CN103235910A - Method achieving network account protection control based on smart card in iOS operation system - Google Patents

Method achieving network account protection control based on smart card in iOS operation system Download PDF

Info

Publication number
CN103235910A
CN103235910A CN2013101032382A CN201310103238A CN103235910A CN 103235910 A CN103235910 A CN 103235910A CN 2013101032382 A CN2013101032382 A CN 2013101032382A CN 201310103238 A CN201310103238 A CN 201310103238A CN 103235910 A CN103235910 A CN 103235910A
Authority
CN
China
Prior art keywords
smart card
application program
symmetric key
log
information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2013101032382A
Other languages
Chinese (zh)
Other versions
CN103235910B (en
Inventor
胡永涛
杨明慧
戴聪
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Third Research Institute of the Ministry of Public Security
Original Assignee
Third Research Institute of the Ministry of Public Security
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Third Research Institute of the Ministry of Public Security filed Critical Third Research Institute of the Ministry of Public Security
Priority to CN201310103238.2A priority Critical patent/CN103235910B/en
Publication of CN103235910A publication Critical patent/CN103235910A/en
Application granted granted Critical
Publication of CN103235910B publication Critical patent/CN103235910B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention relates to a method achieving network account protection control based on a smart card in an iOS operation system. An appliance program in electronic equipment loaded with the iOS operation system is connected with the smart card through a card reader. The method comprises the following steps: symmetric key generation processing operation, user account information adding processing operation and Web site access control processing operation. Through the adoption of the method, The smart card with the PKI function is adopted as protection equipment; in the open and unsafe network environment, a safe and convenient Web site login method is provided for an iOS user; safety equipment is not required to be specially custom-made, so that in the open network environment, the smart card is adopted as a hardware base to provide safe and reliable identity management and password protection for the Apple iOS user, the account safety is improved effectively, the method is suitable for various Web sites, the working performance is stable and reliable, and the application range is relatively wide.

