Method and system for verifying request validity

Through the first server detecting and forwarding query requests to the second server, and using the second server to verify the validity of the request, the problem of low efficiency of online environment authentication testing is solved, and efficient overprivileged query testing and data security improvement is achieved.

CN120017321APending Publication Date: 2025-05-16HANGZHOU HUACHENG SOFTWARE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510039790.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the existing technology, online environment certification testing is relatively low efficiency, and vulnerabilities such as overprivileged queries cannot be directly tested. Due to the limitations of security policies, the complexity and difficulty of testing are increased.

Method used

The query request is obtained through the first server and detects whether the request type is the target type according to the request header. If so, the request is sent to the second server, which verifies the validity of the request based on the identity of the target data.

Benefits of technology

It improves the efficiency of online environment certification testing, realizes overprivileged query vulnerability testing without affecting normal business, and ensures the efficiency and security of the testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017321A_ABST
    Figure CN120017321A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method and system for verifying request validity, a first server obtains a query request and detects whether the type of the query request is a target type according to a request header of the query request, and the query request is used for requesting to query target data; under the condition that the query request is of the target type, the first server sends the query request to a second server; and the second server verifies the validity of the target request according to the identity label of the target data. The problem that the online environment authentication test efficiency is low in the prior art is solved, and the effect of improving the online environment authentication test efficiency is further achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of network security vulnerability testing, and in particular, to a method and system for verifying the validity of a request. Background Art

[0002] In the existing authentication server architecture, security testing in the online environment is often restricted by sensitive data, and it is impossible to directly test vulnerabilities such as unauthorized queries. In the actual application environment, in order to protect the security of users' sensitive information, some systems will use authentication servers to process user requests, including encryption and decryption, user identity verification and other processes. If the test is performed directly in the online environment, it may cause the leakage of sensitive information, such as the user's mobile phone number, ID card number, etc. At the same time, since various security policies will be set in the online environment, for example, the request will use Digest authentication or WSSE authentication to ensure the integrity of the request body, this will also increase the complexity and difficulty of security testing, and the work efficiency is relatively low.

[0003] There is currently no effective solution to the above problems. Summary of the invention

[0004] The embodiments of the present invention provide a method and system for verifying the validity of a request, so as to at least solve the problem of low efficiency of online environment authentication testing in the related art.

[0005] According to one embodiment of the present invention, a method for verifying the validity of a request is provided, comprising: a first server obtains a query request, and detects whether the type of the query request is a target type based on a request header of the query request, wherein the query request is used to request query of target data; in a case where the query request is of the target type, the first server sends the query request to a second server; and the second server verifies the validity of the query request of the target type based on an identity identifier of the target data.

[0006] In an exemplary embodiment, detecting whether the type of the query request is a target type based on the request header of the query request includes: the first server detecting whether the request header of the query request carries the validity of a target authentication identifier; when the request header carries the target authentication identifier, the first server determines that the type of the query request is the target type.

[0007] In an exemplary embodiment, before detecting whether the type of the query request is a target type based on the request header of the query request, the method further includes: the first server obtains a configuration request, wherein the configuration request carries attribute information of the target type; and the first server generates the target authentication identifier based on the attribute information.

[0008] In an exemplary embodiment, after the first server generates the target authentication identifier according to the attribute information, the method further includes: the first server establishing an association relationship between the attribute information and the target authentication identifier.

[0009] In an exemplary embodiment, the second server verifies the validity of the query request of the target type based on the identity identifier of the target data, including: the second server determines whether the target account has the authority to query the target data based on the identity identifier, wherein the query request is a request initiated by the target account; when the target account has the authority, the second server determines that the query request is a valid request.

[0010] In an exemplary embodiment, after the second server verifies the validity of the query request of the target type based on the identity identifier of the target data, the method further includes: if the query request is valid, the second server obtains the target data and desensitizes the target data; the second server sends the desensitized target data to the client logged in by the target account.

[0011] According to another embodiment of the present invention, a system for verifying the validity of a request is provided, comprising: a first server, configured to obtain a query request, and detect whether the type of the query request is a target type based on a request header of the query request, wherein the query request is used to request query of target data; in a case where the query request is of the target type, sending the query request to a second server; and a second server, configured to verify the validity of the query request of the target type based on an identity identifier of the target data.

[0012] According to yet another embodiment of the present invention, a computer-readable storage medium is provided, wherein a computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of any of the above methods when executed by a processor.

