WO2015149582A1 - 密码输入方法、智能密钥设备以及客户端装置 - Google Patents

密码输入方法、智能密钥设备以及客户端装置 Download PDF

Info

Publication number
WO2015149582A1
WO2015149582A1 PCT/CN2015/071852 CN2015071852W WO2015149582A1 WO 2015149582 A1 WO2015149582 A1 WO 2015149582A1 CN 2015071852 W CN2015071852 W CN 2015071852W WO 2015149582 A1 WO2015149582 A1 WO 2015149582A1
Authority
WO
WIPO (PCT)
Prior art keywords
password
user
key device
smart key
user data
Prior art date
Application number
PCT/CN2015/071852
Other languages
English (en)
French (fr)
Inventor
李东声
Original Assignee
天地融科技股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 天地融科技股份有限公司 filed Critical 天地融科技股份有限公司
Publication of WO2015149582A1 publication Critical patent/WO2015149582A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN

Definitions

  • the present invention relates to the field of network information security technologies, and in particular, to a method for performing client password input through a smart key device, a smart key device, and a client device.
  • Password technology is one of the most secure and confidential measures in the current network information system. Online banking, third-party payment, and various shopping social networking websites need to set the corresponding account and login password. With the development of the network information age, people's online activities are becoming more and more frequent, and more and more accounts and passwords need to be set and accurately remembered.
  • the present invention aims to solve at least one of the technical problems in the related art to some extent.
  • an object of the present invention is to provide a method for client password input by using a smart key device, which can automatically input a password without user memory and manually input a password, thereby facilitating user operation.
  • Another object of the present invention is to propose a smart key device.
  • Another object of the present invention is to propose a client device.
  • the method for performing client password input by using a smart key device includes: the smart key device receiving a password output request sent by the client; the smart key device according to the a password output request for displaying a list of entries corresponding to user data pre-stored in the smart key device, wherein the user data includes account information and a corresponding password; the smart key device determines that the user is in the entry The account information selected in the list, and determining a first password according to the account information selected by the user, wherein the first password is a password for login authentication; the smart key device sends the first password to The client, so that the client inputs the first password.
  • the determining, according to the account information selected by the user, the first password comprising: acquiring, according to the account information selected by the user, a password corresponding to the account information selected by the user from the user data; Obtaining the obtained password as the first password, or performing encryption processing on the obtained password to obtain the first password; or acquiring the user from the user data according to the account information selected by the user One or more of selected account information and information corresponding to the account information selected by the user; using a dynamic password calculation algorithm, The obtained information is calculated to obtain a dynamic password, and the dynamic password is determined as the first password.
  • the method further comprises: the smart key device storing the user data.
  • the smart key device stores the user data, including: the smart key device receives an operation instruction input by the user and the user data; and the smart key device performs identity verification on the user, And after the user passes the identity verification, the write permission of the smart key device is opened to the user; and the user data is written to the smart key device.
  • the method further includes: receiving an activation code input by the user on the smart key device, and performing the activation The code performs activation verification, and activates an information storage function of the smart key device after activation verification passes; or receives an activation request sent by the user through the client and activation of the user input through the client Code, and performing activation verification on the activation code, and activating an information storage function of the smart key device after activation verification passes, wherein the information storage function is used to implement writing the user data to the a smart key device; and receiving an open command input by the user, and enabling an information storage function of the smart key device according to the open command.
  • the receiving, by the smart key device, the operation instruction input by the user and the user data specifically includes: receiving, by using an operation interface and a control button provided by the smart key device, the operation instruction and the user data; or by communicating The interface receives the operation instruction and the user data sent by the external device.
  • the method further includes: the smart key device receiving, by the client, the smart key device sent by the client Verifying the request and the random number, encrypting the random number according to the private key of the smart key device, and transmitting the digital certificate of the smart key device and the encrypted random number to the location according to the verification request Declaring a client; the client verifies the digital certificate of the smart key device according to the root certificate, and decrypts the encrypted random number according to the public key of the smart key device, and after decrypting Verifying the random number; after verifying that the digital certificate and the random number pass, displaying the user data; the writing the user data to the smart key device is specifically: receiving the After the user confirms the displayed user data, the smart key device stores the user data.
  • the receiving, by the smart key device, the operation instruction input by the user and the user data specifically includes: the smart key device receiving the user data ciphertext sent by the client, and according to the private key of the smart key device Decrypting the user data ciphertext to obtain the user data, wherein the client encrypts the user data according to a public key of the smart key device to generate the user data ciphertext; or Receiving, by the smart key device, the session key ciphertext and the user data ciphertext sent by the client, and decrypting the session key ciphertext according to the private key of the smart key device to obtain a session key, and Decrypting the user data ciphertext according to the session key to obtain the user data, wherein the client randomly generates a session key, and pairs the session according to the public key of the smart key device Key encryption to generate the session key ciphertext, and encrypting the user data in accordance with the session key to generate the user data ciphertext.
  • the first password is obtained according to the pre-stored user data and sent to the client, so that the client input is received from the smart key device.
  • the password does not require manual input by the user, and is convenient for the user to operate.
  • the password input by the client is generated according to the pre-stored user data, and the user does not need to memorize the password, thereby avoiding the problem that the user is difficult to remember when the account is numerous.
  • a method for performing client password input by using a smart key device includes: the client sending a password output request to the smart key device, so that the smart key device according to the a password output request, displaying a list of entries corresponding to user data pre-stored in the smart key device, and causing the smart key device to determine account information selected by the user in the list of entries, and according to the user
  • the selected account information determines a first password, wherein the user data includes account information and a corresponding password, the first password is a password used for login authentication; and the client receives the location sent by the smart key device The first password is entered; the client receives the first password.
  • the method for performing client password input by using a smart key device can automatically input a password by instructing the smart key device to output a password and inputting the first password sent by the smart key device. It can be operated by users without user input.
  • a smart key device includes: a receiving module, configured to receive a password output request sent by a client; and a display module configured to output a request according to the password, display and a list of entries corresponding to user data pre-stored in the smart key device, wherein the user data includes account information and a corresponding password; and the determining module is configured to determine account information selected by the user in the list of entries, and according to The account information selected by the user determines a first password, where the first password is a password for login authentication, and the sending module is configured to send the first password to the client, so that the client Enter the first password.
  • the determining module includes: a first unit, configured to acquire, according to the account information selected by the user, a password corresponding to the account information selected by the user from the user data; and the second unit is configured to The obtained password is determined as the first password, or the obtained password is encrypted to obtain the first password.
  • the determining module includes: a third unit, configured to acquire, according to the account information selected by the user, the account information selected by the user and the information corresponding to the account information selected by the user from the user data.
  • the fourth unit is configured to use a dynamic password calculation algorithm to calculate the obtained information to obtain a dynamic password, and determine the dynamic password as the first password.
  • the smart key device further includes: a first storage module configured to store a private key and a digital certificate of the smart key device; a second storage module configured to store the user data; and a transceiver module configured to Receiving an operation instruction input by the user and the user data; and an access control module configured to authenticate the user and After the user passes the authentication, the write permission of the second storage module is opened to the user, and the user data is written to the second storage module; and the security chip is set to generate a digital signature. And authentication, as well as encryption and decryption.
  • the smart key device further includes: an activation control module, configured to receive an activation code input by the user on the smart key device, perform activation verification on the activation code, and after activation verification Activating an information storage function of the smart key device; or receiving an activation request sent by the user through the client and an activation code input by the user through the client, and performing activation verification on the activation code And an information storage function of the smart key device activated after the activation verification is passed, wherein the information storage function is used to implement writing the user data to the smart key device; and the opening module is set to Receiving an open command input by the user, and enabling an information storage function of the smart key device according to the open command.
  • an activation control module configured to receive an activation code input by the user on the smart key device, perform activation verification on the activation code, and after activation verification Activating an information storage function of the smart key device; or receiving an activation request sent by the user through the client and an activation code input by the user through the client, and performing activation verification on the
  • the transceiver module receives the operation instruction and the user data through an operation interface and a control button provided by the smart key device; or receives the operation instruction and the user data sent by an external device through a communication interface. .
  • the transceiver module receives an authentication request and a random number sent by the user to the smart key device by using the client, and the security chip pairs the random number according to a private key of the smart key device. Encrypting, and the transceiver module sends the digital certificate of the smart key device and the encrypted random number to the client according to the verification request; wherein the client pairs the smart password according to the root certificate The digital certificate of the key device is verified, and the encrypted random number is decrypted according to the public key of the smart key device, and the decrypted random number is verified; the display module is further set to be in the After receiving the operation instruction input by the user and the user data, the transceiver module displays the user data, and the access control module receives the confirmation of the displayed user data by the user at the transceiver module. After the instruction, the user data is written to the second storage module.
  • the transceiver module receives the user data ciphertext sent by the client, and the security chip decrypts the user data ciphertext according to the private key of the smart key device to obtain the user data, where the client The user encrypts the user data according to the public key of the smart key device to generate the user data ciphertext; or the transceiver module receives the session key ciphertext and the user data ciphertext sent by the client, The security chip decrypts the session key ciphertext according to the private key of the smart key device to obtain a session key, and decrypts the user data ciphertext according to the session key to obtain the user data, where The client randomly generates a session key, encrypts the session key according to the public key of the smart key device to generate the session key ciphertext, and pairs the user according to the session key Data encryption to generate the user data ciphertext.
  • the smart key device obtains the first password by using the pre-stored user data and sends the password to the client, so that the client inputs the password received from the smart key device without manual input by the user. It is convenient for the user to operate, and generates the password input by the client according to the pre-stored user data, and does not need to use The user remembers the password and avoids the problem that the user cannot remember when the account is large.
  • the client device includes: a sending module, configured to send a password output request to the smart key device, so that the smart key device displays according to the password output request. a list of entries corresponding to the user data pre-stored in the smart key device, and causing the smart key device to determine account information selected by the user in the list of entries, and determining the number according to the account information selected by the user a password, wherein the user data includes account information and a corresponding password, the first password is a password for login authentication, and the receiving module is configured to receive the first password sent by the smart key device; An input module configured to input the first password.
  • the client device can automatically input a password by instructing the smart key device to output a password and input the first password sent by the smart key device, without user input, which is convenient for the user to operate. .
  • a client device includes a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed inside a space enclosed by the housing, the processor and the The memory is disposed on the circuit board; the power circuit is configured to supply power to each circuit or device of the client device; the memory is used to store executable program code; and the processor is executable and executable by reading executable program code stored in the memory.
  • a program corresponding to the program code configured to: send a password output request to the smart key device, so that the smart key device displays the user pre-stored in the smart key device according to the password output request a list of entries corresponding to the data, and causing the smart key device to determine account information selected by the user in the list of entries, and determining a first password according to the account information selected by the user, wherein the user data includes account information And a corresponding password, the first password is a password used for login authentication; receiving the smart The key device transmits a first password; enter the first password.
  • the client device can automatically input a password by instructing the smart key device to output a password and input the first password sent by the smart key device, without user input, which is convenient for the user to operate. .
  • a smart key device includes: one or more processors; a memory; one or more programs, and the one or more programs are stored in the memory, And when executed by the one or more processors, the following operations are performed: receiving a password output request sent by the client; and displaying, according to the password output request, a list of entries corresponding to the user data pre-stored in the smart key device
  • the user data includes account information and a corresponding password; determining account information selected by the user in the item list, and determining a first password according to the account information selected by the user, wherein the first password is a password for login authentication; sending the first password to the client, so that the client inputs the first password.
  • the smart key device provided by the embodiment of the sixth aspect of the present invention obtains the first password by using the pre-stored user data and sends the password to the client, so that the client inputs the password received from the smart key device without manual input by the user.
  • the user can operate conveniently, and the password input by the client is generated according to the pre-stored user data, and the user does not need to memorize the password, thereby avoiding the problem that the user is difficult to remember when the account is numerous.
  • FIG. 1 is a schematic flowchart of a method for performing client password input by using a smart key device according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a method for performing client password input by using a smart key device according to another embodiment of the present invention
  • FIG. 3 is a schematic flowchart of a method for performing client password input by using a smart key device according to another embodiment of the present invention.
  • FIG. 4 is a schematic flowchart of a method for performing client password input by using a smart key device according to another embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of a smart key device according to another embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a smart key device according to another embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of a client device according to another embodiment of the present invention.
  • FIG. 1 is a schematic flowchart of a method for performing client password input by using a smart key device according to an embodiment of the present invention, where the method includes the following steps S11 to 14.
  • S11 The smart key device receives a password output request sent by the client.
  • the smart key device may be a device with storage capability, for example, a Universal Serial Bus (USB) key, a key code, a key for wireless communication, and correspondingly, the smart key device can pass The USB mode, the audio code mode or the wireless mode communicates with the client, wherein the wireless mode may include a Bluetooth mode, a wifi mode, or an infrared mode.
  • the USB mode may refer to the smart key device communicating with the client through the USB interface
  • the audio code mode may refer to the smart key device communicating with the client through the audio interface or the speaker
  • the wireless mode may refer to the smart key device and The client communicates after establishing a wireless connection.
  • the client can refer to a device that the user logs in to the network, for example, a personal computer (PC), a mobile phone, a tablet, and the like.
  • PC personal computer
  • mobile phone a mobile phone
  • tablet a tablet
  • the client can send a password output request to the smart key device to obtain the corresponding information from the smart key device.
  • password in the embodiment of the present invention may also be referred to as a password.
  • the smart key device displays, according to the password output request, a list of entries corresponding to user data pre-stored in the smart key device, the user data including account information and a corresponding password.
  • the smart key device may pre-store each account information and corresponding password that the user can use. For example, the user may use online banking, third-party payment, and an e-mail address, and the bank card number and corresponding information may be saved in the smart key device.
  • a module for storing each account information and a corresponding password in the smart key device may be referred to as a password kit.
  • the smart key device may display a list of entries corresponding to the stored user data (of course, may also be displayed in other forms) for the user to select an account to be used for login, which is illustrated by the above example.
  • the bank card number, the user name of the third party payment, and the username of the email address can be displayed.
  • the displayed list of entries includes at least an account, and may also include an account and a corresponding password, for example, displaying a bank card number and a corresponding password, a user name and corresponding password of the third party payment, and a user name and correspondence of the email address. Password.
  • the user data includes the account information and the corresponding password as an example. It can be understood that the user data may further include other information, such as website information corresponding to the account information. For example, the user stores the website name of the Taobao in the smart key device. Username (ie account information) and corresponding password.
  • the user can customize the item to be stored, that is, increase or decrease the item to be stored according to his own needs.
  • the user data stored by the user may be the website name, the account to log in to the website, and the corresponding password, or It is the account and the corresponding password, and it can also be the account, the password corresponding to the account, and the remarks.
  • the stored user data can be divided into two categories: one is a preset item, which can be directly selected by the user, for example, a bank card number, an online banking login name, a password, a web address, a mailbox name, and the like. Under each project, multiple subordinate projects can be preset. For example, under the bank card number, you can set up BOC, ICBC, and ABC. In addition, the other type is blank for user-defined input.
  • a new entry can be created, wherein the entry can include multiple items, for example, bank card type, account number, password, and remarks. Wait.
