User password protection method and device based on white-box algorithm, equipment and medium

By generating random white-box keys and salt values ​​using white-box algorithms, and combining them with encryption and hashing algorithms to generate ciphertext for user passwords and verification credentials, a closed-loop protection is formed. This solves the problems of traditional encryption schemes being easily cracked and poor hardware compatibility, achieving high security and wide applicability of user passwords.

CN122053045APending Publication Date: 2026-05-15CHINA UNIONPAY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA UNIONPAY
Filing Date
2026-01-23
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Traditional symmetric encryption schemes rely on fixed keys, which are easily reverse-engineered, resulting in low password security for users. Furthermore, hardware protection schemes have poor compatibility and cannot meet the general needs of various types of terminal devices.

Method used

A white-box algorithm is used to generate random white-box keys and salt values. White-box encryption algorithms and obfuscation hash algorithms are used to generate user password ciphertext and verification credentials, forming a closed-loop protection. Password security is improved through the association encryption mechanism of salt value and user password.

Benefits of technology

It effectively defends against brute-force attacks, enhances user password security, adapts to various types of terminal devices, reduces the risk of key extraction and abuse, and achieves broad compatibility and lightweight operation and maintenance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053045A_ABST
    Figure CN122053045A_ABST
Patent Text Reader

Abstract

The invention discloses a user password protection method and device based on a white-box algorithm, equipment and a medium, and belongs to the field of data processing. The method comprises the following steps: randomly generating a white box key and a salt value; according to a white-box encryption algorithm, encrypting the salt value by using the white-box key to obtain a salt value ciphertext; and based on the salt value ciphertext, the user password and the salt value, generating a user password ciphertext and a password verification voucher by using a confusion algorithm and a hash algorithm, and storing the user password ciphertext, the password verification voucher and the white-box key, the password verification voucher being used for verifying the to-be-verified password input by the user and the user password. According to the embodiment of the invention, the security of the user password can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data processing, and in particular relates to a user password protection method, apparatus, device and medium based on a white-box algorithm. Background Technology

[0002] With the continuous development of electronic information technology, various terminal devices have become an indispensable part of people's daily lives and work. When users use these devices, they need to authenticate themselves using passwords to complete functions such as unlocking the screen, logging into applications, and verifying software permissions. The security of user passwords is directly related to the security of user data privacy and the security of the terminal device. To improve password security, traditional symmetric encryption schemes can be used. However, these schemes rely on fixed keys, making them vulnerable to reverse engineering, resulting in relatively low password security. Summary of the Invention

[0003] This application provides a user password protection method, apparatus, device, and medium based on a white-box algorithm, which can improve the security of user passwords.

[0004] In a first aspect, embodiments of this application provide a user password protection method based on a white-box algorithm, comprising: randomly generating a white-box key and a salt value; encrypting the salt value using the white-box key according to a white-box encryption algorithm to obtain salt ciphertext; generating user password ciphertext and a password verification credential based on the salt ciphertext, the user password, and the salt value using a confusion algorithm and a hash algorithm; storing the user password ciphertext, the password verification credential, and the white-box key; the password verification credential being used to verify the user-input password against the user password.

[0005] Secondly, embodiments of this application provide a user password protection device based on a white-box algorithm, comprising: a random data generation module for randomly generating a white-box key and a salt value; a first encryption module for encrypting the salt value using the white-box key according to a white-box encryption algorithm to obtain salt ciphertext; a second encryption module for generating user password ciphertext and a password verification credential based on the salt ciphertext, the user password, and the salt value using a confusion algorithm and a hash algorithm, wherein the password verification credential is used to verify the user-input password to be verified against the user password; and a storage module for storing the user password ciphertext, the password verification credential, and the white-box key.

[0006] Thirdly, embodiments of this application provide a terminal device, including: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the user password protection method based on the white-box algorithm of the first aspect.

[0007] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the user password protection method based on a white-box algorithm of the first aspect.

[0008] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the user password protection method based on a white-box algorithm of the first aspect.

