Data encryption transmission method and device
By encrypting and assembling HTTP requests in the Web application front-end service and using asymmetric encryption algorithm to obtain symmetric encryption offsets, the problem of insufficient data exposure and security in data transmission between the Web application front-end service and the back-end service is solved, and higher data transmission security is achieved.
Patent Information
- Application Number
- CN202510339180.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-20
AI Technical Summary
In the data transmission between the front-end service and the back-end service of the web application, the unified resource locator and request body parameters cannot be effectively protected from being exposed by the browser console, which increases the risk of data being tampered with and overridden.
By intercepting unified resource locator and request body parameters in the web application front-end service, encrypted using symmetric encryption algorithm and assembled to generate HTTP requests, and issue them through the browser. At the same time, the asymmetric encryption algorithm is used to obtain the symmetric encryption offset in advance and update it regularly to improve security.
It effectively avoids the plain text exposure of important data in the browser console, reduces the risk of data being tampered with and overrides, and improves the security of data transmission between the front-end services and the back-end services of Web applications.
Smart Images

Figure CN120185885A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a data encryption transmission method and apparatus. Background Art
[0002] With the continuous development of Internet technologies and Web applications, the security of data transmission between the front-end service of a Web application and the back-end service of the Web application has become prominent.
[0003] Currently, the front-end service of a Web application often uses the Hypertext Transfer Protocol Secure (HTTPS) to transmit data between the browser and the back-end service of the Web application to ensure the security of the data channel. HTTPS encrypts requests through a domain name key certificate to prevent packet capture. The disadvantage of this method is that the request address and parameters can be seen in the browser console, exposing important and sensitive data directly in the console, increasing the risk of important data being tampered with and threatening the security of data transmission between the front-end service of the Web application and the back-end service of the Web application.
[0004] Therefore, it is urgent to improve the security of data transmission between the front-end service of a Web application and the back-end service of the Web application. Summary of the Invention
[0005] This application provides a data encryption transmission method and apparatus, which can provide encrypted transmission of the uniform resource locator and request body parameters of a Hypertext Transfer Protocol request, avoid exposing important data in the browser console, and can also provide security protections such as anti-tampering, anti-replay, and anti-overprivilege.
[0006] In a first aspect, a data encryption transmission method is provided, which is applied to the front-end service of a Web application. The method includes:
[0007] Intercept and obtain the uniform resource locator and request body parameters;
[0008] If the uniform resource locator needs to be encrypted, determine a symmetric encryption key according to the authentication parameter, where the authentication parameter is the first encrypted string, and the first string includes the first timestamp corresponding to the request and the first request identifier;
[0009] Based on the symmetric encryption key and the symmetric encryption offset, use the symmetric encryption algorithm to encrypt the uniform resource locator and the request body parameters, and the symmetric encryption offset is pre-obtained through the asymmetric encryption public key and the application identifier;
[0010] Generate a Hypertext Transfer Protocol request, where the Hypertext Transfer Protocol request includes the authentication parameter, the encrypted uniform resource locator, and the encrypted request body parameters;
[0011] Send a Hypertext Transfer Protocol request to the Web application backend service.
[0012] In a feasible design, before encrypting the Uniform Resource Locator and request body parameters using a symmetric encryption algorithm based on a symmetric encryption key and a symmetric encryption offset, the step of pre-obtaining the symmetric encryption offset includes:
[0013] Obtain the asymmetric encryption public key and application identifier corresponding to the Web application;
[0014] After the user first accesses the web page corresponding to the Web application or refreshes the web page, encrypt a second string using an asymmetric encryption algorithm based on the asymmetric encryption public key, where the second string includes a second timestamp and a second request identifier corresponding to the access or refresh of the web page;
[0015] Encrypt a third string, where the third string includes the encrypted second string and the application identifier;
[0016] Generate an offset request for obtaining the symmetric encryption offset based on the encrypted third string;
[0017] Send the offset request to the Web application backend service;
[0018] Receive an offset response from the Web application backend service, where the offset response includes the symmetric encryption offset;
[0019] Store the symmetric encryption offset.
