End-to-end internet application protection method
Through end-to-end Internet application protection methods, combined with OAuth2.0 protocol, multi-factor authentication, RBAC technology, etc., the problems of weak security and insufficient adaptability in the existing technology are solved, and higher security and flexibility are achieved.
Patent Information
- Application Number
- CN202510178585.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-06
AI Technical Summary
The security protection methods of existing Internet applications have problems such as weak security and insufficient system adaptability when facing complex attack methods, especially when token leakage or abuse, static verification methods cannot dynamically adjust verification strength, and traditional RBACs are difficult to adapt to complex security needs.
The end-to-end Internet application protection method is adopted to form a comprehensive security network through basic security architecture design, end-to-end encrypted communication, combined with open authorization OAuth2.0 protocol and multi-factor authentication MFA, role-based access control RBAC technology, application-level security detection, attack detection and response, logging and monitoring, and report generation and response evaluation.
It effectively improves the security of OAuth2.0 protocol and multi-factor authentication, enhances the flexibility and security of authentication, ensures the dynamic and adaptability of permission management, reduces the risk of token abuse, and improves the overall security and adaptability of the system.
Smart Images

Figure CN119945794A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of protection methods, and in particular to an end-to-end Internet application protection method. Background Art
[0002] In the field of security protection of modern Internet applications, as attack methods become increasingly complex, traditional security protection methods can no longer effectively deal with new threats. In order to ensure the security of Internet applications, end-to-end encryption protocols, authentication mechanisms, access control policies, and context-based permission management have become indispensable technical means. However, the single use or independence of these technologies has led to weak security in some key links and insufficient system adaptability.
[0003] In the existing technology, the combination of the open authorization OAuth2.0 protocol and multi-factor authentication MFA has shortcomings: in the existing identity authentication mechanism, once the access token of the OAuth2.0 protocol is authorized, it will continue to be used within a certain validity period. Although this method performs well in most scenarios, if the token is leaked or abused, the attacker can access the system during the validity period of the token, posing a potential security threat. In addition, existing MFA methods usually rely on static, predefined verification methods, such as SMS verification codes or TOTP (time-synchronized one-time passwords), and cannot dynamically adjust the verification strength according to user behavior, resulting in a lack of timely identity re-verification mechanisms in some high-risk scenarios.
[0004] In the existing technology, role-based access control (RBAC) technology has shortcomings: the existing role-based access control (RBAC) method usually relies on static role definition and permission allocation. Once a user is assigned a role, he or she can perform operations within the scope of his or her permissions without real-time monitoring of his or her dynamic behavior. Due to the lack of analysis of user access frequency, resource sensitivity, and operation mode, traditional RBAC is difficult to adapt to complex security requirements. Summary of the invention
[0005] In view of the deficiencies of the prior art, the present invention provides an end-to-end Internet application protection method to solve the problems raised in the above background technology.
[0006] To achieve the above object, the present invention provides the following technical solutions: In a first aspect, an embodiment of the present invention provides an end-to-end Internet application protection method, comprising the following steps: S1. Design of basic security architecture and selection of protection measures to obtain architecture configuration; S2. Perform end-to-end encrypted communication according to the architecture configuration to obtain encrypted data; S3, perform identity authentication and access control based on the encrypted data to obtain authentication information; S4. Perform authority control according to the authentication information to obtain authority control information; S5. Perform application layer security detection according to the permission control information to obtain security detection data; S6. Perform attack detection and response based on security detection data to obtain abnormal data; S7, log and monitor the abnormal data to obtain log data; S8. Generate reports and respond to evaluations based on log data and propose improvement measures.
[0007] To further optimize this technical solution, the basic security architecture design and protection measures in S1 include: Design a basic security architecture that ensures security requirements are covered at the client, server, and network levels, select and configure security protection measures at different levels to form a comprehensive security network.
