Security verification method, device, electronic device and computer storage medium

By verifying the sign-up algorithm between the client and the server and generating and verifying the signature key, the problem of request legitimacy verification when the client source code is exposed is solved, and effective authentication of the request source is achieved.

CN114640456BActive Publication Date: 2025-05-30HUNAN HAPPLY SUNSHINE INTERACTIVE ENTERTAINMENT MEDIA CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210276263.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-21
Publication Date
2025-05-30
Estimated Expiration
2042-03-21

AI Technical Summary

Technical Problem

In the operating environment where the client source code is exposed, it is difficult for the server to ensure that every request comes from a legal and trustworthy client. The existing digital signature algorithm is easily decoded and cannot effectively prevent request simulation.

Method used

The client initiates a verification request to the server, obtains the sign-up algorithm, and uses the randomly selected sign-up algorithm number and timestamp of the server to generate a signature key. The client uses the sign-up algorithm to generate a digital signature, and sends the sign-up key and digital signature to the server for security verification.

Benefits of technology

Even if the client source code is exposed, the server can still ensure that the request comes from a legitimate and trustworthy client through security verification, which improves the legality verification capability of the request.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114640456B_ABST
    Figure CN114640456B_ABST
Patent Text Reader

Abstract

The present application provides a security verification method, apparatus, electronic device and computer storage medium. The method includes: sending a verification request to a server to obtain a signature algorithm required for the current formal request; receiving the number of the second target signature algorithm and the signature secret key sent by the server; the signature secret key is obtained by the server randomly encrypting the number of the first target signature algorithm and the timestamp; the first target signature algorithm is the signature algorithm required for the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm without being tampered with; after obtaining the second target signature algorithm, generating a first target digital signature; sending the first target digital signature, the signature secret key and the service to be requested this time to the server together; receiving the security verification result of the server using the first target digital signature and the signature secret key for security verification. Thus, the purpose of effectively performing security verification is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and particularly to a security verification method, apparatus, electronic device, and computer storage medium. Background Art

[0002] Currently, in the running environment where the client source code is exposed, requests from the client may all be simulated by lawbreakers in a special way, and then certain resources may be obtained. Such behavior will cause economic losses to the operator and may also cause infringement to the operator. How to identify whether each request is legal has become a key means.

[0003] The existing mainstream solution is to calculate a digital signature through a complex algorithm before the request. This algorithm uses code encryption to ensure that its result cannot be simulated by lawbreakers. However, for a client with weak source code protection, it is only a matter of time before the algorithm is reverse-cracked. Therefore, it is still impossible to ensure that each request received by the server comes from a legitimate and trustworthy client. Summary of the Invention

[0004] In view of this, the present application provides a security verification method, apparatus, electronic device, and computer storage medium, which can ensure that the server can still identify that a request comes from a legitimate and trustworthy client even in the running environment where the client source code is exposed.

[0005] The first aspect of the present application provides a security verification method, which is applied to a client and includes:

[0006] Sending a verification request to the server; wherein, the verification request is used to obtain the signature algorithm to be used in the current formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time;

[0007] Receiving the number of the second target signature algorithm and the signature secret key sent by the server; wherein, the signature secret key is obtained by the server randomly encrypting the number of the first target signature algorithm and the timestamp; the first target signature algorithm is the signature algorithm to be used in the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with;

[0008] Querying the second target signature algorithm in the signature algorithm library of the client according to the number of the second target signature algorithm;

[0009] Generating a first target digital signature by using the second target signature algorithm; wherein, the first target digital signature is the digital signature to be used in the current formal request;

[0010] Send the first target digital signature, the signature secret key, and the service to be requested this time to the server; the server uses the first target digital signature and the signature secret key for security verification;

[0011] Receive the security verification result feedback by the server.

[0012] The second aspect of this application provides a security verification method, which is applied to the server and includes:

[0013] Receive the verification request from the client;

[0014] Randomly select a signature algorithm from the signature algorithm library of the server as the first target signature algorithm; where the first target signature algorithm is the signature algorithm required for the official request this time; the signature algorithm is an algorithm for generating digital signatures that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time;

[0015] Randomly select an encryption algorithm from the encryption algorithm library of the server as the target encryption algorithm;

[0016] Use the target encryption algorithm to encrypt the number and timestamp of the first target signature algorithm to obtain the signature secret key;

[0017] Send the number of the first target signature algorithm and the signature secret key to the client;

[0018] Receive the first target digital signature, the signature secret key, and the service to be requested this time sent by the client; where the first target digital signature is that the client uses the second target signature algorithm to generate the target digital signature; the target digital signature is the digital signature used for the official request this time; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with;

[0019] Use the first target digital signature and the signature secret key to perform security verification, and obtain and feedback the security verification result to the client.