[0020] In a feasible design, the offset response further includes an offset validity period for specifying the valid time of the symmetric encryption offset, and the method further includes:
[0021] After the offset validity period expires, re-encrypt a new second string using an asymmetric encryption algorithm based on the asymmetric encryption public key, where the new second string includes a new second timestamp and a new second request identifier;
[0022] Encrypt a new third string, where the new third string includes the encrypted new second string and the application identifier;
[0023] Generate a new offset request for obtaining the symmetric encryption offset again, where the new offset request includes the encrypted new third string;
[0024] Send the new offset request to the Web application backend service;
[0025] Receive a new offset response from the Web application backend service, where the new offset response includes a new symmetric encryption offset;
[0026] Update the stored symmetric encryption offset to a new symmetric encryption offset.
[0027] In a feasible design, according to the symmetric encryption key and the symmetric encryption offset, use the symmetric encryption algorithm to encrypt the uniform resource locator, including:
[0028] Obtain the configured number of levels n of paths that are not encrypted;
[0029] According to the symmetric encryption key and the symmetric encryption offset, use the symmetric encryption algorithm to encrypt the paths in the uniform resource locator whose levels are greater than n.
[0030] In a second aspect, a data encryption and transmission method is provided, which is applied to the Web application backend service. The method includes:
[0031] Intercept and obtain the Hypertext Transfer Protocol request from the Web application front-end service;
[0032] If the Hypertext Transfer Protocol request is an encrypted request, decrypt the authentication parameters of the Hypertext Transfer Protocol request to obtain a first string, where the first string includes a first timestamp corresponding to the request and a first request identifier;
[0033] Determine whether the Hypertext Transfer Protocol request has expired according to the first timestamp;
[0034] Determine whether the Hypertext Transfer Protocol request is a duplicate request according to the first request identifier;
[0035] If the Hypertext Transfer Protocol request has not expired and is not a duplicate request, store the first request identifier;
[0036] Determine the symmetric encryption key according to the authentication parameters;
[0037] According to the symmetric encryption key and the symmetric encryption offset, decrypt the Hypertext Transfer Protocol request to obtain the plaintext of the uniform resource locator and the plaintext of the request body parameters. The symmetric encryption offset is pre-synchronized to the Web application front-end service through the asymmetric encryption public key and the application identifier;
[0038] Send the plaintext of the uniform resource locator and the plaintext of the request body parameters to the microservice that processes the business.
[0039] In a feasible design, the step of pre-synchronizing the symmetric encryption offset to the Web application front-end service includes:
[0040] Receive an offset request from the Web application front-end service. The offset request is used to obtain the symmetric encryption offset, and the offset request includes the ciphertext of a third string;
[0041] Decrypt the ciphertext of the third string to obtain the ciphertext of a second string and the application identifier;
[0042] Determine the asymmetric encryption private key associated with the application identifier according to the application identifier;
[0043] Decrypt the ciphertext of the second string according to the asymmetric encryption private key to obtain the plaintext of the second string. The plaintext of the second string includes the second timestamp and the second request identifier corresponding to accessing or refreshing the web page;
[0044] Determine whether the offset request has expired according to the second timestamp;
[0045] Determine whether the offset request is a duplicate request according to the second request identifier;
[0046] If the offset request has not expired and is not a duplicate request, store the first request identifier;
[0047] Generate an offset response, where the offset response includes a symmetrically encrypted offset;
[0048] Send the offset response to the Web application front-end service.
[0049] In a feasible design, decrypt the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetrically encrypted offset to obtain the plaintext of the Uniform Resource Locator and the plaintext of the request body parameters, including:
[0050] If the Hypertext Transfer Protocol request includes an application identifier, determine the symmetrically encrypted offset associated with the application identifier according to the application identifier;
[0051] Decrypt the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetrically encrypted offset to obtain the plaintext of the Uniform Resource Locator and the plaintext of the request body parameters.
[0052] In a feasible design, the method further includes:
[0053] Receive the response body parameters sent by the microservice;
[0054] If the Hypertext Transfer Protocol request associated with the response body parameters is an encrypted request, encrypt the response body parameters using the symmetric encryption algorithm according to the corresponding symmetric encryption key and the symmetrically encrypted offset;
[0055] Generate a Hypertext Transfer Protocol response, where the Hypertext Transfer Protocol response includes the encrypted response body parameters;
[0056] Send the Hypertext Transfer Protocol response to the Web application front-end service.
[0057] In a third aspect, a data encryption and transmission device is provided, including:
[0058] The first information receiving module is used to intercept and obtain the uniform resource locator and the request body parameters;
[0059] The first encryption module is used to determine the symmetric encryption key according to the authentication parameters if the uniform resource locator needs to be encrypted. The authentication parameters are the encrypted first string, and the first string includes the first timestamp and the first request identifier corresponding to the request;
[0060] The first encryption module is further used to encrypt the uniform resource locator and the request body parameters using the symmetric encryption algorithm according to the symmetric encryption key and the symmetric encryption offset. The symmetric encryption offset is pre-obtained through the asymmetric encryption public key and the application identifier;
[0061] The request generation module is used to generate a Hypertext Transfer Protocol request, and the Hypertext Transfer Protocol request includes the authentication parameters, the encrypted uniform resource locator, and the encrypted request body parameters;
[0062] The first information sending module is used to send the Hypertext Transfer Protocol request to the Web application backend service.
[0063] In a fourth aspect, a data encryption and transmission device is provided, including:
[0064] The second information receiving module is used to intercept and obtain the Hypertext Transfer Protocol request from the Web application front-end service;
[0065] The decryption module is used to decrypt the authentication parameters of the Hypertext Transfer Protocol request to obtain the first string if the Hypertext Transfer Protocol request is an encrypted request. The first string includes the first timestamp and the first request identifier corresponding to the request;
[0066] The verification module is used to determine whether the Hypertext Transfer Protocol request has expired according to the first timestamp;
[0067] The verification module is further used to determine whether the Hypertext Transfer Protocol request is a duplicate request according to the first request identifier;
[0068] The verification module is further used to store the first request identifier if the Hypertext Transfer Protocol request has not expired and is not a duplicate request;
[0069] The decryption module is further used to determine the symmetric encryption key according to the authentication parameters;
[0070] The decryption module is further used to decrypt the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the uniform resource locator and the plaintext of the request body parameters. The symmetric encryption offset is pre-synchronized to the Web application front-end service through the asymmetric encryption public key and the application identifier;
[0071] The second information sending module is used to send the plaintext of the uniform resource locator and the plaintext of the request body parameters to the microservice for processing the service.
[0072] In the existing solution for transmitting HTTP requests using the Hypertext Transfer Security Protocol, the request is encrypted during the transmission process, but the uniform resource locator and the request body parameters are not encrypted before the request is sent. The console of the browser can display the plaintext of the uniform resource locator and the request body parameters, resulting in the problem of unauthorized access due to the exposure of the uniform resource locator parameters. In the solution provided by this application, since the front-end service of the Web application intercepts the uniform resource locator and the request body parameters, encrypts them and then assembles them to generate an HTTP request and sends it through the browser, the browser console can only display the ciphertext of the URL and the request body parameters in the HTTP request, avoiding the problem of unauthorized access caused by the direct exposure of important and sensitive data on the console, and reducing the risk of important data being tampered with, thus improving the security of data transmission between the front-end service and the back-end service of the Web application.
[0073] In addition, the information of the first timestamp included in the HTTP request is used by the back-end service of the Web application to determine whether the request is valid, and the information of the first request identifier is used by the back-end service of the Web application to determine whether the request is repeated, so as to prevent replay attacks. And the symmetric encryption key is obtained by encrypting the first string twice, which can increase the difficulty of cracking the symmetric encryption key, thus further improving the security of data transmission.
[0074] Furthermore, the symmetric encryption offset is pre-obtained through the asymmetric encryption public key and the application identifier, which means using the asymmetric encryption algorithm to pre-obtain the symmetric encryption offset. Since the asymmetric encryption algorithm has the characteristics of high cracking difficulty and relatively high performance loss, and the symmetric encryption algorithm has the characteristics of relatively low cracking difficulty and low performance loss. Considering that the request volume of the symmetric encryption offset is small while the request volume of the HTTP service is large. Therefore, this application uses the asymmetric encryption algorithm to encrypt and update the symmetric encryption offset regularly, and uses the symmetric encryption algorithm to encrypt the parameters in the HTTP request and the HTTP response, so as to improve the cracking difficulty of the HTTP request and the HTTP response while reducing the overall performance loss of the system. Description of the Drawings
[0075] In order to more clearly illustrate the technical solution of this application, the drawings required for the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0076] Figure 1 It is a schematic flowchart of a data encryption transmission method provided by an exemplary embodiment of this application;
[0077] Figure 2 It is a schematic flowchart of another data encryption transmission method provided by an exemplary embodiment of the present application;
[0078] Figure 3 It is a schematic flowchart of another data encryption transmission method provided by an exemplary embodiment of the present application;
[0079] Figure 4 It is a schematic flowchart of another data encryption transmission method provided by an exemplary embodiment of the present application;
[0080] Figure 5 It is a schematic diagram of a data encryption transmission device provided by an exemplary embodiment of the present application;
[0081] Figure 6 It is a schematic diagram of another data encryption transmission device provided by an exemplary embodiment of the present application. Detailed implementation manners
[0082] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0083] To enhance the security of data transmission between the front-end service and the back-end service of a Web application, this application provides a data encryption transmission system, which is used for encrypting and transmitting data between the front-end service and the back-end service of the Web application. The system includes a front-end service and a back-end service of the Web application. Among them, the front-end service of the Web application is configured with a component dependency with an interception function, and the back-end service of the Web application is configured with a component dependency with a filtering function. The front-end service of the Web application intercepts the Uniform Resource Locator (URL) and the request body parameters (i.e., the request body parameters) of the Web application through the interception function of the component, and encrypts the URL and the request body parameters using a symmetric encryption algorithm based on the symmetric encryption key and the symmetric encryption offset. Then, an HTTP (Hypertext Transfer Protocol) request is assembled using the encrypted URL and request body parameters and sent through the browser. After receiving the HTTP request, the back-end service of the Web application decrypts the HTTP request using the symmetric encryption key and the symmetric encryption offset through the filtering function of the component to obtain the plaintext of the URL and the request body parameters, and then sends them to the microservice for corresponding business processing. After receiving the response body parameters corresponding to the HTTP request sent by the microservice, the back-end service of the Web application also encrypts the response body parameters using the symmetric encryption key and the symmetric encryption offset, then assembles an HTTP response and sends it to the front-end service of the Web application.
[0084] In the existing solution of using HTTPS to transmit HTTP requests, the HTTP request is encrypted during the transmission process, but the URL and the request body parameters are not encrypted before the HTTP request is sent. The console of the browser can display the plaintext of the URL and the request body parameters, resulting in the problem of unauthorized access due to the exposure of the URL parameters. In the solution provided by this application, since the front-end service of the Web application intercepts the URL and the request body parameters, encrypts them and then assembles an HTTP request to be sent through the browser, the console of the browser can only display the ciphertext of the URL and the request body parameters in the HTTP request, avoiding the problem of unauthorized access caused by the direct exposure of important and sensitive data on the console, and reducing the risk of important data being tampered with, thus enhancing the security of data transmission between the front-end service and the back-end service of the Web application.
[0085] In addition, to implement the solution of this application, it is only necessary to introduce dependencies and add relevant configurations in the Web application front-end service and the Web application back-end service, so as to achieve unified modification of request parameters and response parameters. By the time it reaches the business layer, the HTTP message has been restored, without affecting business parameters and processing, without affecting business logic, and is non-invasive to the business. It has the characteristics of simple configuration and flexible expansion. The solution of this application can be extended to support multiple front-end and back-end languages, such as the terminal android, ios, and the back-end nginx + lua, etc.
[0086] Exemplarily, in order to further enhance the security of data transmission between the Web application front-end service and the Web application back-end service, the Web application front-end service of this application uses the application identifier appKey and the asymmetric encryption public key RSA_publicKey assigned to the client by the Web application back-end service, and uses the asymmetric encryption algorithm to obtain the symmetric encryption offset from the Web application back-end service to prevent the HTTP request and the HTTP response from being cracked. Further, the Web application front-end service can also regularly obtain a new symmetric encryption offset from the Web application back-end service to further enhance the security of transmitting the HTTP request and the HTTP response.
[0087] Since the asymmetric encryption algorithm has the characteristics of high cracking difficulty and relatively high performance loss, and the symmetric encryption algorithm has the characteristics of relatively low cracking difficulty and low performance loss. Considering that the request volume of the symmetric encryption offset is small while the request volume of the HTTP service is large, therefore, this application uses the asymmetric encryption algorithm to encrypt and regularly update the symmetric encryption offset, and uses the symmetric encryption algorithm to encrypt the parameters in the HTTP request and the HTTP response, so as to improve the cracking difficulty of the HTTP request and the HTTP response while reducing the overall performance loss of the system.
[0088] The following combines Figure 1 , and details the data encryption transmission method adopted by the Web application front-end service in the data encryption transmission system. The method includes:
[0089] S110, intercept and obtain the uniform resource locator and the request body parameters.
[0090] Exemplarily, the Web application front-end service uses the axios interceptor to intercept and obtain the uniform resource locator and the request body parameters corresponding to when the user accesses the Web application through the browser.
[0091] S120, if the uniform resource locator needs to be encrypted, determine the symmetric encryption key according to the authentication parameter.
[0092] Among them, the authentication parameter is the encrypted first string, and the first string includes the first timestamp corresponding to the request and the first request identifier, and the first request identifier is used to identify the HTTP request.
[0093] Specifically, if the uniform resource locator needs to be encrypted, a custom algorithm agreed upon with the Web application backend service is used to calculate the authentication parameters to obtain a symmetric encryption key.
[0094] Exemplarily, when at least one non-encryption path is configured in the Web application front-end service, where the non-encryption path is a path that does not need to be encrypted, the Web application front-end service determines whether the uniform resource locator needs to be encrypted in the following manner:
[0095] Obtain at least one configured non-encryption path;
[0096] Match at least one non-encryption path with the path in the uniform resource locator;
[0097] If at least one non-encryption path contains a path that is the same as the path in the uniform resource locator;
[0098] Determine that the uniform resource locator does not need to be encrypted;
[0099] Otherwise, determine that the uniform resource locator needs to be encrypted.
[0100] This application takes into account that the system may interface with some third-party platform interfaces that do not match the encryption scheme of this application. The paths of the non-matching third-party platform interfaces are configured as non-encryption paths, enabling the system to ignore the encryption of these third-party platform interfaces and enhancing the scenario adaptability of the encryption scheme of this application.
[0101] Exemplarily, the authentication parameters are obtained in the following manner:
[0102] Use a custom encryption algorithm in combination with the MD5 algorithm to encrypt the first string to obtain the authentication parameters (which can be referred to as AUTH_PARM).
[0103] S130, according to the symmetric encryption key and the symmetric encryption offset, use the symmetric encryption algorithm to encrypt the uniform resource locator and the request body parameters.
[0104] Among them, the symmetric encryption offset is obtained in advance through the asymmetric encryption public key and the application identifier.
[0105] In a feasible design, the Web application front-end service is configured with the number of levels of non-encryption paths, and the uniform resource locator is encrypted in the following manner:
[0106] Obtain the configured number of levels of non-encryption paths n;
[0107] According to the symmetric encryption key and the symmetric encryption offset, use the symmetric encryption algorithm to encrypt the paths in the uniform resource locator whose levels are greater than n.
[0108] Among them, the number of levels of the path without encryption n is a pre-configured parameter used to define the number of levels in the URL path that do not require encryption.
[0109] Taking https: / / example.com / api / user / list as an example, the above example is illustrated as follows:
[0110] For example, when the number of levels of the path without encryption n is 0, that is, the entire path "api / user / list" is encrypted, and the encrypted URL is https: / / example.com / xxxxx.
[0111] Another example is that when the number of levels of the path without encryption n is 1, that is, the previous level is ignored and the path "user / list" is encrypted, and the encrypted URL is https: / / example.com / api / xxxxx.
[0112] Another example is that when the number of levels of the path without encryption n is 2, that is, the previous two levels are ignored and the path "list" is encrypted, and the encrypted URL is https: / / example.com / api / user / xxxx.
[0113] Considering that different users have different requirements for the security of HTTP requests, the above example realizes flexible encryption of the path levels in the URL through the configuration of the number of levels of the path without encryption.
[0114] To further improve the security of HTTP requests, the present application also provides a solution in which the front-end service of the Web application obtains a symmetric encryption offset from the back-end service of the Web application through an asymmetric encryption algorithm. To implement this solution, the back-end service of the Web application generates the application identifier of the Web application, the asymmetric encryption public key and the asymmetric encryption private key corresponding to the Web application, and saves the association relationship of these three parameters. Then, the application identifier and the corresponding asymmetric encryption public key are synchronized to the Web application. The front-end service of the Web application configures the application identifier and the asymmetric encryption public key corresponding to the Web application according to the relevant information of the Web application.
[0115] In a feasible design, the front-end service of the Web application realizes the pre-obtainment of the symmetric encryption offset in the following manner:
[0116] Obtain the asymmetric encryption public key and the application identifier corresponding to the Web application;
[0117] After the user first accesses the web page corresponding to the Web application or refreshes the web page, according to the asymmetric encryption public key, use the asymmetric encryption algorithm to encrypt the second string, and the second string includes the second timestamp and the second request identifier corresponding to the access or refresh of the web page;
[0118] Encrypt the third string, where the third string includes the encrypted second string and the application identifier;
[0119] Generate an offset request for obtaining the symmetric encryption offset based on the encrypted third string;
[0120] Send the offset request to the Web application backend service;
[0121] Receive an offset response from the Web application backend service, where the offset response includes the symmetric encryption offset;
[0122] Store the symmetric encryption offset.
[0123] Wherein, the application identifier is used to identify the Web application, and the second request identifier is used to identify the offset request.
[0124] It should be noted that the Web application front-end service sends an offset request to the Web application backend service, that is, the Web application front-end service requests an interface for obtaining the symmetric encryption offset from the Web application backend service.
[0125] Exemplarily, encrypt the third string using Base64.
[0126] In the above example, after opening the web page or refreshing the web page, it triggers the Web application front-end service to encrypt the second string composed of the second timestamp and the second request identifier using the asymmetric encryption algorithm, and then encrypt the encrypted second string and the application identifier, realizing the secondary encryption of the second string, which can improve the security of the offset request. Among them, the second timestamp can be used by the Web application backend service to determine whether the offset request has expired to ensure the timeliness of the request; the second request identifier can be used by the Web application backend service to determine whether the offset request is repeated, which can prevent replay attacks.
[0127] In a feasible design, the offset response further includes an offset validity period, and the offset validity period is used to specify the valid time of the symmetric encryption offset. The symmetric encryption offset is updated regularly through the following method:
[0128] After the offset validity period expires, re-encrypt a new second string based on the asymmetric encryption public key using the asymmetric encryption algorithm. The new second string includes a new second timestamp and a new second request identifier;
[0129] Encrypt the new third string, where the new third string includes the encrypted new second string and the application identifier;
[0130] Generate a new offset request for obtaining the symmetric encryption offset again, where the new offset request includes the encrypted new third string;
[0131] Send a new offset request to the Web application backend service;
[0132] Receive a new offset response from the Web application backend service, where the new offset response includes a new symmetric encryption offset;
[0133] Update the stored symmetric encryption offset to the new symmetric encryption offset.
[0134] The above example further increases the cracking difficulty of the symmetrically encrypted HTTP request by periodically obtaining a new symmetric encryption offset. Additionally, considering the relatively small number of requests in the scenario of periodically obtaining the symmetric encryption offset, using an asymmetric encryption method with a greater cracking difficulty to encrypt the offset request can greatly enhance the security of the offset request and will not consume too much of the overall system performance.
[0135] S140, Generate a Hypertext Transfer Protocol request.
[0136] Among them, the Hypertext Transfer Protocol request includes authentication parameters, an encrypted Uniform Resource Locator, and encrypted request body parameters.
[0137] Exemplarily, the authentication parameters are located in the request header of the Hypertext Transfer Protocol request.
[0138] S150, Send the Hypertext Transfer Protocol request to the Web application backend service.
[0139] Specifically, the Web application front-end service sends the Hypertext Transfer Protocol request to the Web application backend service through a browser.
[0140] Exemplarily, the method further includes:
[0141] S160, Receive a Hypertext Transfer Protocol response from the Web application backend service;
[0142] S170, If the Hypertext Transfer Protocol request corresponding to the Hypertext Transfer Protocol response is an encrypted request, use the corresponding symmetric encryption key and symmetric encryption offset to decrypt the ciphertext of the response body parameters in the Hypertext Transfer Protocol response to obtain the plaintext of the response body parameters;
[0143] S180, Display the corresponding data on the Web page according to the plaintext of the response body parameters.
[0144] Exemplarily, the Web application front-end service is also configured with an encryption enabling switch to meet the security requirements of different users. If the encryption enabling switch indicates encrypting the HTTP request, the Web application front-end service executes S110 - S180; if the encryption enabling switch indicates not encrypting the HTTP request, the Web application front-end service directly generates an HTTP request based on the plaintext of the URL and the plaintext of the request body parameters, and then sends it to the Web application back-end service.
[0145] In the embodiment of the present application, when a user accesses a Web application, after the Web application front-end service intercepts the uniform resource locator and the request body parameters, it uses a symmetric encryption algorithm for encryption and then assembles and generates a hypertext transfer protocol request. At this time, the hypertext transfer protocol request displayed in the browser console contains the ciphertext of the uniform resource locator and the ciphertext of the request body parameters, avoiding problems such as tampering and unauthorized access caused by important and sensitive data being directly exposed in the console, and improving the security of data transmission. Among them, the information of the first timestamp included in the hypertext transfer protocol request is used by the Web application back-end service to determine whether the request is valid, and the information of the first request identifier is used by the Web application back-end service to determine whether the request is repeated, so as to prevent replay attacks. In addition, the symmetric encryption key is obtained by double-encrypting the first string, which can increase the difficulty of cracking the symmetric encryption key, thereby further improving the security of data transmission.
[0146] Further, the symmetric encryption offset is pre-obtained through the asymmetric encryption public key and the application identifier, which means that using the asymmetric encryption algorithm to pre-obtain the symmetric encryption offset can improve the security of obtaining the symmetric encryption offset and increase the difficulty of cracking the hypertext transfer protocol request.
[0147] The following combines Figure 2 , and details the data encryption and transmission method adopted by the Web application back-end service in the data encryption and transmission system. The method includes:
[0148] S210, intercept and obtain the hypertext transfer protocol request from the Web application front-end service.
[0149] Among them, the hypertext transfer protocol request includes authentication parameters, the ciphertext of the uniform resource locator, and the ciphertext of the request body parameters.
[0150] Exemplarily, the Web application back-end service intercepts the hypertext transfer protocol request from the Web application front-end service through the configured spring filter.
[0151] S220, if the hypertext transfer protocol request is an encrypted request, decrypt the authentication parameters of the hypertext transfer protocol request to obtain the first string.
[0152] Among them, the first string includes the first timestamp corresponding to the request and the first request identifier.
[0153] Exemplarily, the authentication parameter is decrypted according to the decryption algorithm corresponding to the custom encryption algorithm combined with the MD5 algorithm to obtain the first string.
[0154] Exemplarily, the Web application backend service is configured with at least one non-encrypted path, and the following method is used to determine whether the Hypertext Transfer Protocol request is encrypted:
[0155] When parsing the Uniform Resource Locator of the Hypertext Transfer Protocol request, at least one non-encrypted path is matched with the resource path in the Uniform Resource Locator.
[0156] If none of the at least one non-encrypted paths contains a path consistent with the path in the Uniform Resource Locator, it is determined that the path of the Uniform Resource Locator is an encrypted path, that is, the Hypertext Transfer Protocol request is an encrypted request.
[0157] Otherwise, it is determined that the Hypertext Transfer Protocol request is not encrypted.
[0158] It should be understood that if the Hypertext Transfer Protocol request is not encrypted, the Web application backend service can directly perform corresponding business processing according to the Uniform Resource Locator and the request body parameters.
[0159] S230. Determine whether the Hypertext Transfer Protocol request has expired according to the first timestamp.
[0160] Among them, the Web application backend service is configured with an expiration time, and it can be determined whether the Hypertext Transfer Protocol request has expired according to the expiration time and the first timestamp.
[0161] S240. Determine whether the Hypertext Transfer Protocol request is a duplicate request according to the first request identifier.