[0008] To further optimize the technical solution, the end-to-end encrypted communication in S2 includes: All transmitted sensitive data is encrypted through end-to-end encryption protocols to ensure that attackers cannot decrypt the information if the data is intercepted during transmission.
[0009] To further optimize this technical solution, the identity authentication and access control in S3 include: User identity authentication is performed through the combination of open authorization OAuth2.0 protocol and multi-factor authentication MFA to enhance security.
[0010] To further optimize this technical solution, the open authorization OAuth2.0 protocol and multi-factor authentication MFA include: Token validity check: ; in: : Token validity status, 0 means invalid, 1 means valid; : Current timestamp; : Token expiration timestamp; : The generation timestamp of the access token in the OAuth2.0 protocol; : Valid time window; Multi-factor authentication judgment: The system dynamically adjusts the complexity of multi-factor authentication based on the request resource sensitivity and token validity; ; in: : Multi-factor authentication verification results, including SMS verification code and fingerprint verification; : The sensitivity level of the requested resource, 0 is low sensitivity and 1 is high sensitivity; Dynamic tokens and authentication granularity adjustment: ; When users access highly sensitive resources, each request is verified based on the current token and timestamp, and the authentication granularity is dynamically adjusted. Users are required to perform secondary authentication after the token expires or the authentication fails.
[0011] To further optimize this technical solution, the authority control in S4 includes: Through role-based access control (RBAC) technology, user permissions are subdivided into role levels to ensure that users of different roles can only access resources within their permission scope.
[0012] To further optimize this technical solution, the role-based access control includes: Dynamic role adjustment: Calculate user behavior scores based on user behaviors and adjust roles based on the behavior scores; ; in: : User's current role status; , : User's current role permissions, For high permissions, For low permissions; : Comprehensive score of user behavior, calculated based on access frequency and number of visits to sensitive resources; : Behavior score threshold; Contextual permission adjustments: Dynamically adjust role permissions based on user context, including time, location, and device type; ; in: : The permissions actually obtained by the user; : The basic permission set corresponding to the role; : context adjustment factor, Reduce permissions, remain unchanged; Final authority calculation: ; Dynamically calculate the user's final permissions by combining real-time behavior and context information.
[0013] To further optimize the technical solution, the application layer security detection in S5 includes: All inputs are checked in real time through the web application firewall (WAF) technology, and all requests are filtered before they reach the server, malicious requests are identified and blocked, and common vulnerability attacks are prevented.
[0014] To further optimize the technical solution, the attack detection and response in S6 includes: Use intrusion detection system IDS and intrusion prevention system IPS technology, combined with behavioral analysis algorithms to identify potential attack activities. When the IDS system detects abnormal activities, the system automatically responds through IPS to block suspicious requests and traffic.
[0015] To further optimize the technical solution, the log recording and monitoring in S7 include: All abnormal behaviors are recorded through the log management system SIEM, and the logs are analyzed in real time. When abnormal behaviors are detected, the relevant log information is sent to the SIEM platform in real time for the security team to analyze and respond.
[0016] In a second aspect, an embodiment of the present invention provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program instructions are executed by the processor, the steps of an end-to-end Internet application protection method as described in the first aspect of the present invention are implemented.
[0017] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program instructions are executed by a processor, the steps of an end-to-end Internet application protection method as described in the first aspect of the present invention are implemented.
[0018] Compared with the prior art, the present invention provides an end-to-end Internet application protection method, which has the following beneficial effects: This end-to-end Internet application protection method introduces dynamic token verification to ensure that each request is checked based on the current timestamp and verification status, greatly reducing the risk of token abuse and effectively improving the security of the OAuth2.0 protocol and multi-factor authentication.
[0019] By introducing context-based authentication granularity adjustment technology, the system will dynamically change the complexity of authentication based on the user's current access environment (such as location, device type, and network environment). When a user accesses the system in a high-risk environment, the system will automatically require a higher-intensity multi-factor authentication (such as biometric authentication or behavioral analysis authentication), enhancing the security and flexibility of authentication.