[0020] Optionally, the using the first target digital signature and the signature secret key to perform security verification, obtaining and feedbacking the security verification result to the client includes:

[0021] Use the target encryption algorithm to parse the signature secret key to obtain the timestamp in the signature secret key and the number of the first target signature algorithm in the signature secret key;

[0022] Judge whether the timestamp in the signature secret key is greater than the current timestamp;

[0023] If it is determined that the timestamp in the signature secret key is greater than the current timestamp, then use the number of the first target signature algorithm in the signature secret key to query the first target signature algorithm in the signature algorithm library of the server;

[0024] Use the first target signature algorithm to generate a second target digital signature;

[0025] Determine whether the first target digital signature is equal to the second target digital signature;

[0026] If it is determined that the first target digital signature is equal to the second target digital signature, then generate a security verification result indicating verification passed and feedback the security verification result to the client;

[0027] If it is determined that the first target digital signature is not equal to the second target digital signature, then generate a security verification result indicating verification failed and feedback the security verification result to the client.

[0028] Optionally, after generating a security verification result indicating verification passed and feedbacking the security verification result to the client when it is determined that the first target digital signature is equal to the second target digital signature, it further includes:

[0029] Establish a communication connection with the client to implement the service required for this request.

[0030] The third aspect of this application provides a security verification device, which is applied to a client and includes:

[0031] A request unit, configured to initiate a verification request to the server; wherein, the verification request is used to obtain the signature algorithm required for this formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client;

[0032] A first receiving unit, configured to receive the number of the second target signature algorithm and the signature secret key sent by the server; wherein, the signature secret key is obtained by the server randomly encrypting the number of the first target signature algorithm and the timestamp; the first target signature algorithm is the signature algorithm required for this formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm without being tampered with;

[0033] A first query unit, configured to query the second target signature algorithm in the signature algorithm library of the client according to the number of the second target signature algorithm;

[0034] The first generation unit is used to generate a first target digital signature by using the second target signature algorithm; wherein, the first target digital signature is the digital signature used for this formal request.

[0035] The first sending unit is used to send the first target digital signature, the signature secret key, and the service to be requested this time to the server; the server uses the first target digital signature and the signature secret key for security verification.

[0036] The second receiving unit is used to receive the security verification result fed back by the server.

[0037] The fourth aspect of this application provides a security verification device, which is applied to the server and includes:

[0038] The third receiving unit is used to receive the verification request from the client.

[0039] The first extraction unit is used to randomly select a signature algorithm from the signature algorithm library of the server as the first target signature algorithm; wherein, the first target signature algorithm is the signature algorithm required for this formal request; the signature algorithm is an algorithm for generating digital signatures that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time.

[0040] The second extraction unit is used to randomly select an encryption algorithm from the encryption algorithm library of the server as the target encryption algorithm.

[0041] The encryption unit is used to encrypt the number and timestamp of the first target signature algorithm by using the target encryption algorithm to obtain the signature secret key.

[0042] The second sending unit is used to send the number of the first target signature algorithm and the signature secret key to the client.

[0043] The fourth receiving unit is used to receive the first target digital signature, the signature secret key, and the service to be requested this time sent by the client; wherein, the first target digital signature is the target digital signature generated by the client by using the second target signature algorithm; the target digital signature is the digital signature used for this formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with.

[0044] The verification unit is used to perform security verification by using the first target digital signature and the signature secret key, and obtain and feed back the security verification result to the client.