Description

Realize the method for network account protection control in the iOS operating system based on smart card
Technical field
The present invention relates to information security field, particularly internet account authentication information security protection technology field specifically refers to realize the method that the network account protection is controlled based on smart card in a kind of iOS operating system.
Background technology
The senior vice-president Scott Forstall of iOS operating system software of Apple represents that in the WWDC conference apple has been sold 200,000,000 iOS equipment up to now.Along with iOS user group is more and more huger, the user is increasing by the download of channels such as App Store, iTunes, and Apple account number of times under attack also gets more and more, and common account safety problem is as follows:
(1) Malware leaks privacy: can make iOS user obtain safe software though possess the App Store of strict review mechanism, but the source of the software beyond the App Store just seems so unreliable, in a single day the user uses the software of built-in malicious code, very easily cause the local accounts information of preserving to be revealed, even cause economic loss.
(2) phishing attack: phishing attack is finished with the form of forging webpage usually, namely utilize the page user cheating similar to the targeted sites height, even mislead the public by forging address field, allow user's branch evident of having no way of, automatically accounts information is revealed to the assailant.
(3) number of the account is lost: because the event of Web website leakage user account information under attack happens occasionally, the user uses a plurality of websites of unified user name password combination Login Register no longer desirable; On the other hand, some Web website is for security consideration, require the user just to change password at set intervals one time, simultaneously the complicacy of password is also made requirement, more than these all make the user have a large amount of accounts simultaneously, if effectively do not take care of mode, the user is easy to forget user name or password, causes account to use.
In the prior art, current protection account safety has multiple solution, has such as the scheme based on software, and safety problem, the audit of standby mailbox etc. are set, but be not that all Web websites have these requirements when registration, brought the too loaded down with trivial details problem of each operation simultaneously yet; Hardware based scheme, as the cryptoguard equipment lifting account safety of employing Mobile banking, but this equipment does not have universality equally, can't use except particular station.
Summary of the invention
The objective of the invention is to have overcome above-mentioned shortcoming of the prior art, provide a kind of Web website login that safe and convenient is provided for iOS user in open, unsafe network environment, need not customized especially safety equipment, effectively improve account security, stable and reliable working performance, the scope of application realize network account protection control comparatively widely in the iOS operating system based on smart card method.
In order to realize above-mentioned purpose, realize that based on smart card the method for network account protection control is as follows in the iOS operating system of the present invention:
Realize the method for network account protection control in this iOS operating system based on smart card; the application program that is mounted with in the electronic equipment of iOS operating system is connected with described smart card by card reader; its principal feature is; described method comprises that symmetric key generate to handle operation, user account information and add and handle operation and operation is handled in the control of Web site access; described symmetric key generates handles operation, may further comprise the steps:
(11) described application program is obtained the unique identification UID information of described smart card;
(12) whether described Application inspection has the log-on message file that the unique identification UID information with this smart card is complementary;
(13) if having, then finish this processing operation; If do not have, then newly-built described log-on message file, and continuation following steps (14);
(14) described smart card produces random number as symmetric key, and encrypts this symmetric key with asymmetric arithmetic and obtain the ciphertext symmetric key, and delivers to described application program;
(15) described application program writes described ciphertext symmetric key in the described log-on message file;
Described user account information is added the processing operation, may further comprise the steps:
(21) system operates according to the user, starts described application program, and is connected with described smart card;
(22) described application program is obtained the unique identification UID information of this smart card;
(23) described application program reads described ciphertext symmetric key from the log-on message file that is complementary with this unique identification UID information, and delivers in the described smart card;
(24) described smart card is deciphered described ciphertext symmetric key by private key and is obtained expressly symmetric key, and delivers to described application program;
(25) described application program loads the Web site list, and is added corresponding user account information according to user's selection operation to operating website;
(26) the described application program user account information of being added with described plaintext symmetric key encryption, and obtain writing in the described log-on message file after the user account ciphertext;
Operation is handled in described Web site access control, may further comprise the steps:
(31) system operates according to the user, starts described application program, and is connected with described smart card;
(32) described application program is obtained the unique identification UID information of this smart card;
(33) described application program reads described ciphertext symmetric key from the log-on message file that is complementary with this unique identification UID information, and delivers in the described smart card;
