Bidirectional pairing method of password application and password management system and related equipment

By generating public key information in collaboration with the certificate authentication center and the password management system through the first terminal, the problems of cumbersome manual operations and weak security before cryptographic applications can access the password management system are solved, and an efficient and secure two-way registration process is achieved.

CN121644137APending Publication Date: 2026-03-10ANHUI GUOKE QUANTUM NETWORK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-10
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In existing technologies, cryptographic applications require a lot of manual operation before being connected to a cryptographic management system, resulting in poor usability and weak security due to the independent generation and storage of keys.

Method used

The first terminal collaborates with the certificate authentication center and the password management system to generate public key information, transmit data uniformly, replace manual operation by users, realize two-way registration between password applications and the password management system, and use public key information for two-way registration, while private key components are stored separately to improve security.

Benefits of technology

It improves the efficiency and security of two-way registration between cryptographic applications and the cryptographic management system, reduces manual operations, and enhances the security of subsequent cryptographic management and interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644137A_ABST
    Figure CN121644137A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and discloses a two-way pairing method of a password application and a password management system and related equipment, the method is applied to a first terminal, and the first terminal is connected with a certificate authentication center and the password management system; the method comprises the following steps: responding to calling of a password application, so that the password application and a first terminal cooperatively generate public key information; sending the service information and the public key information of the password application to a certificate authentication center, so that the certificate authentication center generates a first certificate according to the public key information and the service information; wherein the first certificate is used for enabling the password management system to complete registration of the password application; and sending the second certificate from the password management system to the password application, so that the password application completes registration of the password management system according to the second certificate. The method has the beneficial effects that the efficiency of two-way registration of the password application and the password management system can be improved, and the security of password management and interaction is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of information security, and in particular to a password application and password management system bidirectional pairing method and related devices. BACKGROUND

[0002] Bidirectional pairing between a password application and a password management system, such as bidirectional registration, refers to mutual authentication between the password application and the password management system to establish a secure channel, implement key exchange, establish a secure and trusted identity association, and ensure the authenticity of both parties and the confidentiality of data transmission. This process usually involves multi-factor authentication, dynamic key generation, encrypted communication, and other technologies to resist risks such as man-in-the-middle attacks and data breaches.

[0003] In related technologies, before a password application accesses a password management system, a user needs to perform a series of offline operations. In the case of a large number of password applications, a large amount of preparation work needs to be done manually, which is not user-friendly. In the entire process, the password application independently generates and stores the key, resulting in weak security in subsequent password management and interaction. SUMMARY

[0004] Embodiments of the present application aim to provide a password application and password management system bidirectional pairing method and related devices to improve the efficiency of password application and password management system bidirectional registration and improve the security of password management and interaction.

[0005] To solve the above technical problems, embodiments of the present application provide a password application and password management system bidirectional pairing method, applied to a first terminal, the first terminal being connected to a certificate authentication center and a password management system respectively; the method comprises: in response to a call of a password application, causing the password application and the first terminal to generate public key information in cooperation; sending business information of the password application and the public key information to the certificate authentication center, causing the certificate authentication center to generate a first certificate according to the public key information and the business information; wherein the first certificate is used to cause the password management system to complete registration of the password application; sending a second certificate from the password management system to the password application, causing the password application to complete registration of the password management system according to the second certificate.

[0006] Embodiments of the present application also provide a first terminal, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 7.

[0007] The embodiment of the present application also provides a computer readable storage medium, which stores computer instructions, and the computer instructions are executed by a processor to implement the method described above.

[0008] The embodiment of the present application also provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the method described above.

[0009] The two-way pairing method of the password management system in the present application is based on the connection between the first terminal, the certificate authentication center and the password management system. When the first terminal connects the password application, the password application cooperates to generate public key information, and then the public key information is sent to the authentication center to generate a certificate, and the registration of the password application on the password management system side is realized. Based on the second certificate fed back by the password management system, the two-way registration is realized on the password application side. Therefore, the entire two-way registration process is activated based on the connection of the password application, and the data is transmitted and realized through the first terminal, which replaces the manual operation of the user and also unifies the authentication entrance, significantly improves the efficiency of the two-way registration of the password application and the password management system, and the first terminal cooperates with the password application to generate key information, wherein the public key information is used for two-way registration, and the private key component can be saved respectively, thereby improving the security of subsequent password management and interaction application scenarios. BRIEF DESCRIPTION OF DRAWINGS