[0020] By combining dynamic role adjustment and context-based permission allocation, user roles can be adjusted in real time to ensure that their access rights are consistent with actual needs. In addition, information such as time, geographic location, and device type are combined to ensure that users' access rights are dynamically adjusted in different environments, avoiding the abuse of permissions. RBAC can flexibly adjust permissions based on user behavior and environmental changes, thereby effectively improving the security and adaptability of the system and meeting the complex permissions management needs of modern Internet applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0022] Figure 1 A schematic diagram of a process flow of an end-to-end Internet application protection method proposed by the present invention; Figure 2 A schematic diagram of the end-to-end encryption process of an end-to-end Internet application protection method proposed by the present invention; Figure 3 A schematic diagram of the process flow of identity authentication and access control of an end-to-end Internet application protection method proposed by the present invention; Figure 4 A schematic diagram of a process flow of role-based access control for an end-to-end Internet application protection method proposed by the present invention. DETAILED DESCRIPTION
[0023] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0024] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0025] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or selective embodiment that is mutually exclusive with other embodiments. Example
[0026] Reference Figure 1 to Figure 4 , which is the first embodiment of the present invention, and provides an end-to-end Internet application protection method, comprising the following steps: S1. Design the basic security architecture and select protection measures to obtain the architecture configuration.
[0027] In this embodiment, the basic security architecture design and protection measures selection include: Design a basic security architecture that covers the security requirements of the client, server, and network layers, select and configure different levels of security protection measures to form a comprehensive security network. Measures include network layer protection based on firewalls, transport layer protection based on SSL / TLS encryption, and input validation measures at the application layer. Firewalls, encryption, and input validation technologies form the basic framework of the security protection system.
[0028] S2. Perform end-to-end encrypted communication according to the architecture configuration to obtain encrypted data.
[0029] In this embodiment, end-to-end encrypted communication includes: All transmitted sensitive data is encrypted through an end-to-end encryption protocol to ensure that attackers cannot decrypt the information if the data is intercepted during transmission. The communication between the client and the server uses an asymmetric encryption method. Each message is encrypted by the public key of the recipient, and only the corresponding private key can decrypt it. By encrypting each data packet independently, the potential security risks that may be caused by centralized key management in traditional encryption methods are avoided, ensuring the security of data throughout its life cycle.
[0030] End-to-end encryption protocol: Packet cutting: ; in: : the i-th segment of data; : data packet; Each data segment encryption key is generated and encrypted: ; in: : Encryption operation; : encryption key; : Encrypted data segment; Dynamic key generation: Every time a piece of data is transmitted, the key is updated based on the timestamp and the previous key to generate a new key; ; in: : The key at time point t; : The key of the previous time point; : key generation function; :time; Decryption of encrypted data packets: The receiver uses the same key generation algorithm to decrypt; ; in: : Decrypt the data segment; : Decryption operation; Model usage: Data segment encryption: By encrypting the data packet in segments and using different keys to encrypt each segment, the key leakage is prevented from threatening the security of the entire data packet. For example, if a segment key is cracked, the attacker can only obtain the content of that segment, and the other segments of data are still encrypted, which increases the difficulty of cracking.
[0031] Dynamic key replacement: The key update is based on the timestamp and the dynamic key generated by the previous key. Even if the attacker successfully cracks the key at a certain point in time, the subsequent data cannot be decrypted. This mechanism ensures the long-term security of the encryption process. Through the dynamic key generation function, the key will change every certain period of time, which increases the complexity and security of key management.
[0032] Increased encryption depth: Through the strategy of encryption stacking, that is, introducing random factors (such as timestamps, random numbers, etc.) in each layer of encryption, the security of data packets during transmission is increased. Even if an attacker can crack some of the encryption layers, the difficulty of decryption is still very high due to the different random numbers of each layer of encryption.