[0045] Optionally, the verification unit includes:

[0046] A decryption unit, configured to parse the signature key by using the target encryption algorithm to obtain the timestamp in the signature key and the number of the first target signature algorithm in the signature key;

[0047] A first judgment unit, configured to judge whether the timestamp in the signature key is greater than the current timestamp;

[0048] A second query unit, configured to, if the first judgment unit judges that the timestamp in the signature key is greater than the current timestamp, query the first target signature algorithm from the signature algorithm library of the server by using the number of the first target signature algorithm in the signature key;

[0049] A second generation unit, configured to generate a second target digital signature by using the first target signature algorithm;

[0050] A second judgment unit, configured to judge whether the first target digital signature is equal to the second target digital signature;

[0051] A third generation unit, configured to, if the second judgment unit judges that the first target digital signature is equal to the second target digital signature, generate a security verification result indicating verification passed and feedback the security verification result to the client;

[0052] The third generation unit is further configured to, if the second judgment unit judges that the first target digital signature is not equal to the second target digital signature, generate a security verification result indicating verification failed and feedback the security verification result to the client.

[0053] Optionally, the security verification device further includes:

[0054] An establishment unit, configured to establish a communication connection with the client to implement the service required for this request.

[0055] The fifth aspect of the present application provides an electronic device, including:

[0056] One or more processors;

[0057] A storage device, on which one or more programs are stored;

[0058] When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the security verification method as in the first aspect or the security verification method as described in any item of the second aspect.

[0059] A fourth aspect of the present application provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the security verification method in the first aspect or the security verification method described in any item of the second aspect.

[0060] As can be seen from the above solutions, the present application provides a security verification method, device, electronic device and computer storage medium. The security verification method includes: First, the client sends a verification request to the server to obtain the signature algorithm to be used in the current formal request. The signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time. The client receives the number of the second target signature algorithm and the signature key sent by the server. The signature key is randomly encrypted by the server using the number of the first target signature algorithm and the timestamp. The first target signature algorithm is the signature algorithm to be used in the current formal request. The number of the second target signature algorithm should be equal to the number of the first target signature algorithm when it is not tampered with. According to the number of the second target signature algorithm, the second target signature algorithm is queried in the signature algorithm library of the client. The client uses the second target signature algorithm to generate the first target digital signature. The first target digital signature is the digital signature used for the current formal request. The client sends the first target digital signature, the signature key and the service to be requested this time to the server. The server uses the first target digital signature and the signature key for security verification. Finally, the client receives the security verification result feedback by the server. Thus, the purpose of ensuring that the server can still identify that the request comes from a legitimate and trustworthy client can be achieved even in a running environment where the source code of the client is exposed. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0062] Figure 1 It is a specific flowchart of a security verification method provided by an embodiment of the present application;

[0063] Figure 2 It is a specific flowchart of a security verification method provided by another embodiment of the present application;

[0064] Figure 3Schematic diagram of a security verification device applied to a client provided by another embodiment of the present application;

[0065] Figure 4 Schematic diagram of a security verification device applied to a server provided by another embodiment of the present application;

[0066] Figure 5 Schematic diagram of a verification unit provided by another embodiment of the present application;

[0067] Figure 6 Schematic diagram of an electronic device for implementing a security verification method provided by another embodiment of the present application. Detailed implementation manners

[0068] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0069] It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order of functions executed by these devices, modules or units or their interdependent relationships. The terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.

[0070] The embodiments of the present application provide a security verification method, as Figure 1 shown, specifically including:

[0071] S101. The client sends a verification request to the server.

[0072] Among them, the verification request is used to obtain the signature algorithm required for the current formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time. And it is ensured that the server and the client can normally implement each signature algorithm.

[0073] The algorithm for generating digital signatures can be, but is not limited to, various permutations, concatenations, encryptions, and obfuscations of some parameters of the client, request information, fixed characters, etc., to generate n different algorithms for generating digital signatures (hereinafter simply referred to as signature addition). The larger the value of n, the better. The signature addition algorithms are implemented once using the code of the client and the code of the server respectively, and each signature addition algorithm is numbered.

[0074] For example:

[0075] Signature addition algorithm 1:

[0076] Obtain the version number of the client (c_version = 123456789); user ID (u_id = 11223344556677); video ID (v_id = 66668888).

[0077] Take the 3 - 10 digits after performing MD5 on c_version to get c_md5; take the 2 - 9 digits after performing Base64 on u_id to get u_base; take the 10 - 14 digits after performing MD5 on v_id to get v_md5.

[0078] Finally, concatenate c_md5 with v_md5 and then concatenate with u_base to obtain a digital signature 1.

[0079] Signature addition algorithm 2:

[0080] Obtain the version number of the client (c_version = 123456789); video ID (v_id = 66668888).

[0081] Take the 10 - 20 digits after performing MD5 on c_version to get c_md5; take the 2 - 18 digits after performing Base64 on v_id to get v_base.

