A login link encryption processing system and method based on digital signature

By generating the master key in the server and calculating the rotation cycle, and using the digital signature encryption processing system and method, the problem of insufficient data security during login in the prior art is solved, and high security protection of the login link and accurate judgment of user behavior is achieved.

CN119814469BActive Publication Date: 2025-05-09SHENZHEN GOLDEN VISION TECHNOLOGY DEVELOPMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510219040.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-05-09
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

The prior art is difficult to effectively improve the security of data during login, especially when multiple logins cannot be accurately judged whether it is a malicious login or a user is logged in for unknown reasons, which makes it difficult for the server to adopt corresponding strategies.

Method used

The login link encryption processing system and method based on digital signature is adopted. By generating a master key in the server and calculating the rotation period, the user login information is encrypted by using the master key to generate a temporary key, a digital signature is generated, and a login link is constructed. At the same time, by collecting the number of login requests and time intervals of users, calculating the request threshold and normal login index, and judging the user's login behavior.

Benefits of technology

It enhances the security of login links, reduces the probability of data being stolen and key leaks, improves data integrity and immutability, and ensures users' secure login.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814469B_ABST
    Figure CN119814469B_ABST
Patent Text Reader

Abstract

The invention discloses a login link encryption processing system and method based on digital signature, and relates to the technical field of data encryption. When the login system is started, the invention uses a key generator to generate a master key pair in a server, and calculates the master key rotation period of the server; uses the collected login request times and interval time to calculate the request threshold of the normal login of the user; calculates the normal login index of the user; uses the request threshold to judge the normal login index; uses the digital signature and user information to build a login link and send it to the user; when the user receives the login link, clicks the login link to initiate an HTTP request and returns the information in the login link to the server, and the server verifies the returned login link information; when the verification passes, creates a user session channel; when the verification fails, refuses the user login, discards the existing master key, and executes key rotation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular to a login link encryption processing system and method based on digital signature. Background Art

[0002] Data encryption is an important technology for protecting the confidentiality of information and is widely used in fields such as communications, data storage, and identity authentication. Its history can be traced back to ancient times, but the development of modern encryption technology has mainly evolved in the past few centuries, especially with the advancement of computer science. Digital signature is a cryptography-based technology used to verify the authenticity and integrity of data and the identity of the signer. It is one of the important applications of public key cryptography; before the advent of the computer age, handwritten signatures and seals were often used in the physical world to verify the authenticity of documents. Although these methods are effective, they cannot meet the needs in the digital environment, especially when communications, transactions, and documents are transmitted digitally. The development history of digital signatures and data encryption has evolved from simple encryption methods in ancient times to today's highly complex public key cryptography and modern cryptographic algorithms. Together, the two form the cornerstone of the modern information security system and are widely used in electronic communications, identity authentication, e-commerce, blockchain and other fields. Nowadays, with the development of computer technology, not only has encryption technology made rapid progress, but the means of stealing data have also become more sophisticated. Therefore, improving the security of data during login and judging in advance whether the user has logged in normally can improve the security of user login; when a user logs in multiple times, it is impossible to specifically judge whether it is a malicious login or a user logging in for unknown reasons, and the server will then make corresponding strategies. Summary of the invention

[0003] The purpose of the present invention is to provide a login link encryption processing system and method based on digital signature to solve the problems raised in the prior art.

[0004] To achieve the above object, the present invention provides the following technical solutions:

[0005] A method for encrypting a login link based on a digital signature, the method comprising the following steps:

[0006] S100, when the login system is started, a master key pair is generated in the server using a key generator, the time interval of key leakage in the historical server is collected, and the master key rotation period of the server is calculated according to the time interval of key leakage in the historical server;

[0007] Furthermore, the specific steps for calculating the server's master key rotation period based on the historical server's key leakage time are:

[0008] S101, when the login system starts, a key generator is used to generate a key {Mz1, Mz2, Mz3, ..., Mz n}, Mz1, Mz2, Mz3,..., Mz n represents the 1st, 2nd, 3rd, ..., nth key generated by the key generator in the server, where n is a positive integer; the total number of characters in the character set used by the key generator to generate each key is G, and the number of characters in each key generated is {S1, S2, S3, ..., S n}, S1, S2, S3, ..., S n Indicates the number of characters in the generated 1st, 2nd, 3rd, ..., nth keys;

[0009] S102, screening the keys generated by the key generator in the server, and calculating the complexity of each key respectively, the formula is: com = log2 (G S ), where com represents the complexity of each generated key; the complexity of each key is calculated as

[0010] {com1, com2, com3,...,com n}, com1, com2, com3,..., com n Indicates the complexity of the first, second, third, ..., nth keys generated by calculation; compares the complexity of the n keys calculated, and selects the maximum complexity as the master key M of the server;

[0011] S103: The time interval for collecting key leakage in the history server is

[0012] {Tx1, Tx2, Tx3, ..., Tx m}, Tx1, Tx2, Tx3,..., Tx m Represents the time interval of the 1st, 2nd, 3rd, ...mth key leakage in the historical server, where m is a positive integer; calculates the average value and standard deviation of the key leakage time interval collected in the m servers; calculates the server master key rotation period, the formula is: TL=Txp-Txs, where TL represents the rotation period of the master key in the server, Txp represents the average value of the m collected key leakage time intervals, and Txs represents the standard deviation of the m collected key leakage time intervals; uses the calculated master key rotation period to regularly rotate the master key generated in the server.

[0013] When using the key generator to generate the master key in the server, multiple keys are generated and the complexity of each key is calculated; the key with the highest complexity is selected as the master key; the complexity of the master key in the server is guaranteed to prevent the master key from being cracked due to being too simple; the master key is rotated and updated using a rotation cycle to prevent the theft of data in the server due to the leakage of the master key, thereby enhancing the security of the server.

[0014] S200, collecting the number of login requests and the interval time sent by the user to the server when the user logs into the system normally in the history, and calculating the request threshold of the user's normal login by using the collected number of login requests and the interval time;

[0015] Furthermore, the specific steps for calculating the request threshold for a user to log in normally are as follows:

[0016] S201, collect the number of login requests and interval time sent by the user to the server when the user logs into the system normally in the history; suppose the number of login requests sent by the user to the server each time in the collected history is {Dc1, Dc2, Dc3, ..., Dc k}, Dc1, Dc2, Dc3,..., Dc k represents the number of login requests sent to the server when the user logs in for the 1st, 2nd, 3rd, ..., kth time in the history, where k is a positive integer; let the time interval for sending each login request to the server when the user logs in in the collected history be {Td1, Td2, Td3, ..., Td Dc-1}, Td1, Td2, Td3,..., Td Dc-1 Indicates the 1st, 2nd, 3rd, ..., Dc-1th time interval when the user sends a login request to the server during login in the collected history;

[0017] S202, using the number of login requests and interval time sent by the user to the server in the collected history to calculate the request threshold for the user's normal login, the formula is:

[0018]

[0019] In the formula, Re represents the calculated request threshold for normal user login, Tdp represents the average time interval for sending login requests to the server when the user logs in, Dcp represents the average number of login requests sent to the server when the user logs in, Tds represents the standard deviation of the time interval for sending login requests to the server when the user logs in, and Dcs represents the standard deviation of the number of login requests sent to the server when the user logs in.

[0020] S300. When the user sends a login request to the server, the server receives the user's login request in real time, collects the number of requests and the interval time of the user, calculates the user's normal login index, and uses the request threshold to judge the normal login index.

[0021] Further, the specific steps for using the request threshold to judge the normal login index are as follows:

[0022] S301. When the user sends a login request to the server, the number of login requests sent by the user to the server is detected in real time as Ds, and the time intervals for the user to send Ds login requests to the server are collected as {Ts1, Ts2, Ts3,..., Ts Ds-1}, where Ts1, Ts2, Ts3,..., Ts Ds-1 represent the 1st, 2nd, 3rd,..., Ds - 1th time intervals for the user to send login requests to the server.

[0023] S302. Calculate the user's normal login index using the number of login requests and the time intervals sent by the user to the server in real time. The formula is:

[0024]

[0025] In the formula, In represents the calculated user's normal login index, Ts represents the time interval for the user to send a login request to the server, and Ds represents the number of login requests sent by the user to the server.

[0026] S303. Use the request threshold to judge the calculated user's normal login index. When In ≥ Re, it is judged that the corresponding user has an abnormal login, and an abnormal login warning is issued; when In < Re, it is judged that the user has a normal login.

[0027] Calculate the request threshold for the user's normal login based on the number of user login requests and the time intervals in history, use the request threshold to judge the user's real-time login request, and when the user has an abnormal login, the server improves the security of the login link to ensure the user's secure login.

[0028] S400. When it is judged that the user's login is normal, the server collects the user's login information and request time, and calculates the hash value of the user's login information and request time; uses the master key to generate a temporary key to encrypt the user's login information and hash value to generate a digital signature, and constructs a login link using the digital signature and user information and sends it to the user.

[0029] Further, the specific steps for constructing a login link using the digital signature and user information and sending it to the user are as follows:

[0030] S401. When it is determined that the real-time login of the user is a normal login, the server collects the user login information and the real-time request time, constructs a timestamp using the collected real-time request time, marks the user login information using the timestamp, and uses the marked user login information as login data;

[0031] S402. After obtaining the login data, use a hash function to calculate the hash value Ha of the login data, use the master key generated in S100 as input, input the master key into the key derivation function to generate a temporary key Key_L; use the temporary key to encrypt the login data and the hash value Ha, and obtain a digital signature after encrypting the hash value; combine the encrypted login data and the digital signature to construct a login link; the server sends the constructed login link to the user end.

[0032] S500: When it is determined that the user logs in abnormally, for each login request of the user, the digital signature of each login link is associated to generate a digital signature chain; the login link is constructed using the digital signature chain and sent to the user;

[0033] Furthermore, the specific steps of using the digital signature chain to construct a login link and send it to the user are:

[0034] S501, when it is determined that the user has logged in abnormally, a login link is generated for each login request sent by the user, the first login request is extracted to generate a login link, the digital signature in the first login link is extracted, the digital signature in the first login link is decrypted, and a hash value Ha(1) of the login data in the first login link is obtained;

[0035] S502, when the server constructs a login link for the second login request sent by the user, the server calculates the hash value Hab of the login data in the second login request according to the method described in S402, associates the hash value Ha(1) of the login data in the first login link with the hash value of the login data in the second login request to obtain an associated hash value, the formula is: Ha(2)=Ha(1)+Hab, where Ha(2) represents the associated hash value in the second login request, encrypts the associated hash value using the temporary key, obtains the digital signature of the second login link, and generates a login link in combination with the second encrypted login data;

[0036] S503, process each login request sent by the user in turn, build a login link, and associate the hash value in the digital signature of each login link with the hash value in the digital signature of the previous login link. The formula is:

[0037] Ha(D)=Ha(D-1)+Hab

[0038] In the formula, Ha(D) represents the associated hash value calculated in the D-th login request, Ha(D-1) represents the associated hash value in the previous D-1-th login request, and Hab represents the unassociated hash value calculated for the login data in each login request. The calculated hash value is then encrypted to generate a digital signature chain and build a login link.

[0039] When a user logs in abnormally, a digital signature chain is constructed to generate a login link. When the server verifies the digital signature, it can verify the login link for each login request, which greatly enhances the integrity of the login link and improves data security.

[0040] S600. When the user receives the login link, he clicks the login link to initiate an HTTP request and returns the information in the login link to the server. The server verifies the returned login link information; when the verification is successful, a user session channel is created; when the verification fails, the user login is denied, the existing master key is discarded, and key rotation is performed.

[0041] Furthermore, the specific steps for the server to verify the returned login link information are as follows:

[0042] S601. After the user receives the login link sent by the server, the user clicks the received login link, the user's browser generates an HTTP request and returns the information in the login link to the server. The server receives the information in the login link, decrypts the received login data and digital signature using a temporary key, and discards the generated temporary key after decryption; recalculates the hash value Has of the decrypted login data; when the user logs in normally, compares the recalculated hash value with the hash value Ha obtained after the digital signature is encrypted, and when Has=Ha, Ha is the hash value of the digital signature after decryption; determines that the data has not been tampered with, the login is normal, and builds a user session channel; when Has≠Ha, determines that the data has been tampered with, the server immediately stops communicating with the user, and determines that the master key in the server has been leaked, discards the master key, and performs master key rotation;

[0043] S602. When the user logs in abnormally, after decrypting the data in the received login link, the hash value Has of the decrypted login data is calculated in real time, and the hash value of the previous login link is extracted. When Has+Ha(D-1)=Ha, it is determined that the data has not been tampered with, the login is normal, and the user session channel is established; Ha is the hash value after decryption of the digital signature, and Ha(D-1) represents the hash value in the previous login link; when Has+Ha(D-1)≠Ha, it is determined that the data has been tampered with, the server immediately stops communicating with the user, and determines that the master key in the server has been leaked, the master key is discarded, and the master key rotation is performed.

[0044] A login link encryption processing system based on digital signature, the login link encryption processing system includes a data collection module, a master key rotation module, a request judgment module, a login link module and a verification module;

[0045] The data collection module is used to collect the number of login requests and time intervals when users log into the system in history;

[0046] The master key rotation module is used to generate the master key of the server, calculate the rotation period of the master key, and rotate the master key in the server using the rotation period;

[0047] The request judgment module is used to calculate the request threshold according to the number of user login requests and time interval in history. The server collects the number of user login requests and time interval in real time, calculates the normal login index, and uses the request threshold to judge the normal login index;

[0048] The login link module is used for generating a digital signature and constructing a login link according to user information and timestamp after the server receives the user's login request;

[0049] The verification module is used for the server to verify the digital signature in the login link and build a session channel after the user clicks the login link.

[0050] The request judgment module includes a request threshold calculation unit, a login index calculation unit and a judgment unit;

[0051] The request threshold calculation unit is used to calculate the request threshold according to the number of login requests and time intervals of the user in history;

[0052] The login index calculation unit is used to collect the number of user login requests and time intervals in real time and calculate the user's real-time normal login index;

[0053] The judgment unit is used to judge whether the user login is normal by using the request threshold to the calculated normal login index.

[0054] The login link module includes a classification construction unit, an encryption unit, a digital signature chain unit and a login link construction unit;

[0055] The classification construction unit is used to classify the normal login and abnormal login status of the user after judgment, and construct login links respectively;

[0056] The encryption unit is used to encrypt the login data and the calculated hash value;

[0057] The digital signature chain unit is used to associate the digital signature of each login request to generate a digital signature chain;

[0058] The login link construction unit is used to construct a login link using the encrypted login data and the digital signature.

[0059] Compared with the prior art, the present invention has the following beneficial effects:

[0060] 1. The present invention generates a master key in the server, uses the master key to generate a temporary key for encryption when encrypting data and generating a digital signature, and discards the temporary key after completing the encryption and decryption of the data; using a new temporary key each time greatly enhances the security of the data and reduces the probability of data theft and key leakage.

[0061] 2. The present invention constructs a master key rotation mechanism. When verification fails, the master key is rotated according to the rotation cycle. When the verification fails, the key is rotated immediately. When a master key is leaked, the attacker can only use the key within a very short time window. The validity period of the master key is greatly shortened, reducing the risk of exposure.

[0062] 3. The present invention verifies the login link by building a digital signature chain to ensure the data integrity and non-tamperability in each transmission step, and prevents attackers from forging links to guide users to visit malicious websites. Only login links that are truly generated and signed by the server can be successfully verified. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 This is a module distribution diagram of a login link encryption processing system based on digital signature of the present invention;

[0064] Figure 2 The present invention is a user login process diagram of a login link encryption processing method based on digital signature. DETAILED DESCRIPTION

[0065] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0066] Example: Figure 1-Figure 2 As shown, the present invention provides a technical solution.

[0067] A method for encrypting a login link based on a digital signature, the method comprising the following steps:

[0068] S100, when the login system is started, a master key pair is generated in the server using a key generator, the time interval of key leakage in the historical server is collected, and the master key rotation period of the server is calculated according to the time interval of key leakage in the historical server;

[0069] The specific steps for calculating the server's master key rotation period based on the historical server's key leakage time are:

[0070] S101, when the login system starts, a key generator is used to generate a key {Mz1, Mz2, Mz3, ..., Mz n}, Mz1, Mz2, Mz3,..., Mz n represents the 1st, 2nd, 3rd, ..., nth key generated by the key generator in the server, where n is a positive integer; the total number of characters in the character set used by the key generator to generate each key is G, and the number of characters in each key generated is {S1, S2, S3, ..., S n}, S1, S2, S3, ..., S n Indicates the number of characters in the generated 1st, 2nd, 3rd, ..., nth keys;

[0071] S102, screening the keys generated by the key generator in the server, and calculating the complexity of each key respectively, the formula is: com = log2 (G S ), where com represents the complexity of each generated key; the complexity of each key is calculated as

[0072] {com1, com2, com3,...,com n}, com1, com2, com3,..., com n Indicates the complexity of the first, second, third, ..., nth keys generated by calculation; compares the complexity of the n keys calculated, and selects the maximum complexity as the master key M of the server;

[0073] S103: The time interval for collecting key leakage in the history server is

[0074] {Tx1, Tx2, Tx3, ..., Tx m}, Tx1, Tx2, Tx3,..., Tx mRepresents the time interval of the 1st, 2nd, 3rd, ...mth key leakage in the historical server, where m is a positive integer; calculates the average value and standard deviation of the key leakage time interval collected in the m servers; calculates the server master key rotation period, the formula is: TL=Txp-Txs, where TL represents the rotation period of the master key in the server, Txp represents the average value of the m collected key leakage time intervals, and Txs represents the standard deviation of the m collected key leakage time intervals; uses the calculated master key rotation period to regularly rotate the master key generated in the server.

[0075] When using the key generator to generate the master key in the server, multiple keys are generated and the complexity of each key is calculated; the key with the highest complexity is selected as the master key; the complexity of the master key in the server is guaranteed to prevent the master key from being cracked due to being too simple; the master key is rotated and updated using a rotation cycle to prevent the theft of data in the server due to the leakage of the master key, thereby enhancing the security of the server.

[0076] S200, collecting the number of login requests and the interval time sent by the user to the server when the user logs into the system normally in the history, and calculating the request threshold of the user's normal login by using the collected number of login requests and the interval time;

[0077] The specific steps for calculating the request threshold for normal user login are:

[0078] S201, collect the number of login requests and interval time sent by the user to the server when the user logs into the system normally in the history; suppose the number of login requests sent by the user to the server each time in the collected history is {Dc1, Dc2, Dc3, ..., Dc k}, Dc1, Dc2, Dc3,..., Dc k represents the number of login requests sent to the server when the user logs in for the 1st, 2nd, 3rd, ..., kth time in the history, where k is a positive integer; let the time interval for sending each login request to the server when the user logs in in the collected history be {Td1, Td2, Td3, ..., Td Dc-1}, Td1, Td2, Td3,..., Td Dc-1 Indicates the 1st, 2nd, 3rd, ..., Dc-1th time interval when the user sends a login request to the server during login in the collected history;

[0079] S202, using the number of login requests and interval time sent by the user to the server in the collected history to calculate the request threshold for the user's normal login, the formula is:

[0080]

[0081] In the formula, Re represents the calculated request threshold for normal user login, Tdp represents the average value of the time intervals between the user's login requests sent to the server during collection, Dcp represents the average value of the number of login requests sent by the user to the server during collection, Tds represents the standard deviation of the time intervals between the user's login requests sent to the server during collection, and Dcs represents the standard deviation of the number of login requests sent by the user to the server during collection.

[0082] S300. When the user sends a login request to the server, the server receives the user's login request in real time, collects the number of requests and the interval time of the user, and calculates the normal login index of the user; uses the request threshold to judge the normal login index.

[0083] The specific steps for using the request threshold to judge the normal login index are as follows:

[0084] S301. When the user sends a login request to the server, it is detected in real time that the number of login requests sent by the user to the server is Ds, and the time intervals for the user to send Ds login requests to the server are collected as {Ts1, Ts2, Ts3,..., Ts Ds-1}, Ts1, Ts2, Ts3,..., Ts Ds-1 represent the 1st, 2nd, 3rd,..., Ds - 1st time intervals for the user to send login requests to the server during collection.

[0085] S302. Calculate the normal login index of the user using the number of login requests and the time intervals sent by the user to the server in real time. The formula is:

[0086]

[0087] In the formula, In represents the calculated normal login index of the user, Ts represents the time interval of the login request sent by the user to the server, and Ds represents the number of login requests sent by the user to the server.

[0088] S303. Use the request threshold to judge the calculated normal login index of the user. When In ≥ Re, it is judged that the corresponding user has an abnormal login, and an abnormal login warning is issued; when In < Re, it is judged that the user has a normal login.

[0089] Calculate the request threshold for normal user login based on the number of login requests and the time intervals of the user in history, use the request threshold to judge the user's real-time login request. When the user has an abnormal login, the server improves the security of the login link to ensure the user's secure login.

[0090] S400, when it is determined that the user login is normal, the server collects the user login information and request time, and calculates the hash value of the user login information and request time; uses the master key to generate a temporary key to encrypt the user login information and the hash value to generate a digital signature, and uses the digital signature and user information to construct a login link and send it to the user;

[0091] The specific steps to use digital signature and user information to build a login link and send it to the user are:

[0092] S401. When it is determined that the real-time login of the user is a normal login, the server collects the user login information and the real-time request time, constructs a timestamp using the collected real-time request time, marks the user login information using the timestamp, and uses the marked user login information as login data;

[0093] S402. After obtaining the login data, use a hash function to calculate the hash value Ha of the login data, use the master key generated in S100 as input, input the master key into the key derivation function to generate a temporary key Key_L; use the temporary key to encrypt the login data and the hash value Ha, and obtain a digital signature after encrypting the hash value; combine the encrypted login data and the digital signature to construct a login link; the server sends the constructed login link to the user end.

[0094] S500: When it is determined that the user logs in abnormally, for each login request of the user, the digital signature of each login link is associated to generate a digital signature chain; the login link is constructed using the digital signature chain and sent to the user;

[0095] The specific steps to use the digital signature chain to build a login link and send it to the user are:

[0096] S501, when it is determined that the user has logged in abnormally, a login link is generated for each login request sent by the user, the first login request is extracted to generate a login link, the digital signature in the first login link is extracted, the digital signature in the first login link is decrypted, and a hash value Ha(1) of the login data in the first login link is obtained;

[0097] S502, when the server constructs a login link for the second login request sent by the user, the server calculates the hash value Hab of the login data in the second login request according to the method described in S402, associates the hash value Ha(1) of the login data in the first login link with the hash value of the login data in the second login request to obtain an associated hash value, the formula is: Ha(2)=Ha(1)+Hab, where Ha(2) represents the associated hash value in the second login request, encrypts the associated hash value using the temporary key, obtains the digital signature of the second login link, and generates a login link in combination with the second encrypted login data;

[0098] S503, process each login request sent by the user in turn, build a login link, and associate the hash value in the digital signature of each login link with the hash value in the digital signature of the previous login link. The formula is:

[0099] Ha(D)=Ha(D-1)+Hab

[0100] In the formula, Ha(D) represents the associated hash value calculated in the D-th login request, Ha(D-1) represents the associated hash value in the previous D-1-th login request, and Hab represents the unassociated hash value calculated for the login data in each login request. The calculated hash value is then encrypted to generate a digital signature chain and build a login link.

[0101] When a user logs in abnormally, a digital signature chain is constructed to generate a login link. When the server verifies the digital signature, it can verify the login link for each login request, which greatly enhances the integrity of the login link and improves data security.

[0102] S600. When the user receives the login link, he clicks the login link to initiate an HTTP request and returns the information in the login link to the server. The server verifies the returned login link information; when the verification is successful, a user session channel is created; when the verification fails, the user login is denied, the existing master key is discarded, and key rotation is performed.

[0103] The specific steps for the server to verify the returned login link information are as follows:

[0104] S601. After the user receives the login link sent by the server, the user clicks the received login link, the user's browser generates an HTTP request and returns the information in the login link to the server. The server receives the information in the login link, decrypts the received login data and digital signature using a temporary key, and discards the generated temporary key after decryption; recalculates the hash value Has of the decrypted login data; when the user logs in normally, compares the recalculated hash value with the hash value Ha obtained after the digital signature is encrypted, and when Has=Ha, Ha is the hash value of the digital signature after decryption; determines that the data has not been tampered with, the login is normal, and builds a user session channel; when Has≠Ha, determines that the data has been tampered with, the server immediately stops communicating with the user, and determines that the master key in the server has been leaked, discards the master key, and performs master key rotation;

[0105] S602. When the user logs in abnormally, after decrypting the data in the received login link, the hash value Has of the decrypted login data is calculated in real time, and the hash value of the previous login link is extracted. When Has+Ha(D-1)=Ha, it is determined that the data has not been tampered with, the login is normal, and the user session channel is established; Ha is the hash value after decryption of the digital signature, and Ha(D-1) represents the hash value in the previous login link; when Has+Ha(D-1)≠Ha, it is determined that the data has been tampered with, the server immediately stops communicating with the user, and determines that the master key in the server has been leaked, the master key is discarded, and the master key rotation is performed.

[0106] A login link encryption processing system based on digital signature, the login link encryption processing system includes a data collection module, a master key rotation module, a request judgment module, a login link module and a verification module;

[0107] The data collection module is used to collect the number of login requests and time intervals when users log into the system in history;

[0108] The master key rotation module is used to generate the master key of the server, calculate the rotation period of the master key, and rotate the master key in the server using the rotation period;

[0109] The request judgment module is used to calculate the request threshold according to the number of user login requests and time interval in history. The server collects the number of user login requests and time interval in real time, calculates the normal login index, and uses the request threshold to judge the normal login index;

[0110] The login link module is used for generating a digital signature and constructing a login link according to user information and timestamp after the server receives the user's login request;

[0111] The verification module is used for the server to verify the digital signature in the login link and build a session channel after the user clicks the login link.

[0112] The request judgment module includes a request threshold calculation unit, a login index calculation unit and a judgment unit;

[0113] The request threshold calculation unit is used to calculate the request threshold according to the number of login requests and time intervals of the user in history;

[0114] The login index calculation unit is used to collect the number of user login requests and time intervals in real time and calculate the user's real-time normal login index;

[0115] The judgment unit is used to judge whether the user login is normal by using the request threshold to the calculated normal login index.

[0116] The login link module includes a classification construction unit, an encryption unit, a digital signature chain unit and a login link construction unit;

[0117] The classification construction unit is used to classify the normal login and abnormal login status of the user after judgment, and construct login links respectively;

[0118] The encryption unit is used to encrypt the login data and the calculated hash value;

[0119] The digital signature chain unit is used to associate the digital signature of each login request to generate a digital signature chain;

[0120] The login link construction unit is used to construct a login link using the encrypted login data and the digital signature.

[0121] Example 1: Assume there is a piece of data "Hello, world!". Use the common hash algorithm SHA-256 to calculate its hash value; the SHA-256 hash value of this piece of data can be obtained: "315f5bdb76d078c43b8ac0064e4a0164612b1fce77c869345bfc94c75894edd3".

[0122] Assume that A sends a login request to server B, and "Hello, world!" is the login data;

[0123] B uses the master key to generate a temporary key to encrypt "Hello, world!", and encrypts the hash value to obtain a digital signature. The encrypted login data and digital signature are used to construct a login link: "https: / / example.com / login?token=abc123";

[0124] A receives the login link and clicks it. Server B re-accepts the data in the login link, decrypts it using the temporary key, and recalculates the hash value of the decrypted data "Hello, people!"

[0125] “037c7c6218aa1c6de6ede509fe8b3b38369c312927fce30db82766bee1c327f1”; after decrypting the digital signature, the previous hash value is obtained and compared to determine whether the data has been tampered with.

[0126] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.

Claims

1. A login link encryption processing method based on digital signature, characterized in that: The method comprises the following steps: S100, when the login system is started, a master key pair is generated in the server using a key generator, the time interval of key leakage in the historical server is collected, and the master key rotation period of the server is calculated according to the time interval of key leakage in the historical server; S200, collecting the number of login requests and the interval time sent by the user to the server when the user logs into the system normally in the history, and calculating the request threshold of the user's normal login by using the collected number of login requests and the interval time; S300, when the user sends a login request to the server, the server receives the user's login request in real time and collects the number of requests and interval time of the user, calculates the user's normal login index; and uses the request threshold to judge the normal login index; S400, when it is determined that the user login is normal, the server collects the user login information and request time, and calculates the hash value of the user login information and request time; uses the master key to generate a temporary key to encrypt the user login information and the hash value to generate a digital signature, and uses the digital signature and user information to construct a login link and send it to the user; S500: When it is determined that the user logs in abnormally, for each login request of the user, the digital signature of each login link is associated to generate a digital signature chain; the login link is constructed using the digital signature chain and sent to the user; S600. When the user receives the login link, he clicks the login link to initiate an HTTP request and returns the information in the login link to the server. The server verifies the returned login link information; when the verification is successful, a user session channel is created; when the verification fails, the user login is denied, the existing master key is discarded, and key rotation is performed.

2. According to claim 1, a login link encryption processing method based on digital signature is characterized in that: The specific steps of calculating the server's master key rotation period according to the historical server's key leakage time in S100 are: S101, when the login system starts, a key generator is used to generate a key in the server as , represents the 1st, 2nd, 3rd, ..., nth key generated by the key generator in the server, where n is a positive integer; the total number of characters in the character set used by the key generator to generate each key is G, and the number of characters in each key generated is , Indicates the number of characters in the generated 1st, 2nd, 3rd, ..., nth keys; S102, screening the keys generated by the key generator in the server, and calculating the complexity of each key respectively, the formula is: ,In the formula, com represents the complexity of each generated key; The complexity of calculating each key is , Indicates the complexity of the first, second, third, ..., nth keys generated by calculation; compares the complexity of the n keys calculated, and selects the maximum complexity as the master key M of the server; S103: The time interval for collecting key leakage in the history server is , represents the time intervals of the 1st, 2nd, 3rd, ...mth key leakage in the historical server, where m is a positive integer; calculate the mean and standard deviation of the time intervals of key leakage in the m collected servers; Calculate the server master key rotation period using the formula: , where TL represents the rotation period of the master key in the server, Txp represents the average value of the m collected key leakage time intervals, and Txs represents the standard deviation of the m collected key leakage time intervals; the master key generated in the server is rotated regularly using the calculated master key rotation period.

3. According to claim 1, a login link encryption processing method based on digital signature is characterized in that: The specific steps of calculating the request threshold for normal user login in S200 are: S201, collect the number of login requests and interval time sent by the user to the server when the user logs into the system normally in the history; suppose the number of login requests sent by the user to the server each time the user logs in in the history collected is , represents the number of login requests sent to the server when the user logs in for the 1st, 2nd, 3rd, ..., kth time in the history, where k is a positive integer; let the time interval for sending each login request to the server when the user logs in in the collected history be , Indicates the 1st, 2nd, 3rd, ..., Dc-1th time interval when the user sends a login request to the server during login in the collected history; S202, using the number of login requests and interval time sent by the user to the server in the collected history to calculate the request threshold for the user's normal login, the formula is: ; In the formula, Re represents the calculated request threshold for normal user login, Tdp represents the average time interval for sending login requests to the server when the user logs in, Dcp represents the average number of login requests sent to the server when the user logs in, Tds represents the standard deviation of the time interval for sending login requests to the server when the user logs in, and Dcs represents the standard deviation of the number of login requests sent to the server when the user logs in.

4. According to claim 3, a login link encryption processing method based on digital signature is characterized in that: The specific steps of using the request threshold to judge the normal login index in S300 are: S301, when the user sends a login request to the server, the number of login requests sent by the user to the server is detected in real time as Ds, and the time interval for the user to send Ds login requests to the server is collected as , Indicates the 1st, 2nd, 3rd, ..., Ds-1th time intervals at which the collected users send login requests to the server; S302, using the number of login requests and time intervals collected in real time that users send to the server to calculate the user's normal login index, the formula is: ; In the formula, In represents the calculated user normal login index, Ts represents the time interval between login requests sent by the user to the server, and Ds represents the number of login requests sent by the user to the server; S303. Use the request threshold to judge the calculated normal user login index. When In ≥ Re, it is judged that the corresponding user has an abnormal login, and an abnormal login warning is issued. When In < Re, it is judged that the user has a normal login.

5. According to claim 4, a login link encryption processing method based on digital signature is characterized in that: The specific steps of constructing a login link and sending it to the user by using a digital signature in S400 are as follows: S401. When it is judged that the user's real-time login is a normal login, the server collects the user login information and the real-time request time, constructs a time stamp by using the collected real-time request time, marks the user login information by using the time stamp, and takes the marked user login information as login data. S402. After obtaining the login data, calculate the hash value Ha of the login data by using a hash function, use the master key generated in S100 as input, input the master key into a key derivation function to generate a temporary key Key_L; encrypt the login data and the hash value Ha by using the temporary key, and obtain a digital signature after encrypting the hash value; combine the encrypted login data and the digital signature to construct a login link. The server sends the constructed login link to the user terminal.

6. According to claim 4, a login link encryption processing method based on digital signature is characterized in that: The specific steps of constructing a login link and sending it to the user by using a digital signature chain in S500 are as follows: S501. When it is judged that the user has an abnormal login, a login link is generated for each login request sent by the user. Extract the first login request to generate a login link, extract the digital signature in the first login link, decrypt the digital signature in the first login link, and obtain the hash value Ha(1) of the login data in the first login link. S502, when the server constructs a login link for the second login request sent by the user, the server calculates the hash value Hab of the login data in the second login request according to the method described in S402, associates the hash value Ha(1) of the login data in the first login link with the hash value of the login data in the second login request to obtain an associated hash value, the formula is: In the formula, Ha (2) represents the associated hash value in the second login request. The associated hash value is encrypted using the temporary key to obtain the digital signature of the second login link, and the login link is generated by combining the second encrypted login data; S503. Process each login request sent by the user in turn, construct a login link, and set the hash value in the digital signature of each login link to be associated with the hash value in the digital signature of the previous login link. The formula is: ; In the formula, Indicates the associated hash value calculated in the Dth login request. Represents the associated hash value in the previous D-1th login request. Hab represents the unassociated hash value calculated for the login data in each login request. The calculated hash value is then encrypted to generate a digital signature chain and build a login link.

7. A method for encrypting a login link based on a digital signature according to claim 6, characterized in that: The specific steps of the server verifying the returned login link information in S600 are as follows: S601. When the user receives the login link sent by the server, the user clicks on the received login link. The user browser generates an HTTP request and returns the information in the login link to the server. The server receives the information in the login link, decrypts the received login data and the digital signature by using the temporary key, and discards the generated temporary key after decryption. Recalculate the hash value Has of the decrypted login data. When the user logs in normally, the recalculated hash value is compared with the hash value Ha obtained after the digital signature is encrypted. When Ha is the hash value after decryption of the digital signature, it is judged that the data has not been tampered with, the login is normal, and the user session channel is established; when When the server determines that the data has been tampered with, it immediately stops communicating with the user and determines that the master key in the server has been leaked, discards the master key, and performs master key rotation; S602: When the user logs in abnormally, the data in the received login link is decrypted, the hash value Has of the decrypted login data is calculated in real time, and the hash value of the previous login link is extracted. When the data is judged to have not been tampered with, the login is normal, and the user session channel is established; Ha is the hash value after the digital signature is decrypted, Represents the hash value in the previous login link; when When the server determines that the data has been tampered with, it immediately stops communicating with the user, and determines that the master key in the server has been leaked, discards the master key, and performs master key rotation.

8. A login link encryption processing system based on digital signature, characterized in that: The login link encryption processing system includes a data collection module, a master key rotation module, a request judgment module, a login link module, and a verification module. The data collection module is used to collect the number of login requests and the time interval when the user logs in to the system in history. The master key rotation module is used to generate the master key of the server, calculate the rotation period of the master key, and rotate the master key in the server by using the rotation period. The request judgment module is used to calculate the request threshold according to the number of user login requests and the time interval in history. The server collects the number of user login requests and the time interval in real time, calculates the normal login index, and judges the normal login index by using the request threshold. The login link module is used for generating a digital signature and constructing a login link according to user information and timestamp after the server receives the user's login request; The login link module includes a classification construction unit, an encryption unit, a digital signature chain unit and a login link construction unit; The classification construction unit is used to classify the normal login and abnormal login status of the user after judgment, and construct login links respectively; The encryption unit is used to encrypt the login data and the calculated hash value; The digital signature chain unit is used to associate the digital signature of each login request to generate a digital signature chain; The login link construction unit is used to construct a login link using the encrypted login data and the digital signature; The verification module is used for the server to verify the digital signature in the login link and build a session channel after the user clicks the login link.

9. A login link encryption processing system based on digital signature according to claim 8, characterized in that: The request judgment module includes a request threshold calculation unit, a login index calculation unit and a judgment unit; The request threshold calculation unit is used to calculate the request threshold according to the number of login requests and time intervals of the user in history; The login index calculation unit is used to collect the number of user login requests and time intervals in real time and calculate the user's real-time normal login index; The judgment unit is used to judge whether the user login is normal by using the request threshold to the calculated normal login index.

Citation Information

Patent Citations

  • Automatic secret key rotation method and system, computer equipment and storage medium

    CN115085913A

  • Data security management system based on cloud platform

    CN118890192A