CN103684767A - Dynamic password generation device and method - Google Patents

Dynamic password generation device and method Download PDF

Info

Publication number
CN103684767A
CN103684767A CN201210326523.6A CN201210326523A CN103684767A CN 103684767 A CN103684767 A CN 103684767A CN 201210326523 A CN201210326523 A CN 201210326523A CN 103684767 A CN103684767 A CN 103684767A
Authority
CN
China
Prior art keywords
dynamic password
user
dynamic
sensor assembly
equipment
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201210326523.6A
Other languages
Chinese (zh)
Other versions
CN103684767B (en
Inventor
胡鹏
吴匀
陈杰
靳松
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Watertek Information Technology Co Ltd
Original Assignee
Beijing Watertek Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Watertek Information Technology Co Ltd filed Critical Beijing Watertek Information Technology Co Ltd
Priority to CN201210326523.6A priority Critical patent/CN103684767B/en
Publication of CN103684767A publication Critical patent/CN103684767A/en
Application granted granted Critical
Publication of CN103684767B publication Critical patent/CN103684767B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention provides a dynamic password generation device and method, relates to the field of information security, and solves the problem that an existing token is not convenient. The dynamic password generation device comprises a central processing unit (CPU), a sensor module and a peripheral display device, wherein the CPU is connected with both the sensor module and the peripheral display device; the sensor module is used for generating external information of the dynamic password generation device through collected dynamic passwords, quantifying the external information, and then sending the external information to the CPU; the CPU is used for receiving the quantified external information sent by the sensor module, generating dynamic passwords according to the external information, and outputting the dynamic passwords to the peripheral display device; the peripheral display device is used for displaying the dynamic passwords output by the CPU. The technical scheme provided in the invention is applicable to identity authentication dynamic tokens, and achieves convenient and safe dynamic tokens.

