] The configuration management module defines and manages all configuration parameters for the system.

[0036] The user model and key management module defines the user data structure according to the configuration parameters, handles the generation, encryption and storage of user keys and passwords, and generates graphical token data.

[0037] The graphic token management module defines the graphic token data structure, generates graphic tokens based on the graphic token data structure, and stores them.

[0038] Dynamic rule generation module: Generates dynamic security data and rules during registration and login to guide the generation of graphical token data and the calculation of user login;

[0039] Graphics engine and cue generation module: Generates a challenge sequence based on the login graphic entered by the user during login, and obtains arithmetic prompts through visual challenges and arithmetic cues;

[0040] Security verification module: Verifies the user's response based on the arithmetic prompt to determine if the login was successful.

[0041] Preferably, the system also includes a session management module to manage the lifecycle of user login sessions.

[0042] Preferably, the system also includes a database interaction module, which provides an interface for interacting with the database and performing data creation, deletion, modification, and query operations.

[0043] As can be seen from the above technical solution, compared with the prior art, the present invention discloses a password authentication method and system based on geometric algebraic transformation implications, which has the following beneficial effects:

[0044] 1. Dynamic graphics—implicit binding of password characters;

[0045] By assigning unique values ​​to N geometric shapes (shape + state) during user registration, and cyclically mapping these values ​​to password characters, and storing them after encryption with a special key for each shape, users do not need to directly enter password characters when logging in. They only need to select a geometric shape, and the system then dynamically decrypts the corresponding password character by combining the shape value and salt value, thus avoiding direct text input.

[0046] 2. Multi-step implicit arithmetic chain;

[0047] The user responds with the result value after multiple rounds of "base value → intermediate operation → final operation", rather than a direct password character. In this process, the operators, operands, and modulo at each step are unpredictably generated by the system and displayed as graphical prompt symbols (SVG). This completely breaks the direct correspondence between a single input and a password character. When guessing online, attackers must not only guess the password each time they try, but also reconstruct the operation sequence and calculate the result, which significantly increases the cost of trial and error. It is even more difficult to simulate this real-time calculation process offline.

[0048] 3. Resist keylogging and screen capture;

[0049] The user's "input" is no longer the location of key presses or clicks, but an implicit computational response to a series of geometric shapes and algebraic operations. Even if the attacker has full screenshots and keystroke recordings, they can only obtain the challenge graphic, SVG, and the final numerical answer. They cannot use this information to reconstruct the user's real password or encrypted characters, thus effectively resisting keystroke logging and screen capture attacks. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0051] Figure 1 This is a schematic diagram of the user registration and graphic binding process provided by the present invention;

[0052] Figure 2 This is a schematic diagram illustrating the user login and authentication process for inputting login information provided by the present invention. Detailed Implementation

[0053] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0054] This invention discloses a password authentication method based on geometric algebraic transformation cues, comprising the following steps:

[0055] S1: As Figure 1 As shown, users register and bind their graphs, generating graph tokens;

[0056] S11: The user inputs basic information and sets graphic information; the basic information includes username and password; the graphic information includes graphic descriptions of N predefined geometric figures, and assigns a unique value v to each predefined figure; the graphic description includes the figure shape and figure state.

[0057] S12: Generate and store a unique salt and master key for the user based on the password. Generate a encrypted master key from the master key using key derivation functions such as PBKDF2-HMAC. After adding the salt to the password, encrypt it using the master key and key derivation functions to generate an encrypted password. Calculate the password HMAC value using a hash function based on the password.

[0058] S13: Using the master key and salt value, combined with the graphic description, derive the predefined unique graphic key corresponding to each graphic through key derivation functions such as HKDF;

[0059] S14: Locate the (v-1)%L password character in the password according to the value v corresponding to each graphic, where L represents the password length. Replace the located password character with the corresponding graphic. Encrypt the located password character using authentication and encryption algorithms such as AES-GCM according to the corresponding graphic key to obtain the encrypted password character.

[0060] S15: Store the user's username, salt value, secret master key, encrypted password, password length, password HMAC value, encrypted password characters and their corresponding graphic description, value v and graphic key. Generate a corresponding graphic token for each user based on the stored information and the predefined graphic during registration, for subsequent verification.

[0061] S2: As Figure 2 As shown, the login information entered by the user is validated and a challenge sequence is generated;

[0062] S21: The login information entered by the user includes the username and M login images selected from the predefined image information during user registration for this login;

[0063] S22: Verify the username, login image, and login time based on the username. Verify whether the user exists, whether the account is locked, and check whether the login attempt frequency is within the allowed range. If the session verification passes, proceed to S23; otherwise, login fails.

