Data verification method for preventing process jumps
By receiving random numbers and configuration data verification carried by client requests, ensuring that the interface is called in a predetermined order, solving the problem that the front interface is skipped in the business process, and improving the security and data integrity of the process.
Patent Information
- Application Number
- CN202111466951.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-01
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-12-01
AI Technical Summary
In the prior art, in multiple interface calls of the same business process, the interfaces located in front of the business process are easily skipped directly, resulting in data tampering and poor security of the business process.
By receiving the random number carried by the client request, comparing the consistency of the random number with the random number stored in the cache, and querying the configuration data to determine the interface order, ensuring that the interface is called in a predetermined order, including verification of the salt value and valid time.
It realizes that each interface is called in the order specified in the business process, improves the security of the business process and prevents data tampering and replay attacks.
Smart Images

Figure CN114329515B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing, and more specifically, to a data verification method for preventing process jumps. Background Art
[0002] When data is transmitted over a network, if the data sent by the client is not processed, once the data is intercepted midway, for example, through common packet capture software such as Charles or Fiddler, the client's request data can be directly parsed and obtained, such as parsing the username and password, etc., and after being tampered with, the data can be sent to the server again, which will cause serious security risks.
[0003] In related technologies, data is usually protected. Generally, the protection methods for data include: using signatures, preventing replay attacks, etc. Specifically, using a signature means using a key to sign the transmitted parameters, which can verify the identity of the request, but this method cannot prevent replay attacks. That is, after the attacker intercepts the request, without making any adjustments to the request, the intercepted content is directly sent to the server multiple times at a high frequency. And to prevent replay attacks, an effective method to prevent replay attacks is to enable anti-replay of the API gateway. Through this signature authentication method, each request can only be used once, thus preventing replay. Specifically, this signature authentication method is a digital signature calculated based on the request content, which is used by the API gateway to identify the user identity. Specifically, when the client calls the API, it needs to add the calculated signature to the request. After receiving the request, the API gateway will calculate the signature using the same method and compare it with the signature calculated by the user. If they are the same, the verification passes; if they are different, the authentication fails.
[0004] Although preventing replay attacks can prevent the problem of the same request being called multiple times, it cannot prevent skipping the authentication of the previous interface and directly calling the subsequent interface in the invocation of multiple interfaces in a business process. In a business system, some business processing flows are long and complex, and the data needs to be processed according to the predetermined execution order of the interfaces. In the implementation process, how to ensure that these interfaces process the business process in the predetermined order and prevent data tampering is a problem that needs to be solved.
[0005] That is, in related technologies, when protecting data, there are technical problems that cannot prevent the authentication of the previous interface in the business process from being directly skipped in the invocation of multiple interfaces in the same business process, and directly authenticate and call the subsequent interface, which is likely to cause data tampering and poor security in the execution of the business process.
[0006] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0007] An embodiment of the present application provides a data verification method for preventing process jumps, so as to at least solve the technical problems in the related art that when protecting data, it is impossible to prevent direct skipping of authentication for the interfaces in the front of the same business process during multiple interface calls of the business process, and directly perform authentication calls on the subsequent interfaces, resulting in easy tampering of data and poor security in executing the business process.
[0008] According to one aspect of the embodiments of the present application, a data verification method for preventing process jumps is provided, including: receiving a target request from a client to access a target interface, where the target request carries at least a first random number; comparing whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface; in the case where the first comparison result indicates that the first random number is consistent with the second random number, querying configuration data corresponding to the first random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; at least obtaining a third access address corresponding to the target interface; and determining whether the target request passes verification according to the third access address and the configuration data.
[0009] Optionally, before querying the configuration data corresponding to the first random number, the method further includes: determining whether a historical request to access the previous interface is successfully processed, and in the case where the historical request is successfully processed, querying the configuration data corresponding to the historical request, where the configuration data includes: a first access address, a second access address of the currently to-be-accessed interface, a first verification salt value, and a valid time, where the valid time is a preset interval duration between the client accessing the previous interface and accessing the currently to-be-accessed interface, and the previous interface is the previous interface of the currently to-be-accessed interface in the business process; generating a second random number according to the Universally Unique Identifier (UUID); forming a key-value pair with the second random number as the key and the configuration data as the value, and storing the key-value pair in the cache.
[0010] Optionally, determining whether the target request passes verification according to the third access address and the configuration data includes: determining a first moment when the target request from the client is received; obtaining a second moment when the client accesses the previous interface; determining that a difference between the first moment and the second moment is an actual duration; and in the case where the actual duration is less than the interval duration, determining whether the target request passes verification according to the third access address and the configuration data.