  • the displayed list of entries may include account information, or include account information and corresponding passwords, or include account information and corresponding website information, or include account information and corresponding passwords and corresponding websites.
  • the website information may be at least one of the following: a Uniform Resource Locator (URL) address of the website, an Internet Protocol (IP) address of the website, a domain name, and a website name.
  • URL Uniform Resource Locator
  • IP Internet Protocol
  • the smart key device determines the account information selected by the user in the item list, and determines the first password according to the account information selected by the user, where the first password is a password used for login authentication;
  • the password may be the original password corresponding to the account information selected by the user (that is, the password corresponding to the account information stored in the smart key device), or may be the ciphertext obtained by encrypting the original password, or may be The dynamic password obtained by the user-selected account information and its corresponding information.
  • the user can select the corresponding account information according to the current usage. For example, if the user currently uses online banking, the user can select the bank card number.
  • the user can click the confirmation button to send the confirmation information to the smart key device.
  • the smart key device can determine the user selected according to the account information selected by the user and the confirmation information sent by the user. account information.
  • each account information and a corresponding password may be pre-stored in the smart key device.
  • the smart key device may acquire the corresponding password according to the selected account information. For example, after the user selects the bank card number, the smart key device can obtain the password corresponding to the bank card number from the pre-stored user data. Then, in a specific implementation, the obtained password may be determined as the first password, and the password is in plain text; or the obtained password may be processed to obtain the first password, and the processing may specifically include encryption processing.
  • the first password is an encrypted password, or the processing may be specifically generating a dynamic password according to the obtained password, and the obtained password is used as a seed key, and the dynamic password is used to calculate the dynamic password.
  • the first password is dynamic. password.
  • the account information selected by the user may be used as a seed key, or the account information and the password may be used together as a seed key, and the dynamic password is calculated in combination with the dynamic factor.
  • the seed key is generally a number, and the letters in the account information and/or password information can be converted into numbers through an ASCII code comparison table.
  • the user password includes a password corresponding to the account information, and obtains a password corresponding to the account information, and determines the first password according to the obtained password as an example.
  • the user data may further include website information corresponding to the account information and/or other item information customized by the user.
  • the dynamic password may also be generated according to the website information, and the generated dynamic password is determined as First password.
  • the website information can be first converted into a number, and then the dynamic password algorithm is used to calculate the number, and the dynamic password corresponding to the website information is generated.
  • determining the first password according to the account information selected by the user can be implemented as follows:
  • the website information, the user-defined other item information, and the like are determined; the obtained password is determined as the first password, or the obtained password is encrypted to obtain the first password.
  • At least the account information and the password corresponding to the account information may also include website information, user-defined other item information, etc.; using a dynamic password calculation algorithm, calculating the obtained information to obtain a dynamic password,
  • the dynamic password is determined to be the first password.
  • the user can customize the entry to be stored, and the user selects the account information currently to be used in the user data stored by the smart key device, and the account information and its corresponding information (such as website information, password, etc.)
  • the account information and its corresponding information such as website information, password, etc.
  • S14 The smart key device sends the first password to the client, so that the client inputs the first password.
  • the password may be directly sent to the client, or after the encrypted password is encrypted, the encrypted password is sent to the client. .
  • the dynamic password is generated according to the obtained one or more pieces of information related to the account information selected by the user, and the dynamic password is sent to the client.
  • the first password can be input at the location where the password is input. For example, when the user uses the online banking, the client can input the first password to the password input location.
  • the client can use the input first password to perform login authentication. For example, at the time of authentication, the client sends the first password of the password input location to the bank background, and the login authentication is performed by the bank background to allow or deny the user login. Specifically, if the first password is plaintext, the background directly performs authentication; if the first password is ciphertext, the background decrypts it to obtain a plaintext password, and then performs authentication; if the first password is a dynamic password, the background uses and The same dynamic cryptographic algorithm of the smart key device calculates the information stored in the background, and compares the calculated result with the first password for authentication.
  • the first password is obtained according to the pre-stored user data and sent to the client, so that the client inputs the password received from the smart key device, and the user does not need to manually input, which is convenient for the user to operate, and according to the pre-stored User data generates the password entered by the client, and does not require the user to memorize the password, avoiding the problem that the user cannot remember when the account is numerous.
  • the smart key device of this embodiment can communicate with the client in various manners, and Improve the scope of application.
  • the method may further include: the smart key device storing the user data.
  • the storing, by the smart key device, the user data specifically includes: the smart key device receiving an operation instruction input by the user and the user data; the smart key device performing identity verification on the user, and After the user passes the identity verification, the write permission of the smart key device is opened to the user; and the user data is written to the smart key device.
  • the operation instruction input by the user may be an instruction that the user adds new user data in the smart key device, or an instruction to edit, modify, delete, etc. the user data stored in the smart key device.
  • the identity of the user can be verified based on the PIN code entered by the user.
  • the information storage function of the smart key device may be activated, including: receiving the user input on the smart key device Activation code, and performing activation verification on the activation code, and activating an information storage function of the smart key device after activation verification is passed; or receiving an activation request sent by the user through the client and the An activation code input by the user through the client, and activation verification of the activation code, and activation of an information storage function of the smart key device after activation verification is passed, wherein the information storage function is used to implement The user data is written to the smart key device.
  • a manner of enabling the information storage function of the smart key device for data storage is provided, specifically comprising: receiving an open instruction of the user input, and enabling the smart key device according to the opening instruction.
  • Information storage function specifically comprising: receiving an open instruction of the user input, and enabling the smart key device according to the opening instruction.
  • the receiving, by the smart key device, the operation instruction input by the user and the user data specifically includes: receiving, by using an operation interface and a control button provided by the smart key device, the operation instruction and the user data; or by communicating
  • the interface receives the operation instruction and the user data sent by the external device.
  • the user can input operational commands and user data through a keyboard (eg, a physical keyboard or a virtual keyboard) provided by the smart key device.
  • the user can also connect the smart key device to the client, install the corresponding management application on the client, input operation instructions and user data through the mouse, keyboard, touch screen and other devices in the operation interface of the management application, and then pass the client.
  • the communication interface of the terminal sends the operation instruction and user data to the smart key device.
  • the method further includes: the smart key device receiving, by the client, the smart key device sent by the client Verifying the request and the random number, encrypting the random number according to the private key of the smart key device, and transmitting the digital certificate of the smart key device and the encrypted random number to the location according to the verification request Declaring a client; the client verifies the digital certificate of the smart key device according to the root certificate, and decrypts the encrypted random number according to the public key of the smart key device, and after decrypting The random number is verified. Verify smart key settings before storing user data The identity is guaranteed to ensure its reliability.
  • Displaying the user data before writing the user data to the smart key device; the writing the user data to the smart key device is specifically: receiving the After the confirmation command of the user data, the smart key device stores the user data.
  • the user data may also be displayed after the verification of the smart key device digital certificate and the random number is passed, or the user data is displayed after receiving the user data. After the user confirms it, it stores it to ensure the correctness of the data stored by the user.
  • the receiving, by the smart key device, the operation instruction input by the user and the user data specifically includes: (1) the smart key device receiving the user data ciphertext sent by the client, and according to the smart key The private key of the device decrypts the user data ciphertext to obtain the user data, wherein the client encrypts the user data according to the public key of the smart key device to generate the user data ciphertext; Or (2) the smart key device receives the session key ciphertext and the user data ciphertext sent by the client, and decrypts the session key ciphertext according to the private key of the smart key device.
  • FIG. 2 is a schematic flowchart of a method for performing client password input by using a smart key device according to another embodiment of the present invention, where the method includes the following steps S21 to S23.
  • the client device sends a password output request to the smart key device, so that the smart key device displays a list of entries corresponding to the user data pre-stored in the smart key device according to the password output request, and causes The smart key device determines account information selected by the user in the list of entries, and determines a first password according to the account information selected by the user, wherein the user data includes account information and a corresponding password, where the A password is the password used to log in to the authentication.
  • the client device is, for example, a PC, a mobile phone, or a tablet.
  • the client device may be the password output request sent after receiving the login password input request sent by the password authenticator, such as a bank background, a third party payment platform or a mailbox authentication platform.
  • the password authenticator such as a bank background, a third party payment platform or a mailbox authentication platform.
  • the client device receives the first password sent by the smart key device.
  • the receiving the first password sent by the smart key device includes: receiving a first password sent by the smart key device by using a USB mode; or receiving the smart key device by using a voice code manner The first password sent; or the first password sent by the smart key device in a wireless manner.
  • the client device inputs the first password. For example, the client device enters the password into the login to log in. Enter the location of the password. Thereafter, the client device may also send the first password to an authenticator such as a bank background for password authentication to allow or deny the user to log in.
  • an authenticator such as a bank background for password authentication to allow or deny the user to log in.
  • FIG. 3 is a schematic flowchart of a method for performing client password input by using a smart key device according to another embodiment of the present invention.
  • a smart key device is used as a USB key
  • a client is a PC as an example
  • the user is a user.
  • the online banking is used as an example, and the password corresponding to the account information is obtained, and the password is encrypted after the password is obtained, and then transmitted as an example.
  • the embodiment includes the following steps S301 to S313.
  • S301 When the user wants to log in to the online banking, the bank sends a login password input request to the PC in the background. Since the online banking needs to input a password when logging in, the bank background can send a login password input request for the user to input the login password.
  • S302 The PC sends a password output request to the USB key.
  • the password corresponding to the account is saved in the USB key, and then the password input is directly obtained from the USB key, instead of being manually input by the user. Therefore, in order to obtain the password, the PC can send the password to the USB key. Output request.
  • the USB key has a built-in single chip or a smart card chip, and has a certain storage space, and can store the user's private key and digital certificate.
  • the user identity is authenticated using the public key algorithm built into the USB key.
  • the second-generation USB key adds a physical button from the hardware form, and adds a display module or a voice module, which can display or report the transaction data information sent to the USB key. Eliminate the risk of transaction data being tampered with during the user's client submission to the USB key.
  • the USB key has certain access control security.
  • the USB key itself has a PIN password. The user must correctly input the password before using the USB key function to use it normally, and the continuous error input will automatically lock up after a certain number of times, effectively preventing it. Malicious cracking.
  • USB Key technology At present, people have already solved the problem of network security identity authentication by using USB Key technology, and have been widely used in the field of online banking payment.
  • the high security features of the USB key ensure the security of the user's private key and certificate.
  • the user's account information and the corresponding password are pre-stored in the USB key.
  • the password is directly exported from the USB key for input instead of manual input.
  • the USB key displays a list of entries corresponding to the user data stored in the key.
  • the account information and the corresponding password may be stored in the USB key.
  • the stored information of each item may be displayed to the user, and the user selects the currently used account information.
  • S304 The user selects the currently used account information from the list of entries. For example, users can press more buttons Select one of the entries to select. In addition, the user can confirm the user's choice by clicking the confirmation button after completing the selection.
  • the USB key acquires a password corresponding to the selected account information from the pre-stored user data.
  • the corresponding password is found according to the account information selected by the user.
  • the password is stored in the USB key, no manual memory is required. Therefore, in order to ensure security, the attacker can be prevented from deciphering the password of one account, and the password of the other account can be obtained, and the password corresponding to the different account information can be set. irrelevant.
  • the USB key encrypts the obtained password to obtain a ciphertext.
  • the obtained password may be encrypted after receiving the confirmation information of the user. For example, after the USB key obtains the password, it can display to the user whether to confirm the encryption. If the user clicks the confirmation button, the obtained password is encrypted, otherwise the encryption process is not performed.
  • the encryption algorithm used in the encryption process of the USB key is an algorithm pre-agreed with the bank background, and then the bank uses the agreed algorithm to decrypt.
  • USB key sends the ciphertext to the PC.
  • the USB key displays to the user whether to confirm the sending.
  • the USB key sends the ciphertext to the PC.
  • S308 The PC inputs the ciphertext to the password input location.
  • the USB key can input the ciphertext to the location where the password is required for login. For example, when online banking is logged in, a password input field is displayed, and the PC inputs the ciphertext into the input field.
  • the method can also include:
  • the PC sends the ciphertext to the bank backend. After receiving the ciphertext, the USB key can input the ciphertext to the location where the password is required for login. When the bank is authenticated, the PC sends the information of the password input location to the bank backend, which also sends the ciphertext to the bank backend.
  • the bank backend decrypts the received ciphertext to obtain a plaintext password.
  • the bank backend can decrypt the received ciphertext using an algorithm pre-agreed with the USB key.
  • S311 The bank background authenticates the password of the plaintext, and determines whether the password of the plaintext is correct. If yes, execute S312, otherwise execute S313.
  • the bank background can pre-save the user's password. By comparing the plaintext password with the pre-saved password, it can be determined whether the plaintext password obtained after decryption is correct.
  • S312 The login is successful.
  • the bank sends a login success message to the PC, and after receiving the login success message, the PC can confirm that the user is allowed to log in, and then can display the page after login to the user.
  • S313 Login failed.
  • the bank sends a login failure message to the PC, and the PC may display the login failure to the user after receiving the login failure message.
  • the above smart key device is a USB key. It can be understood that other smart key devices, such as an audio key, a Bluetooth key, etc., can also be referred to.
  • the above client is a PC, and it can be understood that other clients, such as mobile phones, tablets, etc., can also be referred to.
  • the above is the use of online banking by the user. It can be understood that the user can also use other scenarios. For example, the user is performing third-party payment. At this time, the client can authenticate to the third-party payment platform, and other usage scenarios can also refer to the bank background. The corresponding processing flow.
  • the password is obtained from the pre-stored user data, so that the client inputs the password received from the smart key device, and the user does not need to manually input, which can facilitate the user to operate, and the password is pre-stored without the user.
  • the passwords corresponding to different accounts can be set to be irrelevant, so that the problem of cracking one account password generated when many passwords are related can be threatened to threaten other account passwords, and the password of each account is improved. Sex.
  • by encrypting the acquired password security during password transmission can be ensured.
  • FIG. 4 is a schematic flowchart of a method for performing client password input by using a smart key device according to another embodiment of the present invention.
  • a smart key device is used as a USB key
  • a client is a PC as an example
  • the user is a user.
  • the online banking is used as an example, and the password corresponding to the account information is obtained, and after the password is obtained, a dynamic password is generated according to the obtained password and then transmitted as an example.
  • the embodiment includes the following steps S401 to S413.
  • S401 When the user wants to log in to the online banking, the bank sends a login password input request to the PC in the background.
  • S402 The PC sends a password output request to the USBkey.
  • USB key displays a list of entries corresponding to the user data stored in the key.
  • S404 The user selects the currently used account information from the list of entries.
  • the USB key acquires a password corresponding to the selected account information from the pre-stored user data.
  • the USB key generates a dynamic password according to the obtained password.
  • the dynamic password automatically changes with variables such as set time, and is dynamically generated randomly.
  • the bank background and the USB key can pre-agreed the operation factor and the operation method.
  • the bank background and USBkey use the same operation factor and generate the same dynamic password with the same operation method.
  • the operation factor includes a seed key, a time factor, an event factor, and the like. Therefore, the dynamic password used by the user is different every time. Even if the hacker intercepts the password once, the password cannot be used to fake the identity of the legitimate user, because the next login must use another dynamic password. Dynamic password can effectively protect the authentication security of transactions and logins, prevent intruders from maliciously destroying resources, and effectively solve the intrusion problem caused by password leakage.
  • the USB key can be used with the bank background.
  • the pre-agreed operation factor and the pre-agreed operation method calculate the obtained password to obtain a dynamic password.
  • USB key sends the dynamic password to the PC.
  • the USB key displays to the user whether to confirm the transmission.
  • the USB key sends the dynamic password to the PC.
  • S408 The PC inputs the dynamic password to the password input location.
  • the dynamic password can be input to the location where the password is required for login. For example, when online banking is logged in, a password input field is displayed, and the PC inputs the dynamic password into the input field.