[0064] S23: Based on the M login graphs selected by the user, a multi-step arithmetic challenge sequence is dynamically generated by combining the graph tokens associated with the login graphs and the predefined multi-step operation rules;

[0065] The multi-step operation rules include initial operation, intermediate operation, and final operation. The initial operation calculates a base value based on the value in the graphic token associated with the login graphic and the corresponding encrypted password character. For example, assuming M=2, the initial operation uses the value v1 associated with the graphic token of the first login graphic and the value v2 associated with the graphic token of the second login graphic to calculate a base value. For example, the base value Base = ((DecryptedChar(v1)*v2)%10)+1, where DecryptedChar(v1) represents the original password character obtained by decrypting the encrypted password character associated with the value of the first login graphic. The encrypted password character is then decrypted using the associated graphic key. The intermediate operation randomly selects several arithmetic operations (such as addition, subtraction, multiplication, and modulo) and operands (such as 1-10) and applies them sequentially to the base value to generate intermediate values. The final operation introduces a random perturbation value into the fixed modulo of the modulo operation in the intermediate operation to obtain an adjusted modulo. Based on the adjusted modulo, the intermediate value is subjected to modulo operation to obtain the challenge sequence of multi-step arithmetic.

[0066] S3: Based on the challenge sequence, visual challenges and arithmetic cues are provided to generate arithmetic prompts. Users calculate response values ​​based on the arithmetic prompts and compare and verify the response values. Once the verification is successful, the login is successful.

[0067] S31: Retrieve the corresponding graphic description of the graphic token corresponding to the challenge sequence, retrieve the corresponding graphic when the user registered, retrieve the corresponding value v when the user registered according to the random perturbation value and adjustment modulus corresponding to the challenge sequence, and find the corresponding graphic according to the retrieved value v, and combine all the retrieved graphics into a graphical arithmetic prompt.

[0068] S32: The user maps the arithmetic prompt to a response value based on the basic information entered during registration; and converts the arithmetic prompt into a sequence of numbers to form the response value based on the correspondence between the graphic in the arithmetic prompt and the password character position.

[0069] Based on the matching relationship between the image and the value v during the registration process, the correspondence between the image and the password character positions is determined, and the password characters at the corresponding positions of the value v are extracted to form a number sequence; the value v is located to the (v-1)%Lth password character in the password.

[0070] S33: The server derives the corresponding login pattern key based on the pattern description corresponding to the first login pattern, combined with the salt value and the master key; it decrypts the encrypted password characters associated with the first login pattern using the login pattern key to obtain the decrypted characters and converts them into the decrypted value value_digit;

[0071] S34: The server obtains the value v assigned during registration corresponding to the remaining login images, and calculates the initial base value by combining it with the decrypted value value_digit;

[0072] S35: Based on the base value, the expected result value ExpectedValue is dynamically generated through intermediate and final operations;

[0073] S36: Compare and verify the response value and the expected result value. If they are the same, the verification is successful and login is successful; otherwise, the verification fails and login fails.

[0074] Furthermore, the comparison verification process in S36 employs a multi-round or multiple-attempt mechanism. If verification passes, it checks whether the number of successful verifications has reached a preset success threshold. If the success threshold is reached, login is successful. If the success threshold is not reached, it checks whether the number of calculations in the current round of S2-S3 has reached a calculation threshold. If the calculation threshold is reached, an authentication round is determined. If the calculation threshold is not reached, the process returns to S23. If verification fails, it checks whether the number of failed verifications has reached a preset failure threshold. If the failure threshold is reached, an authentication round is determined. If the failure threshold is not reached, the process proceeds to the next authentication round. The authentication round determination involves checking whether the current number of comparison authentications has reached a preset authentication threshold. If the authentication threshold is reached, authentication fails, and login fails. If the authentication threshold is not reached, the process returns to S23.

[0075] If a user successfully authenticates within the limited number of rounds and attempts (e.g., 2 out of 3 attempts), authentication is successful, and the user logs into the system. If the user fails to reach the success threshold within the limited number of attempts, or fails too many times in a single round, login for that round fails. If multiple rounds fail, authentication fails. Multiple consecutive authentication failures (reaching the system's maximum number of attempts) may result in temporary account locking.

[0076] On the other hand, in one specific embodiment, a password authentication system based on geometric algebraic transformations comprises the following main modules:

[0077] Configuration Management Module: Responsible for defining and managing all configuration parameters of the system; configuration parameters include basic configurations such as master key, security policies such as database connection information, cryptographic parameters such as key derivation algorithm, hash algorithm, encryption algorithm, number of iterations, salt length, key length, challenge and response parameters such as graph type and graph display parameters, and error message text;

[0078] User Model and Key Management Module: Defines user data structure during user registration, and handles the generation, encryption, and storage of user keys; Generates, encrypts, and stores user keys: Generates salt value when creating user object, and derives master key from password using algorithms such as PBKDF2-HMAC; Defines user data structure: Structures core user information such as username, encrypted password, salt value, encrypted master key, password length, password HMAC value, and encrypted password characters for easy database storage;

[0079] The graph token management module transforms the structured user core information into a defined graph token data structure, generates graph tokens, and stores them. It defines and generates graph tokens by creating graph information for each graph selected during user registration (including shape, status, assigned value, etc.), encrypting the graph information using the user's master key, and generating a unique graph key. It processes and stores graph tokens by structuring information such as username, graph shape, graph status, encrypted graph key, assigned value, encrypted password, salt value, encrypted master key, password length, password HMAC value, and encrypted password characters, and storing this information in the database.

[0080] Dynamic rule generation module: responsible for generating dynamic security data and rules during registration and login;

[0081] When generating registration data: Receive the password, graphic selection, and salt value; derive the key for each graphic; encrypt the corresponding password characters; calculate the password HMAC; and output the user's core information, including the salt value, a list of encrypted password characters, and the HMAC. When generating the challenge sequence: Receive the login graphic selected by the user; based on the value in the graphic token corresponding to the graphic, generate a challenge sequence containing initial value calculation parameters, multi-step random arithmetic operations, and a final calculation (including perturbation values ​​and dynamic modulo).

[0082] The graphics engine and cue generation module is responsible for generating the visual representation and arithmetic cues of the challenge, obtaining arithmetic hints; based on the graphic token parameters in the challenge sequence, combined with the graphic shape and graphic state in the configuration, and the animation effect rules, it generates the visual attribute description of the challenge graphics, i.e., the arithmetic hints; it converts the arithmetic operation steps in the challenge sequence into HTML format graphical arithmetic hints using the mapping relationship between values ​​and graphics (SVG icons) established during user registration.

[0083] Security verification module: responsible for verifying whether the user's response to the challenge is correct;

[0084] Session Validation: Expected Value Calculation: Based on the challenge sequence, salt value, master key, stored encrypted characters, password length, and other user information in the session, as well as the login pattern selected during login, the server executes a complete expected value calculation process, dynamically generating the expected result value ExpectedValue. The process includes: deriving the decryption key to generate the login pattern key, decrypting the password characters to generate the decryption character, obtaining the pattern value v, performing initial calculations, applying the arithmetic operation sequence, and applying the final operation and modulus; Response Comparison: Compare the calculated expected value with the numerical response submitted by the user; Error Handling and Logging: Handle any exceptions that may occur during the calculation and verification process, and record detailed debugging and error logs;

[0085] Database interaction module: Provides an interface for interacting with the database and performs CRUD operations on data;

[0086] Initialize the database table structure (user table, graph token table, failed registry), and provide database operation methods such as creating users, storing graph tokens, querying users by username, querying user tokens, updating / resetting / checking user login attempt counts, locking / unlocking users, deleting users, recording failed registrations, and checking cooldown times.

[0087] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0088] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A password authentication method based on geometric algebra transformation implication, characterized in that, The method comprises the following steps: S1: a user inputs basic information and sets graphical information, performs registration and graphical binding, and generates a graphical token; S2: login information input by the user and the graphical token are checked and a challenge sequence is generated; S3: a visual challenge and an arithmetic hint are performed according to the challenge sequence, an arithmetic prompt is generated, the user calculates a response value according to the arithmetic prompt, and the response value is compared and verified, and the login is successful after verification.

2. The password authentication method based on geometric algebra transformation implication according to claim 1, characterized in that, The specific implementation process of S1 is as follows: S11: the user inputs basic information and sets graphical information; the basic information includes a username and a password; the graphical information includes graphical descriptions of N predefined graphs and a unique value v assigned to each of the predefined graphs, and the graphical description includes a graph shape and a graph state; S12: a unique salt value and a master key are generated for the user according to the password and stored, a key derivation function is used to generate a cryptic master key according to the master key, the password is encrypted by the key derivation function using the master key after being salted to obtain an encrypted password, and a password HMAC value is obtained by hashing the password; S13: a unique graph key corresponding to each of the predefined graphs is derived by the key derivation function using the master key and the salt value in combination with the graphical description; S14: the (v-1) %L password character in the password is located according to the value v corresponding to each graph, the located password character is replaced with the corresponding graph, and the located password character is encrypted according to the corresponding graph key using an authentication encryption algorithm to obtain an encrypted password character; S15: the username of the user, the salt value, the cryptic master key, the encrypted password, the password length, the password HMAC value, and all encrypted password characters and their corresponding graphical descriptions, values v and graph keys are stored to form a graphical token, which is associated with the predefined graph during user registration.

3. The password authentication method based on geometric algebra transformation implication according to claim 2, characterized in that, The key derivation function includes PBKDF2-HMAC; the authentication encryption algorithm includes AES-GCM.