[0009] This application provides a user password protection method, apparatus, device, and medium based on a white-box algorithm. It can randomly generate a white-box key and a salt value. According to a white-box encryption algorithm, the salt value is encrypted using the white-box key to obtain salt-ciphertext. Based on the salt-ciphertext, the salt value, and the user's password, a confusion algorithm and a hash algorithm are used to generate user password ciphertext and a password verification certificate. The user password ciphertext, password verification certificate, and white-box key are stored. The password verification certificate is used to verify the user's subsequent input password against the user's password. To obtain the user's password, the password verification certificate needs to be verified; to generate the password verification certificate, the salt value is required; and to decrypt the salt value, the user's password is needed. The user password, password verification certificate, and salt value form a closed-loop protection that attackers cannot break through. Furthermore, since both the white-box key and salt value are randomly generated data, attackers cannot reverse-engineer them using algorithms. Even if a dedicated decryption interface is illegally called, the user's password cannot be decrypted, thus significantly reducing the risk of the salt value and user password being independently cracked and improving the security of the user password. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 A flowchart illustrating a user password protection method based on a white-box algorithm provided in an embodiment of this application; Figure 2 A flowchart illustrating an example of a process for encrypted local storage of user passwords provided in an embodiment of this application; Figure 3 A flowchart illustrating an example of a local user password verification process provided in an embodiment of this application; Figure 4 A schematic diagram of the structure of a user password protection device based on a white-box algorithm provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Detailed Implementation

[0012] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the purpose, technical solution, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of the details in these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples of this application. It should be noted that the acquisition, storage, use, and processing of information and data in the embodiments of this application are all authorized by users or relevant organizations and comply with the relevant provisions of national laws and regulations. In the embodiments of this application, certain software, components, models, and other existing solutions in the industry may be mentioned. These should be considered as exemplary, and their purpose is only to illustrate the feasibility of implementing the technical solution of this application, but it does not mean that the applicant has or necessarily used such a solution.

[0013] With the continuous development of electronic information technology, various terminal devices have become an indispensable part of people's daily lives and work. During the use of these devices, users need to authenticate themselves using passwords to complete functions such as unlocking the screen, logging into applications, and verifying software permissions. The security of user passwords is directly related to the security of user data privacy and the security of the terminal device. To improve password security, software protection methods such as traditional symmetric encryption schemes can be used. However, traditional symmetric encryption schemes rely on fixed keys. Once the fixed key is extracted, attackers can directly crack the ciphertext to obtain the plaintext password, or recover the plaintext password by illegally calling the decryption interface. Moreover, user passwords with limited length and combination possibilities are also easily cracked by brute-force attacks, resulting in relatively low password security. To further improve password security, hardware protection schemes such as Secure Enclave can also be relied upon. However, hardware protection schemes rely on proprietary hardware architectures, have poor compatibility, and cannot meet the general needs of various types of terminal devices.

[0014] This application provides a user password protection method, apparatus, device, and medium based on a white-box algorithm. Through a closed-loop protection mechanism involving salt encryption, association between the salt ciphertext and the user password, and association encryption of a verification credential generated by hash operations, it achieves a closed loop where "obtaining the user password requires verifying the verification credential, generating the verification credential requires the salt, and obtaining the salt requires the user password." Even if an unauthorized decryption interface is invoked, the password cannot be decrypted, significantly reducing the possibility of the salt and user password being cracked and improving password security. The white-box keys used for both the salt and the encrypted salt are randomly generated and not stored, effectively defending against brute-force attacks such as rainbow tables. Furthermore, the white-box keys are difficult to extract through reverse engineering or memory dumps, increasing the difficulty of white-box key extraction and abuse, thereby enhancing password security. Moreover, the user password protection method based on the white-box algorithm provided in this application is implemented in software, possessing broad versatility and compatibility, and can meet the general needs of various types of terminal devices.

[0015] The following describes the user password protection method, apparatus, device, medium, and program products based on white-box algorithms provided in this application.

[0016] This application provides a user password protection method based on a white-box algorithm, which can be applied to user authentication scenarios such as screen unlocking, application login, and software permission verification. This white-box algorithm-based user password protection method can be executed by a white-box algorithm-based user password protection device or terminal device; specifically, it can be executed locally on the terminal device. Figure 1 A flowchart of a user password protection method based on a white-box algorithm provided in an embodiment of this application is shown below. Figure 1 As shown, the user password protection method based on the white-box algorithm may include steps S101 to S103.

