Password detection method, server end, user end, and password detection system
By prestoring the target password on the server and generating the second key using the same encryption algorithm for decryption, the problem of low security in the symmetric PAKE protocol and the inability to detect weak passwords in the asymmetric aPAKE protocol is solved, and password detection with high security is achieved.
Patent Information
- Application Number
- PCT/CN2024/117067
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-01
- Filing Date
- 2024-09-05
- Publication Date
- 2025-06-05
AI Technical Summary
In the symmetric PAKE protocol, the server can obtain plaintext information of the user password, resulting in low security; while in the asymmetric aPAKE protocol, the server cannot test whether the user password is a weak password because it does not have plaintext information of the user password.
By pre-stored the target password locally on the server and encrypting each pre-stored password using the same encryption algorithm as the user side, a second key is generated. Then, the server decrypts the second key and the ciphertext sent by the user to determine whether the user password belongs to the target password.
It realizes that without obtaining the plaintext information of the user password, the server can detect whether the user password is a weak password, improves the security of password detection, and has a target password testing mechanism.
Smart Images

Figure CN2024117067_05062025_PF_FP_ABST
Abstract
Description
Password detection method, server, user and password detection system
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 1, 2023, with application number 202311647843.6 and application name “A Password Detection Method, Server, User Terminal and Password Detection System”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of network security technology, and in particular to a password detection method, a server, a user terminal, and a password detection system. Background Art
[0003] Currently, information and communications technology (ICT) product lines require authentication server systems to be able to test whether passwords set by administrators are weak. The industry generally uses the symmetric password-authenticated key (PAKE) protocol. In the symmetric PAKE protocol, the server has the plaintext information of the user's password. The server can directly compare the user's password with weak passwords in the database one by one to determine whether the user's password is weak. However, because the server can obtain the plaintext information of the user's password in the symmetric PAKE protocol, the security of the symmetric PAEK protocol is not high.
[0004] The server can use the asymmetric password-authenticated key (aPAKE) protocol to transmit user passwords. In the aPAKE protocol, the client encrypts the password to generate ciphertext and sends it to the server. The server associates the encrypted ciphertext with the user and stores it on the server. Since the server only has the ciphertext sent by the client and does not have the client's key, it cannot decrypt the ciphertext using the key to obtain the plaintext password, thus ensuring the security of password transmission.
[0005] However, in the aPAKE protocol, the server does not have the plain text information of the user password, so the server cannot test whether the user password is a weak password.
[0006] Summary of the Invention
[0007] The embodiments of the present application provide a password detection method, a server, a user, and a password detection system for implementing weak password detection. The method can detect whether a user password belongs to the target password when the server does not have the user password plaintext information.
[0008] The first aspect of the embodiment of the present application provides a password detection method, in which a user registers at a user terminal, and the user enters a user ID and a user password. The user terminal uses a first encryption algorithm to encrypt the user password to obtain a first key, and then encrypts the ciphertext based on the first key, and the server receives the ciphertext sent by the user terminal. The server locally stores one or more pre-stored passwords, which belong to target passwords. The target password is used to indicate the type of password. The server uses the same second encryption algorithm as the user terminal to encrypt each pre-stored password to obtain a corresponding second key. The server substitutes the second key and the ciphertext into the decryption algorithm for decryption to obtain a target result. The target result is used to indicate whether the second key generated by the server according to the target password is the same as the first key in the ciphertext, and then sends a corresponding feedback message to the user terminal based on the target result.
[0009] In an embodiment of the present application, the server compares the second key obtained according to the target password with the first key obtained by the user according to the user password using the same encryption algorithm as that of the user, so that the server can determine whether the user password belongs to the target password without knowing the plaintext information of the user password, so that the server not only ensures the security of the password detection protocol, but also has a target password testing mechanism.
[0010] In some optional implementations, the target password is one or more of a weak password, an exposed password, or a sensitive password. Specifically, a sensitive password is used to indicate a password that includes sensitive words.
[0011] In an embodiment of the present application, when a user password is a weak password, an exposed password, or a sensitive password, the server can provide feedback to the user, thereby prompting the user to modify the password, thereby improving the security of password detection.
[0012] In some optional implementations, the target password may be a password that does not meet the preset rules. When the server successfully decrypts the ciphertext sent by the user using the second key generated by the preset password belonging to the target password, it proves that the user password does not meet the preset rules.
[0013] In some optional implementations, the target password may be a password with an entropy value lower than a preset value. The entropy value is an indicator for measuring the amount of information in password distribution. A higher entropy value indicates a more random password distribution and a higher security.
[0014] In some optional implementations, the client uses the second encryption algorithm to encrypt the ciphertext using the first key, and the server can use the second key to decrypt the ciphertext sent by the client.
[0015] Specifically, the server substitutes the second key and the ciphertext into a decryption function corresponding to the second encryption algorithm. If the resulting function value is the first value, decryption is successful. Therefore, the second key is the same as the first key, meaning that the user password is the same as one of the preset passwords in the database. Therefore, the user password type and the preset password type are the same, and both belong to the target password.
[0016] In an embodiment of the present application, by using a second key generated based on the target password to decrypt the ciphertext, the server can determine whether the user password belongs to the target password without the plaintext information of the user password, thereby avoiding the risk of the server exposing the user password and improving the security of password detection.
[0017] In some optional implementations, when the ciphertext is successfully decrypted using the second key, the server sends a first message to the user, where the first message is used to indicate that the user password belongs to the target password.
[0018] In an embodiment of the present application, when the server successfully decrypts, the user password is the same as the preset password, so the user password is not secure. The server sends a first message to the user, so that the user prompts the user to modify the password, thereby improving the security of user registration.
[0019] In some optional implementations, if the server-side decryption function obtains the second value, it means that the decryption fails, that is, the first key is different from any of the second keys.
[0020] In some optional embodiments, when decryption of the ciphertext using the second key fails, the server sends a second message to the client indicating that the user password is not a target password. The server stores the ciphertext locally for subsequent login and authentication operations by the corresponding user on the client.
