TW200837596A - A method for verifying authorized access - Google Patents

A method for verifying authorized access Download PDF

Info

Publication number
TW200837596A
TW200837596A TW96107416A TW96107416A TW200837596A TW 200837596 A TW200837596 A TW 200837596A TW 96107416 A TW96107416 A TW 96107416A TW 96107416 A TW96107416 A TW 96107416A TW 200837596 A TW200837596 A TW 200837596A
Authority
TW
Taiwan
Prior art keywords
password
random
verifying
dynamic
input
Prior art date
Application number
TW96107416A
Other languages
Chinese (zh)
Other versions
TWI334987B (en
Inventor
Wen-Xin Yang
Original Assignee
Wen-Xin Yang
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Wen-Xin Yang filed Critical Wen-Xin Yang
Priority to TW96107416A priority Critical patent/TWI334987B/en
Publication of TW200837596A publication Critical patent/TW200837596A/en
Application granted granted Critical
Publication of TWI334987B publication Critical patent/TWI334987B/en

Links

Landscapes

  • Storage Device Security (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

The present invention relates to a method for verifying authorized access more particularly to a method capable of verifying an input password by an improved password input fashion. The method can prevent the password being stolen by a spectator when the password is being input; plus, it can make the password easily to be memorized and difficult to be cracked. The method is characherized in that users preset a combination of random password, fixed password, and dynamic password so that the words and length of the input password for verifying authorized access are different every time, thereby greatly increasing difficulty in cracking the password.

Description

200837596 九、發明說明: 【發明所屬之技術領域】 本發明係有關於一種驗證密碼之方法,尤指一種以改 良的密碼輸入方式進行驗證密碼之方法,係可防止密碼輸 入操作時的旁觀者竊取密碼内容及密碼長度,更可使密碼 易於記憶。 【先前技術】 發明人已於中華民國專利第1268690號揭露一新穎進 步之動態密碼系統’其可避免輸入過程的旁觀者竊取密碼 、 的問題,和傳統之文數字序列密碼相比更易記憶,且不容 ^ 易被破解。然而,以密碼破解理論觀之,此一密碼系統仍 存有「固定長度」之缺憾,即,縱使每次輸入密碼不同, 但密竭長度仍然相同,若由密碼輸入者身旁窺視或經由其 ◎ 他官這得知,即使無法取得完整密碼之全貌,但可確定密 碼之長度,如此再由暴力攻擊(Brute Force Attack)等習知之 密碼破解方法加以破解,使得此密碼系統之強韌性仍存有 疑慮。 【發明内容】 " 本發明係關於一種驗證密碼之方法,主要可應用於利 , 用私子密碼辨識使用人身分之設備。利用識別背景指引使 用者決定一動態密碼,並搭配使用者任意決定之隨機密 碼’以及預先記錄之且以輸入動態產生的隨機碼為驗證密 5 200837596 碼的手段,本方法具有使密碼不易被旁觀者竊取的功能。 尤其在無法避免或確認無他人旁觀輸入密碼的情況下,如 使用門禁系統、各種軟體系統、電腦資訊伺服系統、可儲 存或透過網路取得具隱私性或商業價值資料的個人數位處 理器(Personal Digital Assistant)、與自動櫃員機(Am〇matic200837596 IX. Description of the Invention: [Technical Field] The present invention relates to a method for verifying a password, and more particularly to a method for verifying a password by an improved password input method, which prevents a bystander from stealing during a password input operation. The password content and password length make the password easy to remember. [Prior Art] The inventor has disclosed a novel and progressive dynamic cryptosystem in the Republic of China Patent No. 1268690, which avoids the problem of bystanders entering the process of stealing passwords, and is more memorable than conventional digital serial ciphers, and Can not be easily broken. However, with the theory of password cracking, this cryptosystem still has the shortcoming of "fixed length", that is, even if the password is different each time, the length of exhaustion is still the same, if it is peeped by the password input person or through it ◎ His official knows that even if the full picture of the complete password cannot be obtained, the length of the password can be determined, and then the password cracking method such as Brute Force Attack is used to crack, so that the strong toughness of the cryptosystem remains. Have doubts. SUMMARY OF THE INVENTION The present invention relates to a method for verifying a password, which is mainly applicable to a device for identifying a user identity by using a private sub-password. Using the identification background to guide the user to determine a dynamic password, and with the random password arbitrarily determined by the user and the pre-recorded random code generated by the input dynamics as a means of verifying the password 5 200837596 code, the method has the function of making the password difficult to stand by The function of stealing. Especially in the case of inability to avoid or confirm that no one else is on the side of entering a password, such as access control systems, various software systems, computer information servo systems, personal digital processors that can store or access private or commercial value data via the Internet (Personal Digital Assistant), with ATM (Am〇matic

