Password verification method and system

一种口令校验方法及系统

Abstract

本申请提供一种口令校验方法及系统,所述方法包括:步骤S1、上位机生成PIN值,步骤S2、上位机从USBKEY获取随机数,步骤S3、生成校验PIN指令数据包,步骤S4、USBKEY对指令数据包进行解析,步骤S5、对解析数据进行判断,判断成功通过校验PIN。本申请提出的口令校验方法及系统,通过对随机数、用户PIN值的长度和用户的PIN值进行非对称算法加密保证了校验口令的真正安全,提高口令的安全级别,防止PIN码信息的泄露。可防御USBKEY更高级别的攻击;并且通过对随机数、用户PIN值的长度和用户的PIN值进行分级验证,还节省了判定时间,更提高了USBKEY响应速度,提升用户体验。
The application provides a password verification method and system. The method comprises the step that S1, an upper computer generates a PIN value; S2, the upper computer acquires a random number from a USBKEY; S3, an instruction data packet for PIN verification is generated; S4, the USBKEY parses the instruction data packet; and S5, parsed data are determined, and if the determination is successful, the PIN verification passes. According to the password verification method and system provided by the application, the real security of a verification password is ensured by performing asymmetric algorithm encryption on the random number, the length of a user PIN value and the user PIN value, so that the security level of the password is improved, PIN code information leakage is prevented, and higher-level attack to the USBKEY can be defended; and in addition, through grading verification on the random number, the length of the user PIN value and the user PIN value, the determination time is saved, the USBKEY response speed is higher, and the user experience is improved.

Claims

Description

Topics

Download Full PDF Version (Non-Commercial Use)

Patent Citations (0)

    Publication numberPublication dateAssigneeTitle

NO-Patent Citations (0)

    Title

Cited By (0)

    Publication numberPublication dateAssigneeTitle