[0021] In an embodiment of the present application, by using the second key generated according to the target password to decrypt the ciphertext on the user side, it is possible to determine whether the first key generated according to the user password is the same as the second key, thereby determining whether the user password belongs to the target password, thereby ensuring the security of password detection.
[0022] In some optional embodiments, before the server receives the ciphertext from the client, it also receives a first encrypted value and a user identifier from the client. Because the first encrypted value is obtained by encrypting the user password using a third encryption algorithm, the first encrypted value includes the user password. The server then calculates the first encrypted value and a local long-term key to obtain a second encrypted value, and then sends the second encrypted value and the server identifier to the client. Because the second encrypted value is calculated based on the server's long-term key, the client can obtain the server's long-term key based on the second encrypted value.
[0023] In the embodiment of the present application, since the server embeds the long-term key in the second encrypted value and sends it to the user, the long-term key plays the role of a digital certificate, verifies the legal identity of the server, and improves the security of password detection.
[0024] In some optional implementations, the server encrypts the target password in the database using a third encryption algorithm to obtain a third encrypted value, and then encrypts the third encrypted value with the local long-term key to obtain the first root key. The server then obtains the second key based on the first root key, the user identifier, and the server identifier.
[0025] In the embodiment of the present application, the second key and the first key are both obtained based on the long-term key. Therefore, when the server uses the second key to decrypt the ciphertext, it can be determined whether the target password in the second key and the user password in the first key are consistent.
[0026] A second aspect of an embodiment of the present application provides a password detection method, in which a user terminal obtains a user identifier and a user password input by a user. The user terminal encrypts the user password using a first encryption algorithm to obtain a first key, and then encrypts the password using the first key according to a second encryption algorithm to obtain a ciphertext. The user terminal sends the ciphertext to the server terminal, so that the server terminal can determine whether the user password belongs to the target password based on the ciphertext and the target password in the database. The user terminal receives a feedback message from the server terminal, which includes the user terminal's judgment result on the user password, indicating whether the user password belongs to the target password.
[0027] In some optional implementations, the target password is one or more of a weak password, an exposed password, or a sensitive password. Specifically, a sensitive password is used to indicate a password that includes sensitive words.
[0028] In some optional implementations, if the user password belongs to the target password, the user terminal will receive a first message from the server terminal, where the first message is used to indicate that the server terminal has successfully decrypted the ciphertext.
[0029] In the embodiment of the present application, when the user terminal receives the first message, it indicates that the user password belongs to the target password and the security level of the user password is low. The user terminal can prompt the user to modify the password, thereby improving the security of user registration.
[0030] In some optional implementations, if the user password belongs to the target password, the user terminal will receive a second message from the server, which is used to indicate that the server failed to decrypt the ciphertext, the user password has a high security level, the user terminal has been successfully registered, and subsequent login or authentication operations can be performed.
[0031] In some optional embodiments, before the user terminal encrypts the user password using the first encryption algorithm, the user terminal blinds the user password based on the user password and a randomly generated blinding factor to obtain a first encrypted value. The user terminal sends the first encrypted value and the user identifier to the server terminal. The user terminal receives a second encrypted value and the server identifier from the server terminal, the second encrypted value including the server terminal's long-term key.
[0032] In the embodiment of the present application, the blinded user password is sent to the server, so that the user password will not be exposed to the server, thereby ensuring the security of password detection.
[0033] In some optional implementations, the user terminal substitutes the user password into the third encryption algorithm to obtain a randomized fourth encryption value, and then calculates the blinding factor and the fourth encryption value to obtain the first encryption value.
[0034] In some optional implementations, after receiving the second encrypted value, the user terminal may derive a fifth encrypted value based on the second encrypted value and a blinding factor. The fifth encrypted value removes the blinding factor and includes only the user password and the server's long-term key. The user terminal then derives a second root key based on the fifth encrypted value and encrypts the second root key, the user identifier, and the server identifier to obtain the first key.
[0035] In some optional implementations, the user terminal performs an inverse operation of blinding on the second encrypted value, removes the blinding factor in the second encrypted value, and obtains a fifth encrypted value.
[0036] In the embodiment of the present application, the user terminal restores the blinded user password by performing the inverse operation of blinding on the second encrypted value, while retaining the long-term key of the server in the fifth encrypted value. In this way, the user terminal obtains the long-term key of the server without exposing the user password to the server, thereby improving the security of password detection.
[0037] A third aspect of this embodiment provides a server, including:
[0038] A receiving unit, configured to receive, at the server end, a ciphertext from the client end, the ciphertext including a first key, the first key being obtained by encrypting the user password by the client end;
[0039] An encryption unit, configured for the server to encrypt a pre-stored target password to obtain a second key;
[0040] A calculation unit, configured to obtain a target result on the server side according to the first key and the second key, wherein the target result is used to indicate whether the user password belongs to the target password;
[0041] A sending unit is used for the server to send a feedback message to the user terminal according to the target result.
[0042] A fourth aspect of the embodiments of the present application provides a user terminal, including:
[0043] An encryption unit, configured for the user terminal to encrypt the user password to obtain a first key;
[0044] A sending unit, configured for the user end to send a ciphertext to the server end, the ciphertext including the first key;
[0045] The receiving unit is used for the user end to receive a feedback message from the server end, where the feedback message is used to indicate whether the user password belongs to the target password.
[0046] A fifth aspect of the embodiments of the present application provides a server, including:
[0047] a processor and a memory, the processor being coupled to the memory;
[0048] The memory is used to store programs;
[0049] The processor is used to execute the program in the memory, so that the server executes the method as described in the first aspect above.
[0050] A sixth aspect of the present application provides a user terminal, including:
[0051] a processor and a memory, the processor being coupled to the memory;
[0052] The memory is used to store programs;
[0053] The processor is used to execute the program in the memory, so that the user terminal executes the method as described in the second aspect above.
[0054] A seventh aspect of the present application provides a password detection system, including:
[0055] The server as described in the first aspect above, and the user as described in the second aspect above.