Teller Machine) ’本發明可提供極佳的保護密碼效果。同 日守’也使洽、碼不易被可重複嘗試登入的自動程式破解。 有鑑於先别技術尚待改進之處,本發明致力於改進密 碼長度易為人所取得,而降低破解難度之缺憾,為達成上 述目的,本發明之一種驗證密碼之方法包括以下步驟: (1) 根據預设之識別背景動態產生且顯示一影像,以決 定一動態密碼; (2) 輸入該動悲德·碼和至少一隨機密碼組合而成之密 碼,該隨機密碼係由使用者任意決定; (3) 驗證密碼; (4) 結束。 【實施方式】 請參閱第一圖,係本發明之一種驗證密碼之方法之較 佳實施例’使用者在輸入密碼時,係先根據預設之識別背 景動態產生且顯示一影像,以決定一動態密碼(產生動態 密碼方法係先前技術,不再贅述),但此一動態密碼係根據 一預設之動態規則所配合該識別背景得到,其密碼長度係 為固定,假設其密碼長度為5個字元,且使用者根據指示 200837596 找出動態密碼為AC592,當使用者欲輸入密碼時,係先隨 意決定一第一隨機密碼假設為915,和一第二隨機密碼假 設為7d965,再以該第一隨機密碼、該動態密碼及該第二 « 隨機密碼之順序依序輸入,則其輸入之密碼為 915AC5927d965,密碼長度為13個字元;若在相同動態密 碼之情況下使用者隨意決定一第一隨機密碼假設為4872 ,和一第二隨機密碼假設為p,則輸入之密碼成為 ζ) 4872AC592P,密碼長度為10個字元。系統驗證密碼係根據 輸入之密碼是否存在有動態密碼AC592,以決定使用者是 否通過驗證,每一次密碼輸入之密碼長度均因使用者決定 之不同隨機密碼而有所不同,且完整輸入之密碼包含隨機 ^ 密碼和動態密碼,更增添破解難度。本發明之一種驗證密 碼之方法亦可加入至少一固定密碼以取得更強軔(r〇bust )之輸入密碼,使用者係如傳統方式預先記憶第一固定密碼 和第二固定密碼,使用者可使用易於記憶之字元作為密碼 〇 ,例如使用者之名字和生日,假設為Frank和0218,且使 用者根據指示找出動態密碼為AC592,使用者並任意決定 一第一隨機密碼假設為1235,第二隨機密碼假設為9846, 第三隨機密碼假設為6547和第四隨機密碼假設為713,在 輸入密碼時,依第一隨機密碼、第一固定密碼、第二隨機 # 密碼、動態密碼、第三隨機密碼、第二固定密碼和第四隨 • 機密瑪之順序排列而成。即1235Frank9846AC59265470218713 。當系統欲驗證此密碼時,比對是否有輸入第一固定密碼、 動態密碼和第二固定密碼,且三者上述順序出現,如此可 7 200837596 達到避免窺視者或木馬程式等間諜軟體得知密碼内容和密 碼長度’固定密碼的加入不但不會造成使用者記憶上之不 便’還可增加密碼長度和強軔度,其搭配動態密碼(具有 每次輪入密碼内容不同之功效)和隨機密碼(具有每次輸 入在、碼長度不同之功效),使得密碼更加難以遭竊取以及破 解。需注意的是,系統亦可設定為不檢查固定密碼和動態 在碼出現順序,只檢查是否出現固定密碼和動態密碼;總 而3之’以動態密碼、隨機密碼和固定密碼搭配組合而成 之始、竭系統均該當為本發明所保護之範圍。 综上所述,本發明完全符合專利三要件··新穎性、進 步性和產業上的利用性。以新穎性和進步性而言,本發明 解决了上述普遍存在的問題,如在公共與公開的場所使用 宓2密碼的系統,必須在無法避免或確認無他人旁觀輸入 叫=過程的情況下防止密碼不被他人知悉,且更進一步地 2饴螞容易記憶,同時又不易被可重複嘗試登入的自動程 二破就產業上的利用性而言,利用本發明所衍生的產 备可充分滿足目前市場的需求。 術本發明在上文中已以較佳實施例揭露,然熟習本項技 應理解的是’該實施例僅用於财本發明,而不應解 制本發明之。應注意的是,舉凡與該實施例等 ,變化與置換’均應設為涵蓋於本發明之料内。因此 準發明之保護範圍當以下文之申請專利範園所界定者為 200837596 【圖式簡單說明】 第一圖係為本發明驗證密碼之方法之較佳實施例。 【主要元件符號說明】Teller Machine) 'The invention provides an excellent password protection effect. On the same day, the ‘and the code is not easy to be cracked by the automatic program that can be repeatedly tried to log in. In view of the fact that the prior art needs to be improved, the present invention is directed to improving the length of the password, which is easy to obtain and reduces the difficulty of cracking. To achieve the above object, a method for verifying a password according to the present invention includes the following steps: Dynamically generating and displaying an image according to the preset recognition background to determine a dynamic password; (2) inputting a combination of the spoof code and at least one random password, the random password is arbitrarily determined by the user (3) Verify the password; (4) End. [Embodiment] Please refer to the first figure, which is a preferred embodiment of the method for verifying a password according to the present invention. When a user inputs a password, the user first dynamically generates and displays an image according to the preset recognition background to determine a The dynamic password (the method of generating the dynamic password is the prior art, and will not be described again), but the dynamic password is obtained according to a predetermined dynamic rule, and the password length is fixed, and the password length is assumed to be 5 Character, and the user finds the dynamic password as AC592 according to the instruction 200837596. When the user wants to input the password, the user first arbitrarily decides that a first random password is assumed to be 915, and a second random password is assumed to be 7d965, and then The first random password, the dynamic password and the second «random password are sequentially input, and the input password is 915AC5927d965, and the password length is 13 characters; if the same dynamic password is used, the user randomly decides one. The first random password is assumed to be 4872, and a second random password is assumed to be p, then the entered password becomes ζ) 4872AC592P, and