Description

Dynamic password generates equipment and method
Technical field
The present invention relates to information security field, relate in particular to a kind of dynamic password and generate equipment and method.
Background technology
Fast development along with computer technology, the Internet and development of Mobile Internet technology, domestic enterprise group, government bodies and financial institution are all utilizing network to set up a network channel fast and efficiently between own and masses, for people provide various application service.Owing to being the information service realizing based on the Internet, so the fail safe of application system seems particularly important.Aspect raising security of system, user's authentication is again necessary and important key link.In realizing user's identity identifying technology, dynamic token, USBKey are general selections at present, wherein because dynamic token is without any software is installed in user's client, can meet the instructions for use of the Internet and mobile Internet application system, as can be used simultaneously, be therefore subject to user's favor on PC and smart mobile phone.But because at present fail safe can meet the dynamic token of the challenge response formula of system requirements, its mode that produces dynamic password must allow user carry out key-press input, and has greatly affected the property easy to use of this product.
Summary of the invention
The invention provides a kind of dynamic password and generate equipment and method, solved not problem easily of existing dynamic token.
Dynamic password generates an equipment, comprising:
Central processing unit, sensor assembly and peripheral display device, described central processing unit is all connected with described peripheral display device with described sensor assembly:
The backward described central processing unit of external information quantification that described sensor assembly generates equipment by the described dynamic password collecting sends;
Described central processing unit, receives the described external information after the quantification that described sensor assembly sends, and according to described external information, generates dynamic password, exports described dynamic password to described peripheral display device;
Described peripheral display device shows the dynamic password from described central processing unit output.
Preferably, described central processing unit is also connected with memory module;
Use habit information when described memory module receives user that described sensor assembly collects and swings described dynamic password and generate equipment is also stored described use habit information, and described use habit information is offered to described central processing unit;
Described central processing unit reads the described use habit information in described memory module, and the described external information that described sensor assembly is collected and described use habit information are compared.
Preferably, described sensor assembly comprises the combination of arbitrary following transducer or any number of following transducers:
Gravity sensor, acceleration transducer, gyroscope, electronic compass and light distance-sensor.
Preferably, described central processing unit is also to described peripheral display device output user operation prompt information;
Described peripheral display device shows user's operation prompt information that described central processing unit sends.
Preferably, also comprise keyboard, described keyboard is connected with described central processing unit, and described keyboard comprises numerical key, confirms function key and cancels function key.
The present invention also provides a kind of dynamic password formation method, and dynamic token is built-in with sensor assembly, and the method comprises:
Described dynamic token receives the external information that described sensor assembly is collected and quantized;
Described dynamic token, using described external information as the challenge factor, generates dynamic password according to the described challenge factor.
Preferably, described dynamic token, using described external information as the challenge factor, before generating the step of dynamic password, also comprises according to the described challenge factor:
Described external information and the user's use habit information prestoring are compared;
Described external information with described in user's use habit information of prestoring when consistent, determine that user identity is legal, start dynamic password product process.
Preferably, described dynamic token receive that described sensor assembly is collected and the step of the external information that quantizes before, also comprise:
Select this mode of operation of weave mode, under this weave mode, described dynamic token indicates described sensor assembly to collect external information.
Preferably, above-mentioned dynamic password formation method also comprises:
Select this mode of operation of self-defined pattern, under this self-defined pattern, described dynamic token indicates described sensor assembly to collect user's use habit information.
Preferably, after the step of self-defined this mode of operation of pattern of described selection, also comprise:
Described sensor assembly is collected user's use habit information;
Described dynamic token receives and stores described user's use habit information.
The invention provides a kind of dynamic password and generate equipment and method, dynamic token is built-in with sensor assembly, described dynamic token receives the external information that described sensor assembly is collected and quantized, using described external information as the challenge factor, according to the described challenge factor, generate dynamic password, realized by sensor assembly, gathering user action and operate to trigger generation dynamic password, solved not problem easily of existing dynamic token.
Accompanying drawing explanation
Fig. 1 is the structural representation that a kind of dynamic password that embodiments of the invention one provide generates equipment;
Fig. 2 is the flow chart of a kind of dynamic password formation method of providing of embodiments of the invention two;
Fig. 3 is the structural representation that a kind of dynamic password that embodiments of the invention three provide generates equipment;
Fig. 4 is that a kind of dynamic password that embodiments of the invention three provide generates equipment mode of operation selection flow chart;
Fig. 5 is the flow chart that a kind of dynamic password that embodiments of the invention three provide generates the self-defined mode of operation of equipment;
Fig. 6 is that a kind of dynamic password that embodiments of the invention three provide generates the standby flow chart that swings mode of operation of equipment.
Embodiment
In realizing user's identity identifying technology, dynamic token, USBKey are general selections at present, wherein because dynamic token is without any software is installed in user's client, can meet the instructions for use of the Internet and mobile Internet application system, as can be used simultaneously, be therefore subject to user's favor on PC and smart mobile phone.But because at present fail safe can meet the dynamic token of the challenge response formula of system requirements, its mode that produces dynamic password must allow user carry out key-press input, and has greatly affected the property easy to use of this product.And any acquisition dynamic token can use this equipment per capita, therefore in fail safe, also there is risk.