[0056] In an eighth aspect of an embodiment of the present application, a computer-readable storage medium includes instructions. When the instructions are executed on a computer, the computer executes the method described in the first aspect above, or the computer executes the method described in the second aspect above. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] FIG1 is a diagram of a network architecture according to an embodiment of the present application;
[0058] FIG2 is a schematic diagram of an embodiment of a password detection method in an embodiment of the present application;
[0059] FIG3 is a schematic diagram of an embodiment of user authentication and login in an embodiment of the present application;
[0060] FIG4 is a schematic diagram of an embodiment of user data encryption in an embodiment of the present application;
[0061] FIG5 is a schematic diagram of an embodiment of a server in an embodiment of the present application;
[0062] FIG6 is a schematic diagram of an embodiment of a user terminal according to an embodiment of the present application;
[0063] FIG7 is a schematic diagram of another embodiment of the server in the embodiment of the present application;
[0064] FIG8 is a schematic diagram of another embodiment of a user terminal in an embodiment of the present application. DETAILED DESCRIPTION
[0065] The embodiments of the present application provide a password detection method, a server, a user terminal, and a password detection system, which are applied in the field of network security technology to implement weak password detection.
[0066] The embodiments of the present application are described below in conjunction with the accompanying drawings. Those skilled in the art will appreciate that, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0067] The terms "first", "second" etc. in the specification, claims and drawings of the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0068] First, some of the terms and related technologies involved in this application are explained in conjunction with the accompanying drawings to facilitate understanding by those skilled in the art.
[0069] A key agreement protocol involves two or more parties negotiating and jointly establishing a session key. Any participant can influence the outcome, without requiring a trusted third party. The communicating parties can establish a secure shared secret key by exchanging messages over a public channel. During key agreement, the secret key established by the two parties is typically a function of the input messages.
[0070] Private set intersection (PSI) is a cryptographic technique used in secure multi-party computation. It allows two parties involved in a computation to calculate the intersection of their data without obtaining additional information about the other party (other than the intersection).
[0071] Please refer to Figure 1. The following briefly describes the network architecture based on the password detection method in the embodiment of the present application:
[0072] The network architecture is a "client-server" structure, with multiple client terminals 101 connected to a server terminal 102. Users register and log in through the client terminals 101. Registration involves the client sending user information to the server terminal, which then records the user's legal identity and information, thereby qualifying the user to use the server's services. Login involves the user accessing the server terminal through the client terminal to use the server's services. The server terminal 102 performs password verification on registered users and authenticates logged-in users.
[0073] The user end can be a terminal device, such as a mobile phone, a tablet computer, a computer with transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a wearable device, and an in-vehicle device; and a network device, such as a three-layer switch, a router, a broadband gateway, a firewall, a load balancer and other network devices.
[0074] A server, also referred to as a server, can serve a client. For example, the server can provide resources to the client and / or store client data. The resources can be at least one of text, images, and videos. The server can be a single server or a server cluster, which is not limited in this embodiment. The server can be an application server, i.e., an application server that provides services to the user.
[0075] The embodiment of the present application is based on the standard aPAKE protocol and key agreement protocol, so that the server can detect whether the user password is a weak password without leaking the plaintext information of the user password.
[0076] When registering, a user enters their user ID and password. Client 101 uses an encryption algorithm to encrypt the password into a first key, then uses this key to construct a ciphertext. Client 101 then sends the ciphertext and user ID to server 102. Server 102 uses the same encryption algorithm as client 101 to generate a corresponding second key based on each preset password, and attempts to decrypt the ciphertext using each second key. If decryption succeeds, it indicates that the user password matches one of the preset passwords stored on server 102, and server 102 sends a message to client 101, prompting the user to change their password. If decryption fails, it indicates that the user password differs from any of the preset passwords stored on server 102, and the user registration is successful. The server saves the user's registration information. When the user corresponding to the client logs in to the server, the server can authenticate the client based on this registration information. The preset password is a target password, which can be one or more of a weak password, a compromised password, or a sensitive password.
[0077] When the user logs in, the server 102 authenticates the user and determines whether the user terminal 101 is a legitimate user. After a successful login, the user terminal 101 encrypts the data generated by the user and sends it to the server 102, which then decrypts and stores it.
[0078] The server possesses a long-term key (LTK), a long-term public key (PK), and a long-term secret key (SK). The LTK serves as a digital certificate, proving the server's identity and verifying the client's legitimacy. The PK and SK form a key pair. The server sends the PK to the client, which uses it for encryption and the server uses the SK for decryption, ensuring secure information transmission.
[0079] When a user registers, the user side will also generate a long-term public key and a long-term private key. In this embodiment of the application, x is used to represent the long-term private key of the user side, and X is used to represent the long-term public key of the user side. When the user logs in, the server side will authenticate the user side, at which time both the user side and the server side will generate a temporary public key and a temporary private key. In this embodiment of the application, y1 is used to represent the temporary private key of the user side, y2 is used to represent the temporary private key of the server side, Y1 is used to represent the temporary public key of the user side, and Y2 is used to represent the temporary public key of the server side.
[0080] The first key and the second key are both key encryption keys (KEK), which are generated by the user or server based on the root key (RK). In this embodiment, Ke is used to represent the first key and Ke is used to represent the second key. * Indicates the second key.
[0081] It is understood that in the embodiment of the present application, the above-mentioned key representation is only an example. In actual application, the keys of the user end and the server end can be represented in a variety of ways, which are not limited here.
[0082] Based on the above architecture, in the embodiment of the present application, the server 102 can determine whether the user password is the same as the preset password stored by the server 102 without the plain text information of the user password, thereby detecting whether the user password is a weak password. The following describes the steps of registration, authentication, login and encryption on the user side and the server side respectively:
[0083] 1. Registration;
[0084] Please refer to FIG2 , which is a schematic diagram of an embodiment of password detection during user registration in an embodiment of the present application.
