Password resetting method and device, equipment, chip and storage medium

By using secure chip storage and decryption key technology, the problem of data loss caused by users forgetting their lock screen password is solved, enabling fast and secure password reset and improving the user experience.

CN122065302APending Publication Date: 2026-05-19SHENZHEN HEYTAP TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN HEYTAP TECHNOLOGY CO LTD
Filing Date
2024-11-18
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing technologies typically involve a factory reset when users forget their lock screen password, resulting in data loss and impacting user experience.

Method used

By using a secure chip to store the user's encrypted information and resetting the password using a decryption key, user data security is ensured and passwords can be recovered quickly.

Benefits of technology

Enables quick password resets without losing user data, thus improving the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122065302A_ABST
    Figure CN122065302A_ABST
Patent Text Reader

Abstract

The invention discloses a password resetting method and device, equipment, a chip and a storage medium, and the method comprises the steps: obtaining a first password of a first object in response to a first resetting operation; generating a decryption key based on the first password of the first object and the identification information of the security chip; decrypting the ciphertext information of the first object stored in the security chip based on the decryption key to obtain a second password of the first object; and performing password resetting on the first object based on the second password of the first object. Therefore, the password of the first object is stored by means of the characteristics of high security and reliability of the security chip, password resetting can be realized by using the password stored by the security chip under the condition that a user forgets to set the password at present, and password resetting can be quickly realized on the basis of ensuring user data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a password reset method, apparatus, device, chip, and storage medium. Background Technology

[0002] To ensure user information security, users can configure a lock screen password for their devices. Once configured, users must enter this password to unlock and access the device whenever it wakes from sleep mode or restarts.

[0003] However, in some cases, users may forget their lock screen password, and after multiple failed attempts, the device will be locked and unusable. To solve this problem, current mainstream technology tends to use a factory reset, which erases all user data stored on the electronic device and restores it to its initial system state. This allows users to reset their lock screen password and continue using the device. However, a significant drawback of this method is the loss of user data, greatly impacting the user experience. Summary of the Invention

[0004] This application aims to provide a password reset method, apparatus, device, chip, and storage medium, which implements password reset based on a security chip.

[0005] The technical solution of this application is implemented as follows:

[0006] Firstly, a password reset method is provided, including:

[0007] In response to the first reset operation, obtain the first password of the first object;

[0008] A decryption key is generated based on the first password of the first object and the identification information of the security chip;

[0009] Based on the decryption key, the encrypted information of the first object stored in the security chip is decrypted to obtain the second password of the first object;

[0010] The password of the first object is reset based on the second password of the first object.

[0011] Secondly, a password reset device is provided, comprising:

[0012] The acquisition unit is used to acquire the first password of the first object in response to the first reset operation;

[0013] The first processing unit is used to generate a decryption key based on the first password of the first object and the identification information of the security chip;

[0014] The first processing unit is also used to decrypt the ciphertext information of the first object stored in the security chip based on the decryption key to obtain the second password of the first object;

[0015] The second processing unit is used to perform a password reset on the first object based on the second password of the first object.

[0016] Thirdly, an electronic device is provided, comprising: a processor and a memory configured to store a computer program capable of running on the processor.

[0017] When the processor is configured to run a computer program, the steps of the aforementioned method are executed.

[0018] Fourthly, a security chip is provided, comprising: a processor and a memory, wherein the memory is used to store encrypted information of a first object and to store a computer program;

[0019] A processor is used to retrieve and run a computer program from memory, causing a device equipped with a security chip to perform the steps of the aforementioned method.

[0020] Fifthly, a computer-readable storage medium is provided having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the aforementioned method.

[0021] Sixthly, a computer program product includes a computer program that, when executed by a processor, implements the steps of the aforementioned method.