[0013] According to yet another embodiment of the present invention, there is provided an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0014] According to yet another embodiment of the present invention, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the steps of any of the above methods are implemented.

[0015] Through the present invention, since the first server obtains the query request and detects whether the type of the query request is the target type according to the request header of the query request, wherein the query request is used to request to query the target data; if the query request is the target type, the first server sends the query request to the second server; the second server verifies the validity of the target request according to the identity of the target data. Therefore, the problem of low efficiency of online environment authentication testing in the related art can be solved, and the effect of improving the efficiency of online environment authentication testing can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a hardware structure block diagram of a mobile terminal of a method for verifying the validity of a request according to an embodiment of the present invention;

[0017] Figure 2 is a flowchart of a method for verifying request validity according to an embodiment of the present invention;

[0018] Figure 3 is a flowchart of specific implementation steps according to an embodiment of the present invention;

[0019] Figure 4 4 is a structural block diagram of a system for verifying request validity according to an embodiment of the present invention. DETAILED DESCRIPTION

[0020] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings and in combination with the embodiments.

[0021] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0022] The technologies involved in the embodiments of the present invention are as follows:

[0023] Digest authentication: Digest authentication is an HTTP authentication protocol that provides a secure way to verify the identity between a client and a server. In Digest authentication, the server sends a one-time random number (challenge) to the client, and the client uses the random number and other information (such as username and password) to calculate a hash value and send it to the server for verification.

[0024] Web Services Security UsernameToken (WSSE): WSSE authentication is an authentication method for Web services (SOAP protocol). WSSE authentication uses username and password as credentials and encapsulates them in the WSSE security header of the SOAP message header. After receiving the request, the server will obtain the username and password from the WSSE security header and verify it.

[0025] The method for verifying the validity of a request provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 FIG. 1 is a hardware structure block diagram of a mobile terminal for verifying the validity of a request according to an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1 Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0026] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for verifying the validity of a request in an embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the mobile terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0027] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0028] In this embodiment, a method for verifying the validity of a request running on the above mobile terminal or network architecture is provided. Figure 2 is a flowchart of a method for verifying the validity of a request according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:

[0029] Step S202, the first server obtains a query request, and detects whether the type of the query request is a target type according to a request header of the query request, wherein the query request is used to request query of target data;

[0030] The first server is an authentication server, and the query request is a publishing request (POST request). In this embodiment, the special request is stored in the message header (Header request header), and can be confirmed using Digest authentication or WSSE authentication. If Digest authentication is used, the special request in the message header is set to x-signature-digest:test_security_001. If WSSE authentication is used, the special request in the message header is set to x-signature-wsse:test_security_001. That is, when the request header of the query request contains x-signature-digest:test_security_001 or x-signature-wsse:test_security_001, the type of the request is the target type, which is used to query the target data. The target data is data that can only be queried with corresponding permissions.

[0031] Specifically, detecting whether the type of the query request is the target type according to the request header of the query request includes: the first server detecting whether the request header of the query request carries the validity of the target authentication identifier; when the request header carries the target authentication identifier, the first server determines that the type of the query request is the target type.

[0032] The target authentication identifier can be x-signature-digest:test_security_001 or x-signature-wsse:test_security_001; if Digest authentication is used, the target authentication identifier is x-signature-digest:test_security_001; if WSSE authentication is used, the target authentication identifier is x-signature-wsse:test_security_001. When the request header of the query request carries the target identifier, the request is of the target type and needs to be specially processed by the second server.

[0033] In one embodiment, before detecting whether the type of the query request is a target type according to the request header of the query request, the first server obtains a configuration request, wherein the configuration request carries attribute information of the target type; the first server generates the target authentication identifier according to the attribute information.

[0034] In this embodiment, the special request needs to be configured by the tester in the authentication server (the first server) in advance. The configuration request is used to configure the special request on the authentication server. The attribute information includes access to the Internet Protocol (IP), access time period, access account, etc., to ensure the principle of minimization of permissions. The first server generates a target authentication identifier (x-signature-digest: test_security_001 or x-signature-wsse: test_security_001) based on the attribute information.

[0035] After the first server generates the target authentication identifier according to the attribute information, the first server establishes an association relationship between the attribute information and the target authentication identifier.

[0036] After the first server generates the target authentication identifier according to the attribute information, an association relationship between the attribute information and the authentication identifier must be established for the first server to authenticate the special request.

[0037] Step S204, when the query request is of the target type, the first server sends the query request to the second server;

[0038] The second server is a proxy server, which is used to identify special requests and perform desensitization processing on the response data of the special requests.

[0039] Step S206: the second server verifies the validity of the query request of the target type according to the identity identifier of the target data.

[0040] Specifically, the second server determines whether the target account has the authority to query the target data based on the identity identifier, wherein the query request is a request initiated by the target account; when the target account has the authority, the second server determines that the query request is a valid request.

[0041] In this embodiment, the proxy server processes special requests and no longer authenticates the front-end encryption. The tester can directly modify the POST request body to perform unauthorized queries. Normally, whenever the content in the POST request body changes, the field in the Header request header that verifies data integrity will also change, such as: x-inegrity-md5; when the query id=10001, the front-end encryption logic calculates x-integrity-md5:51231sd213sda123; when the query id=10002, the front-end encryption logic calculates x-integrity-md5:sdas123121gfggd45; when the general unauthorized test logic is used, the id parameter needs to be modified while the front-end encryption logic also needs to calculate the x-inegrity-md5. However, in this embodiment, since the authentication server has pre-filtered out unauthorized requests, the proxy server can directly modify the id parameter to perform unauthorized queries, and the proxy server no longer verifies x-inegrity-md5 to ensure data integrity.

[0042] In one embodiment, when the query request is valid, the second server obtains the target data and desensitizes the target data; the second server sends the desensitized target data to the client logged in by the target account.

[0043] When the above target request is valid, it indicates that the target account has the authority to obtain the target data. In order to avoid the leakage of privacy data, the above second server needs to desensitize the target data when returning the target data to the first server. The above first server returns the desensitized target data to the client logged in by the target account.

[0044] Figure 3 is a flowchart of specific implementation steps according to an embodiment of the present invention, such as Figure 3 As shown, the process includes the following steps:

[0045] S301, the client sends a POST request to the authentication server;

[0046] Specifically, when the authentication server authenticates the request sent by the client, a special authentication judgment condition is added.

[0047] S302, the authentication server detects whether it is a special request; if not, jump to S303, if yes, jump to S305;

[0048] Specifically, after the authentication server confirms the special request, it forwards the request to the proxy server.

[0049] S303, the authentication server confirms that the request is valid;

[0050] S304, the authentication server passes the request to the backend server to process the business logic, and jumps to S308;

[0051] S305, the proxy server identifies the special request;

[0052] Specifically, the proxy server determines whether the special request is a data query interface, and if it is a data query request, transmits the query request to the back-end server to process the business logic.

[0053] S306, the proxy server passes the request to the backend server to process the business logic;

[0054] Specifically, the backend server processes the business logic and returns the response result to the proxy server.

[0055] S307, proxy server desensitized response data;

[0056] S308: Deliver a response to the client.

[0057] Specifically, the proxy server will desensitize the returned result and return the desensitized data information to the client, and the back-end server will pass a normal response to the user.

[0058] Optionally, the executor of the above steps may be a background processor, or other devices with similar processing capabilities, or a machine that integrates at least an image acquisition device and a data processing device, wherein the image acquisition device may include a graphics acquisition module such as a camera, and the data processing device may include a computer, a mobile phone or other terminal, but is not limited thereto.

[0059] Through the above steps, the problem of low efficiency of online environment certification testing in related technologies is solved, and the efficiency of online environment certification testing is improved.

[0060] The advantages of the embodiments of the present invention are as follows:

[0061] 1. Efficient unauthorized query testing: By eliminating the need to verify encryption and decryption, unauthorized query vulnerability testing can be performed in an online environment. This makes the testing process more efficient and convenient without having to consider the encryption, decryption and verification process of real data.

[0062] 2. Improved data security: By desensitizing all response information and outputting sensitive information in a unified desensitized form, the risk of sensitive information leakage can be effectively avoided. This helps improve data security and avoid data leakage caused by testing.

[0063] 3. Standardized output: By desensitizing the import and export information in a standard format, the consistency and standardization of the response data can be ensured. This is conducive to the collation and analysis of the test results, and ensures the comparability and repeatability of the test data.

[0064] 4. No impact on normal business: Use a separate proxy server for testing, and test in an online environment without affecting actual business operations.

[0065] The key points of the embodiments of the present invention are as follows:

[0066] 1. Authentication server: You need to configure special request conditions to the authentication server in advance, use the authentication server to authenticate special requests, and ensure the security and reliability of access to the authentication server.

[0067] 2. Data desensitization: Desensitize all response information and convert sensitive information into virtual, non-real data. This can prevent the leakage of real sensitive information and protect user privacy and data security.

[0068] 3. Special verification information identification: By adding special verification information, the import and export agent can be mounted and the specific request can be processed. This ensures that only specific requests are processed by the agent, and that the test behavior is only effective under specific conditions, avoiding impact and interference on the normal production environment.

[0069] 4. Testing unauthorized vulnerabilities in online environments: Using this solution to query unauthorized vulnerabilities in online environments can significantly improve the authenticity and effectiveness of the vulnerabilities.

[0070] 5. Cancel the front-end encryption logic: Use special requests to cancel the front-end encryption logic, which can effectively improve the efficiency of security testers in detecting unauthorized query vulnerabilities.

[0071] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.

[0072] In this embodiment, a system for verifying the validity of a request is also provided, and the device is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0073] Figure 4 is a structural block diagram of a system for verifying the validity of a request according to an embodiment of the present invention. Figure 4 As shown, the system includes a first server 402, which is used to obtain a query request and detect whether the type of the query request is a target type based on a request header of the query request, wherein the query request is used to request a query for target data; when the query request is of the target type, the query request is sent to a second server; and a second server 404, which is used to verify the validity of the query request of the target type based on the identity identifier of the target data.

[0074] In an exemplary embodiment, the first server is further configured to detect whether the request header carries a target authentication identifier; if the request header carries the target authentication identifier, the first server determines that the type of the query request is the target type.

[0075] In an exemplary embodiment, the first server is further used to obtain a configuration request, wherein the configuration request carries attribute information of a target type; and the first server generates the target authentication identifier according to the attribute information.

[0076] In an exemplary embodiment, the first server is further configured to establish an association relationship between the attribute information and the target authentication identifier.

[0077] In an exemplary embodiment, the second server is also used to determine whether the target account has the authority to query the target data based on the identity identifier, wherein the query request is a request initiated by the target account; when the target account has the authority, the second server determines that the query request is a valid request.

[0078] In an exemplary embodiment, the second server is also used to obtain the target data and desensitize the target data when the query request is valid; the second server sends the desensitized target data to the client logged in by the target account.

[0079] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0080] An embodiment of the present invention further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above methods are implemented.

[0081] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0082] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0083] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0084] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0085] An embodiment of the present invention further provides a computer program product, including a computer program, which implements the steps of the method described in each embodiment of the present application when executed by a processor.

[0086] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.

[0087] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for verifying the validity of a request, characterized in that: include: The first server obtains a query request, and detects whether the type of the query request is a target type according to a request header of the query request, wherein the query request is used to request query of target data; In case the query request is of the target type, the first server sends the query request to the second server; The second server verifies the validity of the query request of the target type according to the identity identifier of the target data.

2. The method according to claim 1, characterized in that Detecting whether the type of the query request is a target type according to the request header of the query request includes: The first server detects whether the request header of the query request carries a target authentication identifier; In a case where the request header carries the target authentication identifier, the first server determines that the type of the query request is the target type.

3. The method according to claim 2, characterized in that Before detecting whether the type of the query request is a target type according to the request header of the query request, the method further includes: The first server obtains a configuration request, wherein the configuration request carries attribute information of a target type; The first server generates the target authentication identifier according to the attribute information.

4. The method according to claim 3, characterized in that After the first server generates the target authentication identifier according to the attribute information, the method further includes: The first server establishes an association relationship between the attribute information and the target authentication identifier.

5. The method according to claim 1, characterized in that The second server verifies the validity of the query request of the target type according to the identity identifier of the target data, including: The second server determines, according to the identity identifier, whether the target account has permission to query the target data, wherein the query request is a request initiated by the target account; In a case where the target account has the authority, the second server determines that the query request is a valid request.

6. The method according to claim 1 or 5, characterized in that: After the second server verifies the validity of the query request of the target type according to the identity identifier of the target data, the method further includes: When the query request is valid, the second server obtains the target data and performs desensitization processing on the target data; The second server sends the desensitized target data to the client logged in by the target account.

7. A system for verifying the validity of a request, characterized in that: include: The first server is used to obtain a query request and detect whether the type of the query request is a target type according to a request header of the query request, wherein the query request is used to request to query target data; if the query request is of the target type, the query request is sent to the second server; The second server is used to verify the validity of the query request of the target type according to the identity identifier of the target data.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program implements the steps of the method described in any one of claims 1 to 6 when executed by a processor.

9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 6 are implemented.