(34) described smart card is deciphered described ciphertext symmetric key by private key and is obtained expressly symmetric key, and delivers to described application program;
(35) described application program is deciphered described accounts information with described plaintext symmetric key, and loads corresponding account tabulation;
(36) described application program obtains corresponding accounts information according to user's selection operation, and obtains the login page code alternately with the Web server in station, resolves the back and inserts corresponding log-on message automatically according to described accounts information;
(37) described application program is operated according to the user and is submitted to corresponding log-on message to the Web server in station.
Comprise ciphertext symmetric key data field and accounts information encrypt data territory based on the log-on message file in the method for smart card realization network account protection control in this iOS operating system.
Comprise that based on the accounts information encrypt data territory in the method for smart card realization network account protection control several are with the log-on message of described symmetric key encryption in this iOS operating system.
Comprise Web Site ID information, username and password based on the log-on message in the method for smart card realization network account protection control in this iOS operating system.
The unique identification UID that is called smart card in this iOS operating system based on the name of the log-on message file in the method for smart card realization network account protection control.
Be complementary based on the log-on message file in the method for smart card realization network account protection control and the unique identification UID information of smart card in this iOS operating system, be specially:
The filename of described log-on message file is identical with the unique identification UID of described smart card.
Comprise username and password based on the user account information in the method for smart card realization network account protection control in this iOS operating system.
Adopted the method that protection is controlled based on smart card realization network account in the iOS operating system of this invention; because it adopts the smart card that has the PKI function as protection equipment; what open; provide safe for iOS user in unsafe network environment; Web website login method easily; and do not need customized especially safety equipment; thereby realized in open network environment, adopting smart card to provide safety as hardware foundation for Apple iOS user; Identity Management and cryptoguard reliably; effectively improved account security; be applicable to various Web websites, stable and reliable working performance; the scope of application is comparatively extensive.Corresponding beneficial effect is specific as follows:
(1) convenience---preserve accounts information in this locality, the user only needs manually to import username and password when initialization, and Web website logon form is filled in automatically by the present invention in the use, and is easy to use;
(2) security---encrypting storing accounts information can only obtain decruption key by the smart card that the user holds, and can guarantee that accounts information do not reveal; On the other hand, the user can avoid false fishing website by the URL visit Web website that the present invention preserves;
(3) universality---the general Web website of login that needs all is suitable for, and the while smart card also need not customized especially, only need have the PKI function and get final product.
Description of drawings
Fig. 1 is the sequential relationship synoptic diagram of the generation symmetric key in the method that protection is controlled based on smart card realization network account in the iOS operating system of the present invention.
Fig. 2 is for adding the sequential relationship synoptic diagram of accounts information based on the user in the method for smart card realization network account protection control in the iOS operating system of the present invention.
Fig. 3 is for visiting the sequential relationship synoptic diagram of Web website based on the user in the method for smart card realization network account protection control in the iOS operating system of the present invention.
Embodiment
In order more to be expressly understood technology contents of the present invention, describe in detail especially exemplified by following examples.
See also Fig. 1 to shown in Figure 3; realize the method for network account protection control in this iOS operating system based on smart card; the application program that is mounted with in the electronic equipment of iOS operating system is connected with described smart card by card reader; wherein this method comprises that symmetric key generate to handle operation, user account information and add and handle operation and operation is handled in the control of Web site access; described symmetric key generates handles operation, may further comprise the steps:
(11) described application program is obtained the unique identification UID information of described smart card;
(12) whether described Application inspection has the log-on message file that the unique identification UID information with this smart card is complementary; This log-on message file comprises ciphertext symmetric key data field and accounts information encrypt data territory, the account, information encrypt data territory comprised that several are with the log-on message of described symmetric key encryption, this log-on message comprises Web Site ID information, username and password, the name of this log-on message file is called the unique identification UID of smart card, and the unique identification UID information of described log-on message file and smart card is complementary, and is specially:
The filename of described log-on message file is identical with the unique identification UID of described smart card;
(13) if having, then finish this processing operation; If do not have, then newly-built described log-on message file, and continuation following steps (14);