[0033] S3. Perform identity authentication and access control based on the encrypted data to obtain authentication information.
[0034] In this embodiment, identity authentication and access control include: Through the combination of open authorization OAuth2.0 protocol and multi-factor authentication MFA, user identity authentication is performed to enhance security. Through OAuth2.0, the system can use authorization tokens instead of passwords for authentication to avoid the risk of password leakage. Through multi-factor authentication, when users access the system, in addition to entering passwords, they also need to authenticate through methods such as SMS verification codes or fingerprint recognition, which further reduces the probability of attacks such as credential hijacking and enhances the security of identity authentication.
[0035] Furthermore, the open authorization OAuth2.0 protocol and multi-factor authentication MFA include: Token validity check: The validity of the access token is first compared by comparing the token timestamp with the current time. If the token has expired or is deemed invalid within the time window, the system will require re-authentication; ; in: : Token validity status, 0 means invalid, 1 means valid; : Current timestamp; : Token expiration timestamp; : The generation timestamp of the access token in the OAuth2.0 protocol; : Valid time window; Multi-factor authentication judgment: The system dynamically adjusts the complexity of multi-factor authentication based on the request resource sensitivity and token validity; ; in: : Multi-factor authentication verification results, including SMS verification code and fingerprint verification; : The sensitivity level of the requested resource, 0 is low sensitivity and 1 is high sensitivity; Dynamic tokens and authentication granularity adjustment: ; When users access highly sensitive resources, each request is verified based on the current token and timestamp, and the authentication granularity is dynamically adjusted. Users are required to perform secondary authentication after the token expires or the authentication fails.
[0036] Model usage: Token validity judgment: By comparing the token timestamp with the current time, dynamically determine whether the token is still valid. For each user request, the system will check in real time whether its token is valid. If the token has expired or is judged to be invalid (for example, the timestamp deviation is too large), the system will force re-authentication.
[0037] Adjustment of multi-factor authentication granularity: Based on the sensitivity of the resource and the validity of the token, the system will decide whether to require multi-factor authentication. For example, for low-sensitivity resources, the system may only require simple username and password verification; while for highly sensitive resources, more complex authentication methods such as SMS verification code, fingerprint recognition, etc. will be required.
[0038] Dynamic token verification and secondary authentication: If the requested resource is very sensitive, the system will require dynamic token verification to ensure the current validity of the token. Even if the token is valid when it is first generated, the system will periodically check the validity of the token based on the timestamp to further enhance the security of the system. If the token expires or the authentication fails, the system will require the user to perform secondary authentication. This dynamic verification mode combines the convenience of OAuth2.0 with the high security of multi-factor authentication to ensure the security of each request.
[0039] S4. Perform authority control according to the authentication information to obtain authority control information.
[0040] In this embodiment, the permission control includes: Through the role-based access control (RBAC) technology, user permissions are subdivided into role levels to ensure that users of different roles can only access resources within their permissions. For example, the permissions of ordinary users and administrators are clearly distinguished in the access control list, and users obtain corresponding permissions through dynamic permission management when logging into the system. Through dynamic permission management combined with fine-grained role division, the system can adjust user permissions in real time to cope with changing security needs, enhance the flexibility of permission control, and cope with complex business scenarios.
[0041] Furthermore, the role-based access control includes: Dynamic role adjustment: Calculate user behavior scores based on user behaviors and adjust roles based on the behavior scores; ; in: : User's current role status; , : User's current role permissions, For high permissions, For low permissions; : Comprehensive score of user behavior, calculated based on access frequency and number of visits to sensitive resources; : Behavior score threshold; Contextual permission adjustments: Dynamically adjust role permissions based on user context, including time, location, and device type; if the system detects that a user is in a low-security environment (such as logging in from a different location or using a non-company device), the user's permissions will be reduced; ; in: : The permissions actually obtained by the user; : The basic permission set corresponding to the role; : context adjustment factor, Reduce permissions, remain unchanged; Final authority calculation: ; Dynamically calculate the user's final permissions by combining real-time behavior and context information.