[0085] 201. The user terminal calculates a first encryption value;
[0086] When a user registers on the client, the client obtains the user password and username entered by the user and generates a user identifier ID_client based on the username. The client can also generate ID_client based on the encoding of the client device, but the specific details are not limited here. The client substitutes the user password into the third encryption algorithm. In actual applications, the third encryption algorithm is a HashToGroup function, and the function value is expressed as: HashToG(user password)
[0087] The user end generates a random number as a blinding factor and blinds the function value, that is, the user end calculates the function value and the blinding factor to obtain the first encrypted value. In this embodiment, r is used to represent the blinding factor and R is used to represent the first encrypted value. The HashToGroup function corresponds to different mathematical systems, and the user end has different blinding methods based on the constructed mathematical system. For example, R is expressed as: R = HashToG(user password)^r
[0088] Or R = HashToG (user password) * r
[0089] There is no specific limitation here.
[0090] In this embodiment, since the HashToGroup function can make the obtained function value difficult to be restored to the input value, the risk of exposing the plain text information of the user password to the server is reduced, thereby improving the security of password detection.
[0091] 202. The user terminal sends the first encrypted value and the user identifier to the server terminal;
[0092] The server saves the ID_client from the user and saves R corresponding to the ID_client.
[0093] In this embodiment, since the server cannot obtain r, the server cannot restore R to obtain the plain text information of the user password, thereby improving the security of password detection.
[0094] 203. The server calculates a second encryption value.
[0095] The server calculates the locally stored LTK and R to obtain a second encrypted value, and the calculation method corresponds to the calculation method of R in step 201. In this embodiment, Y represents the second encrypted value, and Y can be expressed as: Y = R^LTK
[0096] Or Y=R*LTK
[0097] In this embodiment, the LTK functions as a digital certificate, proving the server's authorization to register, authenticate, or log in. The server also sends the LTK to the client, enabling the client to encrypt the user's password based on the LTK. The server calculates Y from the LTK and R, ensuring the confidentiality of the long-term key and improving the security of password verification.
[0098] 204. The server sends the second encrypted value, the server's long-term public key, and the server's identifier to the client.
[0099] Since Y includes the LTK, it can prove the server's authority. The PK is used for subsequent user authentication and login operations. At the same time, in asymmetric encryption algorithms, the user needs to use the PK for encryption, and the server uses the SK for decryption. Therefore, the server sends the PK to the user, allowing the user to use the PK for asymmetric encryption algorithms to encrypt plaintext information.
[0100] In this embodiment, the user needs to confirm that the server has registration permissions and is not a phishing website. At the same time, the server needs to confirm that the user is a legitimate user. Therefore, the server includes the LTK in Y and sends it to the user, thereby verifying the server's identity. After the user receives Y, because Y includes the LTK, the server will identify the user as a legitimate user during subsequent authentication and login operations, improving the security of password verification.
[0101] 205. The user terminal calculates a fifth encryption value;
[0102] After receiving Y, the user terminal calculates the fifth encrypted value based on r. In this embodiment, the fifth encrypted value is represented by T. The user terminal deblinds Y, that is, performs the inverse operation of blinding on Y to obtain T. If R is: R = HashToG(user password)^r
[0103] Then T is: T = Y^(1 / r) = HashToG(user password)^LTK
[0104] If R is: R = HashToG (user password) * r
[0105] Then T is: T=Y*(1 / r)=HashToG(user password)*LTK
[0106] In this embodiment, the user terminal needs to use the server's LTK to verify the server's identity. Through blinding operations, the user terminal obtains the server's LTK without being able to obtain the plain text information of the user's password, thereby improving the security of password detection.
[0107] 206. Generate a first key Ke;
[0108] The user end generates RK based on T. In this embodiment, RK1 represents the RK generated by the user end, and RK2 represents the RK generated by the server end. The user end generates Ke based on RK1.
[0109] Specifically, the user terminal can substitute T and the hash value of the user password Hash(user password) into a pseudo random function (PRF) to generate RK1: RK1 = PRF(T, Hash(user password))
[0110] In practical applications, T may also be substituted into the PRF together with other random numbers generated based on the user password, and the specific details are not limited here.
[0111] The client derives Ke from RK1 through a key derivation function (KDF). The client substitutes ID_client, ID_server, and a fixed string as a salt into the KDF. Ke is expressed as: Ke = KDF(RK1, ID_client||ID_server||REGENC)
[0112] In actual applications, the fixed string can be set by the server. The fixed string in the above formula is only an example, and the form of the fixed string is not limited in the embodiment of the present application.
[0113] In this embodiment, the user terminal uses PRF to encrypt T, and then derives the first Ke from the second root key RK by using KDF, which increases the computing resources required for cracking the key, prevents brute force cracking, and improves the security of the first key Ke.
[0114] 207. The user terminal generates a first ciphertext and a second ciphertext;
[0115] The user terminal generates x, and then calculates x with a generator to obtain X, where the generator is represented by g. The calculation method of X corresponds to the calculation method of R in step 201. In one possible implementation, X is represented as: X = g^x
[0116] Or X = g*x
[0117] The user end uses Ke as the key of the first ciphertext, and uses x, X, ID_client, and PK as the first plaintext information of the first ciphertext, and encrypts it using a symmetric encryption algorithm. In this embodiment, the first ciphertext is represented by C1. In actual applications, the user end can use the Galois / Counter Mode (GCM) in the Advanced Encryption Standard (AES) algorithm to encrypt the first plaintext information. C1 is expressed as C1 = AES-GCM (Ke, x||X||ID_client||PK)
[0118] It is understandable that the user terminal may also use the Data Encryption Standard (DES) algorithm to encrypt the first plaintext information, or use the Triple Data Encryption Algorithm (3DES) to encrypt the first plaintext information, which is not specifically limited here.
[0119] The user end then uses the server's PK as the key for the second ciphertext, and uses ID_client, ID_server, and X as the second plaintext information, and encrypts it using an asymmetric encryption algorithm. In the embodiment of the present application, the second ciphertext is represented by C2. In actual applications, the user end can use the elliptic curve integrated encryption scheme (ECIES) algorithm to encrypt the second plaintext information, and C2 is expressed as C2 = ECIES (PK, ID_client || ID_server || X).
[0120] It is understandable that the user terminal may also use an RSA encryption algorithm to encrypt the second plaintext information, or use a digital signature algorithm (DSA) to encrypt the second plaintext information, which is not specifically limited here.