(14) described smart card produces random number as symmetric key, and encrypts this symmetric key with asymmetric arithmetic and obtain the ciphertext symmetric key, and delivers to described application program;
(15) described application program writes described ciphertext symmetric key in the described log-on message file;
Described user account information is added the processing operation, may further comprise the steps:
(21) system operates according to the user, starts described application program, and is connected with described smart card;
(22) described application program is obtained the unique identification UID information of this smart card;
(23) described application program reads described ciphertext symmetric key from the log-on message file that is complementary with this unique identification UID information, and delivers in the described smart card;
(24) described smart card is deciphered described ciphertext symmetric key by private key and is obtained expressly symmetric key, and delivers to described application program;
(25) described application program loads the Web site list, and is added corresponding user account information according to user's selection operation to operating website;
(26) the described application program user account information of being added with described plaintext symmetric key encryption, and obtain writing in the described log-on message file after the user account ciphertext; This user account information comprises username and password;
Operation is handled in described Web site access control, may further comprise the steps:
(31) system operates according to the user, starts described application program, and is connected with described smart card;
(32) described application program is obtained the unique identification UID information of this smart card;
(33) described application program reads described ciphertext symmetric key from the log-on message file that is complementary with this unique identification UID information, and delivers in the described smart card;
(34) described smart card is deciphered described ciphertext symmetric key by private key and is obtained expressly symmetric key, and delivers to described application program;
(35) described application program is deciphered described accounts information with described plaintext symmetric key, and loads corresponding account tabulation;
(36) described application program obtains corresponding accounts information according to user's selection operation, and obtains the login page code alternately with the Web server in station, resolves the back and inserts corresponding log-on message automatically according to described accounts information;
(37) described application program is operated according to the user and is submitted to corresponding log-on message to the Web server in station.
In the middle of reality is used; the present invention uses smart card that iOS user's network account is protected; core operation is to be installed in the smart card that the application program on the iOS holds by card reader and user to carry out alternately, realizes encrypting storing accounts information and filling login information automatically.
The accounts information encryption protecting method is specific as follows:
(1) accounts information guard method
Accounts information comprises Web site information and login username and the password under the account, and the present invention uses symmetry algorithm protection accounts information, and uses asymmetric arithmetic protection symmetric key.
(a) protection accounts information
The present invention wherein produces symmetric key by smart card at random with symmetric key encryption and decryption accounts information, by application program accounts information is encrypted.
General, smart card all has hard-wired randomizer, can be fixed the random number of length, and the random number of random length can obtain by repeating to get random number splicing shearing.
Be example with the aes algorithm, smart card produces 128bit random number Key PlainAs key, accounts information expressly is Info Plain, ciphertext is Info Cipher, E AESD is encrypted in () expression AES() expression deciphering then has following encryption and decryption process:
Info cipher=E AES(Info plain,Key plain)
Info plain=D AES(Info cipher,Key plain)
Accounts information is kept at this locality with the ciphertext form with encryption key, and obviously encryption key also must be preserved with the ciphertext form and could guarantee accounts information safety.
(b) symmetric key of accounts information is encrypted in protection
Smart card is to encrypt public private key pair encryption and decryption symmetric key.Encryption public private key pair in the smart card is signed and issued and trustship by the third party authority digital authenticating CA of mechanism, guarantees that the public private key pair in each smart card is different; Private key is produced by CA, and is responsible for writing by CA or other trusted authority, then the certificate issuance of corresponding PKI is come out, and the private key that writes is not readable to external world.Be example with the RSA Algorithm, establish n=pq, represent encrypted public key with n, e, p, q and d represent encryption key, and symmetric key expressly is Key Plain, ciphertext is Key Cipher, E RSAD is encrypted in () expression RSA() expression deciphering then has following encryption and decryption process:
Key cipher=E RSA(Key plain)=(Key plain) e?mod?n
Key plain=D RSA(Key cipher)=(Key cipher) d?mod? n
Above encryption and decryption process is all carried out in internal memory, and clear data can be not residual in this locality, even and encrypt data stolen also can't decipher by malice and obtain effective information, realized protection accounts information purpose of safety.
(2) accounts information store method
Accounts information is kept in Web site information file and the log-on message file, is positioned at the application-specific file.
Web site information file is the intrinsic read-only file of application program, and file is made up of some site information, and every site information comprises four data item, and namely ID, URL, title and logon form attribute specifically see also shown in the following table 1.
Table 1.Web site information
Data item Explanation
ID Website numbering hereof increases progressively successively since 1, does not have and repeats
URL Website URL
Title Site name, expressly
The logon form attribute User name, password and the relevant control information of other logins, expressly
The log-on message file is the read-write file that application program generates, and file is filename with smart card unique identification UID, is divided into two data fields, and namely symmetric cryptography and accounts information specifically see also shown in the following table 2.
Table 2. log-on message file
Data field Explanation
Symmetric key Produce for the encryption and decryption accounts information, by smart card public key encryption, ciphertext at random
Accounts information Comprise some by the log-on message of above-mentioned password encryption, ciphertext
Every log-on message comprises three data item, and namely Web Site ID, username and password are specifically as shown in table 3.
Table 3. log-on message
The data item explanation
The Web Site ID is seen Web site information file, by symmetric key encryption, and ciphertext
The user name login username, by symmetric key encryption, ciphertext
The password login password, by symmetric key encryption, ciphertext
Automatically filling login information is specific as follows:
After the user selects to use the affiliated Web website of certain account login, application program Web server in station therewith obtains the login page code alternately, obtain the logon form attribute of this website according to the inquiry of the Web Site ID in log-on message Web site information file, automatically insert page logon form by methods such as Javascript script realization username and password, realize Web website login robotization.Detailed process can be consulted shown in Figure 2.
See also shown in Figure 1ly, the detailed process that generates symmetric key in the method for the present invention is as follows:
After smart card connect to be used, application program can check the log-on message file that whether has with this smart card UID name, if do not have then newly-builtly and write the symmetric key that produces at random, process comprises 3 steps:
Step1---smart card produces random number as symmetric key.
Step2---this smart card uses the asymmetric arithmetic encrypted symmetric key.
Step3---application program writes the log-on message file to the ciphertext symmetric key.
See also again shown in Figure 2, in the method for the present invention the user to add the detailed process of accounts information as follows:
The user needs to add earlier accounts information before using application program to realize automatic filling login information, and process comprises 7 steps:
Step1---user launches application, and connect smart card.
Step2---application program is obtained this smart card UID.
Step3---application program is to read the ciphertext symmetric key in the uniquely identified log-on message file with this UID.
Step4---this smart card private key deciphering obtains the plaintext of this symmetric key.
Step5---application program loads the Web site list, and the user selects respective site to add some username and passwords.
Step6---application program obtains ciphertext and writes this log-on message file with the newly-increased accounts information of this plaintext symmetric key encryption.
Step7---the user closes application program.
See also again shown in Figure 3, in the method for the present invention the user to visit the detailed process of Web website as follows:
For the Web website that in application program, has disposed login username and password, can use the automatic filling login information of application program, process comprises 8 steps:
Step1---user launches application, and connect smart card.
Step2---application program is obtained this smart card UID.
Step3---application program is to read the ciphertext symmetric key in the uniquely identified log-on message file with this UID.
Step4---this smart card private key deciphering obtains this symmetric key expressly.
Step5---application program is with this plaintext symmetric key deciphering accounts information, and the tabulation of loading account.
Step6---the user selects account.
Step7---application program and Web server in station obtain the login page code alternately, resolve back filling login information automatically.
Step8---the user submits log-on message to, and closes application program after browsing end.
Adopted the method that realizes network account protection control in the above-mentioned iOS operating system based on smart card; because it adopts the smart card that has the PKI function as protection equipment; what open; provide safe for iOS user in unsafe network environment; Web website login method easily; and do not need customized especially safety equipment; thereby realized in open network environment, adopting smart card to provide safety as hardware foundation for Apple iOS user; Identity Management and cryptoguard reliably; effectively improved account security; be applicable to various Web websites, stable and reliable working performance; the scope of application is comparatively extensive.Corresponding beneficial effect is specific as follows:
(1) convenience---preserve accounts information in this locality, the user only needs manually to import username and password when initialization, and Web website logon form is filled in automatically by the present invention in the use, and is easy to use;
(2) security---encrypting storing accounts information can only obtain decruption key by the smart card that the user holds, and can guarantee that accounts information do not reveal; On the other hand, the user can avoid false fishing website by the URL visit Web website that the present invention preserves;
(3) universality---the general Web website of login that needs all is suitable for, and the while smart card also need not customized especially, only need have the PKI function and get final product.
In this instructions, the present invention is described with reference to its certain embodiments.But, still can make various modifications and conversion obviously and not deviate from the spirit and scope of the present invention.Therefore, instructions and accompanying drawing are regarded in an illustrative, rather than a restrictive.

