A method, device, electronic device and storage medium for preventing duplicate requests

Through the signature verification and valid duration mechanism, combined with time stamp verification, the problem of replay attacks and tampering in the request prevention method is solved, and the security and stability of the system are improved.

CN115664677BActive Publication Date: 2025-07-11AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211309964.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-25
Publication Date
2025-07-11
Estimated Expiration
2042-10-25

AI Technical Summary

Technical Problem

The existing request prevention method cannot effectively prevent retransmission attacks, especially the problem of man-in-the-middle tampering, and there are security vulnerabilities caused by time fault tolerance windows.

Method used

By receiving the signed and non-signed messages of the target requester, using the public key signature verification process, the random number index value is determined, and the validity time is set, and the validity of the request is verified in combination with the timestamp to prevent replay attacks.

Benefits of technology

It improves the system's ability to resist risks, ensures the stability and security of the system, and prevents request messages from being intercepted, retransmitted or tampered.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664677B_ABST
    Figure CN115664677B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, electronic device and storage medium for preventing request retransmission. A request message sent by a target requestor is received; the signature message and the non-signature message are verified based on the public key corresponding to the target requestor, and when the verification passes, it is determined whether the target cache includes an index value corresponding to the random number in the signature message; if not, the random number is used as the index value corresponding to the request message, and the effective duration corresponding to the index value is set; based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the effective duration, it is determined whether the request message is valid. The technical problem that the timestamp and the random number are randomly tampered with during the user service request process is solved, the service request replay verification is realized, the risk resistance ability of the system is improved, the stability of the system is ensured, and the requirements of system security, stability and compliance can be better met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a method, device, electronic device, and storage medium for preventing request resending. Background Art

[0002] Open banking is a new type of innovative platform-based business model. Banks use financial technology means to embed financial products and services into the application programs of cooperative Internet scenario platforms, enabling financial services to be everywhere. Open banking can mainly provide external services in various forms. However, the Internet scenario is an open scenario, and the network environment, operating environment, etc. are very complex. In the actual application process, the situation of resending attacks will be encountered. Therefore, in order to provide safe, stable, and compliant services, it is necessary to explore methods for preventing request resending.

[0003] In the prior art, there are two methods for preventing request resending: one is to perform verification based on timestamps. The method of adding timestamps is to add a timestamp to the request message. When the receiving party receives the message and after signature verification, the timestamp field in the request is compared with the local time. If the time error is within the specified time, the request is considered reasonable. The other is to perform verification based on random numbers. This method means that after the receiving party receives the message and performs signature verification, it obtains the random number and determines whether the random number has been processed.

[0004] However, the problems with the method of adding timestamps are as follows: The method of adding timestamps sets a time tolerance window, which is a time interval, and resending attacks within this time window cannot be prevented, and there is no clear method for calculating the time tolerance window. The problem with the random number verification method is that during the verification process, it is necessary to ensure historical global uniqueness. Therefore, a large amount of random data needs to be saved, which will cause a serious burden on the operation process of preventing request resending. Moreover, neither of the two methods for preventing request resending can solve the problem of the request message being tampered with by a man-in-the-middle. Summary of the Invention

[0005] The present invention provides a method, device, electronic device, and storage medium for preventing request resending, which realizes the replay verification of service requests, improves the risk resistance ability of the system, and ensures the stability and security of the system.

[0006] In a first aspect, the present invention provides a method for preventing request resending, the method comprising:

[0007] Receiving a request message sent by a target requester; wherein, the request message includes a signed message and an unsigned message, and the request message includes a request timestamp, a random number, and request associated data;

[0008] Verify the signature of the signed message and the unsigned message based on the public key corresponding to the target requestor, and when the signature verification passes, determine whether the target cache includes an index value corresponding to the random number in the signed message;

[0009] If not, use the random number as the index value corresponding to the request message, and set the valid duration corresponding to the index value;

[0010] Based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the valid duration, determine whether the request message is valid.