[0010] Figure 1 Flowchart of the two-way pairing method of the password application and the password management system provided by an embodiment of the present application Figure 1 ; Figure 2 Interaction between the first terminal, the password application, the password management system and the certificate authentication center in the two-way pairing method of the password application and the password management system provided by an embodiment of the present application Figure 1 ; Figure 3 Flowchart of the two-way pairing method of the password application and the password management system provided by an embodiment of the present application Figure 2 ; Figure 4 Flowchart of the two-way pairing method of the password application and the password management system provided by an embodiment of the present application Figure 3 ; Figure 2 Interaction between the first terminal, the password application, the password management system and the certificate authentication center in the two-way pairing method of the password application and the password management system provided by an embodiment of the present application Figure 6 ; Figure 1 Structural diagram of the first terminal provided by an embodiment of the present application. DETAILED DESCRIPTION

[0011] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with reference to the drawings. However, those skilled in the art can understand that, in the embodiments of the present application, many technical details are presented in order to make the readers better understand the present application. However, the technical solutions claimed by the present application can be implemented even without these technical details and based on various changes and modifications of the following embodiments. The division of the following embodiments is for the convenience of description, and should not constitute any limitation on the specific implementation modes of the present application. The embodiments can be combined and referenced to each other without contradiction.

[0012] In the description of the present application, the terms "first", "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more features. In the description of the present application, the meaning of "multiple" is two or more, unless otherwise specifically limited.

[0013] In the related art, before the password application accesses the password management system, a series of operations need to be performed by the user in an offline manner. In the case of a large number of password applications, a large amount of preparation work needs to be performed manually, and the ease of use is poor. In the entire process, the password application independently generates and stores the key, which leads to weak security in subsequent password management and interaction.

[0014] For example, when the user performs a two-way registration operation, the user initializes the password application and then the password application independently generates a signature key pair. Subsequently, the user transmits and receives certificates in the CA (Certificate Authority) and the password management system according to the key pair to complete the two-way registration. The entire process requires a large amount of time, and the ease of use is poor. Moreover, when the password application is usually running in a mobile terminal, a web browser, or an environment in which the authenticity and integrity protection of sensitive security parameters are relatively weak, such as a hardware password module that lacks compliance, the way in which the password application stores the complete key leads to security risks in subsequent password management and interaction.

[0015] In view of this, the present application provides a two-way pairing method of a password application and a password management system, applied to a first terminal, wherein the first terminal is connected with a certificate authentication center and a password management system respectively; the method comprises the following steps: in response to the calling of the password application, the password application and the first terminal cooperatively generate public key information; the business information of the password application and the public key information are sent to the certificate authentication center, so that the certificate authentication center generates a first certificate according to the public key information and the business information; wherein the first certificate is used for the password management system to complete the registration of the password application; the second certificate from the password management system is sent to the password application, so that the password application completes the registration of the password management system according to the second certificate. The method of the present application is applied to the first terminal, based on the connection of the first terminal with the certificate authentication center and the password management system, when the password application is connected with the first terminal, the password application cooperatively generates public key information, and then the public key information is sent to the authentication center to generate a certificate, thereby realizing the registration of the password application on the password management system side, and based on the two-way registration of the second certificate sent from the password management system to the password application side, the access and data interaction of each device based on the first terminal are realized, so as to avoid the dependence of the password application on the user's frequent manual operation on multiple systems before accessing the password management system, improve the use convenience, and the first terminal and the password application cooperatively generate key information, and the specific password application generates public key information for registration, without generating complete key including all private keys, so as to improve the security of subsequent password management and interaction. The implementation details of the two-way pairing method of the password application and the password management system of the embodiment of the present application are described in detail below, and the following content is only provided for the implementation details for easy understanding, and is not essential for implementing the present solution.

[0016] Referring to Figure 2 and Figure 1 , as shown in Figure 2 , the flowchart of the two-way pairing method of the password application and the password management system provided by an embodiment of the present application is shown, Figure 2 , the interaction diagram of the first terminal, the password application, the password management system and the certificate authentication center in the two-way pairing method of the password application and the password management system provided by an embodiment of the present application is shown.

[0017] The present application provides a two-way pairing method of a password application and a password management system, applied to a first terminal, wherein the first terminal is connected with a certificate authentication center and a password management system respectively.

[0018] In this embodiment, the password application can be a software system or a hardware and software password module, and provides the user with password management and password algorithm capabilities. The password application can run on a mobile terminal, a PC terminal, a web browser, or the like. The password application has the ability to perform collaborative key computation with the first terminal.

[0019] The first terminal is configured to connect with a certificate authority (CA) and a password management system, can obtain certificate management related services from the certificate authority, connect with the password management system, obtain password application management related services from the password management system, and after connecting to the password application, can have the ability to perform collaborative key computation with the password application.