  • the method may further include the following steps S409-S413.
  • S409 The PC sends the dynamic password to the bank backend. After the USB key receives the dynamic password, the dynamic password can be input to the location where the password is required for login. When the bank is authenticated, the PC sends the information of the password input location to the bank backend, which enables the dynamic password to be sent to the bank backend.
  • the bank calculates the dynamic password in the background.
  • the bank background may pre-save the user's password, and then calculate the pre-stored password by using an operation factor and an operation method agreed in advance with the USB key to obtain a dynamic password.
  • S411 The bank background compares the calculated dynamic password with the received dynamic password, and determines whether the received dynamic password is correct. If yes, execute S312, otherwise execute S313. In the comparison, when the received dynamic password is different from the calculated dynamic password, it can be concluded that the received dynamic password is incorrect. When the received dynamic password is the same as the calculated dynamic password, the received dynamic can be obtained. The password is correct.
  • S412 The login is successful.
  • the bank sends a login success message to the PC, and after receiving the login success message, the PC can confirm that the user is allowed to log in, and then can display the page after login to the user.
  • the bank sends a login failure message to the PC, and the PC may display the login failure to the user after receiving the login failure message.
  • the above smart key device is a USB key. It can be understood that other smart key devices, such as an audio key, a Bluetooth key, etc., can also be referred to.
  • the above client is a PC, and it can be understood that other clients, such as mobile phones, tablets, etc., can also be referred to.
  • the above is the use of online banking by the user. It can be understood that the user can also use other scenarios. For example, the user is performing third-party payment. At this time, the client can authenticate to the third-party payment platform, and other usage scenarios can also refer to the bank background.
  • the corresponding processing flow The details of the embodiment shown in FIG. 4 are similar to those in the embodiment shown in FIG. 3, and can be understood by referring to the embodiment shown in FIG. 3.
  • the seed key used to calculate the dynamic password is obtained by taking the static password corresponding to the account information as an example. It can be understood that the seed key when calculating the dynamic password may also be other information, as in the above embodiment.
  • the website information that is, the stored user data, may include account information, a password, and corresponding website information, and the corresponding website information may be determined according to the account information selected by the user, and then the dynamic password is generated according to the website information. Among them, you can first convert the website information into numbers, and then calculate the numbers to get the dynamic password.
  • Website information can be specific to the website URL or IP address.
  • the password is obtained from the pre-stored user data, so that the client inputs the password received from the smart key device, and the user does not need to manually input, which can facilitate the user to operate, and the password is pre-stored without the user.
  • the passwords corresponding to different accounts can be set to be irrelevant, so that the problem of cracking one account password generated when many passwords are related can be threatened to threaten other account passwords, and the password of each account is improved. Sex.
  • the dynamic password is authenticated, which can reduce the risk of password theft and ensure the security of the user account.
  • FIG. 5 is a schematic structural diagram of a smart key device according to another embodiment of the present invention.
  • the smart key device 50 includes a receiving module 51, a display module 52, a determining module 53, and a sending module 54.
  • the receiving module 51 is configured to receive a password output request sent by the client;
  • the display module 52 is configured to display an entry list corresponding to the user data pre-stored in the smart key device according to the password output request, wherein the user data includes account information and a corresponding password.
  • the user data and the displayed list of entries have been described in detail before, and will not be described here.
  • the determining module 53 is configured to determine account information selected by the user in the list of entries, and determine a first password according to the account information selected by the user, wherein the first password is a password for login authentication.
  • the first password may be the original password corresponding to the account information selected by the user (ie, the password corresponding to the account information stored in the smart key device), or may be the ciphertext obtained by encrypting the original password, and may also be It is a dynamic password calculated by calculating the account information selected by the user and its corresponding information.
  • each account information and a corresponding password may be pre-stored in the smart key device.
  • the smart key device may acquire the corresponding password according to the selected account information. For example, after the user selects the bank card number, the smart key device can obtain the password corresponding to the bank card number from the pre-stored user data. Then, in a specific implementation, the obtained password may be determined as the first password, and the password is in plain text; or the obtained password may be processed to obtain the first password, and the processing may specifically include encryption processing.
  • the first password is an encrypted password, or the processing may specifically generate a dynamic password according to the obtained password. At this time, the first password is a dynamic password.
  • the account information selected by the user may be used as a seed key, or the account information and the password may be used together as a seed key, and the dynamic password is calculated in combination with the dynamic factor.
  • the seed key is generally a number, and the letters in the account information and/or password information can be converted into numbers through an ASCII code comparison table.
  • the user password includes a password corresponding to the account information, and obtains a password corresponding to the account information, and determines the first password according to the obtained password as an example.
  • the user data may further include website information corresponding to the account information, other item information customized by the user, etc., at this time, the account information selected by the user and corresponding information may be selected. Convert at least one of them to a number as the seed key used to calculate the dynamic password. For details, please refer to the subsequent embodiments.
  • the sending module 54 is arranged to send the first password to the client, so that the client inputs the first password.
  • the password may be directly sent to the client, or after the encrypted password is encrypted, the encrypted password is sent to the client. .
  • the dynamic password is generated according to the obtained one or more pieces of information corresponding to the account information selected by the user, and the dynamic password is sent to the client.
  • the first password can be input at the location where the password is input. For example, when the user uses the online banking, the client can input the first password to the password input location. Afterwards, the client can use the input first password to perform login authentication. For example, at the time of authentication, the client sends the first password of the password input location to the bank background, and the login authentication is performed by the bank background to allow or deny the user login.
  • the sending module 54 is specifically configured to: send the first password to the client by using a USB mode; or send the first password to the client by using a voice code; or, adopt a wireless mode. Sending the first password to the client.
  • the first password is obtained according to the pre-stored user data and sent to the client, so that the client inputs the password received from the smart key device, and the user does not need to manually input, which is convenient for the user to operate, and according to the pre-stored
  • the information generates the password entered by the client, and does not require the user to memorize the password, avoiding the problem that the user cannot remember when the account is numerous.
  • the smart key device of this embodiment can communicate with the client in various manners, and the applicable range can be improved.
  • FIG. 6 is a schematic structural diagram of a smart key device according to another embodiment of the present invention.
  • the smart key device 50 is used.
  • the determination module 53 includes a first unit 531 and a second unit 532.
  • the first unit 531 is configured to acquire a password corresponding to the account information selected by the user from pre-stored user data according to the account information selected by the user, wherein the user data includes at least account information and the account
  • the password corresponding to the information may also include website information, user-defined other item information that needs to be stored, and the like;
  • the second unit 532 is configured to determine the acquired password as the first password, or perform encryption processing on the obtained password to obtain the first password.
  • the obtained password may be encrypted after receiving the confirmation information of the user.
  • the USB key can display whether to confirm the encryption. If the user clicks the confirmation button, the obtained password is encrypted, otherwise the encryption process is not performed.
  • the encryption algorithm used in the encryption process of the USB key is after the bank.
  • the determining module 53 includes: a third unit, configured to acquire, according to the account information selected by the user, account information selected by the user from pre-stored user data and select with the user One or more of the information corresponding to the account information, wherein the user data includes at least account information and a password corresponding to the account information, and of course, may include website information, other user-defined storage that needs to be stored.
  • the fourth unit is configured to use a dynamic password calculation algorithm to calculate the obtained information to obtain a dynamic password, and determine the dynamic password as the first password.
  • the smart key device may further include: a first storage module configured to store a private key and a digital certificate of the smart key device; and a second storage module 55 configured to store the user data; a transceiver module configured to receive an operation instruction input by the user and the user data; the access control module is configured to authenticate the user, and after the user passes the identity verification, write the second storage module The rights are open to the user, and the user data is written to the second storage module; and the security chip is configured to generate and authenticate digital signatures, as well as encryption and decryption.
  • passwords corresponding to different account information are irrelevant.
  • the smart key device further includes: an activation control module, configured to receive an activation code input by the user on the smart key device, perform activation verification on the activation code, and after activation verification Activating an information storage function of the smart key device; or receiving an activation request sent by the user through the client and an activation code input by the user through the client, and performing activation verification on the activation code And an information storage function that activates the smart key device after activation verification passes, wherein the information storage function is to implement writing the user data to the smart key device.
  • an activation control module configured to receive an activation code input by the user on the smart key device, perform activation verification on the activation code, and after activation verification Activating an information storage function of the smart key device; or receiving an activation request sent by the user through the client and an activation code input by the user through the client, and performing activation verification on the activation code
  • an information storage function that activates the smart key device after activation verification passes, wherein the information storage function is to implement writing the user data to the smart
  • the smart key device may further include: an opening module configured to receive an opening instruction of the user input, and enable an information storage function of the smart key device according to the opening instruction.
  • the transceiver module may receive the operation instruction and the user data through an operation interface and a control button provided by the smart key device; or receive the operation instruction and the user data sent by the external device through the communication interface.
  • the transceiver module receives an authentication request and a random number sent by the user to the smart key device by using the client, and the security chip pairs the random number according to a private key of the smart key device. Encrypting, and the transceiver module sends the digital certificate of the smart key device and the encrypted random number to the client according to the verification request; wherein the client pairs the smart password according to the root certificate
  • the digital certificate of the key device is verified, and the encrypted random number is decrypted according to the public key of the smart key device, and the decrypted random number is verified.
  • the identity of the smart key device can be verified to ensure its reliability.
  • the display module is further configured to receive, at the transceiver module, an operation instruction input by the user and the number of users After that, the user data is displayed, and the access control module writes the user data to the second storage after the transceiver module receives the confirmation instruction of the displayed user data by the user. Module. Ensure that the data stored by the user is correct.
  • the transceiver module receives the user data ciphertext sent by the client, and the security chip decrypts the user data ciphertext according to the private key of the smart key device to obtain the user data, where the client The user encrypts the user data according to the public key of the smart key device to generate the user data ciphertext; or the transceiver module receives the session key ciphertext and the user data ciphertext sent by the client, The security chip decrypts the session key ciphertext according to the private key of the smart key device to obtain a session key, and decrypts the user data ciphertext according to the session key to obtain the user data, where The client randomly generates a session key, encrypts the session key according to the public key of the smart key device to generate the session key ciphertext, and pairs the user according to the session key Data encryption to generate the user data ciphertext. Ensure the security of user data when transmitting.
  • the module division of the smart key device is not limited to the embodiment.
  • the transceiver module may be configured to implement a function of receiving a password output request, sending a first password to the client, and receiving an operation instruction and bank data. .
  • the password is obtained from the pre-stored user data, so that the client inputs the password received from the smart key device, and the user does not need to manually input, which can facilitate the user to operate, and the password is pre-stored without the user.
  • the smart key device of this embodiment can communicate with the client in various manners, and the applicable range can be improved.
  • the passwords corresponding to different accounts can be set to be irrelevant, so that the problem of cracking one account password generated when many passwords are related can be threatened to threaten other account passwords, and the password of each account is improved. Sex.
  • the dynamic password is authenticated, which can reduce the risk of password theft and ensure the security of the user account.
  • the obtained website information is calculated to generate a dynamic password, which can ensure the diversity of the dynamic password generation manner and improve the applicable scope.
  • FIG. 7 is a schematic structural diagram of a client device according to another embodiment of the present invention.
  • the device 70 includes a sending module 71, a receiving module 72, and an input module 73.
  • the client device can be a PC, a mobile phone, or a tablet.
  • the sending module 71 is configured to send a password output request to the smart key device, so that the smart key device displays a list of entries corresponding to the user data pre-stored in the smart key device according to the password output request, and causes the The smart key device determines account information selected by the user in the list of entries, and determines a first password according to the account information selected by the user, wherein the user data includes account information and a corresponding password, the first password The password used for login authentication.
  • the client device may be sent after receiving the login password input request sent by the password authenticator.
  • the request is made by a password authenticator such as a bank back office, a third party payment platform or a mailbox authentication platform.
  • a password authenticator such as a bank back office, a third party payment platform or a mailbox authentication platform.
  • the receiving module 72 is configured to receive the first password sent by the smart key device.
  • the receiving module 72 is specifically configured to: receive the first password sent by the smart key device by using a USB mode; or receive the first password sent by the smart key device by using a voice code; or Receiving a first password that is sent by the smart key device in a wireless manner.
  • the input module 73 is arranged to input the first password.
  • the client device enters the password into the location where the password is required to log in. Thereafter, the client device may also send the first password to an authenticator such as a bank background for password authentication to allow or deny the user to log in.
  • an authenticator such as a bank background for password authentication to allow or deny the user to log in.
  • the embodiment of the invention further provides a client device, which comprises a casing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is disposed inside the space enclosed by the casing, the processor and the memory Set on the circuit board; power circuit for powering various circuits or devices of the client device; memory for storing executable program code; the processor running and executing the program by reading executable program code stored in the memory The program corresponding to the code is used to perform the following steps S21'-S23'.
  • S21' transmitting a password output request to the smart key device, so that the smart key device displays a list of entries corresponding to the user data pre-stored in the smart key device according to the password output request, and causes the The smart key device determines account information selected by the user in the list of entries, and determines a first password according to the account information selected by the user, wherein the user data includes account information and a corresponding password, the first password
  • the client device is, for example, a PC, a mobile phone, or a tablet.
  • the client device may be the password output request sent after receiving the login password input request sent by the password authenticator, such as a bank background, a third party payment platform or a mailbox authentication platform.
  • the password authenticator such as a bank background, a third party payment platform or a mailbox authentication platform.
  • the receiving the first password sent by the smart key device includes: receiving a first password sent by the smart key device by using a USB mode; or receiving the smart key device by using a voice code manner The first password sent; or the first password sent by the smart key device in a wireless manner.
  • S23' input the first password.
  • the client device enters the password into the location where the password is required to log in.
  • the client device may also send the first password to an authenticator such as a bank background to perform password authentication to allow or deny the user to log in.
  • an authenticator such as a bank background to perform password authentication to allow or deny the user to log in.
  • An embodiment of the present invention further provides a smart key device, including: one or more processors; a memory; one or more programs, one or more programs stored in the memory, when executed by one or more processors The following operations of step S11'-step S14' are performed.
  • S12' displaying, according to the password output request, a list of entries corresponding to user data pre-stored in the smart key device, wherein the user data includes account information and a corresponding password.
  • S13' determining account information selected by the user in the item list, and determining a first password according to the account information selected by the user, wherein the first password is a password for login authentication.
  • S14' Send the first password to the client, so that the client inputs the first password.
  • the first password is obtained according to the pre-stored user data and sent to the client, so that the client inputs the password received from the smart key device, and the user does not need to manually input, which is convenient for the user to operate, and according to the pre-stored User data generates the password entered by the client, and does not require the user to memorize the password, avoiding the problem that the user cannot remember when the account is numerous.
  • portions of the invention may be implemented in hardware, software, firmware or a combination thereof.
  • multiple steps or methods may be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system.
  • a suitable instruction execution system For example, if implemented in hardware, as in another embodiment, it can be implemented by any one or combination of the following techniques well known in the art: having logic gates for implementing logic functions on data signals. Discrete logic circuits, application specific integrated circuits with suitable combinational logic gates, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
  • each functional unit in each embodiment of the present invention may be integrated into one processing module, or each unit may exist physically separately, or two or more units may be integrated into one module.
  • the above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
  • the integrated modules, if implemented in the form of software functional modules and sold or used as stand-alone products, may also be stored in a computer readable storage medium.
  • the above mentioned storage medium may be a read only memory, a magnetic disk or an optical disk or the like.

Abstract

本发明提出一种通过智能密钥设备进行客户端密码输入的方法、智能密钥设备以及客户端装置,为实现密码自动输入,方便用户操作。该方法包括:智能密钥设备接收客户端发送的密码输出请求;根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,所述用户数据包括账户信息和对应的密码;确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,所述第一密码为用于登录认证的密码;将所述第一密码发送给所述客户端。该方法能够实现密码自动输入,方便用户操作。

Description

密码输入方法、智能密钥设备以及客户端装置 技术领域
本发明涉及网络信息安全技术领域,尤其涉及一种通过智能密钥设备进行客户端密码输入的方法、智能密钥设备以及客户端装置。
背景技术
口令技术是目前网络信息系统中最为安全与保密措施之一,网银、第三方支付、各种购物社交类网站登录都需要设置相应账号以及登录密码。随着网络信息时代的发展,人们网上活动的日趋频繁,就会有越来越多的账号和密码等需要用户去设置并准确记忆。
如果众多的账户和密码都需要用户人为记忆,那么无疑会对用户的记忆能力造成极大的考验,并且,用户手动输入密码时,也比较耗时耗力。
发明内容
本发明旨在至少在一定程度上解决相关技术中的技术问题之一。
为此,本发明的一个目的在于提出一种通过智能密钥设备进行客户端密码输入的方法,该方法可以无需用户记忆和手动输入密码,实现密码自动输入,方便用户操作。
本发明的另一个目的在于提出一种智能密钥设备。
本发明的另一个目的在于提出一种客户端装置。
为达到上述目的,本发明第一方面实施例提出的通过智能密钥设备进行客户端密码输入的方法,包括:智能密钥设备接收客户端发送的密码输出请求;所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,其中,所述用户数据包括账户信息和对应的密码;所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码;所述智能密钥设备将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
此外,所述根据所述用户选择的账户信息确定第一密码,包括:根据所述用户选择的账户信息,从所述用户数据中获取与所述用户选择的账户信息对应的密码;将所述获取的密码确定为所述第一密码,或者对所述获取的密码进行加密处理,得到所述第一密码;或者,根据所述用户选择的账户信息,从所述用户数据中获取所述用户选择的账户信息以及与所述用户选择的账户信息对应的信息中的一种或多种;采用动态密码计算算法,对所述 获取的信息进行计算得到动态密码,将所述动态密码确定为所述第一密码。
此外,在所述显示与所述智能密钥设备中预先存储的用户数据对应的条目列表之前,所述方法还包括:所述智能密钥设备存储所述用户数据。
此外,所述智能密钥设备存储所述用户数据,包括:所述智能密钥设备接收所述用户输入的操作指令和所述用户数据;所述智能密钥设备对所述用户进行身份验证,并在所述用户通过身份验证之后,将所述智能密钥设备的写权限开放给所述用户;将所述用户数据写入至所述智能密钥设备。
此外,在所述智能密钥设备接收用户输入的操作指令和所述用户数据之前,所述方法还包括:接收所述用户在所述智能密钥设备上输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能;或者,接收所述用户通过所述客户端发送的激活请求和所述用户通过所述客户端输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能,其中,所述信息存储功能用于实现将所述用户数据写入至所述智能密钥设备;以及,接收所述用户输入的开启指令,并根据所述开启指令启用所述智能密钥设备的信息存储功能。
此外,所述智能密钥设备接收用户输入的操作指令和所述用户数据具体包括:通过所述智能密钥设备提供的操作界面及控制按钮接收所述操作指令和所述用户数据;或者通过通信接口接收外部设备发送的所述操作指令和所述用户数据。
此外,在将所述用户数据写入至所述智能密钥设备之前,所述方法还包括:所述智能密钥设备接收所述用户通过所述客户端发送的对所述智能密钥设备的验证请求和随机数,并根据所述智能密钥设备的私钥对所述随机数进行加密,以及根据所述验证请求将所述智能密钥设备的数字证书和加密后的随机数发送至所述客户端;所述客户端根据根证书对所述智能密钥设备的数字证书进行验证,并根据所述智能密钥设备的公钥对所述加密后的随机数进行解密,以及对解密后的随机数进行验证;在验证所述数字证书和所述随机数通过后,显示所述用户数据;所述将所述用户数据写入至所述智能密钥设备具体为:在接收到所述用户对显示出的所述用户数据的确认指令之后,所述智能密钥设备存储所述用户数据。
此外,所述智能密钥设备接收用户输入的操作指令和所述用户数据具体包括:所述智能密钥设备接收所述客户端发送的用户数据密文,并根据所述智能密钥设备的私钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端根据所述智能密钥设备的公钥对所述用户数据加密以生成所述用户数据密文;或者,所述智能密钥设备接收所述客户端发送的会话密钥密文和用户数据密文,并根据所述智能密钥设备的私钥对所述会话密钥密文解密以获取会话密钥,以及根据所述会话密钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端随机生成会话密钥,并根据所述智能密钥设备的公钥对所述会话 密钥加密以生成所述会话密钥密文,以及根据所述会话密钥对所述用户数据加密以生成所述用户数据密文。
本发明第一方面实施例提出的通过智能密钥设备进行客户端密码输入的方法,通过根据预先存储的用户数据得到第一密码并发送给客户端,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,根据预先存储的用户数据生成客户端输入的密码,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。
为达到上述目的,本发明第二方面实施例提出的通过智能密钥设备进行客户端密码输入的方法,包括:客户端向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码;所述客户端接收所述智能密钥设备发送的所述第一密码;所述客户端接输入所述第一密码。
本发明第二方面实施例提出的通过智能密钥设备进行客户端密码输入的方法,通过指示智能密钥设备输出密码,并且将智能密钥设备发送的第一密码输入,可以实现密码的自动输入,无需用户输入,可以方便用户操作。
为达到上述目的,本发明第三方面实施例提出的智能密钥设备,包括:接收模块,设置为接收客户端发送的密码输出请求;显示模块,设置为根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,其中,所述用户数据包括账户信息和对应的密码;确定模块,设置为确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码;发送模块,设置为将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
此外,所述确定模块包括:第一单元,设置为根据所述用户选择的账户信息,从所述用户数据中获取与所述用户选择的账户信息对应的密码;第二单元,设置为将所述获取的密码确定为所述第一密码,或者,对所述获取的密码进行加密处理,得到所述第一密码。
此外,所述确定模块包括:第三单元,设置为根据所述用户选择的账户信息,从所述用户数据中获取所述用户选择的账户信息以及与所述用户选择的账户信息对应的信息中的一种或多种;第四单元,设置为采用动态密码计算算法,对所述获取的信息进行计算得到动态密码,将所述动态密码确定为所述第一密码。
此外,所述智能密钥设备还包括:第一存储模块,设置为存储所述智能密钥设备的私钥和数字证书;第二存储模块,设置为存储所述用户数据;收发模块,设置为接收用户输入的操作指令和所述用户数据;访问控制模块,设置为对所述用户进行身份验证,并在所 述用户通过身份验证之后,将所述第二存储模块的写权限开放给所述用户,以及将所述用户数据写入至所述第二存储模块;以及安全芯片,设置为进行数字签名的生成和认证,以及加密和解密。
此外,所述智能密钥设备还包括:激活控制模块,设置为接收所述用户在所述智能密钥设备上输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能;或者,接收所述用户通过所述客户端发送的激活请求和所述用户通过所述客户端输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能,其中,所述信息存储功能用于实现将所述用户数据写入至所述智能密钥设备;以及开启模块,设置为接收所述用户输入的开启指令,并根据所述开启指令启用所述智能密钥设备的信息存储功能。
此外,所述收发模块通过所述智能密钥设备提供的操作界面及控制按钮接收所述操作指令和所述用户数据;或者,通过通信接口接收外部设备发送的所述操作指令和所述用户数据。
此外,所述收发模块接收所述用户通过所述客户端发送的对所述智能密钥设备的验证请求和随机数,所述安全芯片根据所述智能密钥设备的私钥对所述随机数进行加密,以及所述收发模块根据所述验证请求将所述智能密钥设备的数字证书和加密后的随机数发送至所述客户端;其中,所述客户端根据根证书对所述智能密钥设备的数字证书进行验证,并根据所述智能密钥设备的公钥对所述加密后的随机数进行解密,以及对解密后的随机数进行验证;所述显示模块,还设置为在所述收发模块接收所述用户输入的操作指令和所述用户数据之后,显示所述用户数据,以及所述访问控制模块在所述收发模块接收到所述用户对显示出的所述用户数据的确认指令之后,将所述用户数据写入所述第二存储模块。
此外,所述收发模块接收客户端发送的用户数据密文,所述安全芯片根据所述智能密钥设备的私钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端根据所述智能密钥设备的公钥对所述用户数据加密以生成所述用户数据密文;或者,所述收发模块接收客户端发送的会话密钥密文和用户数据密文,所述安全芯片根据所述智能密钥设备的私钥对所述会话密钥密文解密以获取会话密钥,并根据所述会话密钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端随机生成会话密钥,并根据所述智能密钥设备的公钥对所述会话密钥加密以生成所述会话密钥密文,以及根据所述会话密钥对所述用户数据加密以生成所述用户数据密文。
本发明第三方面实施例提出的智能密钥设备,通过根据预先存储的用户数据得到第一密码并发送给客户端,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,根据预先存储的用户数据生成客户端输入的密码,也不需要用 户记忆密码,避免账户众多时用户难以记忆的问题。
为达到上述目的,本发明第四方面实施例提出的客户端装置,包括:发送模块,设置为向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码;接收模块,设置为接收所述智能密钥设备发送的所述第一密码;输入模块,设置为输入所述第一密码。
本发明第四方面实施例提出的客户端装置,通过指示智能密钥设备输出密码,并且将智能密钥设备发送的第一密码输入,可以实现密码的自动输入,无需用户输入,可以方便用户操作。
为达到上述目的,本发明第五方面实施例提出的客户端设备,包括壳体、处理器、存储器、电路板和电源电路,其中,电路板安置在壳体围成的空间内部,处理器和存储器设置在电路板上;电源电路,用于为客户端设备的各个电路或器件供电;存储器用于存储可执行程序代码;处理器通过读取存储器中存储的可执行程序代码来运行与可执行程序代码对应的程序,以用于执行以下步骤:向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码;接收所述智能密钥设备发送的所述第一密码;输入所述第一密码。
本发明第五方面实施例提出的客户端设备,通过指示智能密钥设备输出密码,并且将智能密钥设备发送的第一密码输入,可以实现密码的自动输入,无需用户输入,可以方便用户操作。
为达到上述目的,本发明第六方面实施例提出的智能密钥设备,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时进行如下操作:接收客户端发送的密码输出请求;根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,其中,所述用户数据包括账户信息和对应的密码;确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码;将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
本发明第六方面实施例提出的智能密钥设备,通过根据预先存储的用户数据得到第一密码并发送给客户端,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,根据预先存储的用户数据生成客户端输入的密码,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。
本发明附加的方面和优点将在下面的描述中部分给出,部分将从下面的描述中变得明显,或通过本发明的实践了解到。
附图说明
本发明上述的和/或附加的方面和优点从下面结合附图对实施例的描述中将变得明显和容易理解,其中:
图1为本发明一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图;
图2为本发明另一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图;
图3为本发明另一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图;
图4为本发明另一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图;
图5为本发明另一实施例提出的智能密钥设备的结构示意图;
图6为本发明另一实施例提出的智能密钥设备的结构示意图;
图7为本发明另一实施例提出的客户端装置的结构示意图。
具体实施方式
下面详细描述本发明的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的元件或具有相同或类似功能的元件。下面通过参考附图描述的实施例是示例性的,仅用于解释本发明,而不能理解为对本发明的限制。相反,本发明的实施例包括落入所附加权利要求书的精神和内涵范围内的所有变化、修改和等同物。
图1为本发明一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图,该方法包括以下步骤S11-步骤14。
S11:智能密钥设备接收客户端发送的密码输出请求。
其中,智能密钥设备可以是具有存储能力的设备,例如,通用串行总线(Universal Serial Bus,USB)key、音码key、可进行无线通信的key,相应的,智能密钥设备可以通 过USB方式、音码方式或者无线方式与客户端通信,其中,无线方式可以包括蓝牙方式、wifi方式或者红外方式等。具体地,USB方式可以是指智能密钥设备通过USB接口与客户端通信,音码方式可以是指智能密钥设备通过音频接口或者扬声器与客户端通信,无线方式可以是指智能密钥设备与客户端建立无线连接后进行通信。
客户端可以是指用户进行网络登录的设备,例如,个人电脑(Personal Computer,PC)、手机、平板电脑等。
当用户在客户端上要登录某一账户时,例如,用户使用网银时,需要用户输入密码,此时,客户端可以向智能密钥设备发送密码输出请求,以从智能密钥设备中获取相应密码。另外,本发明实施例中的密码也可以称为口令。
S12:智能密钥设备根据所述密码输出请求,显示与智能密钥设备中预先存储的用户数据对应的条目列表,所述用户数据包括账户信息和对应的密码。
其中,智能密钥设备中可以预先存储用户能够使用的各账户信息以及对应的密码,例如,用户可能使用网银、第三方支付以及电子邮箱,那么可以在智能密钥设备中保存银行卡号和对应的密码,第三方支付的用户名和对应的密码,以及,电子邮箱的用户名和对应的密码。智能密钥设备中用于存储各账户信息以及对应的密码的模块可以称为密码锦囊。
当智能密钥设备接收到密码输出请求后,可以显示与已存储的用户数据对应的条目列表(当然,也可以以其他形式显示)供用户选择登录需要使用的账户,以上述例子进行说明,则可以显示银行卡号、第三方支付的用户名和电子邮箱的用户名。
可以理解的是,显示的条目列表中至少包括账户,也可以包括账户和相应的密码,例如,显示银行卡号和对应的密码,第三方支付的用户名和对应的密码,以及电子邮箱的用户名和对应的密码。
上述以用户数据包括账户信息和对应的密码为例,可以理解的是,用户数据还可以包括其他信息,例如账户信息对应的网站信息,例如,用户在智能密钥设备中存储淘宝的网站名、用户名(即账户信息)和对应的密码。
需要说明的是,用户可以自定义要存储的项目,即根据自己的需求增减要存储的项目,例如,用户存储的用户数据可以是网站名称、登录该网站的账户和对应的密码,也可以是账户和对应的密码,还可以是账户、该账户对应的密码以及备注。
换言之,存储的用户数据可分为两类:一类是预设的项目,可供用户直接进行选择,例如,银行卡号、网上银行登录名、密码、网址、邮箱名等等。在每个项目下还可预设多个下级的项目,例如,在银行卡号下可设置中行,工行,农行等。此外,另一类是空白的可供用户自定义输入的,用户需要存储用户数据时,可新建一个条目,其中,该条目可包括多个项目,例如,银行卡的种类、账号、密码、备注等。
相应的,在显示时,即显示的条目列表中可以包括账户信息,或者包括账户信息和对应的密码,或者包括账户信息和对应的网站信息,或者,包括账户信息和对应的密码以及对应的网站信息,或者包括账户信息和用户自定义的其他需要存储的项目等。
其中,网站信息可以具体为以下至少之一:网站的统一资源定位符(Uniform Resource Locator,URL)地址,网站的互联网协议(Internet Protocol,IP)地址,域名和网站名。
