A data call authentication method, device, equipment and storage medium

By using the target time and time stamp to generate digital parameters for encryption and verification on the front-end and back-end, the problem of data leakage in existing encryption algorithms under brute force cracking is solved, and security recognition and tamper-proof during data call are realized.

CN115842669BActive Publication Date: 2025-05-23HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211482117.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-05-23
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

The existing encryption algorithms still have security problems in data leakage when there is sufficient brute force cracking time, especially when data packet decryption and tampering are performed in the business system through packet capture tools, user information and business information are easily leaked.

Method used

By generating numerical parameters based on the target time and the requested data time stamp, the requested data is encrypted and verified by using the target convention formula to judge the legitimacy of the encrypted requested data on the front-end and back-end, ensuring the consistency of the timestamp to identify tampering.

Benefits of technology

Improves security during data calling, can identify and prevent tampered data transmission, and avoid information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115842669B_ABST
    Figure CN115842669B_ABST
Patent Text Reader

Abstract

The present application discloses a data call authentication method, device, equipment and storage medium, which relates to the field of computer technology and is applied to the front end, including: processing a preset first target time and a first timestamp corresponding to the initial request data to obtain a digital parameter based on a target agreed formula; encrypting the initial request data including the digital parameter to obtain encrypted request data; sending the encrypted request data to the back end so that the back end processes the digital parameters in the encrypted request data to obtain a second target time and a second timestamp, and determines whether the encrypted request data is legal by judging the consistency between the target time and the timestamp; obtaining the response information sent by the back end after judging whether the encrypted request data is legal. In this way, the present application can use the timestamp corresponding to the target time and the request data to perform double-layer verification on the request data, identify the tampered data, and improve the security of the data call.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a data call authentication method, device, equipment and storage medium. Background Art

[0002] In the business system, the front end can access the backend interface. During the attack and defense test of the professional team, the packet capture tool can be used to brute force decrypt the data packets in the cracking process; and after decrypting the data packets, the relevant business information and user information can be obtained by modifying the request parameters. Although the existing technology has RSA algorithm encryption, which can increase the difficulty of brute force cracking through public key and private key technology, its single encryption method still has the security problem of data leakage when there is enough time for brute force cracking. If these data packets are cracked by attackers, there will be a risk of leakage of user information and corresponding business information. Summary of the invention

[0003] In view of this, the purpose of the present invention is to provide a data call authentication method, device, equipment and storage medium, which can verify the request data by generating digital parameters based on the target time and the timestamp corresponding to the request data, identify tampered data, and improve the security of data during the data call process.

[0004] In a first aspect, the present application provides a data call authentication method, which is applied to a front end and includes:

[0005] Obtaining initial request data through the front-end page, and processing a preset first target time and a first timestamp corresponding to the initial request data based on a target agreed formula to obtain a digital parameter;

[0006] Encrypting data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain encrypted request data;

[0007] Sending the encrypted request data to the backend so that the backend decrypts the encrypted request data, and then using the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp, and determining whether the encrypted request data is legal by judging the consistency between the first target time and the second target time and between the first timestamp and the second timestamp;

[0008] Acquire response information for the encrypted request data sent by the backend after determining whether the encrypted request data is legal.

[0009] Optionally, before the process of processing the preset first target time and the first timestamp corresponding to the initial request data to obtain the digital parameter based on the target agreed formula further includes:

[0010] Acquire the preset agreed formula set saved in advance from a database;

[0011] A formula is selected from the preset agreed formula set as the target agreed formula in the current data calling process.

[0012] Optionally, before encrypting the data including the initial request data, the first target time, the first timestamp, and the digital parameter to obtain the encrypted request data, the method further includes:

[0013] encapsulating the initial request data, the first target time, the timestamp and the digital parameter into target request data;

[0014] Accordingly, encrypting the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain the encrypted request data includes:

[0015] The target request data is encrypted using a preset encryption algorithm to obtain the encrypted request data.

[0016] Optionally, the obtaining response information for the encrypted request data sent by the backend after determining whether the encrypted request data is legal includes:

[0017] Obtaining response information containing information indicating an illegal request and for the encrypted request data, which is returned by the backend after determining that the encrypted request data is illegal;

[0018] Or, obtaining response information containing call data corresponding to the encrypted request data, which is returned by the backend after determining that the encrypted request data is legal.

