WO2016188353A1 - 网络监控设备及重置其密码的方法、装置和***、服务器 - Google Patents

网络监控设备及重置其密码的方法、装置和***、服务器 Download PDF

Info

Publication number
WO2016188353A1
WO2016188353A1 PCT/CN2016/082472 CN2016082472W WO2016188353A1 WO 2016188353 A1 WO2016188353 A1 WO 2016188353A1 CN 2016082472 W CN2016082472 W CN 2016082472W WO 2016188353 A1 WO2016188353 A1 WO 2016188353A1
Authority
WO
WIPO (PCT)
Prior art keywords
password
reset
monitoring device
network monitoring
feature code
Prior art date
Application number
PCT/CN2016/082472
Other languages
English (en)
French (fr)
Inventor
斯鲁杰
Original Assignee
杭州海康威视数字技术股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 杭州海康威视数字技术股份有限公司 filed Critical 杭州海康威视数字技术股份有限公司
Priority to EP16799242.9A priority Critical patent/EP3300328B1/en
Priority to US15/576,667 priority patent/US10831879B2/en
Publication of WO2016188353A1 publication Critical patent/WO2016188353A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0442Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/45Structures or tools for the administration of authentication
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2131Lost password, e.g. recovery of lost or forgotten passwords

Definitions

  • the present invention relates to the field of network security, and in particular to a network monitoring device and a method, device, system and server for resetting the password thereof.
  • Each network monitoring device has a fixed serial number that identifies the uniqueness of the device. Using this serial number and a fixed algorithm, a password to restore the default password is calculated.
  • the device serial number is sent to the reset password server, and the server calculates a password by using an algorithm.
  • the password is then provided to the user and entered into the device.
  • the device also calculates the password using the serial number. If the two passwords are the same, the verification passes and the password is restored to the factory defaults.
  • Disadvantage 1 The device serial number exists on the device label, and the device serial number can also be obtained by accessing the device.
  • the fixed encryption algorithm exists in the device. As long as one device is cracked, the algorithm will leak. With serial numbers and algorithms, all devices that use this algorithm have security risks.
  • Disadvantage 2 If the device has a default password, the default password is the public password. Many users' awareness of network security is not high. It is not a security risk to modify the default password to a secure password that you have set.
  • the embodiment of the invention provides a network monitoring device and a method, a device, a system and a server for resetting the password, so as to at least solve the technical problem of low security in the process of restoring the default password and resetting the password in the prior art.
  • a method for resetting a password of a network monitoring device includes: generating a first feature code according to the encrypted content; transmitting the first feature code to a server; and receiving a password from the server Resetting the password and the reset password from the client, wherein after receiving the first signature, the server encrypts the first signature with the first key, obtains the password reset password, and returns The dense Code resetting the password; and decrypting the password reset password with the second key, and resetting the password of the network monitoring device by using the reset password, wherein the first key and the second secret
  • the key is a pair of keys in an asymmetric encryption algorithm.
  • the method before transmitting the first feature code to the server, the method further includes: setting an effective time of the first feature code, receiving a password reset password from the server, and resetting a password from the client Thereafter, the method further includes: determining whether the password reset password is received within the valid time, wherein, in the case that it is determined that the password reset password is received within the valid time, The second key decrypts the password reset password and uses the reset password to reset the password of the network monitoring device.
  • decrypting the password reset password by using the second key, and resetting the password of the network monitoring device by using the reset password comprises: decrypting the password reset password by using the second key, and obtaining a second feature code; determining whether the second feature code is identical to the first feature code; and using the reset password if it is determined that the second feature code is the same as the first feature code Reset the password of the network monitoring device.
  • the method further includes: determining whether the reset password is valid, wherein determining that the reset password is valid In the case that the password of the network monitoring device is reset by using the reset password, and a first reset result is generated, or if it is determined that the reset password is invalid, the first reset result is generated. Not the same second reset result.
  • a method for resetting a password of a network monitoring device includes: receiving a first feature code from the network monitoring device, wherein the network monitoring device generates a location according to the encrypted content Decoding a first feature code; encrypting the first feature code with a first key to obtain a password reset password; and transmitting the password reset password to the network monitoring device, wherein the network monitoring device receives In the case of the password reset password and the reset password from the client, the password is reset using the second key, and the password of the network monitoring device is reset by using the reset password, A key and the second key are a pair of keys in an asymmetric encryption algorithm.
  • an apparatus for resetting a password of a network monitoring device comprising: a generating unit, configured to generate a first feature code according to the encrypted content; and a sending unit, configured to send the first feature a code to server; a receiving unit, configured to receive a password reset password from the server and a reset password from the client, wherein the server encrypts the first key after receiving the first feature code Determining the first signature, obtaining the password reset password, and returning the password reset password; and a reset unit, configured to decrypt the password reset by using the second key, and using the reset password Setting a password of the network monitoring device, where the first key and the second key are a pair of keys in an asymmetric encryption algorithm.
  • the device further includes: a setting unit, configured to set an effective time of the first feature code before the sending unit sends the first feature code to the server; and a first determining unit, configured to After receiving the password reset password from the server and the reset password from the client, the receiving unit determines whether the password reset password is received within the valid time, and the reset unit includes: a first reset a module, configured to: when the first determining unit determines that the password reset password is received within the valid time, decrypt the password reset password by using a second key, and use the reset The password resets the password of the network monitoring device.
  • the resetting unit includes: a decrypting module, configured to decrypt the password reset password by using the second key, to obtain a second feature code; and a determining module, configured to determine the second feature code and the Whether the first feature code is the same; and the second reset module, configured to reset by using the reset password if the determining module determines that the second feature code is the same as the first feature code The password of the network monitoring device.
  • the device further includes: a second determining unit, configured to determine, after the receiving unit receives the password reset password from the server and the reset password from the client, whether the reset password is valid, where And in the case that the second determining unit determines that the reset password is valid, the reset unit resets a password of the network monitoring device by using the reset password, and generates a first reset result, or When the second determining unit determines that the reset password is invalid, the reset unit generates a second reset result that is different from the first reset result.
  • a second determining unit configured to determine, after the receiving unit receives the password reset password from the server and the reset password from the client, whether the reset password is valid, where And in the case that the second determining unit determines that the reset password is valid, the reset unit resets a password of the network monitoring device by using the reset password, and generates a first reset result, or When the second determining unit determines that the reset password is invalid, the reset unit generates a second reset result that is different from the first reset result.
  • a network monitoring device including any device for resetting a network monitoring device password provided by the foregoing content of the present invention.
  • a server including: a receiver, configured to receive a first feature code from a network monitoring device, where the network monitoring device generates the first feature according to the encrypted content And a cipher for encrypting the first feature code with a first key to obtain a password reset password, wherein the first key and the second key are a pair of asymmetric cryptographic algorithms a key; and a sender, configured to send the password reset password to the network monitoring device, wherein the network monitoring device receives the password reset password and a reset password from the client, Decrypting the password reset password with a second key, and resetting a password of the network monitoring device by using the reset password, where the first key and the second key are in an asymmetric encryption algorithm A pair of keys.
  • a system for resetting a password of a network monitoring device including: a client, configured to send a reset password to a network monitoring device; and a server, configured to receive the first feature code, and utilize The first key encrypts the first feature code, obtains a password reset password, and sends the password reset password to the network monitoring device; and a network monitoring device, configured to generate the first feature code according to the encrypted content And decrypting the password reset with the second key if the password reset password and the reset password are received a password, and a password for resetting the network monitoring device by using the reset password, wherein the first key and the second key are a pair of keys in an asymmetric encryption algorithm.
  • the first feature code is generated according to the encrypted content; the first feature code is sent to the server; the password reset password from the server and the reset password from the client are received, wherein the server After receiving the first feature code, encrypting the first feature code with a first key, obtaining the password reset password, and returning the password reset password; and decrypting the second key by using the second key
  • the password resets the password and resets the password of the network monitoring device by using the reset password, wherein the first key and the second key are a pair of keys in an asymmetric encryption algorithm.
  • the data encryption in the password reset process is performed by using an asymmetric encryption algorithm.
  • the second key in the asymmetric encryption algorithm is stored in the network monitoring device
  • the first key in the asymmetric encryption algorithm is stored in the password server.
  • the second key stored in the network monitoring device is a public key, and the public key itself is a publicly disclosed key
  • the security of the entire reset password mechanism does not depend on the network monitoring device.
  • the security of the password server and the private key in the password service is used to ensure the security of the password reset mechanism, and the problem of lower security in the process of restoring the default password and resetting the password in the prior art is solved, thereby improving The effect of network monitoring device security.
  • FIG. 1 is a flow chart of a method of resetting a network monitoring device password according to an embodiment of the present invention
  • FIG. 2 is a timing diagram of an alternative method of resetting a network monitoring device password in accordance with a preferred embodiment of the present invention
  • FIG. 3 is a flow chart of a method for resetting a password of a network monitoring device according to still another embodiment of the present invention.
  • FIG. 4 is a schematic diagram of an apparatus for resetting a password of a network monitoring device according to an embodiment of the present invention
  • FIG. 5 is a schematic diagram of a server according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of a system for resetting a network monitoring device according to an embodiment of the present invention.
  • Network monitoring equipment Security monitoring equipment with network modules that can be accessed by IP address, including DVR, DVS, NVR, CVR, IPC, transmission and display equipment.
  • Signature A string generated by the device based on parameters such as the serial number, time value, key version, and random number.
  • Password According to the key version in the signature, find the corresponding asymmetric encryption algorithm private key, and use the asymmetric encryption algorithm private key to encrypt the signature to obtain the password.
  • Asymmetric encryption algorithm This type of algorithm has a pair of public and private keys, the public key is publicly disclosed, and the private key is kept by the producer (not external). The data is encrypted using the public key during encryption. The encrypted data can only be decrypted using the private key.
  • an embodiment of a method of resetting a network monitoring device password is provided. It is noted that the steps illustrated in the flowchart of the drawings may be performed in a computer system such as a set of computer executable instructions. And, although the logical order is shown in the flowcharts, in some cases the steps shown or described may be performed in a different order than the ones described herein.
  • FIG. 1 is a flowchart of a method for resetting a password of a network monitoring device according to an embodiment of the present invention. As shown in FIG. 1 , the method mainly includes the following steps S102 to S108:
  • Step S102 generating a first feature code according to the encrypted content.
  • the encrypted content may include an identification number and a random value of the network monitoring device, where the identification number may be a device serial number of the network monitoring device.
  • Step S104 sending the first feature code to the server.
  • the client may obtain the first feature code from the network monitoring device, and then the client sends the first feature code to the password server, that is, network monitoring.
  • the device sends the first signature to the server through the client.
  • the network monitoring device can also directly send the first signature to the server.
  • the client and the network monitoring device may use local area network communication for data exchange, and the client may obtain the first feature code from the network monitoring device by using the multicast communication method.
  • the client and the server can exchange data through network communication, and can also exchange data through other offline channels, so that the password reset of the network monitoring device can be normally performed regardless of whether the network monitoring device is connected to the Internet.
  • Step S106 receiving a password reset password from the server and a reset password from the client, wherein after receiving the first signature, the server encrypts the first signature with the first key, obtains a password reset password, and returns Password reset password.
  • the first password may be a private key in the asymmetric encryption algorithm
  • the server receives the first feature code from the network monitoring device forwarded by the client, or receives the direct monitoring by the network.
  • the first signature sent by the device the first signature is encrypted by using an asymmetric algorithm private key
  • a password reset password is generated
  • the password reset password is sent to the network monitoring device, or sent to the client first.
  • the password reset password is then transmitted by the client to the network monitoring device along with the reset password (ie, the new password). Since the first feature code is randomly generated, the first feature code generated by the different network monitoring device is also different.
  • the password reset password obtained by using the first feature code can only be generated in the first feature code. Effective on the network monitoring device, it enables targeted password reset.
  • Step S108 decrypting the password reset password with the second key, and resetting the password of the network monitoring device by using the reset password, wherein the first key and the second key are a pair of keys in the asymmetric encryption algorithm.
  • the second password may be a public key in an asymmetric encryption algorithm, and after receiving the password reset password and resetting the password, the network monitoring device decrypts the password reset password by using an asymmetric algorithm public key. After successful decryption, reset your password with the reset password.
  • the method for resetting the password of the network monitoring device uses the asymmetric encryption algorithm to encrypt the data in the password reset process, because the asymmetric algorithm public key is stored in the network monitoring device, and the asymmetric algorithm private key Saved in the password server. Since the key in the network monitoring device itself is a publicly disclosed key, the security of the entire reset password mechanism does not depend on the network monitoring device. The security of the password server and the private key in the password service is used to ensure the security of the password reset mechanism, and the problem of lower security in the process of restoring the default password and resetting the password in the prior art is solved, thereby improving Network monitoring equipment security Effect.
  • FIG. 2 is a sequence diagram of a method for resetting a password of a network monitoring device according to a preferred embodiment of the present invention. As shown in FIG. 2, the method mainly includes the following steps S201 to S209:
  • the client may send a triggering instruction to the network monitoring device to trigger the network monitoring device to generate the first feature code according to the encrypted content.
  • the network monitoring device returns a signature.
  • step S202 and step S203 are equivalent to step S104 described above, that is, the network monitoring device feeds back the first feature code to the client, and then the client feeds back to the password server.
  • the network monitoring device sets the effective time for the first feature code before feeding the first feature code to the client.
  • the network monitoring device can directly send the first feature code directly to the server.
  • the server converts the signature into a password reset password by using an asymmetric algorithm private key.
  • the server transmits a password reset password to the client.
  • the client transmits the password reset password and the reset password to the network monitoring device.
  • step S204, step S205, and step S206 are equivalent to the foregoing step S106, that is, for the case of communicating by the client, after the client forwards the first feature code from the network monitoring device to the server, the server utilizes an asymmetric algorithm.
  • the private key encrypts the first signature, generates a password reset password, and sends the password reset password to the client, and then the client transmits the password reset password along with the reset password (ie, the new password) to the client.
  • Network monitoring equipment is, for the case of communicating by the client, after the client forwards the first feature code from the network monitoring device to the server.
  • the server utilizes an asymmetric algorithm.
  • the private key encrypts the first signature, generates a password reset password, and sends the password reset password to the client, and then the client transmits the password reset password along with the reset password (ie, the new password) to the client.
  • the reset password ie, the new password
  • the network monitoring device determines whether the password reset password is valid.
  • the network monitoring device determines whether the password reset password is received within the valid time. Wherein, in the case that it is determined that the password reset password is received within the valid time, the password of the network monitoring device is reset by using the reset password. Accordingly, if it is determined that the password reset password is not received within the valid time, it is determined that the password reset has failed.
  • the effective time of the first feature code is controlled by the network monitoring device, so that the corresponding password reset password is valid for a specified period of time. Avoid password reset Password protection is incorrect and the password of the network monitoring device is reset again. Achieve improved password reset stability.
  • the network monitoring device determines whether the reset password is valid.
  • the network monitoring device determines whether the reset password is valid. Specifically, it is mainly determining whether the level of the reset password meets the level requirement, and determining the weight When the password is valid, that is, when it is determined that the level of the reset password reaches the level requirement, the password of the network monitoring device is reset by using the reset password.
  • the user By judging the validity of the reset password, the user is guided to set a password with a relatively high security level, which avoids the security problem caused by the user using the weak password to reset the password, thereby achieving the effect of further improving the security of the network monitoring device. .
  • the password of the network monitoring device is reset by using the reset password, and a first reset result may be generated, where the first reset result indicates that the password reset is successful, or When it is determined that the reset password is invalid, a second reset result that is different from the first reset result is generated, and the second reset result indicates that the password reset fails.
  • the network monitoring device decrypts the password reset password by using the second key, obtains the second feature code, and determines whether the second feature code is the same as the first feature code, where When it is determined that the second feature code is the same as the first feature code, the password of the network monitoring device is reset by using the reset password.
  • the first feature code generated by the different network monitoring device is also different.
  • the password reset password obtained by using the first feature code can only be generated in the first feature code. It is effective on the network monitoring device.
  • FIG. 3 is a flowchart of a method for resetting a password of a network monitoring device according to another embodiment of the present invention. As shown in FIG. 3, the method mainly includes the following steps S302 to S306:
  • the network monitoring device when the network monitoring device is shipped from the factory, an asymmetric algorithm public key is reserved in the device, and the corresponding asymmetric algorithm private key is saved to the cryptographic server.
  • the network monitoring device When the user needs to reset the password of the network monitoring device, the network monitoring device generates a first feature code according to the encrypted content, and then sends the first feature code to the service through the client. Device.
  • the network monitoring device can also directly send the first signature to the server.
  • the encrypted content includes an identification number and a random value of the network monitoring device, and the identification number may be a device serial number of the network monitoring device.
  • the server after receiving the first feature code, the server encrypts the first feature code with the first key, obtains a password reset password, and returns a password reset password. That is, after the client forwards the first signature from the network monitoring device to the server, the server encrypts the first signature using the asymmetric algorithm private key to generate a password reset password.
  • S306. Send a password reset password to the network monitoring device, where the network monitoring device decrypts the password and uses the second key to decrypt the password and receives the reset password when receiving the password reset password and the reset password from the client.
  • the password resets the password of the network monitoring device, and the first key and the second key are a pair of keys in the asymmetric encryption algorithm.
  • the server may send the password reset password to the client, and then the client transmits the password reset password to the network monitoring device along with the reset password (ie, the new password). Since the first feature code is randomly generated, the first feature code generated by the different network monitoring device is also different. Thus, the password reset password obtained by using the first feature code can only be generated in the first feature code. Effective on the network monitoring device, it enables targeted password reset. After receiving the password reset password and resetting the password, the network monitoring device resets the password of the network monitoring device according to the password reset password and the reset password.
  • the method for resetting the password of the network monitoring device uses the asymmetric encryption algorithm to encrypt the data in the password reset process, because the asymmetric algorithm public key is stored in the network monitoring device, and the asymmetric algorithm private key Saved in the password server. Since the key in the network monitoring device itself is a publicly disclosed key, the security of the entire reset password mechanism does not depend on the network monitoring device. The security of the password server and the private key in the password service is used to ensure the security of the password reset mechanism, and the problem of lower security in the process of restoring the default password and resetting the password in the prior art is solved, thereby improving The effect of network monitoring device security.
  • FIG. 4 is a schematic diagram of an apparatus for resetting a password of a network monitoring device according to an embodiment of the present invention.
  • the apparatus mainly includes a generating unit 110, a sending unit 120, a receiving unit 130, and a reset unit 140, where:
  • the generating unit 110 is configured to generate a first feature code according to the encrypted content.
  • the encrypted content may include an identification number and a random value of the network monitoring device, where the identification number may be a device serial number of the network monitoring device.
  • the sending unit 120 is configured to send the first feature code to the server.
  • the client may obtain the first feature code from the network monitoring device, and then the client sends the first feature code to the password server, that is, resets.
  • the transmitting unit 120 of the device of the network monitoring device transmits the first feature code to the server through the client.
  • the network monitoring device can also directly send the first signature to the server.
  • the client and the sending unit 120 can use local area network communication for data exchange, and the client can obtain the first feature code from the network monitoring device by using the multicast communication mode.
  • the client and the server can exchange data through network communication, and can also exchange data through other offline channels, so that the password reset of the network monitoring device can be normally performed regardless of whether the network monitoring device is connected to the Internet.
  • the receiving unit 130 is configured to receive a password reset password from the server and a reset password from the client, wherein after receiving the first signature, the server encrypts the first signature with the first key to obtain a password reset password. And return the password reset password.
  • the first password may be a private key in the asymmetric encryption algorithm
  • the server receives the first feature code from the network monitoring device forwarded by the client, or receives the direct monitoring by the network.
  • the first signature sent by the device the first signature is encrypted by using an asymmetric algorithm private key
  • a password reset password is generated
  • the password reset password is sent to the network monitoring device, or sent to the client first.
  • the password reset password is then transmitted by the client to the network monitoring device along with the reset password (ie, the new password). Since the first feature code is randomly generated, the first feature code generated by the different network monitoring device is also different.
  • the password reset password obtained by using the first feature code can only be generated in the first feature code. Effective on the network monitoring device, it enables targeted password reset.
  • the reset unit 140 is configured to decrypt the password reset password by using the second key, and reset the password of the network monitoring device by using the reset password, where the first key and the second key are a pair of asymmetric encryption algorithms. Key.
  • the second password may be a public key in an asymmetric encryption algorithm, and after receiving the password reset password and resetting the password, the network monitoring device decrypts the password reset password by using an asymmetric algorithm public key. After successful decryption, reset your password with the reset password.
  • the device for resetting the password of the network monitoring device performs data encryption in the password reset process by using an asymmetric encryption algorithm.
  • the asymmetric algorithm public key is stored in the network monitoring device
  • the asymmetric algorithm private key is stored in the network monitoring device. Saved in the password server. Since the key in the network monitoring device itself is a publicly disclosed key, the security of the entire reset password mechanism does not depend on the network monitoring device.
  • the security of the password server and the private key in the password service is used to ensure the security of the password reset mechanism, and the problem of lower security in the process of restoring the default password and resetting the password in the prior art is solved, thereby improving Network monitoring equipment security Effect.
  • the apparatus for resetting the network monitoring device further includes a setting unit and a first determining unit, where the reset unit 140 includes a first reset module, where the setting unit is configured to send the first in the sending unit 120.
  • the reset unit 140 includes a first reset module
  • the setting unit is configured to send the first in the sending unit 120.
  • the first determining unit is configured to determine whether the receiving time is received within the valid time after the receiving unit 130 receives the password reset password from the server and the reset password from the client Go to the password reset password.
  • the first reset module is configured to: when the first determining unit determines that the password reset password is received within the valid time, decrypt the password reset password by using the second key, and reset the network monitoring by using the reset password The password for the device.
  • the corresponding password reset password is valid for a specified period of time. Avoid password reset Password protection is incorrect and the password of the network monitoring device is reset again. Achieve improved password reset stability.
  • the reset unit 140 further includes a decryption module, a determination module, and a second reset module, wherein the decryption module is configured to decrypt the password reset password by using the second key to obtain a second signature; the determining module is configured to determine Whether the second signature is the same as the first signature; the second reset module is configured to reset the password of the network monitoring device by using the reset password if the determining module determines that the second signature is the same as the first signature.
  • the first feature code generated by the different network monitoring device is also different.
  • the password reset password obtained by using the first feature code can only be generated in the first feature code. It is effective on the network monitoring device.
  • the apparatus for resetting the network monitoring device provided by the embodiment of the present invention further includes a second determining unit, configured to receive, at the receiving unit 130, a password reset password from the server and a reset from the client. After the password is determined, it is determined whether the reset password is valid.
  • the reset unit 140 determines whether the level of the reset password meets the level requirement, wherein, when the second determining unit determines that the reset password is valid, that is, when the reset is determined When the level of the password reaches the level requirement, the reset unit 140 resets the password of the network monitoring device by using the reset password, and generates a first reset result, the first reset result indicating that the password reset is successful, or in the second When the determining unit determines that the reset password is invalid, the reset unit 140 generates a second reset result that is different from the first reset result, and the second reset result indicates that the password reset fails.
  • the user By judging the validity of the reset password, the user is guided to set a password with a relatively high security level, which avoids the security problem caused by the user using the weak password to reset the password, thereby achieving the effect of further improving the security of the network monitoring device. .
  • the embodiment of the present invention further provides a network monitoring device, which includes any device for resetting the password of the network monitoring device provided by the foregoing content in the embodiment of the present invention.
  • FIG. 5 is a schematic diagram of a server according to an embodiment of the present invention.
  • the server mainly includes a receiver 310, an encryptor 320, and a transmitter 330, where:
  • the receiver 310 is configured to receive a first feature code from the network monitoring device, where the network monitoring device generates the first feature code according to the encrypted content.
  • an asymmetric algorithm public key is reserved in the device, and the corresponding asymmetric algorithm private key is saved to the cryptographic server.
  • the network monitoring When the user needs to reset the password of the network monitoring device, the network monitoring generates a first feature code according to the first key, and then sends the first feature code to the receiver 310 of the server through the client.
  • the encrypted content includes an identification number and a random value of the network monitoring device, and the identification number may be a device serial number of the network monitoring device.
  • the encryptor 320 is configured to encrypt the first feature code with the first key to obtain a password reset password.
  • the encryptor 320 encrypts the first feature code with the first key, obtains a password reset password, and returns a password reset password. That is, after the client forwards the first signature from the network monitoring device to the server, the server encrypts the first signature using the asymmetric algorithm private key to generate a password reset password.
  • the transmitter 330 is configured to send a password reset password to the network monitoring device, where the network monitoring device decrypts the password reset password by using the second key, when receiving the password reset password and the reset password from the client, and The password of the network monitoring device is reset by using a reset password, and the first key and the second key are a pair of keys in the asymmetric encryption algorithm.
  • the sender 330 may send the password reset password to the client, and then the client transmits the password reset password to the network monitoring device along with the reset password (ie, the new password). Since the first feature code is randomly generated, the first feature code generated by the different network monitoring device is also different. Thus, the password reset password obtained by using the first feature code can only be generated in the first feature code. Effective on the network monitoring device, it enables targeted password reset. After receiving the password reset password and resetting the password, the network monitoring device resets the password of the network monitoring device according to the password reset password and the reset password.
  • the server provided by the embodiment of the present invention performs data encryption in the password reset process by using an asymmetric encryption algorithm. Since the asymmetric algorithm public key is stored in the network monitoring device, the asymmetric algorithm private key is stored in the password server. Since the key in the network monitoring device itself is a publicly disclosed key, the security of the entire reset password mechanism does not depend on the network monitoring device. The security of the password reset mechanism is ensured by using the security of the private key in the password server and the password service, and the process of restoring the default password and resetting the password in the prior art is solved. The problem of lower security, which in turn achieves the effect of improving the security of network monitoring equipment.
  • FIG. 6 is a schematic diagram of a system for resetting a network monitoring device according to an embodiment of the present invention. As shown in FIG. 6, the system mainly includes a network monitoring device 100. , client 200 and server 300, wherein:
  • the network monitoring device 100 is configured to generate a first feature code according to the encrypted content.
  • the encrypted content may include an identification number and a random value of the network monitoring device 100, and the identification number may be a device serial number of the network monitoring device 100.
  • the client 200 can be used to obtain the first feature code from the network monitoring device 100, and then the first feature code is sent by the client 200 to the password server 300, ie, The network monitoring device 100 transmits the first feature code to the server 300 through the client 200.
  • the server 300 is configured to receive the first feature code, encrypt the first feature code with the first key, obtain a password reset password, and send the password reset password to the network monitoring device 100.
  • the first password may be a private key in the asymmetric encryption algorithm
  • the server 300 encrypts the first signature by using an asymmetric algorithm private key to generate a password.
  • the password is reset and the password reset password is transmitted to the network monitoring device 100, or the password reset password is sent to the client 200, and the password reset password and reset password (ie, new password) are then used by the client 200. Transferred to the network monitoring device 100 together. Since the first feature code is randomly generated, the first feature code generated by the different network monitoring device 100 is also different. Thus, the password reset password obtained by using the first feature code can only be generated in the first feature code.
  • the network monitoring device 100 is effective, and the password reset can be performed in a targeted manner.
  • the data exchange between the client 200 and the network monitoring device 100 can be performed by using the local area network communication, and the client 200 can obtain the first feature code from the network monitoring device 100 by using the multicast communication mode.
  • the client 200 and the server 300 can exchange data through network communication, and can also exchange data through other offline channels, so that the password reset of the network monitoring device can be normally performed regardless of whether the network monitoring device 100 accesses the Internet.
  • the system for resetting the password of the network monitoring device performs data encryption in the password reset process by using an asymmetric encryption algorithm.
  • the asymmetric algorithm public key is stored in the network monitoring device
  • the asymmetric algorithm private key is stored in the network monitoring device. Saved in the password server. Since the key in the network monitoring device itself is a publicly disclosed key, the security of the entire reset password mechanism does not depend on the network monitoring device.
  • the security of the password server and the private key in the password service is used to ensure the security of the password reset mechanism, and the problem of lower security in the process of restoring the default password and resetting the password in the prior art is solved, thereby improving Network monitoring equipment security Effect.
  • the disclosed technical contents may be implemented in other manners.
  • the device embodiments described above are only schematic.
  • the division of the unit may be a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or may be Integrate into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, unit or module, and may be electrical or otherwise.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention which is essential or contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer device (which may be a personal computer, server or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a removable hard disk, a magnetic disk, or an optical disk, and the like. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明公开了一种网络监控设备及重置其密码的方法、装置和***、服务器。其中,重置网络监控设备密码的方法包括:根据加密内容生成第一特征码;发送第一特征码至服务器;接收来自服务器的密码重置口令和来自客户端的重置密码,其中,服务器在接收到第一特征码之后,采用第一密钥加密第一特征码,得到密码重置口令,并返回密码重置口令;以及采用第二密钥解密密码重置口令,并利用重置密码重置网络监控设备的密码,其中,第一密钥和第二密钥为非对称加密算法中的一对密钥。通过本发明,解决了现有技术中恢复默认密码、重置密码过程中的安全性较低的问题,进而达到了提高网络监控设备安全性的效果。

Description

网络监控设备及重置其密码的方法、装置和***、服务器 技术领域
本发明涉及网络安全领域,具体而言,涉及一种网络监控设备及重置其密码的方法、装置和***、服务器。
背景技术
每一个网络监控设备有一个固定序列号,用来标识设备的唯一性。利用这个序列号和一种固定的算法,计算得到一个恢复默认密码的口令。
用户需要恢复默认密码时,将设备序列号发送给重置密码服务器,服务器用算法计算得出一个口令。再将口令提供给用户并输入到设备中。设备也用序列号计算得出口令。如果两个口令相同,则验证通过,此时密码恢复到出厂默认值。
上述对网络监控设备进行密码重置的方法存在以下缺点:
缺点一:设备序列号在设备标签上就存在,也可以通过访问设备得到设备序列号。而固定的加密算法又存在设备中,只要有一台设备被破解,就会造成算法泄露。有了序列号和算法,所有采用该算法的设备,都有安全风险。
缺点二:如果设备有默认密码,那默认密码就是公开的密码。很多用户的网络安全意识还不高。不会把默认密码修改成自己设定的一个安全密码,这也是一种安全隐患。
针对上述的问题,目前尚未提出有效的解决方案。
发明内容
本发明实施例提供了一种网络监控设备及重置其密码的方法、装置和***、服务器,以至少解决现有技术中恢复默认密码、重置密码过程中的安全性较低的技术问题。
根据本发明实施例的一个方面,提供了一种重置网络监控设备密码的方法,包括:根据加密内容生成第一特征码;发送所述第一特征码至服务器;接收来自所述服务器的密码重置口令和来自客户端的重置密码,其中,所述服务器在接收到所述第一特征码之后,采用第一密钥加密所述第一特征码,得到所述密码重置口令,并返回所述密 码重置口令;以及采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
进一步地,在发送所述第一特征码至服务器之前,所述方法还包括:设置所述第一特征码的有效时间,在接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,所述方法还包括:判断是否在所述有效时间内接收到所述密码重置口令,其中,在判断出在所述有效时间内接收到所述密码重置口令的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码。
进一步地,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码包括:采用所述第二密钥解密所述密码重置口令,得到第二特征码;判断所述第二特征码与所述第一特征码是否相同;以及在判断出所述第二特征码与所述第一特征码相同的情况下,利用所述重置密码重置所述网络监控设备的密码。
进一步地,在接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,所述方法还包括:判断所述重置密码是否有效,其中,在判断出所述重置密码有效的情况下,利用所述重置密码重置所述网络监控设备的密码,并生成第一重置结果,或在判断出所述重置密码无效的情况下,生成与所述第一重置结果不相同的第二重置结果。
根据本发明实施例的又一个方面,提供了一种重置网络监控设备密码的方法,包括:接收来自所述网络监控设备的第一特征码,其中,所述网络监控设备根据加密内容生成所述第一特征码;利用第一密钥加密所述第一特征码,得到密码重置口令;以及发送所述密码重置口令至所述网络监控设备,其中,所述网络监控设备在接收到所述密码重置口令和来自客户端的重置密码的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
根据本发明实施例的又一个方面,提供了一种重置网络监控设备密码的装置,包括:生成单元,用于根据加密内容生成第一特征码;发送单元,用于发送所述第一特征码至服务器;接收单元,用于接收来自所述服务器的密码重置口令和来自客户端的重置密码,其中,所述服务器在接收到所述第一特征码之后,采用第一密钥加密所述第一特征码,得到所述密码重置口令,并返回所述密码重置口令;以及重置单元,用于采用第二密钥解密所述密码重置,并利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
进一步地,所述装置还包括:设置单元,用于在所述发送单元发送所述第一特征码至服务器之前,设置所述第一特征码的有效时间;第一判断单元,用于在所述接收单元接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,判断是否在所述有效时间内接收到所述密码重置口令,所述重置单元包括:第一重置模块,用于在所述第一判断单元判断出在所述有效时间内接收到所述密码重置口令的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码。
进一步地,所述重置单元包括:解密模块,用于采用所述第二密钥解密所述密码重置口令,得到第二特征码;判断模块,用于判断所述第二特征码与所述第一特征码是否相同;以及第二重置模块,用于在所述判断模块判断出所述第二特征码与所述第一特征码相同的情况下,利用所述重置密码重置所述网络监控设备的密码。
进一步地,所述装置还包括:第二判断单元,用于在所述接收单元接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,判断所述重置密码是否有效,其中,在所述第二判断单元判断出所述重置密码有效的情况下,所述重置单元利用所述重置密码重置所述网络监控设备的密码,并生成第一重置结果,或在所述第二判断单元判断出所述重置密码无效的情况下,所述重置单元生成与所述第一重置结果不相同的第二重置结果。
根据本发明实施例的又一个方面,提供了一种网络监控设备,包括本发明上述内容所提供的任一种重置网络监控设备密码的装置。
根据本发明实施例的又一个方面,提供了一种服务器,包括:接收器,用于接收来自网络监控设备的第一特征码,其中,所述网络监控设备根据加密内容生成所述第一特征码;加密器,用于利用第一密钥加密所述第一特征码,得到密码重置口令,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥;以及发送器,用于发送所述密码重置口令至所述网络监控设备,其中,所述网络监控设备在接收到所述密码重置口令和来自客户端的重置密码的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
根据本发明实施例的又一个方面,提供了一种重置网络监控设备密码的***,包括:客户端,用于发送重置密码至网络监控设备;服务器,用于接收第一特征码,利用第一密钥加密所述第一特征码,得到密码重置口令,并发送所述密码重置口令至所述网络监控设备;以及网络监控设备,用于根据加密内容生成所述第一特征码,并在接收到所述密码重置口令和所述重置密码的情况下,采用第二密钥解密所述密码重置 口令,以及利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
在本发明实施例中,采用根据加密内容生成第一特征码;发送所述第一特征码至服务器;接收来自所述服务器的密码重置口令和来自客户端的重置密码,其中,所述服务器在接收到所述第一特征码之后,采用第一密钥加密所述第一特征码,得到所述密码重置口令,并返回所述密码重置口令;以及采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。通过使用非对称加密算法进行密码重置过程中的数据加密,由于非对称加密算法中的第二密钥保存在网络监控设备中,非对称加密算法中的第一密钥保存在密码服务器中。由于网络监控设备中保存的第二密钥是公钥,而公钥本身就是对外公开的密钥,所以,整套重置密码机制的安全性不依赖网络监控设备。实现利用密码服务器以及密码服务中私钥的安全性来保证重置密码机制的安全性,解决了现有技术中恢复默认密码、重置密码过程中的安全性较低的问题,进而达到了提高网络监控设备安全性的效果。
附图说明
此处所说明的附图用来提供对本发明的进一步理解,构成本申请的一部分,本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1是根据本发明实施例的重置网络监控设备密码的方法的流程图;
图2是根据本发明优选实施例的一种可选的重置网络监控设备密码的方法的时序图;
图3是根据本发明又一实施例的重置网络监控设备密码的方法的流程图;
图4是根据本本发明实施例的一种重置网络监控设备密码的装置的示意图;
图5是根据本发明实施例的一种服务器的示意图;以及
图6是根据本发明实施例的一种重置网络监控设备的***的示意图。
具体实施方式
为了使本技术领域的人员更好地理解本发明方案,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。基于本发明中的实施例,本领 域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本发明保护的范围。
需要说明的是,本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序,以便这里描述的本发明的实施例能够以除了在这里图示或描述的那些以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、***、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。
首先,对本发明实施例中所涉及的技术术语解释如下:
网络监控设备:带有网络模块,可以通过IP地址访问的安防监控设备,包括DVR、DVS、NVR、CVR、IPC、传输和显示设备等。
特征码:设备根据本机序列号,时间值,密钥版本,随机数等参数生成的一个字符串。
口令:根据特征码中的密钥版本,找到对应的非对称加密算法私钥,并用此非对称加密算法私钥对特征码加密后得到口令。
非对称加密算法:该类型算法有一对公私钥,公钥对外公开,私钥由生成方保管(不对外)。加密时使用公钥对数据进行加密,加密后的数据只有使用私钥才能完成解密。
根据本发明实施例,提供了一种重置网络监控设备密码的方法实施例,需要说明的是,在附图的流程图示出的步骤可以在诸如一组计算机可执行指令的计算机***中执行,并且,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。
图1是根据本发明实施例的重置网络监控设备密码的方法的流程图,如图1所示,该方法主要包括如下步骤S102至步骤S108:
步骤S102,根据加密内容生成第一特征码。
具体地,网络监控设备在出厂时,该设备中会保留一个非对称算法公钥,同时,对应的非对称算法私钥保存到密码服务器中。其中,加密内容可以包括网络监控设备的标识号和随机值,标识号可以是网络监控设备的设备序列号。
步骤S104,发送第一特征码至服务器。
具体地,当用户需要重置网络监控设备的密码时,可以利用客户端从网络监控设备中获取到第一特征码,然后由客户端将该第一特征码发送至密码服务器,即,网络监控设备通过客户端发送第一特征码至服务器。网络监控设备也可以直接发送第一特征码至服务器。其中,对于利用客户端进行通信的情况,客户端和网络监控设备之间可以采用局域网通信来进行数据交换,客户端可以利用多播通信方式从网络监控设备获取到第一特征码。客户端和服务器之间可以通过网络通信来交换数据,也可以通过线下其它途径进行数据交换,实现不管网络监控设备是否接入互联网,都可以正常进行网络监控设备的密码重置。
步骤S106,接收来自服务器的密码重置口令和来自客户端的重置密码,其中,服务器在接收到第一特征码之后,采用第一密钥加密第一特征码,得到密码重置口令,并返回密码重置口令。
具体地,在本发明实施例中,第一密码可以是非对称加密算法中的私钥,服务器在接收到客户端转发的来自网络监控设备的第一特征码之后,或在接收到直接由网络监控设备发送过来的第一特征码之后,利用非对称算法私钥对第一特征码进行加密,生成密码重置口令,并将该密码重置口令发送给网络监控设备,或者先发送给客户端,再由客户端将该密码重置口令与重置密码(即,新密码)一起传输至网络监控设备。由于第一特征码是随机生成的,所以不同的网络监控设备生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备上有效,实现了能够有针对性地进行密码重置。
步骤S108,采用第二密钥解密密码重置口令,并利用重置密码重置网络监控设备的密码,其中,第一密钥和第二密钥为非对称加密算法中的一对密钥。
具体地,在本发明实施例中,第二密码可以是非对称加密算法中公钥,网络监控设备在接收到密码重置口令和重置密码之后,利用非对称算法公钥解密密码重置口令,成功解密后,利用重置密码重置自身的密码。
本发明实施例所提供的重置网络监控设备密码的方法,通过使用非对称加密算法进行密码重置过程中的数据加密,由于非对称算法公钥保存在网络监控设备中,非对称算法私钥保存在密码服务器中。由于网络监控设备中的密钥本身就是对外公开的密钥,所以,整套重置密码机制的安全性不依赖网络监控设备。实现利用密码服务器以及密码服务中私钥的安全性来保证重置密码机制的安全性,解决了现有技术中恢复默认密码、重置密码过程中的安全性较低的问题,进而达到了提高网络监控设备安全性 的效果。
图2是根据本发明优选实施例的重置网络监控设备密码的方法的时序图,如图2所示,该方法主要包括如下步骤S201至步骤S209:
S201,获取网络监控设备的特征码。
具体地,同上述步骤S102,当用户需要重置网络监控设备的密码时,可以利用客户端向网络监控设备下发一个触发指令,以触发网络监控设备根据加密内容生成第一特征码。
S202,网络监控设备返回特征码。
S203,将特征码反馈至服务器。
具体地,步骤S202和步骤S203相当于上述步骤S104,即,网络监控设备将第一特征码反馈至客户端,再由客户端反馈至密码服务器。不同的是,在将第一特征码反馈至客户端之前,网络监控设备会对第一特征码设置有效时间。同样,网络监控设备也可以直接将第一特征码直接发送给服务器。
S204,服务器利用非对称算法私钥把特征码转为密码重置口令。
S205,服务器将密码重置口令传输至客户端。
S206,客户端将密码重置口令和重置密码传输至网络监控设备。
具体地,步骤S204、步骤S205和步骤S206相当于上述步骤S106,即,对于通过客户端进行通信的情况,在客户端转发来自网络监控设备的第一特征码至服务器之后,服务器利用非对称算法私钥对第一特征码进行加密,生成密码重置口令,并将该密码重置口令发送给客户端,再由客户端将密码重置口令与重置密码(即,新密码)一起传输至网络监控设备。
S207,网络监控设备判断密码重置口令是否有效。
即,在接收来自服务器的密码重置口令和来自客户端的重置密码之后,网络监控设备判断是否在有效时间内接收到密码重置口令。其中,在判断出在有效时间内接收到密码重置口令的情况下,利用重置密码重置网络监控设备的密码。相应地,如果判断出未在有效时间内接收到密码重置口令,则确定密码重置失败。
通过网络监控设备控制第一特征码的有效时间,使得对应的密码重置口令在指定的时间段内才有效。避免密码重置口令保护不当导致网络监控设备的密码再次被重置。达到提高密码重置稳定性的效果。
S208,在密码重置口令有效的情况下,网络监控设备判断重置密码是否有效。
S209,在判断出重置密码有效的情况下,利用重置密码重置网络监控设备的密码,并返回重置密码成功的结果至客户端。
即,在接收来自服务器的密码重置口令和来自客户端的重置密码之后,网络监控设备判断重置密码是否有效,具体地,主要是判断重置密码的等级是否达到等级要求,在判断出重置密码有效的情况下,也即在判断出重置密码的等级达到等级要求的情况下,利用重置密码重置网络监控设备的密码。
通过对重置密码的有效性进行判断,实现了引导用户设置安全等级相对较高的密码,避免用户因为重置密码使用弱密码而引发的安全问题,达到了进一步提高网络监控设备安全性的效果。
其中,在判断出重置密码有效的情况下,利用重置密码对网络监控设备的密码进行重置,同时可以生成第一重置结果,该第一重置结果表示密码重置成功,或在判断出重置密码无效的情况下,生成与第一重置结果不相同的第二重置结果,该第二重置结果表示密码重置失败。
进一步地,在重置网络监控设备的密码过程中,网络监控设备会采用第二密钥解密密码重置口令,得到第二特征码,并判断第二特征码与第一特征码是否相同,其中,在判断出第二特征码与第一特征码相同的情况下,利用重置密码重置网络监控设备的密码。
由于第一特征码是随机生成的,所以不同的网络监控设备生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备上有效,通过判断服务器传输过来的特征码与本地存储的特征码是否相同,在判断出第二特征码与第一特征码相同的情况下,利用重置密码重置网络监控设备的密码,实现了能够有针对性地进行密码重置。
图3是根据本发明又一实施例的重置网络监控设备密码的方法的流程图,如图3所示,该方法主要包括如下步骤S302至步骤S306:
S302,接收来自网络监控设备的第一特征码,其中,网络监控设备根据加密内容生成第一特征码。
具体地,网络监控设备在出厂时,该设备中会保留一个非对称算法公钥,同时,对应的非对称算法私钥保存到密码服务器中。当用户需要重置网络监控设备的密码时,网络监控设备根据加密内容生成第一特征码,然后通过客户端发送第一特征码至服务 器。网络监控设备也可以直接发送第一特征码至服务器。其中,加密内容包括网络监控设备的标识号和随机值,标识号可以是网络监控设备的设备序列号。
S304,利用第一密钥加密第一特征码,得到密码重置口令。
具体地,服务器在接收到第一特征码之后,采用第一密钥加密第一特征码,得到密码重置口令,并返回密码重置口令。即,在客户端转发来自网络监控设备的第一特征码至服务器之后,服务器利用非对称算法私钥对第一特征码进行加密,生成密码重置口令。
S306,发送密码重置口令至网络监控设备,其中,网络监控设备在接收到密码重置口令和来自客户端的重置密码的情况下,采用第二密钥解密密码重置口令,并利用重置密码重置网络监控设备的密码,第一密钥和第二密钥为非对称加密算法中的一对密钥。
具体地,服务器可以将该密码重置口令发送给客户端,再由客户端将该密码重置口令与重置密码(即,新密码)一起传输至网络监控设备。由于第一特征码是随机生成的,所以不同的网络监控设备生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备上有效,实现了能够有针对性地进行密码重置。网络监控设备在接收到密码重置口令和重置密码后,按照密码重置口令和重置密码重置网络监控设备的密码。
本发明实施例所提供的重置网络监控设备密码的方法,通过使用非对称加密算法进行密码重置过程中的数据加密,由于非对称算法公钥保存在网络监控设备中,非对称算法私钥保存在密码服务器中。由于网络监控设备中的密钥本身就是对外公开的密钥,所以,整套重置密码机制的安全性不依赖网络监控设备。实现利用密码服务器以及密码服务中私钥的安全性来保证重置密码机制的安全性,解决了现有技术中恢复默认密码、重置密码过程中的安全性较低的问题,进而达到了提高网络监控设备安全性的效果。
图4是根据本本发明实施例的重置网络监控设备密码的装置的示意图,如图4所示,该装置主要包括生成单元110、发送单元120、接收单元130和重置单元140,其中:
生成单元110用于根据加密内容生成第一特征码。
具体地,网络监控设备在出厂时,该设备中会保留一个非对称算法公钥,同时,对应的非对称算法私钥保存到密码服务器中。其中,加密内容可以包括网络监控设备的标识号和随机值,标识号可以是网络监控设备的设备序列号。
发送单元120用于发送第一特征码至服务器。
具体地,当用户需要重置网络监控设备的密码时,可以利用客户端从网络监控设备中获取到第一特征码,然后由客户端将该第一特征码发送至密码服务器,即,重置网络监控设备的装置的发送单元120通过客户端发送第一特征码至服务器。网络监控设备也可以直接发送第一特征码至服务器。其中,对于利用客户端进行通信的情况,客户端和发送单元120之间可以采用局域网通信来进行数据交换,客户端可以利用多播通信方式从网络监控设备获取到第一特征码。客户端和服务器之间可以通过网络通信来交换数据,也可以通过线下其它途径进行数据交换,实现不管网络监控设备是否接入互联网,都可以正常进行网络监控设备的密码重置。
接收单元130用于接收来自服务器的密码重置口令和来自客户端的重置密码,其中,服务器在接收到第一特征码之后,采用第一密钥加密第一特征码,得到密码重置口令,并返回密码重置口令。
具体地,在本发明实施例中,第一密码可以是非对称加密算法中的私钥,服务器在接收到客户端转发的来自网络监控设备的第一特征码之后,或在接收到直接由网络监控设备发送过来的第一特征码之后,利用非对称算法私钥对第一特征码进行加密,生成密码重置口令,并将该密码重置口令发送给网络监控设备,或者先发送给客户端,再由客户端将该密码重置口令与重置密码(即,新密码)一起传输至网络监控设备。由于第一特征码是随机生成的,所以不同的网络监控设备生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备上有效,实现了能够有针对性地进行密码重置。
重置单元140用于采用第二密钥解密密码重置口令,并利用重置密码重置网络监控设备的密码,其中,第一密钥和第二密钥为非对称加密算法中的一对密钥。
具体地,在本发明实施例中,第二密码可以是非对称加密算法中公钥,网络监控设备在接收到密码重置口令和重置密码之后,利用非对称算法公钥解密密码重置口令,成功解密后,利用重置密码重置自身的密码。
本发明实施例所提供的重置网络监控设备密码的装置,通过使用非对称加密算法进行密码重置过程中的数据加密,由于非对称算法公钥保存在网络监控设备中,非对称算法私钥保存在密码服务器中。由于网络监控设备中的密钥本身就是对外公开的密钥,所以,整套重置密码机制的安全性不依赖网络监控设备。实现利用密码服务器以及密码服务中私钥的安全性来保证重置密码机制的安全性,解决了现有技术中恢复默认密码、重置密码过程中的安全性较低的问题,进而达到了提高网络监控设备安全性 的效果。
优选地,本发明实施例所提供的重置网络监控设备的装置还包括设置单元和第一判断单元,重置单元140包括第一重置模块,其中,设置单元用于在发送单元120发送第一特征码至服务器之前,设置第一特征码的有效时间;第一判断单元用于在接收单元130接收来自服务器的密码重置口令和来自客户端的重置密码之后,判断是否在有效时间内接收到密码重置口令。第一重置模块用于在第一判断单元判断出在有效时间内接收到密码重置口令的情况下,采用第二密钥解密所述密码重置口令,并利用重置密码重置网络监控设备的密码。
通过控制第一特征码的有效时间,使得对应的密码重置口令在指定的时间段内才有效。避免密码重置口令保护不当导致网络监控设备的密码再次被重置。达到提高密码重置稳定性的效果。
进一步地,重置单元140还包括解密模块、判断模块和第二重置模块,其中,解密模块用于采用第二密钥解密密码重置口令,得到第二特征码;判断模块用于判断第二特征码与第一特征码是否相同;第二重置模块用于在判断模块判断出第二特征码与第一特征码相同的情况下,利用重置密码重置网络监控设备的密码。
由于第一特征码是随机生成的,所以不同的网络监控设备生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备上有效,通过判断服务器传输过来的特征码与本地存储的特征码是否相同,在判断出第二特征码与第一特征码相同的情况下,利用重置密码重置网络监控设备的密码,实现了能够有针对性地进行密码重置。
进一步优选地,本发明实施例所提供的重置网络监控设备的装置还包括第二判断单元,该第二判断单元用于在接收单元130接收来自服务器的密码重置口令和来自客户端的重置密码之后,判断重置密码是否有效,具体地,主要是判断重置密码的等级是否达到等级要求,其中,在第二判断单元判断出重置密码有效的情况下,也即在判断出重置密码的等级达到等级要求的情况下,重置单元140利用重置密码重置网络监控设备的密码,并生成第一重置结果,该第一重置结果表示密码重置成功,或在第二判断单元判断出重置密码无效的情况下,重置单元140生成与第一重置结果不相同的第二重置结果,该第二重置结果表示密码重置失败。
通过对重置密码的有效性进行判断,实现了引导用户设置安全等级相对较高的密码,避免用户因为重置密码使用弱密码而引发的安全问题,达到了进一步提高网络监控设备安全性的效果。
本发明实施例还提供了一种网络监控设备,该网络监控设备包括本发明实施例上述内容所提供的任一种重置网络监控设备密码的装置。
本发明实施例还提供了一种服务器,图5是根据本发明实施例的服务器的示意图,如图5所示,该服务器主要包括接收器310、加密器320和发送器330,其中:
接收器310用于接收来自网络监控设备的第一特征码,其中,网络监控设备根据加密内容生成第一特征码。
具体地,网络监控设备在出厂时,该设备中会保留一个非对称算法公钥,同时,对应的非对称算法私钥保存到密码服务器中。当用户需要重置网络监控设备的密码时,网络监控根据第一密钥生成第一特征码,然后通过客户端发送第一特征码至服务器的接收器310。其中,加密内容包括网络监控设备的标识号和随机值,标识号可以是网络监控设备的设备序列号。
加密器320用于利用第一密钥加密第一特征码,得到密码重置口令。
具体地,在接收器310在接收到第一特征码之后,加密器320采用第一密钥加密第一特征码,得到密码重置口令,并返回密码重置口令。即,在客户端转发来自网络监控设备的第一特征码至服务器之后,服务器利用非对称算法私钥对第一特征码进行加密,生成密码重置口令。
发送器330用于发送密码重置口令至网络监控设备,其中,网络监控设备在接收到密码重置口令和来自客户端的重置密码的情况下,采用第二密钥解密密码重置口令,并利用重置密码重置网络监控设备的密码,第一密钥和第二密钥为非对称加密算法中的一对密钥。
具体地,发送器330可以将该密码重置口令发送给客户端,再由客户端将该密码重置口令与重置密码(即,新密码)一起传输至网络监控设备。由于第一特征码是随机生成的,所以不同的网络监控设备生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备上有效,实现了能够有针对性地进行密码重置。网络监控设备在接收到密码重置口令和重置密码后,按照密码重置口令和重置密码重置网络监控设备的密码。
本发明实施例所提供的服务器,通过使用非对称加密算法进行密码重置过程中的数据加密,由于非对称算法公钥保存在网络监控设备中,非对称算法私钥保存在密码服务器中。由于网络监控设备中的密钥本身就是对外公开的密钥,所以,整套重置密码机制的安全性不依赖网络监控设备。实现利用密码服务器以及密码服务中私钥的安全性来保证重置密码机制的安全性,解决了现有技术中恢复默认密码、重置密码过程 中的安全性较低的问题,进而达到了提高网络监控设备安全性的效果。
本发明实施例还提供了一种重置网络监控设备的***,图6是根据本发明实施例的重置网络监控设备的***的示意图,如图6所示,该***主要包括网络监控设备100、客户端200和服务器300,其中:
网络监控设备100用于根据加密内容生成第一特征码。
具体地,网络监控设备100在出厂时,该设备中会保留一个非对称算法公钥,同时,对应的非对称算法私钥保存到密码服务器中。其中,加密内容可以包括网络监控设备100的标识号和随机值,标识号可以是网络监控设备100的设备序列号。当用户需要重置网络监控设备100的密码时,可以利用客户端200从网络监控设备100中获取到第一特征码,然后由客户端200将该第一特征码发送至密码服务器300,即,网络监控设备100通过客户端200发送第一特征码至服务器300。
服务器300用于接收第一特征码,利用第一密钥加密第一特征码,得到密码重置口令,并发送密码重置口令至网络监控设备100。
具体地,在本发明实施例中,第一密码可以是非对称加密算法中的私钥,服务器300在接收到第一特征码之后,利用非对称算法私钥对第一特征码进行加密,生成密码重置口令,并将该密码重置口令传输至网络监控设备100,或者将密码重置口令发送至客户端200,再由客户端200将密码重置口令与重置密码(即,新密码)一起传输至网络监控设备100。由于第一特征码是随机生成的,所以不同的网络监控设备100生成的第一特征码也不同,这样,利用第一特征码得到的密码重置口令,只能是在产生该第一特征码的网络监控设备100上有效,实现了能够有针对性地进行密码重置。
其中,客户端200和网络监控设备100之间可以采用局域网通信来进行数据交换,客户端200可以利用多播通信方式从网络监控设备100获取到第一特征码。客户端200和服务器300之间可以通过网络通信来交换数据,也可以通过线下其它途径进行数据交换,实现不管网络监控设备100是否接入互联网,都可以正常进行网络监控设备的密码重置。
本发明实施例所提供的重置网络监控设备密码的***,通过使用非对称加密算法进行密码重置过程中的数据加密,由于非对称算法公钥保存在网络监控设备中,非对称算法私钥保存在密码服务器中。由于网络监控设备中的密钥本身就是对外公开的密钥,所以,整套重置密码机制的安全性不依赖网络监控设备。实现利用密码服务器以及密码服务中私钥的安全性来保证重置密码机制的安全性,解决了现有技术中恢复默认密码、重置密码过程中的安全性较低的问题,进而达到了提高网络监控设备安全性 的效果。
在本发明的上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
在本申请所提供的几个实施例中,应该理解到,所揭露的技术内容,可通过其它的方式实现。其中,以上所描述的装置实施例仅仅是示意性的,例如所述单元的划分,可以为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个***,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,单元或模块的间接耦合或通信连接,可以是电性或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可为个人计算机、服务器或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述仅是本发明的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本发明原理的前提下,还可以做出若干改进和润饰,这些改进和润饰也应视为本发明的保护范围。

Claims (12)

  1. 一种重置网络监控设备密码的方法,包括:
    根据加密内容生成第一特征码;
    发送所述第一特征码至服务器;
    接收来自所述服务器的密码重置口令和来自客户端的重置密码,其中,所述服务器在接收到所述第一特征码之后,采用第一密钥加密所述第一特征码,得到所述密码重置口令,并返回所述密码重置口令;以及
    采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
  2. 根据权利要求1所述的方法,其中:
    在发送所述第一特征码至服务器之前,所述方法还包括:设置所述第一特征码的有效时间,
    在接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,所述方法还包括:判断是否在所述有效时间内接收到所述密码重置口令,
    其中,在判断出在所述有效时间内接收到所述密码重置口令的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码。
  3. 根据权利要求1所述的方法,其中,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码包括:
    采用所述第二密钥解密所述密码重置口令,得到第二特征码;
    判断所述第二特征码与所述第一特征码是否相同;以及
    在判断出所述第二特征码与所述第一特征码相同的情况下,利用所述重置密码重置所述网络监控设备的密码。
  4. 根据权利要求1所述的方法,其中,在接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,所述方法还包括:
    判断所述重置密码是否有效,
    其中,在判断出所述重置密码有效的情况下,利用所述重置密码重置所述网络监控设备的密码,并生成第一重置结果,或在判断出所述重置密码无效的情况下,生成与所述第一重置结果不相同的第二重置结果。
  5. 一种重置网络监控设备密码的方法,包括:
    接收来自所述网络监控设备的第一特征码,其中,所述网络监控设备根据加密内容生成所述第一特征码;
    利用第一密钥加密所述第一特征码,得到密码重置口令;以及
    发送所述密码重置口令至所述网络监控设备,其中,所述网络监控设备在接收到所述密码重置口令和来自客户端的重置密码的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
  6. 一种重置网络监控设备密码的装置,包括:
    生成单元,用于根据加密内容生成第一特征码;
    发送单元,用于发送所述第一特征码至服务器;
    接收单元,用于接收来自所述服务器的密码重置口令和来自客户端的重置密码,其中,所述服务器在接收到所述第一特征码之后,采用第一密钥加密所述第一特征码,得到所述密码重置口令,并返回所述密码重置口令;以及
    重置单元,用于采用第二密钥解密所述密码重置,并利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
  7. 根据权利要求6所述的装置,其中,所述装置还包括:
    设置单元,用于在所述发送单元发送所述第一特征码至服务器之前,设置所述第一特征码的有效时间;
    第一判断单元,用于在所述接收单元接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,判断是否在所述有效时间内接收到所述密码重置口令,
    所述重置单元包括:第一重置模块,用于在所述第一判断单元判断出在所述有效时间内接收到所述密码重置口令的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码。
  8. 根据权利要求6所述的装置,其中,所述重置单元包括:
    解密模块,用于采用所述第二密钥解密所述密码重置口令,得到第二特征码;
    判断模块,用于判断所述第二特征码与所述第一特征码是否相同;以及
    第二重置模块,用于在所述判断模块判断出所述第二特征码与所述第一特征码相同的情况下,利用所述重置密码重置所述网络监控设备的密码。
  9. 根据权利要求6所述的装置,其中,所述装置还包括:
    第二判断单元,用于在所述接收单元接收来自所述服务器的密码重置口令和来自客户端的重置密码之后,判断所述重置密码是否有效,
    其中,在所述第二判断单元判断出所述重置密码有效的情况下,所述重置单元利用所述重置密码重置所述网络监控设备的密码,并生成第一重置结果,或在所述第二判断单元判断出所述重置密码无效的情况下,所述重置单元生成与所述第一重置结果不相同的第二重置结果。
  10. 一种网络监控设备,包括权利要求6至9中任一项所述的重置网络监控设备密码的装置。
  11. 一种服务器,包括:
    接收器,用于接收来自网络监控设备的第一特征码,其中,所述网络监控设备根据加密内容生成所述第一特征码;
    加密器,用于利用第一密钥加密所述第一特征码,得到密码重置口令;以及
    发送器,用于发送所述密码重置口令至所述网络监控设备,其中,所述网络监控设备在接收到所述密码重置口令和来自客户端的重置密码的情况下,采用第二密钥解密所述密码重置口令,并利用所述重置密码重置所述网络监控设备的密码,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
  12. 一种重置网络监控设备密码的***,包括:
    客户端,用于发送重置密码至网络监控设备;
    服务器,用于接收第一特征码,利用第一密钥加密所述第一特征码,得到密码重置口令,并发送所述密码重置口令至所述网络监控设备;以及
    网络监控设备,用于根据加密内容生成所述第一特征码,并在接收到所述密码重置口令和所述重置密码的情况下,采用第二密钥解密所述密码重置口令,以 及利用所述重置密码重置所述网络监控设备的密码,其中,所述第一密钥和所述第二密钥为非对称加密算法中的一对密钥。
PCT/CN2016/082472 2015-05-22 2016-05-18 网络监控设备及重置其密码的方法、装置和***、服务器 WO2016188353A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP16799242.9A EP3300328B1 (en) 2015-05-22 2016-05-18 Network monitoring device and method, apparatus and system for resetting password thereof, and server
US15/576,667 US10831879B2 (en) 2015-05-22 2016-05-18 Network monitoring device, method, apparatus and system for resetting password thereof, and server

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510268009.5 2015-05-22
CN201510268009.5A CN106302335B (zh) 2015-05-22 2015-05-22 网络监控设备及重置其密码的方法、装置和***、服务器

Publications (1)

Publication Number Publication Date
WO2016188353A1 true WO2016188353A1 (zh) 2016-12-01

Family

ID=57392474

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/082472 WO2016188353A1 (zh) 2015-05-22 2016-05-18 网络监控设备及重置其密码的方法、装置和***、服务器

Country Status (4)

Country Link
US (1) US10831879B2 (zh)
EP (1) EP3300328B1 (zh)
CN (1) CN106302335B (zh)
WO (1) WO2016188353A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114697000A (zh) * 2020-12-28 2022-07-01 深圳Tcl新技术有限公司 配网方法、装置、终端及计算机可读存储介质

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10404689B2 (en) * 2017-02-09 2019-09-03 Microsoft Technology Licensing, Llc Password security
CN108400982A (zh) * 2018-02-12 2018-08-14 天津天地伟业信息***集成有限公司 一种嵌入式设备密码找回方法
CN111600732B (zh) * 2019-02-20 2023-06-20 浙江宇视科技有限公司 一种前端管理设备自动激活添加前端设备的方法及装置
CN111355708B (zh) * 2020-02-17 2022-06-24 浙江大华技术股份有限公司 一种设备密码重置方法及装置
CN111935191B (zh) * 2020-10-12 2021-01-26 杭州海康威视数字技术股份有限公司 密码重置方法、***、装置及电子设备
CN113345139A (zh) * 2021-06-03 2021-09-03 珠海优特物联科技有限公司 开锁方法、智能锁芯和智能锁***
CN114826567A (zh) * 2022-03-17 2022-07-29 北京旷视科技有限公司 一种终端密码的更新方法、装置、电子设备、介质及产品

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1731408A (zh) * 2005-08-17 2006-02-08 杭州海康威视数字技术有限公司 一种嵌入式安防设备管理员密码遗失的恢复方法
CN1780413A (zh) * 2004-11-25 2006-05-31 华为技术有限公司 一种组播广播业务密钥控制方法
US7861287B2 (en) * 2006-05-17 2010-12-28 International Business Machines Corporation System and method for utilizing audit information for challenge/response during a password reset process

Family Cites Families (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2347248A (en) * 1999-02-25 2000-08-30 Ibm Super passwords
US20030182420A1 (en) * 2001-05-21 2003-09-25 Kent Jones Method, system and apparatus for monitoring and controlling internet site content access
US20030158929A1 (en) * 2002-01-14 2003-08-21 Mcnerney Shaun Charles Computer network policy compliance measurement, monitoring, and enforcement system and method
US8078881B1 (en) * 2004-11-12 2011-12-13 Liu Gary G Password resetting method
EP2339776B1 (en) * 2006-05-13 2018-02-28 BlackBerry Limited System and method for remote reset of password and encryption key
US8099765B2 (en) * 2006-06-07 2012-01-17 Red Hat, Inc. Methods and systems for remote password reset using an authentication credential managed by a third party
GB0718817D0 (en) * 2007-09-26 2007-11-07 British Telecomm Password management
US20090092248A1 (en) * 2007-10-04 2009-04-09 Advanced Micro Devices, Inc. Encryption-based authentication for binding modules
US8332918B2 (en) * 2007-12-06 2012-12-11 Novell, Inc. Techniques for real-time adaptive password policies
US8756690B2 (en) * 2009-09-30 2014-06-17 Symbol Technologies, Inc. Extensible authentication protocol attack detection systems and methods
US8880895B2 (en) * 2009-10-29 2014-11-04 At&T Intellectual Property I, L.P. Methods, systems, and computer program products for recovering a password using user-selected third party authorization
US8732462B2 (en) 2011-07-07 2014-05-20 Ziptr, Inc. Methods and apparatus for secure data sharing
CN103246841A (zh) * 2012-02-09 2013-08-14 富泰华工业(深圳)有限公司 电子装置的解锁密码重置***及方法
US9698975B2 (en) * 2012-02-15 2017-07-04 Blackberry Limited Key management on device for perimeters
CN103473497A (zh) * 2012-06-06 2013-12-25 苏州宝时得电动工具有限公司 自动行走设备及其密码重置方法、自动行走***
EP2747333A1 (en) * 2012-12-19 2014-06-25 Nagravision S.A. A secure storage system including a virtual safe device and a mobile secure storage device
MY181777A (en) * 2013-11-11 2021-01-06 Adallom Inc Cloud service security broker and proxy
US9996686B2 (en) * 2014-04-28 2018-06-12 Blackberry Limited Password retrieval system and method involving token usage without prior knowledge of the password
CN103997679B (zh) * 2014-05-19 2017-11-07 深圳市九洲电器有限公司 一种机顶盒智能卡密码重置方法及***

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1780413A (zh) * 2004-11-25 2006-05-31 华为技术有限公司 一种组播广播业务密钥控制方法
CN1731408A (zh) * 2005-08-17 2006-02-08 杭州海康威视数字技术有限公司 一种嵌入式安防设备管理员密码遗失的恢复方法
US7861287B2 (en) * 2006-05-17 2010-12-28 International Business Machines Corporation System and method for utilizing audit information for challenge/response during a password reset process

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3300328A4 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114697000A (zh) * 2020-12-28 2022-07-01 深圳Tcl新技术有限公司 配网方法、装置、终端及计算机可读存储介质

Also Published As

Publication number Publication date
US10831879B2 (en) 2020-11-10
CN106302335A (zh) 2017-01-04
CN106302335B (zh) 2020-02-07
US20180137269A1 (en) 2018-05-17
EP3300328A1 (en) 2018-03-28
EP3300328B1 (en) 2022-08-31
EP3300328A4 (en) 2019-01-23

Similar Documents

Publication Publication Date Title
WO2016188353A1 (zh) 网络监控设备及重置其密码的方法、装置和***、服务器
US10785019B2 (en) Data transmission method and apparatus
EP2060056B1 (en) Method and apparatus for transmitting data using authentication
JP6168415B2 (ja) 端末認証システム、サーバ装置、及び端末認証方法
CN103166958B (zh) 一种文件的保护方法及***
US9992017B2 (en) Encrypting and storing data
CN108111497B (zh) 摄像机与服务器相互认证方法和装置
TWI642288B (zh) Instant communication method and system
CN110059458B (zh) 一种用户口令加密认证方法、装置及***
EP2398208A2 (en) Method for securing transmission data and security system for implementing the same
CN106790037B (zh) 一种用户态加密的即时通讯方法与***
JP2003501877A (ja) 公開鍵/秘密鍵対の安全な分配のための方法及び装置
JP2008533882A (ja) 暗号化キーをバックアップ及び復元する方法
JP6807153B2 (ja) セキュアな聴覚装置の通信のための装置および関係する方法
US11456999B2 (en) Network monitoring apparatus, and remote encryption and remote activation method, device and system thereof
GB2574433A (en) Dongle for ciphering data
JP7160605B2 (ja) 安全にデータを転送する方法およびシステム
US20190199722A1 (en) Systems and methods for networked computing
CN105959648B (zh) 一种加密方法、装置及视频监控***
WO2005088892A1 (en) A method of virtual challenge response authentication
US20220385644A1 (en) Sharing encrypted items with participants verification
EP4037250A1 (en) Message transmitting system with hardware security module
US11671411B2 (en) Secure storage and data exchange/sharing system using one time pads
KR101541165B1 (ko) 모바일 메시지 암호화 방법, 이 방법을 수행하는 프로그램을 기록한 컴퓨터 판독가능 기록매체 및 이 방법을 저장한 다운로드 서버
CN102118311B (zh) 一种数据传输方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16799242

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15576667

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2016799242

Country of ref document: EP