In order to address the above problem, embodiments of the invention provide a kind of dynamic password to generate Apparatus and method for, realize and adopting without the mode of producing dynamic password after user key-press, solved equipment easy applied performance problem, simultaneously, transformation dynamic token equipment is realized the identity authentication function to user, thereby has realized three factor authentication, has greatly strengthened the fail safe of network application system.
Hereinafter in connection with accompanying drawing, embodiments of the invention are elaborated.It should be noted that, in the situation that not conflicting, the embodiment in the application and the feature in embodiment be combination in any mutually.
First by reference to the accompanying drawings, embodiments of the invention one are described.
The embodiment of the present invention provides a kind of dynamic password to generate equipment, and the structure of this equipment as shown in Figure 1, comprising:
Central processing unit 101, sensor assembly 102 and peripheral display device 103, described central processing unit 101 is all connected with described peripheral display device 103 with described sensor assembly 102:
The backward described central processing unit 101 of external information quantification that described sensor assembly 102 generates equipment by the described dynamic password collecting sends;
Described central processing unit 101, receives the described external information after the quantification that described sensor assembly 102 sends, and according to described outside token, generates dynamic password, exports described dynamic password to described peripheral display device 103;
Described peripheral display device 103 shows the dynamic password from described central processing unit 101 outputs.
Preferably, described central processing unit 101 is also connected with memory module 104, use habit information when the user that the described sensor assembly 102 of described memory module 104 reception collects swings described dynamic password generation equipment is also stored described use habit information, and described use habit information is offered to described central processing unit 101;
Described central processing unit 101 reads the described use habit information in described memory module 104, and the described external information that described sensor assembly 102 is collected and described use habit information are compared.
Preferably, described sensor assembly 102 comprises the combination of arbitrary following transducer or any number of following transducers:
Gravity sensor, acceleration transducer, gyroscope, electronic compass and light distance-sensor.It should be noted that, in the embodiment of the present invention, related transducer is not limited to above-mentioned several.Sensor assembly 102 is external input equipments of equipment, the various state informations of equipment can be provided to central processing unit 101, as position, acceleration, inclination angle etc., the various state informations of assisting central processing unit 101 that the dynamic password of collection is generated to equipment are carried out quantization operation.
Preferably, described central processing unit 101 is also to described peripheral display device 103 output user operation prompt information;
Described peripheral display device 103 shows user's operation prompt information that described central processing unit 101 sends.
Preferably, above-mentioned dynamic password generates equipment and also comprises keyboard 105, and described keyboard 105 is connected with described central processing unit 101, and described keyboard comprises numerical key, confirms function key and cancels function key.
Below in conjunction with accompanying drawing, embodiments of the invention two are described.
The embodiment of the present invention provides a kind of dynamic password formation method, and dynamic token is built-in with sensor assembly, and in the embodiment of the present invention, this dynamic token specifically can be realized by dynamic password generation equipment as shown in Figure 1.Use the flow process of the method generation dynamic password as shown in Figure 2, comprising:
Step 201, selection mode of operation;
In the embodiment of the present invention, dynamic token is selected mode of operation, can set in advance multiple-working mode selects for user, as self-defined pattern (is used for recording the operation that user puts dynamic token, as user's use habit information, for identifying user identity legitimacy provide according to), weave mode (external information while being used for collecting the operations such as user put), button pattern (when dynamic password is equipped with keyboard, by keyboard input, carries out authentication or input and challenge the factor by keyboard) etc.
Preferably, while being equipped with keyboard on dynamic token, consider cost-saving problem, too much function button is not set on keyboard, but adopt the mode of digital keys combination to carry out the selection of associative mode.Such as: after " 1 " and " 2 " digital keys is pressed simultaneously, system enters " weave mode "; After " 2 " and " 3 " digital keys is pressed simultaneously, system enters " button pattern "; After " 4 " and " 5 " digital keys is pressed simultaneously, system enters " self-defined pattern ".Because compound mode is diversified, so do not setting forth at this, the key combination mode that can realize selection function all belongs to the scope that the embodiment of the present invention is protected.
In this step, if selected self-defined pattern, described dynamic token indicates described sensor assembly to collect user's use habit information, enters step 202; If selected weave mode, described dynamic token indicates described sensor assembly to collect external information, enters step 204.
Step 202, described sensor assembly are collected user's use habit information;
User's use habit information has comprised the information that in sensor assembly, various transducers gather, and these information have been described user's use habit, can be used as the foundation that user's legal identity is confirmed.
Preferably, in the display screen of dynamic token, can point out user to carry out multiple operation, as swing dynamic token from left to right, or swing dynamic token from top to bottom, or swing dynamic token from front to back etc.Dynamic token is opened its inner sensor assembly, gathers the residing state information of dynamic token.As utilize the gravity sensitive of sensor assembly to answer device, based on piezoelectric effect, pass through to measure the numerical value of inner a slice weight gravity quadrature both direction component, the horizontal direction of discriminating device, and the residing angle of inclination of sensing apparatus; Utilize the 3-axis acceleration sensor of sensor assembly to extrapolate equipment gradient, attitude and the direction of motion with respect to the horizontal plane according to the acceleration of gravity sensing generation.
Under the acting in conjunction of a plurality of transducers, after can and quantizing informations such as the dynamics of user's rocking apparatus, amplitude, acceleration, spread out of and process to central processing unit, central processing unit produces digital code and is retained in memory module.