[0019] Optionally, after sending the encrypted request data to the backend, the method further includes:

[0020] Determine whether a response message returned by the back end is received within a preset waiting time;

[0021] If the response information returned by the back end is not received within the preset waiting time, the encrypted request data is sent to the back end again.

[0022] In the second aspect, the present application provides a data call authentication method, which is applied to the backend, including:

[0023] Get the encrypted request data;

[0024] Decrypting the encrypted request data, and processing the digital parameters in the decrypted request data using the target agreed formula to obtain the corresponding second target time and second timestamp;

[0025] Determining whether the second target time is consistent with the first target time in the decrypted request data;

[0026] If the second target time is inconsistent with the first target time, determining that the encrypted request data is illegal, and sending a response message containing illegal data to the front end for the encrypted request data;

[0027] If the second target time is consistent with the first target time, determining whether the second timestamp is consistent with the first timestamp in the decrypted request data;

[0028] If the second timestamp is inconsistent with the first timestamp, the encrypted request data is determined to be illegal, and a response message containing illegal data is sent to the front end for the encrypted request data;

[0029] If the second timestamp is consistent with the first timestamp, the encrypted request data is determined to be legal, and a response message including the call data corresponding to the encrypted request data is sent to the front end.

[0030] In a third aspect, the present application provides a data call authentication device, which is applied to a front end and includes:

[0031] A parameter processing module, used to obtain the initial request data through the front-end page, and process the preset first target time and the first timestamp corresponding to the initial request data based on the target agreed formula to obtain a digital parameter;

[0032] A data encryption module, used for encrypting the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain encrypted request data;

[0033] A data sending module, used for sending the encrypted request data to a backend so that the backend decrypts the encrypted request data, and then uses the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp, and determines whether the encrypted request data is legal by judging the consistency between the first target time and the second target time and between the first timestamp and the second timestamp;

[0034] The response information acquisition module is used to obtain the response information for the encrypted request data sent by the back end after determining whether the encrypted request data is legal.

[0035] In a fourth aspect, the present application provides a data call authentication device, which is applied to a backend, including:

[0036] A data acquisition module is used to acquire encrypted request data;

[0037] A data decryption module, used to decrypt the encrypted request data, and process the digital parameters in the decrypted request data using a target agreed formula to obtain a corresponding second target time and a second timestamp;

[0038] A first parameter determination module, used to determine whether the second target time is consistent with the first target time in the decrypted request data;

[0039] A first information sending module, configured to determine that the encrypted request data is illegal when the second target time is inconsistent with the first target time, and send a response message containing illegal data to the front end for the encrypted request data;

[0040] A second parameter judgment module, used for judging whether the second timestamp is consistent with the first timestamp in the decrypted request data when the second target time is consistent with the first target time;

[0041] A second information sending module is used for determining that the encrypted request data is illegal when the second timestamp is inconsistent with the first timestamp, and sending a response message containing illegal data to the front end for the encrypted request data;

[0042] The third information sending module is used to determine that the encrypted request data is legal when the second timestamp is consistent with the first timestamp, and send a response message containing the call data corresponding to the encrypted request data to the front end.

[0043] In a fifth aspect, the present application provides an electronic device, including:

[0044] Memory, used to store computer programs;

[0045] The processor is used to execute the computer program to implement the above-mentioned data call authentication method.

[0046] In a sixth aspect, the present application provides a computer-readable storage medium for storing a computer program, which implements the above-mentioned data call authentication method when executed by a processor.

[0047] It can be seen that the present application can obtain the initial request data input by the user through the front-end page, and process the first target time and the first timestamp corresponding to the initial request data based on the target agreement formula to obtain digital parameters; then encrypt the data including the initial request data, the first target time, the first timestamp and the digital parameters to obtain encrypted request data; and send the encrypted request data to the back-end so that the back-end decrypts the encrypted request data to obtain decrypted request data, and then use the target agreement formula to process the digital parameters in the decrypted request data and verify the relevant data in the decrypted request data according to the processed second target time and the processed second timestamp to determine whether the decrypted request data is legal; and then obtain the response information for the encrypted request data sent by the back-end after determining whether the encrypted request data is legal. In this way, the application can process the first target time and the timestamp corresponding to the initial request data according to the target agreed formula to obtain a digital parameter. The backend can use the first target time to verify the time obtained using the digital parameter, and can further use the timestamp obtained by the digital parameter to verify the timestamp pair corresponding to the initial request data. In this way, it can be determined whether the encrypted request data has been tampered with during the transmission process, and illegal data can be identified. This can avoid the situation where the timestamp of the request data after tampering still corresponds to the request data after tampering, and it is impossible to determine whether the request data has been tampered with, further improving the security of the data during transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0049] Figure 1 A flow chart of a data call authentication method disclosed in this application;

[0050] Figure 2 A flow chart of a specific data call authentication method disclosed in this application;

[0051] Figure 3 A flow chart of a specific data call authentication method disclosed in this application;

[0052] Figure 4 A schematic diagram of the structure of a data call authentication device disclosed in this application;

[0053] Figure 5A schematic diagram of the structure of a data call authentication device disclosed in this application;

[0054] Figure 6 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0055] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0056] Existing packet capture tools can capture data packets during the data call process. Although encryption algorithms can be used to encrypt data, existing encryption algorithms use public key and private key technology to improve data security. Even if such an encryption method is used, the data packets during the data call process can still be forcibly cracked and tampered with when there is sufficient time to crack. This application can generate corresponding digital parameters based on the target time and the timestamp corresponding to the request data, and then verify the request data based on the digital parameters, so that illegally modified request data can be found, which can improve the security of data calls.

[0057] See also Figure 1 As shown, an embodiment of the present invention discloses a data call authentication method, including:

[0058] Step S11, obtaining initial request data through the front-end page, and processing the preset first target time and the first timestamp corresponding to the initial request data based on the target agreed formula to obtain digital parameters.

[0059] In this embodiment, it should be pointed out that before the preset first target time and the first timestamp corresponding to the initial request data are processed based on the target agreed formula to obtain the digital parameter, it can also include: obtaining the preset agreed formula set saved in advance from the database; screening out a formula from the preset agreed formula set as the target agreed formula in the current data call process. Specifically, the preset agreed formulas that may be used can be saved in advance to the database. It can be understood that the preset agreed formula set can be obtained from the database before obtaining the initial request data, and a agreed formula can be screened out from the preset agreed formula set as the target agreed formula in the current data call process; it should be pointed out that the preset agreed formula set in the database can be modified periodically.

[0060] In this embodiment, after obtaining the initial request data, the target agreed formula can be used to process the preset first target time and the first timestamp corresponding to the initial request data, so that the digital parameter with a mapping relationship with the first target time and the first timestamp can be obtained. It should be pointed out that the first target time can be the current time when the initial request data is obtained, or it can be a preset random time. In a specific embodiment, the current time when the initial request data is obtained is often used as the first target time.

[0061] Step S12: Encrypt the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain encrypted request data.

[0062] In this embodiment, after obtaining the digital parameter, the method may further include: encapsulating the initial request data, the first target time, the timestamp and the digital parameter into target request data; specifically, the initial request data, the first target time, the first timestamp and the digital parameter may be encapsulated into target request data; in this way, the target request data may be encrypted using a preset encryption algorithm to obtain the encrypted request data. It is understandable that the preset encryption algorithm may be an existing commonly used encryption algorithm, such as the AES (Advanced Encryption Standard) encryption algorithm, the RSA algorithm, i.e., an asymmetric encryption algorithm, etc.

[0063] Step S13, sending the encrypted request data to the back end so that the back end can decrypt the encrypted request data, and then use the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp, and determine whether the encrypted request data is legal by judging the consistency between the first target time and the second target time and between the first timestamp and the second timestamp.

[0064] In this embodiment, after the front end obtains the encrypted request data, it can send the encrypted request data to the back end, and the back end can decrypt the encrypted request data, and then use the target agreed formula to process the digital parameters in the decrypted request data, so that the second target time and the second timestamp corresponding to the digital parameters in the decrypted request data can be obtained. It can be understood that the decrypted request data includes the first target time and the first timestamp; at this time, it can be determined whether the second target time is consistent with the first target time to determine whether the encrypted request data has been illegally tampered with, and it can be further determined whether the second timestamp is consistent with the first timestamp to determine whether the decrypted request data has been illegally tampered with. Further, the back end can generate a response message for the encrypted request data according to the judgment result of the decrypted request data.

[0065] Step S14: Acquire response information for the encrypted request data sent by the back end after determining whether the encrypted request data is legal.

[0066] In this embodiment, after the front end sends the encrypted request data to the back end, it can wait to obtain the response information returned by the back end; wherein obtaining the response information can include: obtaining the response information returned by the back end after determining that the encrypted request data is illegal and containing the response information representing the illegal request; or obtaining the response information returned by the back end after determining that the encrypted request data is legal and containing the call data corresponding to the encrypted request data. Specifically, when the encrypted request data is determined by the back end to contain illegal data, the front end can receive the response information sent by the back end representing that the encrypted request data is illegal data; correspondingly, if the encrypted request data is determined by the back end to be legal data, the front end can receive the response information sent by the back end containing the call data corresponding to the encrypted request data.

[0067] It should be noted that after the front end sends the encrypted request data to the back end, it may also include: judging whether the response information returned by the back end is received within the preset waiting time; if the response information returned by the back end is not received within the preset waiting time, the encrypted request data is sent to the back end again. Specifically, after the front end sends the encrypted request data to the back end, a timer may be started to judge whether the response information for the encrypted request data sent by the back end is received within the preset waiting time. If the response information for the encrypted request data sent by the back end is not received within the preset waiting time, it may be considered that the encrypted request data is lost during the transmission process, and the encrypted request data may be sent to the back end again.

[0068] It can be seen that the embodiment of the present application can use the target agreement formula to process the preset first target time and the first timestamp corresponding to the initial request data to obtain a digital parameter, and then the digital parameter, the first target time, the first timestamp and the initial request data can be encapsulated into the target request data, and the target request data is encrypted to obtain the encrypted request data, and the encrypted request data is sent to the back end, the back end can decrypt the encrypted request data, and according to the target agreement formula, the digital parameter in the decrypted request data can be processed to obtain the second target time and the second timestamp, and by judging whether the second target time is consistent with the first target time and the second timestamp is consistent with the second timestamp, it can be determined whether the encrypted request data has been illegally tampered with, and then the front end can obtain the response information sent by the back end for the encrypted request data. In this way, the request data that has been illegally tampered with can be identified by the timestamp corresponding to the target time and the initial request data, which can avoid the information leakage caused by the request data encrypted by the encryption algorithm alone being tampered and unable to be identified, thereby improving the security of the data.

[0069] The above embodiment introduces the steps of the front end using the target agreed formula, the target time and the timestamp corresponding to the initial request data to obtain the digital parameter, so that the back end can verify whether the encrypted request data is legal according to the digital parameter, which can improve the security of the data; the following embodiment will introduce the steps of the back end verifying whether the encrypted request is legal according to the digital parameter in detail. Figure 2 As shown, an embodiment of the present invention discloses a data call authentication method, including:

[0070] Step S21, obtaining encrypted request data.

[0071] In this embodiment, the back end first obtains the encrypted request data sent by the front end. It can be understood that the encrypted request data includes the initial request data, a preset first target time, a first timestamp corresponding to the initial request data, and the digital parameters obtained by the front end using the target agreed formula to process the first target time and the first timestamp.

[0072] Step S22: decrypt the encrypted request data, and use the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp.

[0073] In this embodiment, after obtaining the encrypted request data, the backend can decrypt the encrypted request data to obtain the decrypted request data. It should be noted that the encrypted request data received by the backend may be illegally tampered with during the transmission process; in this embodiment, after obtaining the decrypted request data, the backend can use the target agreed formula to process the digital parameters in the decrypted request data, so as to obtain the second target time and the second timestamp corresponding to the digital parameters in the decrypted request data. It can be understood that in a specific embodiment, if the encrypted request data is tampered with during the transmission process, the digital parameters in the decrypted request data may not be processed by the target agreed formula to obtain the second target time. At this time, the decrypted request data can be directly determined to be illegal, and a response message indicating that the encrypted request data is illegal is sent to the front end.

[0074] Step S23: Determine whether the second target time is consistent with the first target time in the decrypted request data.

[0075] It is understandable that when the encrypted request data is tampered with during transmission, the digital parameters therein, the first target time, the first timestamp, and the initial request data may be tampered with. If the backend can use the target agreed formula to process the digital parameters in the decrypted request data to obtain the second target time, it can be preliminarily explained that the digital parameters may be legal, and whether other parameters are legal requires further verification. In this embodiment, after obtaining the second target time and the second timestamp, it can be first determined whether the second target time is consistent with the first target time in the decrypted request data.

[0076] Step S24: If the second target time is inconsistent with the first target time, the encrypted request data is determined to be illegal, and a response message containing illegal data is sent to the front end for the encrypted request data.

[0077] In this embodiment, if the second target time obtained by the digital parameter in the decrypted request data is inconsistent with the first target time in the decrypted request data, it means that the encrypted request data has been illegally tampered with during the transmission process. At this time, the back end can generate response information representing illegal data for the decrypted request data that is determined to be illegal, and send the response information to the front end.

[0078] Step S25: If the second target time is consistent with the first target time, further determine whether the second timestamp is consistent with the first timestamp in the decrypted request data.

[0079] In this embodiment, if the second target time obtained by the digital parameters in the decrypted request data is consistent with the first target time in the decrypted request data, it can be further determined whether the second timestamp obtained by the digital parameters in the decrypted request data is consistent with the first timestamp in the decrypted request data; it can be understood that in the process of data transmission, when the request data is intercepted and tampered with, the timestamp is also corresponding to the request data. The present application can verify the timestamp in the request data through digital parameters to achieve the effect of verifying whether the request data is legal.

[0080] Step S26: If the second timestamp is inconsistent with the first timestamp, the encrypted request data is determined to be illegal, and response information containing illegal data is sent to the front end for the encrypted request data.

[0081] In this embodiment, if the second timestamp obtained through the digital parameter in the decrypted request data is inconsistent with the first timestamp in the decrypted request data, it can be explained that the decrypted request data is illegal, that is, the encrypted request data has been tampered with during the transmission process. In this way, the back end can generate response information representing illegal data for the decrypted request data determined to be illegal data, and send the response information to the front end.

[0082] Step S27: If the second timestamp is consistent with the first timestamp, the encrypted request data is determined to be legal, and a response message containing call data corresponding to the encrypted request data is sent to the front end.

[0083] In this embodiment, if the second timestamp obtained through the digital parameters in the decrypted request data is consistent with the first timestamp in the decrypted request data, it can be explained that the decrypted request data has not been tampered with during the transmission process, that is, the decrypted request data is legal. At this time, the back end can generate a response information containing the call data corresponding to the initial request data in the decrypted request data, and send the response information containing the call data corresponding to the initial request data in the decrypted request data to the front end.

[0084] It can be seen that in an embodiment of the present application, the back-end can use the target agreement formula to process the digital parameters in the decrypted request data. If the digital parameters cannot be processed to obtain the second target time, it means that the decrypted request data is illegal; if the second target time obtained by the digital parameters in the decrypted request data is inconsistent with the first target time in the decrypted request data, it means that the decrypted request data is illegal; if the second target time obtained by the digital parameters in the decrypted request data is consistent with the first target time in the decrypted request data, but the second timestamp obtained by the digital parameters in the decrypted request data is inconsistent with the first timestamp in the decrypted request data, it means that the decrypted request data is illegal; if the second target time obtained by the digital parameters in the decrypted request data is consistent with the first target time in the decrypted request data, and the second timestamp obtained by the digital parameters in the decrypted request data is consistent with the first timestamp in the decrypted request data, it can be determined that the decrypted request data is legal. In this way, the present application can add a digital parameter corresponding to the timestamp of the initial request data in the request data to realize the back-end verification of the initial request data, identify the tampered request data, avoid the information leakage problem caused by the data tampering, and improve the data security during the data call process.

[0085] The above embodiment introduces in detail the steps of verifying the encrypted request data by the back end, and the digital parameters can be used to verify the legitimacy of the request data, thereby improving the security of the data during transmission. Figure 3 The flowchart disclosed in the embodiment of the present application is specifically described.

[0086] In the present application, firstly, relevant parameter information can be obtained through the front-end page, and the parameter information includes the initial request data mentioned above. Then, the agreed formula, that is, the target agreed formula, can be used for the preset first target time. It can be understood that the first target time can be the current time or a preset random time. Then, the first target time can be processed by the target agreed formula, which also includes using the target agreed formula to process the first timestamp corresponding to the above parameter information, so that a digital parameter with a mapping relationship with the first target time and the first timestamp can be obtained. After obtaining the digital parameters, the digital parameters, the first target time, the initial request data and the first timestamp can be encapsulated into target request data. Further, the target request data can be encrypted using a commonly used encryption algorithm. For example, the target request data can be encrypted using the AES algorithm to obtain encrypted request data. Then, the business interface of the back-end can be called to send the encrypted request data to the back-end.

[0087] Correspondingly, after the backend receives the encrypted request data, it can decrypt the encrypted request data to obtain the decrypted request data. For example, the encrypted request data encrypted by the AES algorithm can be decrypted using the AES algorithm private key to obtain the decrypted request data. It should be noted that if the decryption fails, the encrypted request data can be directly determined to be illegal. It can be understood that the decrypted request data obtained after successful decryption includes a first target time, a first timestamp, initial request data, and digital parameters. These data may be illegal. The present application can process the digital parameters in the decrypted request data according to the target agreed formula. It should be noted that if the digital parameters in the decrypted request data cannot be processed by the target agreed formula, the decrypted request data can be directly determined to be illegal. Correspondingly, after the digital parameters in the decrypted request data are successfully processed by the target agreed formula, the second target time and the second timestamp can be obtained. In the present application, it can be first determined whether the second target time is consistent with the first time in the decrypted request data. Whether the target time is consistent, if it is consistent, it means that the digital parameter in the decrypted request data is legal, and then it can be further determined whether the second timestamp obtained by the digital parameter is consistent with the first timestamp in the decrypted request data. If it is inconsistent, it means that the first timestamp in the decrypted request data is illegal, that is, the encrypted request data has been tampered with during the transmission process. Although the tampered timestamp corresponds to the tampered request data, the second timestamp at this time corresponds to the initial request data. By judging whether the second timestamp is consistent with the first timestamp in the decrypted request data, it can be determined whether the initial request data in the decrypted i request data is legal. If the second timestamp obtained by the digital parameter is consistent with the first timestamp in the decrypted request data, it can be determined that the decrypted i request data is legal, the business logic of the interface can be continued to be executed, and a response message containing the call data corresponding to the initial request data in the decrypted request data can be generated, and the response message is sent to the front end.

[0088] It can be seen from this that the present application can process the preset first target time and the first timestamp corresponding to the initial request data according to the target agreed formula to obtain digital parameters, and use the digital parameters to implement the process of verifying the legality of the decrypted request data on the back end, which can identify tampered data and improve the security of information.

[0089] like Figure 4 As shown, the embodiment of the present invention discloses a data call authentication device, which is applied to a front end and includes:

[0090] The parameter processing module 11 is used to obtain the initial request data through the front-end page, and process the preset first target time and the first timestamp corresponding to the initial request data based on the target agreed formula to obtain a digital parameter;

[0091] A data encryption module 12, configured to encrypt the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain encrypted request data;

[0092] A data sending module 13 is used to send the encrypted request data to the back end so that the back end decrypts the encrypted request data, and then uses the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp, and determines whether the encrypted request data is legal by judging the consistency between the first target time and the second target time and between the first timestamp and the second timestamp;

[0093] The response information acquisition module 14 is used to acquire the response information for the encrypted request data sent by the back end after determining whether the encrypted request data is legal.

[0094] It can be seen that in this application, the preset first target time and the first timestamp corresponding to the initial request data can be processed to obtain digital parameters, and then the digital parameters, the first target time, the first timestamp and the initial request data can be encapsulated and encrypted to obtain encrypted request data, so that after the back end obtains the encrypted request data, it can use the target agreed formula to process the digital parameters therein to obtain the second target time and the second timestamp, and then it can be judged whether the obtained encrypted request data is legal by judging whether the first target time and the second target time are consistent and whether the first timestamp and the second timestamp are consistent, and corresponding response information can be generated for the judgment result and sent to the front end. In this way, based on the digital parameters, it can be judged whether the encrypted request data has been tampered with during the transmission process, thereby improving the security of the data during the transmission process, and avoiding the problem of user information leakage caused by the inability to identify the tampered data.

[0095] In a specific embodiment, the parameter processing module 11 may further include:

[0096] A formula set acquisition unit, used to acquire the preset agreed formula set saved in advance from a database;

[0097] The target formula determination unit is used to select a formula from the preset agreed formula set as the target agreed formula in the current data calling process.

[0098] In a specific embodiment, the data encryption module 12 may further include:

[0099] a data encapsulation unit, configured to encapsulate the initial request data, the first target time, the timestamp and the digital parameter into target request data;

[0100] Accordingly, the data encryption module 12 may include:

[0101] The data encryption unit is used to encrypt the target request data using the preset encryption algorithm to obtain the encrypted request data.

[0102] In a specific embodiment, the response information acquisition module 14 may include:

[0103] A first information acquisition unit, configured to acquire response information containing information indicating an illegal request and for the encrypted request data, returned by the backend after determining that the encrypted request data is illegal;

[0104] The second information acquisition unit is used to acquire response information containing call data corresponding to the encrypted request data, which is returned by the backend after determining that the encrypted request data is legal.

[0105] In a specific embodiment, the response information acquisition module 14 may further include:

[0106] A waiting time determination unit, used to determine whether a response message returned by the back end is received within a preset waiting time;

[0107] The repeated request sending unit is used to send the encrypted request data to the back end again when the response information returned by the back end is not received within a preset waiting time.

[0108] like Figure 5 As shown, an embodiment of the present invention discloses a data call authentication device, which is applied to a backend and includes:

[0109] A data acquisition module 21, used to acquire the encrypted request data;

[0110] A data decryption module 22, used to decrypt the encrypted request data, and process the digital parameters in the decrypted request data using a target agreed formula to obtain a corresponding second target time and a second timestamp;

[0111] A first parameter determination module 23, used to determine whether the second target time is consistent with the first target time in the decrypted request data;

[0112] A first information sending module 24 is used for determining that the encrypted request data is illegal when the second target time is inconsistent with the first target time, and sending a response message containing illegal data to the front end for the encrypted request data;

[0113] A second parameter judgment module 25, configured to judge whether the second timestamp is consistent with the first timestamp in the decrypted request data when the second target time is consistent with the first target time;

[0114] A second information sending module 26 is configured to determine that the encrypted request data is illegal when the second timestamp is inconsistent with the first timestamp, and send a response message containing illegal data to the front end for the encrypted request data;

[0115] The third information sending module 27 is used to determine that the encrypted request data is legal when the second timestamp is consistent with the first timestamp, and send a response message containing the call data corresponding to the encrypted request data to the front end.

[0116] Furthermore, the present application also discloses an electronic device. Figure 6 This is a structural diagram of an electronic device 30 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.

[0117] Figure 6 A schematic diagram of the structure of an electronic device 30 provided in an embodiment of the present application. The electronic device 30 may specifically include: at least one processor 31, at least one memory 32, a power supply 33, a communication interface 34, an input / output interface 35, and a communication bus 36. The memory 32 is used to store a computer program, which is loaded and executed by the processor 31 to implement the relevant steps in the data call authentication method disclosed in any of the aforementioned embodiments. In addition, the electronic device 30 in this embodiment may specifically be an electronic computer.

[0118] In this embodiment, the power supply 33 is used to provide working voltage for each hardware device on the electronic device 30; the communication interface 34 can create a data transmission channel between the electronic device 30 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 35 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0119] In addition, the memory 32, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 321, a computer program 322, etc., and the storage method can be temporary storage or permanent storage.

[0120] The operating system 321 is used to manage and control the hardware devices and computer programs 322 on the electronic device 30, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the data call authentication method performed by the electronic device 30 disclosed in any of the aforementioned embodiments, the computer program 322 can further include a computer program that can be used to complete other specific tasks.

[0121] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned disclosed data call authentication method is implemented. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.

[0122] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0123] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0124] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0125] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0126] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of ​​the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A data call authentication method, It is characterized in that Applied to the front end, including: Obtaining initial request data through the front-end page, and processing a preset first target time and a first timestamp corresponding to the initial request data based on a target agreed formula to obtain a digital parameter; Encrypting data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain encrypted request data; Sending the encrypted request data to the backend so that the backend decrypts the encrypted request data, and then using the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp, and determining whether the encrypted request data is legal by judging the consistency between the first target time and the second target time and between the first timestamp and the second timestamp; Acquire response information for the encrypted request data sent by the backend after determining whether the encrypted request data is legal.

2. The data call authentication method according to claim 1, It is characterized in that Before the preset first target time and the first timestamp corresponding to the initial request data are processed based on the target agreed formula to obtain the digital parameter, the method further includes: Obtain a pre-saved set of preset convention formulas from a database; A formula is selected from the preset agreed formula set as the target agreed formula in the current data calling process.

3. The data call authentication method according to claim 1, It is characterized in that Before encrypting the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain the encrypted request data, the method further includes: encapsulating the initial request data, the first target time, the timestamp and the digital parameter into target request data; Accordingly, encrypting the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain the encrypted request data includes: The target request data is encrypted using a preset encryption algorithm to obtain the encrypted request data.

4. The data call authentication method according to claim 1, It is characterized in that The obtaining of response information for the encrypted request data sent by the backend after determining whether the encrypted request data is legal includes: Obtaining response information containing information indicating an illegal request and for the encrypted request data, which is returned by the backend after determining that the encrypted request data is illegal; Or, obtaining response information including call data corresponding to the encrypted request data, which is returned by the backend after determining that the encrypted request data is legal.

5. The data call authentication method according to any one of claims 1 to 4, It is characterized in that After sending the encrypted request data to the backend, the method further includes: Determine whether a response message returned by the back end is received within a preset waiting time; If the response information returned by the back end is not received within the preset waiting time, the encrypted request data is sent to the back end again.

6. A data call authentication method, It is characterized in that Applied to the backend, including: Get the encrypted request data; Decrypting the encrypted request data, and processing the digital parameters in the decrypted request data using the target agreed formula to obtain the corresponding second target time and second timestamp; Determining whether the second target time is consistent with the first target time in the decrypted request data; If the second target time is inconsistent with the first target time, the encrypted request data is determined to be illegal, and a response message containing illegal data is sent to the front end for the encrypted request data; If the second target time is consistent with the first target time, determining whether the second timestamp is consistent with the first timestamp in the decrypted request data; If the second timestamp is inconsistent with the first timestamp, the encrypted request data is determined to be illegal, and a response message containing illegal data is sent to the front end for the encrypted request data; If the second timestamp is consistent with the first timestamp, the encrypted request data is determined to be legal, and a response message including the call data corresponding to the encrypted request data is sent to the front end.

7. A data call authentication device, It is characterized in that Applied to the front end, including: A parameter processing module, used to obtain the initial request data through the front-end page, and process the preset first target time and the first timestamp corresponding to the initial request data based on the target agreed formula to obtain a digital parameter; A data encryption module, used for encrypting the data including the initial request data, the first target time, the first timestamp and the digital parameter to obtain encrypted request data; A data sending module, used for sending the encrypted request data to a backend so that the backend decrypts the encrypted request data, and then uses the target agreed formula to process the digital parameters in the decrypted request data to obtain the corresponding second target time and second timestamp, and determines whether the encrypted request data is legal by judging the consistency between the first target time and the second target time and between the first timestamp and the second timestamp; The response information acquisition module is used to obtain the response information for the encrypted request data sent by the back end after determining whether the encrypted request data is legal.

8. A data call authentication device, It is characterized in that Applied to the backend, including: A data acquisition module is used to acquire encrypted request data; A data decryption module, used to decrypt the encrypted request data, and process the digital parameters in the decrypted request data using a target agreed formula to obtain a corresponding second target time and a second timestamp; A first parameter determination module, used to determine whether the second target time is consistent with the first target time in the decrypted request data; A first information sending module is used for determining that the encrypted request data is illegal when the second target time is inconsistent with the first target time, and sending a response message containing illegal data to the front end for the encrypted request data; A second parameter judgment module, used for judging whether the second timestamp is consistent with the first timestamp in the decrypted request data when the second target time is consistent with the first target time; A second information sending module is used for determining that the encrypted request data is illegal when the second timestamp is inconsistent with the first timestamp, and sending a response message containing illegal data to the front end for the encrypted request data; The third information sending module is used to determine that the encrypted request data is legal when the second timestamp is consistent with the first timestamp, and send a response message containing the call data corresponding to the encrypted request data to the front end.

9. An electronic device, It is characterized in that include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the data call authentication method according to any one of claims 1 to 6.

10. A computer-readable storage medium, It is characterized in that Used to store a computer program, which, when executed by a processor, implements the data call authentication method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Remote procedure calling (RPC) method based on security authentication

    CN107493286A

  • Intelligent electric meter lightweight authentication method and system in edge computing scene

    CN111147472A