[0042] Model usage: Dynamic role adjustment: The user's comprehensive behavior score is obtained through behavioral analysis, and the user's role is dynamically adjusted based on the behavior score. The comprehensive behavior score combines the type of resources accessed by the user, access frequency and sensitivity to ensure that the user obtains sufficient permissions when actually needed, while avoiding excessive authorization without reason.
[0043] Contextual adjustment: By detecting the user's current context information (such as time, device, network location, etc.), the system can adjust the user's permissions in real time. For example, when a user accesses resources on the company's internal network, the system may allow higher permissions; while when the user is on an external network or using a non-company device, the system will automatically reduce their permissions to enhance security.
[0044] Comprehensive permission calculation: Ultimately, the system combines roles, behaviors, and context information to comprehensively derive the user's final permissions. This approach enables the RBAC system to dynamically adjust the user's permissions based on the user's behavior and environment, thus avoiding the problem of static roles and easy abuse in traditional RBAC.
[0045] S5. Perform application layer security detection according to the permission control information to obtain security detection data.
[0046] In this embodiment, application layer security detection includes: All inputs are checked in real time through the network application firewall (WAF) technology, and all requests are filtered before they reach the server, identifying malicious requests and blocking them to prevent common vulnerability attacks. Ensure the legitimacy of user input and prevent untrusted code from posing a security threat to the server. WAF technology intelligently identifies attack behaviors through rule sets and learning algorithms, greatly improving the security of the application layer.
[0047] S6. Perform attack detection and response based on the security detection data to obtain abnormal data.
[0048] In this embodiment, attack detection and response include: Using intrusion detection system IDS and intrusion prevention system IPS technology, combined with behavioral analysis algorithms to identify potential attack activities, when the IDS system finds abnormal activities, the system automatically responds through IPS to block suspicious requests and traffic. By combining behavioral analysis with signature-based detection, the ability to identify zero-day attacks and unknown threats is improved, avoiding the detection blind spots brought by traditional signature-based detection methods, thereby improving overall security protection capabilities.
[0049] S7. Perform log recording and monitoring according to the abnormal data to obtain log data.
[0050] In this embodiment, logging and monitoring include: All abnormal behaviors are recorded through the log management system SIEM, and the logs are analyzed in real time. After abnormal behaviors are detected, the relevant log information is sent to the SIEM platform in real time for the security team to analyze and respond. Through centralized log management, SIEM can provide support for tracing the source of security incidents and effectively integrate monitoring information from multiple security sources to improve the efficiency of security incident response. Centralized log management ensures that every link of the security incident can be traced in detail according to the timeline.
[0051] S8. Generate reports and respond to evaluations based on log data and propose improvement measures.
[0052] In this embodiment, the system generates detailed security reports based on all collected log data. These reports not only contain all detected security events, but also evaluate the current security status of the system and propose possible improvement measures. The reports are generated by a custom report generation tool, which can display detailed information such as attack frequency, source, response measures taken, etc., providing comprehensive security data support for the security team, helping them to continuously optimize the security protection system and take timely defensive measures to deal with new threats. Example
[0053] This embodiment also provides a computer device, which is suitable for an end-to-end Internet application protection method, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement an end-to-end Internet application protection method proposed in the above embodiment.
[0054] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, an end-to-end Internet application protection method proposed in the above embodiment is implemented.
[0055] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covered on the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.
[0056] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0057] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0058] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk case (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0059] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit with a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit with a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0060] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. An end-to-end Internet application protection method, characterized in that: The following steps are involved: S1. Design of basic security architecture and selection of protection measures to obtain architecture configuration; S2. Perform end-to-end encrypted communication according to the architecture configuration to obtain encrypted data; S3, perform identity authentication and access control based on the encrypted data to obtain authentication information; S4. Perform authority control according to the authentication information to obtain authority control information; S5. Perform application layer security detection according to the permission control information to obtain security detection data; S6. Perform attack detection and response based on security detection data to obtain abnormal data; S7, log and monitor the abnormal data to obtain log data; S8. Generate reports and respond to evaluations based on log data and propose improvement measures.
2. According to claim 1, an end-to-end Internet application protection method is characterized in that: The basic security architecture design and protection measures selected in S1 include: Design a basic security architecture that ensures security requirements are covered at the client, server, and network levels, select and configure security protection measures at different levels to form a comprehensive security network.
3. According to claim 1, an end-to-end Internet application protection method is characterized in that: The end-to-end encrypted communication in S2 includes: All transmitted sensitive data is encrypted through end-to-end encryption protocols to ensure that attackers cannot decrypt the information if the data is intercepted during transmission.
4. According to claim 1, an end-to-end Internet application protection method is characterized in that: The authentication and access control in S3 include: User authentication is performed through a combination of the open authorization OAuth2.0 protocol and multi-factor authentication MFA to enhance security.
5. According to claim 4, an end-to-end Internet application protection method is characterized in that: The open authorization OAuth2.0 protocol and multi-factor authentication MFA include: Token validity check: ; in: : Token validity status, 0 means invalid, 1 means valid; : Current timestamp; : Token expiration timestamp; : The generation timestamp of the access token in the OAuth2.0 protocol; : Valid time window; Multi-factor authentication judgment: The system dynamically adjusts the complexity of multi-factor authentication based on the request resource sensitivity and token validity; ; in: : Multi-factor authentication verification results, including SMS verification code and fingerprint verification; : The sensitivity level of the requested resource, 0 is low sensitivity and 1 is high sensitivity; Dynamic tokens and authentication granularity adjustment: ; When users access highly sensitive resources, each request is verified based on the current token and timestamp, and the authentication granularity is dynamically adjusted. Users are required to perform secondary authentication after the token expires or the authentication fails.
6. The end-to-end Internet application protection method according to claim 1, characterized in that: The permission control in S4 includes: Through role-based access control (RBAC) technology, user permissions are subdivided into role levels to ensure that users of different roles can only access resources within their permission scope.
7. The end-to-end Internet application protection method according to claim 6 is characterized in that: The role-based access control includes: Dynamic role adjustment: Calculate user behavior scores based on user behaviors and adjust roles based on the behavior scores; ; in: : User's current role status; , : User's current role permissions, For high permissions, For low permissions; : Comprehensive score of user behavior, calculated based on access frequency and number of visits to sensitive resources; : Behavior score threshold; Contextual permission adjustments: Dynamically adjust role permissions based on user context, including time, location, and device type; ; in: : The permissions actually obtained by the user; : The basic permission set corresponding to the role; : context adjustment factor, Reduce permissions, remain unchanged; Final authority calculation: ; Dynamically calculate the user's final permissions by combining real-time behavior and context information.
8. The end-to-end Internet application protection method according to claim 1, characterized in that: The application layer security detection in S5 includes: All inputs are checked in real time through the web application firewall (WAF) technology, and all requests are filtered before they reach the server, malicious requests are identified and blocked, and common vulnerability attacks are prevented.
9. The end-to-end Internet application protection method according to claim 1, characterized in that: The attack detection and response in S6 includes: Use intrusion detection system IDS and intrusion prevention system IPS technology, combined with behavioral analysis algorithms to identify potential attack activities. When the IDS system detects abnormal activities, the system automatically responds through IPS to block suspicious requests and traffic.
10. The end-to-end Internet application protection method according to claim 1, characterized in that: The logging and monitoring in S7 include: All abnormal behaviors are recorded through the log management system SIEM, and the logs are analyzed in real time. When abnormal behaviors are detected, the relevant log information is sent to the SIEM platform in real time for the security team to analyze and respond.