[0022] This application provides a password reset method, apparatus, device, chip, and storage medium. The method includes: in response to a first reset operation, obtaining a first password for a first object; generating a decryption key based on the first password of the first object and the identification information of a security chip; decrypting the encrypted information of the first object stored in the security chip based on the decryption key to obtain a second password for the first object; and performing a password reset on the first object based on the second password. Thus, relying on the high security and reliability of the security chip, the password of the first object is stored, allowing for password reset when the user forgets their current password. This ensures user data security while quickly achieving password reset. Attached Figure Description

[0023] Figure 1 This is a flowchart illustrating the password reset method in an embodiment of this application;

[0024] Figure 2 This is a schematic diagram of the first process of password backup in an embodiment of this application;

[0025] Figure 3 This is a schematic diagram of the password retrieval process in an embodiment of this application;

[0026] Figure 4 This is a schematic diagram of the second process for password backup in an embodiment of this application;

[0027] Figure 5 This is a schematic diagram of the composition of the password reset device in the embodiments of this application;

[0028] Figure 6 This is a schematic diagram of the composition structure of the electronic device in the embodiments of this application;

[0029] Figure 7 This is a schematic diagram of the composition structure of the security chip in the embodiments of this application. Detailed Implementation

[0030] In order to gain a more detailed understanding of the features and technical content of the embodiments of this application, the implementation of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not intended to limit the embodiments of this application.

[0031] This application provides a password reset method, specifically a password reset method based on a secure chip. The secure chip (SE), also known as a security unit, integrates cryptographic algorithms and features physical anti-attack design. It has an independent processor and memory, as well as rich external communication interfaces, and can execute programs. The secure chip, with its independence, physical protection, encryption and decryption capabilities, identity authentication and authorization, high-level security authentication, flexibility, and scalability, ensures the security of storing and processing sensitive data.

[0032] Figure 1 This is a flowchart illustrating the password reset method in an embodiment of this application, as shown below. Figure 1 As shown, the method may specifically include:

[0033] Step 101: In response to the first reset operation, obtain the first password of the first object;

[0034] The first reset operation is the operation that triggers the password reset process. For example, the first reset operation can be a reset operation performed after a user forgets their current password.

[0035] In some embodiments, the method further includes: obtaining a first password of a first object; recording the cumulative number of errors if the first password does not match the current password of the first object; and outputting a prompt message to prompt the user to perform a first reset operation if the cumulative number of errors exceeds a preset value.

[0036] The first object can be any object that requires a password to unlock, including but not limited to: electronic devices, online accounts, applications, files, folders, computer systems, etc.

[0037] The primary password is used to control access to the security chip's storage space. Different objects use their own corresponding primary passwords, enabling fine-grained access control to the security chip and ensuring the security of user data. The primary password consists of a series of characters, which can be letters (uppercase or lowercase), numbers, special symbols (such as punctuation marks, spaces, etc.) or combinations thereof. The primary password can also be composed of biometric features, image features, physical tokens, or combinations thereof.

[0038] In some embodiments, the first password may be a password used by the first object or a unique password assigned to the first object.

[0039] In some embodiments, the method further includes: in response to a first reset operation, obtaining a reset interval time since the last password reset; if the reset interval time is less than or equal to a first preset value, outputting a first prompt message to prompt the user to enter a first password for the first object; if the reset interval time is greater than the first preset value, outputting a second prompt message to prompt the user that password retrieval failed. When performing the first reset operation, outputting prompt messages guides the user to perform the reset operation, improving the user experience.

[0040] In some embodiments, the method further includes: deleting the ciphertext information of the first object stored in the security chip when the reset interval is greater than a first preset value. For example, to ensure password security, the ciphertext information stored in the security chip will be physically erased after a period of time following a user password reset, avoiding the risk of password leakage caused by long-term password storage.

[0041] Step 102: If the first condition is met, generate a decryption key based on the first password of the first object and the identification information of the security chip;

[0042] The first condition is the access condition for the security chip. Only when the first condition is met can the security chip's storage space be accessed based on the first password; otherwise, access is denied.

[0043] In some embodiments, the first condition includes: access to the security chip is permitted; and the first password of the first object is consistent with the access password of the security chip.

