目前,数字组合密码作为身份认证的凭证被广泛用于生活中的各个领域,而传统的静态物理键盘作为数字密码的输入设备更是被广泛部署于各类终端(如银行的ATM自动取款机)。但是,这种密码输入设备存在着许多不可忽视的安全隐患。针对一系列的安全问题,我们设计了一套以颜色为关键字进行动态乱序刷新,以击键间隔和击键压力为辅助的密码输入系统,在一定程度上提升了密码的强度与系统的整体安全性。文章分析发掘了目前静态密码键盘的安全问题,同时介绍了系统的制作原理与一些必要的细节。
At present, the digital codes, as the identity authentication credentials, are widely used in various fields in life,the static physical keyboard ,as a traditional digital password input device, is widely applied in lots of terminal such as bank ATM. The password input device, however, has many potential safety hazards which can not be ignored. Aiming at a series of security problems, we design a password input system with dynamicly random display of color sequence, assisted by keystroke interval and keystroke pressure. Instead of the traditional digital password, the use of color sequence, to some extent, improves the strength of the password and the whole.security of the system. This paper analyses the safety hazards of the static password keyboard and at the same time introduces the work principle and some necessary details.