[0121] In this embodiment, the user uses a symmetric encryption algorithm to encrypt the first plaintext information, so that the server can only decrypt C1 when the server and the user have the same key. Based on this, the server can determine whether the user password is weak without knowing the plaintext password, thereby improving the security of password detection.
[0122] In this embodiment, x and X are only examples. In actual applications, the long-term private key and long-term public key of the user terminal can be represented in various ways. For example, a is used to represent the long-term private key of the user terminal, A is used to represent the long-term public key of the user terminal, or SA is used to represent the long-term private key of the user terminal, and PA is used to represent the long-term public key of the user terminal. The specific examples are not limited here.
[0123] 208. The user terminal sends the user identifier, the first ciphertext, and the second ciphertext to the server terminal.
[0124] The user sends ID_client to the server to prove the user's identity. C1 is used by the server to detect whether the user's password is a weak password. C2 is used by the server to authenticate the user's subsequent login operations.
[0125] 209. The server generates a second key;
[0126] The server locally stores multiple preset passwords. In actual applications, the server substitutes each preset password into the third encryption algorithm, and the function value is expressed as: HashToG(target password)
[0127] The server then calculates each function value with K to obtain multiple third encrypted values. In this embodiment, the third encrypted value is T * Indicates that T * Expressed as: T * =HashToG(target password)^LTK
[0128] or T * =HashToG(target password)*LTK
[0129] The server will * The hash value Hash (target password) of the corresponding preset password is substituted into PRF to obtain multiple RK2, which is expressed as: RK2 = PRF (T * ,Hash(target password))
[0130] The server uses KDF from each RK * Export Ke * , where the server substitutes ID_client, ID_server and a fixed string as salt value into KDF, Ke * Expressed as: Ke *=KDF(RK2,ID_client||ID_server||REGENC)
[0131] In this embodiment, step 209 may be performed after step 208 or before step 208 and after step 202, and the specific steps are not limited here.
[0132] 210. The server decrypts the first ciphertext using the second key.
[0133] The server will use different Ke * Substitute into the decryption function to decrypt C1 and get: Dec(Ke * ,C1)
[0134] Among them, Dec represents the decryption function, Ke * is the key used for decryption, and C1 is the ciphertext to be decrypted.
[0135] Since the user end uses a symmetric encryption algorithm to encrypt C1, when Ke * If the decryption function obtains the first value when it is the same as Ke, it indicates that the decryption is successful, that is, the user password is a weak key, an exposed key, or a sensitive password containing sensitive words, and step 211 is executed. * If the decryption function obtains a second value when Ke is different, it indicates that the decryption fails, that is, the user password is different from any preset password, and step 212 is executed.
[0136] In practical applications, the first value and the second value can be expressed in multiple ways, for example, the first value is 1 to indicate successful decryption, and the second value is 0 to indicate failed decryption, or the first value is success to indicate successful decryption, and the second value is fail to indicate failed decryption. The specifics are not limited here.
[0137] 211. The server sends a first message to the user terminal;
[0138] The decryption function obtains the first value, the server terminates the program, saves ID_client and C1, deletes C2, and sends a first message to the user. The first message is used to indicate that the user registration failed. After receiving the first message, the user prompts the user to change the user password.
[0139] 212. The server sends a second message to the user terminal;
[0140] The server will * Substituting the second value into the decryption function, the server saves the ID_client, C1, and C2 sent by the user and sends a second message to the user. The second message is used to indicate that the user registration is successful.
[0141] In this embodiment, the server uses Ke * The decryption C1 method detects whether the user password is a weak password, avoids exposing the plain text information of the user password to the server, and improves the security of password detection.
[0142] It is understandable that in this embodiment, the target password can be a password that does not meet the preset rules. For example, the preset rule is that the password must contain at least 4 characters, then the preset password includes all passwords with a character count of 0 to 3. * When C1 is successfully decrypted, it proves that the user password belongs to the target password and the user password does not meet the preset rules. * Decrypting C1 proves that the user password meets the preset rules. Therefore, this embodiment can detect whether the user password meets the preset rules without exposing the plain text information of the user password.
[0143] In practical applications, the target password may also be a password with an entropy value lower than a preset value, an exposed password, or a password containing sensitive words, which is not specifically limited here.
[0144] In the embodiment of the present application, the aPAKE protocol and PSI are combined to achieve highly secure asymmetric password two-way authentication and session key negotiation. At the same time, the server can achieve the business goal of testing the user's weak password without knowing the plaintext information of the user's password, thereby avoiding the security risks brought by the traditional PAKE protocol, improving security, and filling the functional gap of the standard aPAKE protocol in this regard.
[0145] 2. Authentication and login;
[0146] Please refer to Figure 3, which is a schematic diagram of an embodiment of the server authenticating user login in an embodiment of the present application.
[0147] 301. The user terminal calculates a sixth encryption value and a temporary public key of the user terminal;
[0148] The client obtains the user password and username entered by the user and generates ID_client. The client substitutes ID_client and user password into the third encryption algorithm to obtain the function value: HashToG(user password||ID_client)
[0149] The user generates a random number and y1, and uses the random number as a blinding factor to blind the function value to obtain the sixth encrypted value. In this embodiment, r1 represents the blinding factor, and R1 represents the sixth encrypted value. According to the mathematical system used by the HashToG function, R1 is expressed as: R1 = HashToG(user password || ID_client)^r1
[0150] Or R1 = HashToG (user password || ID_client) * r1
[0151] The user end then calculates Y1 based on y1 and the generator. In this embodiment, the generator is represented by g, and Y1 is represented by: Y1 = g^y1
[0152] Or Y1=g*y1
[0153] 302. The user terminal sends the user identifier, the sixth encrypted value, and the temporary public key of the user terminal to the server terminal;
[0154] The server receives ID_client, R1, and Y1 from the client, and retrieves the corresponding C1 and C2 from the database based on ID_client.
[0155] 303. Calculate the seventh encryption value and the server's temporary public key;
[0156] The server calculates the seventh encrypted value based on R1 and LTK sent by the client. The seventh encrypted value is represented by W1, which is expressed as: W1 = R1^K
[0157] Or W1=R1*K
[0158] The server generates a random y2 and obtains Y2 based on y2 and the generator. The generator is represented by g, and Y2 is expressed as: Y2=g^y2
[0159] Or Y2=g*y2
[0160] 304. The server sends the server identifier, the seventh encrypted value, the first ciphertext, and the server's temporary public key to the client.
[0161] The user terminal unblinds W1 to obtain the seventh encrypted value, which is represented by T1. T1 is expressed as: T1 = W1^(1 / r1)
[0162] Or T1=W1*(1 / r1)
[0163] The user end generates the third root key RK3 through PRF based on T1. RK3 is: RK3 = PRF (T1, Hash (user password))
[0164] The client derives the third key from RK3 through KDF, which is represented by Ke1. The client substitutes ID_client, ID_server, and a fixed string as a salt into KDF, and Ke1 is represented as: Ke1 = KDF(RK3, ID_client||ID_server||REGENC)
[0165] The client substitutes Ke1 into the AES algorithm to decrypt C1 to obtain the first plaintext information. If the user password entered by the user is the same as the user password in C1 saved by the server, the decryption is successful. If the user password entered by the user is different from the user password in the first ciphertext C1, the decryption fails. Specifically expressed as: AES-GCM(Ke1,C1)=x||X||ID_client||PK
[0166] When C1 decryption fails, the user terminal prompts the user that the password input is incorrect and re-executes step 301 until C1 decryption succeeds.
[0167] 305. The server calculates the first authentication parameter.
[0168] The server's SK and PK form a key pair, and C2's key is the server's PK. Therefore, the server can use SK to decrypt C2 to obtain the second plaintext information, which includes the user's X.
[0169] The server calculates the master key (MK) based on SK, y2, X, and Y1. The server's master key is represented by mk1, which is expressed as: mk1 = X^SK||Y1^SK||X^y2||Y1^y2
[0170] Or mk1=X*SK||Y1*SK||X*y2||Y1*y2
[0171] MK1 consists of four parts: X and SK, Y1 and SK, X and y2, and Y1 and y2. When MK1 is obtained by exponentiation, the public key is the base and the private key is the exponent.
[0172] In the embodiment of the present application, authentication using four keys to form mk1 can detect whether the user has all the keys, thereby improving the security of user authentication.
[0173] The server generates a message authentication code key (K_MAC) based on mk1. K_MAC is used to protect data security during communication. It is obtained through the PRF based on mk1, R1, W1, Y1, Y2, ID_client, ID_server, and a fixed string. The server's K_MAC is specifically expressed as: K_MAC = PRF(mk1, R1||W1||Y1||Y2||ID_client||ID_server||"MAC")
[0174] The server generates an authentication parameter (Auth) based on K_MAC. This authentication parameter is the first authentication parameter and is represented by Auth1. The server uses a symmetric encryption algorithm and encrypts the server's K_MAC as the key. Auth1 is represented by: Auth1 = AES-GCM (K_MAC, R1||W1||Y1||Y2||ID_client||ID_server||"server")
[0175] In this embodiment, the timing of step 305 and step 304 is not limited. Step 305 can be executed before step 304 or after step 304, and the specific sequence is not limited here.
[0176] 306. The server sends the first authentication parameter to the client.
[0177] The server sends Auth1 to the client, allowing the client to authenticate the server.
[0178] 307. The user terminal compares the first authentication parameter and the second authentication parameter;
[0179] The user side calculates MK based on PK, x, y1 and Y2. The MK of the user side is represented by mk2, which is expressed as: mk2 = PK^x||PK^y1||Y2^x||Y2^y1
[0180] Or mk2=PK*x||PK*y1||Y2*x||Y2*y1
[0181] The user end calculates K_MAC based on mk2. The user end's K_MAC is expressed as: K_MAC=PRF(mk2,R1||W1||Y1||Y2||ID_client||ID_server||"MAC")
[0182] The user end uses the symmetric encryption algorithm to encrypt the user end's K_MAC as the key to obtain the second authentication parameter. The second authentication parameter is Auth1 * Indicates that Auth1 * Represented as: Auth1 * =AES-GCM(K_MAC,R1||W1||Y1||Y2||ID_client||ID_server||"server")
[0183] If the Auth1 generated by the user * If the Auth1 from the server is the same as the Auth1 from the server, the authentication of the client to the server is successful; *Different from Auth1, the user fails to authenticate the server, and the server's identity is illegal.
[0184] 308. The user terminal calculates a third authentication parameter;
[0185] The user end uses a symmetric encryption algorithm to encrypt the user end's K_MAC as the key to obtain the third authentication parameter, which is represented by Auth2. Auth2 is expressed as: Auth2 = AES-GCM (K_MAC, R1||W1||Y1||Y2||ID_client||ID_server||"client")
[0186] Auth2 is used by the server to authenticate the user.
[0187] 309. The user terminal sends the third authentication parameter to the server terminal;
[0188] The client sends the third authentication parameter to the server, so that the server authenticates the client.
[0189] 310. The server compares the third authentication parameter and the fourth authentication parameter;
[0190] The server generates the fourth authentication parameter based on K_MAC and uses Auth2 * The server uses a symmetric encryption algorithm and uses the server's K_MAC as the key to encrypt. * Represented as: Auth2 * =AES-GCM(K_MAC,R1||W1||Y1||Y2||ID_client||ID_server||"client")
[0191] If the Auth2 generated by the user is different from the Auth2 from the server * If the server authenticates the client successfully, then step 311 is executed; if Auth2 is the same as Auth2 * If they are different, the server fails to authenticate the user, and the identity of the user is illegal, and step 312 is executed.
[0192] 311. The server sends a login success message to the user.
[0193] If the user successfully authenticates the server and the server successfully authenticates the user, the server sends a login success message to the user, indicating that the user name and password entered by the user are the same as the data stored on the server, and the user login is successful.
[0194] 312. The server sends a login failure message to the user.
[0195] If the user fails to authenticate the server or the server fails to authenticate the user, the server sends a login failure message to the user, indicating that the user name or password entered by the user is incorrect, and prompts the user to re-enter.
[0196] 3. Encryption.
[0197] Please refer to FIG4 , which is a schematic diagram of an embodiment of user data encryption in an embodiment of the present application.
[0198] 401. The user generates an encryption key.
[0199] The client generates an encryption key (K_ENC) through the PRF based on the mk2 generated during authentication. K_ENC is expressed as: K_ENC = PRF(mk2, R1||W1||Y1||Y2||ID_client||ID_server||"ENC")
[0200] 402. The user terminal encrypts the user-generated data using the encryption key;
[0201] The user end obtains the data generated by the user and encrypts the data using a symmetric encryption algorithm, specifically expressed as: AES_GCM(K_ENC,m)
[0202] Where m represents the data that the user terminal needs to encrypt. In actual applications, the user terminal can also use K_ENC and K_MAC to encrypt user data, which is not limited here.
[0203] 403. The client sends encrypted data to the server.
[0204] Since the user end uses a symmetric encryption algorithm to encrypt user data, the encrypted data can only be decrypted by K_ENC to obtain the user data. Terminals without K_ENC cannot obtain user data, ensuring the security of user data.
[0205] 404. The server generates an encryption key.
[0206] The server generates K_ENC through PRF based on the mk1 generated during authentication. K_ENC is expressed as: K_ENC = PRF (mk1, R1||W1||Y1||Y2||ID_client||ID_server||"ENC")
[0207] Since the user and server have successfully authenticated each other, mk1 and mk2 are the same, and the K_ENC generated by the user and the server are the same.
[0208] 405. The server uses the encryption key to decrypt the encrypted data.
[0209] The server can use K_ENC to decrypt the encrypted data, obtain the user data, and save the user data locally on the server.
[0210] In this embodiment, the user end and the server end construct a secure transmission channel by generating K_ENC, so that user data can be securely transmitted from the user end to the server end, thereby ensuring the security of data transmission.
[0211] The above describes the password detection method in the embodiment of the present application. The following describes the server and user end in the embodiment of the present application.
[0212] Please refer to FIG5 , an embodiment of the server in the embodiment of the present application includes:
[0213] The receiving unit 501 is configured to receive ciphertext from a user terminal, where the ciphertext is encrypted using a first key, which is obtained by encrypting a user password using a first encryption algorithm.
[0214] The encryption unit 502 is configured to encrypt the pre-stored target password using a first encryption algorithm to obtain a second key;
[0215] A calculation unit 503 is configured to determine whether the user password belongs to the target password based on the ciphertext and the second key;
[0216] The sending unit 504 is configured to send a feedback message to the user terminal, where the feedback message is used to indicate whether the user password belongs to the target password.
[0217] Please refer to FIG6 , an embodiment of a user terminal in the embodiment of the present application includes:
[0218] The encryption unit 601 is configured to encrypt the user password using a first encryption algorithm to obtain a first key;
[0219] A sending unit 602 is configured to send a ciphertext to a server, where the ciphertext is obtained by encrypting the first key by the client using a second encryption algorithm;
[0220] The receiving unit 603 is configured to receive a feedback message from the server, where the feedback message indicates whether the user password belongs to a target password, and the target password indicates a password type.
[0221] Please refer to FIG7 , another embodiment of the server in the embodiment of the present application includes:
[0222] FIG7 is a schematic diagram of a server structure provided in an embodiment of the present application. The server 700 may include one or more central processing units (CPUs) 701 and a memory 705 . The memory 705 stores one or more applications or data.
[0223] Memory 705 may be volatile or persistent storage. The program stored in memory 705 may include one or more modules, each of which may include a series of instruction operations on the server. Furthermore, central processing unit 701 may be configured to communicate with memory 705 and execute the series of instruction operations in memory 705 on server 700.
[0224] The server 700 may also include one or more power supplies 702, one or more wired or wireless network interfaces 703, one or more input and output interfaces 704, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0225] The central processing unit 701 can execute the operations performed by the server in the aforementioned embodiment, and the details will not be repeated here.
[0226] Please refer to FIG8 , another embodiment of the user terminal in the embodiment of the present application includes:
[0227] FIG8 is a schematic diagram of a user terminal structure provided in an embodiment of the present application. The user terminal 800 may include one or more central processing units (CPUs) 801 and a memory 805 . The memory 805 stores one or more applications or data.
[0228] Memory 805 may be volatile or persistent storage. The program stored in memory 805 may include one or more modules, each of which may include a series of instruction operations on the server. Furthermore, the central processing unit 801 may be configured to communicate with memory 805 and execute the series of instruction operations in memory 805 on the user terminal 800.
[0229] The user end 800 may also include one or more power supplies 802, one or more wired or wireless network interfaces 803, one or more input and output interfaces 804, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0230] The central processing unit 801 can execute the operations performed by the user terminal in the aforementioned embodiment, and the details will not be repeated here.
[0231] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0232] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0233] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0234] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0235] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
Claims
1. A password detection method, characterized in that: The method comprises: The server receives a ciphertext from the client, the ciphertext being encrypted based on a first key, the first key being encrypted based on a first encryption algorithm to encrypt a user password; The server encrypts the pre-stored target password using the first encryption algorithm to obtain a second key; The server determines whether the user password belongs to the target password according to the ciphertext and the second key; The server sends a feedback message to the user, where the feedback message is used to indicate whether the user password belongs to the target password.
2. The password detection method according to claim 1, characterized in that: The target password is one or more of a weak password, an exposed password, or a sensitive password, and the sensitive password is a password including sensitive words.
3. The password detection method according to claim 1 or 2, characterized in that: The ciphertext is calculated by the first key based on the second encryption algorithm; The server determines whether the user password belongs to the target password according to the ciphertext and the second key, including: The server substitutes the second key and the ciphertext into a decryption algorithm and uses the second key to decrypt the ciphertext, wherein the decryption algorithm corresponds to the second encryption algorithm; If the decryption is successful, the second key is the same as the first key, and the user password belongs to the target password.
4. The password detection method according to claim 3, characterized in that: The server sends a feedback message to the user terminal according to the target result, including: The server sends a first message to the client, where the first message is used to indicate that the user password belongs to the target password.
5. The password detection method according to claim 3, characterized in that: The server substitutes the second key and the ciphertext into a decryption algorithm, and after using the second key to decrypt the ciphertext, the method further includes: If the decryption fails, the second key is different from the first key and the user password does not belong to the target password.
6. The password detection method according to claim 5, characterized in that: The server sends a feedback message to the user terminal according to the target result, including: The server sends a second message to the user, where the second message is used to indicate that the user password does not belong to the target password; The server stores the ciphertext, and the ciphertext is used by the server to authenticate the client when the client logs in.
7. The password detection method according to any one of claims 1 to 6, characterized in that: Before the server receives the ciphertext from the client, the method further includes: The server receives a first encrypted value and a user identifier from the client, wherein the first encrypted value is obtained by encrypting the user password based on a third encryption algorithm, and the user identifier is used to identify a user corresponding to the user password; The server obtains a second encryption value according to the long-term key of the server and the first encryption value, and the long-term key of the server is used by the user end to encrypt the user password; The server sends the second encrypted value and the server identifier to the user.
8. The password detection method according to claim 7, characterized in that: The server uses the first encryption algorithm to encrypt the pre-stored target password to obtain a second key, including: The server encrypts the pre-stored target password using the third encryption algorithm to obtain a third encrypted value; The server obtains a first root key according to the third encrypted value and the long-term key of the server; The server substitutes the first root key, the user identifier and the server identifier into the first encryption algorithm to obtain the second key.
9. A password detection method, characterized in that: The method comprises: The user end encrypts the user password using a first encryption algorithm to obtain a first key; The user terminal sends a ciphertext to the server terminal, where the ciphertext is obtained by the user terminal encrypting the first key using a second encryption algorithm; The user end receives a feedback message from the server end, where the feedback message is used to indicate whether the user password belongs to a target password.
10. The password detection method according to claim 9, characterized in that: The target password is one or more of a weak password, an exposed password, or a sensitive password, and the sensitive password is a password including sensitive words.
11. The password detection method according to claim 9 or 10, characterized in that: The user end receives a feedback message from the server end, including: The user terminal receives a first message from the server terminal, where the first message is used to indicate that the user password belongs to the target password.
12. The password detection method according to claim 9 or 10, characterized in that: The user end receives a feedback message from the server end, including: The user end receives a second message from the server end, where the second message is used to indicate that the user password does not belong to the target password.
13. The password detection method according to any one of claims 9 to 12, characterized in that: Before encrypting the user password using the first encryption algorithm to obtain the first key, the method further includes: The user terminal calculates a first encrypted value according to the user password and the blinding factor; The user terminal sends the first encrypted value and the user identifier to the server terminal; The user terminal receives a second encrypted value and a server identifier from the server terminal, where the second encrypted value includes a long-term key of the server terminal.
14. The password detection method according to claim 13, characterized in that: The user terminal calculates a first encryption value according to the user password and the blinding factor, including: The user terminal substitutes the user password into the third encryption algorithm to obtain a fourth encrypted value; The user end blinds the fourth encrypted value using the blinding factor to obtain the first encrypted value.
15. The password detection method according to claim 13 or 14, characterized in that: The user end encrypts the user password to obtain a first key, including: The user terminal obtains a fifth encrypted value according to the second encrypted value and the blinding factor; The user terminal obtains a second root key according to the fourth encryption value; The user end obtains the first key according to the second root key, the user identifier and the server identifier.
16. The password detection method according to claim 15, characterized in that: The user end obtains a fifth encrypted value according to the second encrypted value and the blinding factor, including: The user terminal removes the blinding factor in the second encrypted value to obtain the fifth encrypted value.
17. A server, characterized in that: include: A receiving unit, configured to receive a ciphertext from a user terminal, wherein the ciphertext is encrypted based on a first key, wherein the first key is obtained by encrypting a user password based on a first encryption algorithm; An encryption unit, used to encrypt the pre-stored target password using the first encryption algorithm to obtain a second key; a judging unit, configured to judge whether the user password belongs to the target password according to the ciphertext and the second key; The sending unit is used to send a feedback message to the user terminal, where the feedback message is used to indicate whether the user password belongs to the target password.
18. A user terminal, characterized in that: include: An encryption unit, used to encrypt the user password using a first encryption algorithm to obtain a first key; A sending unit, used to send a ciphertext to a server, where the ciphertext is obtained by encrypting the first key by the client using a second encryption algorithm; The receiving unit is used to receive a feedback message from the server, wherein the feedback message is used to indicate whether the user password belongs to a target password.
19. A server, characterized in that: include: A processor and a memory, wherein the processor is coupled to the memory; The memory is used to store programs; The processor is used to execute the program in the memory so that the server executes the method as described in any one of claims 1 to 8.
20. A user terminal, characterized in that: include: A processor and a memory, wherein the processor is coupled to the memory; The memory is used to store programs; The processor is used to execute the program in the memory so that the user terminal executes the method as described in any one of claims 9 to 16.
21. A password detection system, characterized in that: It includes the user side and the server side, among which, The user terminal is used to encrypt the user password using a first encryption algorithm to obtain a first key; The client terminal is also used to send a ciphertext to the server terminal, wherein the ciphertext is encrypted by the client terminal using a second encryption algorithm to encrypt the first key Encrypted; The server is used to receive the ciphertext from the client; The server is further configured to encrypt the pre-stored target password using the first encryption algorithm to obtain a second key; The server is further configured to determine whether the user password belongs to the target password according to the ciphertext and the second key; The server is further configured to send a feedback message to the user, wherein the feedback message is configured to indicate whether the user password belongs to the target password; The user end is also used to receive the feedback message from the server end.
22. A computer-readable storage medium comprising instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 8, or enable the computer to execute the method according to any one of claims 9 to 16.
Citation Information
Patent Citations
Weak-password detection system and method of linux system
CN107679397A
Data inspection method and device, computer readable storage medium and electronic equipment
CN114697119A
Weak password detection method and device, storage medium, electronic equipment and computer program product
CN115062293A
Security chip encryption and decryption method and device based on multi-key encryption and decryption
CN115065472A
Weak password identification method, device and system, electronic equipment and storage medium
CN116846608A