Method for preventing H5 page in APP from being attacked by man-in-the-middle

By encrypting and signing the data of the H5 page in the APP, the confidentiality and integrity of the data during the transmission process are ensured, and the problem of H5 pages in the APP in the prior art are easily attacked by man-in-the-middles, reducing the risk of data leakage and tampering, and reducing the complexity of certificate management and operation and maintenance.

CN120050101APending Publication Date: 2025-05-27BEIJING BITAUTO INTERNET INFORMATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510205494.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the prior art, the H5 pages in APPs are easily attacked by man-in-the-middles. Existing security measures such as HTTPS and certificate pinning have risks of abuse, complex certificate management, high cost of frequent updates, and possible security vulnerabilities.

Method used

Encrypting data through the client and generating signatures ensures the confidentiality and integrity of the data during transmission. The server verifies the signature and decrypts the data to ensure that the data has not been tampered with.

Benefits of technology

It effectively reduces the risk of data leakage and tampering caused by man-in-the-middle attacks, avoids frequent certificate replacement by clients, and reduces security vulnerabilities and operation and maintenance complexity that may be caused by improper implementation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050101A_ABST
    Figure CN120050101A_ABST
Patent Text Reader

Abstract

The invention provides a method for preventing an H5 page in an APP from being attacked by a man-in-the-middle, and the specific operation steps of the method are as follows: step 1, a client prepares request data, step 2, the client encrypts the data, and the client encrypts the data, step 3, the client generates a signature, step 4, the client sends an encryption request, step 5, a server verifies the signature, and step 6, the server verifies the signature. The method comprises the following steps: step 1, a client receives response data, step 2, a server decrypts the data, step 7, the server processes the data, step 8, the server generates a response, step 9, the server sends an encrypted response, step 10, the client receives the response data, step 11, the client verifies a signature, step 12, the client decrypts the response data, and step 13, the client completes data processing. According to the method, the risk of data leakage and tampering caused by the fact that the data is attacked by a man-in-the-middle can be effectively reduced, frequent certificate replacement of the client is avoided, security vulnerabilities possibly caused by improper implementation are reduced, the risk of service interruption caused by configuration errors is reduced, and the complexity of operation and maintenance is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a method for preventing a man-in-the-middle attack on an H5 page in an APP. Background Art

[0002] APP, the full name is Application, which is translated into Chinese as "application (program)". In the context of modern technology, it mainly refers to software installed on mobile devices such as smart phones and tablets. These software can provide users with rich functions and services. An APP is a software program specifically designed for mobile devices, aiming to meet the specific needs of users in mobile scenarios. The functions of an APP are diverse, including but not limited to social entertainment, shopping payment, news and information, learning and education, health management, etc. They greatly improve the efficiency of users' life and work by providing a convenient operation interface and rich interactive experience. An H5 page is a web page developed based on HTML5 technology, with high interactivity and visual effects, suitable for a variety of devices and scenarios. Through reasonable production and optimization, an H5 page can provide strong digital marketing and brand promotion support for enterprises and brands.

[0003] During the use of an APP, there is a risk of a man-in-the-middle supply attack on an H5 page. In order to effectively prevent a man-in-the-middle attack on an H5 page in an APP, a variety of security measures can be adopted to enhance the security of communication between the application program and the server. In the prior art, generally two methods of HTTPS (SSL / TLS) and certificate pinning are adopted.

[0004] HTTPS (SSL / TLS) is the most basic and commonly used measure to prevent a man-in-the-middle attack. It is based on SSL / TLS encryption technology to ensure the security of data transmission between the client and the server. Its specific operation method is as follows: encrypt communication, using HTTPS can encrypt HTTP request and response content to prevent a man-in-the-middle from tampering with or stealing data; certificate verification, the server uses an SSL certificate to prove its identity, and the client will verify whether the certificate is valid to prevent connecting to a forged server.

[0005] Certificate pinning is to force the client to verify whether the SSL certificate or public key of the server matches a pre-set value to prevent it from being replaced by a forged certificate by a man-in-the-middle. The client hard-codes the public key or certificate fingerprint of the server to verify the identity of the server. Even if a man-in-the-middle obtains a valid certificate, unless they hold the same private key, they cannot deceive the client.