[0011] Optionally, determining whether the target request passes the verification according to the third access address and the configuration data includes: when the actual duration is less than the interval duration, comparing whether the second access address is the same as the third access address to obtain a second comparison result; when the second comparison result indicates that the second access address is the same as the third access address, determining that the target request passes the verification.
[0012] Optionally, determining whether the target request passes the verification according to the third access address and the configuration data includes: when the actual duration is less than the interval duration, obtaining the fourth access address of the previous interface corresponding to the target interface; when it is determined that the first access address is the same as the fourth access address and the second access address is the same as the third access address, determining that the target request passes the verification.
[0013] Optionally, the target request also carries a second verification salt value. Determining whether the target request passes the verification according to the third access address and the configuration data includes: comparing whether the second verification salt value is the same as the first verification salt value to obtain a third comparison result; when the third comparison result indicates whether the second verification salt value is the same as the first verification salt value, determining whether the target request passes the verification according to the third access address and the configuration data.
[0014] Optionally, after querying the configuration data corresponding to the first random number, the method further includes: after querying the configuration data, deleting the configuration data from the cache.
[0015] According to another aspect of the embodiments of the present application, there is also provided a data verification device for preventing process jumps, including: a receiving module, configured to receive a target request for a client to access a target interface, where the target request carries at least a first random number; a comparison module, configured to compare whether the first random number is consistent with a second random number stored in the cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses the first access address corresponding to the previous interface; a query module, configured to query the configuration data corresponding to the first random number when the first comparison result indicates that the first random number is consistent with the second random number, where the configuration data at least includes: the second access address of the currently to-be-accessed interface; an obtaining module, configured to at least obtain the third access address corresponding to the target interface; a determining module, configured to determine whether the target request passes the verification according to the third access address and the configuration data.
[0016] According to another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, where the non-volatile storage medium includes a stored program, and when the program runs, it controls the device where the non-volatile storage medium is located to execute any data verification method for preventing process jumps.
[0017] According to another aspect of the embodiments of the present application, a processor is further provided, and the processor is used to run a program. When the program runs, it executes any data verification method for preventing process jumps.
[0018] In the embodiments of the present application, a method is adopted in which a random number is carried in an access request, and random number matching and interface matching are performed through the random number. By receiving a target request from a client to access a target interface, where the target request carries at least a first random number; comparing whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result. It should be noted that the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface; in the case where the first comparison result indicates that the first random number is consistent with the second random number, querying configuration data corresponding to the first random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; at least obtaining a third access address corresponding to the target interface; determining whether the target request passes verification according to the third access address and the configuration data, achieving the purpose of preventing the previous interface in the business process from being directly skipped for authentication, thereby realizing calling each interface in the order of each interface specified in the business process, ensuring the high security of executing the business process, and further solving the technical problems that in the related art, when protecting data, it is impossible to prevent the previous interface in the same business process from being directly skipped for authentication and directly authenticating and calling the subsequent interface, resulting in easy tampering of data and poor security of executing the business process. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0020] Figure 1 is a flowchart of an optional data verification method for preventing process jumps according to the embodiments of the present application;
[0021] Figure 2 is a schematic diagram of an optional application scenario for preventing process jumps according to the present application;
[0022] Figure 3 is a schematic flowchart of an optional technical implementation according to the present application;
[0023] Figure 4 is a schematic structural diagram of an optional data verification device for preventing process jumps according to the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0026] For the convenience of those skilled in the art to better understand the related embodiments of this application, the following are the explanations of some technical terms or partial nouns that may be involved in the related embodiments of this application:
[0027] Anti-replay attack: Resend the previous request exactly as it is, twice... n times. Generally, normal requests will pass the verification and enter the normal logic. If this normal logic is an operation of inserting into a database, then once the statement for inserting into the database is not written well, there may be multiple duplicate data. Once it is a relatively slow query operation, it may cause the database to become blocked and other situations.
[0028] Verification process: In a logical processing process, multiple clients may need to call multiple interfaces to jointly complete this process. These interface requests will be called in a certain order. During use, after the previous interface is verified successfully, the subsequent interface can be called for verification. After all verifications are successfully completed in order, this process is considered to have passed. For example, in the payment process, it is necessary to first verify the mobile phone verification code, then verify the payment password, and finally the payment can be successful.
[0029] Valid time: It refers to the time interval from the request of the previous interface to the request of the next interface. If this interval is exceeded, the system will fail the verification.
[0030] Verification salt value (Verify salt value): Used to determine the uniqueness of an interface request. For the same interface request, different business data requests can be distinguished and verified through the salt value. Generally, the unique identifier in the business data is used, such as the order number. It can be empty, and in this case, the salt value will not be verified.
[0031] According to an embodiment of the present application, an embodiment of a data verification method for preventing process jumps is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0032] Figure 1 is a data verification method for preventing process jumps according to an embodiment of the present application, as Figure 1 shown, the method includes the following steps:
[0033] Step S102, receive a target request from a client to access a target interface, where the target request carries at least a first random number;
[0034] Step S104, compare whether the first random number is the same as the second random number stored in the cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses the first access address corresponding to the previous interface;
[0035] Step S106, when the first comparison result indicates that the first random number is the same as the second random number, query the configuration data corresponding to the first random number, where the configuration data at least includes: the second access address of the currently to-be-accessed interface;
[0036] Step S108, obtain at least the third access address corresponding to the target interface;
[0037] Step S110, determine whether the target request passes the verification according to the third access address and the configuration data.
[0038] In this method, a target request for accessing a target interface by a client is received. The target request carries at least a first random number. It is compared whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result. The second random number is a random number generated after the client accesses a first access address corresponding to the previous interface. When the first comparison result indicates that the first random number is consistent with the second random number, configuration data corresponding to the first random number is queried. The configuration data at least includes: a second access address of the currently to-be-accessed interface. At least a third access address corresponding to the target interface is obtained. Whether the target request passes verification is determined according to the third access address and the configuration data, achieving the purpose of preventing the previous interface in the business process from being directly skipped for authentication, thereby realizing calling each interface in the order of each interface specified in the business process, ensuring the high security of executing the business process, and further solving the technical problems that in the related art, when protecting data, it is impossible to prevent the previous interface in the same business process from being directly skipped for authentication during multiple interface calls of the business process, and directly authenticating and calling the subsequent interface, resulting in easy tampering of data and poor security of executing the business process.
[0039] In some optional embodiments of the present application, before querying the configuration data corresponding to the first random number, it may be determined whether a historical request for accessing the previous interface has been successfully processed. When the historical request is successfully processed, the configuration data corresponding to the historical request is queried. It should be noted that the configuration data includes but is not limited to: the first access address, the second access address of the currently to-be-accessed interface, the first verification salt value, and the valid time. It can be understood that the valid time is a preset interval duration between the client accessing the previous interface and accessing the currently to-be-accessed interface. The previous interface is the previous interface of the currently to-be-accessed interface in the business process. A second random number is generated according to the Universally Unique Identifier (UUID). A key-value pair is formed with the second random number as the key and the configuration data as the value, and the key-value pair is stored in the cache.
[0040] In some embodiments of the present application, it can be determined whether the target request passes verification according to the third access address and the configuration data. Specifically, a first moment when the client accesses the target request is determined; a second moment when the client accesses the previous interface is obtained; the difference between the first moment and the second moment is determined as the actual duration. When the actual duration is less than the interval duration, it is determined whether the target request passes verification according to the third access address and the configuration data. For example, the actual duration is 5 seconds, and the effective interval duration is 6 seconds, then it is determined whether the target request passes verification according to the third access address and the configuration data.
[0041] Specifically, to determine whether a target request passes verification based on a third access address and configuration data, it is possible to compare whether the second access address is the same as the third access address when the actual duration is less than the interval duration, obtaining a second comparison result; when the second comparison result indicates that the second access address is the same as the third access address, it is determined that the target request passes the verification. For example, to implement a certain business process, four interfaces can be executed in sequence: interface A, interface B, interface C, and interface D. Among them, the access addresses corresponding to interface A, interface B, interface C, and interface D are 001, 002, 003, and 004 respectively. Suppose interface A has been executed, that is, the second random number 100 is generated after the client accesses 001. Next, interface B should be executed. At this time, the third access address corresponding to the target interface should be 002. However, when the target request from the client is received and it is determined that the first random number carried in it is 200, since this first random number is not 100, the target request sent by the client this time is not responded to. For another example, when the target request from the client is received and it is determined that the first random number carried in it is also 100, it is determined that the first random number is consistent with the second random number. Then, it is determined whether the third access address corresponding to the target interface is 002 (that is, it is determined whether the accessed interface is interface B). If it is not 002, the access request this time is refused; if it is 002, that is, the interface accessed this time is interface B, it is determined that the target request passes the verification, and then operations such as calling interface B can be executed.
