A protection method and device for website access

By using the target random identifier in the user session instead of the original identifier in the operation request and performing verification and matching, the problem of insufficient security of attack methods such as malicious tampering messages in the prior art is solved, and a more efficient blocking effect of illegal user access is achieved.

CN116248365BActive Publication Date: 2025-06-13CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310071610.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-17
Publication Date
2025-06-13
Estimated Expiration
2043-01-17

AI Technical Summary

Technical Problem

The prior art is poor in protecting user information security, identifying and preventing cross-site and over-authorized access of illegal users, and especially has limited effectiveness in attack methods such as malicious tampering with messages.

Method used

By using the target random identifier in the user session instead of the original identifier in the operation request, and verifying whether the random identifier exists, then determining whether the user is a legitimate user based on the matching result of the function module name corresponding to the random identifier and the request address of the operation request, thereby preventing the attack of the illegal user.

Benefits of technology

It effectively prevents malicious users from attacking by tampering with messages, improves the security of website access, and prevents cross-site access of malicious websites and malicious users' level of overright access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248365B_ABST
    Figure CN116248365B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a protection method and device for website access, which are applied in the field of Internet technology, and include: receiving an operation request sent by a terminal device for a target data record, where the operation request carries a target random identifier; if the target random identifier is included in the user session, obtaining the function module name and the original identifier corresponding to the target random identifier from the user session; if the function module name corresponding to the target random identifier matches the request address of the operation request, operating on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result, and returning it to the terminal device. The present application uses a random identifier to replace the original identifier to mark the data record, and determines whether the user initiating the operation request is a legitimate user by verifying whether the random identifier exists and the matching result between the function module name corresponding to the random identifier and the request address of the operation request, effectively preventing the attack method of maliciously tampering with packets by illegal users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of Internet technologies, and in particular, to a method and device for protecting website access. Background Art

[0002] With the rapid development of Internet technologies, WEB systems based on the browser and server architecture (Browser / Server, abbreviated as B / S) are increasingly widely used. In this architecture, the core part of the system function implementation is centralized on the server, which simplifies the system development and maintenance, and at the same time brings convenience to users. While bringing convenience to users, WEB systems also bring a series of challenges to system security. For example, how to effectively protect user information security, identify and prevent cross-site access and unauthorized access by illegal users has become the biggest challenge faced by website developers.

[0003] In the related art, the system background verifies the Referer information in the http message header of each user request. Only when the Referer information is consistent with the current website is it regarded as a legitimate user access.

[0004] However, the above solution is only effective in preventing and controlling regular user page operations, and its effect on attack methods such as malicious tampering of messages by users is very limited, that is, the security is poor. Summary of the Invention

[0005] Embodiments of the present application provide a method and device for protecting website access, which are used to identify and prevent cross-site access and unauthorized access by illegal users.

[0006] In a first aspect, embodiments of the present application provide a method for protecting website access, which is applied to a server and includes:

[0007] Receiving an operation request for a target data record sent by the terminal device, where the operation request carries a target random identifier;

[0008] If the target random identifier is included in the user session, obtaining, from the user session, a function module name and an original identifier corresponding to the target random identifier, where the user session is used to store the original identifiers, random identifiers, and function module names of at least one data record with operation permissions;

[0009] If the function module name corresponding to the target random identifier matches the request address of the operation request, operating on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result;

[0010] Returning the operation result to the terminal device.

[0011] The present application marks data records with a random identifier instead of the original identifier in the operation request, verifies whether the random identifier exists, and then determines whether the user who initiates the operation request is a legitimate user based on the matching result of the function module name corresponding to the random identifier and the request address of the operation request, thereby effectively preventing illegal users from maliciously tampering with messages.

[0012] Optionally, if the target random identifier is not included in the user session, a response message rejecting the operation is returned to the terminal device.

[0013] Since the target random identifier is a 64-bit random number composed of uppercase and lowercase letters and numbers, the possibilities of the target random identifier are 62 to the power of 64, which effectively prevents malicious users from cracking it in a short period of time, and effectively prevents cross-site access by malicious websites and horizontal unauthorized access by malicious users.

[0014] Optionally, if the function module name corresponding to the target random identifier does not match the request address of the operation request, a response message rejecting the operation is returned to the terminal device.