[0006] In the above two methods, in HTTPS (SSL / TLS), relying on trusted certificate authorities (CAs) has the risk of being abused. Certificate management is complex. Expiration or misconfiguration may lead to service interruption, and it is still vulnerable to man-in-the-middle attacks, especially when the network environment is insecure (such as DNS hijacking, malicious Wi-Fi hotspots).

[0007] In certificate pinning, it is difficult to replace certificates, and the client may need to be updated frequently. The client needs to be updated in a timely manner, resulting in relatively high maintenance costs. Security depends on the quality of implementation, and improper implementation may lead to security vulnerabilities, while increasing the complexity of development and operation and maintenance. Summary of the Invention

[0008] The technical problem to be solved by the present invention is to overcome the defect that the H5 page in the existing APP is vulnerable to man-in-the-middle attacks, and to provide a method for preventing the H5 page in the APP from being attacked by a man-in-the-middle.

[0009] The present invention solves the above technical problems through the following technical solutions:

[0010] The present invention provides a method for preventing the H5 page in the APP from being attacked by a man-in-the-middle. The specific operation steps of the method are as follows:

[0011] Step 1: The client prepares request data and data information.

[0012] Step 2: The client encrypts the data to ensure the confidentiality during the transmission process.

[0013] Step 3: The client generates a signature to ensure the integrity and authenticity of the data.

[0014] Step 4: The client sends an encrypted request, and the client sends the encrypted data and signature to the server.

[0015] Step 5: The server verifies the signature to ensure that the received data has not been tampered with.

[0016] Step 6: The server decrypts the data, and the server uses the key to decrypt the request data.

[0017] Step 7: The server processes the data, and the server performs corresponding processing according to the request.

[0018] Step 8: The server generates a response, and the server generates response data and signs it to ensure the integrity of the response data.

[0019] Step 9: The server sends an encrypted response, and the server sends the encrypted response data and signature to the client.

[0020] Step Ten: The client receives the response data, and the client receives the encrypted response data and the signature.

[0021] Step Eleven: The client verifies the signature. The client verifies the signature of the response data to confirm that the data has not been tampered with.

[0022] Step Twelve: The client decrypts the response data. The client decrypts the server's response data.

[0023] Step Thirteen: The client completes data processing. The client completes subsequent processing based on the decrypted data.

[0024] In this technical solution, when bypassing HTTPS security, it can effectively reduce the risk of data leakage and tampering caused by man-in-the-middle attacks, avoid the client from frequently changing certificates, reduce security vulnerabilities that may be caused by improper implementation, reduce the risk of service interruption caused by configuration errors, and reduce the complexity of operation and maintenance.

[0025] Preferably, the data information in Step One includes sensitive data and request header information.

[0026] In this technical solution, confirm the type of data information.

[0027] Preferably, the signature generated in Step Two includes a data digest and a key.

[0028] In this technical solution, confirm the content of the signature.

[0029] Preferably, in Step Five, the server verifies the signature by decrypting the data signature with the public key and then verifying the data signature to confirm that the data has not been tampered with.

[0030] In this technical solution, confirm the operation process of Step Five.

[0031] Preferably, in Step Eleven, the steps for the client to verify the signature are that the client decrypts the data signature with the public key and then verifies the data signature to confirm that the data has not been tampered with.

[0032] In this technical solution, confirm the operation process of Step Eleven.

[0033] Preferably, the request header information is part of an HTTP request and contains metadata about the request, the client environment, and the expected response.

[0034] In this technical solution, confirm the definition of the request header information.

[0035] Preferably, the signature mechanism in Step Three can be used in the transfer process to ensure that the target is authentic when received, mainly because it can ensure that the signed thing has not been tampered with during the transfer process.

[0036] In this technical solution, a signature mechanism is determined.

[0037] Preferably, the H5 page is a web page developed based on HTML5 technology and is a mobile web page based on the HTML5 technology standard.

[0038] In this technical solution, the type of the H5 page is confirmed.

[0039] Preferably, in step seven, necessary operations for processing data are performed.

[0040] In this technical solution, the operation of step seven is confirmed.

[0041] Preferably, the sensitive data includes personal privacy information or confidential information that needs to be protected by enterprises or social institutions.

[0042] In this technical solution, the type of sensitive data is confirmed.

[0043] On the basis of conforming to the common knowledge in the art, the above preferred conditions can be combined arbitrarily to obtain various preferred examples of the present invention.

[0044] The positive and progressive effects of the present invention are as follows:

[0045] When the present invention bypasses HTTPS security, it can effectively reduce the risk of data leakage and tampering caused by man-in-the-middle attacks, avoid frequent certificate replacement on the client side, reduce security vulnerabilities that may be caused by improper implementation, reduce the risk of service interruption caused by configuration errors, and reduce the complexity of operation and maintenance;

[0046] Furthermore, it reduces the risk of data being tampered with or stolen due to certificate expiration, using untrusted CAs, or forging root certificates to bypass HTTPS security, reduces the time cost and maintenance cost consumed by certificate replacement, and reduces the risk of security vulnerabilities or service interruption caused by improper implementation or configuration. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a schematic diagram of the overall process of the method for preventing H5 pages in an APP from being attacked by a man-in-the-middle in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] The present invention will be further described below by way of examples, but the present invention is not limited to the scope of the described examples.

[0049] Figure 1 Shown is a schematic structural diagram of an embodiment of the method for preventing H5 pages in an APP from being attacked by a man-in-the-middle. The specific operation steps of the method for preventing H5 pages in an APP from being attacked by a man-in-the-middle are as follows:

[0050] Step 1: The client prepares the request data and the client prepares the data information;

[0051] Step 2: The client encrypts the data. The client encrypts the data to ensure confidentiality during transmission;

[0052] Step 3: The client generates a signature. The client generates a digital signature to ensure the integrity and authenticity of the data;

[0053] Step 4: The client sends an encrypted request. The client sends the encrypted data and the signature to the server;

[0054] Step 5: The server verifies the signature. The server verifies the received data signature to ensure that the data has not been tampered with;

[0055] Step 6: The server decrypts the data. The server uses the key to decrypt the request data;

[0056] Step 7: The server processes the data. The server performs corresponding processing according to the request;

[0057] Step 8: The server generates a response. The server generates response data and signs it to ensure the integrity of the response data;

[0058] Step 9: The server sends an encrypted response. The server sends the encrypted response data and the signature to the client;

[0059] Step 10: The client receives the response data. The client receives the encrypted response data and the signature;

[0060] Step 11: The client verifies the signature. The client verifies the signature of the response data to confirm that the data has not been tampered with;

[0061] Step 12: The client decrypts the response data. The client decrypts the server's response data;

[0062] Step 13: The client completes data processing. The client completes subsequent processing according to the decrypted data.

[0063] When the certificate expires or an http request is used, the request data can be encrypted to prevent data leakage. Additionally, a signature calculation is performed on the encrypted data to ensure the integrity of the data and prevent it from being tampered with by attackers.

[0064] In this technical solution, when bypassing HTTPS security, the risk of data leakage and tampering caused by man-in-the-middle attacks can be effectively reduced, the need for the client to frequently change certificates can be avoided, security vulnerabilities caused by improper implementation can be reduced, the risk of service interruption caused by configuration errors can be reduced, and the complexity of operation and maintenance can be reduced.

[0065] As an important carrier of mobile Internet services, the H5 page is closely connected to the platform account system. Therefore, it is very easy to become an important target for attackers to steal accounts and crack passwords. When the H5 page is subjected to a Man-in-the-Middle Attack (MITM), the attacker can intercept, tamper with, or steal communication data, thus posing serious security risks to users and enterprises.

[0066] MITM attack is a form of network attack. The attacker places himself between the two communicating parties to intercept, eavesdrop on, or tamper with data. In the scenario of the H5 page, the attacker may induce users to visit a forged website or execute malicious scripts by forging H5 web links, tampering with H5 web code, or implanting malicious code, etc., so as to steal the user's account password and other sensitive information.

[0067] The specific threats of MITM attacks to H5 pages are as follows: account password theft. The attacker can steal the user's account password through MITM attacks, and then log in to the user's account to perform illegal operations or steal the user's personal information;

[0068] Data tampering. The attacker can tamper with the data in the H5 page, such as transaction amounts, product information, etc., to deceive users or achieve other purposes;

[0069] Information leakage. Through MITM attacks, the attacker can steal sensitive data such as the user's personal information and browsing records, and then use them for illegal activities or sell them to third parties.

[0070] The data information in the first step includes sensitive data and request header information.

[0071] In this technical solution, the type of data information is confirmed.

[0072] The signature generated in the second step includes a data digest and a key.

[0073] In this technical solution, the content of the signature is confirmed.

[0074] In the fifth step, the server verifies the signature by decrypting the data signature with the public key and then verifying the data signature to confirm that the data has not been tampered with.

[0075] In this technical solution, the operation process of the fifth step is confirmed.

[0076] In the eleventh step, the steps for the client to verify the signature are that the client decrypts the data signature with the public key and then verifies the data signature to confirm that the data has not been tampered with.

[0077] In this technical solution, the operation process of the eleventh step is confirmed.

[0078] The said request header information is part of an HTTP request and contains metadata about the request, the client environment, and the expected response.

[0079] In this technical solution, the definition of the request header information is confirmed.

[0080] HTTP is an application layer protocol used for transmitting data on the Web. It is one of the core protocols that form the basis of data communication on the World Wide Web (WWW). The working mode of HTTP can be simply described as the client (usually a Web browser) sending a request to the server. After receiving the request, the server processes it according to the content of the request and returns a corresponding response to the client.

[0081] The signature mechanism in step three can be used in the transfer process to ensure that the target is authentic when received, mainly because it can ensure that the signed thing has not been tampered with during the transfer process.

[0082] In this technical solution, the signature mechanism is determined.

[0083] The signature in step three includes the following operation processes:

[0084] S1. Apply for a certificate, apply for a digital certificate from a certificate authority (CA);

[0085] S2. Install signature tools, such as signature tools like SafeNet, and signtool.exe in the Windows Kit, etc.;

[0086] S3. Prepare the signature file, prepare the application program files to be signed (such as EXE, DLL, etc.);

[0087] S4. Insert the token and enter the password, insert the token used for signing into the computer, and enter the corresponding password during the signing process;

[0088] S5. Execute the signature command, use signature tools like signtool.exe to execute the signature command, specifying parameters such as the timestamp server, file digest algorithm, etc.;

[0089] S6. Verify the signature. After the signature is completed, the signature can be verified by viewing the digital signature information in the properties of the application program.

[0090] CA is a third-party trusted entity responsible for issuing and managing digital certificates. In the public key infrastructure (PKI), CA plays a crucial role in ensuring the authenticity and validity of digital certificates.

[0091] The functions of CA are:

[0092] Certificate issuance: The CA is responsible for generating and issuing digital certificates, which contain key information such as public key information, the identity information of the certificate holder, and the validity period of the certificate.

[0093] Certificate management: The CA is also responsible for managing the issued certificates, including certificate renewal, revocation, and expiration handling. When a user needs to renew a certificate or a certificate is revoked, the CA will perform corresponding processing.

[0094] Key management: Although the CA usually does not directly manage the user's private key, it ensures the correct pairing of the public key and the private key and assists the user in backing up and restoring the key when necessary.

[0095] Identity authentication: Before issuing a certificate, the CA will strictly verify the identity of the applicant to ensure the authenticity and credibility of the certificate.

[0096] An H5 page is a web page developed based on HTML5 technology and is a mobile web page based on the HTML5 technical standard.

[0097] In this technical solution, confirm the type of the H5 page.

[0098] HTML5 is the fifth major revision of the HyperText Markup Language (HTML), which is designed to better support multimedia on mobile devices and provides many new functions and features.

[0099] The main design purpose of HTML5 is to support multimedia content, such as video and audio, on mobile devices without relying on third-party plugins (such as Flash). In addition, HTML5 also aims to improve the structure and semanticization of web pages, enhancing the readability and maintainability of web pages.

[0100] An HTML5 responsive website can automatically detect the size of the device screen and automatically adjust the content and layout of the website, improving usability and the user-friendly experience.

[0101] Using HTML5 technology can bring more multimedia elements (video and audio) to the website and can well replace FLASH and Silverlight.

[0102] The development cost of HTML5 is low, and the website content can be updated in real time. Developers do not need to develop different versions of the website or APP for different devices. They only need to design one page, which reduces the website development cost and also saves a lot of manpower and time costs for later maintenance.

[0103] Perform the necessary operations for processing data in step seven.

[0104] In this technical solution, confirm the operations in step seven.

[0105] The sensitive data includes personal privacy information or confidential information that enterprises or social institutions need to protect.

[0106] In this technical solution, the type of sensitive data is confirmed.

[0107] Personal privacy information includes name, ID number, address, phone number, bank account number, email, password, medical information, educational background, etc. The leakage of this information may lead to the theft of personal identity, and then cause property losses or credit risks.

[0108] Confidential data of enterprises or social institutions refers to the business conditions of enterprises, network structures, IP address lists, etc., which also belong to sensitive data. If this data is leaked, it may have a serious impact on the operation security of enterprises, the protection of trade secrets, and market competitiveness.

[0109] The leakage of sensitive data may bring various security threats, including identity theft. The leakage of personal privacy data may lead to the theft of personal identity, and then be used for illegal activities such as credit card fraud and online fraud; property losses. The leakage of sensitive data may cause property losses to individuals or enterprises, such as the theft of bank accounts and economic losses caused by the leakage of trade secrets; legal risks. The leakage of sensitive data may violate relevant laws and regulations, resulting in risks such as legal lawsuits and fines for individuals or enterprises; reputation damage. The leakage of sensitive data may damage the reputation of individuals or enterprises, affecting their image and credibility in society, etc.

[0110] Although the specific implementation manners of the present invention are described above, those skilled in the art should understand that this is only an example. The protection scope of the present invention is defined by the appended claims. Without departing from the principles and essence of the present invention, those skilled in the art can make various changes or modifications to these implementation manners, but these changes and modifications all fall within the protection scope of the present invention.

Claims

1. A method for preventing H5 pages in an APP from being attacked by a man-in-the-middle, characterized in that: The specific operation steps of the method are: Step 1: The client prepares request data and data information; Step 2: The client encrypts the data to ensure confidentiality during transmission; Step 3: The client generates a digital signature to ensure the integrity and authenticity of the data; Step 4: The client sends an encryption request, and the client sends the encrypted data and signature to the server; Step 5: The server verifies the signature. The server verifies the signature of the received data to ensure that the data has not been tampered with. Step 6: The server decrypts the data. The server uses the key to decrypt the request data. Step 7: The server processes the data. The server performs corresponding processing according to the request; Step 8: The server generates a response. The server generates response data and signs it to ensure the integrity of the response data. Step 9: The server sends an encrypted response, and the server sends the encrypted response data and signature to the client; Step 10: The client receives the response data. The client receives the encrypted response data and signature. Step 11: The client verifies the signature. The client verifies the signature of the response data to confirm that the data has not been tampered with. Step 12: The client decrypts the response data. The client decrypts the response data of the server; Step 13: The client completes data processing, and the client completes subsequent processing based on the decrypted data.

2. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: The data information in step 1 includes sensitive data and request header information.

3. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: The signature generated in step 2 includes a data summary and a key.

4. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: The server verification signature in step five includes the server decrypting the data signature with the public key and then verifying the data signature to confirm that the data has not been tampered with.

5. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: The step of verifying the signature by the client in step 11 is that the client decrypts the data signature with the public key, and then verifies the data signature to confirm that the data has not been tampered with.

6. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 2, characterized in that: The request header information is part of the HTTP request and contains metadata about the request, client environment, and expected response.

7. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: The signature mechanism in step three can be used in the delivery process to ensure that the target object is authentic when received, mainly because it can ensure that the signed object has not been tampered with during the delivery process.

8. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: The H5 page is a web page developed based on HTML5 technology. It is a mobile web page based on the HTML5 technology standard.

9. The method for preventing H5 pages in an APP from being attacked by a man-in-the-middle attack as claimed in claim 1, characterized in that: In step seven, necessary operations for processing data are performed.

10. The method for preventing H5 pages in APP from being attacked by a man-in-the-middle attack as claimed in claim 2, characterized in that: The sensitive data includes personal privacy information or confidential information that needs to be protected by enterprises or social organizations.