[0020] The certificate authority provides the first terminal with certificate management related services.

[0021] The password management system provides the first terminal with password application management related services, and after implementing bidirectional pairing with the password application, can interact with the password application for keys.

[0022] When the password application needs to implement bidirectional pairing with the password management system, the password application connects with the first terminal, and constructs a secure channel based on a unidirectional authentication security protocol, such as a unidirectional SLL (Secure Sockets Layer) protocol. In an optional embodiment, the first terminal authenticates the password application to complete the authentication of the password application. Specifically, the first terminal can provide an authentication interface, after the password application connects with the first terminal, the password application calls the authentication interface of the first terminal to obtain the authorization of the first terminal, implements the authentication of the password application by the first terminal, and ensures the authenticity and legality of the password application. The first terminal and the password application complete the establishment of a 1-1 secure channel as shown in Figure 2 .

[0023] The first terminal, the certificate authority, and the password management system can construct a 1-2 secure channel and a 1-3 secure channel based on a bidirectional authentication security protocol, such as a bidirectional SLL protocol, for subsequent secure data transmission. Figure 2

[0024] Thus, after the connection between the components, data transmission is performed through the secure channel to ensure confidentiality and integrity.

[0025] The method includes the following steps: Step 100, in response to the call of the password application, to make the password application and the first terminal generate public key information collaboratively.

[0026] ​In one embodiment, after the new cryptographic application is connected to the first terminal, a response signal is sent to invoke a system service interface of the first terminal, so that the first terminal and the cryptographic application cooperatively generate a key, which can include a signature key pair and an encryption key pair. In the cooperation process, the first terminal and the second terminal exchange some cryptographic data through at least one cooperative calculation, so as to jointly generate a unified public key, and the first terminal and the cryptographic application each hold a part of the private key.

[0027] In step 200, the business information of the cryptographic application and the public key information are sent to a certificate authority center, so that the certificate authority center generates a first certificate according to the public key information and the business information. The first certificate is used to enable the cryptographic management system to complete the registration of the cryptographic application.

[0028] The public key information can include the public key of the signature key pair and the public key of the encryption key pair, and the first certificate has corresponding signature certificate and encryption certificate. The business information includes the identification information of the cryptographic application itself, such as device information, and the information of the registration target of the cryptographic application, such as registration object information representing where the cryptographic application needs to be registered. In this way, the information is sent to the certificate authority center to apply for a certificate by invoking the certificate issuing service interface of the certificate authority center. The certificate authority center generates the signature certificate and the encryption certificate according to the public key of the signature key pair, the public key of the encryption key pair, and the business information.

[0029] The public key information and the business information can be sent by the cryptographic application to the first terminal.

[0030] The first certificate can be directly sent by the certificate authority center to the cryptographic management system to enable the cryptographic management system to complete the registration of the cryptographic application. In another embodiment, the first certificate can also be returned by the certificate authority center to the first terminal, and then sent by the first terminal to the cryptographic management system. Specifically, the first terminal receives the first certificate from the certificate authority center and sends the business information and the first certificate to the corresponding cryptographic management system. After receiving the first certificate, the cryptographic management system can verify the certificate signature legality and validity period, and then complete the registration according to the corresponding business information.

[0031] In step 300, the second certificate from the cryptographic management system is sent to the cryptographic application, so that the cryptographic application completes the registration of the cryptographic management system according to the second certificate.

[0032] The password management system receives the service information and the first certificate, completes the registration of the password application, and can generate a second certificate and send it to the first terminal. The first terminal sends the second certificate information to the password application, so that the password application completes the registration of the password management system. Thus, the password application and the password management system complete the registration of each other, realizing bidirectional registration.

[0033] Thus, the bidirectional pairing method of the password management system in the application is based on the connection of the first terminal with the certificate authentication center and the password management system. When the first terminal connects the password application, the public key information is generated in cooperation with the password application, and then the public key information is sent to the authentication center for certificate generation, and the registration of the password application on the password management system side is realized. Based on the second certificate fed back by the password management system, the bidirectional registration is realized on the password application side. Thus, the entire bidirectional registration process is activated based on the connection of the password application, and the data is transmitted and realized through the first terminal, replacing the manual operation of the user, and also unifying the authentication entrance, significantly improving the efficiency of bidirectional registration of the password application and the password management system. The first terminal cooperates with the password application to generate key information, wherein the public key information is used for bidirectional registration, and the private key component can be saved respectively, thereby improving the security of subsequent password management and interaction application scenarios.