[0017] In step S101, a white-box key and salt value are randomly generated.

[0018] The white-box key here is a randomly generated key, but it can be directly regarded as the white-box key in the white-box algorithm. The length of the white-box key can be set according to the scenario, requirements, experience, etc., and is not limited here. For example, the white-box key can be a randomly generated 16-byte data. The randomly generated white-box key will correspond to the actual key and root key in the white-box algorithm. For example, the relationship between the white-box key, the actual key and the root key in the white-box algorithm can be shown in the following formula (1): E rootKey ( realkey ) = wbkey (1) in, rootKey E is the root key in the white-box algorithm. rootKey() represents the SM4 encryption algorithm that utilizes the root key; realkey This is the actual key in the white-box algorithm; wbkey The key is a white-box key. White-box algorithms may include, but are not limited to, the Scholl-Lay white-box SM4 algorithm and a modified Scholl-Lay white-box SM4 algorithm. It should be noted that the white-box key in this embodiment has the characteristics of a white-box algorithm, but it cannot be cracked by the actual key and the root key. This is because the white-box key in this embodiment is randomly generated, rather than obtained by the above formula (1), so the plaintext of the actual key and the root key cannot be obtained.

[0019] Here, the salt value is randomly generated data, which is plaintext data. The salt value can be data with cryptographic randomness used in cryptographic key derivation or hash operations. In some examples, different salt values ​​are generated under different terminal devices and / or different time conditions. The length of the salt value can be determined based on the scenario, requirements, experience, etc., and is not limited here. For example, the salt value can be a randomly generated 16-byte array.

[0020] In step S102, the salt value is encrypted using the white-box key according to the white-box encryption algorithm to obtain the salt ciphertext.

[0021] White-box encryption algorithms may include, but are not limited to, the white-box SM4 encryption algorithm. Salted ciphertext is the ciphertext obtained by encrypting the salt value using a white-box key according to the white-box encryption algorithm. For example, salted ciphertext can be represented by the following formula (2): WboxE wbkey ( Salt ) =Salt_Enc (2) in, wbkey White-box key; WboxE wbkey () indicates the white-box SM4 encryption algorithm using a white-box key; Salt Salt value; Salt_Enc This is a salt value ciphertext.

[0022] White-box keys are used for salt encryption, so that white-box keys can only achieve encryption and decryption effects by calling the encryption and decryption interface on the terminal device. It is difficult to build a simulated cracking environment outside the terminal device. Even if the white-box key is obtained by an attacker, it is difficult to perform an effective decryption operation due to the lack of the root key in the white-box algorithm, thus significantly reducing the risk of abuse of white-box keys.

[0023] In step S103, based on the salt ciphertext, user password, and salt value, the user password ciphertext and password verification certificate are generated using a confusion algorithm and a hash algorithm, and the user password ciphertext, password verification certificate, and white-box key are stored.

[0024] A user password is a local password set by the user, which may include, but is not limited to, gesture passwords, numeric passwords, mixed passwords, etc.

[0025] Obfuscation algorithms can be used to process the salt-valued ciphertext and the user's password to obtain the ciphertext of the user's password. A hash algorithm can then be used to obtain a password verification credential based on the user's password and salt value. This credential is used to verify the user's input password against their actual password. The user's input password is the password used for authentication, which verifies whether the input password matches the user's actual password. Since both the white-box key and salt value are randomly generated, the same user password will generate different ciphertexts on different terminal devices and / or at different times, and thus different password verification credentials. The same user password will generate different encrypted passwords on the same terminal device at different times; the same user password at the same time on different terminal devices will generate different encrypted passwords; the same user password on different terminal devices at different times will generate different encrypted passwords; the same user password on the same terminal device at different times will generate different password verification credentials; the same user password at the same time on different terminal devices will generate different password verification credentials; the same user password on different terminal devices at different times will generate different password verification credentials. This method can effectively resist rainbow table brute-force attacks.

[0026] To obtain a user's password by cracking the ciphertext, the salt value must be obtained. To obtain the salt value, both the white-box key and the salt value are needed. While the white-box key can be obtained from the data stored on the terminal device, the salt value is not stored and cannot be obtained. Furthermore, the hash algorithm is irreversible, and the salt value cannot be obtained from the password verification credential. Therefore, it is extremely difficult to obtain the user's password by cracking the ciphertext, significantly improving password security. Conversely, to obtain the password by verifying the password verification credential, the credential must be verified first. Generating the credential requires the salt value, and obtaining the salt value requires the user's password, thus forming a closed-loop protection mechanism that attackers cannot breach, further enhancing password security.

[0027] In this embodiment, a white-box key and a salt value can be randomly generated. Based on a white-box encryption algorithm, the salt value is encrypted using the white-box key to obtain ciphertext. Based on the ciphertext, the salt value, and the user's password, a confusion algorithm and a hash algorithm are used to generate ciphertext and a password verification credential. These are then stored. The password verification credential is used to verify the user's subsequent input of a password to be verified. To obtain the user's password, the password verification credential needs to be verified. Generating the password verification credential requires the salt value, and decrypting it requires the user's password. The user's password, password verification credential, and salt value form a closed-loop protection system, preventing attackers from breaching it. Furthermore, since both the white-box key and salt value are randomly generated, attackers cannot easily deduce them through algorithmic reverse engineering. Even unauthorized calls to the dedicated decryption interface will not decrypt the user's password, significantly reducing the risk of the salt value and user password being independently compromised and improving password security. Furthermore, the white-box key is randomly generated locally on the terminal device, without requiring distribution or updating from the backend system. The root key in the white-box algorithm corresponding to the random generation of the white-box key is hidden in multiple lookup tables, making it difficult for attackers to extract the root key through reverse engineering or memory dumping. The user password protection method based on the white-box algorithm provided in this application is resistant to key extraction attacks, brute-force attacks, static analysis, and dynamic debugging attacks, constructing a multi-layered anti-attack system to improve user password security. Moreover, the user password protection in this application is implemented through a software method, adaptable to various scenarios and terminal devices, and has wider versatility and compatibility.

[0028] In some examples, the salt ciphertext and the user password can be processed according to the obfuscation algorithm to generate the user password ciphertext; the user password and the salt value are concatenated to obtain the first concatenation information; the first concatenation information is processed according to the hash algorithm to generate the password verification certificate. The user password ciphertext is the ciphertext obtained by obfuscating the salt ciphertext and the user password. In some examples, the obfuscation algorithm may include, but is not limited to, the XOR algorithm, the modular addition algorithm, the modular subtraction algorithm, the finite field multiplication algorithm, etc. For example, the obfuscation algorithm includes the XOR algorithm, and the user password ciphertext can be shown in the following formula (3): Salt_Enc ⊕ plainKey =Ct (3) in, Salt_Enc This is the salt value ciphertext; ⊕ is the XOR symbol; plainKey For user password; Ct This is the encrypted password for the user.

[0029] The first concatenation information is the information obtained by concatenating the user password and the salt value. The hash algorithm may include, but is not limited to, the SM3 algorithm, the SHA-2 algorithm, etc. The password verification certificate obtained by the hash algorithm is the hash value. The length of the password verification certificate can be adapted to specific scenarios and requirements, and is not limited here. For example, after concatenating the user password and the salt value, the SM3 algorithm can be used to perform a hash operation to generate a 32-byte password verification certificate, which can be shown in the following formula (4): SM3 ( plainKey + Salt ) =Hash_Store (4) Where SM3() represents the SM3 algorithm; plainKey For user password; + Indicates splicing; Salt Salt value; Hash_ Store This is a password verification credential.

[0030] The white-box key, the encrypted user password, and the password verification credential can be stored as a group locally on the terminal device. Furthermore, the white-box key, the encrypted user password, the password verification credential, and the user identifier can be stored as a group locally on the terminal device, whereby the user identifier identifies the user corresponding to the password.