[0082] Finally, concatenate v_base with c_md5 to obtain a digital signature 2.

[0083] S102. The server receives the verification request from the client.

[0084] S103. The server randomly selects a signature addition algorithm in the signature addition algorithm library of the server as the first target signature addition algorithm.

[0085] Among them, the first target signature addition algorithm is the signature addition algorithm to be used for the formal request this time; the signature addition algorithm is a digital signature generation algorithm that is pre - stored in both the signature addition algorithm library of the server and the signature addition algorithm library of the client.

[0086] S104. The server randomly selects an encryption algorithm in the encryption algorithm library of the server as the target encryption algorithm.

[0087] Among them, the encryption algorithm library contains various encryption algorithms such as symmetric encryption, asymmetric encryption, combined encryption, etc., which are not limited here.

[0088] S105. The server uses the target encryption algorithm to encrypt the number and timestamp of the first target signature algorithm to obtain the signature key.

[0089] It should be noted that the timestamp prevents criminals from having enough time to decompile the signature algorithm and make illegal requests.

[0090] S106. The server sends the number of the first target signature algorithm and the signature key to the client.

[0091] It can be seen that even if someone intercepts at this time, they can only obtain the number of a signature algorithm and the signature key, and even if the signature key is decrypted, they can only obtain the number of the signature algorithm and the timestamp, and cannot obtain the specific signature algorithm.

[0092] S107. The client receives the number of the second target signature algorithm and the signature key sent by the server.

[0093] Among them, the signature key is randomly encrypted by the server using the number and timestamp of the first target signature algorithm; the first target signature algorithm is the signature algorithm to be used for the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm without being tampered with. That is to say, in the case of no interception and replacement, the client should receive the number of the first target signature algorithm.

[0094] S108. The client queries the second target signature algorithm in the client's signature algorithm library according to the number of the second target signature algorithm.

[0095] S109. The client uses the second target signature algorithm to generate the first target digital signature.

[0096] Among them, the first target digital signature is the digital signature used for the current formal request.

[0097] S110. The client sends the first target digital signature, the signature key, and the service to be requested this time to the server.

[0098] Subsequently, the server uses the first target digital signature and the signature key for security verification.

[0099] Specifically, the client does not need to process the signature key and can send the signature key sent by the server back to the server without any changes.

[0100] S111. The server receives the first target digital signature, the signature secret key, and the service to be requested this time sent by the client.

[0101] Among them, the first target digital signature is generated by the client using the second target signature algorithm; the target digital signature is the digital signature used for this formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with.

[0102] S112. The server uses the first target digital signature and the signature secret key to perform security verification, and obtains and feedbacks the security verification result.

[0103] Optionally, in another embodiment of the present application, an implementation manner of step S112 is as Figure 2 shown, including:

[0104] S201. Parse the signature secret key using the target encryption algorithm to obtain the timestamp in the signature secret key and the number of the first target signature algorithm in the signature secret key.

[0105] S202. Determine whether the timestamp in the signature secret key is greater than the current timestamp.

[0106] Specifically, if it is determined that the timestamp in the signature secret key is greater than the current timestamp, then step S203 is executed; if it is determined that the timestamp in the signature secret key is less than the current timestamp, it means that the signature secret key has expired, and the service requested by the client this time is rejected.

[0107] S203. Use the number of the first target signature algorithm in the signature secret key to query the first target signature algorithm in the signature algorithm library of the server.

[0108] S204. Use the first target signature algorithm to generate the second target digital signature.

[0109] S205. Determine whether the first target digital signature is equal to the second target digital signature.

[0110] Specifically, if it is determined that the first target digital signature is equal to the second target digital signature, then step S206 is executed; if it is determined that the first target digital signature is not equal to the second target digital signature, then step S207 is executed.

[0111] S206. Generate a security verification result indicating verification passed and feedback the security verification result to the client.

[0112] Optionally, in another embodiment of the present application, after generating a security verification result indicating verification passed and feedbacking the security verification result to the client, it further includes:

[0113] Establish a communication connection with the client to realize the service that needs to be requested this time. That is, the service that the client needs to request this time after the holiday.

[0114] S207: Generate a security verification result that fails the verification and feed back the security verification result to the client.

[0115] S113: The client receives the security verification result fed back by the server.

[0116] Specifically, when the client receives a security verification result indicating that the verification is passed, the client can initiate verification again, or notify relevant staff of the server to manually change the verification result, etc., which is not limited here.

[0117] From the above scheme, it can be seen that the present application provides a security verification method: first, the client initiates a verification request to the server to obtain the signing algorithm required for this formal request; the signing algorithm is an algorithm for generating digital signatures that is pre-stored in both the signing algorithm library of the server and the signing algorithm library of the client; the client receives the number of the second target signing algorithm and the signature key sent by the server; wherein the signature key is obtained by randomly encrypting the number and timestamp of the first target signing algorithm by the server; the first target signing algorithm is the signing algorithm required for this formal request; the number of the second target signing algorithm The number should be equal to the number of the first target signing algorithm if it has not been tampered with; according to the number of the second target signing algorithm, the second target signing algorithm is queried in the signing algorithm library of the client; the client generates the first target digital signature using the second target signing algorithm; the first target digital signature is the digital signature used when making this formal request; the client sends the first target digital signature, signature key, and the service to be requested this time to the server; the server uses the first target digital signature and signature key for security verification; finally, the client receives the security verification result fed back by the server. In this way, even if the client source code is exposed in the operating environment, the server can still ensure that the request comes from a legitimate and trusted client.

[0118] Another embodiment of the present application provides a security verification device, which is applied to a client, such as Figure 3 As shown, specifically including:

[0119] The request unit 301 is used to initiate a verification request to the server.

[0120] The verification request is used to obtain the signing algorithm required for this formal request; the signing algorithm is an algorithm for generating digital signatures that is pre-stored in both the signing algorithm library of the server and the signing algorithm library of the client.

[0121] The first receiving unit 302 is configured to receive the number of the second target signature algorithm and the signature secret key sent by the server.

[0122] The signature secret key is obtained by the server randomly encrypting the number of the first target signature algorithm and the timestamp; the first target signature algorithm is the signature algorithm to be used in the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with.

[0123] The first query unit 303 is configured to query the second target signature algorithm from the signature algorithm library of the client according to the number of the second target signature algorithm.

[0124] The first generating unit 304 is configured to generate the first target digital signature by using the second target signature algorithm.

[0125] The first target digital signature is the digital signature to be used in the current formal request.

[0126] The first sending unit 305 is configured to send the first target digital signature, the signature secret key, and the service to be requested this time to the server together.

[0127] It should be noted that the server uses the first target digital signature and the signature secret key for security verification.

[0128] The second receiving unit 306 is configured to receive the security verification result fed back by the server.

[0129] For the specific working process of the unit disclosed in the above embodiments of the present application, reference may be made to the corresponding method embodiment content, as Figure 1 shown, which will not be elaborated here.

[0130] It can be seen from the above scheme that the present application provides a security verification device applied to the client: the request unit 301 initiates a verification request to the server to obtain the signing algorithm required for this formal request; the signing algorithm is an algorithm for generating digital signatures that is pre-stored in the signing algorithm library of the server and the signing algorithm library of the client; the first receiving unit 302 receives the number of the second target signing algorithm and the signature key sent by the server; wherein the signature key is obtained by the server randomly encrypting the number and timestamp of the first target signing algorithm; the first target signing algorithm is the signing algorithm required for this formal request; the number of the second target signing algorithm is not tampered with In the case of modification, it should be equal to the number of the first target signing algorithm; the first query unit 303 queries the second target signing algorithm in the signing algorithm library of the client according to the number of the second target signing algorithm; the first generation unit 304 generates the first target digital signature using the second target signing algorithm; wherein, the first target digital signature is the digital signature used when making this formal request; the first sending unit 305 sends the first target digital signature, the signature key and the service to be requested this time to the server; the server uses the first target digital signature and the signature key for security verification; the second receiving unit 306 receives the security verification result fed back by the server. Thus, even in the operating environment where the client source code is exposed, the server can still ensure that the request comes from a legitimate and trusted client.

[0131] Another embodiment of the present application provides a security verification device, which is applied to a server, such as Figure 4 As shown, specifically including:

[0132] The third receiving unit 401 is configured to receive a verification request from a client.

[0133] The first extraction unit 402 is used to randomly select a signing algorithm from the signing algorithm library of the server as the first target signing algorithm.

[0134] Among them, the first target signing algorithm is the signing algorithm required for this formal request; the signing algorithm is an algorithm for generating a digital signature that is pre-stored in the signing algorithm library of the server and the signing algorithm library of the client.

[0135] The second extraction unit 403 is used to randomly select an encryption algorithm from the encryption algorithm library of the server as a target encryption algorithm.

[0136] The encryption unit 404 is used to encrypt the number and timestamp of the first target signing algorithm by using the target encryption algorithm to obtain a signature key.

[0137] The second sending unit 405 is used to send the serial number and the signature key of the first target signing algorithm to the client.

[0138] The fourth receiving unit 406 is configured to receive a first target digital signature, a signature secret key, and a service to be requested this time sent by the client.

[0139] Wherein, the first target digital signature is a target digital signature generated by the client using a second target signature algorithm; the target digital signature is the digital signature used for this formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with.

[0140] The verification unit 407 is configured to perform security verification using the first target digital signature and the signature secret key, and obtain and feedback the security verification result to the client.

[0141] For the specific working process of the unit disclosed in the foregoing embodiments of the present application, reference may be made to the corresponding method embodiment content, as Figure 1 shown, which will not be elaborated here.

[0142] Optionally, in another embodiment of the present application, an implementation manner of the verification unit 407, as Figure 5 shown, includes:

[0143] The decryption unit 501 is configured to parse the signature secret key using the target encryption algorithm to obtain the timestamp in the signature secret key and the number of the first target signature algorithm in the signature secret key.

[0144] The first judgment unit 502 is configured to judge whether the timestamp in the signature secret key is greater than the current timestamp.

[0145] The second query unit 503 is configured to, if the first judgment unit 502 determines that the timestamp in the signature secret key is greater than the current timestamp, query the first target signature algorithm in the signature algorithm library of the server using the number of the first target signature algorithm in the signature secret key.

[0146] The second generation unit 504 is configured to generate a second target digital signature using the first target signature algorithm.

[0147] The second judgment unit 505 is configured to judge whether the first target digital signature is equal to the second target digital signature.

[0148] The third generation unit 506 is configured to, if the second judgment unit 505 determines that the first target digital signature is equal to the second target digital signature, generate a security verification result of verification passed and feedback the security verification result to the client.

[0149] Optionally, in another embodiment of the present application, an implementation manner of the security verification device further includes:

[0150] A establishing unit, configured to establish a communication connection with a client to implement the service required for this request.

[0151] For the specific working process of the unit disclosed in the above embodiments of the present application, reference may be made to the corresponding method embodiment content, which will not be elaborated here.

[0152] The third generating unit 506 is further configured to, if the second determining unit 505 determines that the first target digital signature is not equal to the second target digital signature, generate a security verification result indicating that the verification fails and feedback the security verification result to the client.

[0153] For the specific working process of the unit disclosed in the above embodiments of the present application, reference may be made to the corresponding method embodiment content, as Figure 2 shown, which will not be elaborated here.

[0154] As can be seen from the above solution, the present application provides a security verification device applied to a server: The third receiving unit 401 receives a verification request from a client. The first extraction unit 402 randomly selects a signature algorithm from the signature algorithm library of the server as the first target signature algorithm. The first target signature algorithm is the signature algorithm required for the official request this time; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm libraries of the server and the client at the same time. The second extraction unit 403 randomly selects an encryption algorithm from the encryption algorithm library of the server as the target encryption algorithm. The encryption unit 404 encrypts the number of the first target signature algorithm and the time stamp using the target encryption algorithm to obtain a signature key. The second sending unit 405 sends the number of the first target signature algorithm and the signature key to the client. The fourth receiving unit 406 receives the first target digital signature, the signature key, and the service required for this request sent by the client. The first target digital signature is a target digital signature generated by the client using the second target signature algorithm; the target digital signature is the digital signature used for the official request this time; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with. The verification unit 407 performs security verification using the first target digital signature and the signature key, and obtains and feedbacks the security verification result to the client. Thus, the purpose of ensuring that the server can still identify that the request comes from a legitimate and trustworthy client even in a running environment where the client source code is exposed can be achieved.

[0155] Another embodiment of the present application provides an electronic device, as Figure 6 shown, including:

[0156] One or more processors 601.

[0157] A storage device 602, on which one or more programs are stored.

[0158] When the one or more programs are executed by the one or more processors 601, the one or more processors 601 are caused to implement the security verification method described in any one of the above embodiments.

[0159] Another embodiment of the present application provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the security verification method described in any one of the above embodiments is implemented.

[0160] In the above embodiments disclosed in the present application, it should be understood that the disclosed apparatus and method can also be implemented in other ways. The apparatus and method embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of apparatuses, methods, and computer program products according to multiple embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0161] In addition, each functional module in various embodiments of the present disclosure may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part. If the function is implemented in the form of a software functional module and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a live broadcast device, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present disclosure. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program code.

[0162] Professional technicians can implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A security verification method, characterized in that, applied to the client, including: sending a verification request to the server; wherein, the verification request is used to obtain the signature algorithm required for the current formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time; receiving the number of the second target signature algorithm and the signature secret key sent by the server; wherein, the signature secret key is randomly encrypted by the server using the number of the first target signature algorithm and the timestamp; the first target signature algorithm is the signature algorithm required for the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm without being tampered with; querying the second target signature algorithm in the signature algorithm library of the client according to the number of the second target signature algorithm; generating a first target digital signature using the second target signature algorithm; wherein, the first target digital signature is the digital signature used for the current formal request; sending the first target digital signature, the signature secret key, and the service to be requested this time to the server; the server uses the first target digital signature and the signature secret key for security verification; receiving the security verification result feedback by the server; wherein, the server uses the first target digital signature and the signature secret key for security verification, including: the server parses the signature secret key to obtain the timestamp in the signature secret key and the number of the first target signature algorithm in the signature secret key; judging whether the timestamp in the signature secret key is greater than the current timestamp; if it is judged that the timestamp in the signature secret key is greater than the current timestamp, then query the first target signature algorithm in the signature algorithm library of the server using the number of the first target signature algorithm in the signature secret key; generating a second target digital signature using the first target signature algorithm; judging whether the first target digital signature is equal to the second target digital signature; if it is judged that the first target digital signature is equal to the second target digital signature, then generate a security verification result of verification passed and feedback the security verification result to the client; if it is judged that the first target digital signature is not equal to the second target digital signature, then generate a security verification result of verification failed and feedback the security verification result to the client.

2. A security verification method, characterized in that, applied to the server, including: receiving the verification request of the client; randomly selecting a signature algorithm in the signature algorithm library of the server as the first target signature algorithm; wherein, the first target signature algorithm is the signature algorithm required for the current formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time; randomly selecting an encryption algorithm in the encryption algorithm library of the server as the target encryption algorithm; Using the target encryption algorithm, encrypt the number and timestamp of the first target signature algorithm to obtain a signature key; Send the number of the first target signature algorithm and the signature key to the client; Receive the first target digital signature, the signature key, and the service to be requested this time sent by the client; wherein, the first target digital signature is the target digital signature generated by the client using the second target signature algorithm; the target digital signature is the digital signature used for the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with; Use the first target digital signature and the signature key to perform security verification, and obtain and feedback the security verification result to the client; Among them, the using the first target digital signature and the signature key to perform security verification, obtaining and feedbacking the security verification result to the client includes: Use the target encryption algorithm to parse the signature key to obtain the timestamp in the signature key and the number of the first target signature algorithm in the signature key; Judge whether the timestamp in the signature key is greater than the current timestamp; If it is judged that the timestamp in the signature key is greater than the current timestamp, use the number of the first target signature algorithm in the signature key to query the first target signature algorithm in the signature algorithm library of the server; Use the first target signature algorithm to generate a second target digital signature; Judge whether the first target digital signature is equal to the second target digital signature; If it is judged that the first target digital signature is equal to the second target digital signature, generate a security verification result of verification passed and feedback the security verification result to the client; If it is judged that the first target digital signature is not equal to the second target digital signature, generate a security verification result of verification failed and feedback the security verification result to the client.

3. The security verification method according to claim 2, characterized in that, After the step of if it is judged that the first target digital signature is equal to the second target digital signature, generating a security verification result of verification passed and feedbacking the security verification result to the client, further includes: Establish a communication connection with the client to implement the service to be requested this time.

4. A security verification device, characterized in that, Applied to the client, including: A request unit, configured to initiate a verification request to the server; wherein, the verification request is used to obtain the signature algorithm required for the current formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm library of the server and the signature algorithm library of the client at the same time; A first receiving unit, configured to receive the number of the second target signature algorithm and the signature secret key sent by the server; wherein, the signature secret key is obtained by the server randomly encrypting the number of the first target signature algorithm and the timestamp; the first target signature algorithm is the signature algorithm to be used for the current formal request; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with; A first querying unit, configured to query the second target signature algorithm from the signature algorithm library of the client according to the number of the second target signature algorithm; A first generating unit, configured to generate a first target digital signature by using the second target signature algorithm; wherein, the first target digital signature is the digital signature to be used for the current formal request; A first sending unit, configured to send the first target digital signature, the signature secret key, and the service to be requested this time to the server; and the server performs security verification by using the first target digital signature and the signature secret key; A second receiving unit, configured to receive the security verification result fed back by the server; Wherein, the server performs security verification by using the first target digital signature and the signature secret key, including: The server parses the signature secret key to obtain the timestamp in the signature secret key and the number of the first target signature algorithm in the signature secret key; Judge whether the timestamp in the signature secret key is greater than the current timestamp; If it is judged that the timestamp in the signature secret key is greater than the current timestamp, query the first target signature algorithm from the signature algorithm library of the server by using the number of the first target signature algorithm in the signature secret key; Generate a second target digital signature by using the first target signature algorithm; Judge whether the first target digital signature is equal to the second target digital signature; If it is judged that the first target digital signature is equal to the second target digital signature, generate a security verification result of passed verification and feedback the security verification result to the client; If it is judged that the first target digital signature is not equal to the second target digital signature, generate a security verification result of failed verification and feedback the security verification result to the client.

5. A security verification device, characterized in that, applied to the server, and includes: A third receiving unit, configured to receive a verification request from the client; A first extraction unit, configured to randomly select a signature algorithm from the signature algorithm library of the server as the first target signature algorithm; wherein, the first target signature algorithm is the signature algorithm to be used for the current formal request; the signature algorithm is an algorithm for generating a digital signature that is pre-stored in the signature algorithm libraries of the server and the client at the same time; A second extraction unit, configured to randomly select an encryption algorithm from the encryption algorithm library of the server as the target encryption algorithm; An encryption unit, configured to encrypt the number of the first target signature algorithm and the timestamp by using the target encryption algorithm to obtain a signature secret key; A second sending unit, configured to send the number of the first target signature algorithm and the signature secret key to the client; A fourth receiving unit, configured to receive a first target digital signature, the signature secret key, and the service to be requested this time sent by the client; wherein, the first target digital signature is a target digital signature generated by the client using a second target signature algorithm; the target digital signature is a digital signature used for the official request this time; the number of the second target signature algorithm should be equal to the number of the first target signature algorithm when not tampered with; A verification unit, configured to perform security verification using the first target digital signature and the signature secret key, and obtain and feedback a security verification result to the client; Wherein, the verification unit includes: A decryption unit, configured to parse the signature secret key using the target encryption algorithm to obtain the timestamp in the signature secret key and the number of the first target signature algorithm in the signature secret key; A first determination unit, configured to determine whether the timestamp in the signature secret key is greater than the current timestamp; A second query unit, configured to, if the first determination unit determines that the timestamp in the signature secret key is greater than the current timestamp, query the first target signature algorithm in the signature algorithm library of the server using the number of the first target signature algorithm in the signature secret key; A second generation unit, configured to generate a second target digital signature using the first target signature algorithm; A second determination unit, configured to determine whether the first target digital signature is equal to the second target digital signature; A third generation unit, configured to, if the second determination unit determines that the first target digital signature is equal to the second target digital signature, generate a security verification result of verification passed and feedback the security verification result to the client; The third generation unit is further configured to, if the second determination unit determines that the first target digital signature is not equal to the second target digital signature, generate a security verification result of verification failed and feedback the security verification result to the client.

6. The security verification device according to claim 5, wherein, further includes: An establishment unit, configured to establish a communication connection with the client to implement the service to be requested this time.

7. An electronic device, wherein, includes: One or more processors; A storage device, on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the security verification method described in claim 1, or the security verification method described in any one of claims 2 to 3.

8. A computer storage medium, wherein, a computer program is stored thereon, and when the computer program is executed by a processor, the security verification method described in claim 1, or the security verification method described in any one of claims 2 to 3 is implemented.

Citation Information

Patent Citations

  • Method and system for preventing illegal connection

    CN102629925A

  • Method, device and terminal for dynamically detecting simulator

    CN110147329A

  • Accessory access method, server and access end

    CN112434315A