[0042] In some embodiments of the present application, to determine whether a target request passes verification based on a third access address and configuration data, it includes: when the actual duration is less than the interval duration, obtaining the fourth access address of the previous interface corresponding to the target interface; when it is determined that the first access address is the same as the fourth access address and the second access address is the same as the third access address, it is determined that the target request passes the verification. For example, the fourth access address of the previous interface corresponding to the target interface is 001, and during the actual interface call process by the client, the first access address it accesses is also 001; and both the second access address and the third access address are 002, then it is determined that the target request passes the verification.
[0043] In some embodiments of the present application, the target request also carries a second verification salt value. To determine whether the target request passes verification based on the third access address and configuration data, it includes: comparing whether the second verification salt value is the same as the first verification salt value, obtaining a third comparison result; when the third comparison result indicates whether the second verification salt value is the same as the first verification salt value, determining whether the target request passes verification based on the third access address and configuration data.
[0044] It should be noted that after querying the configuration data corresponding to the first random number, after the configuration data is retrieved, the configuration data can be deleted from the cache.
[0045] Figure 2 This is a schematic diagram of an optional application scenario for preventing process jumps in this application. As Figure 2 shown, in this scenario, the business process consists of four interfaces: Interface A, Interface B, Interface C, and Interface D. The computer and the server can communicate through the Internet. The computer can send request data to the server and receive the results returned by the server.
[0046] To better understand the relevant examples of this application, an optional implementation method is given as an example. It should be noted that this implementation method does not limit the relevant embodiments of this application. Specifically:
[0047] 1. Server configuration:
[0048] On the server side, save the interface request paths used in a process in a set. For example, the previous interface path can be used as the key, and the path of the next interface, the valid time of the two interface requests, and the verification salt value can be stored in the value respectively.
[0049] 2. The client requests the previous interface in the process:
[0050] The client assembles the service parameters and requests the previous interface;
[0051] 3. Server-side service processing interface:
[0052] After receiving the interface request, the server performs service processing. After successful processing, it returns service data to the client. Among them, code = 200 is the flag for successful processing. The server performs unified interception processing before returning to the client. The process is as follows:
[0053] Judge whether the current request is successfully processed, that is, code = 200;
[0054] If the processing is successful, check whether there is a configuration for the current request address in the anti-process jump configuration;
[0055] If there is, take out the data such as the address of the next interface, the valid time, and the verification salt value in the configuration;
[0056] Generate a random number randomNum using UUID and return it to the client;
[0057] The random number randomNum can be saved in the cache in the form of key-value. The key is the random number, and the value contains the current interface address, the next interface address, and the verification salt value. The verification salt value is obtained from the interface return data, and the valid time of the cache is set at the same time.
[0058] 4. The client requests the next interface in the process:
[0059] After the client receives the random number randomNum returned by the server of the previous interface call, this request brings this random number and requests the next interface together with the service parameters.
[0060] 5. Server verifies interface anti-process jump:
[0061] The server uniformly intercepts interface requests and queries whether there is corresponding configuration data in the anti-process jump configuration through the interface path; if it exists, it is necessary to verify whether the random number randomNum uploaded by the interface exists in the cache; if it does not exist or the random number is incorrect, it means that the request has timed out or the data has been tampered with, and this request fails. If the random number randomNum exists in the cache, the corresponding value is retrieved, and the value contains the previous interface address, the current interface address, and the verification salt value; through the configuration information, verify whether the interface address to be accessed this time is consistent with the "next interface address" stored in the cache after accessing the previous interface last time. If they are inconsistent, the verification fails, indicating that the interface request is not accessed in the process order.
[0062] If there is a verification salt value in the configuration, the verification salt value can also be verified to strengthen the verification. Obtain the corresponding value from the parameters according to the configured verification salt value field name and compare it with the value in the cache. If they are inconsistent, it means that the data has been tampered with and the verification fails. It can be understood that after obtaining the random number randomNum from the cache, this data is deleted. In this way, when the next same request requests the server again, the cache cannot be obtained, and the verification fails, further achieving the purpose of preventing repeated calls. After the unified verification passes, the business method can be entered to perform business logic processing; if there are multiple interfaces in a process that need to request methods in sequence, repeating the above steps can achieve the orderly processing of the entire process business logic.