[0031] The above describes the process of encrypting and storing user passwords locally. To facilitate understanding, an example will be provided below to illustrate the process of encrypting and storing user passwords locally. Figure 2 A flowchart illustrating an example of the encrypted local storage process for user passwords provided in this application embodiment is shown below. Figure 2 As shown, the process of encrypting and storing the user password locally may include steps a1 to a6.

[0032] In step a1, a 16-byte white-box key is randomly generated.

[0033] In step a2, a 16-byte salt value is randomly generated.

[0034] In step a3, the salt value is encrypted using the white-box key through the white-box SM4 encryption algorithm to obtain the salt ciphertext.

[0035] In step a4, the salt ciphertext and the user password are XORed to generate the user password ciphertext.

[0036] In step a5, a hash operation is performed on the concatenated user password and salt value to generate a password verification credential.

[0037] In step a6, the white-box key, the user password ciphertext, and the password verification credential are stored.

[0038] The specific details of steps a1 to a6 above can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0039] In some embodiments, when a user needs to authenticate their identity using a user password, the terminal device can receive the password to be verified entered by the user; generate a verification association value using an inverse obfuscation algorithm based on the encrypted user password and the password to be verified; decrypt the verification association value using a white-box key using a white-box decryption algorithm to obtain a verification salt value; and perform verification based on the password to be verified, the verification salt value, and the password verification credential to obtain a verification result, which is used to characterize whether the password to be verified is consistent with the user password.

[0040] The password to be verified is the password entered by the user during user authentication. When receiving the password to be verified by the user, the user identifier can also be obtained, and the user password ciphertext, password verification certificate and white-box key corresponding to the user identifier can be obtained from the local terminal device based on the user identifier. The de-obfuscation algorithm is the inverse algorithm of the obfuscation algorithm. The associated value to be verified is the information obtained by processing the user password ciphertext using the de-obfuscation algorithm. In some examples, the de-obfuscation algorithm may include the XOR algorithm, and the associated value to be verified may be as shown in the following formula (5): Ct ⊕ Key_Check = Assoc_Check (5) in, Ct This is the user's password ciphertext; ⊕ is the XOR symbol; Key_Check Password to be verified; Assoc_Check This is the associated value to be verified.

[0041] White-box decryption algorithms correspond to white-box encryption algorithms. For example, if the white-box encryption algorithm is the white-box SM4 encryption algorithm, then the white-box decryption algorithm is the white-box SM4 decryption algorithm, and the salt value to be verified can be shown in the following formula (6): WboxD wbkey ( Assoc_Check ) =Salt_Check (6) Among them, WboxD wbkey () indicates a white-box SM4 decryption algorithm using a white-box key; wbkey White-box key; Assoc_Check The associated value to be verified; Salt_Check This is the salt value to be verified.

[0042] A hash value is generated using a hash algorithm based on the password and salt value to be verified. This hash value is then compared with the password verification credential to determine if the password matches the user's password. If the password matches, the verification association value matches the salt ciphertext in the above embodiment, the verification salt value matches the salt value in the above embodiment, and the hash value obtained from the password and salt value matches the password verification credential. If the password does not match, the verification association value does not match the salt ciphertext in the above embodiment, the verification salt value does not match the salt value in the above embodiment, and the hash value obtained from the password and salt value does not match the password verification credential. The verification result is determined by comparing the hash value obtained from the password and salt value with the password verification credential.

[0043] In some examples, the password to be verified and the salt value to be verified can be concatenated to obtain the second concatenated information; the second concatenated information is processed according to the hash algorithm to generate the verification credential; if the verification credential to be verified is consistent with the password verification credential, a verification result indicating that the password to be verified is consistent with the user's password is generated; if the verification credential to be verified is inconsistent with the password verification credential, a verification result indicating that the password to be verified is inconsistent with the user's password is generated. The second concatenated information is the information after concatenating the password to be verified and the salt value to be verified. For details of the hash algorithm, please refer to the relevant descriptions in the above embodiments, which will not be repeated here. For example, after concatenating the password to be verified and the salt value to be verified, the SM3 algorithm is executed to generate a 32-byte verification credential, which can be shown in the following formula (7): SM3 ( Key_Check+Salt_Check ) =Hash_Check (7) Where SM3() represents the SM3 algorithm; Key_Check Password to be verified; Salt_Check The salt value to be verified; + Indicates splicing; Hash_Check This is the certificate to be verified.

