HTTP proxy method and device based on dynamic certificate, equipment and medium

By storing self-signed certificate information of multiple website servers in the proxy server and establishing a ciphertext communication channel, the problem that existing proxy servers cannot monitor the access behavior of external website servers is solved, and flexible access behavior monitoring is realized, suitable for multiple access scenarios.

CN119996395AActive Publication Date: 2025-05-13BEIJING TOPSEC NETWORK SECURITY TECH +2

Patent Information

Application Number
CN202510236394.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-13
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

When existing proxy servers such as Nginx monitor the behavior of internal terminals to access external websites, they cannot obtain the private key of the external website server, resulting in the inability to decrypt the access response of the external website server and the inability to monitor the access behavior of the external website server.

Method used

By pre-storing the self-signed certificate information of multiple website servers in the proxy server, responding to the client's connection request, it is determined whether the certificate information of the destination website server matches the stored self-signed certificate information. If it matches, a ciphertext communication channel is established to realize access behavior monitoring between the client and the external website server.

Benefits of technology

It realizes monitoring the access behavior of the destination website server when the private key of the destination website server cannot be obtained. It is suitable for access scenarios of different websites without manually configuring fixed certificate information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996395A_ABST
    Figure CN119996395A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an HTTP proxy method and device based on a dynamic certificate, equipment and a medium. The method is applied to a proxy server in which self-visa certificate information of a plurality of web servers is stored. The method comprises the following steps: in response to a first connection request initiated by a client for a target website server, determining whether certificate information of the target website server is matched with self-visa certificate information of any website server; if yes, establishing a first ciphertext communication channel with the target website server and establishing a second ciphertext communication channel with the client according to the self-visa certificate information of the website server; and forwarding an access request initiated by the client for the target website server to the target website server through the first ciphertext communication channel, and forwarding an access response returned by the target website server to the client through the second ciphertext communication channel. According to the embodiment of the invention, the access behavior of the target website server can be monitored under the scene that the private key of the target website server cannot be obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a dynamic certificate-based HTTP proxy method, device, equipment and medium. Background Art

[0002] Currently, HTTP (Hypertext Transfer Protocol) / HTTPS (Hypertext Transfer Protocol Secure) protocols are widely used to ensure data transmission security. Considering the security issues of enterprise network, enterprises usually choose to deploy proxy servers, such as Nginx (engine x, a high-performance HTTP and reverse proxy web server) to audit and control the access of internal terminals to external websites.

[0003] However, in actual applications, it was found that when proxy servers such as Nginx monitor the behavior of internal terminals accessing external websites, they cannot obtain the private key of the external website server, so they cannot decrypt the access response returned by the external website server, and cannot monitor the access behavior of the external website server. Summary of the invention

[0004] The purpose of the embodiments of the present application is to provide an HTTP proxy method, apparatus, device and medium based on a dynamic certificate, so as to achieve the technical effect of monitoring the access behavior of a destination website server in a scenario where the private key of the destination website server cannot be obtained.

[0005] In a first aspect, an embodiment of the present application provides an HTTP proxy method based on a dynamic certificate, which is applied to a proxy server, wherein the proxy server stores self-signed certificate information of multiple website servers;

[0006] The method comprises:

[0007] In response to a first connection request initiated by a client to a destination website server, determining whether certificate information of the destination website server matches self-signed certificate information of any website server among the multiple website servers;

[0008] If they match, a first encrypted communication channel with the target website server is established according to the self-signed certificate information of the website server, and a second encrypted communication channel with the client is established;

[0009] The access request initiated by the client to the destination website server is forwarded to the destination website server through the first ciphertext communication channel, and the access response returned by the destination website server is forwarded to the client through the second ciphertext communication channel.

[0010] In the above implementation process, by pre-storing the self-signed certificate information of multiple website servers in the proxy server, the proxy server responds to the first connection request initiated by the client for the destination website server, and determines whether the certificate information of the destination website server matches the self-signed certificate information of any website server. If it matches, a first ciphertext communication channel with the destination website server is established according to the self-signed certificate information of the website server, and a second ciphertext communication channel with the client is established. The access request initiated by the client for the destination website server is forwarded to the destination website server through the first ciphertext communication channel, and the access response returned by the destination website server is forwarded to the client through the second ciphertext communication channel. It can flexibly adapt to the customer's access scenarios to different websites, dynamically match the self-signed certificate information of the corresponding website server to establish the first ciphertext communication channel and the second ciphertext communication channel, so as to monitor the access behavior between the client and the external website server based on the first ciphertext communication channel and the second ciphertext communication channel. Not only does it not need to manually configure fixed certificate information, but it can also monitor the access behavior of the destination website server in the scenario where the private key of the destination website server cannot be obtained.

[0011] Furthermore, before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers, the method further includes:

[0012] Generate a second connection request according to the client configuration information in the first connection request; wherein the second connection request includes the client configuration information;

[0013] The second connection request is sent to the destination website server, and a connection response returned by the destination website server is received; wherein the connection response includes the certificate information of the destination website server.

[0014] In the above implementation process, the proxy server generates a second connection request including the client configuration information according to the client configuration information in the first connection request, sends the second connection request to the destination website server, and receives a connection response returned by the destination website server to obtain the certificate information of the destination website server from the connection response. The client configuration information can be forwarded to the destination website server, so that the destination website server returns the certificate information of the destination website server itself according to the client configuration information, thereby ensuring that the certificate information of the destination website server is effectively obtained.