[0044] Access to the security chip is determined based on one or more of the chip's status, access operation, and access time. Access to the security chip's storage space is only permitted if the security chip is allowed and the initial password matches the security chip's access password; otherwise, access is denied.

[0045] In some embodiments, the first condition includes: the first password of the first object and the access password of the security chip are consistent.

[0046] In some embodiments, the method further includes: updating the cumulative error count if the first password of the first object and the access password of the security chip are inconsistent; determining that the security chip is allowed to access if the cumulative error count is less than or equal to a second preset value; and determining that the security chip is allowed to access if the cumulative error count is greater than the second preset value and the verification interval between the first password and the last verification is greater than a third preset value.

[0047] In some embodiments, the method further includes: if the cumulative number of errors is greater than a second preset value and the verification interval from the last verification is less than or equal to a third preset value, determining that the security chip does not allow access, and outputting a third prompt message to prompt the user to enter the first password of the first object again after the first interval time to reset the password; if the cumulative number of errors is greater than a fourth preset value, determining that the security chip does not allow access.

[0048] In some embodiments, the method further includes: if the cumulative number of errors exceeds a fourth preset value, outputting a second prompt message to indicate to the user that password retrieval has failed.

[0049] The second preset value is used to limit the number of consecutive password verifications. The second preset value can be an integer greater than 1. For example, the second preset value can be 3 times, 4 times, 5 times, 10 times, etc. If the cumulative number of incorrect attempts is less than or equal to the second preset value, access to the security chip is not limited by the verification interval time. If the cumulative number of incorrect attempts is greater than the second preset value, the verification interval time is limited to reduce the risk of password leakage caused by frequent verification.

[0050] The third preset value is used to limit the verification interval between the first password and the last verification. The third preset value can be a fixed value, such as 10 minutes, 1 hour or 1 day.

[0051] The third preset value can also be related to the cumulative number of errors. In some embodiments, the method further includes: after updating the cumulative number of errors, reconfiguring the third preset value based on the latest cumulative number of errors. Specifically, the third preset value is positively correlated with the cumulative number of errors; the more cumulative the number of errors, the larger the third preset value. More specifically, the third preset value and the cumulative number of errors are linearly or non-linearly correlated.

[0052] The fourth preset value is used to limit the cumulative number of incorrect password attempts. The fourth preset value is greater than the second preset value and can be an integer greater than 2. For example, the fourth preset value can be 5 times, 10 times, 15 times, etc.

[0053] This application embodiment sets up the above-mentioned cooling mechanism so that if the cumulative number of incorrect password attempts exceeds a second preset value, a certain interval must be waited before the next password verification can be performed. If the cumulative number of incorrect password attempts exceeds a fourth preset value, access to the security chip is prohibited, thereby preventing others from leaking passwords through frequent verification.

[0054] The identification information of a security chip includes, but is not limited to, its authentication information. For example, the security chip's serial number (SN), which is usually composed of a series of numbers or letters, is used to distinguish different individual chips and ensure the chip's legitimacy and security.

[0055] For example, a hash-based message authentication code (HMAC) algorithm is used to hash the first password and the identification information of the security chip to generate a hash value, which is then used as the decryption key. Specifically, based on the first password input by the user and the security chip's serial number (SN), the HMAC algorithm is used to calculate the decryption key, which is then used to decrypt the ciphertext information stored on the security chip to obtain the second password, thus ensuring the security of the second password.

[0056] Step 103: Decrypt the ciphertext information of the first object stored in the security chip based on the decryption key to obtain the second password of the first object;

[0057] The second password is the current password of the first object. The ciphertext information of the second password is stored in the security chip during the last password reset. The second password consists of a series of characters, which can be letters (uppercase or lowercase), numbers, special symbols (such as punctuation marks, spaces, etc.) or combinations thereof. The second password can also be composed of biometric features, image features, physical tokens, or combinations thereof.

[0058] In this embodiment, a security chip is used to store the encrypted information of the current password. With the security chip as the root of trust, if the user forgets the newly changed password after modifying the password of the first object, the password can be reset by using the first password (e.g., the old password before modification). This achieves fast password retrieval while ensuring user data security.

[0059] In some embodiments, the method further includes: deleting the encrypted information of the first object stored in the security chip when a second condition is met, wherein the second condition is a condition for deleting the encrypted information of the first object.

[0060] If the second condition is met, the encrypted information of the first object stored in the security chip is deleted to ensure the security of user data.

[0061] In some embodiments, the second condition includes at least one of the following: the reset interval since the last password reset is greater than a first preset value; the cumulative number of errors in the first password of the first object is greater than a fourth preset value; and a preset operation for the security chip is detected.

[0062] If the time since the last password reset exceeds a first preset value, the encrypted information stored in the security chip will be deleted. In other words, after a user resets their password, the encrypted information stored in the security chip will be physically erased, avoiding the risk of password leakage due to prolonged password storage.

[0063] If the cumulative number of incorrect password attempts for the first user exceeds a fourth preset value, the encrypted information stored in the security chip will be deleted. In other words, if a user attempts to reset their password again after a certain period, and the cumulative number of incorrect password attempts exceeds the fourth preset value, it indicates a potential for password cracking through frequent verification. In this case, the encrypted information stored in the security chip will be physically erased to ensure the security of user data.

[0064] The preset operations include one or more operations that may threaten the data security of the security chip. Upon detecting a preset operation targeting the security chip, the encrypted information stored on the security chip is deleted. This prevents the security chip from being maliciously attacked or cracked, leading to password leakage. For example, the preset operations include at least one of the following: upgrade operations, physical tampering, malware attacks, etc.

[0065] Step 104: Perform a password reset on the first object based on the second password of the first object.

[0066] In some embodiments, the password reset operation may specifically include: outputting a fourth prompt message based on the second password of the first object to prompt the user to enter a third password for resetting the first object; obtaining the third password for resetting the first object; generating an encryption key based on the first password of the first object and the identification information of the security chip; encrypting the third password of the first object based on the encryption key to obtain the ciphertext information of the third password; and replacing the ciphertext information of the second password in the security chip with the ciphertext information of the third password.

[0067] In some embodiments, the encryption key and decryption key are the same key. That is, the HMAC algorithm is used to perform a hash operation on the first password and the identification information of the security chip to generate a hash value, and this hash value is used as the encryption key. Specifically, based on the first password input by the user and the serial number (SN) of the security chip, the HMAC algorithm is used to calculate the encryption key, encrypt the third password, and obtain the ciphertext information of the third password, which is then stored in the security chip.

[0068] The third password is the new password set by the first user. In other words, after a password reset, the newly modified third password can be encrypted and stored in the security chip. If the new password is forgotten again, the third key stored in the security chip can still be used to reset the password using the first password.

[0069] In some embodiments, the method further includes: in response to a second reset operation, obtaining a first password and a second password of a first object; configuring the first password of the first object as an access password for a security chip; generating an encryption key based on the first password of the first object and the identification information of the security chip; encrypting the second password based on the encryption key to obtain ciphertext information of the second password, and storing it in the security chip.

[0070] The second reset operation is the operation that triggers the password reset process. For example, the second reset operation can specifically be a reset operation performed by the user when the old password is known. When the user knows the old password, the old password is configured as the access password for the security chip, and an encryption key is generated using the old password and the security chip's identification information. This newly modified second password is then encrypted and stored.

[0071] By adopting the above technical solution, relying on the high security and reliability of the security chip, the password of the first object is stored. If the user forgets the current password, the password can be reset using the password stored in the security chip. This allows for a quick password reset while ensuring user data security.

[0072] To better illustrate the purpose of this application, further examples are provided based on the above embodiments, such as... Figure 2 As shown, the password backup process during the first reset operation may specifically include:

[0073] Step 201: The user resets their password and retrieves the old first password (passcodeA) and the newly modified second password (passcodeB).