[0011] In a second aspect, the present invention provides a request anti-duplicate transmission device, which includes:

[0012] A request message receiving module, configured to receive a request message sent by a target requestor; wherein, the request message includes a signed message and an unsigned message, and the request message includes a request timestamp, a random number, and request associated data;

[0013] A signature verification processing module, configured to verify the signature of the signed message and the unsigned message based on the public key corresponding to the target requestor, and when the signature verification passes, determine whether the target cache includes an index value corresponding to the random number in the signed message;

[0014] A valid duration setting module, configured to, if the target cache does not include an index value corresponding to the random number in the signed message, use the random number as the index value corresponding to the request message, and set the valid duration corresponding to the index value;

[0015] A request validity determination module, configured to determine whether the request message is valid based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the valid duration.

[0016] In a third aspect, the present invention provides an electronic device for request anti-duplicate transmission, including:

[0017] At least one processor; and

[0018] A memory communicatively connected to the at least one processor; wherein,

[0019] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the request anti-duplicate transmission method of any embodiment of the present invention.

[0020] In a fourth aspect, the present invention provides a computer-readable storage medium, which stores computer instructions for causing a processor to implement the request anti-duplicate transmission method of any embodiment of the present invention when executed.

[0021] Fifth aspect, the present invention provides a computer program product, which includes a computer program that, when executed by a processor, implements the request anti-duplicate transmission method according to any embodiment of the present invention.

[0022] The technical solution provided by the embodiments of the present invention is to receive a request message including a signed message and an unsigned message sent by a target requester. Subsequently, verify the signature of the signed message and the unsigned message based on the public key corresponding to the target requester. When the signature verification passes, determine whether the target cache includes an index value corresponding to the random number in the signed message. If the target cache does not include an index value corresponding to the random number in the signed message, use the random number as the index value corresponding to the request message and set the effective duration corresponding to the index value. Furthermore, based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the effective duration, determine whether the request message is valid. The above technical solution solves the technical problem that the request message is intercepted and retransmitted or arbitrarily tampered with during the user service request process. By using random numbers and timestamps to prevent the request message from being subject to replay attacks, service request replay verification is achieved. By signature verification, it is prevented that the random number or timestamp is tampered with, so as to achieve the effect of avoiding replay attacks, improve the risk resistance ability of the system, ensure the stability of the system, and better meet the requirements of system security, stability, and compliance.

[0023] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0025] Figure 1 It is a schematic diagram of the overall structure of the system provided in Embodiment 1 of the present invention;

[0026] Figure 2 It is a flowchart of a request anti-duplicate transmission method provided in Embodiment 1 of the present invention;

[0027] Figure 3 It is a flowchart of a request anti-duplicate transmission method provided in Embodiment 2 of the present invention;

[0028] Figure 4 It is a flowchart of a request anti-duplicate transmission method provided in Embodiment 3 of the present invention;

[0029] Figure 5 Schematic structural diagram of a request anti-retransmission device provided in Embodiment 4 of the present invention;

[0030] Figure 6 Schematic structural diagram of an electronic device provided in Embodiment 5 of the present invention. Detailed implementation manners

[0031] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0032] It should be noted that the terms "first preset condition", "second preset condition", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0033] Embodiment 1

[0034] Before introducing the technical solution, an exemplary description of the application scenario can be given first. Open service is a technology that uses technologies such as open application programming interface (API) to realize data sharing between service providers and third-party institutions, plug-and-play of business services and products, thereby improving the user experience and building an open ecosystem. For the overall structural diagram of the system, see Figure 1 . As Figure 1 shown, the system may include two main bodies, a requester and a service provider. The requester sends a request message, and the service provider receives the request message, validates the message, and responds to the request. In this process, there is a risk of replay attack. Replay attack is a form of network attack that maliciously or fraudulently repeats or delays valid data. This replay attack can be executed by the initiator or by an opponent who intercepts the data and retransmits the data. Therefore, the technical solution proposed in the embodiments of the present invention realizes the prevention of replay attack in the request process.

[0035] Figure 2 This is a flowchart of a request replay prevention method provided in Embodiment 1 of the present invention. This embodiment can be applied to the situation of preventing request replay attacks. The method can be executed by a request replay prevention device, which can be implemented in the form of hardware and / or software. The request replay prevention device can be configured on a computer device, which can be a notebook, a desktop computer, a smart tablet, etc. Figure 2 As shown, the method includes:

[0036] S110: Receive a request message sent by a target requester.

[0037] The target requester can be understood as the client that initiates the request. The target requester can initiate the business processing request through the system front-end entrance. The request message is a message sent from the requester to the service provider. The request message can be understood as a data block sent between applications. These data blocks begin with some text-based meta-information that describes the content and meaning of the message, followed by an optional data part. These messages can flow between the requester and the service provider.

[0038] In this embodiment, before receiving the request message sent by the target requester, it also includes: sending a business processing request based on the target requester, and determining a request timestamp corresponding to the business processing request; generating a random number based on a universal unique identifier; and determining the request message based on the request timestamp, the random number, and the request associated data corresponding to the business processing request.

[0039] Among them, the request timestamp is the time information corresponding to the moment when the target requester initiates the request. In order to clearly introduce the technical solution provided by the embodiment of the present invention, the timestamp can be represented by the abbreviation "T"; the random number can be dynamically obtained by using a programming language to obtain a universal unique identifier (UUID) as a request random number. The characteristic of the random number is that the random number requested at the current moment will not be repeated. In this embodiment, the abbreviation "R" can be used to represent the random number; the request-related data is some business data associated with the business processing request, for example, the account number involved in the transaction process that needs to be purchased, the account payment password, the corresponding order number and other information. In this embodiment, the abbreviation "B" can be used to represent the request-related data. The request timestamp, random number and request-related data determined above are spliced ​​to determine the request message.

[0040] It should be noted that the request message includes a signed message and an unsigned message. Next, a detailed introduction will be given on how to generate the signed message and the unsigned message. Optionally, based on the request timestamp, random number, and request associated data corresponding to the service processing request, a request message is determined, including: determining the unsigned message by concatenating the request timestamp, random number, and request associated data; and performing a signature process on the unsigned message based on the private key corresponding to the target requestor to obtain the signed message.

[0041] In this embodiment, the unsigned message is the string information content obtained by concatenating the request timestamp, random number, and request associated data. In this embodiment, the unsigned message can be represented by the abbreviation "P" for simplicity. Since the request timestamp T, random number R, and request associated data B are three different data contents with different data formats and different meanings, subsequent processing is performed on each of them separately, which increases the complexity of the processing process and is not conducive to subsequent processing. Therefore, the request timestamp T, random number R, and request associated data B are simply concatenated to obtain a string containing the contents of the three, which is convenient for subsequent data processing.

[0042] Furthermore, a signature process is performed on the unsigned message to obtain the signed message. In this process, a signature process is involved. The signature process can use digital signature, which refers to a digital string that cannot be forged by others generated by using asymmetric key encryption technology and digital digest technology. This digital string is also an effective proof of the authenticity of the information sent by the information sender. In the actual application process, the requestor is configured with a requestor private key, and the requestor private key is unique for each target requestor. Therefore, a signature process can be performed on the unsigned message based on the private key corresponding to the target requestor to obtain the signed message. The signed message can also be represented as a string. In this embodiment, the signed message can be represented by the abbreviation "P1" for simplicity.

[0043] Exemplarily, the target requestor sends a service processing request through the system front-end entry. At this time, the request timestamp T corresponding to the service processing request is obtained, a random number R is generated based on the Universally Unique Identifier, and the request associated data B corresponding to the service processing request is obtained; subsequently, the timestamp T, random number R, and request associated data B are concatenated to obtain the unsigned message P; furthermore, a digital signature process is performed on the unsigned message based on the private key corresponding to the target requestor to obtain the signed message P1; finally, the unsigned message P and the signed message P1 are sent to the service provider as the request message, and the service provider receives the request message sent by the target requestor.

[0044] S120. Perform a verification process on the signed message and the unsigned message based on the public key corresponding to the target requestor, and when the verification passes, determine whether the target cache includes an index value corresponding to the random number in the signed message.

[0045] In this embodiment, the public key and the private key are a key pair obtained through an algorithm (i.e., a public key and a private key). One of them is made public to the outside world and is called the public key; the other is kept by oneself and is called the private key. The key pair obtained through this algorithm can ensure uniqueness worldwide. Each requester is equipped with a private key, and the public key is the key that can encrypt the private key of the target requester. When using this key pair, if one key is used to encrypt a piece of data, the other key must be used to decrypt it. For example, if the public key is used to encrypt the data, the private key must be used to decrypt it; if the private key is used to encrypt, the public key must also be used to decrypt it, otherwise the decryption will not succeed. In the actual application process, the private key of the target requester and the corresponding public key of the service provider are pre-configured, that is, the public key of the service provider and the private key of the target requester are a key pair. The private key of the target requester is used to encrypt the request message, and the corresponding public key of the service provider can be used to decrypt the request message.

[0046] In this embodiment, the signature verification process refers to that for the request message received by the service provider, the service provider performs a signature process, compares the signature generated by the service provider's signature with the received signature value. If the pre-set decryption rule is satisfied, the signature verification is successful. If the pre-set decryption rule is not satisfied, the signature verification is not successful.

[0047] In this embodiment, the target cache can refer to the value stored in the Remote Dictionary Server (Redis). When it is necessary to repeatedly confirm the current random number, the value stored in Redis can be called. Among them, Redis is an open-source database, a key-value storage database written in C language that can be based on memory or persistent. The value supports multiple storage types, including String, Hash, List, sets, and sorted sets, and can be used as a database, cache, and message middleware. The index value is the random number stored in Redis, and the index value can be the random number generated within a period of time before the target request.

[0048] Exemplarily, when the service provider receives the request message sent by the target requester, the public key corresponding to the target requester is used to decrypt the signature message in the request message to obtain the digest information D corresponding to the signature message. Then, the service provider generates the digest information d according to the non-signature message using the public key corresponding to the target requester. At this time, the service provider compares whether D is the same as d. If D is not the same as d, it means that the signature verification fails; if D is the same as d, it means that the signature verification passes. At this time, it is determined whether the Redis includes the index value corresponding to the random number in the signature message.

[0049] S130. If the verification of the signed message and the unsigned message using the public key corresponding to the target requester fails, the random number is used as the index value corresponding to the request message, and the valid duration corresponding to the index value is set.

[0050] Among them, the valid duration is the pre-set time information. For example, the valid duration can be set to 2 minutes. Specifically, it can be understood that within 2 minutes, if it is detected that the random number in the current request message has appeared before, the current request is considered an illegal request. In the actual application process, the random number in the request message sent by the target requester can be cached in Redis. However, in the actual application process, it is impossible to permanently cache the random number in Redis. Therefore, it is necessary to pre-set the valid duration.

[0051] Exemplarily, if the result of verifying the signed message and the unsigned message using the public key fails, the random number in the current request message is cached in Redis as the index value corresponding to the request message, and then the valid duration corresponding to the current index value is set. For example, if the limited duration is set to 2 minutes, it means that starting from the reception of the current index value, within the next 2 minutes, if a random number identical to the current index value is found, the corresponding request at this time is regarded as an illegal request; starting from the reception of the current index value, after 2 minutes, the current index value will be cleared from the Redis cache data.

[0052] Furthermore, based on the above example, when the verification fails or the target cache includes the random number in the signed message, it is determined that the service processing request corresponding to the request message is invalid.

[0053] In this embodiment, during the verification process, if D and d are different, it means that the verification passes. At this time, the service processing request corresponding to the request message is regarded as invalid, and the corresponding request content is not responded to; or, the target cache includes the random number in the signed message. At this time, there may also be a risk of request replay, and the service processing request corresponding to the request message is regarded as invalid, and the corresponding request content is not responded to.

[0054] S140. Based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the valid duration, determine whether the request message is valid.

[0055] Among them, the current timestamp is the time information corresponding to the moment when the service side receives the request message.

[0056] In this embodiment, based on the current timestamp and the request timestamp of the service processing request corresponding to the request message, it is possible to know the time elapsed from when the target requester sends the request message to when the service receives the request message. According to the pre-set rules, it can be confirmed whether the relationship between the current timestamp and the request timestamp of the service processing request corresponding to the request message satisfies the pre-set rules, so as to determine whether the request message is valid. Through this step, it can be confirmed whether the time elapsed from when the target requester sends the request message to when the service receives the request message has exceeded the preset value. If it has exceeded the preset value, it indicates that there may be an intermediate interception and a delayed request situation. At this time, there may be a risk of replay attack, and the request message at this time can be considered an illegal request.

[0057] In the above technical solution, by receiving a request message sent by a target requester, which includes a signed message and an unsigned message, subsequently, the signed message and the unsigned message are verified based on the public key corresponding to the target requester. When the verification passes, it is determined whether the target cache includes an index value corresponding to the random number in the signed message. If the target cache does not include an index value corresponding to the random number in the signed message, the random number is used as the index value corresponding to the request message, and the effective duration corresponding to the index value is set. Furthermore, based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the effective duration, it is determined whether the request message is valid. The technical solution provided by the embodiment of the present invention solves the technical problem that the request message is intercepted and retransmitted or arbitrarily tampered with during the user service request process. Through random numbers and timestamps, it prevents the request message from being subject to replay attacks, realizing replay verification of service requests; through signature verification, it prevents the random number or timestamp from being tampered with to avoid replay verification, enhancing the system's ability to resist risks, ensuring the stability of the system, and being able to better meet the requirements of system security, stability, and compliance.

[0058] Embodiment 2

[0059] Figure 3 It is a flowchart of a request anti-replay method provided by Embodiment 2 of the present invention. In this embodiment of the present invention, the content corresponding to S130 - S140 in the foregoing embodiment is further refined on the basis of the above embodiment. This embodiment of the present invention can be combined with various optional solutions in one or more of the above embodiments. As Figure 3 shown, the method includes:

[0060] S210. Receive a request message sent by a target requester.

[0061] S220. Perform signature verification on the signed message and the unsigned message based on the public key corresponding to the target requester.

[0062] S230. When the signature verification passes, traverse at least one index value to be selected in the target cache, and determine whether it includes an index value corresponding to the random number in the signature message.

[0063] Among them, the index value to be selected is the index value that has been cached in the target cache. The caching process of the index value to be selected can be understood as follows: If the current request message is the first request sent by the requesting party to the entire system, at this time, the random number in the first request message is directly stored in the target cache as the index value to be selected, and the number of index values is 1 at this time. Then, the requesting party will also send request messages. Therefore, as the system continues to run, more and more index values to be selected will be stored in the target index, and the number of index values to be selected is multiple at this time.

[0064] In this embodiment, the service party decrypts the signature message in the request message using the public key corresponding to the target requesting party to obtain the digest information D corresponding to the signature message. Furthermore, the service party generates digest information d using the public key corresponding to the target requesting party based on the non-signature message. If D and d are the same, it means that the signature verification passes. At this time, traverse the index values to be selected cached in the target cache, and determine whether the index values to be selected include an index value corresponding to the random number in the signature message.

[0065] S240. If so, store the random number as the index value to be selected in the target cache, and set the effective duration corresponding to the index value to be selected; if not, use the random number as the index value corresponding to the request message, and set the effective duration corresponding to the index value.

[0066] Based on the above embodiment, at this time, traverse the index values to be selected cached in the target cache. If the index values to be selected include an index value corresponding to the random number in the signature message, it means that there is a situation where the random number repeats within the effective time. Store the random number in the current request message as the index value to be selected in the target cache, and set the effective duration corresponding to the index value to be selected; if the index values to be selected do not include an index value corresponding to the random number in the signature message, it means that the random number in the current request message does not repeat with the index values in the target cache. At this time, use the random number as the index value corresponding to the request message, and set the effective duration corresponding to the index value.

[0067] S250. Based on the current timestamp and the request timestamp, determine the business processing interval duration.

[0068] In this embodiment, the business processing interval duration can be understood as the difference between the current timestamp and the request timestamp, which can represent the time elapsed from when the target requesting party sends a request message to when the service party receives the request message. The formula for calculating the business processing interval duration can be expressed as:

[0069] VT = T now -T

[0070] Wherein, VT is the service processing interval duration, and T now is the current timestamp, and T is the request timestamp.

[0071] S260. Determine whether the request message is valid based on the service processing interval duration and the valid duration.

[0072] In this embodiment, according to a pre-set rule, it can be confirmed whether the relationship between the service processing interval duration and the valid duration meets the pre-set rule to determine whether the request message is valid. Optionally, determining whether the request message is valid based on the service processing interval duration and the valid duration includes: if the service processing interval duration is greater than half of the valid duration, it is determined that the request message is invalid; if the service processing interval duration is less than half of the valid duration, it is determined that the request message is valid.

[0073] In this embodiment, if the set valid duration is V, based on the above embodiment, it can be determined that the absolute value of the service processing interval duration should be less than a time interval. Assuming this time interval is σ, here σ can be called the time tolerance window, then it can be expressed by the formula:

[0074] |T now -T| < σ

[0075] Wherein, T now is the current timestamp, T is the request timestamp, and σ is the time tolerance window.

[0076] Then, according to the above formula, it can be deduced that the time range in which random numbers may appear repeatedly is:

[0077] T now -σ < T < T now +σ

[0078] Then, according to the above formula, it can be deduced that the formula for the valid duration of the random number cache is:

[0079] V = (T now +σ) - (T now -σ) = 2σ

[0080] Then, according to the above formula, it can be deduced that the calculation formula for the time tolerance window σ is:

[0081]

[0082] In this embodiment, if the business processing interval duration is greater than half of the effective duration, it indicates that the business processing duration has exceeded the reasonable time range. There may be a man-in-the-middle interception and a situation of delayed requests. At this time, there may be a risk of replay attack, and the request message at this time can be considered an illegal request; if the business processing interval duration is less than half of the effective duration, it indicates that the business processing duration is within the reasonable time range and is recognized as a reasonable request. The service side can respond to the request message sent by the target requester for processing and feedback it to the front end of the user's system within the preset time.

[0083] For the above technical solution, by receiving a request message including a signature message and a non-signature message sent by the target requester, and then performing signature verification processing on the signature message and the non-signature message based on the public key corresponding to the target requester. When the signature verification passes, traverse at least one to-be-selected index value in the target cache and determine whether it includes an index value corresponding to the random number in the signature message. If so, store the random number as the to-be-selected index value in the target cache and set the effective duration corresponding to the to-be-selected index value; if not, use the random number as the index value corresponding to the request message and set the effective duration corresponding to the index value. Then, based on the current timestamp and the request timestamp, determine the business processing interval duration. If the business processing interval duration is greater than half of the effective duration, determine that the request message is valid; if the business processing interval duration is less than half of the effective duration, determine that the request message is invalid. The technical solution provided by the embodiment of the present invention determines half of the effective duration as the time tolerance window through theoretical derivation, proposes a simple calculation method for calculating the time tolerance window, improves the risk resistance ability of the system, and ensures the stability of the system.

[0084] Embodiment Three

[0085] In the embodiment of the present invention, a request anti-replay method is introduced in a specific implementation manner. The flowchart of the request anti-replay method is as Figure 4 shown. This method specifically corresponds to two execution entities, namely the requester and the service side. First, the requester sends a request message; the service side first receives the request message, and then completes the request anti-replay processing task through 3 judgment steps. The first judgment step is to verify the content of the request message to determine whether the request can pass the signature verification. The second judgment step is to confirm whether the random number in the request message is repeated. The third judgment step is to determine whether the request is legal according to the effective duration. The method specifically includes the following steps:

[0086] For the requester:

[0087] Step C1: The requester dynamically obtains the request timestamp T using a programming language;

[0088] Step C2: The requester dynamically obtains a Universally Unique Identifier (UUID) as the request random number R using a programming language.

[0089] Step C3: Concatenate the request timestamp T + request random number R + request associated data B into an unsigned message P.

[0090] Step C4: Perform digital signature processing on the unsigned message P using the requester's private key to obtain a signed message P1.

[0091] Step C5: The requester sends a request message.

[0092] Service provider:

[0093] Step S1: Verify the signature for the request timestamp T + request random number R + request associated data B in the request message.

[0094] Step S2: Concatenate in the order of request timestamp T + request random number R + request associated data B, and perform digital signature verification on the signed message P using the requester's public key. If the verification is successful, execute S3; otherwise, determine the request as invalid.

[0095] Step S3: Determine whether the random number R exists in the Redis cache. If it does not exist, execute S4; if it exists, determine the request as invalid.

[0096] Step S4: Cache it in Redis with R as the KEY, and set the cache expiration time to V.

[0097] Step S5: Compare the request timestamp T with the current timestamp T now to check if the error exceeds V / 2. If the error between the request timestamp T and the current timestamp T now exceeds V / 2, determine the request as invalid; if the error between the request timestamp T and the current timestamp T now does not exceed V / 2, determine the request as valid and allow subsequent business processing; otherwise, determine the request as invalid.

[0098] In the above technical solution, by using random numbers and timestamps, replay attacks on request messages are prevented. Through signature verification, tampering of random numbers or timestamps is prevented to avoid replay verification, thereby implementing service request replay verification. This solves the technical problem of intercepted and retransmitted or arbitrarily tampered request messages during the user service request process, realizes service request replay verification, improves the system's risk resistance ability, ensures the system's stability, and can better meet the system's security, stability, and compliance requirements.

[0099] Example 4

[0100] Figure 5A structural schematic diagram of a request anti-duplicate transmission device provided in Embodiment 4 of the present invention. This device can execute a request anti-duplicate transmission method provided in the embodiments of the present invention. The device includes: a request message receiving module 410, an index value determination module 420, a finite duration setting module 430, and a request validity determination module 440.

[0101] The request message receiving module 410 is used to receive a request message sent by a target requestor; wherein, the request message includes a signed message and an unsigned message, and the request message includes a request timestamp, a random number, and request associated data;

[0102] The index value determination module 420 is used to perform signature verification on the signed message and the unsigned message based on the public key corresponding to the target requestor, and when the signature verification passes, determine whether the target cache includes an index value corresponding to the random number in the signed message;

[0103] The finite duration setting module 430 is used to, if the signature verification of the signed message and the unsigned message by the public key corresponding to the target requestor fails, use the random number as the index value corresponding to the request message, and set the valid duration corresponding to the index value;

[0104] The request validity determination module 440 is used to determine whether the request message is valid based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the valid duration.

[0105] Based on the above technical solutions, the request anti-duplicate transmission device is further used to send a service processing request based on the target requestor, and determine the request timestamp corresponding to the service processing request; generate a random number based on a universally unique identifier; determine a request message based on the request timestamp, the random number, and the request associated data corresponding to the service processing request.

[0106] Based on the above technical solutions, the request anti-duplicate transmission device is further used to determine an unsigned message by performing splicing processing on the request timestamp, the random number, and the request associated data; perform signature processing on the unsigned message based on the private key corresponding to the target requestor to obtain a signed message.

[0107] Based on the above technical solutions, the request anti-duplicate transmission device is further used to determine that the service processing request corresponding to the request message is invalid when the signature verification fails or the target cache includes the random number in the signed message.

[0108] Based on the above technical solutions, the index value determination module 420 includes: an index value traversal unit and a valid duration setting unit.

[0109] An index value traversal unit for traversing at least one index value to be selected in a target cache and determining whether it includes an index value corresponding to the random number in the signature message;

[0110] An effective duration setting unit for storing the random number as an index value to be selected in the target cache and setting the effective duration corresponding to the index value to be selected if the target cache includes an index value corresponding to the random number in the signature message.

[0111] Based on the above technical solutions, the request validity determination module 440 includes: an interval duration determination unit and a request message determination unit.

[0112] The interval duration determination unit for determining the service processing interval duration based on the current timestamp and the request timestamp;

[0113] The request message determination unit for determining whether the request message is valid based on the service processing interval duration and the effective duration.

[0114] Based on the above technical solutions, the request message determination unit includes: a message validity determination subunit and a message invalidity determination subunit.

[0115] The message validity determination subunit for determining that the request message is invalid if the service processing interval duration is greater than half of the effective duration;

[0116] The message invalidity determination subunit for determining that the request message is valid if the service processing interval duration is less than half of the effective duration.

[0117] In the above technical solutions, by receiving a request message including a signature message and a non-signature message sent by a target requestor, then, performing signature verification processing on the signature message and the non-signature message based on the public key corresponding to the target requestor, and when the signature verification passes, determining whether the target cache includes an index value corresponding to the random number in the signature message. If the target cache does not include an index value corresponding to the random number in the signature message, the random number is used as the index value corresponding to the request message, and the effective duration corresponding to the index value is set. Furthermore, based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the effective duration, it is determined whether the request message is valid. The technical solutions provided by the embodiments of the present invention solve the technical problem that the request message is intercepted and retransmitted or arbitrarily tampered with during the user service request process, realize the replay verification of the service request, improve the risk resistance ability of the system, ensure the stability of the system, and can better meet the requirements of system security, stability, and compliance.

[0118] The data processing device provided by the embodiments of the present disclosure can execute the video determination method provided by any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects for executing the method.

[0119] It should be noted that the various units and modules included in the above device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the embodiments of the present disclosure.

[0120] Embodiment Five

[0121] Figure 6 FIG. is a schematic structural diagram of an electronic device provided in Embodiment Five of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as, for example, personal digital assistants, cellular telephones, smart telephones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0122] As Figure 6 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 may execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 may also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0123] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0124] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the road surface recognition method.

[0125] In some embodiments, the road surface recognition method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the road surface recognition method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the road surface recognition method in any other suitable manner (e.g., by means of firmware).

[0126] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs, which can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a special or general-purpose programmable processor, can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0127] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0128] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0129] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0130] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0131] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services. It should be understood that various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein. The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for preventing duplicate requests, characterized in that Including: Receiving a request message sent by a target requester; wherein, the request message includes a signed message and an unsigned message, and the request message includes a request timestamp, a random number, and request correlation data; Performing signature verification processing on the signed message and the unsigned message based on the public key corresponding to the target requester, and when the signature verification passes, determining whether an index value corresponding to the random number in the signed message is included in the target cache; If not, using the random number as the index value corresponding to the request message, and setting an effective duration corresponding to the index value; Determining whether the request message is valid based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the effective duration.

2. The method according to claim 1, wherein Before receiving the request message sent by the target requester, further including: Sending a service processing request based on the target requester, and determining a request timestamp corresponding to the service processing request; Generating a random number based on a universally unique identifier; Determining the request message based on the request timestamp, the random number, and the request correlation data corresponding to the service processing request.

3. The method according to claim 2, characterized in that, The determining the request message based on the request timestamp, the random number, and the request correlation data corresponding to the service processing request includes: Determining the unsigned message by concatenating and processing the request timestamp, the random number, and the request correlation data; Performing signature processing on the unsigned message based on the private key corresponding to the target requester to obtain the signed message.

4. The method according to claim 1, wherein Further including: When the signature verification fails or the target cache includes the random number in the signed message, determining that the service processing request corresponding to the request message is invalid.

5. The method according to claim 1, characterized in that, The determining whether an index value corresponding to the random number in the signed message is included in the target cache includes: Traversing at least one index value to be selected in the target cache, and determining whether an index value corresponding to the random number in the signed message is included; If so, storing the random number as the index value to be selected in the target cache, and setting an effective duration corresponding to the index value to be selected.

6. The method according to claim 1, wherein The determining whether the request message is valid based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the effective duration includes: Determining a service processing interval duration based on the current timestamp and the request timestamp; Determining whether the request message is valid based on the service processing interval duration and the effective duration.

7. The method according to claim 6, characterized in that, The determining whether the request message is valid based on the service processing interval duration and the effective duration includes: If the service processing interval duration is greater than half of the effective duration, determining that the request message is invalid; If the service processing interval duration is less than half of the effective duration, determining that the request message is valid.

8. A request anti-duplicate transmission device, characterized in that, Including: A request message receiving module, configured to receive a request message sent by a target requester; wherein, the request message includes a signed message and an unsigned message, and the request message includes a request timestamp, a random number, and request correlation data; An index value determination module, configured to verify the signature message and the non-signature message based on the public key corresponding to the target requester, and determine whether an index value corresponding to the random number in the signature message is included in the target cache when the verification passes; A limited duration setting module, configured to, if the verification of the signature message and the non-signature message by the public key corresponding to the target requester fails, use the random number as the index value corresponding to the request message, and set a valid duration corresponding to the index value; A request validity determination module, configured to determine whether the request message is valid based on the current timestamp, the request timestamp of the service processing request corresponding to the request message, and the valid duration.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the request anti-duplicate method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to implement the request anti-duplicate method according to any one of claims 1-7 when executed.

Citation Information

Patent Citations

  • Method for actively defending web attack and web security gateway based on active defense

    CN114745202A

  • Method for preventing replay attack of API (Application Program Interface) gateway

    CN115065503A