[0015] Further, the proxy server is configured with a self-signed certificate hash table, and the self-signed certificate hash table is used to store hash values ​​corresponding to the self-signed certificate information of the multiple website servers;

[0016] The determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers includes:

[0017] Query whether there is a hash value identical to the target hash value in the self-signed certificate hash table; wherein the target hash value is a hash value corresponding to the certificate information of the target website server;

[0018] If yes, determine whether the certificate information of the destination website server matches the self-signed certificate information of the website server corresponding to the queried hash value;

[0019] Otherwise, it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each website server in the multiple website servers.

[0020] In the above implementation process, by pre-storing the hash values ​​corresponding to the self-signed certificate information of multiple website servers in the self-signed certificate hash table configured by the proxy server, the proxy server uses a hash search method to query whether there is a hash value corresponding to the certificate information of the target website server, that is, a hash value that is the same as the target hash value. According to the query result, it is determined whether the certificate information of the target website server matches the self-signed certificate information of any website server among the multiple website servers. It can quickly and accurately determine whether the certificate information of the target website server matches the self-signed certificate information of any website server among the multiple website servers.

[0021] Further, the access request is encrypted by the client;

[0022] The forwarding the access request initiated by the client to the destination website server through the first ciphertext communication channel includes:

[0023] receiving the access request;

[0024] decrypting the access request according to a second session key corresponding to the second ciphertext communication channel;

[0025] Auditing the decrypted access request according to a predefined request audit rule;

[0026] re-encrypting the audited access request according to the first session key corresponding to the first ciphertext communication channel;

[0027] Send the re-encrypted access request to the destination website server.

[0028] In the above implementation process, the proxy server decrypts the client's encrypted access request according to the second session key corresponding to the second ciphertext communication channel, audits the decrypted access request according to the pre-defined request audit rules, re-encrypts the audited access request according to the first session key corresponding to the first ciphertext communication channel, and sends the re-encrypted access request to the destination website server, thereby ensuring that the access request is transmitted securely and transparently through the second ciphertext communication channel and the first ciphertext communication channel.

[0029] Further, the access response is encrypted by the destination website server, and forwarding the access response returned by the destination website server to the client through the second ciphertext communication channel includes:

[0030] receiving the access response;

[0031] decrypting the access response according to a first session key corresponding to the first ciphertext communication channel;

[0032] Auditing the decrypted access response according to a predefined response audit rule;

[0033] re-encrypting the audited access response according to the second session key corresponding to the second ciphertext communication channel;

[0034] Sending the re-encrypted access response to the client.

[0035] In the above implementation process, the proxy server decrypts the access response encrypted by the destination website server according to the first session key corresponding to the first ciphertext communication channel, audits the decrypted access response according to the predefined response audit rules, re-encrypts the audited access response according to the second session key corresponding to the second ciphertext communication channel, and sends the re-encrypted access response to the client, thereby ensuring that the access response is transmitted securely and transparently through the first ciphertext communication channel and the second ciphertext communication channel.

[0036] Furthermore, before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers, the method further includes:

[0037] It is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server among the multiple website servers; wherein the self-signed certificates of each target website server do not support data encryption and decryption.

[0038] In the above implementation process, the proxy server first matches the certificate information of the destination website server with the stored self-signed certificate information of each target website server that does not support data encryption and decryption. Then, when it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server, the certificate information of the destination website server is matched with the stored self-signed certificate information of each website server respectively. Only under the premise that the certificate of the destination website server supports data encryption and decryption, it can match the self-signed certificate information of all website servers, thereby ensuring the effective establishment of the first ciphertext communication channel and the second ciphertext communication channel.

[0039] Furthermore, the method further comprises:

[0040] When it is determined that the certificate information of the destination website server matches the self-signed certificate information of any target website server among the multiple website servers, or the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers, a first plaintext communication channel with the destination website server is established, and a second plaintext communication channel with the client is established;

[0041] The access request is forwarded to the destination website server through the first plaintext communication channel, and the access response is forwarded to the client through the second plaintext communication channel.

[0042] In the above implementation process, the proxy server directly establishes a first plaintext communication channel with the destination website server and a second plaintext communication channel with the client when it determines that the certificate information of the destination website server matches the self-signed certificate information of any target website server among multiple website servers, or the certificate information of the destination website server does not match the self-signed certificate information of each website server among multiple website servers, so as to monitor the access behavior between the client and the external website server based on the first plaintext communication channel and the second plaintext communication channel, and can monitor the access behavior of the destination website server without the need for data encryption and decryption.

[0043] In a second aspect, an embodiment of the present application provides an HTTP proxy device based on a dynamic certificate, which is applied to a proxy server, wherein the proxy server stores self-signed certificate information of multiple website servers;

[0044] The device comprises:

[0045] A self-signed certificate matching module, configured to respond to a first connection request initiated by a client to a destination website server, and determine whether certificate information of the destination website server matches self-signed certificate information of any website server among the plurality of website servers;

[0046] A communication connection module, used for establishing a first encrypted communication channel with the destination website server and a second encrypted communication channel with the client according to the self-signed certificate information of the website server if a match is found;

[0047] The ciphertext communication module is used to forward the access request initiated by the client to the destination website server to the destination website server through the first ciphertext communication channel, and to forward the access response returned by the destination website server to the client through the second ciphertext communication channel.

[0048] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method as described above is implemented.

[0049] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0051] Figure 1 A flowchart of a dynamic certificate-based HTTP proxy method provided in the first embodiment of the present application;

[0052] Figure 2 A schematic diagram of the structure of a dynamic certificate-based HTTP proxy device provided in the second embodiment of the present application;

[0053] Figure 3 A schematic diagram of the structure of an electronic device provided in the third embodiment of the present application. DETAILED DESCRIPTION

[0054] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0055] It should be noted that in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance. At the same time, the step numbers in the text are only for the convenience of explaining the embodiments of this application and do not serve to limit the order of execution of the steps.

[0056] Currently, HTTP (Hypertext Transfer Protocol) / HTTPS (Hypertext Transfer Protocol Secure) protocols are widely used to ensure data transmission security. Considering the security issues of enterprise network, enterprises usually choose to deploy proxy servers, such as Nginx (engine x, a high-performance HTTP and reverse proxy web server) to audit and control the access of internal terminals to external websites.

[0057] In the related art, the stream module of Nginx is configured as follows:

[0058] stream{

[0059] server{

[0060] Listen 443; / / Nginx listens to port 443 to receive HTTPS requests sent by clients;

[0061] proxy_pass backend_server_ip:443; / / Used to specify the IP address of the external website server that forwards HTTPS requests to and the 443 port that provides HTTPS service;

[0062] proxy_ssl on; / / Enable the proxy SSL (Secure Socket Layer) function;

[0063] proxy_ssl certificate / path / to / nginx / certificate.crt; / / Configure the certificate file path for SSL encryption and decryption;

[0064] proxy_ssl_certificate_key / path / to / nginx / private.key; / / Configure the private key file path for SSL decryption;

[0065] }

[0066] }.

[0067] Nginx HTTP proxy requires manual configuration of fixed certificates and private keys. In actual applications, when monitoring the behavior of internal terminals accessing external websites, Nginx cannot obtain the private key of the external website server, so it cannot decrypt the access response returned by the external website server and cannot monitor the access behavior of the external website server.

[0068] To this end, the present application proposes an HTTP proxy method based on dynamic certificates, which stores the self-signed certificate information of multiple website servers in the proxy server in advance, and the proxy server responds to the first connection request initiated by the client to the destination website server, and determines whether the certificate information of the destination website server matches the self-signed certificate information of any website server. If it matches, a first ciphertext communication channel with the destination website server is established according to the self-signed certificate information of the website server, and a second ciphertext communication channel with the client is established, and the access request initiated by the client to the destination website server is forwarded to the destination website server through the first ciphertext communication channel, and the access response returned by the destination website server is forwarded to the client through the second ciphertext communication channel. It can flexibly adapt to the customer's access scenarios to different websites, dynamically match the self-signed certificate information of the corresponding website server to establish the first ciphertext communication channel and the second ciphertext communication channel, so as to monitor the access behavior between the client and the external website server based on the first ciphertext communication channel and the second ciphertext communication channel. Not only does it not need to manually configure fixed certificate information, but it can also monitor the access behavior of the destination website server in the scenario where the private key of the destination website server cannot be obtained.

[0069] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments.

[0070] The method provided in the embodiment of the present application can be executed by a relevant terminal device, and the following description will be given using a proxy server as an example of the execution subject.

[0071] Please see Figure 1 , Figure 1 A flowchart of a dynamic certificate-based HTTP proxy method provided in the first embodiment of the present application. The first embodiment of the present application provides a dynamic certificate-based HTTP proxy method, which is applied to a proxy server, and the proxy server stores self-signed certificate information of multiple website servers;

[0072] The method comprises steps S101 to S103:

[0073] S101: In response to a first connection request initiated by a client to a destination website server, determine whether certificate information of the destination website server matches self-signed certificate information of any website server among a plurality of website servers.

[0074] As an example, according to the actual application scenario, the self-signed certificate information of multiple website servers is collected in advance, such as the self-signed certificate information of the website servers corresponding to multiple commonly used websites, and the self-signed certificate information of the multiple website servers is stored in the proxy server.

[0075] In actual applications, the self-signed certificate information of each website server includes the self-signed certificate public key of each website server and the domain name of each website server.

[0076] When a client needs to visit any website, namely a destination website, he / she inputs an instruction to connect to the destination website server on the client. At this time, the client generates a first connection request for the destination website server according to the instruction input by the client and sends the first connection request to the proxy server.

[0077] After receiving the first connection request initiated by the client to the destination website server, the proxy server responds to the first connection request, obtains the certificate information of the destination website server, matches the certificate information of the destination website server with the self-signed certificate information of each stored website server, and determines whether the certificate information of the destination website server matches the self-signed certificate information of any website server.

[0078] S102: If they match, a first encrypted communication channel with the destination website server is established according to the self-signed certificate information of the website server, and a second encrypted communication channel with the client is established.

[0079] As an example, when the proxy server determines that the certificate information of the destination website server matches the self-signed certificate information of any website server, it considers that the destination website is the same as the website corresponding to this website server. Since the self-signed certificate information of this website server is pre-stored, the proxy server directly establishes a first ciphertext communication channel with the destination website server and a second ciphertext communication channel with the client based on the self-signed certificate information of this website server.

[0080] In actual applications, the proxy server first negotiates with the destination website server to generate a first session key based on the self-signed certificate information of this website server, completes the establishment of a first ciphertext communication channel with the destination website server, and then sends the self-signed certificate information of this website server to the client, negotiates with the client to generate a second session key, and completes the establishment of a second ciphertext communication channel with the client.

[0081] S103: forwarding the access request initiated by the client to the destination website server through the first ciphertext communication channel, and forwarding the access response returned by the destination website server to the client through the second ciphertext communication channel.

