This invention discloses a
secure authentication method and
system based on a general
server interface, belonging to the field of interface security control technology. The method involves acquiring the original request message, extracting the interface identifier,
timestamp, request parameters, and a first signature value; generating an interface context
feature code based on the interface identifier and an interface mapping table, containing call hierarchy and permission domain information; and comparing this with a second signature value generated using a pre-shared key to determine message legitimacy. After confirming message legitimacy, a
dynamic channel identifier bound to the interface context
feature code is generated and written into the call context stack. The consistency between the
dynamic channel identifier and the interface path vector is verified using a Merkle path binding
verification algorithm, controlling the execution of the target business module. This invention achieves
strong binding between interface message
authentication and the
server's internal call path, effectively preventing cross-module replay and path mismatch risks, and improving the security and reliability of general interfaces in complex operating environments.