[0034] In an optional embodiment of the application, the method further comprises: Sending system information from the password management system to the password application, so that the password application establishes a secure channel with the password management system according to the system information.

[0035] The system information includes the identification information of the password management system itself, such as the device information of the password management system. Specifically, it can include information such as the port number for accessing the password management system for establishing a secure channel. Correspondingly, the service information sent to the password application of the password management system also includes similar information, so that the proxy system receives the system information and the second certificate sent by the password management system and forwards them to the password application through the secure channel.

[0036] After the password application verifies the integrity and legality of the information, the password management system and the password application can establish a secure channel based on the system information (such as the secure channel 1-4 established in the above embodiment). Figure 3 The secure channel is used to ensure the security of subsequent interaction.

[0037] In an optional embodiment of the application, the method further comprises: receive registration result information from the password management system, and send the registration result information to the password application, so that the password application completes registration with the password management system according to the registration result information and the second certificate.

[0038] The first terminal receives registration result information returned by the password management system, such as a registration success result, and forwards it to the password application through a secure channel. After the password application confirms the integrity and legality of the registration process based on the result information and the second certificate, it completes the final registration with the password management system.

[0039] Referring to Figure 4 In an optional embodiment of the present application, in response to the call of the password application, the first terminal and the password application jointly generate public key information, including: Step 101, in response to the call of the password application, generate a first part of the private key and generate first intermediate data according to the first part of the private key; Step 102, send the first intermediate data to the password application, so that the password application generates the public key information according to the first intermediate data and the second part of the private key saved by the password application.

[0040] When the first terminal connects to the password application, the password application and the first terminal jointly generate a key. The first terminal and the password application respectively generate and retain a private key component, wherein the first terminal generates and retains a first part of the private key, and the password application generates and retains a second part of the private key. Then the first terminal generates first intermediate data (such as calculating an elliptic curve point) according to its first part of the private key, and then sends it to the password application. At this time, the password application can also generate second intermediate data according to its second part of the private key. Therefore, the second terminal jointly calculates the final public key information according to the second intermediate data it masters and the first intermediate data sent by the first terminal. The complete private key information is generated jointly according to the first part of the private key and the second part of the private key, but the password application and the first terminal respectively master part of it, that is, this complete private key information is never completely calculated or stored anywhere. In this way, the security of subsequent application scenarios such as password management and interaction is significantly improved.

[0041] Referring to Figure 5 As shown in the figure, the password application and the password management system also include a bidirectional pairing method, including: Step 400, generate a first part of the temporary key according to the first part of the private key information; Step 500, send the first part of the temporary key to the password application, so that the password application signs or decrypts according to the first part of the temporary key and the second part of the private key saved by the password application.

[0042] In subsequent two-way interactions between the cryptographic application and the cryptographic management system, when the cryptographic application needs the complete key for signing or decryption, the first terminal generates temporary key information based on its independently stored private key fragment and provides it to the cryptographic application for generating the complete key. In an optional embodiment, the first terminal generates a first part of a temporary key, such as a temporary private key, based on the first part of the private key information using a corresponding algorithm. This temporary key is strongly correlated with the first part of the private key information but cannot be reversed. After generation, the first terminal sends the first part of the temporary key to the cryptographic application through a secure channel established with the cryptographic application. Upon receiving it, the cryptographic application extracts its second part of the private key, generates a second part of the temporary key, and uses a corresponding synthesis algorithm to associate the two parts of the temporary key to generate a complete session key or signature key. Based on this key, the digital signature or decryption of the target data is then performed, thereby preventing key information leakage and improving security.

[0043] Reference Figure 6 As shown, in a specific embodiment of this application, the interaction between the first terminal, the cryptographic application, the certificate authentication center, and the cryptographic management system is as follows: 1.1 The cryptographic application calls the authentication interface of the first terminal to obtain authorization from the first terminal, ensuring the authenticity and legitimacy of the cryptographic application. The authentication method can be flexibly selected from other methods that are not based on certificates.

[0044] 1.2 The cryptographic application calls the collaborative service interface of the first terminal to collaboratively generate signature key pairs and encryption key pairs.

[0045] 1.3 The cryptographic application sends business information and public key information to the first terminal and calls the first terminal's automatic registration interface to initiate automatic registration.

[0046] 1.4 The first terminal sends the business information and public key information of the cryptographic application to the certificate authentication center and calls the certificate issuance service interface of the certificate authentication center to apply for a certificate.