[0082] As an example, after the proxy server establishes the first encrypted communication channel and the second encrypted communication channel, the client can input instructions to access the destination website on the client. At this time, the client generates an access request for the destination website server based on the instructions entered by the client, and sends the access request to the proxy server.

[0083] After receiving the access request initiated by the client to the destination website server, the proxy server forwards the access request to the destination website server through the first encrypted communication channel, so that the destination website server can receive and process the access request and return an access response to the access request to the proxy server.

[0084] After receiving the access response returned by the destination website server, the proxy server forwards the access response to the client through the second ciphertext communication channel, so that the client can determine whether to allow access to the destination website.

[0085] The embodiment of the present application stores the self-signed certificate information of multiple website servers in a proxy server in advance, and the proxy server responds to the first connection request initiated by the client to the destination website server, determines whether the certificate information of the destination website server matches the self-signed certificate information of any website server, and if so, establishes a first ciphertext communication channel with the destination website server and a second ciphertext communication channel with the client based on the self-signed certificate information of the website server, forwards the access request initiated by the client to the destination website server to the destination website server through the first ciphertext communication channel, and forwards the access response returned by the destination website server to the client through the second ciphertext communication channel. This can flexibly adapt to the customer's access scenarios to different websites, dynamically match the self-signed certificate information of the corresponding website server to establish the first ciphertext communication channel and the second ciphertext communication channel, so as to monitor the access behavior between the client and the external website server based on the first ciphertext communication channel and the second ciphertext communication channel. This not only eliminates the need to manually configure fixed certificate information, but also enables monitoring of the access behavior of the destination website server in scenarios where the private key of the destination website server cannot be obtained.

[0086] In an optional embodiment, before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers, it also includes: generating a second connection request based on the client configuration information in the first connection request; wherein the second connection request includes the client configuration information; sending the second connection request to the destination website server, and receiving a connection response returned by the destination website server; wherein the connection response includes the certificate information of the destination website server.

[0087] As an example, after receiving a first connection request initiated by a client to a destination website server, the proxy server responds to the first connection request, extracts the client configuration information from the first connection request, and generates a second connection request including the client configuration information.

[0088] In actual applications, the client configuration information includes: the SSL / TLS (Transport Layer Security) version supported by the client, such as TLS1.0 and TLS1.2; the random number generated by the client; and the encryption suite supported by the client.

[0089] After generating the second connection request, the proxy server sends the second connection request to the destination website server, so that the destination website server can receive and process the second connection request and return a connection response to the proxy server, wherein the connection response includes the certificate information of the destination website server.

[0090] In actual applications, the certificate information of the destination website server includes the certificate public key of the destination website server, the domain name of the destination website server, and information of the certificate authority (CA).

[0091] In actual applications, the connection response also includes the destination website server configuration information. The destination website server configuration information includes: the SSL / TLS version supported by the destination website server; and the random number generated by the destination website server.

[0092] After receiving the connection response, the proxy server extracts the certificate information of the destination website server from the connection response to match the certificate information of the destination website server with the self-signed certificate information of each stored website server, and determines whether the certificate information of the destination website server matches the self-signed certificate information of any website server.

[0093] In the embodiment of the present application, a proxy server generates a second connection request including the client configuration information according to the client configuration information in the first connection request, sends the second connection request to the destination website server, and receives a connection response returned by the destination website server to obtain the certificate information of the destination website server from the connection response. The proxy server can forward the client configuration information to the destination website server, so that the destination website server returns the certificate information of the destination website server itself according to the client configuration information, thereby ensuring that the certificate information of the destination website server is effectively obtained.

[0094] In an optional embodiment, the proxy server is configured with a self-signed certificate hash table, which is used to store hash values ​​corresponding to self-signed certificate information of multiple website servers; the determination of whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers includes: querying the self-signed certificate hash table whether there is a hash value that is the same as the target hash value; wherein the target hash value is the hash value corresponding to the certificate information of the destination website server; if so, determining that the certificate information of the destination website server matches the self-signed certificate information of the website server corresponding to the queried hash value; otherwise, determining that the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers.

[0095] As an example, a self-signed certificate hash table is configured in advance for the proxy server, and hash values ​​corresponding to the collected self-signed certificate information of multiple website servers are stored in the self-signed certificate hash table, thereby storing the self-signed certificate information of multiple website servers in the proxy server.

[0096] Under this premise, after obtaining the certificate information of the destination website server, the proxy server calculates the hash value corresponding to the certificate information of the destination website server, that is, the target hash value, and calls the self-signed certificate hash table to query whether there is a hash value identical to the target hash value in the self-signed certificate hash table. If so, it is determined that the certificate information of the destination website server matches the self-signed certificate information of the website server corresponding to the queried hash value; otherwise, it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers.

[0097] The embodiment of the present application stores the hash values ​​corresponding to the self-signed certificate information of multiple website servers in a self-signed certificate hash table configured by the proxy server in advance, and the proxy server uses a hash search method to query whether there is a hash value corresponding to the certificate information of the target website server, that is, a hash value that is the same as the target hash value in the self-signed certificate hash table, and determines whether the certificate information of the target website server matches the self-signed certificate information of any website server among the multiple website servers based on the query result. This can quickly and accurately determine whether the certificate information of the target website server matches the self-signed certificate information of any website server among the multiple website servers.

[0098] In an optional embodiment, the access request is encrypted by the client; the access request initiated by the client to the destination website server is forwarded to the destination website server through the first ciphertext communication channel, including: receiving the access request; decrypting the access request according to the second session key corresponding to the second ciphertext communication channel; auditing the decrypted access request according to a predefined request audit rule; re-encrypting the audited access request according to the first session key corresponding to the first ciphertext communication channel; and sending the re-encrypted access request to the destination website server.

[0099] As an exemplary example, request audit rules may be predefined according to actual access monitoring requirements.

[0100] In actual applications, request audit rules include audit rules for verifying whether the identity and permissions of the requester are correct, and audit rules for auditing whether the request parameters of the request contain malicious input and sensitive data.

[0101] After monitoring the access request initiated by the client to the destination website server, the proxy server receives the access request. Since the access request is encrypted by the client according to the second session key corresponding to the second ciphertext communication channel, the access request is decrypted according to the second session key to obtain the decrypted access request.

[0102] After receiving the decrypted access request, the proxy server audits the decrypted access request according to a predefined request audit rule to obtain an audited access request.

[0103] After receiving the audited access request, the proxy server re-encrypts the audited access request according to the first session key corresponding to the first ciphertext communication channel, obtains the re-encrypted access request, and sends the re-encrypted access request to the destination website server. After receiving the re-encrypted access request, the destination website server can decrypt and process the re-encrypted access request according to the first session key, and return an access response to the proxy server.

[0104] In the embodiment of the present application, the proxy server decrypts the access request encrypted by the client according to the second session key corresponding to the second ciphertext communication channel, audits the decrypted access request according to a predefined request audit rule, re-encrypts the audited access request according to the first session key corresponding to the first ciphertext communication channel, and sends the re-encrypted access request to the destination website server, thereby ensuring that the access request is transmitted securely and transparently through the second ciphertext communication channel and the first ciphertext communication channel.

[0105] In an optional embodiment, the access response is encrypted by the destination website server, and the access response returned by the destination website server is forwarded to the client through the second ciphertext communication channel, including: receiving the access response; decrypting the access response according to the first session key corresponding to the first ciphertext communication channel; auditing the decrypted access response according to a predefined response audit rule; re-encrypting the audited access response according to the second session key corresponding to the second ciphertext communication channel; and sending the re-encrypted access response to the client.

[0106] As an exemplary example, according to actual access monitoring requirements, response audit rules may be predefined.

[0107] In actual applications, response audit rules include audit rules for verifying whether the identity and permissions of the responder are correct, and audit rules for auditing whether the return parameters of the response contain malicious input and sensitive data.

[0108] After monitoring the access response returned by the destination website server, the proxy server receives the access response. Since the access response is encrypted by the destination website server according to the first session key corresponding to the first ciphertext communication channel, the access response is decrypted according to the first session key to obtain the decrypted access response.

[0109] After obtaining the decrypted access response, the proxy server audits the decrypted access response according to a predefined response audit rule to obtain an audited access response.

[0110] After obtaining the audited access response, the proxy server re-encrypts the audited access response according to the second session key corresponding to the second ciphertext communication channel, obtains the re-encrypted access response, and sends the re-encrypted access response to the client. After the client subsequently receives the re-encrypted access response, it can decrypt the re-encrypted access response according to the second session key to determine whether access to the destination website is allowed.

[0111] In the embodiment of the present application, a proxy server decrypts an access response encrypted by a destination website server according to a first session key corresponding to a first ciphertext communication channel, audits the decrypted access response according to a predefined response audit rule, re-encrypts the audited access response according to a second session key corresponding to a second ciphertext communication channel, and sends the re-encrypted access response to the client, thereby ensuring secure and transparent transmission of the access response through the first ciphertext communication channel and the second ciphertext communication channel.

[0112] In an optional embodiment, before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers, it also includes: determining that the certificate information of the destination website server does not match the self-signed certificate information of each target website server among the multiple website servers; wherein the self-signed certificates of each target website server do not support data encryption and decryption.

[0113] As an example, self-signed certificate information of multiple website servers is collected in advance, and a website server whose self-signed certificate does not support data encryption and decryption among the multiple website servers is marked as a target website server.

[0114] After obtaining the certificate information of the destination website server, the proxy server first matches the certificate information of the destination website server with the self-signed certificate information of each target website server. Then, if it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server, the proxy server matches the certificate information of the destination website server with the self-signed certificate information of each website server to determine whether the certificate information of the destination website server matches the self-signed certificate information of any website server.

[0115] In the embodiment of the present application, the proxy server first matches the certificate information of the destination website server with the stored self-signed certificate information of each target website server that does not support data encryption and decryption, and then, if it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server, matches the certificate information of the destination website server with the stored self-signed certificate information of each website server respectively. Only under the premise that the certificate of the destination website server supports data encryption and decryption, it can match the self-signed certificate information of all website servers, thereby ensuring that the first ciphertext communication channel and the second ciphertext communication channel are effectively established.

[0116] In an optional embodiment, the proxy server is configured with a whitelist hash table, and the whitelist hash table is used to store hash values ​​corresponding to the self-signed certificate information of each target website server; the method further includes steps S104 to S106:

[0117] S104, querying whether there is a hash value identical to the target hash value in the whitelist hash table; wherein the target hash value is a hash value corresponding to the certificate information of the destination website server;

[0118] S105, if yes, determine that the certificate information of the destination website server matches the self-signed certificate information of the destination website server corresponding to the queried hash value;

[0119] S106: Otherwise, it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server.

[0120] As an example, a whitelist hash table is configured in advance for the proxy server, and the hash values ​​corresponding to the self-signed certificate information of each target website server in multiple website servers are stored in the whitelist hash table, so that the self-signed certificate information of each target website server is classified and stored in the proxy server.

[0121] Under this premise, after obtaining the certificate information of the destination website server, the proxy server calculates the hash value corresponding to the certificate information of the destination website server, that is, the target hash value, and calls the whitelist hash table to query whether there is a hash value identical to the target hash value in the whitelist hash table. If so, it is determined that the certificate information of the destination website server matches the self-signed certificate information of the target website server corresponding to the queried hash value; otherwise, it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server, so as to continue to match the certificate information of the destination website server with the self-signed certificate information of each website server respectively, and determine whether the certificate information of the destination website server matches the self-signed certificate information of any website server.

[0122] The embodiment of the present application stores the hash values ​​corresponding to the self-signed certificate information of each target website server in a whitelist hash table configured by the proxy server in advance, and the proxy server uses a hash search method to query whether there is a hash value corresponding to the certificate information of the target website server, that is, a hash value that is the same as the target hash value in the whitelist hash table, and determines whether the certificate information of the target website server matches the self-signed certificate information of any target website server among multiple website servers based on the query result. This can quickly and accurately determine whether the certificate information of the target website server matches the self-signed certificate information of any target website server among multiple website servers.

[0123] In an optional embodiment, the method further includes steps S107 to S108:

[0124] S107, when it is determined that the certificate information of the destination website server matches the self-signed certificate information of any target website server among the multiple website servers, or the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers, establish a first plaintext communication channel with the destination website server, and establish a second plaintext communication channel with the client;

[0125] S108. Forward the access request to the destination website server through the first plaintext communication channel, and forward the access response to the client through the second plaintext communication channel.

[0126] As an example, when the proxy server determines that the certificate information of the destination website server matches the self-signed certificate information of any target website server among multiple website servers, or that the certificate information of the destination website server does not match the self-signed certificate information of each website server among multiple website servers, it believes that the communication data between the client and the destination website server does not need to be encrypted or decrypted. At this time, a first plaintext communication channel with the destination website server is directly established, and a second plaintext communication channel with the client is established.

[0127] After the proxy server establishes the first plaintext communication channel and the second plaintext communication channel, the client can input instructions for accessing the destination website on the client. At this time, the client generates an access request for the destination website server according to the instructions input by the client, and sends the access request to the proxy server.

[0128] After receiving the access request initiated by the client to the destination website server, the proxy server forwards the access request to the destination website server through the first plaintext communication channel, so that the destination website server can receive and process the access request and return an access response to the access request to the proxy server.

[0129] After receiving the access response returned by the destination website server, the proxy server forwards the access response to the client through the second plaintext communication channel, so that the client can determine whether to allow access to the destination website.

[0130] In the embodiment of the present application, the proxy server directly establishes a first plaintext communication channel with the destination website server and a second plaintext communication channel with the client when it is determined that the certificate information of the destination website server matches the self-signed certificate information of any target website server among multiple website servers, or the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers, so as to monitor the access behavior between the client and the external website server based on the first plaintext communication channel and the second plaintext communication channel, and can monitor the access behavior of the destination website server without the need for data encryption and decryption.

[0131] In order to more clearly illustrate an HTTP proxy method based on dynamic certificates provided in the first embodiment of the present application, the specific process of the proxy server applying the method is as follows:

[0132] 1. The system is enabled and initialized to read the self-signed certificate information of multiple website servers, cache the hash value corresponding to the self-signed certificate information of each website server into the self-signed certificate hash table configured by the proxy server, and cache the hash value corresponding to the self-signed certificate information of each target website server in the multiple website servers into the whitelist hash table configured by the proxy server.

[0133] 2. Configure transparent proxy and specify the proxy port.

[0134] 3. The proxy configuration takes effect, the configuration file is changed in the background, and the proxy server reloads the configuration file.

[0135] 4. The proxy server listens to the proxy port. When receiving the first connection request initiated by the client to the destination website server, the proxy server extracts the client configuration information, that is, the client hello information, from the first connection request. This information includes the SSL / TLS version supported by the client, the random number generated by the client (Client Random), and the encryption suite (Cipher Suites) supported by the client. The proxy server generates a second connection request including this information and sends the second connection request to the destination website server.

[0136] 5. The proxy server listens to the proxy port, and when receiving the connection response returned by the destination website server, extracts the destination website server configuration information from the connection response. The destination website server configuration information includes the SSL / TLS version supported by the destination website server, the random number generated by the destination website server, and the certificate information of the destination website server. The certificate information of the destination website server includes the public key of the certificate and other related information, such as the domain name of the destination website server, information of the certificate authority (CA), etc.

[0137] 6. The proxy server calculates the hash value corresponding to the certificate information of the destination website server, that is, the target hash value, such as the hash value corresponding to the domain name of the destination website server, and queries whether there is a hash value identical to the target hash value in the whitelist hash table. If the target hash value is not in the whitelist hash table, continue to query whether there is a hash value identical to the target hash value in the self-signed certificate hash table. If the target hash value is in the self-signed certificate hash table, complete the SSL connection with the destination website server, establish the first ciphertext communication channel, and send the matching website server's certificate information to the client, including the certificate, random number and supported SSL / TLS version, complete the SSL connection with the client, and establish the second ciphertext communication channel.

[0138] 7. The proxy server listens to the proxy port. When receiving an access request initiated by the client to the destination website server, since the access request is encrypted by the client according to the second session key corresponding to the second ciphertext communication channel, the access request is decrypted according to the second session key, and the decrypted access request is audited according to the pre-defined request audit rules. The audited access request is re-encrypted according to the first session key corresponding to the first ciphertext communication channel, and the re-encrypted access request is sent to the destination website server.

[0139] 8. The proxy server listens to the proxy port. After receiving the access response returned by the destination website server, since the access response is encrypted by the destination website server according to the first session key corresponding to the first ciphertext communication channel, the access response is decrypted according to the first session key corresponding to the first ciphertext communication channel, and the decrypted access response is audited according to the pre-defined response audit rules. The audited access response is re-encrypted according to the second session key corresponding to the second ciphertext communication channel, and the re-encrypted access response is sent to the client.

[0140] Please see Figure 2 , Figure 2 A structural diagram of a dynamic certificate-based HTTP proxy device provided for the second embodiment of the present application. The second embodiment of the present application provides a dynamic certificate-based HTTP proxy device, which is applied to a proxy server, and the proxy server stores self-signed certificate information of multiple website servers; the device includes: a self-signed certificate matching module 201, which is used to respond to a first connection request initiated by a client to a destination website server, and determine whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers; a communication connection module 202, which is used to establish a first ciphertext communication channel with the destination website server and a second ciphertext communication channel with the client according to the self-signed certificate information of the website server if they match; a ciphertext communication module 203, which is used to forward the access request initiated by the client to the destination website server to the destination website server through the first ciphertext communication channel, and forward the access response returned by the destination website server to the client through the second ciphertext communication channel.

[0141] In an optional embodiment, the self-signed certificate matching module 201 is also used to generate a second connection request based on the client configuration information in the first connection request before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers; wherein the second connection request includes the client configuration information; send the second connection request to the destination website server, and receive a connection response returned by the destination website server; wherein the connection response includes the certificate information of the destination website server.

[0142] In an optional embodiment, the proxy server is configured with a self-signed certificate hash table, which is used to store hash values ​​corresponding to self-signed certificate information of multiple website servers; the determination of whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers includes: querying the self-signed certificate hash table whether there is a hash value that is the same as the target hash value; wherein the target hash value is the hash value corresponding to the certificate information of the destination website server; if so, determining that the certificate information of the destination website server matches the self-signed certificate information of the website server corresponding to the queried hash value; otherwise, determining that the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers.

[0143] In an optional embodiment, the access request is encrypted by the client; the access request initiated by the client to the destination website server is forwarded to the destination website server through the first ciphertext communication channel, including: receiving the access request; decrypting the access request according to the second session key corresponding to the second ciphertext communication channel; auditing the decrypted access request according to a predefined request audit rule; re-encrypting the audited access request according to the first session key corresponding to the first ciphertext communication channel; and sending the re-encrypted access request to the destination website server.

[0144] In an optional embodiment, the access response is encrypted by the destination website server, and the access response returned by the destination website server is forwarded to the client through the second ciphertext communication channel, including: receiving the access response; decrypting the access response according to the first session key corresponding to the first ciphertext communication channel; auditing the decrypted access response according to a predefined response audit rule; re-encrypting the audited access response according to the second session key corresponding to the second ciphertext communication channel; and sending the re-encrypted access response to the client.

[0145] In an optional embodiment, the self-signed certificate matching module 201 is also used to determine that the certificate information of the destination website server does not match the self-signed certificate information of the target website server among the multiple website servers before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers; wherein the self-signed certificate of the target website server does not support data encryption and decryption.

[0146] In an optional embodiment, the device also includes a plaintext communication module: a communication connection module 202, which is also used to establish a first plaintext communication channel with the destination website server and a second plaintext communication channel with the client when it is determined that the certificate information of the destination website server matches the self-signed certificate information of the target website server, or the certificate information of the destination website server does not match the self-signed certificate information of each website server in a plurality of website servers; a plaintext communication module, which is used to forward an access request to the destination website server through the first plaintext communication channel, and to forward an access response to the client through the second plaintext communication channel.

[0147] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the method described in the first embodiment of the present application, and will not be repeated here.

[0148] Please see Figure 3 , Figure 3 The third embodiment of the present application provides an electronic device 30, comprising a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, the method described in the first embodiment of the present application is implemented and the same beneficial effects can be achieved.

[0149] When the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, the method of any embodiment included in the method described in the first embodiment of the present application can be implemented.

[0150] Processor 301 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 301 can be a microprocessor.

[0151] The memory 302 may be used to store instructions executed by the processor 301 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 301 of the disclosed embodiment may be used to execute instructions in the memory 302 to implement the method described in the first embodiment of the present application. The memory 302 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.

[0152] The fourth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described in the first embodiment of the present application, and can achieve the same beneficial effects as the method.

[0153] The method described in the first embodiment of the present application can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed on a computer, the process or function described in each embodiment of the present application is executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model) or other programmable device.

[0154] The computer program or instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instructions may be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; it may also be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0155] In summary, the embodiments of the present application provide an HTTP proxy method, apparatus, device and medium based on dynamic certificates. The HTTP proxy method based on dynamic certificates is applied to a proxy server, and the proxy server stores self-signed certificate information of multiple website servers; the method includes: responding to a first connection request initiated by a client to a destination website server, determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers; if they match, establishing a first ciphertext communication channel with the destination website server and a second ciphertext communication channel with the client according to the self-signed certificate information of the website server; forwarding an access request initiated by the client to the destination website server to the destination website server through the first ciphertext communication channel, and forwarding an access response returned by the destination website server to the client through the second ciphertext communication channel. The embodiment of the present application stores the self-signed certificate information of multiple website servers in a proxy server in advance, and the proxy server responds to the first connection request initiated by the client to the destination website server, determines whether the certificate information of the destination website server matches the self-signed certificate information of any website server, and if so, establishes a first ciphertext communication channel with the destination website server and a second ciphertext communication channel with the client based on the self-signed certificate information of the website server, forwards the access request initiated by the client to the destination website server to the destination website server through the first ciphertext communication channel, and forwards the access response returned by the destination website server to the client through the second ciphertext communication channel. This can flexibly adapt to the customer's access scenarios to different websites, dynamically match the self-signed certificate information of the corresponding website server to establish the first ciphertext communication channel and the second ciphertext communication channel, so as to monitor the access behavior between the client and the external website server based on the first ciphertext communication channel and the second ciphertext communication channel. This not only eliminates the need to manually configure fixed certificate information, but also enables monitoring of the access behavior of the destination website server in scenarios where the private key of the destination website server cannot be obtained.

[0156] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0157] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0158] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0159] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A hypertext transfer protocol (HTTP) proxy method based on dynamic certificates, characterized in that: Applied to a proxy server, the proxy server stores self-signed certificate information of multiple website servers; The method comprises: In response to a first connection request initiated by a client to a destination website server, determining whether certificate information of the destination website server matches self-signed certificate information of any website server among the multiple website servers; If they match, a first encrypted communication channel with the target website server is established according to the self-signed certificate information of the website server, and a second encrypted communication channel with the client is established; The access request initiated by the client to the destination website server is forwarded to the destination website server through the first ciphertext communication channel, and the access response returned by the destination website server is forwarded to the client through the second ciphertext communication channel.

2. The method according to claim 1, characterized in that Before determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers, the method further includes: Generate a second connection request according to the client configuration information in the first connection request; wherein the second connection request includes the client configuration information; The second connection request is sent to the destination website server, and a connection response returned by the destination website server is received; wherein the connection response includes the certificate information of the destination website server.

3. The method according to claim 1, characterized in that The proxy server is configured with a self-signed certificate hash table, and the self-signed certificate hash table is used to store hash values ​​corresponding to the self-signed certificate information of the multiple website servers; The determining whether the certificate information of the destination website server matches the self-signed certificate information of any website server among the multiple website servers includes: Query whether there is a hash value identical to the target hash value in the self-signed certificate hash table; wherein the target hash value is a hash value corresponding to the certificate information of the target website server; If yes, determine whether the certificate information of the destination website server matches the self-signed certificate information of the website server corresponding to the queried hash value; Otherwise, it is determined that the certificate information of the destination website server does not match the self-signed certificate information of each website server in the multiple website servers.

4. The method according to claim 1, characterized in that: The access request is encrypted by the client; The forwarding the access request initiated by the client to the destination website server through the first ciphertext communication channel includes: receiving the access request; decrypting the access request according to a second session key corresponding to the second ciphertext communication channel; Auditing the decrypted access request according to a predefined request audit rule; re-encrypting the audited access request according to the first session key corresponding to the first ciphertext communication channel; Send the re-encrypted access request to the destination website server.

5. The method according to claim 1, characterized in that The access response is encrypted by the destination website server, and forwarding the access response returned by the destination website server to the client through the second ciphertext communication channel includes: receiving the access response; decrypting the access response according to a first session key corresponding to the first ciphertext communication channel; Auditing the decrypted access response according to a predefined response audit rule; re-encrypting the audited access response according to the second session key corresponding to the second ciphertext communication channel; Sending the re-encrypted access response to the client.

6. The method according to any one of claims 1 to 5, characterized in that: Before determining whether the certificate information of the target website server matches the self-signed certificate information of any website server among the multiple website servers, the method further includes: It is determined that the certificate information of the destination website server does not match the self-signed certificate information of each target website server among the multiple website servers; wherein the self-signed certificates of each target website server do not support data encryption and decryption.

7. The method according to claim 6, characterized in that The method further comprises: When it is determined that the certificate information of the destination website server matches the self-signed certificate information of any target website server among the multiple website servers, or the certificate information of the destination website server does not match the self-signed certificate information of each website server among the multiple website servers, a first plaintext communication channel with the destination website server is established, and a second plaintext communication channel with the client is established; The access request is forwarded to the destination website server through the first plaintext communication channel, and the access response is forwarded to the client through the second plaintext communication channel.

8. An HTTP proxy device based on dynamic certificates, characterized in that: Applied to a proxy server, the proxy server stores self-signed certificate information of multiple website servers; The device comprises: A self-signed certificate matching module, configured to respond to a first connection request initiated by a client to a destination website server, and determine whether certificate information of the destination website server matches self-signed certificate information of any website server among the plurality of website servers; A communication connection module, used for establishing a first encrypted communication channel with the destination website server and a second encrypted communication channel with the client according to the self-signed certificate information of the website server if a match is found; The ciphertext communication module is used to forward the access request initiated by the client to the destination website server to the destination website server through the first ciphertext communication channel, and to forward the access response returned by the destination website server to the client through the second ciphertext communication channel.

9. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Encrypted data transmission method and device, equipment and storage medium

    CN116800499A

  • Encrypted traffic detection method and device, storage medium and terminal

    CN117879932A

  • Systems and methods for policy driven fine grain validation of servers' SSL certificate for clientless sslvpn access

    US20170126664A1

  • Https enabled client tool

    US20190068580A1

Cited By

  • Ticket business safety access system and method based on terminal network self-adaption and communication channel matching

    CN120768690A

  • Ticket security access system and method based on terminal network adaptation and communication channel matching

    CN120768690B