[0044] If the credential to be verified matches the password verification credential, it means the password to be verified matches the user's password. If the credential to be verified does not match the password verification credential, it means the password to be verified does not match the user's password.

[0045] Based on the verification results, the corresponding functional operation for user authentication can be determined. For example, if the user authentication function is screen unlock, and the verification result indicates that the password to be verified matches the user's password, then screen unlock is performed; if the password to be verified does not match the user's password, then screen unlock is not performed, and a password error message can be issued. If the user authentication function is application login, and the verification result indicates that the password to be verified matches the user's password, then application login is allowed; if the password to be verified does not match the user's password, then application login is prohibited, and a login failure message can be issued. If the user authentication function is software permission verification, and the verification result indicates that the password to be verified matches the user's password, then software permissions are granted to the user; if the password to be verified does not match the user's password, then software permissions are not granted to the user, and a password error message can be issued.

[0046] The above describes the local password verification process. To make it easier to understand, an example is provided below to illustrate the local password verification process. Figure 3 A flowchart illustrating an example of a local user password verification process provided in an embodiment of this application is shown below. Figure 3 As shown, the local verification process for the user password may include steps b1 to b5.

[0047] In step b1, the white-box key, the user password ciphertext, and the password verification credential are read locally from the terminal device.

[0048] In step b2, the encrypted user password is XORed with the password to be verified to obtain the associated value to be verified.

[0049] In step b3, the salt value to be verified is obtained by decrypting the associated value to be verified using the white-box key through the white-box SM4 decryption algorithm.

[0050] In step b4, a hash operation is performed on the concatenated salt value to be verified and the salt value to be verified to generate a credential to be verified.

[0051] In step b5, the verification credential and the password verification credential are compared to obtain the verification result.

[0052] The specific details of steps b1 to b5 above can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0053] The user password protection method based on white-box algorithms in this application can achieve a closed-loop security protection system covering the entire chain of white-box key hiding, salt encryption, password binding, and hash verification by modifying the encrypted storage and verification process of user passwords. This can comprehensively improve the security of white-box key storage, salt protection, and user password protection, and significantly enhance the ability to resist reverse engineering attacks, brute-force attacks, and debugging attacks.

[0054] The user password protection method based on white-box algorithm in this application embodiment can support multiple types of user passwords such as gestures, numbers, and mixed characters. This user password protection method based on white-box algorithm can be directly deployed in various scenarios such as screen unlocking, local login of applications, and software permission verification of terminal devices. It does not require customized development for different scenarios or different terminal devices and is compatible with multiple scenarios and multiple types of terminal devices.

[0055] In this embodiment, the white-box key, user password ciphertext, and password verification credentials are uniformly stored locally on the terminal device, eliminating the need for a background key management system. This significantly reduces system deployment and maintenance costs and avoids compatibility issues caused by storage separation design, thereby achieving lightweight operation and maintenance management.

[0056] Throughout the encryption and verification process, the salt value, the root key of the white-box key, and the actual key will not appear in memory or storage media. Instead, they will be stored in intermediate data and ciphertext as much as possible, making them difficult to crack. This significantly reduces the risk of key, salt value, and user password leakage.

[0057] This application also provides a user password protection device based on a white-box algorithm. Figure 4 This is a schematic diagram of the structure of a user password protection device based on a white-box algorithm provided in an embodiment of this application, as shown below. Figure 4 As shown, the user password protection device 200 based on the white-box algorithm may include a random data generation module 201, a first encryption module 202, a second encryption module 203, and a storage module 204.

[0058] The random data generation module 201 can be used to randomly generate white-box keys and salt values.

[0059] The first encryption module 202 can be used to encrypt the salt value using a white-box key according to a white-box encryption algorithm to obtain the salt ciphertext.

[0060] The second encryption module 203 can be used to generate a user password ciphertext and a password verification credential based on the salt ciphertext, the user password and the salt value, using a confusion algorithm and a hash algorithm. The password verification credential is used to verify the password to be verified entered by the user against the user password.

[0061] Storage module 204 can be used to store user password ciphertext, password verification credentials, and white-box keys.

[0062] In some embodiments, the second encryption module 203 may be specifically used to: process the salt ciphertext and the user password according to the obfuscation algorithm to generate the user password ciphertext; concatenate the user password and the salt value to obtain the first concatenation information; and process the first concatenation information according to the hash algorithm to generate the password verification credential.

[0063] In some examples, the obfuscation algorithm includes the XOR algorithm.

[0064] In some embodiments, the same user password generates different ciphertexts under different terminal devices and / or different times; the same user password generates different password verification credentials under different terminal devices and / or different times.

[0065] In some embodiments, the user password protection device 200 based on white-box algorithm may further include a receiving module, a first decryption module, a second decryption module, and a verification module.

[0066] The receiving module can be used to receive the password to be verified entered by the user.

[0067] The first decryption module can be used to generate a verification associated value based on the user's ciphertext password and the password to be verified using a reverse obfuscation algorithm.

[0068] The second decryption module can be used to decrypt the associated value to be verified using a white-box key based on a white-box decryption algorithm, thereby obtaining the salt value to be verified.

[0069] The verification module can be used to perform verification based on the password to be verified, the salt value to be verified, and the password verification credential, and obtain the verification result. The verification result is used to indicate whether the password to be verified is consistent with the user's password.

[0070] In some embodiments, the verification module may be specifically used to: concatenate the verification password and the salt value to be verified to obtain second concatenation information; process the second concatenation information according to a hash algorithm to generate a verification credential; if the verification credential to be verified is consistent with the password verification credential, generate a verification result indicating that the password to be verified is consistent with the user's password; if the verification credential to be verified is inconsistent with the password verification credential, generate a verification result indicating that the password to be verified is inconsistent with the user's password.

[0071] In some examples, the de-obfuscation algorithm includes the XOR algorithm.

[0072] It should be noted that the user password protection device 200 based on the white-box algorithm is a device corresponding to the user password protection method based on the white-box algorithm described above. All implementation methods in the above method embodiments are applicable to the embodiments of this device and can achieve the same technical effect.

[0073] This application also provides a terminal device. Figure 5 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application, as shown below. Figure 5 As shown, the terminal device 300 includes a memory 301, a processor 302, and a computer program stored in the memory 301 and capable of running on the processor 302.

[0074] In some examples, the processor 302 described above may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or one or more integrated circuits that may be configured to implement the embodiments of this application.

[0075] Memory 301 may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the user password protection method based on a white-box algorithm according to embodiments of this application.

[0076] The processor 302 runs a computer program corresponding to the executable program code by reading the executable program code stored in the memory 301, so as to implement the user password protection method based on the white-box algorithm in the above embodiments.

[0077] In some examples, terminal device 300 may also include communication interface 303 and bus 304. For example, Figure 5 As shown, the memory 301, processor 302, and communication interface 303 are connected through bus 304 and complete communication with each other.

[0078] The communication interface 303 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application. Input devices and / or output devices can also be connected through the communication interface 303.

[0079] Bus 304 includes hardware, software, or both, that couples the components of terminal device 300 together. For example, and not limitingly, bus 304 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-E) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 304 may include one or more buses. Although specific buses are described and illustrated in the embodiments of this application, this application considers any suitable bus or interconnection.

[0080] This application also provides a computer-readable storage medium storing computer program instructions. When executed by a processor, these computer program instructions can implement the user password protection method based on the white-box algorithm described in the above embodiments and achieve the same technical effect. To avoid repetition, further details are omitted here. The aforementioned computer-readable storage medium may include non-transitory computer-readable storage media, such as read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, etc., and is not limited thereto.

[0081] This application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it can implement the user password protection method based on the white-box algorithm in the above embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0082] It should be clarified that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. For the device embodiments, terminal device embodiments, computer-readable storage medium embodiments, and computer program product embodiments, the relevant parts can be referred to the description section of the method embodiments. This application is not limited to the specific steps and structures described above and shown in the figures. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application. Furthermore, for the sake of brevity, detailed descriptions of known methods and techniques are omitted here.

[0083] The aspects of this application have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0084] Those skilled in the art will understand that the above embodiments are exemplary and not restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Based on a study of the drawings, specification, and claims, those skilled in the art should be able to understand and implement other variations of the disclosed embodiments. In the claims, the term "comprising" does not exclude other means or steps; the quantifier "a" does not exclude a plurality; the terms "first" and "second" are used to identify names and not to indicate any particular order. No reference numerals in the claims should be construed as limiting the scope of protection. The functionality of multiple parts appearing in the claims can be implemented by a single hardware or software module. The appearance of certain technical features in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.

Claims

1. A user password protection method based on a white-box algorithm, characterized in that, include: Randomly generate white-box keys and salt values; According to the white-box encryption algorithm, the salt value is encrypted using the white-box key to obtain the salt ciphertext; Based on the salt ciphertext, the user password, and the salt value, a user password ciphertext and a password verification credential are generated using a confusion algorithm and a hash algorithm. The user password ciphertext, the password verification credential, and the white-box key are stored. The password verification credential is used to verify the user's input password against the user password.

2. The method according to claim 1, characterized in that, The process of generating ciphertext for the user password and password verification credentials based on the salt-encrypted ciphertext, the user password, and the salt value, using an obfuscation algorithm and a hash algorithm, includes: The salt ciphertext and the user password are processed according to the obfuscation algorithm to generate the user password ciphertext; By concatenating the user password and the salt value, the first concatenation information is obtained; The first concatenated information is processed according to the hash algorithm to generate the password verification credential.

3. The method according to claim 1, characterized in that, The obfuscation algorithm includes the XOR algorithm.

4. The method according to claim 1, characterized in that, The same user password can generate different ciphertexts under different terminal devices and / or different times. The same user password can generate different password verification credentials under different terminal devices and / or different times.

5. The method according to claim 1, characterized in that, Also includes: Receive the password to be verified entered by the user; Based on the encrypted user password and the password to be verified, a reverse obfuscation algorithm is used to generate a verification association value. According to the white-box decryption algorithm, the white-box key is used to decrypt the associated value to be verified to obtain the salt value to be verified. Verification is performed based on the password to be verified, the salt value to be verified, and the password verification credential to obtain a verification result. The verification result is used to indicate whether the password to be verified is consistent with the user's password.

6. The method according to claim 5, characterized in that, The verification is performed based on the password to be verified, the salt value to be verified, and the password verification credential to obtain a verification result, including: By concatenating the password to be verified and the salt value to be verified, a second concatenation information is obtained; The second concatenated information is processed according to the hash algorithm to generate a credential to be verified; If the credential to be verified matches the password verification credential, then a verification result is generated indicating that the password to be verified matches the user's password; If the credential to be verified is inconsistent with the password verification credential, then a verification result is generated indicating that the password to be verified is inconsistent with the user's password.

7. The method according to claim 5, characterized in that, The de-obfuscation algorithm includes the XOR algorithm.

8. A user password protection device based on a white-box algorithm, characterized in that, include: The random data generation module is used to randomly generate white-box keys and salt values; The first encryption module is used to encrypt the salt value using the white-box key according to the white-box encryption algorithm to obtain the salt value ciphertext. The second encryption module is used to generate a user password ciphertext and a password verification credential based on the salt ciphertext, the user password and the salt value, using a confusion algorithm and a hash algorithm. The password verification credential is used to verify the password to be verified entered by the user against the user password. The storage module is used to store the encrypted user password, the password verification certificate, and the white-box key.

9. A terminal device, characterized in that, include: Processor and memory storing computer program instructions; When the processor executes the computer program instructions, it implements the user password protection method based on a white-box algorithm as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the user password protection method based on a white-box algorithm as described in any one of claims 1 to 7.

11. A computer program product, characterized in that, The method includes a computer program that, when executed by a processor, implements the user password protection method based on a white-box algorithm as described in any one of claims 1 to 7.