[0063] It is easy to notice that by using a unified configuration, defining the access order of multiple interfaces in a process, using unified interception verification, and unified return to generate random numbers, the intrusion into the specific business logic is greatly reduced. Business developers do not need to care about the specific verification process. With just a simple configuration, the security of the process can be efficiently guaranteed. At the same time, it can avoid replay attacks, improve the security of the system, protect the confidentiality of data, and ensure the timeliness of the process. In multiple interface requests that need to ensure the execution order, it can protect the interface from replay and also ensure that the interface requests are executed in order, without skipping the verification of the previous interfaces and directly executing the verification of the subsequent interfaces. Using this technology can effectively protect the security of the process execution. The convenient operation of the server can be easily integrated into the system to quickly deploy and protect the safe operation of the system.
[0064] Figure 3This is an optional technical implementation flowchart of the present application. As Figure 3 shown, the client can send an interface request to the public server. The server can be used to read a random number from the cached data, read configuration data from the process configuration, and then perform data request verification. If the verification is successful, it enters the specific business processing and returns data to the client; if the verification fails, the failed random number is written into the cache, and a failure result can be returned to the client.
[0065] Figure 4 This is a data verification device for preventing process jumps according to an embodiment of the present application. As Figure 4 shown, the device includes:
[0066] A receiving module 40, configured to receive a target request for the client to access a target interface, where the target request carries at least a first random number;
[0067] A comparison module 42, configured to compare whether the first random number is the same as a second random number stored in the cache, and obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface;
[0068] A query module 46, configured to query configuration data corresponding to the first random number when the first comparison result indicates that the first random number is the same as the second random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface;
[0069] An obtaining module 48, configured to at least obtain a third access address corresponding to the target interface;
[0070] A determination module 50, configured to determine whether the target request passes the verification according to the third access address and the configuration data.
[0071] In this device, a receiving module 40 is configured to receive a target request from a client to access a target interface, where the target request carries at least a first random number; a comparing module 42 is configured to compare whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface; a querying module 46 is configured to query configuration data corresponding to the first random number when the first comparison result indicates that the first random number is consistent with the second random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; an obtaining module 48 is configured to obtain at least a third access address corresponding to the target interface; a determining module 50 is configured to determine whether the target request passes verification according to the third access address and the configuration data, achieving the purpose of preventing the previous interface in the service process from being directly skipped for authentication, thereby realizing calling each interface in the order of each interface specified in the service process, ensuring the high security of executing the service process, and further solving the technical problems that in the related art, when protecting data, it is impossible to prevent the previous interface in the same service process from being directly skipped for authentication during multiple interface calls of the service process, and directly authenticating and calling the subsequent interfaces, resulting in easy tampering of data and poor security of executing the service process.
[0072] According to another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, where the non-volatile storage medium includes a stored program, and when the program runs, it controls a device where the non-volatile storage medium is located to execute any data verification method for preventing process jumps.
[0073] Specifically, the above storage medium is used to store program instructions for executing the following functions to implement the following functions:
[0074] Receive a target request from a client to access a target interface, where the target request carries at least a first random number; compare whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface; when the first comparison result indicates that the first random number is consistent with the second random number, query configuration data corresponding to the first random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; obtain at least a third access address corresponding to the target interface; determine whether the target request passes verification according to the third access address and the configuration data.
[0075] According to another aspect of the embodiments of the present application, there is also provided a processor, where the processor is used to run a program, and when the program runs, it executes any data verification method for preventing process jumps.
[0076] Specifically, the above-mentioned processor is used to call program instructions in the memory to implement the following functions:
[0077] Receive a target request from a client to access a target interface, where the target request carries at least a first random number; compare whether the first random number is the same as a second random number stored in the cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface; in the case where the first comparison result indicates that the first random number is the same as the second random number, query configuration data corresponding to the first random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; at least obtain a third access address corresponding to the target interface; determine whether the target request passes verification according to the third access address and the configuration data.
[0078] In the embodiments of the present application, a method is adopted in which a random number is carried in an access request, and random number matching and interface matching are performed through the random number. By receiving a target request from a client to access a target interface, where the target request carries at least a first random number; compare whether the first random number is the same as a second random number stored in the cache to obtain a first comparison result. It should be noted that the second random number is a random number generated after the client accesses a first access address corresponding to the previous interface; in the case where the first comparison result indicates that the first random number is the same as the second random number, query configuration data corresponding to the first random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; at least obtain a third access address corresponding to the target interface; determine whether the target request passes verification according to the third access address and the configuration data, achieving the purpose of preventing the previous interface in the business process from being directly skipped for authentication, thereby realizing calling each interface in the order of each interface specified in the business process, ensuring the high security of executing the business process, and further solving the technical problems in the related art that when protecting data, it is impossible to prevent the previous interface in the same business process from being directly skipped for authentication during multiple interface calls, and directly authenticating and calling the subsequent interfaces, resulting in easy tampering of data and poor security of executing the business process.
[0079] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0080] In the above embodiments of the present application, the descriptions of each embodiment have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0081] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.
[0082] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0083] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0084] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs and other media that can store program codes.
[0085] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A data verification method for preventing process jumps, characterized in that, Including: Receiving a target request from a client to access a target interface, where the target request carries at least a first random number; Comparing whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to a previous interface; When the first comparison result indicates that the first random number is consistent with the second random number, querying configuration data corresponding to the first random number, where the configuration data at least includes: a second access address of the currently to-be-accessed interface; At least obtaining a third access address corresponding to the target interface; Determining whether the target request passes verification according to the third access address and the configuration data.
2. The method according to claim 1, characterized in that, Before querying the configuration data corresponding to the first random number, the method further includes: Judging whether a historical request to access the previous interface is successfully processed. When the historical request is successfully processed, querying the configuration data corresponding to the historical request, where the configuration data includes: the first access address, the second access address of the currently to-be-accessed interface, a first verification salt value, and a valid time, where the valid time is a preset interval duration between the client accessing the previous interface and accessing the currently to-be-accessed interface, and the previous interface is the previous interface of the currently to-be-accessed interface in a business process; Generating the second random number according to a Universally Unique Identifier (UUID); Using the second random number as a key and the configuration data as a value to form a key-value pair, and storing the key-value pair in the cache.
3. The method according to claim 2, wherein Determining whether the target request passes verification according to the third access address and the configuration data includes: Determining a first moment when the client accesses the target request; Obtaining a second moment when the client accesses the previous interface; Determining a difference between the first moment and the second moment as an actual duration; When the actual duration is less than the interval duration, determining whether the target request passes verification according to the third access address and the configuration data.
4. The method according to claim 3, wherein Determining whether the target request passes verification according to the third access address and the configuration data includes: When the actual duration is less than the interval duration, comparing whether the second access address is the same as the third access address to obtain a second comparison result; When the second comparison result indicates that the second access address is the same as the third access address, determining that the target request passes verification.
5. The method according to claim 3, characterized in that, Determining whether the target request passes verification according to the third access address and the configuration data includes: When the actual duration is less than the interval duration, obtaining a fourth access address of the previous interface corresponding to the target interface; When it is determined that the first access address is the same as the fourth access address and the second access address is the same as the third access address, determining that the target request passes verification.
6. The method according to any one of claims 2 to 5, characterized in that, The target request also carries a second verification salt value. Determining whether the target request passes verification according to the third access address and the configuration data includes: Comparing whether the second verification salt value is the same as the first verification salt value to obtain a third comparison result; When the third comparison result indicates that the second verification salt value is the same as the first verification salt value, determining whether the target request passes verification according to the third access address and the configuration data.
7. The method according to claim 1, wherein After querying the configuration data corresponding to the first random number, the method further includes: After obtaining the configuration data by querying, deleting the configuration data from the cache.
8. A data verification device for preventing process jumps, characterized in that, Including: A receiving module, configured to receive a target request for a client to access a target interface, where the target request carries at least a first random number; A comparing module, configured to compare whether the first random number is consistent with a second random number stored in a cache to obtain a first comparison result, where the second random number is a random number generated after the client accesses a first access address corresponding to a previous interface; A querying module, configured to query the configuration data corresponding to the first random number when the first comparison result indicates that the first random number is consistent with the second random number, where the configuration data at least includes: a second access address of a currently to-be-accessed interface; An obtaining module, configured to at least obtain a third access address corresponding to the target interface; A determining module, configured to determine whether the target request passes verification according to the third access address and the configuration data.
9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, where when the program runs, it controls the device where the non-volatile storage medium is located to execute the data verification method for preventing process jump according to any one of claims 1 to 7.
10. A processor, characterized in that, The processor is used to run a program, where when the program runs, it executes the data verification method for preventing process jump according to any one of claims 1 to 7.
Citation Information
Patent Citations
Database platform access method, device, equipment and medium
CN111259445A
Data access method and device and server
CN112783954A