[0047] 1.5 The certificate authentication center returns the completed first certificate (signature certificate and encryption certificate) to the first terminal.

[0048] 1.6 The first terminal sends the business information of the password application and the first certificate to the password management system, and calls the password application registration interface of the password management system to register the password application.

[0049] 1.7 The password management system returns the registration results, system information, and the password management system's second certificate to the first terminal.

[0050] 1.8 The first terminal returns the registration result, the first certificate, the system information of the password management system, and the second certificate to the password application.

[0051] 1.9, the password application and the password management system complete bidirectional registration, each has the certificate of the other, and the password application establishes a secure channel based on a collaborative algorithm and the password management system.

[0052] Figure 6 A structural schematic diagram of a first terminal is provided for an embodiment of the present application. As shown in the figure, the first terminal includes at least one processor; and a memory connected in communication with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method as described in the above method embodiment. ​

[0053] The memory and the processor can be connected in a bus manner, the bus can include any number or kind of interconnected buses and bridges, and the bus connects various circuits of one or more processors and memories together. The bus can also connect various other circuits such as peripheral devices together, which are well known in the art, and thus, further description thereof will not be given herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on a transmission medium. Data processed by the processor is transmitted on a wireless medium through the antenna, and further, the antenna also receives data and transmits the data to the processor.

[0054] The processor is responsible for managing the bus and general processing, and can also provide various functions including timing, peripheral interface, voltage regulation, power management and other control functions. And the memory can also be used to store data used by the processor in performing operations.

[0055] Another embodiment of the present application relates to a computer readable storage medium, and the computer readable storage medium stores computer instructions, and the computer instructions are executed by a processor to implement the method described in the above method embodiment.

[0056] Another embodiment of the present application relates to a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the steps of the above method.

[0057] ​That is, a person skilled in the art can understand that all or part of the steps in the above-mentioned embodiment methods can be completed by instructing the relevant hardware by a program stored in a storage medium, including a plurality of instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0058] The first terminal, the computer readable storage medium, and the computer program product in the embodiments of the present application have similar technical effects to the above-mentioned two-way pairing method of the password application and the password management system, and will not be described again here.

[0059] A person skilled in the art can understand that the above-mentioned embodiments are specific embodiments for implementing the present application, and in actual applications, various changes can be made in form and details without departing from the spirit and scope of the present application.

Claims

1. A method of two-way pairing of a cryptographic application with a cryptographic management system, characterized in that, The method is applied to a first terminal connected with a certificate authentication center and a password management system respectively, and comprises the following steps: In response to a call of a password application, the password application generates public key information in cooperation with the first terminal; The password application sends service information and the public key information to the certificate authentication center, so that the certificate authentication center generates a first certificate according to the public key information and the service information; wherein the first certificate is used for the password management system to complete registration of the password application; The password application receives a second certificate from the password management system, and completes registration of the password management system according to the second certificate.

2. The password application and password management system bidirectional pairing method according to claim 1, wherein, The method further comprises: The password application receives system information from the password management system, and establishes a secure channel with the password management system according to the system information.

3. The password application and password management system bidirectional pairing method according to claim 2, wherein, The method further comprises: The password application receives registration result information from the password management system, and completes registration of the password management system according to the registration result information and the second certificate.

4. The method of claim 1-3, wherein the password application and the password management system are bidirectionally paired. The method of generating the public key information in cooperation with the first terminal in response to the call of the password application comprises the following steps: In response to the call of the password application, a first partial private key is generated, and first intermediate data is generated according to the first partial private key; The password application sends the first intermediate data to the password application, so that the password application generates the public key information according to the first intermediate data and a second partial private key saved by the password application.

5. The password application and password management system bidirectional pairing method according to claim 4, wherein, The method further comprises: A first partial temporary key is generated according to the first partial private key information; The password application sends the first partial temporary key to the password application, so that the password application performs signature or decryption according to the first partial temporary key and the second partial private key saved by the password application.

6. The method of bidirectional pairing of a password application with a password management system according to any one of claims 1-3 and 5, characterized in that, The method further comprises: The password application receives a first certificate from the certificate authentication center, and sends the service information and the first certificate to the corresponding password management system.

7. The method of bidirectional pairing of a password application with a password management system according to any one of claims 1-3 and 5, characterized in that, Before the password application generates the public key information in cooperation with the first terminal in response to the call of the password application, the method further comprises: The password application is authenticated to complete authentication of the password application.

8. A first terminal, characterized by, The method comprises: At least one processor; and The memory is connected in communication with the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are executed by the processor to implement the method of any one of claims 1 to 7.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1 to 7.