S13:智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码;第一密码可以是用户选择的账户信息对应的原始密码(即存储在智能密钥设备中的与该账户信息对应的密码),也可以是对该原始密码进行加密后得到的密文,还可以是对用户选择的账户信息及其对应的信息进行计算得到的动态密码。
其中,在智能密钥设备向用户显示上述的条目列表后,用户就可以根据当前使用情况选择相应的账户信息。例如,用户当前要使用网银,那么用户可以选择银行卡号。
当用户完成对账户信息的选择后,用户可以点击确认键以向智能密钥设备发送确认信息,相应的,智能密钥设备根据用户选择的账户信息以及用户发送的确认信息,可以确定用户选择的账户信息。
如上所述,智能密钥设备中可以预先存储各账户信息以及对应的密码,当用户选择其中的一个账户信息后,智能密钥设备根据该选择的账户信息可以获取对应的密码。例如,用户选择银行卡号后,智能密钥设备可以从预先存储的用户数据中获取与银行卡号对应的密码。之后,在具体实施时,可以将获取的密码确定为第一密码,此时是采用明文的密码;或者,可以对获取的密码进行处理,得到第一密码,处理可以具体包括加密处理,此时,第一密码是加密后的密码,或者,处理也可以具体是根据获取的密码生成动态密码,即将获取的密码作为种子密钥,结合动态因子计算得到动态密码,此时,第一密码是动态密码。当然,也可以将用户选择的账号信息作为种子密钥,或者,将账号信息和密码一起作为种子密钥,结合动态因子计算得到动态密码。需要说明的是,种子密钥一般为数字,账号信息和/或密码信息中的字母等可以通过ASCII码对照表转换为数字。
上述以用户数据包括账户信息对应的密码,获取账户信息对应的密码,并根据获取的密码确定第一密码为例。可以理解的是,如上所述,用户数据还可以包括账户信息对应的网站信息和/或用户自定义的其他项目信息,此时,也可根据网站信息生成动态密码,将生成的动态密码确定为第一密码。其中,可以首先将网站信息转换为数字,之后再采用动态密码算法对数字进行运算,生成网站信息对应的动态密码。
由上述可知,所述根据所述用户选择的账户信息确定第一密码,可以采用如下方式实现:
根据所述用户选择的账户信息,从用户数据中获取与所述用户选择的账户信息对应的密码,其中,所述用户数据至少包括账户信息以及与所述账户信息对应的密码,当然,还可以包括网站信息、用户自定义的其他项目信息等;将所述获取的密码确定为所述第一密码,或者,对所述获取的密码进行加密处理,得到所述第一密码。
或者,
根据所述用户选择的账户信息,从预先存储的用户数据中获取所述用户选择的账户信息以及与所述用户选择的账户信息对应的信息中的一种或多种,其中,所述用户数据至少包括账户信息以及与所述账户信息对应的密码,当然,还可以包括网站信息、用户自定义的其他项目信息等;采用动态密码计算算法,对所述获取的信息进行计算得到动态密码,将所述动态密码确定为所述第一密码。
如上所述,用户可以自定义要存储的条目,用户在智能密钥设备存储的用户数据中选择当前要使用的账户信息,该账户信息及其对应的信息(例如网站信息、密码等)中的一种或多种,在能够转换为数字的情况下,均可以作为种子密钥,结合动态因子计算动态密码,例如,将账户信息与对应的网站信息转换为数字后作为种子密钥。
S14:智能密钥设备将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
其中,当智能密钥设备获取与用户选择的账户信息对应的密码后,可以直接将该密码发送给客户端,或者,对获取的密码进行加密处理后,将加密处理后的密码发送给客户端。或者,根据获取的与用户选择的账户信息相关的一种或多种信息生成动态密码,将该动态密码发送给客户端。
当客户端接收到第一密码后,就可以在输入密码的位置输入所述第一密码,例如,用户在使用网银时,客户端可以将第一密码输入到密码输入位置。
之后,客户端可以采用该输入的第一密码进行登录认证,例如,在认证时客户端将密码输入位置的第一密码发送给银行后台,由银行后台进行登录认证,以允许或拒绝用户登录。具体的,如果第一密码是明文,则后台直接进行认证;如果第一密码是密文,则后台对其进行解密得到明文密码,再进行认证;如果第一密码是动态密码,则后台采用与智能密钥设备相同的动态密码算法对存储在后台的信息进行计算,将计算结果与第一密码比对,以进行认证。
本实施例通过根据预先存储的用户数据得到第一密码并发送给客户端,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,根据预先存储的用户数据生成客户端输入的密码,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。另外,本实施例的智能密钥设备可以通过多种方式与客户端通信,可以 提高适用范围。
此外,在S12中显示与所述智能密钥设备中预先存储的用户数据对应的条目列表之前,上述方法还可以包括:所述智能密钥设备存储所述用户数据。
所述智能密钥设备存储所述用户数据具体包括:所述智能密钥设备接收所述用户输入的操作指令和所述用户数据;所述智能密钥设备对所述用户进行身份验证,并在所述用户通过身份验证之后,将所述智能密钥设备的写权限开放给所述用户;将所述用户数据写入至所述智能密钥设备。具体而言,用户输入的操作指令可以是用户在智能密钥设备中添加新的用户数据的指令,或者对智能密钥设备中已存储的用户数据进行编辑、修改、删除等指令。可根据用户输入的PIN码对用户的身份进行验证。
此外,在所述智能密钥设备接收用户输入的操作指令和所述用户数据之前,还可以激活智能密钥设备的信息存储功能,具体包括:接收所述用户在所述智能密钥设备上输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能;或者,接收所述用户通过所述客户端发送的激活请求和所述用户通过所述客户端输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能,其中,所述信息存储功能用于实现将所述用户数据写入至所述智能密钥设备。
在一个实施例中,提供了一种启用智能密钥设备的信息存储功能进行数据存储的方式,具体包括:接收所述用户输入的开启指令,并根据所述开启指令启用所述智能密钥设备的信息存储功能。
此外,所述智能密钥设备接收用户输入的操作指令和所述用户数据具体包括:通过所述智能密钥设备提供的操作界面及控制按钮接收所述操作指令和所述用户数据;或者通过通信接口接收外部设备发送的所述操作指令和所述用户数据。具体而言,用户可通过智能密钥设备提供的键盘(例如,物理键盘或者虚拟键盘)输入操作指令和用户数据。用户还可将智能密钥设备连接到客户端,在客户端上安装相应的管理应用程序,在管理应用程序的操作界面中通过鼠标、键盘、触摸屏等设备输入操作指令和用户数据,然后通过客户端的通信接口将操作指令和用户数据发送至智能密钥设备。
此外,在将所述用户数据写入至所述智能密钥设备之前,所述方法还包括:所述智能密钥设备接收所述用户通过所述客户端发送的对所述智能密钥设备的验证请求和随机数,并根据所述智能密钥设备的私钥对所述随机数进行加密,以及根据所述验证请求将所述智能密钥设备的数字证书和加密后的随机数发送至所述客户端;所述客户端根据根证书对所述智能密钥设备的数字证书进行验证,并根据所述智能密钥设备的公钥对所述加密后的随机数进行解密,以及对解密后的随机数进行验证。在存储用户数据之前,验证智能密钥设 备的身份,保证其可靠性。
在将用户数据写入至智能密钥设备之前,显示所述用户数据;所述将所述用户数据写入至所述智能密钥设备具体为:在接收到所述用户对显示出的所述用户数据的确认指令之后,所述智能密钥设备存储所述用户数据。也可以在对智能密钥设备数字证书和随机数的验证通过后,显示用户数据,或者在接收到用户数据之后就显示该用户数据。由用户确认之后再进行存储,确保用户存储的数据的正确性。
此外,所述智能密钥设备接收用户输入的操作指令和所述用户数据具体包括:(1)所述智能密钥设备接收所述客户端发送的用户数据密文,并根据所述智能密钥设备的私钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端根据所述智能密钥设备的公钥对所述用户数据加密以生成所述用户数据密文;或者,(2)所述智能密钥设备接收所述客户端发送的会话密钥密文和用户数据密文,并根据所述智能密钥设备的私钥对所述会话密钥密文解密以获取会话密钥,以及根据所述会话密钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端随机生成会话密钥,并根据所述智能密钥设备的公钥对所述会话密钥加密以生成所述会话密钥密文,以及根据所述会话密钥对所述用户数据加密以生成所述用户数据密文。保证用户数据在传输时的安全性。
图2为本发明另一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图,该方法包括以下步骤S21-步骤S23。
S21:客户端装置向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码。
其中,客户端装置例如为PC、手机或者平板电脑等。
客户端装置可以是在接收到密码认证方发送的登录密码输入请求后,发送的该密码输出请求,密码认证方例如银行后台、第三方支付平台或者邮箱认证平台等。
对于智能密钥设备接收到密码输出请求后执行的流程可以具体参见其他实施例中关于智能密钥设备侧的描述,在此不再赘述。
S22:客户端装置接收所述智能密钥设备发送的所述第一密码。可选的,所述接收所述智能密钥设备发送的第一密码,包括:接收所述智能密钥设备采用USB方式发送的第一密码;或者,接收所述智能密钥设备采用音码方式发送的第一密码;或者,接收所述智能密钥设备采用无线方式发送的第一密码。
S23:客户端装置输入所述第一密码。例如,客户端装置将该密码输入到登录时所需输 入密码的位置。之后,客户端装置还可以将该第一密码发送给银行后台等认证方进行密码认证,以允许或拒绝用户登录。
本实施例通过指示智能密钥设备输出密码,并且将智能密钥设备发送的第一密码输入,可以实现密码的自动输入,无需用户输入,可以方便用户操作。
图3为本发明另一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图,本实施例以智能密钥设备为USB key,客户端为PC为例,且,以用户使用网银为例,以及,以获取账户信息对应的密码,并在获取密码后对密码进行加密处理后再传输为例。参见图3,本实施例包括以下步骤S301-步骤S313。
S301:当用户要登录网银时,银行后台向PC发送登录密码输入请求。由于网银登录时需要输入密码,因此,此时银行后台可以发送登录密码输入请求,以便用户输入登录密码。
S302:PC向USB key发送密码输出请求。本实施例为了方便用户的操作,将账户对应的密码保存在USB key中,之后直接从USB key中获取密码输入,而不是由用户手动输入,因此,为了获取密码,PC可以向USB key发送密码输出请求。
相关技术中,USB key内置单片机或智能卡芯片,有一定的存储空间,可以存储用户的私钥以及数字证书。利用USB key内置的公钥算法实现对用户身份的认证。二代USB key从硬件形态上增加了一个物理按键,并增加了显示模块或语音模块,可以把送到USB key内的交易数据信息显示或报读出来。杜绝了交易数据在用户客户端提交到USB key过程中被篡改的危险性。并且USB key具有一定的访问控制安全性,USB key本身具有一个PIN密码,用户在使用USB key功能之前需正确输入该密码才能正常使用,并且连续错误输入超过一定次数将会自动锁死,有效防止恶意破解。
目前人们已经利用USB Key技术很好地解决了网络安全身份认证的难题,并已广泛应用于网银支付领域。USB key的高安全特性确保了用户的私钥和证书的安全。
但是,相关技术中,使用USB key进行网银交易时仍然需要用户手动地输入账户以及登录密码,对于较为复杂的密码输入较费时费力。
而本实施例中,将用户的账户信息和对应的密码预先存储在USB key中,当需要输入密码时,直接从USB key中导出密码进行输入以替代手动输入。
S303:USB key显示与key中已存储的用户数据对应的条目列表。
由于用户可能使用的账户是众多的,例如,用户可能使用网银、第三方支付、电子邮箱、社交网站等,为了避免用户记忆众多的密码,可以将这些账户信息以及对应的密码存储在USB key中,当用户需要某一密码时,可以将存储的各条目的信息显示给用户,由用户选择当前使用的账户信息。
S304:用户从该条目列表中选择当前使用的账户信息。例如,用户可以通过按键在多 个条目中选择一个要选择的条目。另外,用户在完成选择后可以通过点击确认键,确认用户的选择。
S305:USB key从预先存储的用户数据中获取选择的账户信息对应的密码。
由于USB key中的用户数据是对应保存账户信息和密码,根据用户选择的账户信息找到对应的密码。
相关技术中,如果用户将多个账号和密码设置为不相关的,用户难以记忆并容易遗忘。而如果用户为了便于记忆并不易遗忘时,可以选择相同或类似特征的组合作为密码,但是,关联性较大的众多密码一旦其中某一个被破解,将直接威胁其他账户的安全,对其信息安全保护带来了极大的隐患。
而本实施例中,由于密码保存在USB key内,不需要人工记忆,因此,为了保证安全性,避免攻击者破译一个账户的密码就可以获取其他账户的密码,可以设置不同账户信息对应的密码不相关。
S306:USB key对获取的密码进行加密处理,得到密文。可选的,可以是接收到用户的确认信息后对获取的密码进行加密处理。例如,USB key获取密码后,可以向用户显示是否确认加密,如果用户点击了确认键,那么就会获取的密码进行加密处理,否则不进行加密处理。
为了使得银行后台可以正确解密,USB key进行加密处理时采用的加密算法是与银行后台预先约定的算法,之后银行采用该约定算法进行解密。
S307:USB key将该密文发送给PC。可选的,USB key在得到密文后向用户显示是否确认发送,当用户点击确认键后,USB key将密文发送给PC。
S308:PC将该密文输入到密码输入位置。其中,USB key接收到密文后,可以将该密文输入到登录时所需输入密码的位置。例如,网银登录时,会显示密码输入栏,PC将该密文输入到该输入栏。
由于输入密码通常是要进行登录认证的,因此,该方法还可以包括:
S309:PC将该密文发送给银行后台。其中,USB key接收到密文后,可以将该密文输入到登录时所需输入密码的位置。在银行认证时,PC会将密码输入位置的信息发送给银行后台,也就实现了将密文发送给银行后台。
S310:银行后台对接收的密文进行解密处理,得到明文的密码。如上所述,银行后台可以采用与USB key预先约定的算法对接收的密文进行解密处理。
S311:银行后台对明文的密码进行认证,判断该明文的密码是否正确,若正确,执行S312,否则执行S313。其中,银行后台可以预先保存用户的密码,通过比对明文的密码与预先保存的密码,可以判断出解密后得到的明文密码是否正确。
S312:登录成功。例如,银行后台向PC发送登录成功消息,PC接收到登录成功消息后可以确认允许用户登录,之后可以向用户显示登录后的页面等。
S313:登录失败。例如,银行后台向PC发送登录失败消息,PC接收到登录失败消息后可以向用户显示登录失败。
需要说明的是,上述的智能密钥设备为USB key,可以理解的是,其他的智能密钥设备,例如音频key、蓝牙key等也可以参照执行。上述的客户端为PC,可以理解的是,其他的客户端,例如,手机、平板电脑等也可以参照执行。上述是用户使用网银,可以理解的是,用户也可以在其他使用场景,例如,用户在进行第三方支付,此时客户端可以向第三方支付平台进行认证,其他使用场景也可以参照银行后台的相应处理流程。
本实施例通过从预先存储的用户数据中获取密码,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,将密码进行预先存储,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。另外,本实施例通过预先存储密码,可以将不同账户对应的密码设置为不相关,因此可以避免众多密码相关时产生的破解一个账户的密码就威胁其他账户密码的问题,提高各账户密码的安全性。本实施例通过对获取的密码进行加密处理,可以保证密码传输时的安全性。
图4为本发明另一实施例提出的通过智能密钥设备进行客户端密码输入的方法的流程示意图,本实施例以智能密钥设备为USB key,客户端为PC为例,且,以用户使用网银为例,以及,以获取账户信息对应的密码,并在获取密码后根据获取的密码生成动态密码再传输为例。参见图4,本实施例包括以下步骤S401-步骤S413。
S401:当用户要登录网银时,银行后台向PC发送登录密码输入请求。S402:PC向USBkey发送密码输出请求。
S403:USB key显示与key中已存储的用户数据对应的条目列表。
S404:用户从该条目列表中选择当前使用的账户信息。
S405:USB key从预先存储的用户数据中获取选择的账户信息对应的密码。
S406:USB key根据获取的密码生成动态密码。其中,动态密码随着设定的时间等变量而自动变化,动态随机生成。
本实施例中,银行后台和USB key可以预先约定运算因子和运算方法。银行后台和USBkey以相同的运算因子,采用相同的运算方法,会生成相同的动态密码。运算因子中包含种子密钥、时间因子、事件因子等。因此用户每次使用的动态密码都不相同,即使黑客截获了一次密码,也无法利用这个密码来仿冒合法用户的身份,因为下一次登录必须使用另外一个动态密码。动态密码可以有效保护交易和登录的认证安全,防止入侵者恶意破坏资源,能有效解决由密码泄密导致的入侵问题。本实施例中,USB key可以采用与银行后台 预先约定的运算因子,以及预先约定的运算方法,对获取的密码进行计算,得到动态密码。
S407:USB key将该动态密码发送给PC。可选的,USB key在得到动态密码后向用户显示是否确认发送,当用户点击确认键后,USB key将动态密码发送给PC。
S408:PC将该动态密码输入到密码输入位置。其中,USB key接收到动态密码后,可以将该动态密码输入到登录时所需输入密码的位置。例如,网银登录时,会显示密码输入栏,PC将该动态密码输入到该输入栏。
由于输入密码通常是要进行登录认证的,因此,该方法还可以包括以下步骤S409-S413。
S409:PC将该动态密码发送给银行后台。其中,USB key接收到动态密码后,可以将该动态密码输入到登录时所需输入密码的位置。在银行认证时,PC会将密码输入位置的信息发送给银行后台,也就实现了将动态密码发送给银行后台。
S410:银行后台计算动态密码。其中,银行后台可以预先保存用户的密码,之后,采用与USB key预先约定的运算因子和运算方法,对预先保存的密码进行计算,得到动态密码。
S411:银行后台比对计算得到的动态密码与接收的动态密码,判断接收的动态密码是否正确,若正确,执行S312,否则执行S313。其中,通过比对,当接收的动态密码与计算得到的动态密码不同时,可以得出接收的动态密码不正确,当接收的动态密码与计算得到的动态密码相同时,可以得出接收的动态密码正确。
S412:登录成功。例如,银行后台向PC发送登录成功消息,PC接收到登录成功消息后可以确认允许用户登录,之后可以向用户显示登录后的页面等。
S413:登录失败。例如,银行后台向PC发送登录失败消息,PC接收到登录失败消息后可以向用户显示登录失败。
需要说明的是,上述的智能密钥设备为USB key,可以理解的是,其他的智能密钥设备,例如音频key、蓝牙key等也可以参照执行。上述的客户端为PC,可以理解的是,其他的客户端,例如,手机、平板电脑等也可以参照执行。上述是用户使用网银,可以理解的是,用户也可以在其他使用场景,例如,用户在进行第三方支付,此时客户端可以向第三方支付平台进行认证,其他使用场景也可以参照银行后台的相应处理流程。图4所示实施例中的部分具体内容与图3所示实施例中类似,可参照图3所示实施例进行理解。
本实施例以计算动态密码使用时的种子密钥是获取的与账户信息对应的静态密码为例,可以理解的是,计算动态密码时的种子密钥也可以是其他信息,如上述实施例所述的网站信息,即存储的用户数据中可以包括账户信息、密码和对应的网站信息,根据用户选择的账户信息可以确定对应的网站信息,之后根据该网站信息生成动态密码。其中,可以首先将网站信息转换为数字,再对数字进行运算得到动态密码。网站信息可以具体为网站 的URL地址或IP地址。
本实施例通过从预先存储的用户数据中获取密码,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,将密码进行预先存储,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。另外,本实施例通过预先存储密码,可以将不同账户对应的密码设置为不相关,因此可以避免众多密码相关时产生的破解一个账户的密码就威胁其他账户密码的问题,提高各账户密码的安全性。本实施例通过根据获取的密码生成动态密码,对动态密码进行认证,可以降低密码被盗风险,保证用户账户安全。
图5为本发明另一实施例提出的智能密钥设备的结构示意图,该智能密钥设备50包括接收模块51、显示模块52、确定模块53和发送模块54。
接收模块51设置为接收客户端发送的密码输出请求;
显示模块52设置为根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,其中,所述用户数据包括账户信息和对应的密码。用户数据、显示的条目列表之前已详细描述,此处不再赘述。
确定模块53设置为确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码。第一密码可以是用户选择的账户信息对应的原始密码(即存储在智能密钥设备中的与该账户信息对应的密码),也可以是对该原始密码进行加密后得到的密文,还可以是对用户选择的账户信息及其对应的信息进行计算得到的动态密码。
如上所述,智能密钥设备中可以预先存储各账户信息以及对应的密码,当用户选择其中的一个账户信息后,智能密钥设备根据该选择的账户信息可以获取对应的密码。例如,用户选择银行卡号后,智能密钥设备可以从预先存储的用户数据中获取与银行卡号对应的密码。之后,在具体实施时,可以将获取的密码确定为第一密码,此时是采用明文的密码;或者,可以对获取的密码进行处理,得到第一密码,处理可以具体包括加密处理,此时,第一密码是加密后的密码,或者,处理也可以具体是根据获取的密码生成动态密码,此时,第一密码是动态密码。当然,也可以将用户选择的账号信息作为种子密钥,或者,将账号信息和密码一起作为种子密钥,结合动态因子计算得到动态密码。需要说明的是,种子密钥一般为数字,账号信息和/或密码信息中的字母等可以通过ASCII码对照表转换为数字。
上述以用户数据包括账户信息对应的密码,获取账户信息对应的密码,并根据获取的密码确定第一密码为例。可以理解的是,用户数据除了包括账户信息和对应的密码,还可以包括账户信息对应的网站信息、用户自定义的其他项目信息等,此时,可以将用户选中的账户信息及其对应的信息中至少之一转换为数字,作为计算动态密码使用的种子密钥, 具体内容可以参见后续实施例。
发送模块54设置为将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
其中,当智能密钥设备获取与用户选择的账户信息对应的密码后,可以直接将该密码发送给客户端,或者,对获取的密码进行加密处理后,将加密处理后的密码发送给客户端。或者,根据获取的与用户选择的账户信息对应的一种或多种信息生成动态密码,将该动态密码发送给客户端。
当客户端接收到第一密码后,就可以在输入密码的位置输入所述第一密码,例如,用户在使用网银时,客户端可以将第一密码输入到密码输入位置。之后,客户端可以采用该输入的第一密码进行登录认证,例如,在认证时客户端将密码输入位置的第一密码发送给银行后台,由银行后台进行登录认证,以允许或拒绝用户登录。
一个实施例中,所述发送模块54具体设置为:采用USB方式将所述第一密码发送给客户端;或者,采用音码方式将所述第一密码发送给客户端;或者,采用无线方式将所述第一密码发送给客户端。
本实施例通过根据预先存储的用户数据得到第一密码并发送给客户端,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,根据预先存储的信息生成客户端输入的密码,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。另外,本实施例的智能密钥设备可以通过多种方式与客户端通信,可以提高适用范围。
图6为本发明另一实施例提出的智能密钥设备的结构示意图,本实施例中,所述第一密码为对所述获取的密码进行处理后得到的密码时,该智能密钥设备50在图5所示的实施例的基础上,确定模块53包括第一单元531和第二单元532。
第一单元531设置为根据所述用户选择的账户信息,从预先存储的用户数据中获取与所述用户选择的账户信息对应的密码,其中,所述用户数据至少包括账户信息以及与所述账户信息对应的密码,当然,还可以包括网站信息、用户自定义的其他需要存储的项目信息等;
第二单元532设置为将所述获取的密码确定为所述第一密码,或者,对所述获取的密码进行加密处理,得到所述第一密码。
其中,可选的,可以是接收到用户的确认信息后对获取的密码进行加密处理。以智能密钥设备是USB key为例,例如,USB key获取密码后,可以向用户显示是否确认加密,如果用户点击了确认键,那么就会获取的密码进行加密处理,否则不进行加密处理。
为了使得银行后台可以正确解密,USB key进行加密处理时采用的加密算法是与银行后 台预先约定的算法,之后银行采用该约定算法进行解密。
在另一实施例中,所述确定模块53包括:第三单元,设置为根据所述用户选择的账户信息,从预先存储的用户数据中获取所述用户选择的账户信息以及与所述用户选择的账户信息对应的信息中的一种或多种,其中,所述用户数据至少包括账户信息以及与所述账户信息对应的密码,当然,还可以包括网站信息、用户自定义的其他需要存储的项目信息等;第四单元,设置为采用动态密码计算算法,对所述获取的信息进行计算得到动态密码,将所述动态密码确定为所述第一密码。
另一个实施例中,该智能密钥设备还可以包括:第一存储模块,设置为存储所述智能密钥设备的私钥和数字证书;第二存储模块55,设置为存储所述用户数据;收发模块,设置为接收用户输入的操作指令和所述用户数据;访问控制模块,设置为对所述用户进行身份验证,并在所述用户通过身份验证之后,将所述第二存储模块的写权限开放给所述用户,以及将所述用户数据写入至所述第二存储模块;以及安全芯片,设置为进行数字签名的生成和认证,以及加密和解密。
一个实施例中,所述第二存储模块55存储的用户数据中,不同账户信息对应的密码不相关。
此外,所述智能密钥设备还包括:激活控制模块,设置为接收所述用户在所述智能密钥设备上输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能;或者,接收所述用户通过所述客户端发送的激活请求和所述用户通过所述客户端输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能,其中,所述信息存储功能用于实现将所述用户数据写入至所述智能密钥设备。
智能密钥设备还可以包括:开启模块,设置为接收所述用户输入的开启指令,并根据所述开启指令启用所述智能密钥设备的信息存储功能。
收发模块可以通过所述智能密钥设备提供的操作界面及控制按钮接收所述操作指令和所述用户数据;或者,通过通信接口接收外部设备发送的所述操作指令和所述用户数据。
此外,所述收发模块接收所述用户通过所述客户端发送的对所述智能密钥设备的验证请求和随机数,所述安全芯片根据所述智能密钥设备的私钥对所述随机数进行加密,以及所述收发模块根据所述验证请求将所述智能密钥设备的数字证书和加密后的随机数发送至所述客户端;其中,所述客户端根据根证书对所述智能密钥设备的数字证书进行验证,并根据所述智能密钥设备的公钥对所述加密后的随机数进行解密,以及对解密后的随机数进行验证。可以验证智能密钥设备的身份,保证其可靠性。
所述显示模块,还设置为在所述收发模块接收所述用户输入的操作指令和所述用户数 据之后,显示所述用户数据,以及所述访问控制模块在所述收发模块接收到所述用户对显示出的所述用户数据的确认指令之后,将所述用户数据写入所述第二存储模块。确保用户存储的数据的正确性。
此外,所述收发模块接收客户端发送的用户数据密文,所述安全芯片根据所述智能密钥设备的私钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端根据所述智能密钥设备的公钥对所述用户数据加密以生成所述用户数据密文;或者,所述收发模块接收客户端发送的会话密钥密文和用户数据密文,所述安全芯片根据所述智能密钥设备的私钥对所述会话密钥密文解密以获取会话密钥,并根据所述会话密钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端随机生成会话密钥,并根据所述智能密钥设备的公钥对所述会话密钥加密以生成所述会话密钥密文,以及根据所述会话密钥对所述用户数据加密以生成所述用户数据密文。保证用户数据在传输时的安全性。
需要说明的是,智能密钥设备的模块划分并不限于本实施例所示,例如,可以设置收发模块,实现接收密码输出请求、向客户端发送第一密码以及接收操作指令和银行数据的功能。
本实施例通过从预先存储的用户数据中获取密码,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,将密码进行预先存储,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。另外,本实施例的智能密钥设备可以通过多种方式与客户端通信,可以提高适用范围。另外,本实施例通过预先存储密码,可以将不同账户对应的密码设置为不相关,因此可以避免众多密码相关时产生的破解一个账户的密码就威胁其他账户密码的问题,提高各账户密码的安全性。本实施例通过对获取的密码进行加密处理,可以保证密码传输时的安全性。或者,本实施例通过根据获取的密码生成动态密码,对动态密码进行认证,可以降低密码被盗风险,保证用户账户安全。或者,本实施例对获取的网站信息进行运算生成动态密码,可以保证动态密码生成方式的多样性,提高适用范围。
图7为本发明另一实施例提出的客户端装置的结构示意图,该装置70包括发送模块71、接收模块72和输入模块73。其中,客户端装置可以为PC、手机或者平板电脑等。
发送模块71设置为向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码。
客户端装置可以是在接收到密码认证方发送的登录密码输入请求后,发送的该密码输 出请求,密码认证方例如银行后台、第三方支付平台或者邮箱认证平台等。对于智能密钥设备接收到密码输出请求后执行的流程可以具体参见其他实施例中关于智能密钥设备侧的描述,在此不再赘述。
接收模块72设置为接收所述智能密钥设备发送的所述第一密码。可选的,所述接收模块72具体设置为:接收所述智能密钥设备采用USB方式发送的第一密码;或者,接收所述智能密钥设备采用音码方式发送的第一密码;或者,接收所述智能密钥设备采用无线方式发送的第一密码。
输入模块73设置为输入所述第一密码。例如,客户端装置将该密码输入到登录时所需输入密码的位置。之后,客户端装置还可以将该第一密码发送给银行后台等认证方进行密码认证,以允许或拒绝用户登录。
本实施例通过指示智能密钥设备输出密码,并且将智能密钥设备发送的第一密码输入,可以实现密码的自动输入,无需用户输入,可以方便用户操作。
本发明实施例还提供了一种客户端设备,该客户端设备包括壳体、处理器、存储器、电路板和电源电路,其中,电路板安置在壳体围成的空间内部,处理器和存储器设置在电路板上;电源电路,用于为客户端设备的各个电路或器件供电;存储器用于存储可执行程序代码;处理器通过读取存储器中存储的可执行程序代码来运行与可执行程序代码对应的程序,以用于执行以下步骤S21’-步骤S23’。
S21’:向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码。其中,客户端设备例如为PC、手机或者平板电脑等。
客户端设备可以是在接收到密码认证方发送的登录密码输入请求后,发送的该密码输出请求,密码认证方例如银行后台、第三方支付平台或者邮箱认证平台等。对于智能密钥设备接收到密码输出请求后执行的流程可以具体参见其他实施例中关于智能密钥设备侧的描述,在此不再赘述。
S22’:接收所述智能密钥设备发送的所述第一密码。可选的,所述接收所述智能密钥设备发送的第一密码,包括:接收所述智能密钥设备采用USB方式发送的第一密码;或者,接收所述智能密钥设备采用音码方式发送的第一密码;或者,接收所述智能密钥设备采用无线方式发送的第一密码。
S23’:输入所述第一密码。例如,客户端设备将该密码输入到登录时所需输入密码的位置。
之后,客户端设备还可以将该第一密码发送给银行后台等认证方进行密码认证,以允许或拒绝用户登录。
本实施例通过指示智能密钥设备输出密码,并且将智能密钥设备发送的第一密码输入,可以实现密码的自动输入,无需用户输入,可以方便用户操作。
本发明实施例还提供了一种智能密钥设备,包括:一个或者多个处理器;存储器;一个或者多个程序,一个或者多个程序存储在存储器中,当被一个或者多个处理器执行时进行如下步骤S11’-步骤S14’的操作。
S11’:接收客户端发送的密码输出请求。
S12’:根据密码输出请求,显示与智能密钥设备中预先存储的用户数据对应的条目列表,其中,用户数据包括账户信息和对应的密码。
S13’:确定用户在条目列表中选择的账户信息,并根据用户选择的账户信息确定第一密码,其中,第一密码为用于登录认证的密码。
S14’:将第一密码发送给客户端,以便客户端输入第一密码。
本实施例通过根据预先存储的用户数据得到第一密码并发送给客户端,使得客户端输入从智能密钥设备接收的密码,不需要用户手动输入,可以方便用户操作,并且,根据预先存储的用户数据生成客户端输入的密码,也不需要用户记忆密码,避免账户众多时用户难以记忆的问题。
需要说明的是,在本发明的描述中,术语“第一”、“第二”等仅用于描述目的,而不能理解为指示或暗示相对重要性。此外,在本发明的描述中,除非另有说明,“多个”的含义是两个或两个以上。
流程图中或在此以其他方式描述的任何过程或方法描述可以被理解为,表示包括一个或更多个用于实现特定逻辑功能或过程的步骤的可执行指令的代码的模块、片段或部分,并且本发明的优选实施方式的范围包括另外的实现,其中可以不按所示出或讨论的顺序,包括根据所涉及的功能按基本同时的方式或按相反的顺序,来执行功能,这应被本发明的实施例所属技术领域的技术人员所理解。
应当理解,本发明的各部分可以用硬件、软件、固件或它们的组合来实现。在上述实施方式中,多个步骤或方法可以用存储在存储器中且由合适的指令执行系统执行的软件或固件来实现。例如,如果用硬件来实现,和在另一实施方式中一样,可用本领域公知的下列技术中的任一项或他们的组合来实现:具有用于对数据信号实现逻辑功能的逻辑门电路的离散逻辑电路,具有合适的组合逻辑门电路的专用集成电路,可编程门阵列(PGA),现场可编程门阵列(FPGA)等。
本技术领域的普通技术人员可以理解实现上述实施例方法携带的全部或部分步骤是可 以通过程序来指令相关的硬件完成,所述的程序可以存储于一种计算机可读存储介质中,该程序在执行时,包括方法实施例的步骤之一或其组合。
此外,在本发明各个实施例中的各功能单元可以集成在一个处理模块中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。所述集成的模块如果以软件功能模块的形式实现并作为独立的产品销售或使用时,也可以存储在一个计算机可读取存储介质中。
上述提到的存储介质可以是只读存储器,磁盘或光盘等。
在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本发明的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不一定指的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任何的一个或多个实施例或示例中以合适的方式结合。
尽管上面已经示出和描述了本发明的实施例,可以理解的是,上述实施例是示例性的,不能理解为对本发明的限制,本领域的普通技术人员在本发明的范围内可以对上述实施例进行变化、修改、替换和变型。

Claims (18)

  1. 一种通过智能密钥设备进行客户端密码输入的方法,其特征在于,包括:
    智能密钥设备接收客户端发送的密码输出请求;
    所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,其中,所述用户数据包括账户信息和对应的密码;
    所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码;
    所述智能密钥设备将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
  2. 根据权利要求1所述的方法,其特征在于,所述根据所述用户选择的账户信息确定第一密码,包括:
    根据所述用户选择的账户信息,从所述用户数据中获取与所述用户选择的账户信息对应的密码;将所述获取的密码确定为所述第一密码,或者对所述获取的密码进行加密处理,得到所述第一密码;
    或者,
    根据所述用户选择的账户信息,从所述用户数据中获取所述用户选择的账户信息以及与所述用户选择的账户信息对应的信息中的一种或多种;采用动态密码计算算法,对所述获取的信息进行计算得到动态密码,将所述动态密码确定为所述第一密码。
  3. 根据权利要求1或2所述的方法,其特征在于,在所述显示与所述智能密钥设备中预先存储的用户数据对应的条目列表之前,所述方法还包括:
    所述智能密钥设备存储所述用户数据。
  4. 根据权利要求3所述的方法,其特征在于,所述智能密钥设备存储所述用户数据,包括:
    所述智能密钥设备接收所述用户输入的操作指令和所述用户数据;
    所述智能密钥设备对所述用户进行身份验证,并在所述用户通过身份验证之后,将所述智能密钥设备的写权限开放给所述用户;
    将所述用户数据写入至所述智能密钥设备。
  5. 根据权利要求4所述的方法,其特征在于,在所述智能密钥设备接收用户输入的操作指令和所述用户数据之前,所述方法还包括:
    接收所述用户在所述智能密钥设备上输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能;或者,接收所述 用户通过所述客户端发送的激活请求和所述用户通过所述客户端输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能,其中,所述信息存储功能用于实现将所述用户数据写入至所述智能密钥设备;以及
    接收所述用户输入的开启指令,并根据所述开启指令启用所述智能密钥设备的信息存储功能。
  6. 根据权利要求4所述的方法,其特征在于,所述智能密钥设备接收用户输入的操作指令和所述用户数据具体包括:
    通过所述智能密钥设备提供的操作界面及控制按钮接收所述操作指令和所述用户数据;或者
    通过通信接口接收外部设备发送的所述操作指令和所述用户数据。
  7. 根据权利要求4所述的方法,其特征在于,在将所述用户数据写入至所述智能密钥设备之前,所述方法还包括:
    所述智能密钥设备接收所述用户通过所述客户端发送的对所述智能密钥设备的验证请求和随机数,并根据所述智能密钥设备的私钥对所述随机数进行加密,以及根据所述验证请求将所述智能密钥设备的数字证书和加密后的随机数发送至所述客户端;
    所述客户端根据根证书对所述智能密钥设备的数字证书进行验证,并根据所述智能密钥设备的公钥对所述加密后的随机数进行解密,以及对解密后的随机数进行验证;
    在验证所述数字证书和所述随机数通过后,显示所述用户数据;
    所述将所述用户数据写入至所述智能密钥设备具体为:在接收到所述用户对显示出的所述用户数据的确认指令之后,所述智能密钥设备存储所述用户数据。
  8. 根据权利要求4所述的方法,其特征在于,所述智能密钥设备接收用户输入的操作指令和所述用户数据具体包括:
    所述智能密钥设备接收所述客户端发送的用户数据密文,并根据所述智能密钥设备的私钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端根据所述智能密钥设备的公钥对所述用户数据加密以生成所述用户数据密文;或者,
    所述智能密钥设备接收所述客户端发送的会话密钥密文和用户数据密文,并根据所述智能密钥设备的私钥对所述会话密钥密文解密以获取会话密钥,以及根据所述会话密钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端随机生成会话密钥,并根据所述智能密钥设备的公钥对所述会话密钥加密以生成所述会话密钥密文,以及根据所述会话密钥对所述用户数据加密以生成所述用户数据密文。
  9. 一种通过智能密钥设备进行客户端密码输入的方法,其特征在于,包括:
    客户端向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码;
    所述客户端接收所述智能密钥设备发送的所述第一密码;
    所述客户端输入所述第一密码。
  10. 一种智能密钥设备,其特征在于,包括:
    接收模块,设置为接收客户端发送的密码输出请求;
    显示模块,设置为根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,其中,所述用户数据包括账户信息和对应的密码;
    确定模块,设置为确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述第一密码为用于登录认证的密码;
    发送模块,设置为将所述第一密码发送给所述客户端,以便所述客户端输入所述第一密码。
  11. 根据权利要求10所述的智能密钥设备,其特征在于,所述确定模块包括:
    第一单元,设置为根据所述用户选择的账户信息,从所述用户数据中获取与所述用户选择的账户信息对应的密码;
    第二单元,设置为将所述获取的密码确定为所述第一密码,或者,对所述获取的密码进行加密处理,得到所述第一密码。
  12. 根据权利要求10所述的智能密钥设备,其特征在于,所述确定模块包括:
    第三单元,设置为根据所述用户选择的账户信息,从所述用户数据中获取所述用户选择的账户信息以及与所述用户选择的账户信息对应的信息中的一种或多种;
    第四单元,设置为采用动态密码计算算法,对所述获取的信息进行计算得到动态密码,将所述动态密码确定为所述第一密码。
  13. 根据权利要求10至12任一项所述的智能密钥设备,其特征在于,所述智能密钥设备还包括:
    第一存储模块,设置为存储所述智能密钥设备的私钥和数字证书;
    第二存储模块,设置为存储所述用户数据;
    收发模块,设置为接收用户输入的操作指令和所述用户数据;
    访问控制模块,设置为对所述用户进行身份验证,并在所述用户通过身份验证之后,将所述第二存储模块的写权限开放给所述用户,以及将所述用户数据写入至所述 第二存储模块;以及
    安全芯片,设置为进行数字签名的生成和认证,以及加密和解密。
  14. 根据权利要求13所述的智能密钥设备,其特征在于,所述智能密钥设备还包括:
    激活控制模块,设置为接收所述用户在所述智能密钥设备上输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能;或者,接收所述用户通过所述客户端发送的激活请求和所述用户通过所述客户端输入的激活码,并对所述激活码进行激活验证,以及在激活验证通过后激活所述智能密钥设备的信息存储功能,其中,所述信息存储功能用于实现将所述用户数据写入至所述智能密钥设备;
    开启模块,设置为接收所述用户输入的开启指令,并根据所述开启指令启用所述智能密钥设备的信息存储功能。
  15. 根据权利要求13所述的智能密钥设备,其特征在于,所述收发模块通过所述智能密钥设备提供的操作界面及控制按钮接收所述操作指令和所述用户数据;或者,通过通信接口接收外部设备发送的所述操作指令和所述用户数据。
  16. 根据权利要求13所述的智能密钥设备,其特征在于,所述收发模块接收所述用户通过所述客户端发送的对所述智能密钥设备的验证请求和随机数,所述安全芯片根据所述智能密钥设备的私钥对所述随机数进行加密,以及所述收发模块根据所述验证请求将所述智能密钥设备的数字证书和加密后的随机数发送至所述客户端;其中,所述客户端根据根证书对所述智能密钥设备的数字证书进行验证,并根据所述智能密钥设备的公钥对所述加密后的随机数进行解密,以及对解密后的随机数进行验证;
    所述显示模块,还设置为在所述收发模块接收所述用户输入的操作指令和所述用户数据之后,显示所述用户数据,以及所述访问控制模块在所述收发模块接收到所述用户对显示出的所述用户数据的确认指令之后,将所述用户数据写入所述第二存储模块。
  17. 根据权利要求13所述的智能密钥设备,其特征在于,所述收发模块接收客户端发送的用户数据密文,所述安全芯片根据所述智能密钥设备的私钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端根据所述智能密钥设备的公钥对所述用户数据加密以生成所述用户数据密文;或者,
    所述收发模块接收客户端发送的会话密钥密文和用户数据密文,所述安全芯片根据所述智能密钥设备的私钥对所述会话密钥密文解密以获取会话密钥,并根据所述会话密钥对所述用户数据密文解密以获取所述用户数据,其中,所述客户端随机生成会 话密钥,并根据所述智能密钥设备的公钥对所述会话密钥加密以生成所述会话密钥密文,以及根据所述会话密钥对所述用户数据加密以生成所述用户数据密文。
  18. 一种客户端装置,其特征在于,包括:
    发送模块,设置为向智能密钥设备发送密码输出请求,以便所述智能密钥设备根据所述密码输出请求,显示与所述智能密钥设备中预先存储的用户数据对应的条目列表,以及使得所述智能密钥设备确定用户在所述条目列表中选择的账户信息,并根据所述用户选择的账户信息确定第一密码,其中,所述用户数据包括账户信息和对应的密码,所述第一密码为用于登录认证的密码;
    接收模块,设置为接收所述智能密钥设备发送的所述第一密码;
    输入模块,设置为输入所述第一密码。
PCT/CN2015/071852 2014-04-02 2015-01-29 密码输入方法、智能密钥设备以及客户端装置 WO2015149582A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410132586.7 2014-04-02
CN201410132586.7A CN103929307B (zh) 2014-04-02 2014-04-02 密码输入方法、智能密钥设备以及客户端装置

Publications (1)

Publication Number Publication Date
WO2015149582A1 true WO2015149582A1 (zh) 2015-10-08

Family

ID=51147392

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/071852 WO2015149582A1 (zh) 2014-04-02 2015-01-29 密码输入方法、智能密钥设备以及客户端装置

Country Status (2)

Country Link
CN (1) CN103929307B (zh)
WO (1) WO2015149582A1 (zh)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106789848A (zh) * 2015-11-23 2017-05-31 阿里巴巴集团控股有限公司 一种用户密钥存储方法及服务器
CN107896221A (zh) * 2017-12-01 2018-04-10 北京深思数盾科技股份有限公司 一种账户绑定方法及装置
CN108549808A (zh) * 2018-04-19 2018-09-18 北京华大智宝电子系统有限公司 一种密码管理方法和装置
CN109889342A (zh) * 2018-12-15 2019-06-14 中国平安人寿保险股份有限公司 接口测试鉴权方法、装置、电子设备及存储介质
CN110247758A (zh) * 2019-05-30 2019-09-17 世纪龙信息网络有限责任公司 密码管理的方法、装置及密码管理器
CN111615105A (zh) * 2016-07-18 2020-09-01 阿里巴巴集团控股有限公司 信息提供、获取方法、装置及终端
CN113472793A (zh) * 2021-07-01 2021-10-01 中易通科技股份有限公司 一种基于硬件密码设备的个人数据保护系统

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103929307B (zh) * 2014-04-02 2018-06-01 天地融科技股份有限公司 密码输入方法、智能密钥设备以及客户端装置
CN107026737B (zh) * 2016-01-29 2021-02-09 李明 一种通过可穿戴设备进行密码管理的系统
CN106126149A (zh) * 2016-06-30 2016-11-16 联想(北京)有限公司 一种信息处理的方法、电子设备及输入装置
CN106533683A (zh) * 2016-11-11 2017-03-22 西安远眺网络科技有限公司 一种采用国家商用密码算法的设备认证方法
CN108476140B (zh) * 2016-11-26 2021-04-20 华为技术有限公司 一种安全控制智能家居的方法及终端设备
CN108092764B (zh) * 2017-11-02 2021-06-15 捷开通讯(深圳)有限公司 一种密码管理方法、设备和具有存储功能的装置
CN110581829A (zh) * 2018-06-08 2019-12-17 中国移动通信集团有限公司 通信方法及装置
CN109214147A (zh) * 2018-09-28 2019-01-15 内蒙古师范大学 一种会计软件的加密系统
CN110399717B (zh) * 2018-11-21 2023-03-14 腾讯科技(深圳)有限公司 密钥获取方法和装置、存储介质及电子装置
CN110430043B (zh) * 2019-07-05 2022-11-08 视联动力信息技术股份有限公司 一种认证方法、系统及装置和存储介质
CN110704254A (zh) * 2019-09-03 2020-01-17 福建升腾资讯有限公司 一种低成本自动化测试pos交易的按键控制器、方法和系统
CN112039901B (zh) * 2020-09-02 2023-06-13 联仁健康医疗大数据科技股份有限公司 一种数据传输的方法、装置及系统
CN112685698A (zh) * 2020-12-07 2021-04-20 湖南麒麟信安科技股份有限公司 一种基于USB Key的软件授权方法及系统
CN113132369A (zh) * 2021-04-12 2021-07-16 西安赤鸾信息科技有限公司 一种Android手机密码自动填充方法及装置
CN114553409B (zh) * 2022-02-24 2023-08-08 广东电网有限责任公司 密码验证方法、系统、设备、存储介质及程序产品

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008282096A (ja) * 2007-05-08 2008-11-20 Winbond Electron Corp アカウント・パスワード出力装置
CN102932341A (zh) * 2012-10-25 2013-02-13 北京小米科技有限责任公司 一种密码处理方法、装置及设备
CN102970299A (zh) * 2012-11-27 2013-03-13 西安电子科技大学 文件安全保护系统及其方法
CN103023875A (zh) * 2012-11-21 2013-04-03 北京荣之联科技股份有限公司 一种账户管理系统及方法
CN103929306A (zh) * 2014-04-02 2014-07-16 天地融科技股份有限公司 智能密钥设备和智能密钥设备的信息管理方法
CN103929307A (zh) * 2014-04-02 2014-07-16 天地融科技股份有限公司 密码输入方法、智能密钥设备以及客户端装置

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2110774A4 (en) * 2007-02-07 2010-08-11 Nippon Telegraph & Telephone CLIENT DEVICE, KEY DEVICE, DEVICE FOR PROVIDING A SERVICE, USER AUTHENTICATION SYSTEM, USER AUTHENTICATION PROCESS, PROGRAM AND RECORDING MEDIUM
CN101895513A (zh) * 2009-05-20 2010-11-24 广州盛华信息技术有限公司 服务网站登录认证系统及实现方法
CN101697537A (zh) * 2009-10-20 2010-04-21 宇龙计算机通信科技(深圳)有限公司 一种互联网的访问方法、系统及移动终端
CN201717885U (zh) * 2010-03-12 2011-01-19 薛明 密码提供设备和密码认证系统
CN103336746A (zh) * 2013-06-19 2013-10-02 江苏意源科技有限公司 一种安全加密u盘及其数据加密方法

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008282096A (ja) * 2007-05-08 2008-11-20 Winbond Electron Corp アカウント・パスワード出力装置
CN102932341A (zh) * 2012-10-25 2013-02-13 北京小米科技有限责任公司 一种密码处理方法、装置及设备
CN103023875A (zh) * 2012-11-21 2013-04-03 北京荣之联科技股份有限公司 一种账户管理系统及方法
CN102970299A (zh) * 2012-11-27 2013-03-13 西安电子科技大学 文件安全保护系统及其方法
CN103929306A (zh) * 2014-04-02 2014-07-16 天地融科技股份有限公司 智能密钥设备和智能密钥设备的信息管理方法
CN103929307A (zh) * 2014-04-02 2014-07-16 天地融科技股份有限公司 密码输入方法、智能密钥设备以及客户端装置

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106789848A (zh) * 2015-11-23 2017-05-31 阿里巴巴集团控股有限公司 一种用户密钥存储方法及服务器
WO2017088677A1 (zh) * 2015-11-23 2017-06-01 阿里巴巴集团控股有限公司 一种用户密钥存储方法及服务器
CN111615105A (zh) * 2016-07-18 2020-09-01 阿里巴巴集团控股有限公司 信息提供、获取方法、装置及终端
CN111615105B (zh) * 2016-07-18 2023-08-04 创新先进技术有限公司 信息提供、获取方法、装置及终端
CN107896221A (zh) * 2017-12-01 2018-04-10 北京深思数盾科技股份有限公司 一种账户绑定方法及装置
CN107896221B (zh) * 2017-12-01 2019-11-12 北京深思数盾科技股份有限公司 一种账户绑定方法及装置
CN108549808A (zh) * 2018-04-19 2018-09-18 北京华大智宝电子系统有限公司 一种密码管理方法和装置
CN109889342A (zh) * 2018-12-15 2019-06-14 中国平安人寿保险股份有限公司 接口测试鉴权方法、装置、电子设备及存储介质
CN110247758A (zh) * 2019-05-30 2019-09-17 世纪龙信息网络有限责任公司 密码管理的方法、装置及密码管理器
CN110247758B (zh) * 2019-05-30 2023-03-24 天翼数字生活科技有限公司 密码管理的方法、装置及密码管理器
CN113472793A (zh) * 2021-07-01 2021-10-01 中易通科技股份有限公司 一种基于硬件密码设备的个人数据保护系统
CN113472793B (zh) * 2021-07-01 2023-04-28 中易通科技股份有限公司 一种基于硬件密码设备的个人数据保护系统

Also Published As

Publication number Publication date
CN103929307B (zh) 2018-06-01
CN103929307A (zh) 2014-07-16

Similar Documents

Publication Publication Date Title
WO2015149582A1 (zh) 密码输入方法、智能密钥设备以及客户端装置
US10904234B2 (en) Systems and methods of device based customer authentication and authorization
US20210350013A1 (en) Security systems and methods for continuous authorized access to restricted access locations
JP6701364B2 (ja) パスワードなしのコンピュータログインのサービス支援モバイルペアリングのためのシステム及び方法
US8769612B2 (en) Portable device association
CN108809659B (zh) 动态口令的生成、验证方法及系统、动态口令系统
JP6399382B2 (ja) 認証システム
EP2316097B1 (en) Protocol for device to station association
JP6691262B2 (ja) グラフィックコード情報を提供及び取得する方法及び装置並びに端末
US10848304B2 (en) Public-private key pair protected password manager
US20130205380A1 (en) Identity verification
US10645077B2 (en) System and method for securing offline usage of a certificate by OTP system
CN103929306A (zh) 智能密钥设备和智能密钥设备的信息管理方法
CN103905188A (zh) 利用智能密钥设备生成动态口令的方法和智能密钥设备
KR20170124953A (ko) 암호화된 otp를 모바일폰에서 지문 등을 이용하여 복호화하여 사용자 인증을 자동화하는 방법과 그 시스템
WO2017050152A1 (zh) 用于移动设备的密码安全系统及其密码安全输入方法
KR101570773B1 (ko) 모바일 기기를 사용한 인터넷 서비스의 클라우드 인증 방법
KR102171377B1 (ko) 로그인 제어 방법
US11968202B2 (en) Secure authentication in adverse environments
KR20110078960A (ko) 휴대형 저장매체를 이용한 인증시스템 및 방법, 그 단말기, 인증서버 및 휴대형 저장매체
Eleftherios FIDO2 Overview, Use Cases, and Security Considerations
Georgi Visual approach for secure transfer of user credentials
CN117176357A (zh) 一种基于智能密码钥匙的多因子认证加密存储方法及系统
JP2013061881A (ja) 画像表示システム、画像表示装置、及びパスワード生成装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15773528

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase
122 Ep: pct application non-entry in european phase

Ref document number: 15773528

Country of ref document: EP

Kind code of ref document: A1