After having collected user's use habit information after prompting, dynamic token enters the next stage, but when after dynamic token is pointing out user to operate, a period of time user does not do any operation, dynamic token automatically returns to mode of operation selection mode, and retains the interior original user habit information of dynamic token in memory module.
Step 203, described dynamic token receive and store described user's use habit information;
Preferably, this step can record user's use habit information that multi collect arrives, and compare and record after each sample information, according to sampling statistics rule, form user and swing custom digital information characteristic value, obtain user's use habit token more accurately, and be recorded in device storage module.
Step 204, dynamic token receive the external information that described sensor assembly is collected and quantized;
In this step, user need to login the Internet or mobile Internet application system, utilize dynamic password system interface or dynamic token display screen prompting user that equipment is waved to operation, can specify pendulum direction (as from top to bottom, from left to right, from front to back etc.) and number of oscillations.System backstage is that the numeral after quantizing according to the swing mode of equipment is carried out dynamic password calculating as dynamic password seed, and this swing mode swings mode to consistent with device interior.The quantification of swing mode can adopt first up and then down mode to equal " 1 "; Adopt first left and then right mode to equal " 2 "; Mode after lower before and after adopting first equals " 3 "; The mode that employing gets on, get off equals " 4 "; Adopt the first mode on a right back left side to equal " 5 "; Mode before and after after adopting successively equals " 6 "; Differently by that analogy be combined to form different quantification numerals.
Because the mode that dynamic token motion mode is quantized is a lot, its principle is all identical, is all that the action by specific program activates dynamic token, so do not enumerate at this.
Step 205, described external information and user's use habit information of prestoring are compared;
In this step, the numerical value of relevant parameter in the data such as the amplitude swinging in the external information collecting, acceleration and user's use habit information of having stored is compared, confirm user's identity.When comparison result is consistent, think that user identity is legal.
Step 206, described external information with described in user's use habit information of prestoring when consistent, determine that user identity is legal, start dynamic password product process.
If external information with described in user's use habit information of prestoring inconsistent, determine that user identity is illegal, does not carry out the operation that generates dynamic password.
Step 207, dynamic token, using described external information as the challenge factor, generate dynamic password according to the described challenge factor;
In this step, central processing unit calls dynamic password generating algorithm and calculates dynamic password.
Step 208, show described dynamic password.
Afterwards, user just can be input to dynamic password in the network system dynamic password confirmation page, completes identity validation.
Below in conjunction with accompanying drawing, embodiments of the invention three are described.
The embodiment of the present invention provides a kind of dynamic password to generate Apparatus and method for, to improve convenience and the fail safe of authentication in network application system.
The structure of the dynamic password generation equipment that the embodiment of the present invention provides as shown in Figure 3, comprising:
Central processing unit 301, the generation of realization to the control of whole equipment, dynamic password, the collection of transducer control and information, the calculating of the custom of user's rocking apparatus, it is subject to battery that power work is provided.
Sensor assembly 302: it is comprised of various transducer, such as gravity sensor, acceleration transducer, gyroscope, electronic compass and light distance-sensor etc., but is not limited to this.It is the external input equipment of equipment, can to central processing unit, provide the position of the various states of equipment, acceleration, and the information such as inclination angle, assist central processing unit that the various state informations of the equipment of collection are carried out to quantization operation.
Key-press module 303: as keyboard etc., by numerical key, confirm to cancel function key, a plurality of buttons such as function switch key form, but are not only confined to this.It is also the external input equipment of equipment.User can carry out Password Input, function switching etc. by this button.
Battery 304: for whole equipment provides power supply support.
Memory module 305: user's use habit of equipment records and the various states of equipment can be kept at this inside, and it can realize repeatedly erasable, central processing unit can read its internal information and carries out various comparison operations if desired, and realizes the confirmation of user habit.
Display module 306: for user provides function information to show and the functions such as demonstration of dynamic password, be the peripheral display device of equipment.
In the embodiment of the present invention, on the basis of conventional dynamic token device, increased sensor assembly, this module can gather and quantize the motor habit that user uses equipment, with this by tradition the challenge factor by key-press input dynamic password, change into user by rocking apparatus complete challenge the factor input.The present invention simultaneously also provides by user's rocking apparatus and has realized the method that dynamic password generates.The Internet or mobile Internet application system related in the embodiment of the present invention can be including, but not limited to Internet bank's system, cell phone bank system, office automation yarn system, information management systems; Certainly, can be also some systems of using towards the public, as network game system.
In the embodiment of the present invention, it is a safe SOC chip of height based on 8 or above risc processor that dynamic password generates chip that the central processing unit of equipment adopts, possesses the features such as high throughput, high security, low-power consumption, low cost.As the Z8D168U chip of national technology or chip of the same type etc.The generation to the control dynamic password of this equipment by the exploitation realization to its embedded OS on this chip, the collection of transducer control and information, the calculating of the custom of user's rocking apparatus, it is subject to battery that power work is provided.
Sensor assembly is partly to realize the key modules that obtains the dynamic password challenge factor by swing, it is comprised of various transducer, such as gravity sensor, acceleration transducer, gyroscope, electronic compass and light distance-sensor etc., but be not limited to this.Sensor assembly is the external input equipment of equipment, can to central processing unit, provide the position of the various states of equipment, acceleration, and the information such as inclination angle, assist central processing unit that the various state informations of the equipment of collection are carried out to quantization operation.