[0015] By matching the function module name corresponding to the target random identifier with the request address of the operation request, the target random identifier is verified twice, thereby preventing malicious users from using the target random identifier to access a record of other functions, and preventing malicious users from using a random identifier to operate records of other function modules.

[0016] Optionally, before receiving the operation request for the target data record sent by the terminal device, the method further includes:

[0017] Receiving a record query request sent by the terminal device;

[0018] Querying and obtaining at least one data record and an original identifier and a function module name of each data record based on the record query request;

[0019] Generate a random identifier corresponding to the original identifier of each data record, and save the original identifier, the random identifier and the function module name of each data record in the user session accordingly;

[0020] Sending a query result to the terminal device, the query result including the at least one data record and a corresponding random identifier.

[0021] Optionally, the storing the original identifier, the random identifier and the function module name of each data record in the user session accordingly includes:

[0022] A hash table structure is used to store the original identifier, random identifier and function module name of each data record in the user session accordingly.

[0023] Optionally, the performing an operation on the target data record based on the original identifier corresponding to the target random identifier and obtaining the operation result further includes:

[0024] The target random identifier saved in the user session is deleted.

[0025] Effectively solve the problem of malicious users attacking by replaying messages.

[0026] Optionally, if the function module name corresponding to the target random identifier matches the request address of the operation request, then operating the target data record based on the original identifier corresponding to the target random identifier, before obtaining the operation result, further includes:

[0027] Obtaining an access address of a function module name corresponding to the target random identifier from the user session;

[0028] If the access address of the function module name corresponding to the target random identifier is the same as the request address of the operation request, it is determined that the function module name corresponding to the target random identifier matches the request address of the operation request.

[0029] In a second aspect, an embodiment of the present application provides a website access protection device, including:

[0030] An acquisition module, configured to receive an operation request for a target data record sent by the terminal device, wherein the operation request carries a target random identifier;

[0031] The acquisition module is further configured to acquire the function module name and the original identifier corresponding to the target random identifier from the user session if the target random identifier is included in the user session, wherein the user session is used to store the original identifier, the random identifier and the function module name of at least one data record with operation authority;

[0032] a matching module, configured to operate the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result if the function module name corresponding to the target random identifier matches the request address of the operation request;

[0033] The returning module is used to return the operation result to the terminal device.

[0034] The present application marks data records with a random identifier instead of the original identifier in the operation request, verifies whether the random identifier exists, and then determines whether the user who initiates the operation request is a legitimate user based on the matching result of the function module name corresponding to the random identifier and the request address of the operation request, thereby effectively preventing illegal users from maliciously tampering with messages.

[0035] Optionally, the return module is specifically configured to:

[0036] If the target random identifier is not included in the user session, return a response message for rejecting the operation to the terminal device.

[0037] Optionally, the acquisition module is specifically configured to:

[0038] Receive a record query request sent by the terminal device;

[0039] Query and obtain at least one data record, the original identifier of each data record, and the function module name based on the record query request;

[0040] Generate a random identifier corresponding to the original identifier of each data record, and store the original identifier, random identifier, and function module name of each data record in the user session in a corresponding manner;

[0041] Send a query result to the terminal device, where the query result includes the at least one data record and the corresponding random identifier.

[0042] Optionally, the acquisition module is specifically configured to:

[0043] Use a hash table structure to store the original identifier, random identifier, and function module name of each data record in the user session in a corresponding manner.

[0044] Optionally, the matching module is specifically configured to:

[0045] Delete the target random identifier saved in the user session.

[0046] Optionally, the acquisition module is specifically configured to:

[0047] Obtain the access address of the function module name corresponding to the target random identifier from the user session;

[0048] If the access address of the function module name corresponding to the target random identifier is the same as the request address of the operation request, determine that the function module name corresponding to the target random identifier matches the request address of the operation request.

[0049] In a third aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the website access protection method according to any one of the first aspects above.

[0050] Fourthly, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program executable by a computer device. When the program runs on the computer device, the computer device is enabled to execute the website access protection method described in any of the above first aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0052] Figure 1 A schematic diagram of a website access protection system architecture provided by an embodiment of the present application;

[0053] Figure 2 A flowchart of a website access protection method provided by an embodiment of the present application;

[0054] Figure 3 A flowchart of a website access protection method provided by an embodiment of the present application;

[0055] Figure 4 A schematic diagram of the structure of a website access protection device provided by an embodiment of the present application;

[0056] Figure 5 A schematic diagram of the structure of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0057] In order to make the objectives, technical solutions and beneficial effects of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0058] See Figure 1, which is an architecture diagram of a website access protection system used in an embodiment of the present application, the website access system 100 includes a terminal device 101 and a server 102, wherein the terminal device 101 can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., but is not limited thereto. The server 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0059] The terminal device 101 and the server 102 may be connected directly or indirectly via wired or wireless communication, which is not limited in this application.

[0060] Based on the above system architecture, Figure 2 The process of a method for protecting website access is exemplarily shown. The process of the method is executed by a server and includes the following steps:

[0061] Step S201: receiving an operation request for a target data record sent by a terminal device, wherein the operation request carries a target random identifier.

[0062] Specifically, the server receives an operation request sent by a terminal device, and the operation request includes adding, deleting, modifying, querying, etc. a target data record. The operation request carries a target random identifier of the target data record, and the target random identifier is used to identify the target data record, and the target random identifier and the target data record have a corresponding relationship. The target random identifier is a 64-bit random number composed of uppercase and lowercase English letters and numbers.

[0063] Step S202: If the user session includes the target random identifier, the function module name and the original identifier corresponding to the target random identifier are obtained from the user session. The user session is used to store the original identifier, random identifier and function module name of at least one data record with operation authority.

[0064] Specifically, at least one data record with operation authority is stored in the user session, each data record corresponds to an original identifier, a random identifier and a function module name corresponding to the random identifier, and each random identifier has a corresponding function module name and a corresponding original identifier. If the target random identifier corresponding to the operation request exists in the user session, it is preliminarily determined that the user who initiated the user request is a legitimate user, and the function module name and the original identifier corresponding to the target random identifier are obtained from the user session according to the target random identifier.

[0065] Step S203: If the function module name corresponding to the target random identifier matches the request address of the operation request, an operation is performed on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result.

[0066] Specifically, the operation request received by the server includes a target random identifier and a request address. The server searches for the corresponding function module name in the database according to the target random identifier in the operation request, and matches the function module name with the request address. If the two match, the target data record stored in the database of the server is found according to the original identifier corresponding to the target random identifier, and the target data record is operated according to the operation request to obtain the operation result.

[0067] Step S204: Return the operation result to the terminal device.

[0068] Specifically, the server returns the result of executing the operation request to the terminal device.

[0069] The present application marks data records with a random identifier instead of the original identifier in the operation request, verifies whether the random identifier exists, and then determines whether the user who initiates the operation request is a legitimate user based on the matching result of the function module name corresponding to the random identifier and the request address of the operation request, thereby effectively preventing illegal users from maliciously tampering with messages.

[0070] In some embodiments, if the target random identifier is not included in the user session, a response message rejecting the operation is returned to the terminal device.

[0071] Specifically, if the target random identifier carried in the operation request is not in the user session, the user who issues the operation request is regarded as an illegal user, and the server returns a response message to the terminal device refusing to execute the operation request.

[0072] Since the target random identifier is a 64-bit random number composed of uppercase and lowercase letters and numbers, the possibilities of the target random identifier are 62 to the power of 64, which effectively prevents malicious users from cracking it in a short period of time, and effectively prevents cross-site access by malicious websites and horizontal unauthorized access by malicious users.

[0073] In some embodiments, if the function module name corresponding to the target random identifier does not match the request address of the operation request, a response message rejecting the operation is returned to the terminal device.

[0074] Specifically, the operation request received by the server includes a target random identifier and a request address. The server looks up the corresponding function module name in the database based on the target random identifier in the operation request. The server matches the function module name with the request address. If the two do not match, the user who sent the operation request is regarded as an illegal user, and the server returns a response message rejecting the execution of the operation request to the terminal device.

[0075] By matching the function module name corresponding to the target random identifier with the request address of the operation request, the target random identifier is secondarily verified, thereby preventing malicious users from accessing a certain record of other functions by brute-forcing the target random identifier, and preventing malicious users from using a certain random identifier to operate the records of other function modules.

[0076] In some embodiments, before receiving the operation request for the target data record sent by the terminal device, it further includes: receiving a record query request sent by the terminal device; querying at least one data record and the original identifier and function module name of each data record based on the record query request; generating a random identifier corresponding to the original identifier of each data record, and storing the original identifier, random identifier, and function module name of each data record in the user session in a corresponding manner; sending a query result to the terminal device, where the query result includes at least one data record and the corresponding random identifier.

[0077] Specifically, the server receives the query request of the terminal device and obtains at least one data record. Each data record has an original identifier, and the original identifier is used to mark the data record. The server generates a random identifier for each data record and replaces the original identifier with the random identifier to mark each data record. The length of each random identifier is 64 bits, and it is a random number generated by uppercase and lowercase letters and numbers according to a preset generation rule. The random identifier of each data record corresponds to an original identifier and a function module name. The server stores the random identifier, original identifier, function module name corresponding to the random identifier of each data record, and the corresponding relationship among the three in the user session. The server sends at least one data record and the random identifier marking the data record to the terminal device as the query result.

[0078] In some embodiments, storing the original identifier, random identifier, and function module name of each data record in the user session in a corresponding manner includes: using a hash table structure to store the original identifier, random identifier, and function module name of each data record in the user session in a corresponding manner.

[0079] In some embodiments, after operating on the target data record based on the original identifier corresponding to the target random identifier and obtaining an operation result, it further includes: deleting the target random identifier stored in the user session.

[0080] Specifically, after the server executes the user's operation request and obtains the operation result, it deletes the target random identifier in the user session, that is, only the original identifier is used to mark each data record. This effectively solves the problem of malicious users attacking by replaying packets.

[0081] In some embodiments, if the function module name corresponding to the target random identifier matches the request address of the operation request, before operating on the target data record based on the original identifier corresponding to the target random identifier and obtaining the operation result, it further includes: obtaining the access address of the function module name corresponding to the target random identifier from the user session; if the access address of the function module name corresponding to the target random identifier is the same as the request address of the operation request, it is determined that the function module name corresponding to the target random identifier matches the request address of the operation request.

[0082] Specifically, after the server obtains the target random identifier from the target data record, it obtains the access address of the function module name corresponding to the target random identifier from the user session based on the obtained target random identifier; if the request address of the operation request is the same as the access address of the function module name corresponding to the target random identifier, it is determined that the function module name corresponding to the target random identifier matches the request address of the operation request.

[0083] See Figure 3 , which is a schematic flowchart of a website access protection method provided by an embodiment of the present application, including the following steps:

[0084] Step S301, the terminal device initiates a record query request;

[0085] Specifically, the user initiates a query request for data records to the server through the terminal device.

[0086] Step S302, the server generates a random identifier for each data record;

[0087] Specifically, after the server receives the query request sent by the terminal device and completes the database query operation, for each data record queried, a random identifier with a length of 64 is randomly generated according to a pre-set generation rule, and the original identifier marking the data record is replaced. Since only the original identifier of each data record is replaced with a random identifier and the rest of the information remains unchanged, this replacement identifier operation has no impact on the page display of the terminal device and the interaction between the terminal device and the server, so no transformation is required on the front-end page.

[0088] Step S303, save the random identifier, the function module name corresponding to the random identifier, and the original identifier to the user session;

[0089] Specifically, the server stores the original identifier corresponding to the random identifier and the function module name and the corresponding relationship between the three in the user session using a hash table data structure row format. The hash table can ensure the storage of relevant information of multiple data records.

[0090] Step S304, the server returns the query result to the terminal device;

[0091] Step S305, the terminal device initiates an operation request for a certain data record;

[0092] Specifically, if the user wants to add, delete, modify, or view at least one data record being queried, an operation request needs to be initiated to the server, wherein the user's operation request carries a random identifier for marking the data record.

[0093] Step S306, the server verifies whether the user session contains the random identifier of the data record;

[0094] Specifically, the server verifies whether the random identifier in the operation request exists in the user session. If so, the server determines that the user who initiated the operation request is a legitimate user; if not, the server determines that the user who initiated the operation request is an illegal user.

[0095] Step S307, the server verifies whether the function module name corresponding to the random identifier of the data record matches the request address of the operation request;

[0096] Specifically, the server obtains the access address of the function module name corresponding to the random identifier from the user session; if the access address of the function module name corresponding to the random identifier is the same as the request address of the operation request, it is determined that the function module name corresponding to the random identifier matches the request address of the operation request, and the server determines that the operation request is a legitimate user request; otherwise, the server determines it to be illegal.

[0097] Step S308, the server replaces the original identifier of the data record with the random identifier and executes the operation request;

[0098] Specifically, the server replaces the random identifier with the original identifier and executes the operation request, thereby ensuring that subsequent operations have no impact on the original program.

[0099] Step S309, the server deletes the random identifier of the data record in the user session;

[0100] Specifically, after the server executes the user's operation request and obtains the operation result, it deletes the target random identifier in the user session, that is, only marks each data record with the original identifier, which effectively solves the problem of malicious users attacking by replaying messages.

[0101] Step S310, the server returns the operation request result to the terminal device.

[0102] In this application, a random identifier is used to replace the original identifier in the operation request to mark the data record. By verifying whether the random identifier exists and based on the matching result between the function module name corresponding to the random identifier and the request address of the operation request, it is determined whether the user initiating the operation request is a legitimate user, effectively preventing the attack method of maliciously tampering with the message by illegal users.

[0103] Based on the same technical concept, an embodiment of this application provides a schematic structural diagram of a website access protection device, as Figure 4 shown. The device 400 includes:

[0104] An obtaining module 401, configured to receive an operation request for a target data record sent by the terminal device, where the operation request carries a target random identifier;

[0105] The obtaining module 401 is further configured to, if the target random identifier is included in the user session, obtain the function module name and the original identifier corresponding to the target random identifier from the user session, where the user session is used to store the original identifiers, random identifiers, and function module names of at least one data record with operation permissions;

[0106] A matching module 402, configured to, if the function module name corresponding to the target random identifier matches the request address of the operation request, perform an operation on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result;

[0107] A returning module 403, configured to return the operation result to the terminal device.

[0108] In this application, a random identifier is used to replace the original identifier in the operation request to mark the data record. By verifying whether the random identifier exists and based on the matching result between the function module name corresponding to the random identifier and the request address of the operation request, it is determined whether the user initiating the operation request is a legitimate user, effectively preventing the attack method of maliciously tampering with the message by illegal users.

[0109] Optionally, the returning module 403 is specifically configured to:

[0110] If the target random identifier is not included in the user session, return a reply message rejecting the operation to the terminal device.

[0111] Optionally, the obtaining module 401 is specifically configured to:

[0112] Receive a record query request sent by the terminal device;

[0113] Query at least one data record, as well as the original identifier and function module name of each data record, based on the record query request;

[0114] Generate a random identifier corresponding to the original identifier of each data record, and store the original identifier, random identifier, and function module name of each data record in the user session correspondingly;

[0115] Send the query result to the terminal device, where the query result includes the at least one data record and the corresponding random identifier.

[0116] Optionally, the obtaining module 401 is specifically configured to:

[0117] Adopt a hash table structure to store the original identifier, random identifier, and function module name of each data record in the user session correspondingly.

[0118] Optionally, the matching module 402 is specifically configured to:

[0119] Delete the target random identifier stored in the user session.

[0120] Optionally, the obtaining module 401 is specifically configured to:

[0121] Obtain the access address of the function module name corresponding to the target random identifier from the user session;

[0122] If the access address of the function module name corresponding to the target random identifier is the same as the request address of the operation request, it is determined that the function module name corresponding to the target random identifier matches the request address of the operation request.

[0123] Based on the same technical concept, an embodiment of the present application provides a computer device, as Figure 5 shown, including at least one processor 501 and a memory 502 connected to at least one processor. In the embodiment of the present application, the specific connection medium between the processor 501 and the memory 502 is not limited, Figure 5 taking the connection between the processor 501 and the memory 502 through a bus as an example. The bus can be divided into an address bus, a data bus, a control bus, etc.

[0124] In the embodiment of the present application, the memory 502 stores instructions executable by at least one processor 501. By executing the instructions stored in the memory 502, at least one processor 501 can execute the steps of the above website access protection method.

[0125] Among them, the processor 501 is the control center of the computer device. It can connect various parts of the computer device through various interfaces and circuits. By running or executing the instructions stored in the memory 502 and calling the data stored in the memory 502, it can prevent cross-site access and unauthorized access by illegal users. Optionally, the processor 501 may include one or more processing units. The processor 501 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 501. In some embodiments, the processor 501 and the memory 502 may be implemented on the same chip. In some embodiments, they may also be separately implemented on independent chips.

[0126] The processor 501 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0127] The memory 502, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 502 may include at least one type of storage medium, for example, it may include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, and so on. The memory 502 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 502 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0128] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium storing a computer program executable by a computer device. When the program runs on the computer device, it causes the computer device to execute the steps of the above-mentioned website access protection method.

[0129] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0130] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocksFigure 1 means for the functions specified in one or more blocks.

[0131] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 1 process or more processes and / or blocks Figure 1 or more blocks.

[0132] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 process or more processes and / or blocks Figure 1 or more blocks.

[0133] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these changes and modifications.

Claims

1. A protection method for website access, applied to a server, Characterized in that, It includes: Receiving an operation request for a target data record sent by a terminal device, where the operation request carries a target random identifier; If the target random identifier is included in the user session, obtaining the function module name and original identifier corresponding to the target random identifier from the user session, where the user session is used to save the original identifiers, random identifiers, and function module names of at least one data record with operation permissions; If the function module name corresponding to the target random identifier matches the request address of the operation request, operating on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result; Returning the operation result to the terminal device; Before receiving the operation request for the target data record sent by the terminal device, it further includes: Receiving a record query request sent by the terminal device; Querying based on the record query request to obtain at least one data record and the original identifier and function module name of each data record; Generating a random identifier corresponding to the original identifier of each data record, and correspondingly saving the original identifier, random identifier, and function module name of each data record in the user session; Sending a query result to the terminal device, where the query result includes the at least one data record and the corresponding random identifier.

2. The method according to claim 1, Characterized in that, It further includes: If the target random identifier is not included in the user session, returning a reply message rejecting the operation to the terminal device.

3. The method according to claim 1, Characterized in that, It further includes: If the function module name corresponding to the target random identifier does not match the request address of the operation request, returning a reply message rejecting the operation to the terminal device.

4. The method according to claim 3, Characterized in that, The correspondingly saving the original identifier, random identifier, and function module name of each data record in the user session includes: Using a hash table structure to correspondingly save the original identifier, random identifier, and function module name of each data record in the user session.

5. The method according to claim 1, Characterized in that, After operating on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result, it further includes: Deleting the target random identifier saved in the user session.

6. The method according to any one of claims 1 to 5, Characterized in that, Before operating on the target data record based on the original identifier corresponding to the target random identifier to obtain an operation result if the function module name corresponding to the target random identifier matches the request address of the operation request, it further includes: Obtaining the access address of the function module name corresponding to the target random identifier from the user session; If the access address of the function module name corresponding to the target random identifier is the same as the request address of the operation request, determining that the function module name corresponding to the target random identifier matches the request address of the operation request.

7. A protection device for website access, It is characterized in that It includes An acquisition module, configured to receive an operation request for a target data record sent by a terminal device, where a target random identifier is carried in the operation request The acquisition module is further configured to, if the target random identifier is included in a user session, obtain a function module name and an original identifier corresponding to the target random identifier from the user session, where the user session is used to store original identifiers, random identifiers, and function module names of at least one data record with operation permissions A matching module, configured to, if the function module name corresponding to the target random identifier matches the request address of the operation request, perform an operation on the target data record based on the original identifier corresponding to the target random identifier, and obtain an operation result A return module, configured to return the operation result to the terminal device The acquisition module is further configured to: receive a record query request sent by the terminal device Query and obtain at least one data record and the original identifier and function module name of each data record based on the record query request; generate a random identifier corresponding to the original identifier of each data record, and store the original identifier, random identifier, and function module name of each data record in the user session in a corresponding manner Send a query result to the terminal device, where the query result includes the at least one data record and the corresponding random identifier 8. A computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor It is characterized in that When the processor executes the program, the steps of the method according to any one of claims 1 to 6 are implemented 9. A computer-readable storage medium It is characterized in that It stores a computer program executable by a computer device, and when the program runs on the computer device, the computer device is caused to execute the steps of the method according to any one of claims 1 to 6

Citation Information

Patent Citations

  • System access permission granting method and device, server and storage medium

    CN111698228A

  • Data transmission method, data processing equipment, data transmission device and computer storage medium

    CN111756777A