Title:
USER PASSWORD MANAGEMENT METHOD AND SERVER
Document Type and Number:
WIPO Patent Application WO/2018/024056
Kind Code:
A1
Abstract:
Embodiments of the present invention relate to the field of computers, and disclose a user password management method and server. The method comprises: upon receiving a user registration request including a user ID and password, generating, according to a salt value, salt value extension information, and joining, according to a predetermined order, the salt value and the salt value extension information to be salt value information; and after the password is encrypted, simply associatively storing the user ID and twice-encrypted second ciphertext without storing the salt value. The present invention addresses the problem of the prior art in which a large storage space is occupied on a server for storing salt values. In addition, since salt values are not required to be stored, the present invention prevents an attacker from stealing a salt value and establishing a rainbow table attack to crack a user password.
Inventors:
OU DUANHAO (CN)
Application Number:
PCT/CN2017/090878
Publication Date:
February 08, 2018
Filing Date:
June 29, 2017
Export Citation:
Assignee:
HUAWEI TECH CO LTD (CN)
International Classes:
H04L9/14
Foreign References:
CN105812357A | 2016-07-27 | |||
CN105721390A | 2016-06-29 | |||
CN102045169A | 2011-05-04 | |||
US9021269B2 | 2015-04-28 |
Download PDF:
Previous Patent: UPLINK DATA TRANSMISSION METHOD AND APPARATUS
Next Patent: METHOD AND APPARATUS FOR ACCESSING SERVICE
Next Patent: METHOD AND APPARATUS FOR ACCESSING SERVICE