In the embodiment of the present invention, gravity sensor and acceleration transducer are combined with, the swingable scope of equipment is expanded to 360 degree.Gravity sensor getting up early appears at the transducer on mobile phone.At present, most of main flow intelligent machines are all equipped with this configuration.In iOS, Android platform, a lot of game all apply to gravity sensor, and they bring user fresh experience.Gravity sensor, based on piezoelectric effect, by measuring the numerical value of inner a slice weight gravity quadrature both direction component, is differentiated horizontal direction like this.The acceleration that 3-axis acceleration sensor in this programme can produce according to gravity sensing is extrapolated mobile phone gradient with respect to the horizontal plane.Utilize above sensor device can awareness apparatus the static attitude of gravity around, equipment and the direction of motion etc., realize thus the situation of its current residing angle of device-aware, rotation and amplitude of fluctuation, and corresponding data feedback is carried out to data processing to central processing unit.
Preferably, in the embodiment of the present invention, can also increase electronic compass transducer and distinguish earth magnetic field conditions; Increase three-axis gyroscope and utilize conservation of angular momentum principle, can differentiate the variation of relative position, direction, angle and the level of object in space; Increase light distance-sensor and utilize the perception to light, the power of identifying extraneous light allows equipment carry out the input etc. of the dynamic password factor.Above transducer only need combine the input that can realize the more dynamic password factor flexibly, because compound mode is varied, and can be according to user's actual demand customization, therefore do not enumerate at this.
Key-press module is by numerical key, confirms to cancel function key, and a plurality of buttons such as function switch key form, but are not only confined to this.It is also the external input equipment of equipment.User can carry out Password Input, function switching etc. by this button.
Battery provides power supply support for whole equipment.
Memory module is that user's use habit of equipment records and the various states of equipment can be kept at this inside, and it can realize repeatedly erasable, and central processing unit can read its internal information and carries out various comparison operations if desired, and realizes the confirmation of user habit.
Display module: for user provides function information to show and the functions such as demonstration of dynamic password, be the peripheral display device of equipment.
Be that in the embodiment of the present invention, dynamic password generates equipment mode of operation selection flow chart as shown in Figure 4, its step is as follows:
Step 401, device start;
At this, when user need to login the Internet or mobile Internet application system, system requirements user adopts dynamic password login, and user produces the selection of dynamic password mode according to the prompting of system.
The selection of step 402, mode of operation;
At this, user loads by the own button of equipment, carries out the selection of function.The key device of equipment may be the direct selection of function key, as " weave mode ", " button pattern ", " self-defined pattern "; Or owing to considering cost-saving problem, too much function button is not set on equipment, but adopts the mode of digital keys combination to carry out the selection of associative mode.Such as: after " 1 " and " 2 " digital keys is pressed simultaneously, system enters " weave mode "; After " 2 " and " 3 " digital keys is pressed simultaneously, system enters " button pattern "; After " 4 " and " 5 " digital keys is pressed simultaneously, system enters " self-defined pattern ".At this because compound mode is diversified, so do not setting forth at this.
Step 403, User Defined pattern;
At this, equipment collection recording user use habit, the foundation of confirming as user's legal identity.Visible Fig. 5 of detailed description of this process.
Step 404, swing produce dynamic password pattern;
At this, equipment can be realized the generation of dynamic password factor according to user's swing situation, and confirms user's legal identity, and finally forms dynamic password.Visible Fig. 6 of detailed description of this process.
Step 405, the first heavy dynamic password pattern of button;
In this step, the keyboard of usining input is as the challenge factor.
Step 406, finish and wait for;
At this, the dynamic password that user has produced equipment inputs and submits to application system to carry out identity validation by computer, mobile terminal or smart mobile phone.Now because having completed one, equipment completes flow process, so equipment is in finishing and wait state, until user's activated equipment need to again carry out identity validation time.
Be the flow chart that the dynamic password generation equipment that provides of the embodiment of the present invention generates the self-defined mode of operation of dynamic password as shown in Figure 5, its step is as follows:
Step 501, self-defined mode of operation start;
Equipment is selected according to user's keypress function on last stage, and has entered in this flow process.At this stage equipment, can gather user's use habit, the foundation of confirming as user's legal identity.
Step 502, device display screen curtain prompting user carry out swinging operation;
At this, equipment points out user to carry out multiple operation in the display screen carrying, as rocking apparatus from left to right, or rocking apparatus from top to bottom, or rocking apparatus from front to back.Its inner sensor assembly of opening of device, the residing state information of collecting device.After equipment has collected information after prompting, enter the next stage, but when equipment is not when a period of time is done any operation after prompting, equipment automatically returns to mode of operation selection mode, and the interior original user habit information of retaining device is in memory module.
Step 503, equipment are according to the dynamics of user's rocking apparatus, amplitude, the informations such as acceleration;
At this, the gravity sensitive of the sensor assembly of equipment utilization self is answered device, passes through to measure the numerical value of inner a slice weight gravity quadrature both direction component, the horizontal direction of discriminating device, and the residing angle of inclination of sensing apparatus based on piezoelectric effect.Meanwhile, the acceleration that the 3-axis acceleration sensor of the sensor assembly of equipment utilization self produces according to gravity sensing is extrapolated equipment gradient, attitude and the direction of motion with respect to the horizontal plane.
In the situation that the work of a plurality of transducers, equipment is by the dynamics of user's rocking apparatus, and amplitude, spreads out of to central processing unit and process after the informations such as acceleration and quantification, and central processing unit production figures code is retained in memory module.