Claims (7)

1. realize the method that the network account protection is controlled based on smart card in an iOS operating system; the application program that is mounted with in the electronic equipment of iOS operating system is connected with described smart card by card reader; it is characterized in that; described method comprises that symmetric key generate to handle operation, user account information and add and handle operation and operation is handled in the control of Web site access; described symmetric key generates handles operation, may further comprise the steps:
(11) described application program is obtained the unique identification UID information of described smart card;
(12) whether described Application inspection has the log-on message file that the unique identification UID information with this smart card is complementary;
(13) if having, then finish this processing operation; If do not have, then newly-built described log-on message file, and continuation following steps (14);
(14) described smart card produces random number as symmetric key, and encrypts this symmetric key with asymmetric arithmetic and obtain the ciphertext symmetric key, and delivers to described application program;
(15) described application program writes described ciphertext symmetric key in the described log-on message file;
Described user account information is added the processing operation, may further comprise the steps:
(21) system operates according to the user, starts described application program, and is connected with described smart card;
(22) described application program is obtained the unique identification UID information of this smart card;
(23) described application program reads described ciphertext symmetric key from the log-on message file that is complementary with this unique identification UID information, and delivers in the described smart card;
(24) described smart card is deciphered described ciphertext symmetric key by private key and is obtained expressly symmetric key, and delivers to described application program;
(25) described application program loads the Web site list, and is added corresponding user account information according to user's selection operation to operating website;
(26) the described application program user account information of being added with described plaintext symmetric key encryption, and obtain writing in the described log-on message file after the user account ciphertext;
Operation is handled in described Web site access control, may further comprise the steps:
(31) system operates according to the user, starts described application program, and is connected with described smart card;
(32) described application program is obtained the unique identification UID information of this smart card;
(33) described application program reads described ciphertext symmetric key from the log-on message file that is complementary with this unique identification UID information, and delivers in the described smart card;
(34) described smart card is deciphered described ciphertext symmetric key by private key and is obtained expressly symmetric key, and delivers to described application program;
(35) described application program is deciphered described accounts information with described plaintext symmetric key, and loads corresponding account tabulation;
(36) described application program obtains corresponding accounts information according to user's selection operation, and obtains the login page code alternately with the Web server in station, resolves the back and inserts corresponding log-on message automatically according to described accounts information;
(37) described application program is operated according to the user and is submitted to corresponding log-on message to the Web server in station.
2. realize the method for network account protection control in the iOS operating system according to claim 1 based on smart card, it is characterized in that described log-on message file comprises ciphertext symmetric key data field and accounts information encrypt data territory.
3. realize the method for network account protection control in the iOS operating system according to claim 2 based on smart card, it is characterized in that described accounts information encrypt data territory comprises that several are with the log-on message of described symmetric key encryption.
4. realize the method for network account protection control in the iOS operating system according to claim 3 based on smart card, it is characterized in that described log-on message comprises Web Site ID information, username and password.
5. realize the method for network account protection control in the iOS operating system according to claim 2 based on smart card, it is characterized in that the name of described log-on message file is called the unique identification UID of smart card.
6. realize the method for network account protection control in the iOS operating system according to claim 5 based on smart card, it is characterized in that the unique identification UID information of described log-on message file and smart card is complementary, and is specially:
The filename of described log-on message file is identical with the unique identification UID of described smart card.
7. according to the method that realizes network account protection control in each described iOS operating system in the claim 1 to 6 based on smart card, it is characterized in that described user account information comprises username and password.
CN201310103238.2A 2013-03-27 2013-03-27 IOS operating system realizes, based on smart card, the method that network account protection controls Active CN103235910B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310103238.2A CN103235910B (en) 2013-03-27 2013-03-27 IOS operating system realizes, based on smart card, the method that network account protection controls

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310103238.2A CN103235910B (en) 2013-03-27 2013-03-27 IOS operating system realizes, based on smart card, the method that network account protection controls

Publications (2)

Publication Number Publication Date
CN103235910A true CN103235910A (en) 2013-08-07
CN103235910B CN103235910B (en) 2016-06-22

Family

ID=48883950

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310103238.2A Active CN103235910B (en) 2013-03-27 2013-03-27 IOS operating system realizes, based on smart card, the method that network account protection controls

Country Status (1)

Country Link
CN (1) CN103235910B (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104980332A (en) * 2014-04-14 2015-10-14 深圳市亚汇讯实业有限公司 System and method for remote data management
CN106874800A (en) * 2016-12-22 2017-06-20 北京握奇智能科技有限公司 The access method and system of a kind of smart card device

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040162903A1 (en) * 2002-12-28 2004-08-19 Lg Electronics Inc. Apparatus and method for automatically logging in internet web site
US6834795B1 (en) * 2001-06-29 2004-12-28 Sun Microsystems, Inc. Secure user authentication to computing resource via smart card
CN1627684A (en) * 2003-12-09 2005-06-15 联想(北京)有限公司 Security management method and system for networked computer users
CN1668003A (en) * 2004-03-10 2005-09-14 技嘉科技股份有限公司 Method for filling-in user data automatically using fingerprint identification
CN101815291A (en) * 2010-03-22 2010-08-25 中兴通讯股份有限公司 Method and system for logging on client automatically
CN102495855A (en) * 2011-11-21 2012-06-13 奇智软件(北京)有限公司 Automatic login method and device

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6834795B1 (en) * 2001-06-29 2004-12-28 Sun Microsystems, Inc. Secure user authentication to computing resource via smart card
US20040162903A1 (en) * 2002-12-28 2004-08-19 Lg Electronics Inc. Apparatus and method for automatically logging in internet web site
CN1627684A (en) * 2003-12-09 2005-06-15 联想(北京)有限公司 Security management method and system for networked computer users
CN1668003A (en) * 2004-03-10 2005-09-14 技嘉科技股份有限公司 Method for filling-in user data automatically using fingerprint identification
CN101815291A (en) * 2010-03-22 2010-08-25 中兴通讯股份有限公司 Method and system for logging on client automatically
CN102495855A (en) * 2011-11-21 2012-06-13 奇智软件(北京)有限公司 Automatic login method and device

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
刘彤等: "基于动态口令和智能卡技术的网络游戏身份认证系统", 《第二十次全国计算机安全学术交流会论文集》, 5 August 2005 (2005-08-05), pages 114 - 116 *
焦远东: "账号密码藏身U盘中", 《电脑爱好者》, no. 9, 31 May 2007 (2007-05-31), pages 45 *

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104980332A (en) * 2014-04-14 2015-10-14 深圳市亚汇讯实业有限公司 System and method for remote data management
CN106874800A (en) * 2016-12-22 2017-06-20 北京握奇智能科技有限公司 The access method and system of a kind of smart card device
CN106874800B (en) * 2016-12-22 2023-06-23 北京握奇智能科技有限公司 Access method and system of smart card device

Also Published As

Publication number Publication date
CN103235910B (en) 2016-06-22

Similar Documents

Publication Publication Date Title
Ma et al. Security flaws in two improved remote user authentication schemes using smart cards
US9935925B2 (en) Method for establishing a cryptographically protected communication channel
EP2639997B1 (en) Method and system for secure access of a first computer to a second computer
Choi et al. A mobile based anti-phishing authentication scheme using QR code
US20150349960A1 (en) Two factor authentication using a protected pin-like passcode
US9372987B1 (en) Apparatus and method for masking a real user controlling synthetic identities
KR101744747B1 (en) Mobile terminal, terminal and method for authentication using security cookie
US10250589B2 (en) System and method for protecting access to authentication systems
CN107453880B (en) Cloud data secure storage method and system
GB2522445A (en) Secure mobile wireless communications platform
Amin et al. Remote access control mechanism using rabin public key cryptosystem
US9917694B1 (en) Key provisioning method and apparatus for authentication tokens
KR101358375B1 (en) Prevention security system and method for smishing
US10764260B2 (en) Distributed processing of a product on the basis of centrally encrypted stored data
US10341110B2 (en) Securing user credentials
CN106257859A (en) A kind of password using method
Al-Attab et al. Authentication scheme for insecure networks in cloud computing
Tsague et al. An advanced mutual-authentication algorithm using 3DES for smart card systems
CN103235910A (en) Method achieving network account protection control based on smart card in iOS operation system
WO2018114574A1 (en) Method for secure management of secrets in a hierarchical multi-tenant environment
Wang et al. Matrix barcode based secure authentication without trusting third party
Hsieh et al. A time and location information assisted OTP scheme
Elmufti et al. Anonymous authentication for mobile single sign-on to protect user privacy
Attia et al. E-mail systems in cloud computing environment privacy, trust and security challenges
Abhishek et al. A comprehensive study on two-factor authentication with one time passwords

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant