A replay attack prevention method, client and server, and storage medium

By generating and verifying the anti-playback code between the client and the server, the problem of low quality of anti-playback attacks in the prior art is solved, and higher security and anti-attack effects are achieved.

CN115174199BActive Publication Date: 2025-05-16WEBANK (CHINA)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210768522.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-05-16
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

The prior art has low quality problems when preventing playback attacks, and attackers can bypass anti-playback protection by tampering with random numbers.

Method used

By determining the first time stamp, processor information and self-increment between the client and the server, an anti-playback code is generated, and the code is added to the service request, and multi-layer calculation and encryption processing are performed to improve the security of the anti-playback code.

Benefits of technology

It improves the quality of anti-replay attacks, enhances the legality verification of service requests, and reduces the possibility of successful attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115174199B_ABST
    Figure CN115174199B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses an anti-replay attack method, a client and a server, and a storage medium, including: when obtaining a service request for calling an anti-replay interface to transmit, determining a first timestamp, and obtaining the processor information of the client and an auto-increment number corresponding to the anti-replay interface; updating the auto-increment number with a preset value to obtain an updated auto-increment number; determining an anti-replay code according to a client identifier, a first timestamp, processor information, and an updated auto-increment number corresponding to the anti-replay interface; adding the anti-replay code and the client identifier to the service request; and sending the service request to the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of front-end security technology, and in particular to an anti-replay attack method, a client and a server, and a storage medium. Background Art

[0002] With the development of computer technology, more and more technologies are applied in the financial field. The traditional financial industry is gradually transforming to financial technology (Fintech). However, due to the security and real-time requirements of the financial industry, Fintech has also put forward higher requirements for technology. In the field of Fintech, information security is becoming more and more important. In the process of sending HTTP requests from the request direction to the destination host, it will pass through many intermediate devices. Network attackers can intercept the request data packet by capturing packets, and then send a packet that has been received to the destination host, resulting in information theft or even system paralysis.

[0003] In the prior art, the anti-replay attack is that the front end uses MD5, Tiger and other algorithms to determine a random number before calling the interface. When the front end calls the interface to send a request to the destination host, the front end adds the random number and the current timestamp to the request. When the destination host processes the request, it adds the random number to the database. When the destination host receives a new request containing the random number again within the end time, the destination host determines that the new request is an illegal request and rejects the request. If the attacker obtains the rules for generating random numbers by the front end, he can tamper with the random number in the captured request message according to the random number generation rules when launching a replay attack, so that the tampered random number is different from the random number in the database. This will cause the anti-replay protection to be bypassed, reducing the quality of the anti-replay attack. Summary of the invention

[0004] In order to solve the above technical problems, the embodiments of the present application hope to provide an anti-replay attack method, a client and a server, and a storage medium, which can improve the quality of anti-replay attack.

[0005] The technical solution of this application is implemented as follows:

[0006] The present application provides an anti-replay attack method, which is applied to a client. The anti-replay attack method includes:

[0007] In the case of obtaining a service request for calling an anti-replay interface to transmit, determining a first timestamp, and obtaining processor information of the client and an auto-increment number corresponding to the anti-replay interface;

[0008] The self-increment number is updated using a preset value to obtain an updated self-increment number;

[0009] Determine an anti-replay code according to the client identifier corresponding to the anti-replay interface, the first timestamp, the processor information and the updated auto-increment number;

[0010] The anti-replay code and the client identifier are added to the service request; and the service request is sent to the server.

[0011] The present application provides an anti-replay attack method, which is applied to a server. The anti-replay attack method includes:

[0012] When receiving a service request transmitted by a client, obtaining a client identifier and an anti-replay code from the service request, and determining a second timestamp when the service request is received;

[0013] In the database, obtaining the server-side auto-increment number and server-side processor information according to the client identifier;

[0014] Decrypt the anti-replay code according to the client identifier, the server-side self-increment number and the server-side processor information to obtain a first timestamp, processor information and an updated self-increment number;

[0015] Verify the first timestamp, processor information, and updated auto-increment number according to the second timestamp, the server auto-increment number, and the server processor information;

[0016] If the verification is successful, the service request is determined to be a legitimate request, and the service processing procedure corresponding to the service request is executed.

[0017] An embodiment of the present application provides a client, the client comprising:

[0018] A first determination unit is used to determine a first timestamp when a service request for calling an anti-replay interface is obtained; and determine an anti-replay code according to a client identifier corresponding to the anti-replay interface, the first timestamp, the processor information, and the updated auto-increment number;

[0019] A first acquisition unit, used to acquire processor information of the client and an auto-increment number corresponding to the anti-replay interface;

[0020] A first updating unit, configured to update the auto-increment number using a preset value to obtain an updated auto-increment number;

[0021] an adding unit, configured to add the anti-replay code and the client identifier to the service request,

[0022] A sending unit is used to send the service request to the server.

[0023] An embodiment of the present application provides a server, wherein the server includes:

[0024] The second acquisition unit is used to obtain the client identification and anti-replay code from the service request when receiving the service request transmitted by the client; and obtain the server self-increment number and server processor information in the database according to the client identification;

[0025] A second determining unit, configured to determine a second timestamp when the service request is received; if the verification is successful, determining that the service request is a legitimate request;

[0026] A decryption unit, used to decrypt the anti-replay code according to the client identifier, the server-side self-increment number and the server-side processor information to obtain a first timestamp, processor information and an updated self-increment number;

[0027] A verification unit, configured to verify the first timestamp, the processor information, and the updated auto-increment number according to the second timestamp, the server auto-increment number, and the server processor information;

[0028] The execution unit is used to execute the business processing process corresponding to the business request.

[0029] An embodiment of the present application provides a client, the client comprising:

[0030] A first memory, a first processor and a first communication bus, wherein the first memory communicates with the first processor via the first communication bus, the first memory stores an anti-replay attack program executable by the first processor, and when the anti-replay attack program is executed, the anti-replay attack method applied in the client described above is executed by the first processor.

[0031] An embodiment of the present application provides a server, wherein the server includes:

[0032] A second memory, a second processor and a second communication bus, wherein the second memory communicates with the second processor via the second communication bus, and the second memory stores an anti-replay attack program executable by the second processor. When the anti-replay attack program is executed, the anti-replay attack method applied in the server as described above is executed by the second processor.

[0033] An embodiment of the present application provides a storage medium having a computer program stored thereon, which is applied to a client or a server, and is characterized in that when the computer program is executed by a first processor, the anti-replay attack method applied to the client as described above is implemented, or when the computer program is executed by a second processor, the anti-replay attack method applied to the server as described above is implemented.

[0034] An embodiment of the present application provides an anti-replay attack method, a client and a server, and a storage medium. The anti-replay attack method includes: when obtaining a service request for calling an anti-replay interface to transmit, determining a first timestamp, and obtaining the processor information of the client and an auto-increment number corresponding to the anti-replay interface; updating the auto-increment number with a preset value to obtain an updated auto-increment number; determining an anti-replay code based on a client identifier, a first timestamp, processor information, and an updated auto-increment number corresponding to the anti-replay interface; adding the anti-replay code and the client identifier to the service request; and sending the service request to the server. The above method is used to implement the solution. The client obtains the first timestamp, processor information, and the auto-increment number corresponding to the anti-replay interface, and determines the anti-replay code according to the customer identification, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface. The anti-replay code is used to implement the interface anti-replay process. Since it is necessary to perform multi-layer calculations on the customer identification, and then use the results of the multi-layer calculations on the customer identification to perform multi-layer processing on the first timestamp, processor information and updated auto-increment number, the security of the obtained anti-replay code is improved. The highly secure anti-replay code is used to transmit the service request of the anti-replay interface, which improves the quality of anti-replay attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 A method for preventing replay attacks provided in this application embodiment Figure 1 ;

[0036] Figure 2 An exemplary service initiation request diagram provided in an embodiment of the present application Figure 1 ;

[0037] Figure 3 An exemplary service initiation request diagram provided in an embodiment of the present application Figure 2 ;

[0038] Figure 4 A schematic diagram of an exemplary splicing code provided in an embodiment of the present application;

[0039] Figure 5 A schematic diagram of an exemplary method for filling a position provided in an embodiment of the present application;

[0040] Figure 6 An exemplary XOR inversion data generation schematic diagram provided in an embodiment of the present application;

[0041] Figure 7 An exemplary schematic diagram of obtaining an anti-replay code provided in an embodiment of the present application;

[0042] Figure 8 An exemplary schematic diagram of the front-end initiating interface request phase provided in an embodiment of the present application;

[0043] Fig. 9 A method for preventing replay attacks provided in this application embodiment Figure 2 ;

[0044] Fig.10 An exemplary UID generation schematic diagram provided in an embodiment of the present application;

[0045] Fig.11 An exemplary anti-replay attack schematic diagram provided in the embodiment of the present application Figure 1 ;

[0046] Fig.12 An exemplary anti-replay attack schematic diagram provided in the embodiment of the present application Figure 2 ;

[0047] Fig.13 An exemplary anti-replay attack schematic diagram provided in the embodiment of the present application Figure 3 ;

[0048] Fig.14 An exemplary anti-replay attack schematic diagram provided in the embodiment of the present application Figure 4 ;

[0049] Fig.15 A schematic diagram of the structure of a client provided in an embodiment of the present application Figure 1 ;

[0050] Fig.16 A schematic diagram of the structure of a client provided in an embodiment of the present application Figure 2 ;

[0051] Fig.17 A schematic diagram of the composition structure of a server provided in an embodiment of the present application Figure 1 ;

[0052] Fig.18 A schematic diagram of the composition structure of a server provided in an embodiment of the present application Figure 2 . DETAILED DESCRIPTION

[0053] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. It should be understood that the specific embodiments described here are only used to explain the present application and are not used to limit the present application.

[0054] The embodiment of the present application provides a method for preventing replay attacks, and the method for preventing replay attacks is applied to a client. Figure 1 A flow chart of an anti-replay attack method provided in an embodiment of the present application is as follows: Figure 1 As shown, the anti-replay attack method may include:

[0055] S101. When a service request for calling an anti-replay interface is obtained, a first timestamp is determined, and processor information of the client and an auto-increment number corresponding to the anti-replay interface are obtained.

[0056] An anti-replay attack method provided in an embodiment of the present application is suitable for the scenario of performing anti-replay attack on an anti-replay interface.

[0057] In the embodiments of the present application, the client can be implemented in various forms. For example, the client described in the present application may include devices such as mobile phones, cameras, tablet computers, laptop computers, PDAs, portable media players (PMPs), navigation devices, wearable devices, smart bracelets, pedometers, and devices such as digital TVs and desktop computers.

[0058] In the embodiment of the present application, the first timestamp is the timestamp when the client receives the request to call the anti-replay interface to transmit the service.

[0059] In an embodiment of the present application, there are multiple interfaces in the client, and the client can determine the anti-replay interface and the non-anti-replay interface from the multiple interfaces according to the anti-replay configuration file.

[0060] It should be noted that the anti-replay interface is an interface provided with an anti-replay function, and the non-anti-replay interface is an interface not provided with an anti-replay function.

[0061] In an embodiment of the present application, the number of anti-replay interfaces can be one, the number of anti-replay interfaces can be two, or the number of anti-replay interfaces can be multiple; the specific number of anti-replay interfaces can be determined based on actual conditions, and the embodiment of the present application does not limit this.

[0062] In an embodiment of the present application, the processor information (deviceId) may be graphics card model information and / or driver version field information obtained from the client's device graphics processor (Graphics Processing Unit, GPU) information.

[0063] Exemplarily, if the processor information is the obtained graphics card model information and driver version field information, the client converts the graphics card model information and the driver version field information into hexadecimal strings respectively to obtain the graphics card model string and the driver version field string; the client then concatenates the graphics card model string and the driver version field string to obtain a concatenated string; the client obtains the last four characters of the concatenated string, and uses the last four characters as the processor information. If the processor information is the obtained graphics card model information, the client converts the graphics card model information into a hexadecimal string to obtain the graphics card model string; the client then obtains the last four characters of the graphics card model string, and uses the last four characters as the processor information. If the processor information is the obtained driver version field information, the client converts the driver version field information into a hexadecimal string to obtain the driver version field string; the client then obtains the last four characters of the driver version field string, and uses the last four characters as the processor information.

[0064] It should be noted that, in the process of the client concatenating the graphics card model string and the driver version field string to obtain the concatenated string, the client may add one character in the driver version field string after each bit of the graphics card model string to obtain the concatenated string; the client may also add one character in the graphics card model string after each bit of the driver version field string to obtain the concatenated string; the client may also concatenate the graphics card model string and the driver version field string in other ways to obtain the concatenated string. The specific concatenation method may be determined according to the actual situation, and the embodiments of the present application are not limited to this.

[0065] In the embodiment of the present application, each anti-replay interface is configured with an auto-increment number. Before the anti-replay interface is not called, the value of the auto-increment number corresponding to the anti-replay interface can be 0. Each time the anti-replay interface is called, the corresponding auto-increment number automatically increases by 1.

[0066] Exemplarily, before the anti-replay interface is called, the self-increment number corresponding to the anti-replay interface is 0. After the anti-replay interface is called once, the self-increment number corresponding to the anti-replay interface is increased by 1 to become 1. After the anti-replay interface is called for the second time, the self-increment number corresponding to the anti-replay interface is increased by 1 again to become 2.

[0067] In an embodiment of the present application, a local storage (localStorage) is provided in the client for storing the auto-increment number corresponding to the anti-replay interface.

[0068] In an embodiment of the present application, when the client obtains a request to call an anti-replay interface to transmit a service, before determining the first timestamp, the client will also determine the anti-replay interface from the configuration file; the client determines whether there is a client identifier corresponding to the interface name; if the client identifier does not exist, the client obtains the client identifier from the server.

[0069] It should be noted that the configuration file is specifically an anti-replay configuration file. The anti-replay configuration file is marked with an anti-replay interface, and the anti-replay interface can be determined through the anti-replay configuration file.

[0070] In the embodiment of the present application, there is an interface in the client that can be accessed before the user logs in, so a client identifier is required to identify the user.

[0071] It should be noted that the customer identifier may be a user unique identifier (User Identification, UID).

[0072] In an embodiment of the present application, the process of a client obtaining a client identification from a server includes: the client obtaining the client's processor information and the client program identification; the client generates an identifier acquisition request and adds the processor information and the client program identification in the identifier acquisition request; the client sends an identifier acquisition request to the server to obtain the client identification from the server according to the identifier acquisition request.

[0073] In an embodiment of the present application, the client program identifier can be UA (userAgent), which is a special string that includes the client's operating system and version, CPU type, browser and version, browser rendering engine, browser language, browser plug-in, etc.

[0074] In an embodiment of the present application, before the client obtains the client identifier from the server, when the client receives a service request to call the anti-replay interface to transmit the service request, the client will intercept the service request and put it into a queue, so as to process the service request when the client identifier is obtained from the server.

[0075] In an embodiment of the present application, the process in which the client obtains the service request for calling the anti-replay interface transmission may be that the client obtains the service request for calling the anti-replay interface transmission from a queue.

[0076] For example, Figure 2As shown: In the embodiment of the present application, after the front end (client) is started, when the client receives a request to call the anti-replay interface to transmit a service, the client will obtain the client identifier from the local storage (determine whether the UID exists in localStorage). If the client obtains the client identifier from the local storage (yes), the UID in the localStorage is used to complete the initialization, and the client determines the anti-replay code based on the client identifier, the first timestamp, the processor information, and the updated auto-increment number; the anti-replay code and the client identifier are added to the service request, and the client sends a service request to the server to obtain the corresponding response information according to the service request. When the client receives a request to call the anti-replay interface to transmit a service, if the client does not obtain the client identifier from the local storage, the client obtains the processor information and the client program identifier; the client generates an identifier acquisition request, and adds the processor information and the client program identifier in the identifier acquisition request; the client sends an identifier acquisition request to the server to obtain the client identifier from the server according to the identifier acquisition request.

[0077] For example, Figure 3As shown: Since the process of the client obtaining the UID from the server is asynchronous, it is necessary to intercept all business requests received by the front end before obtaining the UID from the server, and temporarily store these requests in the request queue. When the client receives the UID transmitted by the server, the front end processes the business requests in the request queue in sequence, that is, sends the business requests stored in the request queue to the server one by one. Specifically: After the front end (client) is started, the client will obtain the client identifier from the local storage (determine whether the UID exists in the localStorage). If the client does not obtain the client identifier from the local storage (no), the client obtains the processor information and the client program identifier; the client generates an identifier acquisition request, and adds the processor information and the client program identifier in the identifier acquisition request; the client sends an identifier acquisition request to the server (sends a UID request), and the server determines the client identifier (generates the UID) based on the processor information, the client program identifier, the third timestamp of the identifier acquisition request received, and the client address in the identifier acquisition request, and sends the client identifier to the client (returns the UID). Before the client receives the client identifier sent by the server, when the client receives service request A, the client temporarily stores service request A in the request queue; when the client receives service request B, the client also temporarily stores service request B in the request queue; when the client receives the client identifier sent by the server, after the client completes the initialization of the client identifier, the client stores the client identifier in localStorage (stores UID in localStorage), and processes the service requests in the request queue in sequence (re-initiates the service requests in the request queue), that is, adds the client identifier to service request A and service request B in sequence, sends service request A with the added client identifier to the server, and sends service request B with the added client identifier to the server (initiates service requests A and B), so as to obtain a response message (A response message) corresponding to service request A from the server according to service request A with the added client identifier, and obtain a response message (B response message) corresponding to service request B from the server according to service request B with the added client identifier.

[0078] S102: Use a preset value to update the auto-increment number to obtain an updated auto-increment number.

[0079] In an embodiment of the present application, after the client obtains the processor information of the client and the auto-increment number corresponding to the anti-replay interface, the client can update the auto-increment number using a preset value to obtain an updated auto-increment number.

[0080] In the embodiment of the present application, the preset value may be a value configured in the client and the server. For example, the preset value may be 1, the preset value may be 2, or the preset value may be another positive integer value. The specific preset value may be determined according to the actual situation, and the embodiment of the present application does not limit this.

[0081] In an embodiment of the present application, after obtaining the updated auto-increment number, the client stores the updated auto-increment number in localStorage.

[0082] S103: Determine an anti-replay code according to the client identifier, the first timestamp, the processor information and the updated self-increment number corresponding to the anti-replay interface.

[0083] In an embodiment of the present application, the client updates the auto-increment number using a preset value. After obtaining the updated auto-increment number, the client can determine the anti-replay code based on the client identifier, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface.

[0084] In an embodiment of the present application, the client determines the process of the anti-replay code according to the client identifier, the first timestamp, the processor information and the updated self-increment number corresponding to the anti-replay interface, including: the client splices the first timestamp, the processor information and the updated self-increment number according to a first preset splicing order to obtain a splicing code; the client converts the client identifier to obtain encrypted information; the client encrypts the splicing code using the encrypted information to obtain an anti-replay code.

[0085] In the embodiment of the present application, the first preset splicing order may be a splicing order configured in the client and the server. Specifically, the first splicing order is to splice the processor information after the first timestamp, and then splice the updated auto-increment number after the processor information.

[0086] In an embodiment of the present application, the client splices the first timestamp, the processor information and the updated self-increment number according to the first preset splicing order to obtain the splicing code, including: the client obtains the information of the first preset number of bits from the first timestamp to obtain the first information; the client obtains the information of the second preset number of bits from the processor information to obtain the second information; the client obtains the information of the third preset number of bits from the updated self-increment number to obtain the third information; the client splices the first information, the second information and the third information according to the first preset splicing order to obtain the splicing code.

[0087] In the embodiment of the present application, the first preset number of bits, the second preset number of bits and the third preset number of bits may be the same, or the first preset number of bits, the second preset number of bits and the third preset number of bits may be different; the specific number may be determined according to actual conditions, and the embodiment of the present application does not limit this.

[0088] Exemplarily, if the first preset number of bits, the second preset number of bits, and the third preset number of bits are the same, the bit values ​​corresponding to the first preset number of bits, the second preset number of bits, and the third preset number of bits can all be 4 digits, that is, the client obtains the last 4 bits of information from the first timestamp to obtain the first information; the client obtains the last 4 bits of information from the processor information to obtain the second information; the client obtains the last 4 bits of information from the updated auto-increment number to obtain the third information.

[0089] In an embodiment of the present application, the client splices the first information, the second information and the third information according to the first preset splicing order to obtain the splicing code. The client can splice the second information after the first information; and then splice the third information after the second information to obtain the splicing code.

[0090] For example, Figure 4 As shown, the client splices the second information (ECAD) behind the first information (9316), and then splices the third information (0001) behind the second information, thereby obtaining the splicing code.

[0091] In an embodiment of the present application, the process in which the client converts the client identifier to obtain encrypted information includes: the client groups the characters in the client identifier according to a preset number of characters to obtain multiple groups of characters; the client converts the multiple groups of characters into numbers to obtain multiple groups of values; the client performs XOR inversion on each group of values ​​to obtain multiple XOR inverted data; the client determines an initial vector based on processor information and an updated auto-increment number; the client uses the initial vector to pad the multiple XOR inverted data to obtain multiple padding data, and uses the multiple padding data as encrypted information.

[0092] In the embodiment of the present application, the preset number of characters is the number of characters configured in the client and the server. Exemplarily, the preset number of characters can be 2 characters; the preset number of characters can also be 4 characters; the preset number of characters can also be other number values; the specific number can be determined according to actual conditions, and the embodiment of the present application does not limit this.

[0093] It should be noted that the characters in the customer ID are hexadecimal characters.

[0094] In an embodiment of the present application, the process in which the client converts multiple groups of characters into numbers to obtain multiple groups of values ​​can be that the client converts multiple groups of characters into decimal numbers to obtain multiple groups of values; the client converts multiple groups of characters into numbers in other bases to obtain multiple groups of values; the specific method can be determined based on actual conditions, and the embodiment of the present application is not limited to this.

[0095] In an embodiment of the present application, the process of the client determining the initial vector based on the processor information and the updated auto-increment number can be that the client adds the processor information and the updated auto-increment number to obtain the initial vector; or the client subtracts the processor information and the updated auto-increment number to obtain the initial vector; the client can also determine the initial vector based on the processor information and the updated auto-increment number in other ways; the specific method can be determined based on actual conditions, and the embodiment of the present application is not limited to this.

[0096] In an embodiment of the present application, the client can determine the initial vector based on the processor information and the updated self-increment number, and then use the initial vector to pad the multiple XOR inversion data respectively to obtain multiple padding data. The client pads the multiple XOR inversion data respectively according to the processor information and the updated self-increment number. The method of obtaining multiple padding data can be determined according to actual conditions, and the embodiment of the present application is not limited to this.

[0097] It should be noted that the client determines how many bits of padding data should be added after each of the multiple XOR inversion data based on the processor information and the updated self-increment number (the padding data can be a random number or a configured data), so that the sum of the number of bits of the multiple padding data is the padding data length, and the sum of the padding data length and the splicing code data length is the preset data length.

[0098] It should also be noted that the preset data length can be the length of information carried when the client and the server interact with each other. Exemplarily, the preset data length can be 2048, or 4096; the preset data length can also be other data lengths, and the specific length value of the preset data length can be determined according to actual conditions, and the embodiments of the present application do not limit this.

[0099] In the embodiment of the present application, the padding operation uses incrementId (updated auto-increment number) in the range of (0, 9999) and deviceId in the range of (0, 65535) (the maximum number that can be converted to a hexadecimal four-digit string is 65535) to perform padding processing on multiple XOR inverted data (12 groups of data in the map), and obtains multiple padding data that satisfy:

[0100] 1. The number of the plurality of padding data is the same as the number of the plurality of XOR inversion data. And each of the plurality of padding data is an integer type array;

[0101] 2. The sum of multiple padding data is a result reduceNum calculated using incrementId and deviceId. There is no limit on the number of digits for each padding data in the multiple padding data.

[0102] 3. reduceNum is in the range of 2036 to 4084 (taking into account security strength while preventing the anti-replay code from being too long).

[0103] The specific implementation process is as follows: Figure 5 As shown: the padding operation formula can be: y^2=x^3+ax^2+bx+c. The client can determine the initial vector according to the processor information and the updated self-increment number, and determine the coefficients in the padding operation formula according to the initial vector: a, b and c. The x in the padding operation formula is any one of the multiple XOR inversion data; y is the multiple padding data corresponding to the multiple XOR inversion data determined according to the padding operation formula: after the padding operation, it can be determined that the padding data corresponding to the XOR inversion data 081 is 173, the padding data corresponding to the XOR inversion data 141 is 236, and the XOR inversion data 081 is 173. The corresponding padding data of the inversion data 848 is 148, the corresponding padding data of the XOR inversion data 171 is 100, the corresponding padding data of the XOR inversion data 056 is 415, the corresponding padding data of the XOR inversion data 76 is 402, the corresponding padding data of the XOR inversion data 73 is 06, the corresponding padding data of the XOR inversion data 13 is 65, the corresponding padding data of the XOR inversion data 10 is 171, the corresponding padding data of the XOR inversion data 284 is 48, the corresponding padding data of the XOR inversion data 63 is 158, and the corresponding padding data of the XOR inversion data 371 is 114.

[0104] It should be noted that the preset data length can be 2048, the data length of the splicing code is 12, and the sum of multiple padding data 173, 236, 148, 100, 415, 402, 06, 65, 171, 48, 158, and 114 is 2036, that is, the sum of the padding data length (ReduceNum) is 2036 and the splicing code data length is 2048, that is, the preset data length is 2048.

[0105] In an embodiment of the present application, a process in which a client performs XOR inversion on each group of values ​​in a plurality of groups of values ​​to obtain a plurality of XOR inverted data includes: the client concatenates the plurality of groups of values ​​to obtain a concatenated value string; starting from the starting value of the concatenated value string, the client sequentially compares two adjacent values; when two adjacent values ​​are different, the client divides the value with a smaller number of digits into XOR groups; when two adjacent values ​​are the same, the client divides the value with a smaller number of digits into OR groups; the client determines the bit value corresponding to each group of values ​​in the plurality of groups of values ​​to obtain a plurality of bit values; the client determines the combined bit number of the OR grouped values ​​according to the positive order of the plurality of bit values ​​to obtain at least one OR grouped data; determines the combined bit number of the XOR grouped values ​​according to the reverse order of the plurality of bit values ​​to obtain at least one XOR grouped data; the client uses at least one OR grouped data and at least one XOR grouped data as a plurality of XOR inverted data.

[0106] For example, Figure 6 As shown: The customer identification (UID) can be a 24-bit hexadecimal string: 72BC30AB410649496494ECAD. The UID is grouped in pairs in ascending order to obtain 12 groups of characters, and then each of the 12 groups of characters is converted into a decimal number to obtain 12 groups of values, that is, a 12-bit dictionary map (Mapstring) is generated, and each element in the dictionary is a positive integer in the range of (0,255). The value length (dictionary index) of each of the 12 groups of values ​​is 1-3; the 12 groups of dictionary maps after decimal conversion are: [114,188,48,171,65,06,73,73,100,148,236,173]; record the 12 index lengths of the dictionary map and get the index table indexMap: [3,3,2,3,2,2,2,2,3,3,3,3]; concatenate multiple groups of values ​​in the dictionary map to get the concatenated value string: "1141884817165067373100148236173", starting from the starting value of the concatenated value string, compare the two adjacent values ​​in turn, that is, starting from index 0, perform XOR operation on string[n] and string[n+1] cyclically (0<=n<=string.length) to get the comparison result a, if a is 0, then compare str ing[n] is placed in the "or group" (when two adjacent values ​​are the same, the value with the smaller number of digits is divided into the or group), if a is 1, string[n] is placed in the "different group" (when two adjacent values ​​are different, the value with the smaller number of digits is divided into the different group), n is incremented by 1 after each comparison, and the cycle ends when n=string.length, each index data in the "or group" is arranged in the positive order of indexMap (that is, starting from indexMap[0]) (according to the positive order of multiple digit values, the combination of the number of digits of the or group is determined to obtain at least one or group data), and each index data in the "different group" is arranged in the reverse order of indexMap (that is, starting from indexMap[indexMap.length-1]) (according to the reverse order of multiple digit values, the combination of the number of digits of the different group is determined to obtain at least one different group data).

[0107] In an embodiment of the present application, the client uses encryption information to encrypt the splicing code to obtain an anti-replay code, including: the client determines the number of bits of the splicing code; the client determines the initial number of bits based on the processor information, the updated auto-increment number and the number of bits information; the client adds a plurality of random numbers corresponding to the padding data after each character in the splicing code in the splicing code, starting from the initial number of bits, to obtain the anti-replay code.

[0108] It should be noted that the number of bits of the splicing code is the same as the number of the plurality of padding data.

[0109] In an embodiment of the present application, the process of the client determining the number of digits of the splicing code can be to determine the first digit of the first timestamp, the second digit of the processor information, and the third digit of the updated self-increment number for the client, and determine the sum of the first digit, the second digit, and the third digit, thereby obtaining the number of digits information. It can also be determined for the client The sum of the first preset number of digits, the second preset number of digits, and the third preset number of digits is obtained to obtain the number of digits information; the specific method can be determined according to actual conditions, and the embodiment of the present application is not limited to this.

[0110] In an embodiment of the present application, the process of the client determining the initial number of bits based on the processor information, the updated auto-increment number and the number of bit information can be that the client obtains the information of the second preset number of bits from the processor information to obtain the second information, wherein the second information is hexadecimal information; the client sets each bit in the second information to the maximum value to obtain the largest hexadecimal character, converts the largest hexadecimal character into a decimal number to obtain the first numerical value, the client determines the sum value between the updated auto-increment number and the first numerical value, and uses the sum value to take the modulus of the number of bit information to obtain the initial number of bits.

[0111] For example, if the first value is 60589, the updated auto-increment number is 0001, the bit information is 12, and the splicing code is 3916ECAD0001, then the sum of the updated auto-increment number and the first value is 60590. The client can use 60590 to take the modulus of the bit information 12 to get 2, that is, the initial bit number is 2, which is the second bit in the splicing code (that is, the 1 position in 391 is the initial position).

[0112] In an embodiment of the present application, the client may also use encryption algorithms such as AES, DES, 3DES, SM4, SM2, etc. to encrypt the splicing code to obtain an anti-replay code; the specific number may be determined based on actual conditions, and the embodiment of the present application does not limit this.

[0113] In the embodiments of the present application, Figure 7As shown: the customer identification (UID) is composed of the fourth information, the fifth information, the sixth information and the seventh information. For example, the UID can be: 72BC30AB410649496494ECAD. The UIDs are grouped in pairs in ascending order to obtain 12 groups of characters: 72, BC, 30, AB, 41, 06, 49, 49, 64, 94, EC, AD. Then, each of the 12 groups of characters is converted into a decimal number to obtain 12 groups of values ​​(Map): 114, 188, 48, 171, 65, 06, 73, 73, 100, 148, 236, 1 73, XOR invert each of the multiple sets of values ​​to obtain multiple XOR inverted data: 081, 141, 848, 171, 056, 76, 73, 13, 10, 284, 63, 371. The client determines the initial vector based on the processor information and the updated increment number; the client uses the initial vector to pad the multiple XOR inverted data to obtain multiple padding data, that is, to obtain the new map: 173, 236, 148, 100, 415, 402, 06, 65, 171, 48, 158, 114, and use the multiple padding data as encryption information. If the processor information (deviceId) is 60589, the updated increment number (incrementId) is 0001, and reduceNum is set to 2036. Use (incrementId+deviceId) mode12 to find the initial vector index, and the result is a positive integer in the range of (0, 11). The initialization vector index is 2. In the concatenation code (middleCode), starting from the initialization vector index (initial position), that is, starting from the second bit of the concatenation code, insert a hexadecimal random string of the value of the new map[n] bit after each character of the concatenation code from the first bit of the new Map (n is the map index pointer, increasing from 0), and n increases by 1 after each insertion. If the map pointer has not reached the end when the last bit of middleCode is inserted, continue to execute from the middleCode[0] position until n=map.length-1. The position where middleCode starts to execute insertion is the second bit [1] of the concatenation code (offset starting position). When middleCode reaches the last bit, the new map reaches

[48] . At this time, continue to execute from middleCode[0], that is, [9], insert 158 ​​hexadecimal characters, and then insert 114 hexadecimal characters after [3]. The map reaches the end and the anti-replay code (PreventCode) is obtained.

[0114] It should be noted that the deviceId is 'ECAD', which is converted to 60589 after being digitized, (0001+60589)mode 12=2.

[0115] It should be noted that, information of the fourth preset number of bits is obtained from the client program identifier to obtain the fourth information; information of the fifth preset number of bits is obtained from the client address to obtain the fifth information; information of the sixth preset number of bits is obtained from the third timestamp to obtain the sixth information; information of the seventh preset number of bits is obtained from the processor information to obtain the seventh information.

[0116] In an embodiment of the present application, the client, starting from the initial number of bits in the splicing code, sequentially adds a plurality of random numbers corresponding to the padding data after each character in the splicing code to obtain an anti-replay code, including: the client obtains the first padding data among the plurality of padding data, and adds a random number matching the first padding data after the first splicing character corresponding to the initial number of bits in the splicing code; the client obtains the second padding data after the first padding data among the plurality of padding data, and adds a random number matching the second padding data after the second splicing character after the first splicing code; until the last padding data is obtained among the plurality of padding data, and a random number matching the last padding data is added before the first splicing character to obtain the anti-replay code.

[0117] For example, the splicing code is 9, 3, 1, 6, E, C, A, D, 0, 0, 0, 1, and the plurality of padding data are: 173, 236, 148, 100, 415, 402, 06, 65, 171, 48, 158, 114. The initial number of digits of the splicing code can be 2 digits (the number of digits starts from 0), and the first padding data of the plurality of padding data is the third character [1] in the splicing code. Then, the first padding data (173) is added after the splicing code [1], that is, after the character [1 ] and add 173 random numbers after it; add the second place-filling data (236) after the fourth character [6] of the splicing code, and add 236 random numbers after the character [6]; add the second place-filling data (148) after the fifth character [E] of the splicing code, and add 148 random numbers after the character [E]; add the second place-filling data (100) after the sixth character [C] of the splicing code, and add 100 random numbers after the character [E]; add the second place-filling data (4 15), add 415 random numbers after the character [E]; add the second padding data (402) after the 8th character [D] of the splicing code, add 402 random numbers after the character [E]; add the second padding data (06) after the 9th character [0] of the splicing code, add 6 random numbers after the character [E]; add the second padding data (65) after the 10th character [0] of the splicing code, add 65 random numbers after the character [0]; add the second padding data (06) after the 11th character [0] of the splicing code, add 65 random numbers after the character [0]; add the second padding data (06) after the 9th character [0] of the splicing code, add 65 random numbers after the character [0]; add the second padding data (06) after the 11th character [0] of the splicing code The padding data (171) is used to add 171 random numbers after the character [0]. The second padding data (48) is used to add 48 random numbers after the character [0]. The second padding data (173) is used to add 173 random numbers after the character [9]. The second padding data (236) is used to add 236 random numbers after the character [3] after the character [3]. Thus, the anti-replay code is obtained.

[0118] S104: Add the anti-replay code and the client identifier to the service request; and send the service request to the server.

[0119] In an embodiment of the present application, after the client determines the anti-replay code based on the client identifier, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface, the client can add the anti-replay code and client identifier to the service request; and send a service request to the server to execute the anti-replay attack processing process corresponding to the service request based on the anti-replay code and client identifier.

[0120] For example, Figure 8As shown: After the front-end (client) is started, the client ID (UID) is initialized first. When a business request (demo / test.json) is received, the configuration file (anti-replay interface configuration file) is used to determine whether the interface called by the business request is an anti-replay interface. When it is determined that the business request is a business request to call the anti-replay interface to transmit the business request (hitting anti-replay), the client obtains the auto-increment number corresponding to the anti-replay interface according to the incrementld service (obtaining incrementld), that is, obtains the auto-increment number corresponding to the anti-replay interface from localStorage (query the front-end database to obtain incrementld), and accumulates incrementld according to the preset value in the interface dimension to obtain the updated value. The client determines the first timestamp and obtains the processor information of the client; the anti-replay code is determined according to the client identifier, the first timestamp, the processor information and the updated auto-increment number corresponding to the anti-replay interface; the client obtains the UID from localStorage, the client adds the anti-replay code and the client identifier (UID) to the business request; and sends a business request to the server (transmits the UID and the anti-replay code together with the business request to the server interface demo / test.json), so that the server can verify the anti-replay code according to the client identifier and execute the corresponding business processing according to the business request.

[0121] It can be understood that the client obtains the first timestamp, processor information, and the auto-increment number corresponding to the anti-replay interface, determines the anti-replay code according to the customer identifier, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface, and uses the anti-replay code to implement the interface anti-replay process. Since it is necessary to perform multi-layer calculations on the customer identifier, and then use the results of the multi-layer calculations on the customer identifier to perform multi-layer processing on the first timestamp, processor information and updated auto-increment number, the security of the anti-replay code obtained is improved, and the highly secure anti-replay code is used to transmit the business requests of the anti-replay interface, thereby improving the quality of anti-replay attacks.

[0122] The embodiment of the present application provides a method for preventing replay attacks, wherein the method for preventing replay attacks is applied to a server. Fig. 9 A flow chart of an anti-replay attack method provided in an embodiment of the present application is as follows: Fig. 9 As shown, the anti-replay attack method may include:

[0123] S201. When receiving a service request transmitted by a client, obtain a client identifier and an anti-replay code from the service request, and determine a second timestamp when the service request is received.

[0124] An anti-replay attack method provided in an embodiment of the present application is suitable for the scenario of performing anti-replay attack on an anti-replay interface.

[0125] In the embodiments of the present application, the server can be implemented in various forms, and the specific form can be determined based on actual conditions, and the embodiments of the present application do not limit this.

[0126] In an embodiment of the present application, when the server receives a service request transmitted by the client, the server can first determine whether the service request is to call an anti-replay interface to transmit the service request, or to call a non-anti-replay interface to transmit the service request. When it is determined that the anti-replay interface is called to transmit the service request, the server obtains the client identifier and anti-replay code from the service request, and determines a second timestamp when the service request is received; when it is determined that the non-anti-replay interface is called to transmit the service request, the server processes the service request in accordance with the method of the prior art.

[0127] In an embodiment of the present application, an anti-replay configuration file is configured in the server. The server can determine, based on the anti-replay configuration file, that the service request received from the client is a service request transmitted by calling an anti-replay interface; or determine that the service request received from the client is a service request transmitted by calling a non-anti-replay interface.

[0128] It should be noted that the anti-replay interface is an interface provided with an anti-replay function, and the non-anti-replay interface is an interface not provided with an anti-replay function.

[0129] In an embodiment of the present application, the number of anti-replay interfaces can be one, the number of anti-replay interfaces can be two, or the number of anti-replay interfaces can be multiple; the specific number of anti-replay interfaces can be determined based on actual conditions, and the embodiment of the present application does not limit this.

[0130] In an embodiment of the present application, when the server receives a service request transmitted by the client, before obtaining the client identification and anti-replay code from the service request, the method also includes: when the server receives an identifier acquisition request sent by the client, determining a third timestamp of receiving the identifier acquisition request; and obtaining processor information and client program identification from the identifier acquisition request; the server determines the client address; the server determines the client identification based on the client address, the third timestamp, the processor information and the client program identification.

[0131] In an embodiment of the present application, the processor information (deviceId) may be graphics card model information and / or driver version field information obtained from the client's device graphics processor (Graphics Processing Unit, GPU) information.

[0132] Exemplarily, if the processor information is the obtained graphics card model information and driver version field information, the client converts the graphics card model information and the driver version field information into hexadecimal strings respectively to obtain the graphics card model string and the driver version field string; the client then concatenates the graphics card model string and the driver version field string to obtain a concatenated string; the client obtains the last four characters of the concatenated string, and uses the last four characters as the processor information. If the processor information is the obtained graphics card model information, the client converts the graphics card model information into a hexadecimal string to obtain the graphics card model string; the client then obtains the last four characters of the graphics card model string, and uses the last four characters as the processor information. If the processor information is the obtained driver version field information, the client converts the driver version field information into a hexadecimal string to obtain the driver version field string; the client then obtains the last four characters of the driver version field string, and uses the last four characters as the processor information.

[0133] It should be noted that, in the process of the client concatenating the graphics card model string and the driver version field string to obtain the concatenated string, the client may add one character in the driver version field string after each bit of the graphics card model string to obtain the concatenated string; the client may also add one character in the graphics card model string after each bit of the driver version field string to obtain the concatenated string; the client may also concatenate the graphics card model string and the driver version field string in other ways to obtain the concatenated string. The specific concatenation method may be determined according to the actual situation, and the embodiments of the present application are not limited to this.

[0134] In an embodiment of the present application, the client program identifier can be UA (userAgent), which is a special string that includes the client's operating system and version, CPU type, browser and version, browser rendering engine, browser language, browser plug-in, etc.

[0135] In an embodiment of the present application, the process of the server determining the client identification based on the client address, the third timestamp, the processor information and the client program identification includes: the server obtains information of a fourth preset number of bits from the client program identification to obtain fourth information; the server obtains information of a fifth preset number of bits from the client address to obtain fifth information; the server obtains information of a sixth preset number of bits from the third timestamp to obtain sixth information; the server obtains information of a seventh preset number of bits from the processor information to obtain seventh information; the server splices the fourth information, the fifth information, the sixth information and the seventh information according to the second preset splicing order to obtain the client identification.

[0136] In an embodiment of the present application, the fourth preset number of bits, the fifth preset number of bits, the sixth preset number of bits and the seventh preset number of bits may be the same; the fourth preset number of bits, the fifth preset number of bits, the sixth preset number of bits and the seventh preset number of bits may also be different; the specific number may be determined according to actual conditions, and the embodiment of the present application does not limit this.

[0137] Exemplarily, if the fourth preset number of bits, the fifth preset number of bits, the sixth preset number of bits and the seventh preset number of bits may also be different, the fourth preset number of bits may be 8 bits, the fifth preset number of bits may be 4 bits, the sixth preset number of bits may be 8 bits, and the seventh preset number of bits may be 4 bits, that is: the server obtains the last 8 bits of information from the client program identifier to obtain the fourth information; the server obtains the last 4 bits of information from the client address to obtain the fifth information; the server obtains the last 8 bits of information from the third timestamp to obtain the sixth information; the server obtains the last 4 bits of information from the processor information to obtain the seventh information.

[0138] In the embodiment of the present application, the second preset splicing order may be a splicing order configured in the server. The specific second splicing order is to splice the fifth information after the fourth information; splice the sixth information after the fifth information, and splice the seventh information after the sixth information. That is, the server splices the fourth information, the fifth information, the sixth information, and the seventh information according to the second preset splicing order to obtain the client identification, including: the server splices the fifth information after the fourth information; splices the sixth information after the fifth information, and splices the seventh information after the sixth information, thereby obtaining the client identification.

[0139] For example, Fig.10 As shown: the server obtains the last 8 bits of information from the client program identifier to obtain the fourth information (72BC30AB); the server obtains the last 4 bits of information from the client address to obtain the fifth information (4106); the server obtains the last 8 bits of information from the third timestamp to obtain the sixth information (49496494); the server obtains the last 4 bits of information from the processor information to obtain the seventh information (ECAD). The server splices the fifth information after the fourth information; splices the sixth information after the fifth information, and splices the seventh information after the sixth information, thereby obtaining the client identifier.

[0140] S202: In the database, obtain the server-side auto-increment number and server-side processor information according to the client identifier.

[0141] In an embodiment of the present application, after the server obtains the client identifier and anti-replay code from the service request and determines the second timestamp when the service request is received, the server can obtain the server-side auto-increment number and server-side processor information in the database based on the client identifier.

[0142] In an embodiment of the present application, a database is provided in the server, and the database stores a server-side auto-increment number, server-side processor information and a client identifier.

[0143] S203, decrypt the anti-replay code according to the client identifier, the server self-increment number and the server processor information to obtain the first timestamp, the processor information and the updated self-increment number.

[0144] In an embodiment of the present application, after the server obtains the server-side self-increment number and server-side processor information in the database according to the client identifier, the server can decrypt the anti-replay code according to the client identifier, the server-side self-increment number and the server-side processor information to obtain the first timestamp, processor information, and the updated self-increment number.

[0145] In an embodiment of the present application, the server decrypts the anti-replay code according to the client identification, the server self-increment number and the server processor information to obtain a first timestamp, processor information, and an updated self-increment number, including: the server determines the number of initial bits of the server according to the server self-increment number, the preset value and the server processor information; the server converts the client identification according to the server self-increment number, the preset value and the server processor information to obtain encrypted information; the server decodes the anti-replay code according to the encrypted information and the server initial bit number to obtain a server splicing code; the server de-splices the server splicing code according to the first preset splicing order to obtain a first timestamp, processor information, and an updated self-increment number.

[0146] In the embodiment of the present application, the preset value may be a value configured in the client and the server. For example, the preset value may be 1, the preset value may be 2, or the preset value may be another positive integer value. The specific preset value may be determined according to the actual situation, and the embodiment of the present application does not limit this.

[0147] S204: Verify the first timestamp, processor information, and updated auto-increment number according to the second timestamp, server auto-increment number, and server processor information.

[0148] In an embodiment of the present application, the server decrypts the anti-replay code according to the client identification, the server self-increment number and the server processor information, and after obtaining the first timestamp, the processor information and the updated self-increment number, the server can then verify the first timestamp, the processor information and the updated self-increment number according to the second timestamp, the server self-increment number and the server processor information.

[0149] In an embodiment of the present application, the process of the server verifying the first timestamp, processor information, and updated auto-increment number based on the second timestamp, the server auto-increment number, and the server processor information includes: when the first timestamp and the updated auto-increment number are positive integers, the server compares the processor information with the server processor information; when the processor information is the same as the server processor information, the server determines the time interval between the first timestamp and the second timestamp; when the time interval is greater than a preset time interval, the server determines that the verification has failed; when the time interval is less than or equal to the preset time interval, the server determines that the verification has succeeded.

[0150] In an embodiment of the present application, the preset time interval may be a time interval configured in the server, or a time interval transmitted from other devices to the server; the preset time interval may also be a time interval obtained by the server in other ways; the specific way in which the server obtains the preset time interval may be determined based on actual conditions, and the embodiment of the present application does not limit this.

[0151] Exemplarily, the preset time interval may be 60 seconds; the preset time interval may also be 30 seconds; the preset time interval may also be other time intervals; the specific time interval may be determined based on actual conditions, and the embodiments of the present application are not limited to this.

[0152] In the embodiment of the present application, when the first timestamp or the updated auto-increment number is not a positive integer, the server determines that the verification has failed.

[0153] In the embodiment of the present application, when the processor information is the same as the server processor information, the server determines that the verification has failed.

[0154] In an embodiment of the present application, the process of determining that the verification is successful by the server when the time interval is less than or equal to the preset time interval includes: when the updated self-increment number is a positive integer and the time interval is less than or equal to the preset time interval, the server compares the difference between the updated self-increment number and the server-side self-increment number; when the difference is less than or equal to the preset difference, the server determines that the verification has failed; when the difference is greater than the preset difference, the server determines that the verification is successful, and updates the server-side self-increment number using the preset value to obtain an updated server-side self-increment number.

[0155] In an embodiment of the present application, the preset difference may be a difference configured in the server; the preset difference may also be a difference transmitted to the server by other devices; the preset difference may also be a difference obtained by the server in other ways; the specific way in which the server obtains the preset difference may be determined based on actual conditions, and the embodiment of the present application does not limit this.

[0156] Exemplarily, the preset difference may be 1, the preset difference may be 2, or other positive integer values. The specific preset difference may be determined based on actual conditions, and the embodiments of the present application are not limited thereto.

[0157] For example, Fig.11 As shown: the client transmits a service request to the server, and the service request carries a UID and an anti-replay code. When the server receives the service request, it first checks whether the anti-replay interface is called to transmit the service request (check whether the interface requires anti-replay protection). If not, the server executes the corresponding service processing according to the service request (no, pass the check and process normally). If the anti-replay interface is called to transmit the service request, the server decodes the anti-replay code and verifies the legitimacy of the service request (hit anti-replay, decode the anti-replay code, and verify whether it is legal). Specifically: the server decodes the anti-replay code to obtain a first timestamp and an updated auto-increment number. When the first timestamp and the updated auto-increment number are positive integers, the server determines that the service request is a legal request. The server obtains the verification configuration information (legal, obtains the verification configuration) from the verification rule configuration service, and obtains the verification configuration information including a preset time interval (the maximum interval difference between the interface and the interface). The server determines the second timestamp when the service request is received, and determines the time interval between the first timestamp and the second timestamp; when the time interval is greater than the preset time interval, it is determined that the verification has failed, and the server transmits a response message to the client rejecting the service request (illegal, rejecting the request); when the time interval is less than or equal to the preset time interval, it is determined that the verification is successful (determine the interval difference between the client and the server, compare the maximum interval difference of the interface, and judge whether it is legal). The server also includes a database (DB).

[0158] For example, Fig.12As shown: the client transmits a service request to the server, and the service request carries a UID and an anti-replay code. When the server receives the service request, it first checks whether the service request is transmitted by calling the anti-replay interface. If not, the server executes the corresponding service processing according to the service request (no, pass the check, and process normally). If the service request is transmitted by calling the anti-replay interface, the server decodes the anti-replay code to obtain a first timestamp and an updated auto-increment number. If the first timestamp or the updated auto-increment number is not a positive integer, the server determines that the service request is an illegal request, and the server transmits a response message to the client rejecting the service request (illegal, rejecting the request). When the first timestamp and the updated auto-increment number are positive integers, the server determines that the service request is a legal request. The server obtains the verification configuration information from the verification rule configuration service, and obtains the verification configuration information including a preset time interval. The server determines the second timestamp when the service request is received, and determines the time interval between the first timestamp and the second timestamp; when the time interval is greater than the preset time interval, it is determined that the verification has failed, and the server transmits a response message to the client rejecting the service request (illegal, request rejected); when the time interval is less than or equal to the preset time interval, it is determined that the verification is successful (determine the interval difference between the client and the server, compare it with the maximum interval difference of the interface, and judge whether it is legal). After that, the client obtains the customer ID from the business request, and uses the UID as the key to determine whether there is corresponding record information in the database (server DB). If there is no record in the DB, the verification passes, the business is processed normally, and the record data is created with the UID as the key. The processing flow of the business request continues according to the record data. If there is a record in the DB, the server-side auto-increment number and server-side processor information (return record data) are obtained in the DB according to the customer ID, and the difference between the updated auto-increment number and the server-side auto-increment number is compared (comparing the server-side auto-increment number in the input parameter and the DB). When the difference is less than or equal to the preset difference, the verification is determined to have failed (the server-side auto-increment number in the DB is greater than the input parameter, replay attack, and the request is rejected). When the difference is greater than the preset difference, the verification is determined to have succeeded (the updated auto-increment number in the input parameter is greater than the DB, and it is passed normally). The server-side auto-increment number is updated with the preset value to obtain the updated server-side auto-increment number (the comparison passes, the server-side auto-increment number in the input parameter is updated to the DB, and the server-side auto-increment number under the demo / test.json dimension is updated). The server executes the business processing corresponding to the business request (returns after processing the business).

[0159] S205: If the verification is successful, determine that the business request is a legitimate request, and execute the business processing procedure corresponding to the business request.

[0160] In an embodiment of the present application, after the server verifies the first timestamp, processor information, and updated auto-increment number based on the second timestamp, server-side auto-increment number, and server-side processor information, if the verification is successful, the server determines that the business request is a legitimate request and executes the business processing process corresponding to the business request.

[0161] In the embodiment of the present application, when the verification fails, the server determines that the service request is an illegal request and transmits a response message rejecting the service request to the client.

[0162] In the embodiment of the present application, the service processing process corresponding to the service request executed by the server is a process in the prior art, which can be specifically determined according to actual conditions, and the embodiment of the present application does not limit this.

[0163] Exemplarily, the server decrypts the anti-replay code according to the client identifier, the server self-increment number, and the server processor information to obtain the first timestamp, the processor information, and the updated self-increment number. Fig.13As shown: The UID can be 72BC30AB410649496494ECAD. The server groups the UIDs in pairs in ascending order to obtain 12 groups of characters, and then converts each of the 12 groups of characters into decimal numbers to obtain 12 groups of values, that is, generating a 12-bit dictionary MAP: 114, 188, 48, 171, 65, 06, 73, 73, 100, 148, 236, 173. Each element in the dictionary is a positive integer in the range of (0, 255). The server performs XOR inversion on each of the 12 groups of values, and obtains multiple XOR inversion data: 081, 141, 848, 171, 056, 76, 73, 13, 10, 284, 63, 371; determines the initial vector according to the processor information and the updated auto-increment number; uses the initial vector to perform bit-filling processing on multiple XOR inversion data respectively, and obtains multiple bit-filling data: that is, the new MAP is obtained: 173, 236, 148, 100, 415, 402, 06, 65, 171, 48, 158, 114. If the processor information (deviceId) is 60589, the server auto-increment number is updated with the preset value, and the updated server auto-increment number can be obtained as 0001. Set reduceNum to 2036. Use (updated server auto-increment number + processor information) mode12 to find the initial vector index 2. Starting from the initial vector position, the anti-replay code (9 (158-bit random number) 3 (114-bit random number) 1 (173-bit random number) 6 (236-bit random number) E (148-bit random number) C (100-bit random number) A (415-bit random number) D (402-bit random number) 0 (6-bit random number) 0 (65-bit random number) 0 (171-bit random number) 1 (48-bit random number)) is decoded according to the encryption information and the initial number of bits of the server to obtain the server splicing code (9316ECAD0001); the server splicing code is de-spliced ​​according to the first preset splicing order to obtain the first timestamp (first information: 9316), processor information (second information: ECAD), and updated self-increment number (third information: 0001).

[0164] For example, Fig.14As shown: after the client is started, the client identifier (UID) is initialized. When the corresponding anti-replay code is determined according to the UID, the anti-replay code and the client identifier are added to the first business request (demo / test.json), and the first business request carrying the anti-replay code and the client identifier is sent to the server (the first request interface demo / test.json, denoted as A). The server decrypts (decodes) the anti-replay code to obtain the first timestamp, processor information, and updated auto-increment number. The server compares the time interval between the first timestamp and the second timestamp (decoding, comparing timestamps). If the time interval is greater than the preset time interval, it is determined that the verification failed (illegal, and the request is rejected); if the time interval is less than or equal to the preset time interval, it is determined that the verification is successful, and there is no UID in the DB, then the auto-increment number corresponding to the UID is set to 1 (initialization is completed with input parameters), and the server executes the business processing process corresponding to the business request (verification passed, and business is processed). When the client receives the service request for calling the anti-replay interface to transmit the service (i.e., the second service request) again, the anti-replay code is determined again (demo / test.json is accessed again to redetermine the anti-replay code), and the client sends the second service request to the server again (requesting the interface demo / test.json again, denoted as B). The server decodes the anti-replay code in the second service request to obtain a new first timestamp, new processor information, and a newly updated auto-increment number. The server compares the time interval between the new first timestamp and the new second timestamp (decoding, comparing timestamps). If the time interval is less than or equal to the preset time interval, it is determined that the verification is successful. If the UID already exists in the DB, the server auto-increment number corresponding to the UID is obtained from the DB (the UID already exists in the DB, and the corresponding server auto-increment number is returned). The server compares the difference between the newly updated auto-increment number and the server auto-increment number; if the difference is greater than the preset difference, it is determined that the verification is successful (the verification passes, and the service is processed), and the server auto-increment number is updated with the preset value to obtain the updated server auto-increment number (update the server auto-increment number under the interface dimension in the DB).

[0165] It can be understood that since the anti-replay code is determined based on the customer identifier, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface, it is necessary to perform multi-layer calculations on the customer identifier, and then use the results of the multi-layer calculations on the customer identifier to perform multi-layer processing on the first timestamp, processor information and updated auto-increment number, thereby improving the security of the anti-replay code obtained, and using the highly secure anti-replay code to transmit the business requests of the anti-replay interface, thereby improving the quality of anti-replay attacks.

[0166] Based on the same inventive concept as the above-mentioned anti-replay attack method applied to the client, the embodiment of the present application provides a client 1, corresponding to an anti-replay attack method; Fig.15 A schematic diagram of the structure of a client provided in an embodiment of the present application Figure 1 , the client 1 may include:

[0167] The first determination unit 11 is used to determine the first timestamp when obtaining a request to call the anti-replay interface to transmit a service; determine the anti-replay code according to the client identifier corresponding to the anti-replay interface, the first timestamp, the processor information and the updated auto-increment number;

[0168] A first acquisition unit 12 is used to acquire the processor information of the client and the auto-increment number corresponding to the anti-replay interface;

[0169] A first updating unit 13, configured to update the self-incrementing number using a preset value to obtain an updated self-incrementing number;

[0170] An adding unit 14 is used to add the anti-replay code and the customer identifier to the service request,

[0171] The sending unit 15 is used to send the service request to the server.

[0172] In some embodiments of the present application, the first determining unit 11 is used to determine the anti-replay interface from the configuration file; determine whether there is a client identifier corresponding to the interface name;

[0173] The first acquiring unit 12 is configured to acquire the client identifier from the server when the client identifier does not exist.

[0174] In some embodiments of the present application, the client further includes a generating unit;

[0175] The first acquisition unit 12 is used to acquire the processor information and client program identifier of the client;

[0176] The generating unit is used to generate an identifier acquisition request;

[0177] The adding unit 14 is used to add the processor information and the client program identifier to the identifier acquisition request;

[0178] The sending unit 15 is used to send the identifier acquisition request to the server, so as to obtain the client identifier from the server according to the identifier acquisition request.

[0179] In some embodiments of the present application, the client further includes a first splicing unit, a conversion unit, and an encryption unit;

[0180] The first splicing unit is used to splice the first timestamp, the processor information and the updated self-increment number according to a first preset splicing order to obtain a splicing code;

[0181] The conversion unit is used to convert the customer identification to obtain encrypted information;

[0182] The encryption unit is used to encrypt the splicing code using the encryption information to obtain the anti-replay code.

[0183] In some embodiments of the present application, the client further includes a grouping unit and a padding unit;

[0184] The grouping unit is used to group the characters in the customer identification according to a preset number of characters to obtain multiple groups of characters;

[0185] The conversion unit is used to convert the multiple groups of characters into numbers respectively to obtain multiple groups of numerical values; perform XOR inversion on each group of numerical values ​​in the multiple groups of numerical values ​​to obtain multiple XOR inversion data;

[0186] The first determining unit 11 is used to determine the initial vector according to the processor information and the updated self-increment number;

[0187] The padding unit is used to perform padding processing on the multiple XOR inversion data respectively by using the initial vector to obtain multiple padding data, and use the multiple padding data as the encryption information.

[0188] In some embodiments of the present application, the client further includes a first comparison unit and a grouping unit;

[0189] The first concatenation unit is used to concatenate the multiple groups of values ​​to obtain a concatenated value string;

[0190] The first comparison unit is used to compare two adjacent values ​​in sequence starting from the starting value of the concatenated value string;

[0191] The grouping unit is used to divide the value with the smaller number of digits into different groups when two adjacent values ​​are different; and to divide the value with the smaller number of digits into or groups when two adjacent values ​​are the same;

[0192] The first determination unit 11 is used to determine the bit value corresponding to each group of values ​​in multiple groups of values ​​to obtain multiple bit values; determine the number of combined bits of the values ​​of the OR group according to the positive sorting method among the multiple bit values ​​to obtain at least one OR group data; determine the number of combined bits of the values ​​of the different group according to the reverse sorting method among the multiple bit values ​​to obtain at least one different group data; use the at least one OR group data and the at least one different group data as the multiple XOR inversion data.

[0193] In some embodiments of the present application, the first determining unit 11 is used to determine the number of bits of the splicing code; determine the initial number of bits according to the processor information, the updated self-increment number and the number of bits information;

[0194] The adding unit 14 is used to add a plurality of random numbers corresponding to the padding data after each character in the splicing code in sequence, starting from the initial number of bits, to obtain the anti-replay code; the number of bits in the splicing code is the same as the number of the plurality of padding data.

[0195] In some embodiments of the present application, the first acquiring unit 12 is used to acquire the first place-filling data among the plurality of place-filling data; acquire the second place-filling data after the first place-filling data among the plurality of place-filling data; and until the last place-filling data is acquired among the plurality of place-filling data;

[0196] The adding unit 14 is used to add a random number matching the first place-filling data after the first splicing character corresponding to the initial number of bits in the splicing code; add a random number matching the second place-filling data after the second splicing character after the first splicing code; and add a random number matching the last place-filling data before the first splicing character to obtain the anti-replay code.

[0197] In some embodiments of the present application, the first acquisition unit 12 is used to acquire information of a first preset number of bits from the first timestamp to obtain first information; acquire information of a second preset number of bits from the processor information to obtain second information; acquire information of a third preset number of bits from the updated self-increment number to obtain third information;

[0198] The first splicing unit is used to splice the first information, the second information and the third information according to a first preset splicing order to obtain the splicing code.

[0199] It should be noted that, in actual applications, the above-mentioned first determination unit 11, first acquisition unit 12, first update unit 13, adding unit 14 and sending unit 15 can be implemented by the first processor 16 on the client 1, specifically a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processing) or a field programmable gate array (FPGA); the above-mentioned data storage can be implemented by the first memory 17 on the client 1.

[0200] The present application embodiment also provides a client 1, such as Fig.16 As shown, the client 1 includes: a first processor 16, a first memory 17 and a first communication bus 18. The first memory 17 communicates with the first processor 16 through the first communication bus 18. The first memory 17 stores a program executable by the first processor 16. When the program is executed, the anti-replay attack method described above is executed by the first processor 16.

[0201] In practical applications, the first memory 17 may be a volatile memory, such as a random access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memories, and provide instructions and data to the first processor 16.

[0202] An embodiment of the present application provides a computer-readable storage medium having a computer program thereon, and when the program is executed by the first processor 16, the anti-replay attack method as described above is implemented.

[0203] It can be understood that the client obtains the first timestamp, processor information, and the auto-increment number corresponding to the anti-replay interface, determines the anti-replay code according to the customer identifier, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface, and uses the anti-replay code to implement the interface anti-replay process. Since it is necessary to perform multi-layer calculations on the customer identifier, and then use the results of the multi-layer calculations on the customer identifier to perform multi-layer processing on the first timestamp, processor information and updated auto-increment number, the security of the anti-replay code obtained is improved, and the highly secure anti-replay code is used to transmit the business requests of the anti-replay interface, thereby improving the quality of anti-replay attacks.

[0204] Based on the same inventive concept as the above-mentioned anti-replay attack method applied to the server, the embodiment of the present application provides a server 2 corresponding to an anti-replay attack method; Fig.17 A schematic diagram of the composition structure of a server provided in an embodiment of the present application Figure 1 , the server 2 may include:

[0205] The second acquisition unit 21 is used to obtain the client identification and anti-replay code from the service request when receiving the service request transmitted by the client; and obtain the server self-increment number and server processor information in the database according to the client identification;

[0206] A second determining unit 22 is used to determine a second timestamp when the service request is received; if the verification is successful, determine that the service request is a legitimate request;

[0207] A decryption unit 23, configured to decrypt the anti-replay code according to the client identifier, the server-side self-increment number and the server-side processor information to obtain a first timestamp, processor information and an updated self-increment number;

[0208] A verification unit 24, configured to verify the first timestamp, the processor information, and the updated auto-increment number according to the second timestamp, the server auto-increment number, and the server processor information;

[0209] The execution unit 25 is used to execute the business processing process corresponding to the business request.

[0210] In some embodiments of the present application, the server further includes a processing unit, a decoding unit, and a second splicing unit;

[0211] The second determining unit 22 is used to determine the initial number of bits of the server according to the server self-increment number, the preset value and the server processor information;

[0212] The processing unit is used to convert the client identifier according to the server-side self-increment number, the preset value and the server-side processor information to obtain encrypted information;

[0213] The decoding unit is used to decode the anti-replay code according to the encryption information and the initial number of bits of the server to obtain a server splicing code;

[0214] The second splicing unit is used to de-splice the server-side splicing code according to a first preset splicing order to obtain a first timestamp, processor information, and an updated self-increment number.

[0215] In some embodiments of the present application, the server further includes a second comparison unit;

[0216] The second comparison unit is used to compare the processor information with the server processor information when the first timestamp and the updated self-increment number are positive integers;

[0217] The second determination unit 22 is used to determine the time interval between the first timestamp and the second timestamp when the processor information is the same as the server processor information; determine that the verification has failed when the time interval is greater than a preset time interval; and determine that the verification has succeeded when the time interval is less than or equal to a preset time interval.

[0218] In some embodiments of the present application, the server further includes a second updating unit;

[0219] The second comparison unit is used to compare the difference between the updated self-increment number and the server-side self-increment number when the updated self-increment number is a positive integer and the time interval is less than or equal to the preset time interval;

[0220] The second determination unit 22 is configured to determine that the verification fails if the difference is less than or equal to a preset difference; and determine that the verification succeeds if the difference is greater than the preset difference;

[0221] The second updating unit is used to update the server-side self-increment number using a preset value to obtain an updated server-side self-increment number.

[0222] In some embodiments of the present application, the second determining unit 22 is used to determine, when receiving an identifier acquisition request sent by a client, a third timestamp of receiving the identifier acquisition request; determine the client address; determine the client identifier according to the client address, the third timestamp, the processor information and the client program identifier;

[0223] The second acquisition unit 21 is used to acquire processor information and client program identification from the identifier acquisition request.

[0224] In some embodiments of the present application, the second acquisition unit 21 is used to acquire information of a fourth preset number of digits from the client program identifier to obtain fourth information; acquire information of a fifth preset number of digits from the client address to obtain fifth information; acquire information of a sixth preset number of digits from the third timestamp to obtain sixth information; acquire information of a seventh preset number of digits from the processor information to obtain seventh information;

[0225] The second splicing unit is used to splice the fourth information, the fifth information, the sixth information and the seventh information according to a second preset splicing order to obtain the customer identification.

[0226] It should be noted that, in actual applications, the above-mentioned second acquisition unit 21, second determination unit 22, decryption unit 23, verification unit 24 and execution unit 25 can be implemented by the second processor 26 on the server 2, specifically a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processing) or a field programmable gate array (FPGA); the above-mentioned data storage can be implemented by the second memory 27 on the server 2.

[0227] The present application embodiment also provides a server 2, such as Fig.18 As shown, the server 2 includes: a second processor 26, a second memory 27 and a second communication bus 28. The second memory 27 communicates with the second processor 26 via the second communication bus 28. The second memory 27 stores a program executable by the second processor 26. When the program is executed, the anti-replay attack method described above is executed by the second processor 26.

[0228] In practical applications, the second memory 27 may be a volatile memory, such as a random access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memories, and provide instructions and data to the second processor 26.

[0229] The embodiment of the present application provides a computer-readable storage medium having a computer program thereon, and when the program is executed by the second processor 26, the anti-replay attack method as described above is implemented.

[0230] It can be understood that since the anti-replay code is determined based on the customer identifier, first timestamp, processor information and updated auto-increment number corresponding to the anti-replay interface, it is necessary to perform multi-layer calculations on the customer identifier, and then use the results of the multi-layer calculations on the customer identifier to perform multi-layer processing on the first timestamp, processor information and updated auto-increment number, thereby improving the security of the anti-replay code obtained, and using the highly secure anti-replay code to transmit the business requests of the anti-replay interface, thereby improving the quality of anti-replay attacks.

[0231] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of hardware embodiments, software embodiments, or embodiments in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.

[0232] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0233] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0234] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0235] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.

Claims

1. A method for preventing replay attacks, characterized in that: Applied to a client, the method comprises: In the case of obtaining a service request for calling an anti-replay interface to transmit, determining a first timestamp, and obtaining processor information of the client and an auto-increment number corresponding to the anti-replay interface; The self-increment number is updated using a preset value to obtain an updated self-increment number; Determine an anti-replay code according to the client identifier corresponding to the anti-replay interface, the first timestamp, the processor information and the updated auto-increment number; Adding the anti-replay code and the client identifier to the service request; and sending the service request to the server; The step of determining the anti-replay code according to the client identifier corresponding to the anti-replay interface, the first timestamp, the processor information, and the updated self-increment number includes: splicing the first timestamp, the processor information and the updated self-increment number according to a first preset splicing order to obtain a splicing code; Converting the customer ID to obtain encrypted information; Utilizing the encryption information to encrypt the splicing code to obtain the anti-replay code; The converting process of the customer identification to obtain encrypted information includes: Grouping the characters in the customer identification according to a preset number of characters to obtain multiple groups of characters; Convert the multiple groups of characters into numbers respectively to obtain multiple groups of numerical values; Performing XOR inversion on each group of values ​​in the multiple groups of values ​​to obtain multiple XOR inversion data; Determine an initial vector according to the processor information and the updated self-increment number; Using the initial vector to perform padding processing on the multiple XOR inversion data respectively to obtain multiple padding data, and using the multiple padding data as the encryption information; The performing XOR inversion on each of the plurality of sets of values ​​to obtain a plurality of XOR inversion data includes: The plurality of groups of values ​​are concatenated to obtain a concatenated value string; starting from a starting value of the concatenated value string, two adjacent values ​​are compared in sequence; When two adjacent values ​​are different, the value with the smaller number of digits is divided into different groups; when two adjacent values ​​are the same, the value with the smaller number of digits is divided into or groups; Determine the place value corresponding to each group of values ​​in the multiple groups of values ​​to obtain multiple place values; According to the positive order of the plurality of digit values, the number of combined digits of the values ​​of the or group is determined to obtain at least one or group data; according to the reverse order of the plurality of digit values, the number of combined digits of the values ​​of the different group is determined to obtain at least one different group data; The at least one OR grouped data and the at least one XOR grouped data are used as the plurality of XOR inversion data.

2. The method according to claim 1, characterized in that In the case where a request for calling an anti-replay interface to transmit a service is obtained, before determining the first timestamp, the method further includes: Determine the anti-replay interface from the configuration file; Determine whether there is a customer identifier corresponding to the interface name; If the client identifier does not exist, the client identifier is obtained from the server.

3. The method according to claim 2, characterized in that The obtaining the client identifier from the server includes: Obtaining processor information and client program identification of the client; Generate an identifier acquisition request, and add the processor information and the client program identifier to the identifier acquisition request; The identifier acquisition request is sent to the server to acquire the client identifier from the server according to the identifier acquisition request.

4. The method according to claim 1, characterized in that: The step of encrypting the splicing code using the encryption information to obtain the anti-replay code includes: Determine the number of bits of the splicing code; Determine an initial number of bits according to the processor information, the updated self-increment number and the number of bits information; In the splicing code, starting from the initial bit number, random numbers corresponding to multiple bit-filling data are added after each character in the splicing code in turn to obtain the anti-replay code; the number of bits of the splicing code is the same as the number of the multiple bit-filling data.

5. The method according to claim 4, characterized in that In the splicing code, starting from the initial bit number, a plurality of random numbers corresponding to the padding data are sequentially added after each character in the splicing code to obtain the anti-replay code, including: Obtaining a first place-filling data from the plurality of place-filling data, and adding a random number matching the first place-filling data after the first splicing character corresponding to the initial number of bits in the splicing code; The second place-filling data after the first place-filling data is obtained from the multiple place-filling data, and a random number matching the second place-filling data is added after the second splicing character after the first splicing code; until the last place-filling data is obtained from the multiple place-filling data, and a random number matching the last place-filling data is added before the first splicing character to obtain the anti-replay code.

6. The method according to claim 1, characterized in that The step of splicing the first timestamp, the processor information and the updated self-increment number according to a first preset splicing order to obtain a splicing code includes: Acquire information of a first preset number of bits from the first timestamp to obtain first information; Acquire information of a second preset number of bits from the processor information to obtain second information; Obtain information of a third preset number of bits from the updated self-increment number to obtain third information; The first information, the second information and the third information are spliced ​​according to a first preset splicing order to obtain the splicing code.

7. A method for preventing replay attacks, characterized in that: Applied to a server, the method comprises: When receiving a service request transmitted by a client, obtaining a client identifier and an anti-replay code from the service request, and determining a second timestamp when the service request is received; In the database, obtaining the server-side auto-increment number and server-side processor information according to the client identifier; Decrypt the anti-replay code according to the client identifier, the server-side self-increment number and the server-side processor information to obtain a first timestamp, processor information and an updated self-increment number; Verify the first timestamp, processor information, and updated auto-increment number according to the second timestamp, the server auto-increment number, and the server processor information; If the verification is successful, determine that the service request is a legitimate request, and execute the service processing process corresponding to the service request; The anti-replay code is determined by the client in the following manner: splicing the first timestamp, the processor information and the updated self-increment number according to a first preset splicing order to obtain a splicing code; Grouping the characters in the customer identification according to a preset number of characters to obtain multiple groups of characters; Convert the multiple groups of characters into numbers respectively to obtain multiple groups of numerical values; The plurality of groups of values ​​are concatenated to obtain a concatenated value string; starting from a starting value of the concatenated value string, two adjacent values ​​are compared in sequence; When two adjacent values ​​are different, the value with the smaller number of digits is divided into different groups; when two adjacent values ​​are the same, the value with the smaller number of digits is divided into or groups; Determine the place value corresponding to each group of values ​​in the multiple groups of values ​​to obtain multiple place values; According to the positive order of the plurality of digit values, the number of combined digits of the values ​​of the or group is determined to obtain at least one or group data; according to the reverse order of the plurality of digit values, the number of combined digits of the values ​​of the different group is determined to obtain at least one different group data; taking the at least one OR grouped data and the at least one XOR grouped data as a plurality of XOR inversion data; Determine an initial vector according to the processor information and the updated self-increment number; Using the initial vector to perform padding processing on the plurality of XOR inverted data respectively to obtain a plurality of padding data, and using the plurality of padding data as encryption information; The splicing code is encrypted using the encryption information to obtain the anti-replay code.

8. The method according to claim 7, characterized in that The anti-replay code is decrypted according to the client identifier, the server self-increment number and the server processor information to obtain a first timestamp, processor information and an updated self-increment number, including: Determine the initial number of bits of the server according to the server self-increment number, the preset value and the server processor information; The client identifier is converted according to the server-side self-increment number, the preset value and the server-side processor information to obtain encrypted information; Decoding the anti-replay code according to the encryption information and the initial number of bits of the server to obtain a server splicing code; The server-side splicing code is de-spliced ​​according to a first preset splicing order to obtain a first timestamp, processor information, and an updated self-increment number.

9. The method according to claim 7, characterized in that: The verifying the first timestamp, the processor information, and the updated auto-increment number according to the second timestamp, the server auto-increment number, and the server processor information includes: When the first timestamp and the updated auto-increment number are positive integers, comparing the processor information with the server-side processor information; In a case where the processor information is the same as the server-side processor information, determining a time interval between the first timestamp and the second timestamp; If the time interval is greater than a preset time interval, determining that the verification fails; When the time interval is less than or equal to the preset time interval, it is determined that the verification is successful.

10. The method according to claim 9, characterized in that When the time interval is less than or equal to the preset time interval, determining that the verification is successful includes: When the updated self-increment number is a positive integer and the time interval is less than or equal to the preset time interval, compare the difference between the updated self-increment number and the server-side self-increment number; If the difference is less than or equal to a preset difference, determining that the verification fails; In the case where the difference is greater than the preset difference, it is determined that the verification is successful, and the server-side self-increment number is updated using the preset value to obtain an updated server-side self-increment number.

11. The method according to claim 7, characterized in that In the case of receiving a service request transmitted by a client, before obtaining a client identifier and an anti-replay code from the service request, the method further includes: In the case of receiving an identifier acquisition request sent by the client, determining a third timestamp of receiving the identifier acquisition request; and acquiring processor information and a client program identifier from the identifier acquisition request; Determining the client address; A client identifier is determined according to the client address, the third timestamp, the processor information, and the client program identifier.

12. The method according to claim 11, characterized in that The determining the client identifier according to the client address, the third timestamp, the processor information and the client program identifier includes: Acquire information of a fourth preset number of digits from the client program identifier to obtain fourth information; Acquire information of a fifth preset number of bits from the client address to obtain fifth information; Acquire information of a sixth preset number of bits from the third timestamp to obtain sixth information; Acquire information of a seventh preset number of bits from the processor information to obtain seventh information; The fourth information, the fifth information, the sixth information and the seventh information are concatenated according to a second preset concatenation order to obtain the customer identification.

13. A client, characterized in that: The client comprises: A first determination unit is used to determine a first timestamp when a service request for calling an anti-replay interface is obtained; and determine an anti-replay code according to a client identifier corresponding to the anti-replay interface, the first timestamp, processor information, and an updated auto-increment number; A first acquisition unit, used to acquire processor information of the client and an auto-increment number corresponding to the anti-replay interface; A first updating unit, configured to update the auto-increment number using a preset value to obtain an updated auto-increment number; an adding unit, configured to add the anti-replay code and the client identifier to the service request, A sending unit, used for sending the service request to the server; A first splicing unit, configured to splice the first timestamp, the processor information and the updated self-increment number according to a first preset splicing order to obtain a splicing code; A conversion unit, used for converting the customer identification to obtain encrypted information; An encryption unit, used for encrypting the splicing code using the encryption information to obtain the anti-replay code; A grouping unit, used to group the characters in the customer identification according to a preset number of characters to obtain multiple groups of characters; A conversion unit, used to convert the multiple groups of characters into numbers respectively to obtain multiple groups of numerical values; and to perform XOR inversion on each group of numerical values ​​in the multiple groups of numerical values ​​to obtain multiple XOR inversion data; The first determining unit is further configured to determine an initial vector according to the processor information and the updated self-increment number; a padding unit, configured to perform padding processing on the plurality of XOR inversion data respectively by using the initial vector to obtain a plurality of padding data, and use the plurality of padding data as the encryption information; The first concatenation unit is further used to concatenate the multiple groups of values ​​to obtain a concatenated value string; A first comparison unit is used to compare two adjacent values ​​in sequence starting from the starting value of the concatenated value string; The grouping unit is used to divide the value with the smaller number of digits into different groups when two adjacent values ​​are different; and to divide the value with the smaller number of digits into or groups when two adjacent values ​​are the same; The first determination unit is also used to determine the bit value corresponding to each group of values ​​in multiple groups of values ​​to obtain multiple bit values; determine the number of combined bit positions of the values ​​of the OR group according to the positive sorting method among the multiple bit values ​​to obtain at least one OR group data; determine the number of combined bit positions of the values ​​of the different group according to the reverse sorting method among the multiple bit values ​​to obtain at least one different group data; use the at least one OR group data and the at least one different group data as the multiple XOR inversion data.

14. A server, characterized in that: The server comprises: The second acquisition unit is used to obtain the client identification and anti-replay code from the service request when receiving the service request transmitted by the client; and obtain the server self-increment number and server processor information in the database according to the client identification; A second determining unit, configured to determine a second timestamp when the service request is received; if the verification is successful, determining that the service request is a legitimate request; A decryption unit, used to decrypt the anti-replay code according to the client identifier, the server-side self-increment number and the server-side processor information to obtain a first timestamp, processor information and an updated self-increment number; A verification unit, configured to verify the first timestamp, the processor information, and the updated auto-increment number according to the second timestamp, the server auto-increment number, and the server processor information; An execution unit, used to execute the business processing process corresponding to the business request; The anti-replay code is determined in the following manner: The first timestamp, the processor information and the updated auto-increment number are spliced ​​in a first preset splicing order to obtain a splicing code; the characters in the customer identification are grouped according to a preset number of characters to obtain multiple groups of characters; the multiple groups of characters are converted into numbers respectively to obtain multiple groups of values; the multiple groups of values ​​are spliced ​​to obtain a spliced ​​value string; starting from the starting value of the spliced ​​value string, two adjacent values ​​are compared in sequence; when two adjacent values ​​are different, the value with a smaller number of digits is divided into different groups; when two adjacent values ​​are the same, the value with a smaller number of digits is divided into or groups; the bit value corresponding to each group of values ​​in the multiple groups of values ​​is determined to obtain multiple bit values; according to the According to the positive order sorting method among the multiple bit values, the number of combined digits of the OR grouped values ​​is determined to obtain at least one OR grouped data; according to the reverse order sorting method among the multiple bit values, the number of combined digits of the different grouped values ​​is determined to obtain at least one different grouped data; the at least one OR grouped data and the at least one different grouped data are used as multiple XOR inversion data; an initial vector is determined according to the processor information and the updated self-increment number; the multiple XOR inversion data are respectively supplemented by the initial vector to obtain multiple supplemented data, and the multiple supplemented data are used as encryption information; the splicing code is encrypted by the encryption information to obtain the anti-replay code.

15. A client, characterized in that: The client comprises: A first memory, a first processor and a first communication bus, wherein the first memory communicates with the first processor via the first communication bus, the first memory stores an anti-replay attack program executable by the first processor, and when the anti-replay attack program is executed, the method applied to the client as claimed in any one of claims 1 to 6 is executed by the first processor.

16. A server, characterized in that: The server comprises: A second memory, a second processor and a second communication bus, the second memory communicates with the second processor via the second communication bus, the second memory stores an anti-replay attack program executable by the second processor, and when the anti-replay attack program is executed, the method applied to the server as claimed in any one of claims 7 to 12 is executed by the second processor.

17. A storage medium having a computer program stored thereon, applied to a client or a server, characterized in that: When the computer program is executed by the first processor, the method of any one of claims 1 to 6 is implemented as applied to the client; or when the computer program is executed by the second processor, the method of any one of claims 7 to 12 is implemented as applied to the server.

Citation Information

Patent Citations

  • Method for preventing replay attack of API (Application Program Interface)

    CN113382011A