WO2016106973A1 - 密码验证方法及装置 - Google Patents

密码验证方法及装置 Download PDF

Info

Publication number
WO2016106973A1
WO2016106973A1 PCT/CN2015/073910 CN2015073910W WO2016106973A1 WO 2016106973 A1 WO2016106973 A1 WO 2016106973A1 CN 2015073910 W CN2015073910 W CN 2015073910W WO 2016106973 A1 WO2016106973 A1 WO 2016106973A1
Authority
WO
WIPO (PCT)
Prior art keywords
verification
usage information
user
historical usage
password
Prior art date
Application number
PCT/CN2015/073910
Other languages
English (en)
French (fr)
Inventor
郭守朋
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016106973A1 publication Critical patent/WO2016106973A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials

Definitions

  • the present invention relates to the field of electronic devices, and in particular to a method and device for verifying a password.
  • Electronic devices carry more and more information, for example, contact information, payment information, etc. are related to user privacy or property security. Therefore, the security of electronic devices has become an important issue.
  • the electronic device is encrypted by using a digital password, a pattern password, or the like to improve the security of the electronic device.
  • a digital password e.g., a password e.g., a password e.g., a password e.g., a password e.g., a password e.g., a password e.g., a pattern password, or the like.
  • Jiugongge is used as a pattern lock screen solution.
  • the method of recovering a password after a password is lost often requires a complicated process. Either you need to use the network, or use other mobile devices/web servers, or you need to remember the answers to the default questions.
  • the present invention provides a password verification method and apparatus to solve at least the complexity of the prior art password verification process.
  • a password verification method comprising: acquiring historical usage information of a pre-recorded verification object; and performing password verification based on the historical usage information.
  • performing password verification according to the historical usage information includes: prompting the user to verify the problem according to the historical usage information; and determining whether to pass the password verification according to the input of the verification question by the user.
  • determining whether to pass the password verification according to the input of the verification question by the user comprises: determining a degree of matching of the input of the verification question by the user with the verification question; and accumulating the verification points according to the matching degree, wherein
  • the verification integral is set with a preset initial value; determining whether the verification credit is greater than or equal to a preset integral value; if the verification credit is less than the preset integral value, continuing to prompt the user to verify the problem according to the historical usage information, according to the user's current verification
  • the matching of the problem input and the current verification problem is cumulatively verified until the current verification score is greater than or equal to the preset integral value or the password verification is stopped; if the verification credit is greater than or equal to the preset integral value, it is determined by the password verification.
  • accumulating the verification points according to the matching degree includes: accumulating the verification points according to the matching degree and the attribute of the historical usage information corresponding to the verification problem, wherein the attribute of the historical usage information includes at least one of the following: security of historical usage information Level, complexity, and time when the password is verified.
  • the prompting the verification question to the user according to the historical usage information includes: prompting the user with the first verification question and the second verification question according to the historical usage information, wherein the first verification problem is related to the historical usage information, and the second verification problem Not related to historical usage information. Determining whether to pass the password verification according to the user's input of the verification question, including: when the second input is incorrect, determining that the password verification is not passed; when the first input meets the first preset condition and the second input is correct, determining to pass the password verification .
  • the prompting the verification question to the user according to the historical usage information includes: prompting the user for the classification of the at least one historical usage information; and responding to the user's selection of the at least one classification, prompting the user according to the historical usage information corresponding to the selected classification. At least one verification question.
  • the verification object includes an electronic device; and the classification of the historical usage information includes at least one of the following: classifying according to the software in the electronic device, classifying according to the operation type in the electronic device, or classifying according to the information type.
  • the prompting the user to the verification problem according to the historical usage information includes: prompting, according to the historical usage information, the corresponding number of verification questions to the user according to the historical usage information, wherein the attribute of the historical usage information includes at least the following One: the security level of the historical usage information, the complexity, and the time when the password is verified; whether the password is verified according to the input of the verification question by the user, including: determining whether the user input of the corresponding number of verification questions satisfies the first The second preset condition determines that the password verification is performed when the second preset condition is met.
  • the input of the corresponding number of verification questions by the user satisfies the second preset condition, including one of: determining a verification question that the input matches the verification question, and weighting the historical usage information corresponding to the verification question according to the matching
  • the value determines the verification score, determines whether the verification verification point is greater than or equal to the preset integration value; or determines whether the number of the above-mentioned input matching the corresponding verification question is greater than or equal to a preset number;
  • the historical usage information includes: usage information within a period of time closest to performing password verification.
  • a password verification apparatus including: an acquisition module configured to acquire historical usage information of a pre-recorded verification object; and a verification module configured to perform password verification according to the historical usage information.
  • the verification module includes: a prompting unit, configured to prompt the user to verify the problem according to the historical usage information; and the determining unit is configured to determine whether to pass the password verification according to the input of the verification question by the user.
  • the verification module further includes: a determining unit configured to determine a degree of matching between the input of the verification question and the verification question by the user; and an accumulating unit configured to accumulate the verification points according to the matching degree, wherein the verification point setting has a preset Initial value.
  • the determining unit is configured to determine whether the verification credit is greater than or equal to a preset integration value; and when the verification credit is less than the preset integration value, cause the prompting unit to continue to prompt the user to verify the problem according to the historical usage information until the current verification The score is greater than or equal to the preset integral value or the password verification stops.
  • the accumulating unit is configured to accumulate the verification points according to the matching degree and the attribute of the historical usage information corresponding to the verification problem, wherein the attribute of the historical usage information includes at least one of the following: a security level of the historical usage information, and a complexity Degree, the time when the password is verified.
  • the prompting unit is configured to prompt the user with the first verification question and the second verification question according to the historical usage information, wherein the first verification question is related to the historical usage information, and the second verification question is not related to the historical usage information;
  • the judging unit is configured to determine that the password verification is not passed when the second input is incorrect; and to confirm the password verification when the first input satisfies the first preset condition and the second input is correct.
  • the prompting unit is configured to prompt the user for the classification of the at least one historical usage information; and in response to the user selecting the at least one classification, prompting the user with the at least one verification question according to the historical usage information corresponding to the selected classification.
  • the verification object includes an electronic device; and the classification of the historical usage information includes at least one of the following: classifying according to the software in the electronic device, classifying according to the operation type in the electronic device, or classifying according to the information type.
  • the prompting unit is configured to prompt the user with a corresponding number of verification questions according to the historical usage information according to the attribute of the historical usage information, wherein the attribute of the historical usage information includes at least one of the following: The security level, complexity, and time when the password is verified.
  • the determining unit is configured to determine whether the input of the corresponding number of verification questions by the user meets the second preset condition, and when the second preset condition is met, determine to pass the verification.
  • the determining unit is configured to determine a verification question that the input matches the verification question, determine the verification point according to the weight value of the historical usage information corresponding to the matching verification question, and determine whether the verification credit is greater than or equal to the preset integral value; or It is set to determine whether the number of matches in the above input and the corresponding verification question is greater than or equal to a preset number.
  • the verification of the password is performed using the historical usage information of the electronic device, which reduces the complexity of the verification of the password, and does not require the user to memorize a specific verification problem.
  • FIG. 1 is a flowchart of a password verification method according to an embodiment of the present invention.
  • FIG. 2 is a flow chart of an optional password verification method in accordance with an embodiment of the present invention.
  • FIG. 3 is a block diagram showing the structure of a password verification apparatus according to an embodiment of the present invention.
  • FIG. 4 is a structural block diagram of an optional verification module according to an embodiment of the present invention.
  • FIG. 5 is a structural block diagram of another optional verification module according to an embodiment of the present invention.
  • FIG. 6 is a flowchart of a password verification method according to an alternative embodiment 1 of the embodiment of the present invention.
  • FIG. 7 is a flowchart of a password verification method according to an alternative embodiment 2 of the embodiment of the present invention.
  • FIG. 8 is a flowchart of a password verification method according to an alternative embodiment 3 of the embodiment of the present invention.
  • FIG. 9 is a flowchart of a password verification method according to an alternative embodiment 4 of the embodiment of the present invention.
  • FIG. 10 is a flowchart of a password verification method according to an alternative embodiment 5 of the embodiment of the present invention.
  • FIG. 11 is a flowchart of a password verification method according to an alternative embodiment 6 of the embodiment of the present invention.
  • FIG. 12 is a flowchart of a password verification method according to an alternative embodiment 7 of the embodiment of the present invention.
  • FIG. 1 is a flowchart of a password verification method according to an embodiment of the present invention. As shown in FIG. 1, the process includes the following steps:
  • Step S102 acquiring historical usage information of the pre-recorded verification object
  • Step S104 performing password verification based on the historical usage information.
  • the password verification is performed by using the historical usage information of the electronic device, which reduces the complexity of the verification of the password, and does not require the user to memorize the specific verification problem.
  • the verification of the password information may include verification of the password, or password verification such as unlocking.
  • the historical usage information may be recorded in an electronic device or may be recorded in a remote server.
  • a direct advantage of recording in electronic devices is that there is no need to obtain historical usage information over the network when verifying password information.
  • the historical usage information may relate to the privacy of the user, it may be stored by a dedicated security chip.
  • the historical usage information can also be encrypted and stored in the storage device.
  • the historical usage information includes various behavior information of the user on the electronic device, for example, account information that the user logs in on the electronic device, including but not limited to an email account, instant communication, etc., and the account information may be a mailbox, a nickname or other identifier. Information; or, the information of the e-book read by the user, including the name of the e-book, the time of reading the e-book, the page number of the e-book reading, and the like.
  • the embodiment of the present invention is not limited thereto, and any behavior information of the user on the electronic device can be used as information for verification.
  • FIG. 2 is a flowchart of an optional password verification method according to an embodiment of the present invention. As shown in FIG. 2, the foregoing step S104 is performed. Includes the following steps:
  • Step S104a prompting the user to verify the problem according to the historical use information
  • step S104b it is determined whether the password is verified according to the input of the verification question by the user.
  • the verification question may be prompted to the user in a variety of ways, or the user's input may be received in a variety of ways.
  • verification questions may be displayed on the graphical user interface, and/or verification questions may be prompted to the user via voice, other ways are also conceivable, and the above manner is by way of example only.
  • step S104b includes:
  • A determining the degree to which the user's input to the verification question matches the verification question
  • step S104a if the verification credit is less than the preset integral value or the password verification is not stopped, return to step S104a, and continue to prompt the user to verify the question according to the historical usage information; if the verification score is greater than or equal to the preset integral value, determine to pass the password verification. .
  • the degree of matching may include an exact match, a partial match, and a mismatch.
  • the integral value of different matching degrees can be set in advance, for example, the integral value is 50 points for the exact match, the integral value is 30 points for the partial match, and the integral value is 0 or the negative value for the mismatch.
  • Different hint questions can be set with different integral values, for example, setting an integral value higher than a general problem for important questions.
  • the step D accumulating the verification points according to the matching degree may include: accumulating the verification points according to the matching degree and the attribute of the historical usage information corresponding to the verification question, wherein the attributes of the historical usage information include At least one of the following: the security level of the historical usage information, the complexity, and the time when the password is verified. For example, a high security level prompt question sets a higher integration value.
  • the foregoing step S104a may include: prompting the user with the first verification question and the second verification question according to the historical usage information, where the first verification problem is related to the historical usage information, The verification problem is not related to the historical usage information; correspondingly, in the above step S104b, when the second input is incorrect, it is determined that the password verification is not passed; when the first input meets the first preset condition and the second input is correct, the determination is passed. Password validation.
  • the second verification question is not related to the historical usage information, and is used as an interference problem. For example, the music playing record is not recorded in the historical usage information, and a problem of playing the music recently may be prompted, if the user answers the question. If the input is incorrect, it is determined that the password verification failed.
  • interference by irrelevant problems can at least improve the security of the verification.
  • the foregoing step S104a may include: prompting the user for the classification of the at least one historical usage information; and responding to the user's selection of the at least one classification, the historical usage information corresponding to the selected classification. Prompt the user for at least one verification question.
  • the user is prompted for historical usage information to be selected, so that the user can select historical usage information for password verification based on his or her own situation, such as historical usage information that the user can recall.
  • the verification object may include an electronic device, and may also include an account in a general sense, including a mailbox, an instant messaging software, and the like.
  • the classification of the historical usage information includes at least one of the following: according to the software classification in the electronic device, classifying according to the operation type in the electronic device, or classifying according to the information type.
  • the historical usage information may include multiple categories, where the classification may be a classification according to usage behavior, for example, input information, output information, etc., or may be a classification of an operation object according to usage behavior, for example, according to Different application softwares are classified, payment software as a type, instant communication software as a category; or a behavioral information as a classification, for example, e-book reading behavior as a category, the historical usage information can be Including e-book reading time, e-book name, etc. It should be noted that the embodiments of the present invention are not limited thereto.
  • the user is prompted for verifiable historical usage information including e-book reading information, e-mail login information, telephone call information, and SMS content information, and the like, for the user to select the information he remembers according to the memory condition for verification.
  • the user may be prompted with at least one verification question according to the historical usage information corresponding to the classification selected by the user, for example, “What is the name of the e-book that was last read” and the like.
  • the presentation of the problem is different. For example, for the classification according to the behavior, if it is an input behavior, it can prompt "what is the login account of the last used instant messaging software", "what is the login account of the last used mailbox", and "the last input SMS content” What is it?"
  • the prompting the user to the verification question according to the historical usage information may include: prompting the user according to the attribute of the historical usage information according to the historical usage information.
  • determining whether the input of the corresponding number of verification questions by the user meets the second preset condition including one of: determining a verification problem that the input matches the verification question, according to the foregoing matching
  • the verification value corresponding to the historical usage information determines the verification score, determines whether the verification integration is greater than or equal to the preset integration value; or determines whether the number of the matching input corresponding to the verification question is greater than or equal to a preset number;
  • the historical usage information includes: usage information within a period of time closest to performing password verification.
  • a password verification device is further provided, which is used to implement the above-mentioned embodiments and preferred embodiments, and has not been described again.
  • the term “module” may implement a combination of software and/or hardware of a predetermined function.
  • the apparatus described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware, is also possible and contemplated.
  • the apparatus includes: an acquisition module 1 configured to acquire historical usage information of a pre-recorded verification object; a verification module 2, and an acquisition module 1 is connected, and is set to perform password verification based on the above historical usage information.
  • the verification module 2 includes: a prompting unit 20 configured to prompt a verification problem to the user according to the historical usage information; and the determining unit 22 is configured to The user judges whether the input of the above verification question is verified by the password.
  • the verification module 2 includes, in addition to the unit shown in FIG. 4, a determining unit 24 configured to determine a user input to the verification question. The degree of matching with the verification question; the accumulating unit 26 is arranged to accumulate the verification points according to the matching degree, wherein the verification points are set with a preset initial value.
  • the determining unit 22 is configured to determine whether the verification credit is greater than or equal to a preset integration value; when the verification credit is less than the preset integration value, cause the prompting unit 20 to continue to prompt the user to verify the problem according to the historical usage information until The current verification score is greater than or equal to the preset integration value or the password verification is stopped.
  • the accumulating unit 26 is configured to accumulate the verification points according to the matching degree and the attribute of the historical usage information corresponding to the verification problem, wherein the attribute of the historical usage information includes at least the following One: the security level of the historical usage information, the complexity, and the time when the password is verified.
  • the prompting unit 20 is configured to prompt the user to the first verification question and the second verification question according to the historical usage information, where the first verification question is related to the historical usage information.
  • the second verification problem is not related to the historical usage information;
  • the determining unit 22 is configured to determine that the password verification is not passed when the second input is incorrect; and determine that the first input meets the first preset condition and the second input is correct. Password validation.
  • the prompting unit 20 is configured to prompt the user for the classification of the at least one historical usage information; and in response to the user selecting the at least one classification, according to the history corresponding to the selected classification.
  • the information prompts the user with at least one verification question.
  • the verification object includes an electronic device; and the classification of the historical usage information includes at least one of the following: according to the software classification in the electronic device, according to the operation type in the electronic device, or Classified by information type.
  • the prompting unit 20 is configured to prompt the user with a corresponding number of verification questions according to the historical usage information according to the historical usage information, where the attributes of the historical usage information include At least one of the following: the security level of the historical usage information, the complexity, and the time when the password is verified.
  • the determining unit 22 is configured to determine whether the input of the corresponding number of verification questions by the user satisfies the second preset condition, and when the second preset condition is met, determine to pass the verification.
  • the determining unit 22 is configured to determine a verification question that matches an input and a verification question, and determine a verification point according to a weight value of the historical usage information corresponding to the matched verification question, and determine the foregoing. Verify whether the integral is greater than or equal to the preset integral value; or set to determine whether the number of matches in the above input corresponding to the corresponding verification question is greater than or equal to the preset number.
  • FIG. 6 is a flowchart of a password verification method according to an alternative embodiment 1 of the embodiment of the present invention. As shown in FIG. 6, the process includes the following steps:
  • Step S602 acquiring historical usage information of the electronic device recorded in advance.
  • Step S604 prompting the user to at least one verification question according to the historical usage information
  • Step S606 in response to the user inputting the at least one verification question, performing verification of the password information according to the input.
  • the verification of the password information described above may include verification of the retrieved password or password verification such as unlocking.
  • the historical usage information may be recorded in the electronic device or may be recorded in the remote server.
  • a direct advantage of recording in electronic devices is that when verifying password information, there is no Historical usage information needs to be obtained through the network.
  • the historical usage information may relate to the privacy of the user, it may be stored by a dedicated security chip.
  • the historical usage information can also be encrypted and stored in the storage device.
  • the historical usage information includes various behavior information of the user on the electronic device, for example, account information that the user logs in on the electronic device, including but not limited to an email account, instant communication, etc., and the account information may be a mailbox, a nickname or other identifier. Information; or, the information of the e-book read by the user, including the name of the e-book, the time of reading the e-book, the page number of the e-book reading, and the like.
  • the embodiment of the present invention is not limited thereto, and any behavior information of the user on the electronic device can be used as information for verification.
  • the historical usage information includes: usage information within a period of time from the verification of the password information.
  • the historical usage information may include a plurality of classifications, where the classification may be a classification according to usage behavior, for example, input information, output information, etc.; or may be a classification of operation objects according to usage behavior, For example, classification according to different application software, payment software as a category, instant communication software as a category; or a behavioral information as a classification, for example, e-book reading behavior as a category, such history
  • the usage information may include an e-book reading time, an e-book name, and the like. It should be noted that the embodiments of the present invention are not limited thereto.
  • the user may be prompted with a classification of at least one historical usage information; in response to the user's selection of the at least one classification, the user is prompted with at least one verification question according to the historical usage information corresponding to the selected classification.
  • the user may be provided with historical usage information that he remembers, for example, prompting the user for verifiable historical usage information including e-book reading information, email login information, telephone call information, and short message content information. For the user to select the information they remember based on the memory to verify.
  • the user may be prompted with at least one verification question according to the historical usage information corresponding to the classification selected by the user, for example, “What is the name of the e-book that was last read” and the like.
  • the presentation of the problem is different. For example, for the classification according to the behavior, if it is an input behavior, it can prompt "what is the login account of the last used instant messaging software", “what is the login account of the last used mailbox”, and "the last input SMS content” What is it?"
  • different levels may be set for different historical usage information. Therefore, according to the historical usage information, the user may be prompted with a corresponding number of verification questions according to the level of the historical usage information, where the high level corresponds to The number is less than the number corresponding to the low level.
  • the high level corresponds to The number is less than the number corresponding to the low level.
  • the integration is performed according to a preset ratio, and the next question is prompted to the user until the user inputs The total score reaches the preset score, otherwise it is determined that the verification has not passed.
  • the weight value may be set for different historical usage information, and the verification problem that the input matches the verification question is determined in response to the user inputting the at least one verification according to the verification question; and the verification problem corresponding to the matching
  • the weight value of the historical usage information determines the verification score; determines whether the verification credit is greater than or equal to the preset integration value; if the verification credit is greater than or equal to the preset integration value, the verification by the password information is determined. For example, the user is prompted with five questions, each of which has a weight value, the correct answer for question 1 is 20 points, the answer to question 2 is correct for 10 points, and so on. When the answer is completed, the total score of the verification is calculated. If the total score is greater than or equal to the preset score, the verification by the password is determined.
  • the user's input and verification questions can be matched. If it is completely correct, the verification is performed if other conditions are met, and if the parts are inconsistent, the verification can be continued.
  • FIG. 7 is a flowchart of a password verification method according to an alternative embodiment 2 of the embodiment of the present invention. As shown in FIG. 7, the process includes the following steps:
  • Step S702 acquiring historical usage information of the pre-recorded verification object
  • Step S704 prompting the user to at least one verification question according to the historical usage information
  • Step S706 in response to the user inputting the at least one verification question, determining a degree of matching of the input with the at least one verification question;
  • Step S708 accumulating the verification points according to the above matching degree, wherein the initial value of the verification points is 0;
  • Step S710 it is determined whether the current verification point is greater than or equal to the preset integral value, if not, proceeds to step S712; if yes, proceeds to step S714;
  • Step S712 determining whether the verification end condition is satisfied, and if yes, the verification ends; if not, returning to step S704, continuing to prompt the user with the verification question according to the historical usage information;
  • Step S714 determining to pass the password verification.
  • the verification end condition may be that the number of verification questions exceeds the preset number, or the input of the user does not match the verification question continuously, etc., but is not limited thereto.
  • the user may also be prompted with a question unrelated to the historical usage information when prompting the verification question, as an interference problem.
  • a question unrelated to the historical usage information when prompting the verification question, as an interference problem.
  • the verification end condition may be to determine whether the input to the interference problem is wrong.
  • different historical usage information may correspond to different integral values. Reference may be made to the description of the foregoing embodiment, and details are not described herein again.
  • FIG. 8 is a flowchart of a password verification method according to an alternative embodiment 3 of the embodiment of the present invention. As shown in FIG. 8, the process includes the following steps:
  • Step S802 acquiring historical usage information of the pre-recorded verification object
  • Step S804 prompting the user with the first verification question and the second verification question according to the historical usage information, wherein the first verification question is related to the historical use information, and the second verification question is not related to the historical use information;
  • Step S806 responding to the first input of the first verification question and the second input of the second verification question by the user, when the second input is incorrect, determining that the password verification is not passed; when the first input meets the first preset condition and the first When the two inputs are correct, it is determined by password verification.
  • the foregoing first preset condition may be that the integral of the input of the at least one first verification question is greater than the preset integral value, or the correct number of the at least one first verification question is greater than the preset quantity, Or the input of the important question in the at least one first verification question exactly matches the verification question, etc., but the alternative embodiment is not limited thereto.
  • FIG. 9 is a flowchart of a password verification method according to an alternative embodiment 4 of the embodiment of the present invention. As shown in FIG. 9, the process includes the following steps:
  • Step S902 acquiring a historical usage record of the pre-recorded verification object
  • Step S904 prompting the user for classification of at least one historical usage information
  • Step S906 in response to the user selecting the at least one category, prompting the user to at least one verification question according to the historical usage information corresponding to the selected category;
  • Step S908 determining whether to pass the password verification according to the input of the at least one verification question by the user.
  • step S908 if the password verification is not passed in step S908, it is also possible to return to step S904 to continue to prompt the user for the classification of at least one historical usage information, so that the user selects another classification to continue the verification.
  • classifications for different verification objects. For example, for the verification of mailbox passwords, they can be categorized by behavior, such as contacts, time, email content, and so on.
  • FIG. 10 is a flowchart of a password verification method according to an alternative embodiment 5 of the embodiment of the present invention. As shown in FIG. 10, the process includes the following steps:
  • Step S1002 Obtain historical usage information of the pre-recorded verification object
  • Step S1004 according to the historical usage information, prompting the user with the corresponding number of verification questions according to the attribute of the historical usage information;
  • the attribute of the historical usage information includes at least one of the following: a security level of the historical usage information, a complexity, and a time when the password is verified.
  • Step S1006 Determine whether the input of the corresponding number of verification questions by the user meets the second preset condition, and when the second preset condition is met, determine to pass the password verification.
  • the user may be prompted with the classification of the historical usage information, and in response to the user's selection of the classification, the corresponding number of verification questions are prompted according to the attribute of the historical usage information corresponding to the selected classification.
  • the corresponding number of verification questions may be displayed, and after the user inputs, it is determined whether the verification is passed.
  • the verification question may be displayed one by one, and the user's input may be judged. When the condition is not satisfied, the next verification question is displayed until the number of verification or verification problems is greater than or equal to the corresponding number.
  • the second preset condition may be the above-mentioned integral determination, or may be the above-mentioned number of correct answer questions, etc., but is not limited thereto.
  • FIG. 11 is a flowchart of a password verification method according to an alternative embodiment 6 of the embodiment of the present invention. As shown in FIG. 11, the process includes the following steps:
  • Step S1102 performing unlocking of the mobile phone
  • Step S1104 determining whether the unlock password is wrong, if yes, proceeding to step S1106; if not, completing the unlocking operation and ending;
  • Step S1106 it is determined whether to continue the mobile phone unlock, if yes, proceeds to step S1108; if not, proceeds to step S1110;
  • Step S1108 it is determined whether the number of errors reaches a limit value, and if so, proceeds to step S1110; if not, returns to step S1102;
  • Step S1110 determining a mobile phone behavior verification scheme selected by the user, if yes, proceeding to step S1112; if not, ending;
  • Step S1112 performing password verification using the selected scheme
  • Step S1114 it is determined whether the mobile phone behavior verification is passed, if not, returns to step S1110; if yes, proceeds to step S1116;
  • step S1116 the password is retrieved or reset, and the process ends.
  • FIG. 12 is a flowchart of a password verification method according to an optional seventh embodiment of the present invention. As shown in FIG. 12, the process includes the following steps:
  • Step S1202 selecting a verification scheme
  • the verification scheme includes a contact, a game plan, a music plan, a photo plan, an alarm clock plan, a notepad plan, an e-book, and other programs;
  • Step S1204 using the selected scheme for verification, and determining whether the verification is completely correct, and if so, ending; if not, proceeding to step S1206;
  • Step S1208 it is determined whether the point system verification is qualified, and if so, the end of the verification; if not, proceeds to step S1210;
  • step S1210 it is determined whether the verification is ended, and if so, the verification is ended; if not, the process proceeds to step S1212;
  • step S1212 it is determined whether to re-verify, if yes, return to step S1202; if not, end the verification.
  • the recent behavior of the user operating the electronic device is recorded.
  • the behavior record for the mobile phone includes, but is not limited to, recent contacts, game names, game scores, downloaded or played music, Photographed photos, account/nicknames such as QQ/WeChat/ Renren/Email/Weibo that have been logged in, and the set alarm time, notebook record, e-book recent reading, etc.
  • the machine After the machine records the behavior of the mobile phone, the user is required to perform behavior verification.
  • a level description corresponding to the user verification mode can be given, and the user's answer needs to reach a certain score to unlock the mobile phone and perform password recovery or reset.
  • the verification score is a kind of guarantee.
  • Mobile phone security measures have also increased the fun.
  • the verification score For the verification score, the recent contact verification, when the user enters the contact name, the system starts to query according to the record module, if the name is correctly displayed 70 points, if the basic display is 50 points correctly, then you can choose to input the contact phone, such as The name and phone number are completely correct, and the display of 100 points is successful. If the name is basically correct, the phone number is correct, and 90 points are displayed, which requires further verification by the user. If the phone is entered and the phone is wrong, 20 points are subtracted from the original score.
  • the unlocking success is successful, and it can be tried 3 times.
  • the photo needs to input the last shooting time to an hour of the day, and the time can be unlocked when the time falls between several photos on the same day.
  • the time and period of the alarm can be correctly input (Monday to Saturday), completely correct and directly unlocked, and the entry system is basically correctly entered.
  • Notepad correctly enters the last recorded time specific to a certain day, or the title of the last record. Completely correct and directly unlock, basically enter the point system correctly.
  • E-book reading correctly input the last reading e-book title or time is completely correct and directly unlocked, basically correct, continue to verify the reading chapter or page number, correctly unlock directly, incorrectly deduct points, can also return to verify the reading chapter or page number , choose another verification scheme to continue verification.
  • the user unlocking scheme is based on the user's daily behavior for intelligent analysis, which may include a misleading scheme. Once the user selects, the user will fail to verify. If the user has not played music recently, there is no music in the mobile device, and the user uses the recently played music. The solution is verified.
  • the point system user can also set the point rules according to the user security level based on the system default.
  • modules or steps of the present invention described above can be implemented by a general-purpose computing device that can be centralized on a single computing device or distributed across a network of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device such that they may be stored in the storage device by the computing device and, in some cases, may be different from the order herein.
  • the steps shown or described are performed, or they are separately fabricated into individual integrated circuit modules, or a plurality of modules or steps thereof are fabricated as a single integrated circuit module.
  • the invention is not limited to any specific combination of hardware and software.
  • the verification of the password is performed using the historical usage information of the electronic device, the complexity of the verification of the password is reduced, and the user does not need to memorize the specific verification problem.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Telephone Function (AREA)

Abstract

本发明公开了一种密码验证方法及装置,其中密码验证方法包括:获取预先记录的验证对象的历史使用信息,根据该历史使用信息进行密码验证。通过本发明,解决了现有技术中密码验证复杂的问题,使用历史使用信息进行验证,避免了用户记忆特定的验证问题。

Description

密码验证方法及装置 技术领域
本发明涉及电子设备领域,具体而言,涉及一种密码验证方法及装置。
背景技术
电子设备承载的信息越来越多,例如,联系人信息、支付信息等都关系到用户的隐私或财产安全。因此,电子设备的安全已经成为一个重要的问题。
相关技术中,电子设备采用数字密码、图案密码等进行加密,以提高电子设备的安全性。例如,对于常见的电子设备——智能手机或平板电脑等,采用九宫格作为的图案锁屏方案。
由于密码或图案的复杂性,尤其是图案,使得用户容易忘记加密设置,导致无法使用电子设备。在一些情况下,如果连续尝试很多次都无法解锁,则只能一键刷机、SD卡升级版本或者恢复出厂设置等方式恢复使用。上述的方法常常导致电子设备的数据被清空,另外,如果升级失败可能导致电子设备硬件或软件故障。
相关技术中,密码丢失后找回密码的方式往往需要复杂的过程。要么需要借助网络,或者借助其他手机设备/网络服务器,要么需要对预设问题的答案准确记忆。
针对相关技术中密码验证处理较为复杂的问题,目前尚未提出有效的解决方案。
发明内容
本发明提供了一种密码验证方法及装置,以至少解决现有技术密码验证过程复杂的问题。
根据本发明的一个方面,提供了一种密码验证方法,包括:获取预先记录的验证对象的历史使用信息;根据该历史使用信息进行密码验证。
优选地,根据上述历史使用信息进行密码验证,包括:根据上述历史使用信息向用户提示验证问题;根据用户对该验证问题的输入判断是否通过密码验证。
优选地,根据用户对上述验证问题的输入判断是否通过密码验证,包括:确定用户对验证问题的输入与该验证问题的匹配程度;根据该匹配程度累加验证积分,其中, 该验证积分设置有预设初始值;判断该验证积分是否大于等于预设积分值;如果上述验证积分小于上述预设积分值,继续根据上述历史使用信息向用户提示验证问题,根据用户对当前验证问题的输入与当前验证问题的匹配程度累加验证积分,直到当前验证积分大于等于预设积分值或密码验证停止;如果上述验证积分大于等于上述预设积分值,确定通过密码验证。
优选地,根据上述匹配程度累加验证积分,包括:根据上述匹配程度和上述验证问题对应的历史使用信息的属性累加验证积分,其中,历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。
优选地,根据上述历史使用信息向用户提示验证问题,包括:根据上述历史使用信息向用户提示第一验证问题和第二验证问题,其中,第一验证问题与历史使用信息相关,第二验证问题与历史使用信息无关。根据用户对验证问题的输入判断是否通过密码验证,包括:当第二输入不正确时,确定未通过密码验证;当第一输入满足第一预设条件且第二输入正确时,确定通过密码验证。
优选地,根据上述历史使用信息向用户提示验证问题,包括:向用户提示至少一个历史使用信息的分类;响应于用户对上述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。
优选地,上述验证对象包括电子设备;上述历史使用信息的分类包括按照以下至少之一:按照上述电子设备中软件分类、按照上述电子设备中操作类型分类,或按照信息类型分类。
优选地,根据上述历史使用信息向用户提示至验证问题,包括:根据上述历史使用信息,按照该历史使用信息的属性,向用户提示对应数量的验证问题,其中,历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间;根据用户对上述验证问题的输入判断是否通过密码验证,包括:判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,当满足该第二预设条件时,确定通过密码验证。
优选地,判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,包括以下之一:确定输入与验证问题匹配的验证问题,根据上述匹配的验证问题对应的历史使用信息的权重值确定验证积分,判断上述验证积分是否大于等于预设积分值;或者,判断上述输入中与对应验证问题匹配的个数是否大于等于预设个数;
优选地,上述历史使用信息包括:距离进行密码验证最近的一段时间内的使用信息。
根据本发明实施例的另一个方面,提供了一种密码验证装置,包括:获取模块,设置为获取预先记录的验证对象的历史使用信息;验证模块,设置为根据上述历史使用信息进行密码验证。
优选地,上述验证模块,包括:提示单元,设置为根据上述历史使用信息向用户提示验证问题;判断单元,设置为根据用户对上述验证问题的输入判断是否通过密码验证。
优选地,上述验证模块,还包括:确定单元,设置为确定用户对验证问题的输入与验证问题的匹配程度;累加单元,设置为根据该匹配程度累加验证积分,其中,验证积分设置有预设初始值。上述判断单元,设置为判断上述验证积分是否大于等于预设积分值;在上述验证积分小于上述预设积分值时,使所示提示单元继续根据上述历史使用信息向用户提示验证问题,直到当前验证积分大于等于预设积分值或密码验证停止。
优选地,上述累加单元,设置为根据上述匹配程度和上述验证问题对应的历史使用信息的属性累加验证积分,其中,该历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。
优选地,上述提示单元,设置为根据上述历史使用信息向用户提示第一验证问题和第二验证问题,其中,第一验证问题与历史使用信息相关,第二验证问题与历史使用信息无关;上述判断单元,设置为在第二输入不正确时,确定未通过密码验证;在第一输入满足第一预设条件且第二输入正确时,确定通过密码验证。
优选地,上述提示单元,设置为向用户提示至少一个历史使用信息的分类;响应于用户对上述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。
优选地,上述验证对象包括电子设备;历史使用信息的分类包括按照以下至少之一:按照上述电子设备中软件分类、按照上述电子设备中操作类型分类,或按照信息类型分类。
优选地,上述提示单元,设置为根据历史使用信息,按照该历史使用信息的属性,向用户提示对应数量的验证问题,其中,历史使用信息的属性包括以下至少之一:历 史使用信息的安全等级、复杂度、距离密码验证时的时间。上述判断单元,设置为判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,当满足该第二预设条件时,确定通过上述验证。
优选地,上述判断单元,设置为确定输入与验证问题匹配的验证问题,根据上述匹配的验证问题对应的历史使用信息的权重值确定验证积分,判断上述验证积分是否大于等于预设积分值;或者设置为判断上述输入中与对应验证问题匹配的个数是否大于等于预设个数。
通过本发明,利用电子设备的历史使用信息进行密码的验证,降低了密码的验证的复杂性,并且无需用户记忆特定的验证问题。
附图说明
此处所说明的附图用来提供对本发明的进一步理解,构成本申请的一部分,本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1是根据本发明实施例的密码验证方法的流程图;
图2是根据本发明实施例可选的密码验证方法的流程图;
图3是根据本发明实施例的密码验证装置的结构框图;
图4是根据本发明实施例可选的验证模块的结构框图;
图5是根据本发明实施例另一可选的验证模块的结构框图;
图6是根据本发明实施例可选实施方式一的密码验证方法的流程图;
图7是根据本发明实施例可选实施方式二的密码验证方法的流程图;
图8是根据本发明实施例可选实施方式三的密码验证方法的流程图;
图9是根据本发明实施例可选实施方式四的密码验证方法的流程图;
图10是根据本发明实施例可选实施方式五的密码验证方法的流程图;
图11是根据本发明实施例可选实施方式六的密码验证方法的流程图;以及
图12是根据本发明实施例可选实施方式七的密码验证方法的流程图。
具体实施方式
下文中将参考附图并结合实施例来详细说明本发明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。
在本实施例中提供了一种密码验证方法,图1是根据本发明实施例的密码验证方法的流程图,如图1所示,该流程包括如下步骤:
步骤S102,获取预先记录的验证对象的历史使用信息;
步骤S104,根据该历史使用信息进行密码验证。
通过本发明实施例,利用电子设备的历史使用信息进行密码的验证,降低了密码的验证的复杂性,并且无需用户记忆特定的验证问题。
在本发明实施例中,上述的密码信息的验证可以包括找回密码的验证,也可以作为诸如解锁之类的密码验证。
在本发明实施例的一个可选实施方式中,上述历史使用信息可以记录在电子设备中,也可以记录在远程服务器中。在电子设备中记录的一个直接优点在于,进行密码信息的验证时,无需通过网络获取历史使用信息。可选地,由于历史使用信息可能涉及到用户的隐私,因此,可以通过专用的安全芯片存储。当然,也可以对历史使用信息加密后存储在存储装置中。
上述的历史使用信息包括用户在电子设备上的各种行为信息,例如,用户在电子设备上登陆的账号信息,包括但不限于邮箱账号、即时通信等,账号信息可以是邮箱、昵称或其他标识信息;或者,用户阅读的电子书的信息,包括电子书的名称、阅读电子书的时间、电子书阅读的页码等。在此仅作为举例说明,本发明实施例并不限于此,用户在电子设备上的任何行为信息均可作为验证使用的信息。
在本发明实施例的一个可选实施方式中,提供了一种可选的步骤S104,图2是根据本发明实施例可选的密码验证方法的流程图,如图2所示,上述步骤S104包括以下步骤:
步骤S104a,根据上述历史使用信息向用户提示验证问题;
步骤S104b,根据用户对该验证问题的输入判断是否通过密码验证。
在该可选实施方式中,可以通过多种方式向用户提示验证问题,也可以通过多种方式接收用户的输入。例如,可以在图像用户界面上显示验证问题,和/或通过语音向用户提示验证问题,其他的方式也是可以构想的,上述方式仅作为举例说明。
在本发明实施例的一个可选实施方式中,上述步骤S104b包括:
A,确定用户对验证问题的输入与该验证问题的匹配程度;
B,根据该匹配程度累加验证积分,其中,该验证积分设置有预设初始值;
C,判断该验证积分是否大于等于预设积分值;
D,如果上述验证积分小于上述预设积分值或者密码验证未停止,返回步骤S104a,继续根据上述历史使用信息向用户提示验证问题;如果上述验证积分大于等于上述预设积分值,确定通过密码验证。
在该可选实施方式中,匹配程度可以包括完全匹配、部分匹配以及不匹配。可以预先设置不同匹配程度的积分值,例如,完全匹配时积分值为50分,部分匹配时积分值为30分,不匹配时积分值为0或者为负值。不同的提示问题可以设置不同的积分值,例如,对重要的问题设置比一般问题更高的积分值。
在本发明实施例的一个可选实施方式中,上述步骤D根据匹配程度累加验证积分可以包括:根据匹配程度和验证问题对应的历史使用信息的属性累加验证积分,其中,历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。例如,安全等级高的提示问题设置更高的积分值。
在本发明实施例的一个可选实施方式中,上述步骤S104a可以包括:根据上述历史使用信息向用户提示第一验证问题和第二验证问题,其中,第一验证问题与历史使用信息相关,第二验证问题与历史使用信息无关;对应的,上述步骤S104b中,当第二输入不正确时,确定未通过密码验证;当第一输入满足第一预设条件且第二输入正确时,确定通过密码验证。在该可选实施方式中,第二验证问题与历史使用信息无关,用于作为干扰问题,例如,历史使用信息中未记录音乐播放记录,可以提示一个最近播放音乐的问题,如果用户对该问题的输入错误,则确定密码验证失败。通过该可选实施方式,通过无关问题进行干扰,至少可以提高验证的安全性。
在本发明实施例的一个可选实施方式中,上述步骤S104a可以包括:向用户提示至少一个历史使用信息的分类;响应于用户对上述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。在该可选实施方式中,可以 向用户提示可供选择的历史使用信息,使得用户可以基于自身情况选择用于密码验证的历史使用信息,例如用户能够回忆起的历史使用信息。
在本发明实施例的一个可选实施方式中,上述验证对象可以包括电子设备,当然也可以包括一般意义上的账号,包括邮箱、即时通讯软件等。以电子设备为例,上述历史使用信息的分类包括按照以下至少之一:按照上述电子设备中软件分类、按照上述电子设备中操作类型分类,或按照信息类型分类。
可选地,上述历史使用信息可以包括多个分类,此处的分类可以是按照使用行为的分类,例如,输入信息、输出信息等;也可以是按照使用行为的操作对象的分类,例如,按照不同的应用软件进行分类,支付类软件作为一类,即时通信软件作为一类;还可以是将一个行为的信息作为一个分类,例如,将电子书阅读行为作为一类,该类历史使用信息可以包括电子书阅读时间、电子书名称等。需要说明的是,本发明实施例并不限于此。
例如,向用户提示可供验证的历史使用信息包括电子书阅读信息、邮箱登陆信息、电话通话信息、短信内容信息等不同分类,供用户根据记忆情况选择其记住的信息进行验证。用户选择之后,可以根据用户选择的分类对应的历史使用信息向用户提示至少一个验证问题,例如,“上一次阅读的电子书的名称是什么”等。按照不同的分类方法,问题的呈现有所不同。例如,对于按照行为的分类,如果是输入行为,可以提示“上一次使用的即时通信软件的登陆账号是什么”、“上一次使用的邮箱的登陆账号是什么”、“上一次输入的短信内容是什么”等。
在本发明实施例的一个可选实施方式中,上述步骤S104a中,根据上述历史使用信息向用户提示至验证问题可以包括:根据上述历史使用信息,按照该历史使用信息的属性,向用户提示对应数量的验证问题,其中,历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间;根据用户对上述验证问题的输入判断是否通过密码验证,包括:判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,当满足该第二预设条件时,确定通过密码验证。
在本发明实施例的一个可选实施方式中,判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,包括以下之一:确定输入与验证问题匹配的验证问题,根据上述匹配的验证问题对应的历史使用信息的权重值确定验证积分,判断上述验证积分是否大于等于预设积分值;或者,判断上述输入中与对应验证问题匹配的个数是否大于等于预设个数;
本发明实施例的一个可选实施方式中,上述历史使用信息包括:距离进行密码验证最近的一段时间内的使用信息。
在本实施例中还提供了一种密码验证装置,该装置用于实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“模块”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的装置较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。
图3是根据本发明实施例的密码验证装置的结构框图,如图3所示,该装置包括:获取模块1,设置为获取预先记录的验证对象的历史使用信息;验证模块2,与获取模块1相接,设置为根据上述历史使用信息进行密码验证。
在本发明实施例的一个可选实施方式中,如图4所示,上述验证模块2,包括:提示单元20,设置为根据上述历史使用信息向用户提示验证问题;判断单元22,设置为根据用户对上述验证问题的输入判断是否通过密码验证。
在本发明实施例的一个可选实施方式中,如图5所示,上述验证模块2除了如图4所示的单元之外,还包括:确定单元24,设置为确定用户对验证问题的输入与验证问题的匹配程度;累加单元26,设置为根据该匹配程度累加验证积分,其中,验证积分设置有预设初始值。上述判断单元22,设置为判断上述验证积分是否大于等于预设积分值;在上述验证积分小于上述预设积分值时,使所示提示单元20继续根据上述历史使用信息向用户提示验证问题,直到当前验证积分大于等于预设积分值或密码验证停止。
在本发明实施例的一个可选实施方式中,上述累加单元26,设置为根据上述匹配程度和上述验证问题对应的历史使用信息的属性累加验证积分,其中,该历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。
在本发明实施例的一个可选实施方式中,上述提示单元20,设置为根据上述历史使用信息向用户提示第一验证问题和第二验证问题,其中,第一验证问题与历史使用信息相关,第二验证问题与历史使用信息无关;上述判断单元22,设置为在第二输入不正确时,确定未通过密码验证;在第一输入满足第一预设条件且第二输入正确时,确定通过密码验证。
在本发明实施例的一个可选实施方式中,上述提示单元20,设置为向用户提示至少一个历史使用信息的分类;响应于用户对上述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。
在本发明实施例的一个可选实施方式中,上述验证对象包括电子设备;历史使用信息的分类包括按照以下至少之一:按照上述电子设备中软件分类、按照上述电子设备中操作类型分类,或按照信息类型分类。
在本发明实施例的一个可选实施方式中,上述提示单元20,设置为根据历史使用信息,按照该历史使用信息的属性,向用户提示对应数量的验证问题,其中,历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。上述判断单元22,设置为判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,当满足该第二预设条件时,确定通过上述验证。
在本发明实施例的一个可选实施方式中,上述判断单元22,设置为确定输入与验证问题匹配的验证问题,根据上述匹配的验证问题对应的历史使用信息的权重值确定验证积分,判断上述验证积分是否大于等于预设积分值;或者设置为判断上述输入中与对应验证问题匹配的个数是否大于等于预设个数。
下面对本发明实施例的可选实施方式进行描述
可选实施方式一
在该可选实施方式中,以对电子设备进行密码验证为例进行说明。图6是根据本发明实施例可选实施方式一的密码验证方法的流程图,如图6所示,该流程包括以下步骤:
步骤S602,获取预先记录的电子设备的历史使用信息。
步骤S604,根据该历史使用信息向用户提示至少一个验证问题;
步骤S606,响应于用户对至少一个验证问题的输入,根据该输入进行密码信息的验证。
在该可选实施方式中,上述的密码信息的验证可以包括找回密码的验证,也可以作为诸如解锁之类的密码验证。
在该可选实施方式中,上述历史使用信息可以记录在电子设备中,也可以记录在远程服务器中。在电子设备中记录的一个直接优点在于,进行密码信息的验证时,无 需通过网络获取历史使用信息。可选地,由于历史使用信息可能涉及到用户的隐私,因此,可以通过专用的安全芯片存储。当然,也可以对历史使用信息加密后存储在存储装置中。
上述的历史使用信息包括用户在电子设备上的各种行为信息,例如,用户在电子设备上登陆的账号信息,包括但不限于邮箱账号、即时通信等,账号信息可以是邮箱、昵称或其他标识信息;或者,用户阅读的电子书的信息,包括电子书的名称、阅读电子书的时间、电子书阅读的页码等。在此仅作为举例说明,本发明实施例并不限于此,用户在电子设备上的任何行为信息均可作为验证使用的信息。
在该可选实施方式中,上述历史使用信息包括:距离进行所述密码信息的验证最近的一段时间内的使用信息。
在该可选实施方式中,历史使用信息可以包括多个分类,此处的分类可以是按照使用行为的分类,例如,输入信息、输出信息等;也可以是按照使用行为的操作对象的分类,例如,按照不同的应用软件进行分类,支付类软件作为一类,即时通信软件作为一类;还可以是将一个行为的信息作为一个分类,例如,将电子书阅读行为作为一类,该类历史使用信息可以包括电子书阅读时间、电子书名称等。需要说明的是,本发明实施例并不限于此。
在该可选实施方式中,可以向用户提示至少一个历史使用信息的分类;响应于用户对上述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。通过该可选实施方式,可以为用户提供其记得的历史使用信息,例如,向用户提示可供验证的历史使用信息包括电子书阅读信息、邮箱登陆信息、电话通话信息、短信内容信息等不同分类,供用户根据记忆情况选择其记住的信息进行验证。用户选择之后,可以根据用户选择的分类对应的历史使用信息向用户提示至少一个验证问题,例如,“上一次阅读的电子书的名称是什么”等。按照不同的分类方法,问题的呈现有所不同。例如,对于按照行为的分类,如果是输入行为,可以提示“上一次使用的即时通信软件的登陆账号是什么”、“上一次使用的邮箱的登陆账号是什么”、“上一次输入的短信内容是什么”等。
在该可选实施方式中,针对不同的历史使用信息可以设置不同的等级,因此可以根据上述历史使用信息,按照历史使用信息的等级,向用户提示对应数量的验证问题,其中,高等级对应的数量小于低等级对应的数量。通过该可选实施方式,对于等级高的历史使用信息,可以通过少量的问题进行验证,对于低等级的历史使用信息,可以通过数量较多的问题进行验证。从而可以提高验证的安全性。
在该可选实施方式中,如果用户对验证问题的输入完全正确,则可以确定通过验证,如果该输入部分正确,则按照预设比例进行积分,并向用户提示下一问题,直到用户输入的总积分达到预设的分值,否则确定未通过验证。
在该可选实施方式中,可以针对不同的历史使用信息设置权重值,响应用户对上述至少一个验证根据验证问题的输入,确定输入与验证问题匹配的验证问题;根据该匹配的验证问题对应的历史使用信息的权重值确定验证积分;判断验证积分是否大于等于预设积分值;如果该验证积分大于等于预设积分值,确定通过密码信息的验证。例如,向用户提示了5个问题,其中每个问题具有一个权重值,对于问题1回答正确为20分,对于问题2回答正确为10分,以此类推。回答完成时,计算验证的总分值,如果总分值大于等于预设的分值,则确定通过密码的验证。
在该可选实施方式中,可以根据回答正确的数量来确定是否通过验证。因此,可以响应于用户对上述至少一个验证问题的输入,判断该输入中与对应验证问题匹配的个数是否大于等于预设个数;如果该个数大于等于预设个数,确定通过密码信息的验证。
在该可选实施方式中,可以对用户的输入与验证问题进行匹配,如果完全正确,则在满足其他条件的情况下通过验证,如果部分不一致,则可以继续进行验证。
可选实施方式二
在该可选实施方式中,以通过验证积分进行密码验证进行说明。图7是根据本发明实施例可选实施方式二的密码验证方法的流程图,如图7所示,该流程包括以下步骤:
步骤S702,获取预先记录的验证对象的历史使用信息;
步骤S704,根据该历史使用信息向用户提示至少一个验证问题;
步骤S706,响应用户对该至少一个验证问题的输入,确定该输入与该至少一个验证问题的匹配程度;
步骤S708,根据上述匹配程度累加验证积分,其中,验证积分的初始值为0;
步骤S710,判断当前验证积分是否大于等于预设积分值,如果否,进入步骤S712;如果是,进入步骤S714;
步骤S712,判断是否满足验证结束条件,如果是,验证结束;如果否,返回步骤S704,继续根据历史使用信息向用户提示验证问题;
步骤S714,确定通过密码验证。
上述步骤S712中,验证结束条件可以是验证问题的数量超过预设数量,或者用户的输入与验证问题连续不匹配等,但是不限于此。
在该可选实施方式中,还可以在提示验证问题时,向用户提示与历史使用信息无关的问题,用于作为干扰问题。当用户对干扰问题的输入不匹配或错误时,则确定验证不通过,并结束验证。可选地,验证结束条件可以是判断对干扰问题的输入是否错误。
在该可选实施方式中,不同的历史使用信息可以对应不同的积分值。此处可以参见上述实施例的描述,在此不再赘述。
可选实施方式三
在该可选实施方式中,以提示干扰验证问题为例进行说明。图8是根据本发明实施例可选实施方式三的密码验证方法的流程图,如图8所示,该流程包括以下步骤:
步骤S802,获取预先记录的验证对象的历史使用信息;
步骤S804,根据历史使用信息向用户提示第一验证问题和第二验证问题,其中,第一验证问题与历史使用信息相关,第二验证问题与历史使用信息无关;
步骤S806,响应用户对第一验证问题的第一输入和第二验证问题的第二输入,当第二输入不正确时,确定未通过密码验证;当第一输入满足第一预设条件且第二输入正确时,确定通过密码验证。
在该可选实施方式中,上述第一预设条件可以是对至少一个第一验证问题的输入的积分大于预设积分值,或者至少一个第一验证问题中输入正确的数量大于预设数量,或者至少一个第一验证问题中重要问题的输入与该验证问题完全匹配等,但是该可选实施方式并不限于此。
可选实施方式四
在该可选实施方式中,以向用户提示历史使用信息的分类为例进行说明。图9是根据本发明实施例可选实施方式四的密码验证方法的流程图,如图9所示,该流程包括以下步骤:
步骤S902,获取预先记录的验证对象的历史使用记录;
步骤S904,向用户提示至少一个历史使用信息的分类;
步骤S906,响应于用户对上述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题;
步骤S908,根据用户对上述至少一个验证问题的输入判断是否通过密码验证。
在该可选实施方式中,如果在步骤S908中未通过密码验证,还可以返回步骤S904,继续向用户提示至少一个历史使用信息的分类,以便用户选择其他分类继续验证。
在该可选实施方式中,针对不同的验证对象可以有不同的分类方式。例如,对于邮箱密码的验证,可以按照行为进行分类,例如,联系人、时间、邮件内容等。
可选实施方式五
在该可选实施方式中,以根据历史使用信息的属性确定验证问题的数量为例进行说明。图10是根据本发明实施例可选实施方式五的密码验证方法的流程图,如图10所示,该流程包括以下步骤:
步骤S1002,获取预先记录的验证对象的历史使用信息;
步骤S1004,根据历史使用信息,按照历史使用信息的属性,向用户提示对应数量的验证问题;
其中,该历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。
步骤S1006,判断用户对上述对应数量的验证问题的输入是否满足第二预设条件,当满足第二预设条件时,确定通过密码验证。
在该可选实施方式中,在步骤S1004之前,可以向用户提示历史使用信息的分类,响应用户对分类的选择,根据选择的分类对应的历史使用信息的属性提示对应数量的验证问题。
在该可选实施方式中,可以显示上述对应数量的验证问题,用户输入完毕后,判断是否通过验证。或者,还可以逐一显示验证问题,对用户的输入进行判断,在不满足条件时,显示下一验证问题,直到通过验证或者验证问题的数量大于等于上述对应数量。
在该可选实施方式中,上述的第二预设条件可以是上述的积分判断,也可以是上述的答对问题数量判断等,但是不限于此。
可选实施方式六
在该可选实施方式中,以手机解锁出现错误时的密码验证为例进行说明。图11是根据本发明实施例可选实施方式六的密码验证方法的流程图,如图11所示,该流程包括以下步骤:
步骤S1102,进行手机解锁;
步骤S1104,判断解锁密码是否错误,如果是,进入步骤S1106;如果否,完成解锁操作并结束;
步骤S1106,判断是否继续进行手机解锁,如果是,进入步骤S1108;如果否,进入步骤S1110;
步骤S1108,判断错误次数是否达到限定值,如果是,进入步骤S1110;如果否,返回步骤S1102;
步骤S1110,判断用户选择的手机行为验证方案,如果是,进入步骤S1112;如果否,结束;
步骤S1112,采用选择的方案进行密码验证;
步骤S1114,判断手机行为验证是否通过,如果否,返回步骤S1110;如果是,进入步骤S1116;
步骤S1116,找回或重置密码,结束。
可选实施方式七
在该可选实施方式中,以多个方案进行积分验证为例进行说明。图12是根据本发明实施例可选实施方式七的密码验证方法的流程图,如图12所示,该流程包括以下步骤:
步骤S1202,选择验证方案;
其中,验证方案包括联系人、游戏方案、音乐方案、照片方案、闹钟方案、记事本方案、电子书以及其他方案;
步骤S1204,采用选择的方案进行验证,并判断验证是否完全正确,如果是,结束;如果否,进入步骤S1206;
步骤S1206,采用积分制继续验证;
步骤S1208,判断积分制验证是否合格,如果是,结束验证;如果否,进入步骤S1210;
步骤S1210,判断是否结束验证,如果是,结束验证;如果否,进入步骤S1212;
步骤S1212,判断是否重新验证,如果是,返回步骤S1202;如果否,结束验证。
可选实施方式八
在该可选实施方式中,对用户操作电子设备的近期行为进行记录,以手机为例,对于手机的行为记录包括但不限于近期联系人,游戏名称,游戏分数,下载或播放过的音乐,拍摄过的照片,本机登录过的QQ/微信/人人网/邮箱/微博等的账号/昵称,以及设置的闹钟时间,记事本记录,电子书最近阅读等。本机对于手机行为记录后,待用户进行行为验证。
在该可选实施方式中,从安全角度分析,可以给出用户验证方式对应的等级说明,用户的回答需要达到一定的分数才能解锁手机并进行密码找回或重置,验证分数是一种确保手机安全的措施,也增强了趣味性。
对于验证分数,近期联系人验证,当用户输入联系人名称后,系统开始根据记录模块进行查询,如名称完全正确显示70分,如基本正确显示50分,此时可以选择输入联系人电话,如姓名和电话完全正确,显示100分解锁成功,如姓名基本正确,电话正确,显示90分,需要用户进一步验证。如果输入电话且电话错误,则在原来分数基础上减去20分。
类似的,对于游戏验证,近期用户游戏名称正确,显示70分,游戏的最高或最后分数精确到第一位正确的情况下,即可解锁成功,可尝试3次。对于音乐需要输入正确的音乐名称,照片需要输入上一次拍摄时间具体到某一天的某一个小时,当时间落在同一天几张照片之间即可解锁。
对于登录过的QQ/微信/人人网/邮箱/微博等的账号,需要提供正确的账号以及上一次在本机在线的时间和昵称,系统会根据用户行为智能分析,如用户今天没有打开数据,因此今天没有在线,输入在线时间必须是今天之前的时间,但不能超过5天,如5天都不在线,用户选择了此种验证方案,显示分数0,此方案验证失败。
对于用户闹钟,能够正确输入闹钟的时间和周期(周一到周六),完全正确直接解锁,基本正确进入积分制。记事本正确输入上次记录的时间具体到某一天,或者上次记录的标题。完全正确直接解锁,基本正确进入积分制。
电子书阅读正确输入上次阅读电子书书名或时间完全正确直接解锁,基本正确,继续验证阅读的章节或页数,正确直接解锁,不正确扣分,也可返回不验证阅读章节或页数,选择其他验证方案继续验证。
用户解锁方案是根据用户日常行为进行智能分析的,其中可以包括误导方案,用户一旦选择,便会验证失败,如用户近期没有播放过音乐,手机设备中没有音乐,而用户使用了近期播放音乐的方案进行验证。积分制方案用户还可以在系统默认的基础上根据用户安全等级自行设置积分规则。
显然,本领域的技术人员应该明白,上述的本发明的各模块或各步骤可以用通用的计算装置来实现,它们可以集中在单个的计算装置上,或者分布在多个计算装置所组成的网络上,可选地,它们可以用计算装置可执行的程序代码来实现,从而,可以将它们存储在存储装置中由计算装置来执行,并且在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤,或者将它们分别制作成各个集成电路模块,或者将它们中的多个模块或步骤制作成单个集成电路模块来实现。这样,本发明不限制于任何特定的硬件和软件结合。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
工业实用性
如上所述,通过上述实施例及优选实施方式,利用电子设备的历史使用信息进行密码的验证,降低了密码的验证的复杂性,并且无需用户记忆特定的验证问题。

Claims (19)

  1. 一种密码验证方法,包括:
    获取预先记录的验证对象的历史使用信息;
    根据所述历史使用信息进行密码验证。
  2. 根据权利要求1所述的方法,其中,根据所述历史使用信息进行密码验证,包括:
    根据所述历史使用信息向用户提示验证问题;
    根据用户对所述验证问题的输入判断是否通过密码验证。
  3. 根据权利要求2所述的方法,其中,根据用户对所述验证问题的输入判断是否通过密码验证,包括:
    确定用户对所述验证问题的输入与所述验证问题的匹配程度;
    根据所述匹配程度累加验证积分,其中,所述验证积分设置有预设初始值;
    判断所述验证积分是否大于等于预设积分值;
    如果所述验证积分小于所述预设积分值,继续根据所述历史使用信息向用户提示验证问题,根据用户对当前验证问题的输入与当前验证问题的匹配程度累加验证积分,直到当前验证积分大于等于预设积分值或密码验证停止;
    如果所述验证积分大于等于所述预设积分值,确定通过密码验证。
  4. 根据权利要求3所述的方法,其中,根据所述匹配程度累加验证积分,包括:
    根据所述匹配程度和所述验证问题对应的历史使用信息的属性累加验证积分,其中,所述历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。
  5. 根据权利要求2至4中任一项所述的方法,其中,
    根据所述历史使用信息向用户提示验证问题,包括:根据所述历史使用信息向用户提示第一验证问题和第二验证问题,其中,所述第一验证问题与所述历史使用信息相关,所述第二验证问题与所述历史使用信息无关;
    根据用户对所述验证问题的输入判断是否通过密码验证,包括:当所述第二验证问题的第二输入不正确时,确定未通过所述密码验证;当所述第一验证问题的第一输入满足第一预设条件且所述第二输入正确时,确定通过所述密码验证。
  6. 根据权利要求2所述的方法,其中,根据所述历史使用信息向用户提示验证问题,包括:
    向用户提示至少一个历史使用信息的分类;
    响应于用户对所述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。
  7. 根据权利要求6所述的方法,其中,所述验证对象包括电子设备;所述历史使用信息的分类包括按照以下至少之一:按照所述电子设备中软件分类、按照所述电子设备中操作类型分类,或按照信息类型分类。
  8. 根据权利要求2所述的方法,其中,
    根据所述历史使用信息向用户提示至验证问题,包括:根据所述历史使用信息,按照所述历史使用信息的属性,向用户提示对应数量的验证问题,其中,所述历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间;
    根据用户对所述验证问题的输入判断是否通过密码验证,包括:判断用户对所述对应数量的验证问题的输入是否满足第二预设条件,当满足所述第二预设条件时,确定通过所述密码验证。
  9. 根据权利要求8所述的方法,其中,判断用户对所述对应数量的验证问题的输入是否满足第二预设条件,包括以下之一:
    确定输入与验证问题匹配的验证问题,根据所述匹配的验证问题对应的历史使用信息的权重值确定验证积分,判断所述验证积分是否大于等于预设积分值;
    判断所述输入中与对应验证问题匹配的个数是否大于等于预设个。
  10. 根据权利要求1所述的方法,其中,所述历史使用信息包括:距离进行所述密码验证最近的一段时间内的使用信息。
  11. 一种密码验证装置,包括:
    获取模块,设置为获取预先记录的验证对象的历史使用信息;
    验证模块,设置为根据所述历史使用信息进行密码验证。
  12. 根据权利要求11所述的装置,其中,所述验证模块,包括:
    提示单元,设置为根据所述历史使用信息向用户提示验证问题;
    判断单元,设置为根据用户对所述验证问题的输入判断是否通过密码验证。
  13. 根据权利要求12所述的装置,其中,
    所述验证模块,还包括:确定单元,设置为确定用户对所述验证问题的输入与所述验证问题的匹配程度;累加单元,设置为根据所述匹配程度累加验证积分,其中,所述验证积分设置有预设初始值;
    所述判断单元,设置为判断所述验证积分是否大于等于预设积分值;在所述验证积分小于所述预设积分值时,使所示提示单元继续根据所述历史使用信息向用户提示验证问题,直到当前验证积分大于等于预设积分值或密码验证停止。
  14. 根据权利要求13所述的装置,其中,所述累加单元,设置为根据所述匹配程度和所述验证问题对应的历史使用信息的属性累加验证积分,其中,所述历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间。
  15. 根据权利要求12至14中任一项所述的装置,其中,
    所述提示单元,设置为根据所述历史使用信息向用户提示第一验证问题和第二验证问题,其中,所述第一验证问题与所述历史使用信息相关,所述第二验证问题与所述历史使用信息无关;
    所述判断单元,设置为当所述第二验证问题的第二输入不正确时,确定未通过所述密码验证;当所述第一验证问题的第一输入满足第一预设条件且所述第二输入正确时,确定通过所述密码验证。
  16. 根据权利要求12所述的装置,其中,所述提示单元,设置为向用户提示至少一个历史使用信息的分类;响应于用户对所述至少一个分类的选择,根据选择的分类对应的历史使用信息向用户提示至少一个验证问题。
  17. 根据权利要求16所述的装置,其中,所述验证对象包括电子设备;所述历史使用信息的分类包括按照以下至少之一:按照所述电子设备中软件分类、按照所述电子设备中操作类型分类,或按照信息类型分类。
  18. 根据权利要求12所述的装置,其中,
    所述提示单元,设置为根据所述历史使用信息,按照所述历史使用信息的属性,向用户提示对应数量的验证问题,其中,所述历史使用信息的属性包括以下至少之一:历史使用信息的安全等级、复杂度、距离密码验证时的时间;
    所述判断单元,设置为判断用户对所述对应数量的验证问题的输入是否满足第二预设条件,当满足所述第二预设条件时,确定通过所述密码验证。
  19. 根据权利要求18所述的装置,其中,所述判断单元,
    设置为确定输入与验证问题匹配的验证问题,根据所述匹配的验证问题对应的历史使用信息的权重值确定验证积分,判断所述验证积分是否大于等于预设积分值;或者
    设置为判断所述输入中与对应验证问题匹配的个数是否大于等于预设个数。
PCT/CN2015/073910 2014-12-29 2015-03-09 密码验证方法及装置 WO2016106973A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410836178.XA CN105809023A (zh) 2014-12-29 2014-12-29 密码验证方法及装置
CN201410836178.X 2014-12-29

Publications (1)

Publication Number Publication Date
WO2016106973A1 true WO2016106973A1 (zh) 2016-07-07

Family

ID=56284056

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/073910 WO2016106973A1 (zh) 2014-12-29 2015-03-09 密码验证方法及装置

Country Status (2)

Country Link
CN (1) CN105809023A (zh)
WO (1) WO2016106973A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114158045A (zh) * 2021-12-14 2022-03-08 上海市共进通信技术有限公司 用于提示用户输入正确wifi密码的方法
US11301556B2 (en) 2016-08-31 2022-04-12 Advanced New Technologies Co., Ltd. Verification method and device

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107800672B (zh) * 2016-09-06 2020-12-08 腾讯科技(深圳)有限公司 一种信息验证方法、电子设备、服务器及信息验证系统
CN109948038B (zh) * 2017-11-24 2020-09-15 阿里巴巴集团控股有限公司 问题推送方法及装置
CN107733660A (zh) * 2017-11-29 2018-02-23 佛山市因诺威特科技有限公司 一种密码找回方法
CN108712413B (zh) * 2018-05-15 2021-08-31 上海掌门科技有限公司 一种身份验证的方法及设备
CN108400994B (zh) * 2018-05-30 2022-06-03 深圳市马博士网络科技有限公司 用户认证方法、移动终端、服务器及计算机可读存储介质
CN112926037A (zh) * 2020-12-30 2021-06-08 南京披云信息科技有限公司 物联网认证方法、装置及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101908960A (zh) * 2009-06-02 2010-12-08 上海科大智能科技股份有限公司 涉密电子文件的多重保密方法
EP2336941A1 (en) * 2009-03-12 2011-06-22 Panasonic Corporation Form reader, form authentication method, and program
CN103516701A (zh) * 2012-06-29 2014-01-15 联想(北京)有限公司 一种数据处理方法以及一种密码管理系统
CN103916244A (zh) * 2013-01-04 2014-07-09 深圳市腾讯计算机系统有限公司 验证方法及装置
CN104184705A (zh) * 2013-05-23 2014-12-03 腾讯科技(深圳)有限公司 验证方法、装置、服务器、用户数据中心和系统

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102035649B (zh) * 2009-09-29 2013-08-21 国际商业机器公司 认证方法和装置
CN102855427B (zh) * 2012-08-31 2016-03-02 小米科技有限责任公司 一种设备解锁方法、装置及用户设备

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2336941A1 (en) * 2009-03-12 2011-06-22 Panasonic Corporation Form reader, form authentication method, and program
CN101908960A (zh) * 2009-06-02 2010-12-08 上海科大智能科技股份有限公司 涉密电子文件的多重保密方法
CN103516701A (zh) * 2012-06-29 2014-01-15 联想(北京)有限公司 一种数据处理方法以及一种密码管理系统
CN103916244A (zh) * 2013-01-04 2014-07-09 深圳市腾讯计算机系统有限公司 验证方法及装置
CN104184705A (zh) * 2013-05-23 2014-12-03 腾讯科技(深圳)有限公司 验证方法、装置、服务器、用户数据中心和系统

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11301556B2 (en) 2016-08-31 2022-04-12 Advanced New Technologies Co., Ltd. Verification method and device
CN114158045A (zh) * 2021-12-14 2022-03-08 上海市共进通信技术有限公司 用于提示用户输入正确wifi密码的方法

Also Published As

Publication number Publication date
CN105809023A (zh) 2016-07-27

Similar Documents

Publication Publication Date Title
WO2016106973A1 (zh) 密码验证方法及装置
Reynolds et al. A tale of two studies: The best and worst of yubikey usability
US9131377B2 (en) Method and apparatus for unlocking operating system
CN103548031B (zh) 图片手势认证
CN101416196B (zh) 本人认证系统及本人认证方法
US7874011B2 (en) Authenticating user identity when resetting passwords
CN105827683B (zh) 一种数据同步的方法、服务器及电子设备
EP1669836A1 (en) User authentication by combining speaker verification and reverse turing test
US9721079B2 (en) Image authenticity verification using speech
US10044710B2 (en) Device and method for validating a user using an intelligent voice print
CN115396114A (zh) 基于可验证声明的授权方法、装置、设备及系统
CN102073807A (zh) 信息处理设备、信息处理方法和程序
US10909233B2 (en) Payment password reset method and apparatus, and electronic device
CN108960839B (zh) 一种支付方法及装置
CN109472915B (zh) 一种应用于社交系统的基于区块链的投票系统
Owens et al. User perceptions of the usability and security of smartphones as {FIDO2} roaming authenticators
JP2005149388A (ja) パスワード認証装置、並びに、そのプログラムおよび記録媒体
US11244757B1 (en) Computer-based access security and verification
WO2021244471A1 (zh) 一种实名认证方法及装置
CN112560815B (zh) 档案调用方法、装置、介质及电子设备
EP3528151A1 (en) Method and apparatus for user authentication
JP5418361B2 (ja) ユーザ認証システム、ユーザ認証方法及びプログラム
JP4840036B2 (ja) 生体認証装置及び方法
US10740728B1 (en) Computer-based access security and verification
CN106936840B (zh) 一种信息提示方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15874666

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15874666

Country of ref document: EP

Kind code of ref document: A1