Weak password rapid checking method, apparatus, and device

By generating detection hash IDs and querying historical detection data, or encrypting and matching passwords in weak password libraries, the problems of wasted computing resources and inefficiency in existing weak password verification methods are solved, and fast and efficient weak password detection is achieved.

WO2025092581A1PCT designated stage expired Publication Date: 2025-05-08E-SURFING DIGITAL LIFE TECH CO LTD

Patent Information

Application Number
PCT/CN2024/127268
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-01
Filing Date
2024-10-25
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

The existing weak password verification methods are wasteful and inefficient in computing resources, especially when facing a large number of encrypted passwords containing different salt values, resulting in waste of resources and inefficient in detection.

Method used

By obtaining the target verification password and the encryption rules to which it belongs, a hash algorithm is used to generate the detection hash ID, and historical detection data is queried from the historical detection result library. If it exists, historical data is used as the result. Otherwise, the password in the weak password library is encrypted and matched to the target password. If it matches, it is determined to be a weak password.

Benefits of technology

This greatly accelerates the speed of daily repetitive weak password detection verification, reduces waste of computing resources, improves verification efficiency, and solves the problems of wasteful resources and inefficiency in existing methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024127268_08052025_PF_FP_ABST
    Figure CN2024127268_08052025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a weak password rapid checking method, apparatus, and device. For an encrypted password, a hash algorithm is used for generating a detection hash ID on the basis of a target checked password, an encryption rule to which same belongs, and a weak password library version number; if historical detection data is not present, then a password encryption mode corresponding to an obtained encryption rule is used to encrypt passwords in the weak password library one by one; matching is performed on encryption results and the target checked password: if the result is a match, then it is determined that the target checked password is a weak password and the weak password checking result is outputted; otherwise, it is determined that the target checked password is not a weak password and the weak password checking result is outputted; and, if historical detection data is present, then a historical detection result is used as a current detection result, thus greatly increasing the speed of daily, repeated weak password detection and checking, reducing the computing resources used, and solving the technical problems of excessive computing resource waste and low efficiency in existing weak password checking methods.
Need to check novelty before this filing date? Find Prior Art

Description

A method, device and equipment for quickly verifying weak passwords Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device and equipment for quickly verifying weak passwords. Background Art

[0002] With the development of the internet, weak passwords remain a persistent security challenge. Currently, there are many methods for weak password collision detection, but few methods for effectively improving weak password verification. A common approach to improving efficiency is to pre-encrypt the passwords in the weak password database according to encryption rules and then compare the ciphertext with the pre-encrypted result. However, this method only effectively improves efficiency for encryption algorithms without salts. Many password encryption methods on the market use a different salt for each password. If the weak passwords in the weak password database are encrypted for each different salt value, the pre-encrypted database will be too large and will not effectively improve efficiency. For example, if an enterprise needs to verify 200,000 passwords on a daily basis and the weak password database contains 30,000 weak passwords, 200,000 different salt values ​​for 200,000 passwords multiplied by 30,000 weak passwords will generate 6 billion data entries, resulting in a significant waste of resources and low efficiency. Therefore, how to reduce the computing resources required for weak password verification and improve its efficiency is a technical problem that needs to be solved by those skilled in the art.

[0003] Summary of the Invention

[0004] The present invention provides a method, device and equipment for quickly verifying weak passwords, which are used to solve the technical problems of excessive waste of computing resources and low efficiency in existing weak password verification methods.

[0005] In view of this, a first aspect of the present invention provides a method for quickly verifying weak passwords, comprising the following steps:

[0006] S1. Obtain the target verification password and the corresponding encryption rule. The target verification password is plain text with a salt value or ciphertext encrypted according to the encryption rule. The salt value can be empty.

[0007] S2. Obtain the encryption rule and password storage rule of the target verification password from the encryption rule library according to the encryption rule, and determine whether the target verification password is a plaintext password according to the encryption rule. If the target verification password is not a plaintext password, execute step S3;

[0008] S3. Generate a detection hash ID using a hash algorithm based on the target verification password, the obtained encryption rules, and the pre-configured weak password version number. Query historical detection data from the historical detection result library based on the detection hash ID. If historical detection data is found, jump to step S6. If no historical detection data is found, execute step S4.

[0009] S4. Use the password encryption method corresponding to the obtained encryption rule to encrypt the passwords in the weak password database one by one, obtain an encryption result, and execute step S5;

[0010] S5. Match the encryption result with the target verification password. If the matching results are consistent, determine that the target verification password is a weak password and output the weak password verification result. Otherwise, determine that the target verification password is not a weak password and output the weak password verification result.

[0011] S6. Output the retrieved historical detection data as the result of this weak password verification.

[0012] Optionally, it also includes:

[0013] S7. Store the weak password verification result and the detection hash ID in the historical detection result database;

[0014] Step S5 specifically includes:

[0015] The encryption result is matched with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output, and the process jumps to step S7. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output, and the process jumps to step S7.

[0016] Step S6 specifically includes:

[0017] S6. Output the retrieved historical detection data as the weak password verification result, and execute step S7.

[0018] Optionally, step S2 further includes:

[0019] If the target verification password is a plain text password, the target verification password will be matched with the passwords in the weak password library one by one. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output. The target verification password, the encryption rule to which it belongs and the weak password verification result are stored in the historical detection result library.

[0020] Optionally, query historical test data from a historical test result library based on the test hash ID, including:

[0021] Query the local historical detection data cache according to the detection hash ID. If historical detection data exists, the corresponding cache result is returned. Otherwise, query the Redis historical detection data cache according to the detection hash ID. If historical detection data exists, the corresponding cache result is returned and written to the local historical detection data cache. Otherwise, query the Mysq1 database historical detection data according to the detection hash ID. If historical detection data exists, the queried historical detection data is returned and written to the Redis historical detection data cache and the local historical detection data cache. Otherwise, return that no historical detection data was queried.

[0022] Optionally, the encryption rule is SHA-512 encryption, BCrypt encryption, or pbkdf2 encryption.

[0023] The second aspect of the present invention provides a device for quickly checking weak passwords, comprising the following modules:

[0024] The password acquisition module is used to obtain the target verification password and the corresponding encryption rules. The target verification password is a plain text with a salt value or a ciphertext encrypted according to the encryption rule. The salt value can be empty.

[0025] a password type determination module, configured to obtain the encryption rule and password storage rule of the target verification password from an encryption rule library according to the encryption rule, determine whether the target verification password is a plaintext password according to the encryption rule, and jump to the hash ID generation module if the target verification password is not a plaintext password;

[0026] The hash ID generation module is used to generate a detection hash ID using a hash algorithm based on the target verification password, the obtained encryption rules, and the pre-configured weak password version number. The module then queries the historical detection data from the historical detection result library based on the detection hash ID. If the historical detection data exists, the module jumps to the result output module. If no historical detection data is found, the module jumps to the encryption module.

[0027] The encryption module is used to encrypt the passwords in the weak password library one by one using the password encryption method corresponding to the obtained encryption rule, obtain the encryption result, and jump to the password verification module;

[0028] A password verification module is used to match the encryption result with the target verification password. If the matching results are consistent, it is determined that the target verification password is a weak password and outputs the weak password verification result. Otherwise, it is determined that the target verification password is not a weak password and outputs the weak password verification result.

[0029] The result output module is used to output the queried historical detection data as the result of this weak password verification.

[0030] Also includes:

[0031] The storage module is used to store the weak password verification result and the detection hash ID in the historical detection result library;

[0032] The password verification module is specifically used to:

[0033] The encryption result is matched with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output, and the process jumps to the storage module. Otherwise, the target verification password is determined to be not a weak password and the weak password verification result is output, and the process jumps to the storage module.

[0034] The result output module is specifically used for:

[0035] The queried historical detection data is output as the result of this weak password verification and jumped to the storage module.

[0036] Optionally, the password type determination module is further configured to:

[0037] If the target verification password is a plain text password, the target verification password will be matched with the passwords in the weak password library one by one. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output. The target verification password, the encryption rule to which it belongs and the weak password verification result are stored in the historical detection result library.

[0038] Optionally, in the password type determination module, historical detection data is queried from a historical detection result library according to the detection hash ID, including:

[0039] Query the local historical detection data cache according to the detection hash ID. If historical detection data is found, the corresponding cache result is returned. Otherwise, query the Redis historical detection data cache according to the detection hash ID. If historical detection data is found, the corresponding cache result is returned and written to the local historical detection data cache. Otherwise, query the Mysql database historical detection data according to the detection hash ID. If historical detection data is found, the queried historical detection data is returned and written to the Redis historical detection data cache and the local historical detection data cache. Otherwise, return that no historical detection data was found.

[0040] A third aspect of the present invention provides a device for quickly checking weak passwords, the device comprising a processor and a memory:

[0041] The memory is used to store program code and transmit the program code to the processor;

[0042] The processor is used to execute any one of the weak password rapid verification methods described in the first aspect according to the instructions in the program code.

[0043] From the above technical solutions, it can be seen that the method for quickly verifying weak passwords provided by the present invention has the following advantages:

[0044] The weak password rapid verification method provided by the present invention, for encrypted passwords, uses a hash algorithm to generate a detection hash ID according to the target verification password, the encryption rule to which it belongs and the version number of the weak password library; if there is no historical detection data, the passwords in the weak password library are encrypted one by one using the password encryption method corresponding to the obtained encryption rule, and the encryption result is matched with the target verification password; if the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output; otherwise, the target verification password is determined to be not a weak password and the weak password verification result is output; if there is historical detection data, the historical detection result is used as the current detection result, which greatly speeds up the speed of daily repeated weak password detection and verification, and also reduces computing resources, thereby solving the technical problems of excessive waste of computing resources and low efficiency of existing weak password verification methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0046] FIG1 is a schematic diagram of a flow chart of a method for quickly verifying a weak password provided in an embodiment of the present invention;

[0047] FIG2 is a logic block diagram of a method for quickly verifying a weak password provided in an embodiment of the present invention;

[0048] FIG3 is a schematic structural diagram of a device for quickly verifying weak passwords provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0049] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0050] For ease of understanding, please refer to Figures 1 and 2. The present invention provides an embodiment of a method for quickly verifying a weak password, including:

[0051] S1. Obtain the target verification password and the corresponding encryption rule. The target verification password is a plain text containing a salt value or a cipher text encrypted according to the encryption rule. The salt value can be empty.

[0052] It should be noted that, in the present invention, the target verification password and the corresponding encryption rule are first obtained. The target verification password is a plain text containing a salt value or a cipher text encrypted according to the encryption rule. The salt value may be empty.

[0053] S2. According to the encryption rules, the encryption rules and password storage rules of the target verification password are obtained from the encryption rule library, and it is determined whether the target verification password is a plain text password according to the encryption rules. If the target verification password is not a plain text password, step S3 is executed.

[0054] It should be noted that common password encryption methods, such as those used in the Linux operating system, Nacos, and Harbor, can be collected to form an encryption rule library that includes password storage formats and encryption methods. The encryption rule library uses different encryption methods for password collision based on different encryption rules, such as SHA-512, BCrypt, pbkdf2, and MD5, and is highly scalable.

[0055] If the target verification password is not a plaintext password, step S3 is executed. If the target verification password is a plaintext password, the target verification password is matched with the passwords in the weak password library one by one. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output. Otherwise, the target verification password is determined to be not a weak password and the weak password verification result is output. The target verification password, the encryption rule to which it belongs, and the weak password verification result are stored in the historical detection result library.

[0056] S3. Based on the target verification password, the obtained encryption rules and the pre-configured weak password version number, a hash algorithm is used to generate a detection hash ID. Based on the detection hash ID, historical detection data is queried from the historical detection result library. If historical detection data is found, jump to step S6. If no historical detection data is found, execute step S4.

[0057] It should be noted that the method for generating a detection hash ID is: concatenate the submitted password (ciphertext, which may include salt value), encryption rule identifier (the unique identifier of the corresponding encryption rule in the encryption rule library), and weak password library version number in order, and use the SHA-512 hash algorithm to calculate the concatenated string to generate a detection hash ID.

[0058] The specific process of querying historical detection data from the historical detection result library according to the detection hash ID is as follows: query the local historical detection data cache according to the detection hash ID. If the historical detection data is found, the corresponding cache result is returned. Otherwise, query the Redis historical detection data cache according to the detection hash ID. If the historical detection data is found, the corresponding cache result is returned and written to the local historical detection data cache. Otherwise, query the Mysql database historical detection data according to the detection hash ID. If the historical detection data is found, the queried historical detection data is returned and written to the Redis historical detection data cache and the local historical detection data cache. Otherwise, return that no historical detection data was found.

[0059] S4. Use the password encryption method corresponding to the obtained encryption rule to encrypt the passwords in the weak password library one by one to obtain an encryption result, and then execute step S5.

[0060] It should be noted that the default passwords of common middleware, operating systems, databases, etc. and the commonly used weak passwords on the Internet can be collected to form a weak password library.

[0061] For encryption rules, the Linux operating system uses SHA-512 encryption, Nacos uses BCrypt encryption, and Harbor uses pbkdf2 encryption.

[0062] S5. Match the encryption result with the target verification password. If the matching results are consistent, determine that the target verification password is a weak password and output the weak password verification result. Otherwise, determine that the target verification password is not a weak password and output the weak password verification result.

[0063] S6. Output the retrieved historical detection data as the result of this weak password verification.

[0064] In one embodiment, after step S6, the method further includes:

[0065] S7. Store the weak password verification result and the detection hash ID in the historical detection result library.

[0066] Correspondingly, step S5 specifically includes:

[0067] The encryption result is matched with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output, and the process jumps to step S7. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output, and the process jumps to step S7.

[0068] Step S6 specifically includes:

[0069] S6. Output the retrieved historical detection data as the weak password verification result, and execute step S7.

[0070] It should be noted that the historical detection result library is used for the rapid verification of weak passwords. After each detection is completed, the target verification password, the corresponding encryption rule, and the weak password library version number are used to generate a detection hash ID using a hash algorithm, as well as the detection results, and are stored in the database to form a historical detection result library. The next time the same password, the same encryption rule, and the same weak password library version number are used for verification and detection, the historical detection result is directly taken as the current result to reduce the encryption time required for repeated password detection and the waste of computing resources.

[0071] Taking the example of an enterprise that needs to verify 200,000 passwords on a daily basis, the weak password library contains 30,000 weak passwords. There are 200,000 different salt values ​​for 200,000 passwords, and multiplying them by 30,000 weak passwords will generate 6 billion pieces of data, resulting in a huge waste of resources and low efficiency. The weak password rapid verification method provided by the present invention generates a hash value ID based on the password to be detected, encryption rules, and weak password library version number. In the above case, only 200,000 pieces of data need to be generated, which can greatly improve the detection efficiency in the scenario of daily weak password verification in enterprises.

[0072] The weak password rapid verification method provided by the present invention, for encrypted passwords, uses a hash algorithm to generate a detection hash ID according to the target verification password, the encryption rule to which it belongs and the version number of the weak password library; if there is no historical detection data, the passwords in the weak password library are encrypted one by one using the password encryption method corresponding to the obtained encryption rule, and the encryption result is matched with the target verification password; if the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output; otherwise, the target verification password is determined to be not a weak password and the weak password verification result is output; if there is historical detection data, the historical detection result is used as the current detection result, which greatly speeds up the speed of daily repeated weak password detection and verification, and also reduces computing resources, thereby solving the technical problems of excessive waste of computing resources and low efficiency of existing weak password verification methods.

[0073] For ease of understanding, please refer to FIG3 . The present invention provides an embodiment of a device for quickly checking weak passwords, including the following modules:

[0074] The password acquisition module is used to obtain the target verification password and the corresponding encryption rules. The target verification password is a plain text with a salt value or a ciphertext encrypted according to the encryption rule. The salt value can be empty.

[0075] a password type determination module, configured to obtain the encryption rule and password storage rule of the target verification password from an encryption rule library according to the encryption rule, determine whether the target verification password is a plaintext password according to the encryption rule, and jump to the hash ID generation module if the target verification password is not a plaintext password;

[0076] The hash ID generation module is used to generate a detection hash ID using a hash algorithm based on the target verification password, the obtained encryption rules, and the pre-configured weak password version number. The module then queries the historical detection data from the historical detection result library based on the detection hash ID. If the historical detection data exists, the module jumps to the result output module. If no historical detection data is found, the module jumps to the encryption module.

[0077] The encryption module is used to encrypt the passwords in the weak password library one by one using the password encryption method corresponding to the obtained encryption rule, obtain the encryption result, and jump to the password verification module;

[0078] A password verification module is used to match the encryption result with the target verification password. If the matching results are consistent, it is determined that the target verification password is a weak password and outputs the weak password verification result. Otherwise, it is determined that the target verification password is not a weak password and outputs the weak password verification result.

[0079] The result output module is used to output the queried historical detection data as the result of this weak password verification.

[0080] Also includes:

[0081] The storage module is used to store the weak password verification result and the detection hash ID in the historical detection result library;

[0082] The password verification module is specifically used to:

[0083] The encryption result is matched with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output, and the process jumps to the storage module. Otherwise, the target verification password is determined to be not a weak password and the weak password verification result is output, and the process jumps to the storage module.

[0084] The result output module is specifically used for:

[0085] The queried historical detection data is output as the result of this weak password verification and jumped to the storage module.

[0086] The password type judgment module is also used to:

[0087] If the target verification password is a plain text password, the target verification password will be matched with the passwords in the weak password library one by one. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output. The target verification password, the encryption rule to which it belongs and the weak password verification result are stored in the historical detection result library.

[0088] In the password type judgment module, historical detection data is queried from the historical detection result library based on the detection hash ID, including:

[0089] Query the local historical detection data cache according to the detection hash ID. If historical detection data is found, the corresponding cache result is returned. Otherwise, query the Redis historical detection data cache according to the detection hash ID. If historical detection data is found, the corresponding cache result is returned and written to the local historical detection data cache. Otherwise, query the Mysql database historical detection data according to the detection hash ID. If historical detection data is found, the queried historical detection data is returned and written to the Redis historical detection data cache and the local historical detection data cache. Otherwise, return that no historical detection data was found.

[0090] The encryption rule is SHA-512 encryption, BCrypt encryption, or pbkdf2 encryption.

[0091] The present invention provides an embodiment of a device for quickly checking weak passwords, the device comprising a processor and a memory:

[0092] The memory is used to store program code and transmit the program code to the processor;

[0093] The processor is used to execute the weak password rapid verification method provided in the present invention according to the instructions in the program code.

[0094] The weak password rapid verification device and equipment provided in the present invention are used to execute the weak password rapid verification method provided in the present invention. Its principles and technical effects are the same as those of the weak password rapid verification method provided in the present invention, and will not be repeated here.

[0095] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for quickly checking weak passwords, characterized in that: The following steps are involved: S1. Obtain the target verification password and the corresponding encryption rule. The target verification password is a plain text containing a salt value or a ciphertext encrypted according to the encryption rule. The salt value can be empty. S2. According to the encryption rule, the encryption rule and password storage rule of the target verification password are obtained from the encryption rule library, and whether the target verification password is a plain text password is determined according to the encryption rule. If the target verification password is not a plain text password, step S3 is executed; S3, according to the target verification password, the obtained encryption rules and the pre-configured weak password version number, a detection hash ID is generated by using a hash algorithm, and historical detection data is queried from the historical detection result library according to the detection hash ID. If historical detection data exists, jump to step S6, if no historical detection data is found, execute step S4; S4. Use the password encryption method corresponding to the obtained encryption rule to encrypt the passwords in the weak password library one by one, obtain an encryption result, and execute step S5; S5. Match the encryption result with the target verification password. If the matching results are consistent, determine that the target verification password is a weak password and output the weak password verification result. Otherwise, determine that the target verification password is not a weak password and output the weak password verification result. S6. Output the retrieved historical detection data as the result of this weak password verification.

2. The method for rapid verification of weak passwords according to claim 1 is characterized in that: Also includes: S7, storing the weak password verification result and the detection hash ID in the historical detection result library; Step S5 specifically includes: The encryption result is matched with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output, and the process jumps to step S7. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output, and the process jumps to step S7. Step S6 specifically includes: S6. Output the retrieved historical detection data as the weak password verification result and execute step S7.

3. The method for rapid verification of weak passwords according to claim 1 is characterized in that: Step S2 also includes: If the target verification password is a plain text password, the target verification password will be matched with the passwords in the weak password library one by one. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output. The target verification password, the encryption rules to which it belongs, and the weak password verification result are stored in the historical detection result library.

4. The method for rapid verification of weak passwords according to claim 1 is characterized in that: In step S3, historical test data is queried from the historical test result library according to the test hash ID, including: Query the local historical detection data cache according to the detection hash ID. If historical detection data exists, return the corresponding cache result. Otherwise, query the Redis historical detection data cache according to the detection hash ID. If historical detection data exists, return the corresponding cache result and write it to the local historical detection data cache. Otherwise, query the Mysql database historical detection data according to the detection hash ID. If historical detection data exists, return the queried historical detection data and write it to the Redis historical detection data cache and the local historical detection data cache. Otherwise, return that no historical detection data was found.

5. The method for rapid verification of weak passwords according to claim 1 is characterized in that: The encryption rule is SHA-512 encryption, BCrypt encryption or pbkdf2 encryption.

6. A device for quickly checking weak passwords, characterized in that: Includes the following modules: The password acquisition module is used to obtain the target verification password and the corresponding encryption rules. The target verification password is a plain text containing a salt value or a ciphertext encrypted according to the encryption rule. The salt value can be empty. A password type judgment module, used to obtain the encryption rule and password storage rule of the target verification password from the encryption rule library according to the corresponding encryption rule, and determine whether the target verification password is a plain text password according to the encryption rule. If the target verification password is not a plain text password, jump to the hash ID generation module; The hash ID generation module is used to generate a detection hash ID using a hash algorithm according to the target verification password, the obtained encryption rules and the pre-configured weak password version number, and query the historical detection data from the historical detection result library according to the detection hash ID. If the historical detection data exists, it jumps to the result output module; if the historical detection data is not found, it jumps to the encryption module; The encryption module is used to encrypt the passwords in the weak password library one by one using the password encryption method corresponding to the encryption rule obtained, obtain the encryption result, and jump to the password verification module; A password verification module is used to match the encryption result with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output; otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output; The result output module is used to output the queried historical detection data as the result of this weak password verification.

7. The device for rapid checking of weak passwords according to claim 6, characterized in that: Also includes: A storage module is used to store the weak password verification result and the detection hash ID in the historical detection result library; The password verification module is specifically used for: The encryption result is matched with the target verification password. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output, and the process jumps to the storage module. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output, and the process jumps to the storage module. The result output module is specifically used for: The queried historical detection data is output as the result of this weak password verification and jumped to the storage module.

8. The device for rapid checking of weak passwords according to claim 6, characterized in that: The password type determination module is also used to: If the target verification password is a plain text password, the target verification password will be matched with the passwords in the weak password library one by one. If the matching results are consistent, the target verification password is determined to be a weak password and the weak password verification result is output. Otherwise, the target verification password is determined not to be a weak password and the weak password verification result is output. The target verification password, the encryption rules to which it belongs, and the weak password verification result are stored in the historical detection result library.

9. The device for rapid checking of weak passwords according to claim 6, characterized in that: In the password type judgment module, historical detection data is queried from the historical detection result library according to the detection hash ID, including: Query the local historical detection data cache according to the detection hash ID. If historical detection data exists, return the corresponding cache result. Otherwise, query the Redis historical detection data cache according to the detection hash ID. If historical detection data exists, return the corresponding cache result and write it to the local historical detection data cache. Otherwise, query the Mysql database historical detection data according to the detection hash ID. If historical detection data exists, return the queried historical detection data and write it to the Redis historical detection data cache and the local historical detection data cache. Otherwise, return that no historical detection data was found.

10. A device for quickly checking weak passwords, characterized in that: The device comprises a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is used to execute the weak password rapid verification method described in any one of claims 1-5 according to the instructions in the program code.

Citation Information

Patent Citations

  • Weak password checking method and system

    CN105406976A

  • Weak password rapid comparison and searching method

    CN106411530A

  • User password detection method, equipment, device and storage medium

    CN110071917A

  • Weak password quick checking method, device and equipment

    CN117499102A

  • Weak password detection method and device based on deep learning, and electronic device

    US20230315835A1

Cited By

  • Multi-strategy fusion password detection method and system and medium

    CN120768557A

  • A multi-strategy fusion password detection method, system and medium

    CN120768557B