the password length is 10 Characters. The system verification password is based on whether the entered password has a dynamic password AC592 to determine whether the user has passed the verification. The password length of each password input is different according to different random passwords determined by the user, and the complete input password includes Random ^ passwords and dynamic passwords add to the difficulty of cracking. The method for verifying the password of the present invention may also add at least one fixed password to obtain a stronger input password, and the user may pre-memorize the first fixed password and the second fixed password in a conventional manner. Use the easy-to-remember character as the password, such as the user's name and birthday, assuming that Frank and 0218, and the user finds the dynamic password as AC592 according to the instruction, and the user arbitrarily decides that the first random password is assumed to be 1235. The second random password is assumed to be 9846, the third random password is assumed to be 6547, and the fourth random password is assumed to be 713. When the password is input, according to the first random password, the first fixed password, the second random # password, the dynamic password, the first The three random passwords, the second fixed password, and the fourth random minima are arranged in the order. That is 1235Frank9846AC59265470218713. When the system wants to verify the password, whether the first fixed password, the dynamic password and the second fixed password are entered, and the above three sequences appear, so that the system can avoid the spy software such as the peeper or the Trojan. Content and password length 'The addition of a fixed password will not only cause inconvenience to the user's memory. It can also increase the length and strength of the password. It is combined with a dynamic password (with different effects for each round of password content) and a random password ( It has the effect of different input length and code length, which makes the password more difficult to steal and crack. It should be noted that the system can also be set to not check the fixed password and the dynamic order of the code, only check whether there is a fixed password and a dynamic password; in general, the combination of the dynamic password, the random password and the fixed password Both the initial and exhaustive systems should be protected by the present invention. In summary, the present invention fully complies with the three requirements of the patent, novelty, advancement, and industrial applicability. In terms of novelty and advancement, the present invention solves the above-mentioned ubiquitous problems, such as systems that use 宓2 ciphers in public and public places, and must be prevented in the event that it is impossible to avoid or confirm that no one is watching the input = process. The password is not known to others, and further, it is easy to remember, and at the same time, it is not easy to be re-examined by the automatic process. The industrial use of the invention can fully satisfy the current production. Market demand. The invention has been disclosed in the above preferred embodiments, and it is understood that the present invention is intended to be used only for the purpose of the invention. It should be noted that variations and substitutions are to be included in the materials of the present invention. Therefore, the scope of protection of the quasi-invention is defined as the following in the following patent application garden: 200837596 [Simplified description of the drawings] The first figure is a preferred embodiment of the method for verifying a password according to the present invention. [Main component symbol description]