4. The password authentication method based on geometric algebra transformation implication according to claim 2, characterized in that, The specific implementation process of S2 is as follows: S21: the login information input by the user includes a username and M login graphs selected from the graphical information predefined during user registration for this login; S22: the username, login graph and login time are checked according to the username to verify whether the user exists, whether the account is locked, and whether the login attempt frequency is within the allowed range, and if the session verification is passed, S23 is entered, otherwise the login fails; S23: a challenge sequence is dynamically generated based on the M login graphs selected by the user and the associated graphical token in combination with the predefined multi-step operation rule.

5. The password authentication method based on geometric algebra transformation implication according to claim 4, characterized in that, The multi-step operation rule in S23 includes initial operation, intermediate operation and final operation; the initial operation is to calculate a base value according to the value and the corresponding encrypted password character in the graphical token associated with the login graph; the intermediate operation is to randomly select a plurality of arithmetic operations and operands, perform arithmetic operation and modulus operation on the base value, and generate an intermediate value; A random disturbance value is introduced to obtain an adjusted modulus for the modulus operation in the intermediate operation, and the intermediate value is operated with the modulus to obtain the challenge sequence.

6. The password authentication method based on geometric algebra transformation implication according to claim 5, characterized in that, The arithmetic operation includes addition, subtraction, multiplication and modulus operation; and the operation number is a value in the range of 0-10.

7. The password authentication method based on geometric algebra transformation implication according to claim 5, characterized in that, The specific implementation process of S3 is as follows: S31: according to the graphical description of the graphical token corresponding to the challenge sequence, the corresponding graph is retrieved, the corresponding numerical value v is retrieved according to the random disturbance value and the adjustment modulus corresponding to the challenge sequence, and the retrieved all graphs are combined to form a graphical arithmetic prompt; S32: the user maps the password in the basic information input during registration into a response value according to the arithmetic prompt; S33: according to the graphical description corresponding to the first login graph, the corresponding login graph key is derived in combination with the salt value and the master key; the encrypted password character associated with the first login graph is decrypted according to the login graph key to obtain a decrypted character, and the decrypted character is converted into a decrypted numerical value; S34: according to the numerical value v corresponding to the remaining login graph allocated during registration, the basic value is calculated in combination with the decrypted numerical value; S35: the expected result value is dynamically generated through intermediate operation and final operation according to the basic value; S36: the response value and the expected result value are compared and verified, if they are the same, the verification is passed and the login is successful, otherwise the verification is not passed and the login fails.

8. The password authentication method based on geometric algebra transformation implication according to claim 7, characterized in that, In the comparison and verification process of S2-S3, a multi-round or multi-time attempt mechanism is adopted, if the verification is passed, it is judged whether the verification pass times reach the preset success threshold, if the success threshold is reached, the login is successful, if the success threshold is not reached, it is judged whether the calculation times of the current round reach the calculation threshold, if the calculation threshold is reached, the authentication round judgment is performed, if the calculation threshold is not reached, it is returned to S23; If the verification is not passed, it is judged whether the verification failure times reach the preset failure threshold, if the failure threshold is reached, the authentication round judgment is performed, if the failure threshold is not reached, the next round of comparison and verification is entered; The authentication round judgment is to judge whether the number of current comparison and authentication reaches the preset authentication threshold, if the authentication threshold is reached, the authentication fails and the login fails, if the authentication threshold is not reached, it is returned to S23.

9. A password authentication system based on geometric algebra transformation implications, characterized by, The password authentication method based on geometric algebra transformation implication according to any one of claims 1-8 comprises: A configuration management module defines and manages all configuration parameters of the system; A user model and key management module defines a user data structure according to the configuration parameters, processes the generation, encryption and storage of user keys and passwords, and generates graphical token data; A graphical token management module defines a graphical token data structure, generates graphical tokens according to the graphical token data structure, and stores them; A dynamic rule generation module generates dynamic security data and rules during registration and login, and guides the generation of graphical token data and user login calculation; A graphical engine and implication generation module generates a challenge sequence according to the login graph input by the user during login, and performs visual challenge and arithmetic implication to obtain an arithmetic prompt; A security verification module verifies whether the user's response is correct according to the arithmetic prompt, and judges whether the login is successful.

10. A password authentication system based on geometric algebra transformation implication according to claim 9, characterized in that, The system further comprises a session management module and a database interaction module; the session management module manages the life cycle of a user login session; and the database interaction module provides an interface for interacting with a database and performs data addition, deletion, modification and query operations.

Citation Information

Patent Citations

  • Login authentication method and login signature procedure

    CN101286848A

  • Novel verification code design method based on private information

    CN115913622A

  • Network security defense method and system based on data analysis

    CN118101269A

  • Graphic Pattern-Based Passcode Generation and Authentication

    US20200387594A1