Equipment enters next step after being successfully completed and once gathering.If when equipment fails to catch any operation information, equipment automatically returns to previous step, and the interior original user habit information of retaining device is in memory module.
Step 504, in comparison data after sampling repeatedly repeatedly, the swing that quantizes user is accustomed to and is stored in memory module;
At this, equipment is repeating step 503 and step 504 content repeatedly, the habits information of multi collect user rocking apparatus, and compare and record after each sample information, according to sampling statistics rule, form user and swing custom digital information characteristic value, and be recorded in device storage module, this sampling process is no less than 3 times.
Step 505, end.
Be the dynamic password product process figure that the dynamic password generation equipment that provides of the embodiment of the present invention swings mode of operation as shown in Figure 6, its step is as follows:
Step 601, swing mode of operation start;
At this, equipment can be realized the generation of dynamic password factor according to user's swing situation, and confirms user's legal identity, and finally forms dynamic password.
Step 602, the information of pointing out according to dynamic password system interface are carried out left and right or the upper and lower equipment that rocks;
At this, the Internet of the required login of user or mobile Internet application system utilize dynamic password system interface prompting user that equipment is waved to operation, and as from top to bottom, from left to right, from front to back etc. mode swings several times.System backstage is that the numeral after quantizing according to the swing mode of equipment is carried out dynamic password calculating as dynamic password seed, and this swing mode swings mode to consistent with device interior.The quantification of swing mode can adopt first up and then down mode to equal " 1 "; Adopt first left and then right mode to equal " 2 "; Mode after lower before and after adopting first equals " 3 "; The mode that employing gets on, get off equals " 4 "; Adopt the first mode on a right back left side to equal " 5 "; Mode before and after after adopting successively equals " 6 "; Differently by that analogy be combined to form different quantification numerals.
Because the mode that equipment moving mode is quantized is a lot, because mode is similar, so do not do too much elaboration at this.
Step 603, equipment are confirmed user identity according to the custom of the previous self-defining use equipment of user;
At this, user carries out waving of equipment according to the prompting of system, and equipment gathers the amplitude of user's rocking apparatus, and the user habit numerical value that the data such as acceleration have been stored user is compared, and confirms user's identity.
Step 604, after confirming user identity, the generation seed according to the direction of user's rocking apparatus and number of times as dynamic password;
At this, equipment gathers user this time direction and the number of times of rocking apparatus, and is sent in central processing unit and quantizes, and as the generation seed of dynamic password.Central processing unit calls dynamic password generating algorithm and calculates corresponding dynamic password.
Step 605, equipment calculate dynamic password and are presented on display screen;
The dynamic password password that step 606, user generate equipment is input in system by smart machine, completes identity validation;
Step 607, end.
It should be noted that, in embodiments of the invention, use button to produce the consistent of dynamic password pattern and traditional challenge response type dynamic token, so no longer set forth at this.
Embodiments of the invention provide a kind of dynamic password to generate equipment and method, dynamic token is built-in with sensor assembly, dynamic token receives the external information that described sensor assembly is collected and quantized, again described external information and the user's use habit information prestoring are compared, described external information with described in user's use habit information of prestoring when consistent, generate dynamic password, realized by sensor assembly, gathering user action and operate to trigger generation dynamic password, solved the not convenient and unsafe problem of existing dynamic token.
Embodiments of the invention provide triple channel to verify the legitimacy of login user.First passage is the dynamic token equipment that legacy user has, i.e. " thing that user has "; Second channel is the dynamic password that equipment produces according to rocking apparatus mode, i.e. " secret known to user "; Third channel is that equipment can be confirmed user's identity by user's use habit, only has definite user just can use, i.e. " user institute particular attribute " thereby realize.Therefore the technical scheme that, the embodiment of the present invention provides has improved the fail safe of data and people's convenience of equipment use in network application system.
In sum, this invention can be widely used in system login and authentication on the Internet and mobile Internet, such as, bank, security, public security, army and E-Government etc. are in the higher application system of data security requirement, raising system manager and user use the fail safe of system, and it has following advantage:
1, convenient and simple: user, without using key-press input, realizes the generation of dynamic password fast by rocking apparatus.
2, safe: this equipment is the mode that multiple-factor is confirmed, user has an equipment, and this equipment can generate secret dynamic password, equipment is determined the authentication that realizes user by individual use habit simultaneously.
The all or part of step that one of ordinary skill in the art will appreciate that above-described embodiment can realize by computer program flow process, described computer program can be stored in a computer-readable recording medium, described computer program (as system, unit, device etc.) on corresponding hardware platform is carried out, when carrying out, comprise step of embodiment of the method one or a combination set of.
Alternatively, all or part of step of above-described embodiment also can realize with integrated circuit, and these steps can be made into respectively integrated circuit modules one by one, or a plurality of modules in them or step are made into single integrated circuit module realize.Like this, the present invention is not restricted to any specific hardware and software combination.
Each device/functional module/functional unit in above-described embodiment can adopt general calculation element to realize, and they can concentrate on single calculation element, also can be distributed on the network that a plurality of calculation elements form.
The form of software function module of usining each device/functional module/functional unit in above-described embodiment realizes and during as production marketing independently or use, can be stored in a computer read/write memory medium.The above-mentioned computer read/write memory medium of mentioning can be read-only memory, disk or CD etc.
Anyly be familiar with those skilled in the art in the technical scope that the present invention discloses, can expect easily changing or replacing, within all should being encompassed in protection scope of the present invention.Therefore, protection scope of the present invention should be as the criterion with the protection range described in claim.

Claims (10)

1. dynamic password generates an equipment, it is characterized in that, comprise central processing unit, sensor assembly and peripheral display device, described central processing unit is all connected with described peripheral display device with described sensor assembly:
The backward described central processing unit of external information quantification that described sensor assembly generates equipment by the described dynamic password collecting sends;
Described central processing unit, receives the described external information after the quantification that described sensor assembly sends, and according to described external information, generates dynamic password, exports described dynamic password to described peripheral display device;
Described peripheral display device shows the dynamic password from described central processing unit output.
2. dynamic password according to claim 1 generates equipment, it is characterized in that, described central processing unit is also connected with memory module;
Use habit information when described memory module receives user that described sensor assembly collects and swings described dynamic password and generate equipment is also stored described use habit information, and described use habit information is offered to described central processing unit;
Described central processing unit reads the described use habit information in described memory module, and the described external information that described sensor assembly is collected and described use habit information are compared.
3. dynamic password according to claim 1 generates equipment, it is characterized in that, described sensor assembly comprises the combination of arbitrary following transducer or any number of following transducers:
Gravity sensor, acceleration transducer, gyroscope, electronic compass and light distance-sensor.
4. dynamic password according to claim 1 generates equipment, it is characterized in that, described central processing unit is also to described peripheral display device output user operation prompt information;
Described peripheral display device shows user's operation prompt information that described central processing unit sends.
5. dynamic password according to claim 1 generates equipment, it is characterized in that, also comprise keyboard, described keyboard is connected with described central processing unit, and described keyboard comprises numerical key, confirms function key and cancels function key.
6. a dynamic password formation method, is characterized in that, dynamic token is built-in with sensor assembly, and the method comprises:
Described dynamic token receives the external information that described sensor assembly is collected and quantized;
Described dynamic token, using described external information as the challenge factor, generates dynamic password according to the described challenge factor.
7. dynamic password formation method according to claim 6, is characterized in that, described dynamic token, using described external information as the challenge factor, before generating the step of dynamic password, also comprises according to the described challenge factor:
Described external information and the user's use habit information prestoring are compared;
Described external information with described in user's use habit information of prestoring when consistent, determine that user identity is legal, start dynamic password product process.
8. dynamic password formation method according to claim 6, is characterized in that, described dynamic token receive that described sensor assembly is collected and the step of the external information that quantizes before, also comprise:
Select this mode of operation of weave mode, under this weave mode, described dynamic token indicates described sensor assembly to collect external information.
9. dynamic password formation method according to claim 7, is characterized in that, the method also comprises:
Select this mode of operation of self-defined pattern, under this self-defined pattern, described dynamic token indicates described sensor assembly to collect user's use habit information.
10. dynamic password formation method according to claim 9, is characterized in that, after the step of self-defined this mode of operation of pattern of described selection, also comprises:
Described sensor assembly is collected user's use habit information;
Described dynamic token receives and stores described user's use habit information.
CN201210326523.6A 2012-09-05 2012-09-05 Dynamic password generates apparatus and method Active CN103684767B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210326523.6A CN103684767B (en) 2012-09-05 2012-09-05 Dynamic password generates apparatus and method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210326523.6A CN103684767B (en) 2012-09-05 2012-09-05 Dynamic password generates apparatus and method