Claims (1)

200837596 十、申請專利範圍: 1、 一種驗證密碼之方法,包括下列步驟: (1) 根據預設之識別背景動態產生且顯示一影像,以決 定一動態密碼; (2) 輸入該動態密碼和至少一隨機密碼組合而成之密 碼,該隨機密碼係由使用者任意決定; (3) 驗證密碼; (4) 結束。 2、 申請專利範圍第1項所述之驗證密碼之方法,其中該步 驟(2)更包括輸入至少一固定密碼和該動態密碼以及該 隨機密碼組合而成之密碼,該固定密碼係使用者預先記 憶之密碼。 3、 如申請專利範圍第1項所述之驗證密碼之方法,其中, 該步驟(3)係根據輸入之密碼是否存在該動態密碼以進 行驗證。 4、 如申請專利範圍第2項所述之驗證密碼之方法,其中, 談步驟(3)係根據輸入之密碼内該動態密碼和該固定密 碼是否存在且根據預設規則排列以進行驗證。 5、 如申請專利範圍第1項所述之驗證密碼之方法,其中, 該步驟(2)輸入之密碼係由一第一隨機密碼、該動態密 碼和一第二隨機密碼依序排列而成。 6、 如申請專利範圍第2項所述之驗證密碼之方法,其中, 該步驟(2)輸入之密碼係由一第一隨機密碼、一第一固 定密碼、一第二隨機密碼、該動態密碼、一第三隨機密 200837596 碼、一第二固定密碼和一第四隨機密碼依序排列而成 11200837596 X. Patent application scope: 1. A method for verifying a password, comprising the following steps: (1) dynamically generating and displaying an image according to a preset recognition background to determine a dynamic password; (2) inputting the dynamic password and at least A password combined with a random password, which is arbitrarily determined by the user; (3) verification password; (4) end. 2. The method for verifying a password according to the first aspect of the patent application, wherein the step (2) further comprises: inputting at least one fixed password and the dynamic password and the random password combined, the fixed password is a user pre- The password for memory. 3. The method for verifying a password as set forth in claim 1, wherein the step (3) is performed based on whether the dynamic password is present in the entered password. 4. The method for verifying a password as claimed in claim 2, wherein the step (3) is based on whether the dynamic password and the fixed password are present in the entered password and are arranged according to a preset rule for verification. 5. The method for verifying a password according to claim 1, wherein the password input in the step (2) is sequentially arranged by a first random password, the dynamic password and a second random password. 6. The method for verifying a password according to claim 2, wherein the password input in the step (2) is a first random password, a first fixed password, a second random password, and the dynamic password. a third random secret 200837596 code, a second fixed password and a fourth random password are sequentially arranged into 11
TW96107416A 2007-03-03 2007-03-03 A method for verifying password TWI334987B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW96107416A TWI334987B (en) 2007-03-03 2007-03-03 A method for verifying password

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW96107416A TWI334987B (en) 2007-03-03 2007-03-03 A method for verifying password

Publications (2)

Publication Number Publication Date
TW200837596A true TW200837596A (en) 2008-09-16
TWI334987B TWI334987B (en) 2010-12-21

Family

ID=44212183

Family Applications (1)

Application Number Title Priority Date Filing Date
TW96107416A TWI334987B (en) 2007-03-03 2007-03-03 A method for verifying password

Country Status (1)

Country Link
TW (1) TWI334987B (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8739261B2 (en) 2011-08-31 2014-05-27 International Business Machines Corporation Dynamically providing algorithm-based password/challenge authentication
US9122852B2 (en) 2012-11-14 2015-09-01 Wistron Corporation Password input system and method for inputting password

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8739261B2 (en) 2011-08-31 2014-05-27 International Business Machines Corporation Dynamically providing algorithm-based password/challenge authentication
US8745712B2 (en) 2011-08-31 2014-06-03 International Business Machines Corporation Dynamically providing algorithm-based password/challenge authentication
US9122852B2 (en) 2012-11-14 2015-09-01 Wistron Corporation Password input system and method for inputting password

Also Published As

Publication number Publication date
TWI334987B (en) 2010-12-21

Similar Documents

Publication Publication Date Title
US8561174B2 (en) Authorization method with hints to the authorization code
AU2007268223B2 (en) Graphical image authentication and security system
US9117065B2 (en) Dynamic interactive identity authentication method and system
CA2667341C (en) Web site authentication
US8997177B2 (en) Graphical encryption and display of codes and text
AU2005318933B2 (en) Authentication device and/or method
US7770002B2 (en) Multi-factor authentication
US9684780B2 (en) Dynamic interactive identity authentication method and system
TW200818838A (en) Mutual authentication and secure channel establishment between two parties using consecutive one-time passwords
US20070255953A1 (en) Authentication method and apparatus between an internet site and on-line customers using customer-specific streamed audio or video signals
US20070271465A1 (en) Method of Authentication by Challenge-Response and Picturized-Text Recognition
US10033724B2 (en) System of composite passwords incorporating hints
US20050177867A1 (en) Prompt authentication
JP2006293804A (en) Input of password and authentication system
CN101207483A (en) Bidirectional double factor authentication method
US9811828B2 (en) Method for authentication of mobile transactions using video encryption and method for video encryption
CN115396139A (en) System and method for password anti-theft authentication and encryption
TW200837596A (en) A method for verifying authorized access
US20100005303A1 (en) Universal authentication method
GB2449240A (en) Conducting secure online transactions using CAPTCHA
KR20040038031A (en) Method of formation and execution for prevention contents from unauthorized copy
US20090158038A1 (en) Universal authentication method
JP2007164575A (en) Browsing control method and device for electronic content
TWI392310B (en) Method for implementing and authenticating an one time password (otp) for integrated circuit cards
EP1416666A1 (en) Method to simplify the management and enhance the security of passwords

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees