An Application Security Isolation and Protection Method and System
By introducing a unified security protection mechanism into the application architecture, including entry modules, intercept modules, etc., the problem of high complexity in external request security protection management in the existing technology is solved, and low-cost and low-maintenance application security isolation protection is achieved.
Patent Information
- Application Number
- CN202111261642.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-28
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-10-28
AI Technical Summary
When facing diversified external requests, the prior art lacks unified security protection means, resulting in high management complexity and excessive implementation and maintenance costs.
By introducing entry modules, intercept modules, server application modules, database modules and identity authentication server modules into the application architecture, unified interception and verification of external requests is achieved. Specific steps include secondary encapsulation of requests, extraction and verification of metadata information, verification of user identity signatures, interception of requests and logging.
It realizes filtering and interception of malicious requests and illegal users, ensures the security of application data, and reduces implementation and maintenance costs. Each module is independent of each other, and the update of one module will not affect other modules, and the maintenance cost is low.
Smart Images

Figure CN116049778B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of application software isolation and protection security, and particularly relates to a security verification mechanism for application program isolation and protection and for transmitting sensitive information between application program modules. Background Art
[0002] Network isolation technology realizes the isolation and data exchange of internal and external networks, transparently supports a variety of network applications, and through the isolation module, can filter information such as viruses and malicious codes in data exchange. At the same time, the isolation module can also perform operations such as desensitization encryption on sensitive data existing in data exchange, and efficiently realizes the security of data in internal and external networks. Under the guidance of the microservices design concept, in order to reduce the coupling of application programs, they are generally divided into multiple business modules. The business modules are independent of each other and cooperate with each other to meet business requirements. At the same time, each business module also needs to support external requests from different sources, such as APP requests, browser requests, RPC requests, etc. For the security of internal data, an isolation module is usually set between each business module and the database to check and filter the transmitted data content to ensure the security of internal sensitive data; for the security of business modules, the requests are usually checked for legality in the business module to ensure the legality of attributes such as the permissions and sources of the requests, ensuring the security of the business module. Multiple security measures cooperate with each other to improve the guarantee for the safe and stable operation of application programs.
[0003] Due to the diversity of external requests, such as HTTP requests, RPC requests, etc., it is necessary to implement security protection for each type of external request, lacking a unified security protection means and having a high management complexity. HTTP is a stateless application layer protocol, and usually uses Session and Cookie to complete the verification of permissions or request sources. Although data encryption during the transmission process can be completed through the HTTPS protocol, the implementation of a series of security measures such as permission verification is still in the business module. RPC is usually used for function calls between different modules, and there is no encryption involved in the intermediate transmission process. The security verification is usually in the functions of each business module. In the actual software design and development process, although security verification is important, it is too redundant and the implementation cost is too high. At the same time, due to the division of different business modules, modifying one business module usually involves the update of many business modules, and the maintenance cost is too high. Therefore, there is an urgent need to design a method for security verification of application programs. Summary of the Invention
[0004] To solve the cost and technical problems mentioned in the background, the present invention provides a method for secure isolation and protection of application programs. Starting from the architecture design of the application program, each module is re-split and combined internally, and the architecture is redesigned to achieve secure isolation and protection of the application program. The entire application program exposes a unified entry to external requests, is transparent to external applications, does not increase the learning cost and other economic costs, has strong practicability, and meets the requirements of low implementation cost and low maintenance cost.
[0005] To achieve the above object, the present invention is implemented by the following technical solutions: A method for secure isolation and protection of application programs, including the following steps:
[0006] S1. After the application program starts, INTER and CERT communicate with the DB respectively, and synchronize the metadata information to INETR and CERT respectively;
[0007] S2. After E receives the request for the user identity signature, it forwards it to CERT. CERT issues the user identity signature, records it in itself and the DB, returns the user identity signature to E, and further returns it to the user end that issued the request;
[0008] S3. After E receives an external request, according to the type of the request, it extracts the meta-information in the request and performs secondary encapsulation on the request: records the meta-information on the request header after secondary encapsulation;
[0009] S4. INTER intercepts and verifies the request after secondary encapsulation by E, including user identity signature verification and metadata verification; after both verifications pass, the request is sent to the server APP, and for requests that do not pass, they are recorded in the log;
[0010] S5. After the request reaches the server APP, it executes the corresponding business processing logic and encapsulates the processed data into a response body; after the response body is returned to E, E splits it and returns it to the corresponding external request user according to its header information.
[0011] In the above steps, E represents the entry module of the application program, INTER represents the interception module, CERT represents the identity authentication module, DB represents the database module, and the server APP represents the server application program module of the application program.
[0012] The extraction of the meta-information in the request includes: for APP and browser requests, extracting the URL and user identity signature in their request headers as meta-information; for RPC requests, extracting its target function and user identity signature as meta-information.
[0013] The user identity signature verification and metadata verification include:
[0014] a. Send it to CERT for legitimacy verification using the user identity signature in the request header. If it is illegal, discard it directly;
[0015] b. Compare the URL or target function in the request header with the metadata information stored in the DB. If the URL and target function in the request header are illegal, discard the request.
[0016] The response body header information records its corresponding request.
[0017] An application security isolation and protection system includes an entry module, an interception module on the server side, a server-side application module, a database module, and an identity authentication server module;
[0018] The entry module is used to respond to all external requests and re-encapsulate the external requests and send them to the server side;
[0019] The interception module is used to intercept and review the requests sent from the entry module to the server side, discard illegal requests, and not make a response;
[0020] The server-side application module is used to process the business processing logic of the application, process external requests, and respond to the requests;
[0021] The identity authentication server module is used for user identity signature application, user identity signature storage, and user identity signature authentication;
[0022] The database module is responsible for storing all business data information and metadata information in the application.
[0023] The external requests include requests from the APP side, browser-side requests, and RPC requests.
[0024] The metadata information includes request information and identity authentication information.
[0025] Compared with the prior art, the beneficial effects of the present invention are:
[0026] In the application security isolation and protection method of the present invention, it transparently supports various requests externally, extracts metadata information from all requests for unified interception and verification, realizes the filtering and interception of malicious requests and illegal users, and ensures the security of application data. And each module in this method is independent of each other, and the update of one module will not affect other modules, with low maintenance costs. Description of the Drawings
[0027] Figure 1 It is a schematic structural composition diagram of an application security isolation and protection method of the present invention
[0028] Figure 2 This is a flowchart of a method for secure isolation and protection of application programs according to the present invention. Detailed implementation manners
[0029] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following will describe in detail the specific implementation methods of the present invention with reference to the accompanying drawings. Many specific details are set forth in the following description in order to fully understand the present invention. However, the present invention can be implemented in many other ways different from those described herein, and those skilled in the art can make similar improvements without departing from the connotation of the invention. Therefore, the present invention is not limited by the specific implementations disclosed below.
[0030] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention.
[0031] A method for secure isolation and protection of application programs according to the present invention is an enhanced design of the data inspection and verification mechanism between business modules and databases in general application programs, which reduces the implementation cost and maintenance cost on the premise of achieving security protection.
[0032] As Figure 1 shown, the secure isolation and protection mechanism is completed through the cooperation of five units: an entrance module, an interception module, a server application program module, a database module, and an identity authentication server module.
[0033] The entrance module is responsible for responding to all external requests, including requests from the APP side, browser requests, RPC requests, etc., and re-packaging the external requests and sending them to the server side;
[0034] The interception module is responsible for intercepting and auditing the requests sent by the entrance module to the server side, and directly discarding illegal requests without making a response;
[0035] The server application program module is responsible for implementing the business processing logic of the application program, processing external requests, and making responses to the requests;
[0036] The identity authentication server module is responsible for user identity signature application, user identity signature storage, and user identity signature authentication;
[0037] The database module is responsible for storing all business data information and metadata information in the application program. Among them, the metadata information includes request information, identity authentication, and other information.
[0038] As Figure 2As shown in the figure, the interaction process of an application program security isolation and protection specifically includes the following steps:
[0039] In the following steps, E represents the entry module of the entire application program; INTER represents the interception module; CERT represents the identity authentication module; DB represents the database module; Server APP represents the server application program module of the application program.
[0040] Step 1: After the application program starts, INTER and CERT communicate with DB respectively, and synchronize the metadata information to INETR and CERT respectively.
[0041] Step 2: After receiving the request for the user identity signature, E directly forwards it to CERT. After CERT issues the user identity signature, it records it in itself and DB, and returns the user identity signature to E, and further returns it to the end that sent the request.
[0042] Step 3: After receiving an external request, E extracts the meta-information in the request according to the type of the request, performs secondary encapsulation on the request, and records the meta-information on the request header after secondary encapsulation. For APP and browser requests, the URL and user identity signature in the request header are extracted as meta-information. For RPC requests, the target function and user identity signature are extracted as meta-information;
[0043] Step 4: INTER intercepts and verifies the request after E's secondary encapsulation. First, it sends the user identity signature in the request header to CERT for legality verification. If it is illegal, it is directly discarded; after the identity verification passes, it compares the URL or target function in the request header with the metadata information stored in DB. If the URL and target function in the request header are not compliant, the request is discarded; after both the user identity signature verification and the metadata verification pass, it is sent to the Server APP. For requests that do not pass, they are recorded in the log.
[0044] Step 5: After the request reaches the Server APP, it executes the corresponding business processing logic, and encapsulates the processed data into a response body. Similarly, the response body header information records its corresponding request. After the response body returns to E, E splits it and returns it to the corresponding request according to its header information.
[0045] The above embodiments are implemented on the premise of the technical solution of the present invention, and the detailed implementation manners and specific operation processes are given, but the protection scope of the present invention is not limited to the above embodiments. The methods used in the above embodiments are all conventional methods unless otherwise specified.
Claims
1. An application security isolation and protection method, characterized in that, It includes the following steps: S1. After the application starts, INTER and CERT communicate with DB respectively, and synchronize the metadata information into INTER and CERT respectively; S2. After receiving the request for user identity signature, E forwards it to CERT. CERT issues the user identity signature, records it in itself and DB, returns the user identity signature to E, and further returns it to the user side that issues the request; S3. After receiving an external request, E extracts the metadata information in the request according to the type of the request, and performs secondary encapsulation on the request: records the metadata information on the request header after secondary encapsulation; The extraction of the metadata information in the request includes: for APP and browser requests, extracts the URL and user identity signature in their request headers as metadata information; for RPC requests, extracts its target function and user identity signature as metadata information; S4. INTER intercepts and verifies the request after secondary encapsulation by E, including user identity signature verification and metadata verification; after both verifications pass, the request is sent to the server-side APP, and for requests that do not pass, they are recorded in the log; S5. After the request reaches the server-side APP, the corresponding business processing logic is executed, and the processed data is encapsulated into a response body; after the response body is returned to E, E splits it and returns it to the corresponding external request user according to its header information; In the above steps, E represents the entry module of the application, INTER represents the interception module, CERT represents the identity authentication module, DB represents the database module, and the server-side APP represents the server-side application module of the application.
2. The method for secure isolation and protection of an application program according to claim 1, characterized in that The user identity signature verification and metadata verification include: a. Sends the user identity signature in the request header to CERT for legality verification. If it is illegal, it is directly discarded; b. Compares the URL or target function in the request header with the metadata information stored in DB. If the URL and target function in the request header are illegal, the request is discarded.
3. The method for secure isolation and protection of application programs according to any one of claims 1-2, characterized in that, The response body header information records its corresponding request.
4. An application security isolation and protection system, which is used to implement the method described in any one of claims 1-3, and is characterized in that, It includes an entry module, an interception module on the server side, a server-side application module, a database module, and an identity authentication module; The entry module is used to respond to all external requests, and perform secondary encapsulation on the external requests and send them to the server side; the external requests include requests from the APP side, browser requests, and RPC requests; for APP and browser requests, extracts the URL and user identity signature in their request headers as metadata information; For RPC requests, extracts its target function and user identity signature as metadata information; The interception module is used to intercept and review the requests sent by the entry module to the server side, discard illegal requests and do not make a response; The server-side application module is used to process the business processing logic of the application, process external requests, and respond to the requests; The identity authentication module is used for user identity signature application, user identity signature storage, and user identity signature authentication; The described database module is responsible for storing all business data information and metadata information in the application.
Citation Information
Patent Citations
A statistical identity authentication and log processing micro service system and an implementation method thereof
CN109446769A
Unified authentication system based on multi-service system integration
CN110891060A