[0074] Step 202: Reset the Applet_A state within the security chip;

[0075] The purpose of resetting the Applet_A state is to allow access to the security chip to store the newly modified second password, passcodeB.

[0076] Step 203: Set the security access password for the security chip to PasscodeA;

[0077] In this way, the user can access the security chip with the old password PasscodeA to obtain the current password;

[0078] Step 204: Call the security chip's storage interface and send PasscodeA and PasscodeB to the security chip's storage interface;

[0079] Step 205: The security chip's storage interface calculates the encryption key using the HMAC algorithm based on parameters such as the security chip SN and PasscodeA;

[0080] The encryption keys generated using this method should adhere to certain security standards to ensure their randomness and unpredictability.

[0081] Step 206: Encrypt passcodeB using the encryption key to obtain and store the ciphertext information of passcodeB.

[0082] Specifically, the passcodeB is encrypted using an encryption key and a selected encryption algorithm, and the secure chip stores the ciphertext information of the passcodeB.

[0083] Furthermore, such as Figure 3 As shown, when performing the second reset operation, the password retrieval process may specifically include:

[0084] Step 301: User resets password;

[0085] Step 302: Was the last reset within 96 hours? If yes, prompt that the retrieval failed; if no, proceed to step 303.

[0086] It should be noted that Applet_A within the security chip monitors the reset interval. If the reset interval is greater than 96 hours, the stored encrypted information is automatically destroyed; if the reset interval is less than or equal to 96 hours, access to the security chip is allowed.

[0087] Step 303: The user enters the first password, passcodeC;

[0088] Step 304: Is it within the cooldown time T? If yes, prompt to try again in X minutes and continue to step 301; if no, proceed to step 305.

[0089] Step 305: Security chip verification passcodeC;

[0090] Step 306: Determine if passcodeC and passcodeA are consistent. If they are consistent, the verification passes and proceed to step 307; if they are inconsistent, the verification fails and proceed to step 310.

[0091] Step 307: Calculate the decryption key using the security chip SN and passcodeA;

[0092] Step 308: Decrypt passcodeB using the decryption key;

[0093] Step 309: The system resets the password based on passcodeB;

[0094] Step 310: Update the cumulative error count N;

[0095] Step 311: Is the cumulative number of errors N greater than 3? If not, continue to step 301; if yes, proceed to step 312.

[0096] Step 312: Is the cumulative number of errors N greater than 10? If not, proceed to step 313; if yes, proceed to step 314.

[0097] Step 313: Set the cooldown time T = 1 + 2^(N-2) minutes;

[0098] Step 314: The security chip deletes the stored encrypted information.

[0099] It should be noted that the Applet_A inside the security chip also monitors the cumulative number of errors. If the cumulative number of errors exceeds 10, the stored encrypted information will also be automatically destroyed.

[0100] Furthermore, such as Figure 4 As shown, when performing the second password reset operation, the password backup process may include:

[0101] Step 401: The user resets their password and obtains the newly modified third password, passcodeD;

[0102] Step 402: Call the security chip's storage interface and send PasscodeD to the security chip's storage interface;

[0103] Step 403: The security chip's storage interface calculates the encryption key using the HMAC algorithm based on parameters such as the security chip SN and PasscodeA;

[0104] Step 404: Encrypt passcodeD using the encryption key to obtain and store the ciphertext information of passcodeD.

[0105] In other words, if the time between this reset and the last reset is less than 96 hours, the encrypted information of the last reset password will be replaced with the encrypted information of the current reset password, passcodeB. If the time between this reset and the last reset is less than 96 hours, the security chip has already destroyed the stored encrypted information and directly stored the encrypted information of the current reset password, passcodeB, into the security chip.

[0106] The above password reset method relies on the high security and reliability of the security chip to encrypt and back up the password to the security chip. If the user forgets to set the password, the backup password in the security chip can be used to quickly reset the password, solving the problem of the user forgetting the newly changed password after resetting the password.

[0107] To implement the method of the embodiments of this application, based on the same inventive concept, the embodiments of this application also provide a password reset device, such as... Figure 5 As shown, the password reset device 50 includes:

[0108] The acquisition unit 501 is used to acquire the first password of the first object in response to the first reset operation;

[0109] The first processing unit 502 is used to generate a decryption key based on the first password of the first object and the identification information of the security chip;

[0110] The first processing unit 502 is also used to decrypt the ciphertext information of the first object stored in the security chip based on the decryption key to obtain the second password of the first object;

[0111] The second processing unit 503 is used to perform a password reset on the first object based on the second password of the first object.

[0112] In some embodiments, the first processing unit 502 is further configured to, in response to the first reset operation, obtain the reset interval time since the last password reset; if the reset interval time is less than or equal to a first preset value, output a first prompt message to prompt the user to enter the first password of the first object; if the reset interval time is greater than the first preset value, output a second prompt message to prompt the user that the password retrieval failed.

[0113] In some embodiments, the first processing unit 502 is configured to generate a decryption key based on the first password of the first object and the identification information of the security chip when a first condition is met, wherein the first condition is the access condition of the security chip.

[0114] In some embodiments, the first condition includes: access to the security chip is permitted; and the first password of the first object is consistent with the access password of the security chip.

[0115] In some embodiments, the first processing unit 502 is further configured to update the cumulative error count when the first password of the first object and the access password of the security chip are inconsistent; determine that the security chip is allowed to access when the cumulative error count is less than or equal to a second preset value; and determine that the security chip is allowed to access when the cumulative error count is greater than the second preset value and the verification interval between the first password and the last verification is greater than a third preset value.

[0116] In some embodiments, the first processing unit 502 is further configured to determine that the security chip is not allowed to access when the cumulative number of errors is greater than a second preset value and the verification interval time from the last verification is less than or equal to a third preset value, and output a third prompt message to prompt the user to enter the first password of the first object again after the first interval time to reset the password; and to determine that the security chip is not allowed to access when the cumulative number of errors is greater than a fourth preset value.

[0117] In some embodiments, the third preset value is related to the cumulative number of errors. The first processing unit 502 is further configured to reconfigure the third preset value based on the latest cumulative number of errors after updating the cumulative number of errors.

[0118] In some embodiments, the first processing unit 502 is further configured to delete the encrypted information of the first object stored in the security chip when a second condition is met, wherein the second condition is the condition for deleting the encrypted information of the first object.

[0119] In some embodiments, the second condition includes at least one of the following:

[0120] The time interval since the last password reset is greater than the first preset value;

[0121] The cumulative number of incorrect password attempts for the first object is greater than the fourth preset value;

[0122] A preset operation targeting the security chip was detected.

[0123] In some embodiments, the second processing unit 503 is configured to output a fourth prompt message based on the second password of the first object, so as to prompt the user to enter a third password for resetting the first object;

[0124] The acquisition unit 501 is also used to acquire the third password reset by the first object;

[0125] The first processing unit 502 is further configured to generate an encryption key based on the first password of the first object and the identification information of the security chip; encrypt the third password of the first object based on the encryption key to obtain the ciphertext information of the third password; and replace the ciphertext information of the second password in the security chip with the ciphertext information of the third password.

[0126] In some embodiments, the acquisition unit 501 is further configured to acquire the first password and the second password of the first object in response to the second reset operation;

[0127] The first processing unit 502 is further configured to configure the first password of the first object as the access password of the security chip; generate an encryption key based on the first password of the first object and the identification information of the security chip; encrypt the second password based on the encryption key to obtain the ciphertext information of the second password, and store it in the security chip.

[0128] In practical applications, the aforementioned device can be a final electronic device or a chip applied to an electronic device. In this application, the device can implement the functions of multiple units through software, hardware, or a combination of both, enabling the device to execute the password reset method provided in any of the above embodiments. Furthermore, the technical effects of each technical solution of the device can be referenced to the technical effects of the corresponding technical solutions in the password reset method, and will not be elaborated upon further in this application.

[0129] Based on the hardware implementation of each unit in the above-mentioned password reset device, this application embodiment also provides an electronic device, such as... Figure 6 As shown, the electronic device 60 includes: a processor 601 and a memory 602 configured to store computer programs capable of running on the processor;

[0130] The processor 601 is configured to execute the method steps in the foregoing embodiments when running a computer program.

[0131] Of course, in practical applications, such as Figure 6 As shown, the various components in the electronic device 60 are coupled together via a bus system 603. It is understood that the bus system 603 is used to enable communication between these components. In addition to a data bus, the bus system 603 also includes a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled as bus system 603 in the figure.

[0132] In practical applications, the aforementioned processor can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field-Programmable Gate Array (FPGA), controller, microcontroller, and microprocessor. It is understood that, for different devices, the electronic devices used to implement the functions of the aforementioned processor can also be other types, and the embodiments of this application do not specifically limit this.

[0133] The aforementioned memory can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provides instructions and data to the processor.

[0134] The aforementioned electronic devices may include devices that require password reset, such as mobile phones, tablets, laptops, handheld computers, personal digital assistants (PDAs), portable media players (PMPs), navigation devices, wearable devices, smart bracelets, cameras, etc.

[0135] Figure 7 This is a schematic structural diagram of the security chip according to an embodiment of this application. Figure 7 The security chip 70 shown includes a processor 710 and a memory 720. The memory 720 is used to store the encrypted information of the first object and to store a computer program. The processor 710 can call and run the computer program from the memory to implement the method in the embodiments of this application.

[0136] The memory 720 can be a separate device independent of the processor 710, or it can be integrated into the processor 710.

[0137] Optionally, the security chip 70 may further include an input interface 730. The processor 710 can control the input interface 730 to communicate with other devices or security chips; specifically, it can acquire information or data sent by other devices or security chips.

[0138] Optionally, the security chip 70 may also include an output interface 740. The processor 710 can control the output interface 740 to communicate with other devices or security chips; specifically, it can output information or data to other devices or security chips.

[0139] Optionally, the security chip can be applied to electronic devices, and the security chip can implement the corresponding processes of the various methods in the embodiments of this application. For the sake of brevity, these will not be described in detail here.

[0140] In an exemplary embodiment, this application also provides a computer-readable storage medium, such as a memory including a computer program, which can be executed by a processor of an electronic device or a security chip to perform the steps of the aforementioned method.

[0141] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in any one of the embodiments of this application.

[0142] Optionally, the computer program product can be applied to the electronic device or security chip in the embodiments of this application, and the computer program instructions cause the computer to execute the corresponding processes implemented by the electronic device or security chip in the various methods of the embodiments of this application. For the sake of brevity, they will not be described in detail here.

[0143] This application also provides a computer program.

[0144] Optionally, the computer program can be applied to the electronic device or security chip in the embodiments of this application. When the computer program is run on a computer, it causes the computer to execute the corresponding processes implemented by the electronic device or security chip in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0145] It should be understood that in the embodiments of this application, user data such as passwords are involved. When the embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0146] It should be understood that the terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items. The expressions “having,” “may have,” “comprising,” and “including,” or “may include” and “may contain” used herein may be used to indicate the presence of a corresponding feature (e.g., an element such as a number, function, operation, or component), but do not exclude the presence of additional features.

[0147] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another, and are not necessarily used to describe a specific order or sequence. For example, without departing from the scope of this invention, first information may also be referred to as second information, and similarly, second information may also be referred to as first information.

[0148] The technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0149] In the several embodiments provided in this application, it should be understood that the disclosed methods, apparatus, and devices can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical, or other forms.

[0150] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0151] In addition, each functional unit in the various embodiments of this application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0152] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A password reset method, characterized in that, The method includes: In response to the first reset operation, obtain the first password of the first object; A decryption key is generated based on the first password of the first object and the identification information of the security chip; Based on the decryption key, the encrypted information of the first object stored in the security chip is decrypted to obtain the second password of the first object; The password of the first object is reset based on the second password of the first object.

2. The method according to claim 1, characterized in that, The method further includes: In response to the first reset operation, obtain the reset interval since the last password reset; If the reset interval is less than or equal to a first preset value, a first prompt message is output to prompt the user to enter the first password of the first object; If the reset interval is greater than the first preset value, a second prompt message is output to indicate to the user that the password retrieval has failed.

3. The method according to claim 1, characterized in that, The method further includes: If the first condition is met, a decryption key is generated based on the first password of the first object and the identification information of the security chip, wherein the first condition is the access condition of the security chip.

4. The method according to claim 3, characterized in that, The first condition includes: The security chip is allowed access; The first password of the first object is the same as the access password of the security chip.

5. The method according to claim 4, characterized in that, The method further includes: If the first password of the first object and the access password of the security chip are inconsistent, update the cumulative number of errors; If the cumulative number of errors is less than or equal to a second preset value, it is determined that the security chip is allowed to be accessed. If the cumulative number of errors exceeds a second preset value, and the verification interval between the first password and the last verification exceeds a third preset value, then the security chip is determined to be allowed access.

6. The method according to claim 5, characterized in that, The method further includes: If the cumulative number of errors is greater than the second preset value and the verification interval from the last verification is less than or equal to the third preset value, it is determined that the security chip does not allow access, and a third prompt message is output to prompt the user to enter the first password of the first object again after the first interval time to reset the password. If the cumulative number of errors exceeds a fourth preset value, it is determined that the security chip is not allowed to be accessed.

7. The method according to claim 5, characterized in that, The third preset value is related to the cumulative number of errors, and the method further includes: After updating the cumulative error count, the third preset value is reconfigured based on the latest cumulative error count.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: If the second condition is met, the encrypted information of the first object stored in the security chip is deleted. The second condition is the condition for deleting the encrypted information of the first object.

9. The method according to claim 8, characterized in that, The second condition includes at least one of the following: The time interval since the last password reset is greater than the first preset value; The cumulative number of incorrect password attempts for the first object is greater than a fourth preset value; A preset operation targeting the security chip was detected.

10. The method according to claim 1, characterized in that, The step of resetting the password of the first object based on the second password of the first object includes: Based on the second password of the first object, a fourth prompt message is output to prompt the user to enter the third password reset by the first object; Obtain the third password reset by the first object; An encryption key is generated based on the first password of the first object and the identification information of the security chip; The third password of the first object is encrypted based on the encryption key to obtain the ciphertext information of the third password; In the security chip, the ciphertext information of the second password is replaced with the ciphertext information of the third password.

11. The method according to claim 1, characterized in that, The method further includes: In response to the second reset operation, obtain the first password and the second password of the first object; Configure the first password of the first object as the access password of the security chip; An encryption key is generated based on the first password of the first object and the identification information of the security chip; The second password is encrypted using the encryption key to obtain the ciphertext information of the second password, which is then stored in the security chip.

12. A password reset device, characterized in that, The device includes: The acquisition unit is used to acquire the first password of the first object in response to the first reset operation; The first processing unit is used to generate a decryption key based on the first password of the first object and the identification information of the security chip; The first processing unit is further configured to decrypt the ciphertext information of the first object stored in the security chip based on the decryption key to obtain the second password of the first object; The second processing unit is configured to perform a password reset on the first object based on the second password of the first object.

13. An electronic device, comprising: The processor and the memory used to store computer programs that can run on the processor. The memory is used to store computer programs, and the processor is used to call and run the computer programs stored in the memory to perform the steps of the method as described in any one of claims 1-11.

14. A security chip, comprising: A processor and a memory, the memory being used to store encrypted information of the first object and to store a computer program; The processor is configured to retrieve and run a computer program from memory, causing the device equipped with the security chip to perform the method as described in any one of claims 1-11.

15. A computer-readable storage medium for storing a computer program that causes a computer to perform the steps of the method as claimed in any one of claims 1-11.