Publications (2)

Publication Number Publication Date
CN103684767A true CN103684767A (en) 2014-03-26
CN103684767B CN103684767B (en) 2017-12-26

Family

ID=50321165

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210326523.6A Active CN103684767B (en) 2012-09-05 2012-09-05 Dynamic password generates apparatus and method

Country Status (1)

Country Link
CN (1) CN103684767B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104463679A (en) * 2014-12-19 2015-03-25 上海斐讯数据通信技术有限公司 Virtual currency transaction system and method
CN104766206A (en) * 2015-04-22 2015-07-08 广东欧珀移动通信有限公司 NFC payment method and device based on mobile terminal
CN105649470A (en) * 2016-03-22 2016-06-08 百色学院 Password control system of intelligent safety box

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1517889A (en) * 2003-01-14 2004-08-04 盖内蒂克瓦尔有限公司 Keyboard device with authentication function for user and ints method
CN101159551A (en) * 2007-08-23 2008-04-09 北京飞天诚信科技有限公司 Multifunctional information safety equipment and method of use thereof
CN101197665A (en) * 2007-12-24 2008-06-11 北京飞天诚信科技有限公司 Dynamic password generation method and device thereof
CN101753301A (en) * 2008-11-28 2010-06-23 谈剑锋 Fingerprint dynamic password ID authentication device and the implementation method thereof
CN101789862A (en) * 2010-01-25 2010-07-28 中兴通讯股份有限公司 Encryption and decryption device and method based on gravity acceleration
CN101841417A (en) * 2010-03-12 2010-09-22 李勇 Electronic signature device supporting short-distance wireless communication technology and method for ensuring safety of electronic transaction by applying same
CN102129294A (en) * 2011-03-02 2011-07-20 北京天地融科技有限公司 Information input method and device thereof
CN102447560A (en) * 2011-12-30 2012-05-09 深圳市文鼎创数据科技有限公司 Dynamic token with optical communication unit
CN202268898U (en) * 2011-10-08 2012-06-06 北京集联网络技术有限公司 Electronic dynamic token vibration waking circuit and device thereof

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1517889A (en) * 2003-01-14 2004-08-04 盖内蒂克瓦尔有限公司 Keyboard device with authentication function for user and ints method
CN101159551A (en) * 2007-08-23 2008-04-09 北京飞天诚信科技有限公司 Multifunctional information safety equipment and method of use thereof
CN101197665A (en) * 2007-12-24 2008-06-11 北京飞天诚信科技有限公司 Dynamic password generation method and device thereof
CN101753301A (en) * 2008-11-28 2010-06-23 谈剑锋 Fingerprint dynamic password ID authentication device and the implementation method thereof
CN101789862A (en) * 2010-01-25 2010-07-28 中兴通讯股份有限公司 Encryption and decryption device and method based on gravity acceleration
CN101841417A (en) * 2010-03-12 2010-09-22 李勇 Electronic signature device supporting short-distance wireless communication technology and method for ensuring safety of electronic transaction by applying same
CN102129294A (en) * 2011-03-02 2011-07-20 北京天地融科技有限公司 Information input method and device thereof
CN202268898U (en) * 2011-10-08 2012-06-06 北京集联网络技术有限公司 Electronic dynamic token vibration waking circuit and device thereof
CN102447560A (en) * 2011-12-30 2012-05-09 深圳市文鼎创数据科技有限公司 Dynamic token with optical communication unit

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104463679A (en) * 2014-12-19 2015-03-25 上海斐讯数据通信技术有限公司 Virtual currency transaction system and method
CN104766206A (en) * 2015-04-22 2015-07-08 广东欧珀移动通信有限公司 NFC payment method and device based on mobile terminal
CN104766206B (en) * 2015-04-22 2018-03-13 广东欧珀移动通信有限公司 A kind of NFC payment and device based on mobile terminal
CN105649470A (en) * 2016-03-22 2016-06-08 百色学院 Password control system of intelligent safety box

Also Published As

Publication number Publication date
CN103684767B (en) 2017-12-26

Similar Documents

Publication Publication Date Title
KR101662396B1 (en) Method and system for controlling device based internet of things
CN103814380B (en) For strengthening the method and apparatus of the security in equipment using multiple-factor password or dynamic password
CN107735999B (en) Authentication through multiple pathways based on device functionality and user requests
CN106471517B (en) The visualization different because of user to display elements
US20180114004A1 (en) Methods and systems for data entry
CN110135126A (en) Request the user interface of the equipment of remote authorization
CN104392157B (en) Method and device for locking screen by using passwords
CN106485486A (en) The method for processing payment information of electronic equipment and device
CN109583876A (en) For the loyalty account of wearable device and the user interface of Own Brand account
CN106030599A (en) Continuous authentication with a mobile device
CN105320276A (en) Wearable device and method of operating the same
KR20170035294A (en) Electronic device and payment method of providing security thereof
US9721087B1 (en) User authentication
CN107256155A (en) Menu adaptation method, server and the readable storage medium storing program for executing of background management system
CN107316395A (en) A kind of autonomous system for borrowing and returning of sports equipment and its method
CN110324350A (en) Identity identifying method and server based on the non-sensitive sensing data in mobile terminal
CN106464694A (en) Security adjustments in mobile devices
US20190319843A1 (en) Trusted Platform Module-Based Prepaid Access Token for Commercial IoT Online Services
CN103152324A (en) User authentication method based on behavior features
CN105447350A (en) Identity authentication method and device
CN103684767A (en) Dynamic password generation device and method
CN104778587A (en) Safety payment method and device
CN106204185A (en) Mobile terminal and control method thereof
CN202652256U (en) Internet banking client certificate device
CN110197375A (en) A kind of similar users recognition methods, device, similar users identification equipment and medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant