Database identity authentication method, storage medium and electronic equipment

By hashing calculation and maintaining feature association values ​​of the access user, identifying and intercepting illegal authentication requests, the thread resource competition and service interruption caused by frequent authentication attempts by illegal users is solved, and the security and performance improvement of the database is achieved.

CN119939550APending Publication Date: 2025-05-06INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411974241.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, frequent attempts by illegal users to authenticate lead to thread resource competition and service interruption, and there is a lack of effective solutions.

Method used

By obtaining the access feature information of the access user, hash calculations are performed to obtain the hash index value, and the feature correlation value is determined based on the hash index value, including the number of access failures. If the feature correlation value is less than or equal to the threshold, a control instruction is generated to respond to the thread allocation request of the access user, and the authentication thread is distributed in the identity authentication thread pool for legality authentication.

Benefits of technology

It realizes intelligent identification and intercepts illegal authentication requests, reduces the unnecessary consumption of thread pool resources, improves database security, and avoids thread resource competition and service interruption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939550A_ABST
    Figure CN119939550A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, can be applied to the field of financial science and technology, and particularly discloses a database identity authentication method, a storage medium and electronic equipment. The method relates to the technical field of information security, and comprises the following steps: acquiring access feature information of an access user; performing Hash calculation on the access feature information to obtain a Hash index value; determining a feature association value based on the hash index value, the feature association value at least comprising access failure times associated with the access feature information; in response to the fact that the feature association value is smaller than or equal to the threshold value, a first control instruction is generated and used for responding to the thread distribution request of the access user. Through the method and the device, the problems of thread resource scrambling and service interruption caused by frequent authentication attempt of illegal users in related technologies are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology and can be applied to the field of financial technology. Specifically, it relates to a method for database identity authentication, a storage medium, and an electronic device. Background Art

[0002] With the popularity of database software, users can access databases through database software to perform operations such as reading and writing data. Database software can authenticate the permissions of access users to ensure the security of database data. Use threads in the thread pool to process internal and external requests, including identity authentication, business logic processing, background services, etc. During identity authentication and session establishment, users must obtain threads from the thread pool for further authentication. After identity authentication is passed and a session is created, threads must be obtained from the thread pool to execute business logic. When the business logic is executed and the session enters an idle state, the occupied threads are released back to the thread pool to achieve thread reuse. The size of the available thread pool is associated with the available CPU / memory of the computer.

[0003] In the prior art, when a large number of users initiate identity authentication requests at the same time, since the authentication process requires obtaining threads, a large number of threads in the thread pool are occupied. Once the thread pool reaches the upper limit, no new threads can be created. Users who have established sessions cannot obtain available threads and cannot execute business logic. New users cannot obtain threads to complete authentication, resulting in a denial of service attack.

[0004] Currently, no effective solution has been proposed to the above problems. Summary of the invention

[0005] The main purpose of the present application is to provide a database identity authentication method, storage medium, and electronic device to solve the problems of thread resource competition and service interruption caused by frequent authentication attempts by illegal users in the related art.

[0006] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a method for database identity authentication is provided, the method comprising: obtaining access feature information of an accessing user; performing hash calculation on the access feature information to obtain a hash index value; determining a feature association value based on the hash index value, wherein the feature association value includes at least the number of access failures associated with the access feature information; in response to the feature association value being less than or equal to a threshold, generating a first control instruction, the first control instruction being used to respond to a thread allocation request of the accessing user.

[0007] Furthermore, obtaining access characteristic information of the access user includes: obtaining at least one of a client IP address, a client port, and a client MAC address of the access user.

[0008] Furthermore, determining the feature association value based on the hash index value also includes: obtaining a connection feature hash table, the connection feature hash table is used to characterize the mapping relationship between the hash index value and the feature association value; and determining the feature association value based on the hash index value and the connection feature hash table.

[0009] Furthermore, the method also includes: in response to the feature association value being greater than a threshold, generating a second control instruction, the second control instruction being used to update the feature association value in the connection feature hash table.

[0010] Furthermore, after responding to the thread allocation request of the accessing user, the method also includes: distributing an authentication thread from the identity authentication thread pool; authenticating the legitimacy of the accessing user based on the authentication thread; in response to the successful authentication of the legitimacy of the accessing user, generating a third control instruction, the third control instruction being used to return the authentication thread to the identity authentication thread pool, and to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0011] Furthermore, the method also includes: after the business logic corresponding to the working thread is executed, the method also includes: returning the working thread to the working thread pool.

[0012] Furthermore, the method also includes: in response to the access user having created a session with the database, generating a fourth control instruction, the fourth control instruction being used to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0013] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a computer-readable storage medium is provided, the computer-readable storage medium including a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned methods.

[0014] According to another aspect of the present application, an electronic device is provided, comprising: a memory storing an executable program; and a processor for running the program, wherein any one of the above methods is executed when the program is run.

[0015] According to another aspect of the present application, a computer program product is provided, comprising computer instructions, which implement the steps of any one of the above methods when executed by a processor.

[0016] In the embodiment of the present application, a hash calculation is performed on the characteristic information of the accessing user, and a characteristic association value including key information such as the number of failed accesses is maintained to achieve the purpose of intelligently identifying and intercepting illegal authentication requests, thereby achieving the technical effect of reducing unnecessary consumption of thread pool resources and improving the security of the database, and further solving the technical problems of thread resource contention and service interruption caused by frequent authentication attempts by illegal users. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0018] Figure 1 A hardware structure block diagram of a computer terminal for implementing a method for database identity authentication is shown;

[0019] Figure 2 is a flowchart of a method for database identity authentication provided according to an embodiment of the present application;

[0020] Figure 3 is a flowchart of a method for database identity authentication provided according to an embodiment of the present application;

[0021] Figure 4 is a flowchart of a method for database identity authentication provided according to an embodiment of the present application;

[0022] Figure 5 is a structural block diagram of an electronic device according to an embodiment of the present application;

[0023] Figure 6 It is a structural block diagram of a database identity authentication device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] First, some nouns or terms that appear in the description of the embodiments of the present application are subject to the following explanations:

[0027] Denial of Service Attack (Dos): Denial of Service attack is a type of network security attack in which the attacker destroys the availability of the target system by making the target computer or network resources unable to provide services to legitimate users. DoS attacks usually consume the resources of the target system (such as bandwidth, processor time, memory) or overload the services of the target system, resulting in legitimate users being unable to access the system or network services. A common DoS attack method is to use a large number of botnets or forged requests to send requests to the target server that exceed its processing capacity, causing the server to crash or significantly increase its response time.

[0028] Authentication: Authentication is an important part of network security. Its main purpose is to confirm the identity of the user and ensure that only authorized users can access the system or resources. Authentication is usually performed when a user attempts to log in to the system. The authenticity of the user is ensured by comparing the information provided by the user (such as user name, password, biometrics, etc.) with the authentication information stored in the system. This process builds trust between the user and the system and is a key step in protecting data security and personal privacy.

[0029] Thread: A thread is the smallest unit that the operating system can schedule operations on. It is contained in a process and is the actual operating unit in the process. A standard process can have multiple threads, which share resources in the process, but each thread has its own stack and execution state. They can be executed in parallel, allowing the program to handle multiple tasks at the same time. The concept of threads makes multitasking and efficient use of resources possible, especially in multi-core processor systems, where parallel execution of threads can significantly improve the running efficiency of programs.

[0030] Thread Pool: Thread pool is a mechanism for managing threads, which is used to improve the execution efficiency of programs. Without a thread pool, the overhead of creating and destroying threads will be very high, especially when processing a large number of short-time tasks. Frequent thread creation and destruction will seriously affect program performance. The thread pool pre-creates a certain number of threads and stores them in a pool. When a task needs to be executed, a thread can be obtained from the pool to handle the task. When the task is completed, the thread will not be destroyed, but returned to the pool to wait for the next task. This mechanism reduces the overhead of thread creation and destruction, and also facilitates the management and reuse of threads. It is an indispensable part of modern multi-threaded programming.

[0031] Session: In computer science, a session is the duration of an interaction between a specific user and a system, starting from when the user successfully logs into the system until the user logs out or the session times out. During a session, a user can make a series of requests and operations, and the system maintains state information related to the user, such as login status, permission settings, operation history, etc. The session mechanism ensures the consistency and security of user requests, allowing the system to maintain the user's identity and context information between different requests, which is essential for implementing complex application logic and providing personalized services. In a database environment, sessions are often used to track user activities and ensure data consistency and security.

[0032] It should be noted that the collected information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data are in compliance with relevant laws, regulations and standards, necessary confidentiality measures are taken, and public order and good customs are not violated, and corresponding operation entrances are provided for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions to provide users with corresponding operation entrances for users to choose to agree or refuse the results of automated decision-making; if the user chooses to refuse, the expert decision-making process will be entered.

[0033] Example 1

[0034] According to an embodiment of the present application, an embodiment of a method for database authentication is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0035] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal (or mobile device) for implementing a method for database identity authentication is shown. Figure 1As shown, the computer terminal 10 (or mobile device) may include one or more (102a, 102b, ..., 102n are used to illustrate) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.

[0036] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10 (or mobile device). As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0037] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the method of database identity authentication in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, realizing the above-mentioned method of database identity authentication. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0038] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0039] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or mobile device).

[0040] Under the above operating environment, this application provides Figure 2 The database authentication method shown. Figure 2 It is a flowchart of the method for database identity authentication according to Example 1 of the present application.

[0041] Step S101, obtaining access characteristic information of the accessing user;

[0042] Step S102, performing hash calculation on the access feature information to obtain a hash index value;

[0043] Step S103, determining a feature association value based on the hash index value, wherein the feature association value at least includes the number of access failures associated with the access feature information;

[0044] Step S104 , in response to the feature association value being less than or equal to the threshold, generating a first control instruction, the first control instruction being used to respond to a thread allocation request of the accessing user.

[0045] In the embodiment of the present application, a hash calculation is performed on the characteristic information of the accessing user, and a characteristic association value including key information such as the number of failed accesses is maintained to achieve the purpose of intelligently identifying and intercepting illegal authentication requests, thereby achieving the technical effect of reducing unnecessary consumption of thread pool resources and improving the security of the database, and further solving the technical problems of thread resource contention and service interruption caused by frequent authentication attempts by illegal users.

[0046] It should be further explained that performing hash calculation on feature information to obtain a hash index value means that the hash function can convert input (feature information) of any length into an output (hash index value) of a fixed length. The following are some key steps and methods:

[0047] 1. Choose a hash function: It is very important to choose a suitable hash function. An ideal hash function should have the characteristics of uniform distribution, fast calculation, determinism and collision resistance. Common hash functions include MD5, SHA-1, SHA-256, etc.

[0048] 2. Preprocessing feature information: Before applying the hash function, the feature information may need to be preprocessed. This may include removing spaces, converting to lowercase, encoding, etc. to ensure the consistency of the hash.

[0049] 3. Apply hash function: Input the preprocessed feature information into the hash function. The hash function will output a hash value of fixed length.

[0050] 4. Handling hash collisions: Since the output length of a hash function is fixed, different inputs may produce the same output, which is called a hash collision. To handle this problem, open addressing, chain addressing, and other techniques can be used.

[0051] 5. Map to hash table: Map the hash value to a hash table. A hash table is an array where each element corresponds to a hash bucket. The hash value is mapped to the index of the hash table in some way (such as modulus).

[0052] 6. Optimize hash functions: Depending on the application scenario, the hash function may need to be optimized to reduce hash collisions and improve performance. This may include adjusting the parameters of the hash function or using multiple hash functions.

[0053] 7. Security considerations: If hashing is used for security-sensitive applications, such as password storage, a secure hash function needs to be selected and may be combined with a salt to increase security.

[0054] 8. Performance testing: Test the performance of the hash function to ensure that it can maintain good performance under the expected data volume and query load.

[0055] Through these steps, the feature information can be hashed effectively and a hash index value can be obtained for data storage, retrieval and analysis.

[0056] Optionally, in the database authentication method provided in the embodiment of the present application, obtaining access feature information of the accessing user includes: obtaining at least one of the client IP address, client port, and client MAC address of the accessing user.

[0057] To obtain the client IP address of the accessing user, the user's IP address information can be recorded through the network device or server. The IP address is a unique identifier used to identify the location of the device in network communications and can be obtained through network traffic analysis tools or network management systems.

[0058] To obtain the client port of the access user, you can view the port number used by the user in network communication. The port number is used to identify the communication port of different applications or services. The user's port information can be obtained through logging or network monitoring tools.

[0059] To obtain the client MAC address of the accessing user, you can perform packet capture analysis in the LAN or use the MAC address table of the network device to query. The MAC address is the physical address of the network device and can be used to uniquely identify the device, but it is not applicable when communicating across networks. Therefore, obtaining the MAC address is usually limited to the LAN.

[0060] In summary, the access characteristic information of the visiting user can be obtained through network equipment, network monitoring tools or network analysis software. By obtaining the user's IP address, port number or MAC address and other information, the user's access behavior can be monitored and managed. The access characteristic information is used to characterize the unique identifier of the user during this visit. Through these detailed access characteristic information, the identity of the visitor can be more accurately identified, and attacks by simply changing the IP address can be prevented, further enhancing the security protection capabilities of the system.

[0061] Optionally, in the database authentication method provided in an embodiment of the present application, determining the feature association value based on the hash index value also includes: obtaining a connection feature hash table, the connection feature hash table is used to characterize the mapping relationship between the hash index value and the feature association value; determining the feature association value based on the hash index value and the connection feature hash table.

[0062] It should be noted that hash calculation is an algorithm that converts input of any length into output of fixed length, and is usually used for fast search and data integrity verification. In this embodiment, hash calculation is used to create a unique index value to represent the characteristic information set of the accessing user.

[0063] This method of the present embodiment utilizes the efficient search characteristics of the hash table, and can complete the query of the feature association value in a very short time, greatly improving the efficiency of identity authentication, thereby realizing intelligent identification and interception of illegal access, while maintaining the session status of legitimate users, and ensuring the high availability and security of database services. In a financial transaction system, this method can quickly respond to a large number of transaction requests while ensuring the legitimacy of each transaction, thereby improving the overall performance of the system.

[0064] Optionally, in the database authentication method provided in the embodiment of the present application, the method further includes: in response to the feature association value being greater than a threshold, generating a second control instruction, the second control instruction being used to update the feature association value in the connection feature hash table.

[0065] Specifically, when this method is called, it first searches for the corresponding record in the connection feature hash table based on the hash index value of the access feature. If no record is found, it means that this is the first time this access feature is encountered, so a new object is created, the initial number of failures is set to 1, the last access time is set to the current time, and it is added to the hash table.

[0066] like Figure 3 As shown, in a specific embodiment, when the feature association value exceeds the set threshold, the system will automatically identify the potential malicious behavior of the access, and at this time, the record in the connection feature hash table needs to be updated to reflect the latest status. For each illegal or failed authentication request received, the system will search for the corresponding record in the connection feature hash table based on the hash index value of the access feature information, and increase the number of failures. For example, when the threshold is set to 3 times, when the feature association value is 4 times, a second control instruction is generated, and the feature association value is updated to 5 times. At the same time, the time of the last attempted access is updated, which helps with subsequent cleanup work, such as deleting records that have not been attempted to access for a long time, keeping the hash table tidy and efficient.

[0067] This step of the implementation ensures that the system can adjust and optimize security policies in real time, conduct stricter monitoring of frequently failed visitors, and prevent malicious users from consuming system resources by dynamically updating feature association values ​​in the connection feature hash table, thereby ensuring the stability and security of database services.

[0068] It needs to be further explained that if Figure 3 As shown, in order to maintain the efficiency and accuracy of the hash table, the solution of the present invention describes two methods for cleaning records in the table: manual cleaning and scheduled task cleaning, as well as a threshold setting mechanism for cleaning.

[0069] Manual cleanup is usually triggered by database administrators based on system monitoring or security policy needs. When administrators find that the records in the hash table may contain outdated or irrelevant information, or after the system suffers a specific attack, they need to manually check and clean up the records in the table to restore the normal operation of the system. Administrators can selectively delete certain records or clear the entire hash table through specific tools or command line interfaces to exclude incorrect connection characteristics and reduce unnecessary thread resources allocated to invalid or potentially malicious connection attempts.

[0070] In addition to manual cleanup, the system also supports automatic cleanup of records in the connection feature hash table through scheduled tasks. This mechanism operates based on a time interval threshold, and its purpose is to automatically remove client information that has not attempted to connect for a long time. Setting a cleanup interval threshold means that the system will periodically check the records in the hash table. If it is found that the interval between the last connection time and the current time of a record exceeds the preset threshold, then the record will be deemed outdated or no longer active and will be deleted from the hash table. This process can be performed by a scheduled task in the system background to ensure that the hash table is always kept up to date and only recently active connection feature records are retained.

[0071] The cleanup interval threshold is a parameter that determines when a record is considered outdated and cleaned up. Administrators can set reasonable thresholds based on the characteristics of the database service, such as the access frequency of normal users, the active time during business peak hours, and the balance between security and efficiency. For example, if normal users of the database service access the service once an hour on average, the administrator may set the threshold to 2-3 hours to ensure that records that have not been attempted to connect for a long time are cleaned up, while not accidentally deleting user information that may not have been accessed recently but is still active. Reasonable threshold settings are important for maintaining the size of the hash table, reducing storage overhead, improving query speed, and reducing false positives.

[0072] Through the above mechanism, whether it is manual cleaning or scheduled task cleaning, it can ensure that the information in the connection feature hash table remains up-to-date and relevant, thereby effectively improving the response speed and security of the database system when processing identity authentication, while also reducing the consumption of storage resources. This regular cleaning mechanism is particularly important for large database systems, because it can help the system maintain a stable and efficient service level in a highly concurrent and dynamic network environment, while reducing the risk of denial of service attacks.

[0073] Optionally, in the database authentication method provided in an embodiment of the present application, after responding to a thread allocation request from an accessing user, the method further includes: distributing an authentication thread from an authentication thread pool; authenticating the legitimacy of the accessing user based on the authentication thread; in response to successful authentication of the legitimacy of the accessing user, generating a third control instruction, the third control instruction being used to return the authentication thread to the authentication thread pool, and to obtain a working thread from a working thread pool to execute the business logic corresponding to the working thread.

[0074] like Figure 4 As shown in Figure 1, when the thread allocation request of the access user is responded, the system first allocates a thread from the pre-set identity authentication thread pool, which will be used exclusively for user legitimacy authentication. This separation mechanism ensures that the authentication operation does not over-consume the worker thread resources used to execute database business logic.

[0075] The assigned authentication thread executes the authentication process, including but not limited to comparing with the user information in the database, checking passwords, keys, access permissions, etc., to confirm whether the requesting user has legal access to the database. The authentication process may require access to sensitive information, so using a dedicated thread pool can enhance the security of operations and avoid the risk of sensitive information leakage in a high-concurrency environment.

[0076] Once the user's legitimacy authentication is successful, the system generates a third control instruction, which has two main functions: one is to return the authentication thread to the identity authentication thread pool for subsequent authentication requests; the other is to obtain a work thread from the work thread pool to execute the business logic submitted by the authenticated user. Through this instruction, the system can promptly release the authentication thread resources that are no longer needed, and quickly allocate work threads to users to start processing business logic, thereby improving thread utilization and the overall processing efficiency of the system.

[0077] It should be noted that the execution of the third control instruction, in addition to thread allocation and recycling, may also include logging, user session management, resource tracking, etc., to ensure the transparency and auditability of system operations, and also provide a basis for monitoring and optimization for system administrators.

[0078] In this embodiment, by submitting the authentication task to a specific thread pool and generating corresponding control instructions when the task is completed, the system can effectively isolate the execution of the authentication logic from the business logic, ensuring that the stability and responsiveness of the database service can be maintained even in a high-concurrency environment, while responding to potential denial of service attacks by dynamically updating the connection feature hash table. This dynamic management mechanism of the thread pool not only improves the reuse rate of threads, but also ensures the response speed and processing capacity of the system.

[0079] Optionally, in the database authentication method provided in the embodiment of the present application, after the business logic corresponding to the working thread is executed, the method further includes: returning the working thread to the working thread pool.

[0080] The implementation of this method usually relies on the thread recycling logic inside the thread pool. When the worker thread finishes executing, it can automatically return to the worker thread pool and wait for the next task assignment. This process helps maintain the size of the thread pool stable, ensuring that the system can quickly respond to new business requests, while also avoiding excessive consumption of thread resources and enhancing the stability and performance of database services.

[0081] It should be noted that this embodiment is mainly used in bank apps. The business requests executed by bank apps using worker thread pools are quite extensive, covering most user interactions and service provision in daily bank operations. Specifically, these business requests include but are not limited to the following categories:

[0082] (1) Account query: Users can query their account balance, transaction history, deposit details, loan information, etc. The threads in the worker thread pool are responsible for extracting relevant data from the database and returning it to the user.

[0083] (2) Transfer operations: including transfers between users, payments to merchants, cross-border remittances, etc. The worker thread needs to perform complex transaction processing to ensure that the transfer of funds is accurate and needs to record the details of each transaction in the database.

[0084] (3) Deposits and withdrawals: When a user makes a deposit or withdrawal through the bank app, the worker thread is responsible for processing the corresponding account updates, including the increase or decrease of funds, and updating the account balance.

[0085] (4) Loan application and management: Users submit loan applications through the APP. The work thread is responsible for verifying user information, handling the loan approval process, and updating the user's loan status and balance after approval.

[0086] (5) Credit card services: including credit card application, credit limit inquiry, repayment operation, bill management, etc. The worker thread needs to handle all database operations related to credit cards.

[0087] (6) Investment and financial management: Users can purchase financial products, view investment returns, redeem investments, etc. on the APP. The worker thread needs to handle complex calculations and data updates related to investment.

[0088] (7) Account security: operations such as changing passwords, setting or changing security questions, and performing biometric verification (such as fingerprint or facial recognition). Although these operations are closely related to identity authentication, they are usually performed by threads in the worker thread pool after completing the initial identity authentication.

[0089] (8) Customer Service Requests: Process customer service requests submitted by users, such as reporting suspicious activities, querying service status, resolving account issues, etc. This may involve querying and updating user records in the database.

[0090] (9) Reports and Statistics: Generate various financial reports and statistical data, such as daily transaction volume, account activity, loan disbursement statistics, etc., for the bank's internal management and audit needs.

[0091] (10) System maintenance and monitoring: Worker threads may also be responsible for performing system maintenance tasks, such as data cleanup, index optimization, database health checks, etc., as well as monitoring system performance to detect and handle potential problems in advance.

[0092] In the bank's APP, the worker thread pool is the core of processing user requests, which ensures that all business logic can be executed quickly, safely and concurrently. By properly managing and allocating threads, the bank's APP can provide smooth and timely services in a high-concurrency environment while protecting the user's financial security and personal information. In addition, the worker thread pool mechanism can also help the system effectively respond to denial of service attacks. Even when an attack occurs, it can give priority to ensuring that legitimate users' business requests are processed.

[0093] Optionally, in the database authentication method provided in an embodiment of the present application, the method also includes: in response to an access user having created a session with the database, generating a fourth control instruction, the fourth control instruction being used to obtain a work thread from the work thread pool to execute the business logic corresponding to the work thread.

[0094] Once the user passes the identity authentication, the system allows the user to enter the session state, which means that the user can start to perform database-related operations, such as querying, transferring, updating personal information, etc. In this solution, the generation of the fourth control instruction marks the beginning of the user session and triggers the allocation of the working thread to execute specific business logic.

[0095] In this embodiment, this method ensures that after identity authentication, the user's request can quickly transition to the business processing stage, thereby improving the efficiency and response speed of the database service.

[0096] In a specific embodiment, in a transfer operation scenario of a bank APP, the following are specific steps for applying the working thread pool allocation mechanism in the embodiment of the present invention:

[0097] (1) User initiates a transfer request: A user initiates a transfer request to another account through a bank app.

[0098] (2) Authentication: Behind the scenes, the request is first authenticated to verify the user's identity information (such as username and password) to ensure its authenticity. If authentication is successful, the system creates a session and marks the user as logged in.

[0099] (3) Generation of the fourth control instruction: When a user session is created, the system automatically generates a fourth control instruction, which instructs the connection management component to obtain a working thread from the working thread pool.

[0100] (4) Thread allocation: The connection management component selects an idle working thread from the working thread pool according to the fourth control instruction to execute the user's transfer request.

[0101] (5) Business logic execution: The assigned work thread starts to execute specific business logic, including but not limited to checking user account balances, verifying the legitimacy of transfer operations, updating account balances, recording transfer transactions, etc.

[0102] (6) Transaction Commit: Once the business logic is executed without any errors, the worker thread commits the transaction to ensure that all data changes are correctly reflected in the database.

[0103] (7) Thread recycling: After the business logic is executed, the worker thread will be recycled and returned to the worker thread pool, waiting for the next task assignment.

[0104] Through the above steps, the user's transfer request can be processed quickly and safely. The use of the worker thread pool not only improves the speed of the system in processing business requests, but also ensures the rational allocation and utilization of resources, and improves the stability and security of database services. At the same time, this mechanism also effectively prevents denial of service attacks caused by excessive resource occupation by authentication requests, and ensures that users who have created sessions can perform business operations without being affected.

[0105] Example 2

[0106] The embodiment of the present application also provides a database identity authentication device. It should be noted that the database identity authentication device of the embodiment of the present application can be used to execute the database identity authentication method provided by the embodiment of the present application. The database identity authentication device provided by the embodiment of the present application is introduced below.

[0107] According to an embodiment of the present application, a device for implementing the above-mentioned database identity authentication device is also provided, such as Figure 6 As shown, the device comprises:

[0108] An acquisition module 200 is used to acquire access characteristic information of a visiting user;

[0109] The calculation module 202 performs hash calculation on the access feature information to obtain a hash index value;

[0110] A determination module 204 determines a feature association value based on the hash index value, wherein the feature association value at least includes a number of access failures associated with the access feature information;

[0111] The generating module 206 generates a first control instruction in response to the feature association value being less than or equal to a threshold value, where the first control instruction is used to respond to a thread allocation request of an accessing user.

[0112] The database identity authentication device provided in the embodiment of the present application adopts a method of hashing the characteristic information of the accessing user, and achieves the purpose of intelligently identifying and intercepting illegal authentication requests by maintaining a characteristic association value including key information such as the number of access failures, thereby achieving the technical effect of reducing the unnecessary consumption of thread pool resources and improving the security of the database, and further solving the technical problems of thread resource competition and service interruption caused by frequent authentication attempts by illegal users.

[0113] Optionally, in the database identity authentication device provided in the embodiment of the present application, obtaining access feature information of the accessing user includes: obtaining at least one of a client IP address, a client port, and a client MAC address of the accessing user.

[0114] Optionally, in the database identity authentication device provided in the embodiment of the present application, determining the feature association value based on the hash index value also includes: obtaining a connection feature hash table, the connection feature hash table is used to characterize the mapping relationship between the hash index value and the feature association value; determining the feature association value based on the hash index value and the connection feature hash table.

[0115] Optionally, in the database identity authentication device provided in the embodiment of the present application, in response to the feature association value being greater than a threshold, a second control instruction is generated, and the second control instruction is used to update the feature association value in the connection feature hash table.

[0116] Optionally, in the database identity authentication device provided in the embodiment of the present application, after responding to the thread allocation request of the accessing user, the method also includes: distributing an authentication thread from the identity authentication thread pool; authenticating the legitimacy of the accessing user based on the authentication thread; in response to the successful authentication of the legitimacy of the accessing user, generating a third control instruction, the third control instruction being used to return the authentication thread to the identity authentication thread pool, and to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0117] Optionally, in the database identity authentication device provided in the embodiment of the present application, after the business logic corresponding to the working thread is executed, the method further includes: returning the working thread to the working thread pool.

