Permission Verification Method, Device, Equipment and Storage Medium Based on Routing Jump

By setting up a routing verification interface on the server, intercepting and verifying the client's route jump request, the problem that the client caches routing information is easily maliciously modified, effectively blocking malicious routing jumps, and improving the system's security.

CN116232684BActive Publication Date: 2025-06-24BEIJING RUIHESOFT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310010472.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-04
Publication Date
2025-06-24
Estimated Expiration
2043-01-04

AI Technical Summary

Technical Problem

In the existing routing jump technology, the routing information cached by the client is easily maliciously modified, resulting in insufficient security and ineffective preventing malicious routing jumps.

Method used

Set up a routing verification interface on the server to intercept the client's route jump request, check the JWT string and the route address that is required to jump, determine whether route jump is allowed, and send the verification result to the client.

Benefits of technology

By placing the route jump verification on the server, the routing information is effectively prevented from being maliciously modified, and malicious route jump is prevented, improving the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232684B_ABST
    Figure CN116232684B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a permission verification method, apparatus, device, and storage medium based on routing jump. The method includes intercepting a routing jump request initiated by a client by a routing verification interface of a server; verifying a JWT string and a routing address to be jumped carried in the routing jump request; and sending the verification result to the client so that the client determines whether to perform a routing jump according to the verification result. In this way, malicious modification of routing information can be prevented, and malicious routing jumps can be effectively blocked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of routing verification, and particularly to a permission verification method, device, equipment and storage medium based on routing jump. Background Art

[0002] The existing idea of routing jump is to store routing information in the client cache and verify the routing information cached in the client every time a routing jump occurs. However, the client cache information can be modified, and as long as the data stored in the client is relatively insecure. Summary of the Invention

[0003] The present disclosure provides a permission verification method, device, equipment and storage medium based on routing jump, which can effectively prevent malicious routing jumps.

[0004] According to the first aspect of the present disclosure, a permission verification method based on routing jump is provided.

[0005] The method includes:

[0006] The routing verification interface of the server intercepts the routing jump request initiated by the client;

[0007] Verify the JWT string carried in the routing jump request and the routing address to be jumped to;

[0008] Send the verification result to the client so that the client can determine whether to perform a routing jump according to the verification result.

[0009] In some implementable ways of the first aspect, the JWT string is provided to the client through the following steps:

[0010] The login verification interface of the server verifies the account information and password carried in the login request initiated by the client. If the verification is successful, a JWT string is generated and sent to the client.

[0011] In some implementable ways of the first aspect, before the routing verification interface of the server intercepts the routing jump request initiated by the client, the method further includes:

[0012] The server receives the menu routing request initiated by the client, and obtains the corresponding account information according to the JWT string carried in the menu routing request;

[0013] Query the persistent database according to the account information to obtain the routing information corresponding to the account information, and store the JWT string and the routing information in the cache database;

[0014] Send the routing information to the client so that the client can perform menu rendering according to the routing information.

[0015] In some implementations of the first aspect, verifying the JWT string carried in the routing jump request and the routing address to be jumped to includes:

[0016] The server obtains the corresponding routing information from the cache database according to the JWT string carried in the routing jump request, and determines whether the routing information contains the routing address to be jumped to.

[0017] In some implementations of the first aspect, sending the verification result to the client includes:

[0018] If the server determines that the routing information contains the routing address to be jumped to, it sends a verification passed message to the client; otherwise, it sends a verification failed message to the client.

[0019] In some implementations of the first aspect, the client renders the menu according to the routing information, including:

[0020] The client matches the corresponding menu rendering logic according to the routing information and renders the menu according to the menu rendering logic.

[0021] In some implementations of the first aspect, the routing jump request initiated by the client is generated by operating on the menu.

[0022] According to the second aspect of the present disclosure, there is provided a permission verification device based on routing jump.

[0023] The device includes:

[0024] A request interception and verification module, configured to intercept and verify the parameters in the routing jump request initiated by the client;

[0025] A transmission module, configured to complete the information transmission between the client and the server;

[0026] A judgment module, configured to judge whether to perform a routing jump.

[0027] According to the third aspect of the present disclosure, there is provided an electronic device. The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described above.

[0028] According to the fourth aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to cause a computer to execute the method as described above.

[0029] In the present disclosure, by placing the routing jump verification on the server side to prevent malicious modification of routing information, malicious routing jumps are effectively blocked.

[0030] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In combination with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent. The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. In the drawings, the same or similar reference numerals represent the same or similar elements, where:

[0032] Figure 1 FIG. shows a schematic diagram of an exemplary operating environment in which the embodiments of the present disclosure can be implemented;

[0033] Figure 2 FIG. shows a flowchart of a permission verification method based on routing jump provided by an embodiment of the present disclosure;

[0034] Figure 3 FIG. shows a schematic diagram of a permission verification method based on routing jump provided by an embodiment of the present disclosure;

[0035] Figure 4 FIG. shows a block diagram of a permission verification device based on routing jump provided by an embodiment of the present disclosure;

[0036] Figure 5 FIG. shows a block diagram of an exemplary electronic device capable of implementing the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present disclosure belong to the scope of protection of the present disclosure.

[0038] In addition, the term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0039] In view of the problems mentioned in the background art, the embodiments of the present disclosure provide a permission verification method, apparatus, device and storage medium based on routing jump, which can effectively prevent malicious routing jump.

[0040] Specifically, the routing verification interface of the server intercepts the routing jump request initiated by the client; verifies the JWT string carried in the routing jump request and the routing address to be jumped; and sends the verification result to the client, so that the client can judge whether to perform the routing jump according to the verification result.

[0041] In this way, the routing information can be prevented from being maliciously modified, and malicious routing jump can be effectively prevented.

[0042] Next, in conjunction with the accompanying drawings, the permission verification method, apparatus, device and storage medium based on routing jump provided by the embodiments of the present disclosure will be described in detail through specific embodiments.

[0043] Figure 1 The schematic diagram of an exemplary operating environment in which the embodiments of the present disclosure can be implemented is shown. As Figure 1 shown, the operating environment 100 may include: a client device 102 and a server 104.

[0044] Among them, the client device 102 may be a mobile electronic device or a non-mobile electronic device. For example, the mobile electronic device may be a laptop computer, a personal digital assistant or an ultra-mobile personal computer (UMPC), etc., and the non-mobile electronic device may be a personal computer (PC), a supercomputer or a server, etc. The server 104, that is, the server side, may be a cloud server, a server of a distributed system, or a server combined with a blockchain.

[0045] As an example, the client device 102 initiates a routing jump request to the server 106, and the server 106 intercepts the request and calls the routing verification interface to verify the parameters in the request. After the verification is completed, the verification result is sent to the client device 102.

[0046] If the verification result received by the client device 102 is passed, the routing jump is performed; if the verification result received by the client device 102 is not passed, the routing jump is not performed and the login page is returned.

[0047] In this way, the routing jump permission can be effectively verified, the routing information can be prevented from being maliciously modified, and malicious routing jump can be prevented.

[0048] The following will introduce in detail the permission verification method based on route jump provided by the embodiments of the present disclosure. Among them, the permission verification method based on route jump can be applied to the above-mentioned operating environment 100.

[0049] Figure 2 shows a flowchart of a permission verification method based on route jump provided by an embodiment of the present disclosure; as Figure 2 shown, the permission verification method 200 based on route jump may include the following steps:

[0050] S210, the route verification interface of the server intercepts the route jump request initiated by the client.

[0051] Specifically, each time the client initiates a route jump request, the route verification interface of the server first intercepts the request for further route verification.

[0052] In some embodiments, the JWT string is provided to the client through the following steps:

[0053] The login verification interface of the server verifies the account information and password carried in the login request initiated by the client. If the verification is successful, a JWT string is generated and sent to the client.

[0054] In some embodiments, before the route verification interface of the server intercepts the route jump request initiated by the client, the method 200 may further include:

[0055] The server receives the menu route request initiated by the client, and obtains the corresponding account information according to the JWT string carried in the menu route request;

[0056] Query the persistent database according to the account information to obtain the route information corresponding to the account information, and store the JWT string and the route information in the cache database; where the persistent database is a database that can permanently store data; the cache database can be Redis or other types of databases that can achieve the same function.

[0057] Send the route information to the client so that the client can render the menu according to the route information.

[0058] In some embodiments, the client renders the menu according to the route information, including:

[0059] The client matches the corresponding menu rendering logic according to the route information and renders the menu according to the menu rendering logic.

[0060] In some embodiments, the route jump request initiated by the client is generated by operating on the menu.

[0061] S220, verify the JWT string carried in the routing jump request and the routing address to be jumped to.

[0062] In some embodiments, verifying the JWT string carried in the routing jump request and the routing address to be jumped to includes:

[0063] The server obtains the corresponding routing information from the cache database according to the JWT string carried in the routing jump request, and determines whether the routing information contains the routing address to be jumped to.

[0064] S230, send the verification result to the client so that the client can determine whether to perform a routing jump according to the verification result.

[0065] In some embodiments, sending the verification result to the client includes:

[0066] If the server determines that the routing information contains the routing address to be jumped to, it sends a verification passed message to the client; otherwise, it sends a verification failed message to the client.

[0067] It should be noted that if the JWT string corresponding to the account information expires, the JWT string and routing information stored in the cache database will be cleared, and all routing jumps initiated by the client will jump to the login page.

[0068] Figure 3 shows a schematic diagram of an authentication method based on routing jump provided by an embodiment of the present disclosure; as Figure 3 shown, taking client A as an example, the server receives a login request carrying account information and password initiated by client A, intercepts and verifies the account information and password carried in the login request, and if the verification is successful, generates a JWT string and sends it to client A.

[0069] After receiving the JWT string, client A initiates a menu routing request carrying the JWT string.

[0070] The server intercepts the above menu routing request and obtains the corresponding account information according to the JWT string, queries the persistent database according to the account information to obtain the routing information corresponding to the account information, and at the same time stores the JWT string and routing information in the cache database for subsequent verification by querying the corresponding information during routing jumps.

[0071] After the server finishes storing, it sends the queried routing information to client A. After receiving the routing information, client A matches the corresponding menu rendering logic according to the routing information and performs menu rendering according to the menu rendering logic.

[0072] After the menu is rendered, for each routing jump request initiated by Client A within the menu scope, the server will intercept the request and query the corresponding routing information from the cache database based on the JWT string carried in the routing jump request, and determine whether the routing address to be jumped carried in the routing jump request is included in the corresponding routing information. If so, the server will send a verification result of true to Client A; otherwise, it will send a verification result of false to Client A.

[0073] If the verification result is true, Client A will perform a routing jump; if the verification result is false, Client A will jump back to the login page.

[0074] According to the embodiments of the present disclosure, the following technical effects are achieved:

[0075] The routing jump verification is performed on the server side. The time complexity for the server to obtain routing information from the cache database based on the JWT string is O(1). Therefore, compared with performing verification on the client side, the method, device, equipment, and storage medium for permission verification based on routing jump provided by the embodiments of the present disclosure are more secure and the performance and efficiency of routing jumps are not affected. It can effectively prevent the routing information from being maliciously modified and effectively prevent malicious routing jumps.

[0076] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present disclosure is not limited by the described action sequence, because according to the present disclosure, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present disclosure.

[0077] The above is the introduction of the method embodiments. The following further illustrates the solution of the present disclosure through device embodiments.

[0078] Figure 4 The block diagram of a permission verification device based on routing jump provided by an embodiment of the present disclosure is shown. As Figure 4 shown, the permission verification device 400 based on routing jump includes:

[0079] A request interception and verification module 410, configured to intercept and verify the parameters in the routing jump request initiated by the client;

[0080] A transmission module 420, configured to complete the information transmission between the client and the server;

[0081] A judgment module 430, configured to judge whether to perform a routing jump.

[0082] In some embodiments, the apparatus 400 may further include:

[0083] A menu rendering module that matches the corresponding menu rendering logic according to the routing information and performs menu rendering according to the menu rendering logic.

[0084] It can be understood that those skilled in the art can clearly understand that Figure 4 Each module in the permission verification apparatus 400 based on route jump shown has the function of implementing each step in the permission verification method 200 based on route jump provided by the embodiments of the present disclosure, and can achieve its corresponding technical effects. Specifically, reference can be made to the corresponding processes in the foregoing method embodiments. For the sake of brevity, they will not be described herein again.

[0085] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device and a readable storage medium.

[0086] Figure 5 The block diagram of an exemplary electronic device capable of implementing the embodiments of the present disclosure is shown. The electronic device 500 is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device 500 may also represent various forms of mobile devices, such as, for example, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0087] The device 500 includes a computing unit 501, which can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 502 or the computer program loaded from the storage unit 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the device 500 can also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.

[0088] A plurality of components in the device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the device 500 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0089] The computing unit 501 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 executes the various methods and processes described above, such as method 200. For example, in some embodiments, method 200 can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the computing unit 501, one or more steps of method 200 described above can be executed. Alternatively, in other embodiments, the computing unit 501 can be configured to execute method 200 in any other suitable manner (e.g., by means of firmware).

[0090] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general programmable processor, receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0091] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program code is executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0092] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0093] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0094] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0095] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating a blockchain.

[0096] It should be understood that the various forms of processes shown above can be used, with steps reordered, added or deleted. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitation is imposed herein.

[0097] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A permission verification method based on routing jump, characterized in that, The method includes: The server receives a menu routing request initiated by the client, and obtains the corresponding account information according to the JWT string carried in the menu routing request; Query the persistent database according to the account information to obtain the routing information corresponding to the account information, and store the JWT string and the routing information in the cache database; Send the routing information to the client so that the client can perform menu rendering according to the routing information; The routing verification interface of the server intercepts the routing jump request initiated by the client; Verify the JWT string carried in the routing jump request and the routing address to be jumped; wherein, the server obtains the corresponding routing information from the cache database according to the JWT string carried in the routing jump request, and judges whether the routing information contains the routing address to be jumped; Send the verification result to the client so that the client can judge whether to perform a routing jump according to the verification result.

2. The method according to claim 1, wherein The JWT string is provided to the client through the following steps: The login verification interface of the server verifies the account information and password carried in the login request initiated by the client. If the verification is successful, a JWT string is generated and sent to the client.

3. The method according to claim 1, characterized in that The sending the verification result to the client includes: If the server judges that the routing information contains the routing address to be jumped, it sends a verification passed message to the client; otherwise, it sends a verification failed message to the client.

4. The method according to claim 1, characterized in that, The client performing menu rendering according to the routing information includes: The client matches the corresponding menu rendering logic according to the routing information and performs menu rendering according to the menu rendering logic.

5. The method according to claim 1, wherein The routing jump request initiated by the client is generated by operating on the menu.

6. A permission verification device based on routing jump, characterized in that, It includes: A request interception and verification module for intercepting and verifying the parameters in the routing jump request initiated by the client; A transmission module for completing the information transmission between the client and the server; A judgment module for judging whether to perform a routing jump; The permission verification device based on routing jump is further configured to, before the routing verification interface of the server intercepts the routing jump request initiated by the client, the server receives the menu routing request initiated by the client, and obtains the corresponding account information according to the JWT string carried in the menu routing request; Query the persistent database according to the account information to obtain the routing information corresponding to the account information, and store the JWT string and the routing information in the cache database; Send the routing information to the client so that the client can perform menu rendering according to the routing information; Verify the JWT string carried in the routing jump request and the routing address to be jumped; wherein, The server obtains the corresponding routing information from the cache database according to the JWT string carried in the routing jump request, and judges whether the routing information contains the routing address to be jumped.

7. An electronic device, characterized in that, It includes: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions, when executed by the at least one processor, enable the at least one processor to perform the method according to any one of claims 1-5.

8. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are for causing the computer to perform the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Page loading method and device, storage medium and electronic device

    CN113296859A

  • Micro-service access method, apparatus and device, and storage medium

    WO2022126968A1