[0118] Optionally, in the database authentication device provided in the embodiment of the present application, in response to the access user having created a session with the database, a fourth control instruction is generated, and the fourth control instruction is used to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0119] It should be noted that the acquisition module 200 and the calculation module 202 correspond to steps S101 to S102 in Example 1, and the examples and application scenarios implemented by the two modules and the corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned Example 1. It should be noted that the above-mentioned modules or units may be hardware components or software components stored in a memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n), and the above-mentioned modules may also be part of the device and may be run in the computer terminal 10 provided in Example 1.

[0120] Example 3

[0121] An embodiment of the present application may provide an electronic device. Figure 5 is a structural block diagram of an electronic device according to an embodiment of the present application. Figure 5 As shown, the electronic device may include: one or more ( Figure 5 (only one is shown) processor 1002, memory 1004, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.

[0122] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application, and the processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0123] The processor may call the information and application program stored in the memory through the transmission device to perform the following steps:

[0124] Step S101, obtaining access characteristic information of the accessing user;

[0125] Step S102, performing hash calculation on the access feature information to obtain a hash index value;

[0126] Step S103, determining a feature association value based on the hash index value, wherein the feature association value at least includes the number of access failures associated with the access feature information;

[0127] Step S104 , in response to the feature association value being less than or equal to the threshold, generating a first control instruction, the first control instruction being used to respond to a thread allocation request of the accessing user.

[0128] The processor may also call the information and application program stored in the memory through the transmission device to perform the following steps: obtaining at least one of the client IP address, client port, and client MAC address of the accessing user.

[0129] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: obtain a connection feature hash table, which is used to characterize the mapping relationship between hash index values ​​and feature association values; determine the feature association value based on the hash index value and the connection feature hash table.

[0130] The processor may also call the information and application program stored in the memory through the transmission device to perform the following steps: in response to the feature association value being greater than a threshold, generate a second control instruction, the second control instruction being used to update the feature association value in the connection feature hash table.

[0131] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: after responding to the thread allocation request of the accessing user, distribute an authentication thread from the identity authentication thread pool; authenticate the legitimacy of the accessing user based on the authentication thread; in response to the successful authentication of the legitimacy of the accessing user, generate a third control instruction, the third control instruction is used to return the authentication thread to the identity authentication thread pool, and to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0132] The processor may also call the information and application programs stored in the memory through the transmission device to perform the following steps: after the business logic corresponding to the working thread is executed, the working thread is returned to the working thread pool.

[0133] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: in response to the access user having created a session with the database, generate a fourth control instruction, and the fourth control instruction is used to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0134] In the embodiment of the present application, a hash calculation is performed on the characteristic information of the accessing user, and a characteristic association value including key information such as the number of failed accesses is maintained to achieve the purpose of intelligently identifying and intercepting illegal authentication requests, thereby achieving the technical effect of reducing unnecessary consumption of thread pool resources and improving the security of the database, and further solving the technical problems of thread resource contention and service interruption caused by frequent authentication attempts by illegal users.

[0135] It can be understood by those skilled in the art that Figure 5 The structure shown is for illustration only, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, MID), a PAD, or other terminal devices. Figure 5 The structure of the electronic device is not limited. Figure 5 More or fewer components (such as network interfaces, display devices, etc.) shown in, or having Figure 5 Different configurations are shown.

[0136] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0137] Example 4

[0138] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a computer-readable storage medium is provided, the computer-readable storage medium including a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned methods.

[0139] The embodiment of the present application also provides a computer-readable storage medium. It should be noted that the computer-readable storage medium of the embodiment of the present application includes a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located can be used to execute the method for database identity authentication provided by the embodiment of the present application. The following introduces a computer-readable storage medium provided by the embodiment of the present application.

[0140] According to an embodiment of the present application, a computer-readable storage medium for implementing the above-mentioned method for database identity authentication is also provided, and the computer-readable storage medium executes the following steps:

[0141] Step S101, obtaining access characteristic information of the accessing user;

[0142] Step S102, performing hash calculation on the access feature information to obtain a hash index value;

[0143] Step S103, determining a feature association value based on the hash index value, wherein the feature association value at least includes the number of access failures associated with the access feature information;

[0144] Step S104 , in response to the feature association value being less than or equal to the threshold, generating a first control instruction, the first control instruction being used to respond to a thread allocation request of the accessing user.

[0145] By performing hash calculation on the characteristic information of accessing users and maintaining a characteristic association value including key information such as the number of failed accesses, the purpose of intelligently identifying and intercepting illegal authentication requests is achieved, thereby achieving the technical effect of reducing unnecessary consumption of thread pool resources and improving the security of the database, and further solving the technical problems of thread resource contention and service interruption caused by frequent authentication attempts by illegal users.

[0146] Optionally, in the computer-readable storage medium provided in the embodiment of the present application, the following steps are performed: obtaining at least one of the client IP address, client port, and client MAC address of the accessing user.

[0147] Optionally, in the computer-readable storage medium provided in the embodiment of the present application, the following steps are performed: obtaining a connection feature hash table, the connection feature hash table is used to characterize the mapping relationship between hash index values ​​and feature association values; determining the feature association value based on the hash index value and the connection feature hash table.

[0148] Optionally, in the computer-readable storage medium provided in the embodiment of the present application, the following steps are performed: in response to the feature association value being greater than a threshold, a second control instruction is generated, the second control instruction being used to update the feature association value in the connection feature hash table.

[0149] Optionally, in the computer-readable storage medium provided in the embodiment of the present application, the following steps are performed: after responding to the thread allocation request of the accessing user, distributing an authentication thread from the identity authentication thread pool; authenticating the legitimacy of the accessing user based on the authentication thread; in response to the successful authentication of the legitimacy of the accessing user, generating a third control instruction, the third control instruction being used to return the authentication thread to the identity authentication thread pool, and being used to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0150] Optionally, in the computer-readable storage medium provided in the embodiment of the present application, the following steps are performed: after the business logic corresponding to the working thread is executed, the working thread is returned to the working thread pool.

[0151] Optionally, in the computer-readable storage medium provided in the embodiment of the present application, the following steps are performed: in response to the access user having created a session with the database, a fourth control instruction is generated, and the fourth control instruction is used to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

[0152] The embodiment of the present application further provides a computer program product. Optionally, in this embodiment, the computer program product includes computer instructions, and when the computer instructions are executed by a processor, the computer program product implements any of the steps of the above-mentioned database identity authentication method.

[0153] The steps of the method for executing database identity authentication by the computer program product are as follows:

[0154] Step S101, obtaining access characteristic information of the accessing user;

[0155] Step S102, performing hash calculation on the access feature information to obtain a hash index value;

[0156] Step S103, determining a feature association value based on the hash index value, wherein the feature association value at least includes the number of access failures associated with the access feature information;

[0157] Step S104 , in response to the feature association value being less than or equal to the threshold, generating a first control instruction, the first control instruction being used to respond to a thread allocation request of the accessing user.

[0158] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0159] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0160] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0161] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0162] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0163] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.

[0164] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for database identity authentication, characterized in that: include: Obtain access characteristic information of accessing users; Performing hash calculation on the access feature information to obtain a hash index value; Determining a feature association value based on the hash index value, wherein the feature association value includes at least a number of access failures associated with the access feature information; In response to the feature association value being less than or equal to a threshold, a first control instruction is generated, where the first control instruction is used to respond to a thread allocation request of the access user.

2. The method according to claim 1, characterized in that The access characteristic information of the access user includes: Obtain at least one of the client IP address, client port, and client MAC address of the access user.

3. The method according to claim 1, characterized in that Determining a feature association value based on the hash index value also includes: Obtaining a connection feature hash table, where the connection feature hash table is used to represent a mapping relationship between the hash index value and the feature association value; The feature association value is determined based on the hash index value and the connection feature hash table.

4. The method according to claim 3, characterized in that The method further comprises: In response to the feature association value being greater than a threshold, a second control instruction is generated, wherein the second control instruction is used to update the feature association value in the connection feature hash table.

5. The method according to any one of claims 1 to 4, characterized in that After responding to the thread allocation request of the access user, the method further includes: Distribute an authentication thread from the authentication thread pool; Authenticating the legitimacy of the access user based on the authentication thread; In response to the successful legitimacy authentication of the accessing user, a third control instruction is generated, wherein the third control instruction is used to return the authentication thread to the identity authentication thread pool, and to obtain a working thread from the working thread pool to execute the business logic corresponding to the working thread.

6. The method according to claim 5, characterized in that The method further includes: after the business logic corresponding to the working thread is executed, the method further includes: returning the working thread to the working thread pool.

7. The method according to claim 5, characterized in that The method further includes: in response to the access user having created a session with the database, generating a fourth control instruction, wherein the fourth control instruction is used to obtain a work thread from a work thread pool to execute business logic corresponding to the work thread.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.

9. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 7 when running.

10. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Method and apparatus for preventing service function entity of general authentication framework from attack

    CN101039312A

  • A realization method for mobile IP user notification service

    CN101242357A

  • Method and device for processing resource allocation as well as network service system

    CN102143484A

  • AU7395600A