[0162] Exemplarily, the Web application backend service is connected to the storage device through the network. The Web application backend service can store data in the storage device to expand the data storage capacity and save its own storage space. In this case, the following method is used to determine whether the Hypertext Transfer Protocol request is a duplicate request according to the first request identifier:
[0163] Obtain the request identifier queue stored locally;
[0164] If the request identifier queue contains a request identifier identical to the first request identifier, it is determined that the Hypertext Transfer Protocol request is a duplicate request;
[0165] If the request ID queue does not contain a request ID identical to the first request ID, send the first request ID to the storage device so that the storage device can determine whether it stores a request ID identical to the first request ID;
[0166] Receive indication information from the storage device. If the indication information indicates that the storage device stores a request ID identical to the first request ID, determine that the HTTP request is a duplicate request; otherwise, determine that the HTTP request is not a duplicate request.
[0167] Wherein, if the request IDs in the request ID queue stored by the storage device are all different from the first request ID, the storage device stores the first request ID into the request ID queue.
[0168] Exemplarily, if the HTTP request expires or is a repeatedly sent request, the Web application backend service sends response information indicating request failure to the Web application frontend service.
[0169] S250, if the HTTP request has not expired and is not a duplicate request, store the first request ID.
[0170] Specifically, store the first request ID into the request ID queue to update the request ID queue.
[0171] S260, determine the symmetric encryption key according to the authentication parameter.
[0172] Use a custom algorithm agreed upon with the Web application frontend service to calculate the authentication parameter to obtain the symmetric encryption key.
[0173] S270, decrypt the HTTP request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the uniform resource locator and the plaintext of the request body parameters. The symmetric encryption offset is pre-synchronized to the Web application frontend service through the asymmetric encryption public key and the application identifier.
[0174] Considering the situation that the Web application backend service is responsible for the business processing of multiple Web applications and stores multiple symmetric encryption offsets, it can also be implemented in the following way: decrypt the HTTP request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the uniform resource locator and the plaintext of the request body parameters:
[0175] If the HTTP request includes an application identifier, determine the symmetric encryption offset associated with the application identifier according to the application identifier;
[0176] Decrypt the HTTP request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the uniform resource locator and the plaintext of the request body parameters.
[0177] In the above example, by applying the association relationship between the identifier and the symmetric encryption offset, the symmetric encryption offset required for decrypting the current Hypertext Transfer Protocol request can be accurately determined.
[0178] In a feasible design, the synchronization of the symmetric encryption offset to the front-end service of the Web application is achieved in the following manner:
[0179] Receive an offset request from the front-end service of the Web application. The offset request is used to obtain the symmetric encryption offset and includes the ciphertext of the third string;
[0180] Decrypt the ciphertext of the third string to obtain the ciphertext of the second string and the application identifier;
[0181] Determine the asymmetric encryption private key associated with the application identifier according to the application identifier;
[0182] Decrypt the ciphertext of the second string according to the asymmetric encryption private key to obtain the plaintext of the second string. The plaintext of the second string includes the second timestamp and the second request identifier corresponding to accessing or refreshing the web page;
[0183] Determine whether the offset request has expired according to the second timestamp;
[0184] Determine whether the offset request is a duplicate request according to the second request identifier;
[0185] If the offset request has not expired and is not a duplicate request, store the first request identifier;
[0186] Generate an offset response, where the offset response includes the symmetric encryption offset;
[0187] Send the offset response to the front-end service of the Web application.
[0188] Among them, the method for determining whether the offset request has expired refers to the description of determining whether the Hypertext Transfer Protocol request has expired in S230, which will not be elaborated here.
[0189] Exemplarily, Base64 is used to decrypt the third string.
[0190] Exemplarily, when the back-end service of the Web application is connected to the storage device through the network, the method of querying the local request queue and the request queue of the storage device is used to determine whether the offset request is a duplicate request. The specific implementation method refers to the description of determining whether the Hypertext Transfer Protocol request is a duplicate request in S240, which will not be elaborated here.
[0191] In the above example, after decrypting the offset request, the Web application backend service obtains the second timestamp and the second request identifier. The validity of the request can be determined by the second timestamp, and whether the request is repeated can be determined by the second request identifier, thereby preventing replay attacks.
[0192] Exemplarily, the offset response further includes an offset validity period, which is used to specify the valid time of the symmetrically encrypted offset, enabling the timed update of the symmetrically encrypted offset and further increasing the difficulty of cracking the symmetrically encrypted HTTP request.
[0193] Exemplarily, if the offset request expires or is a repeatedly sent request, the Web application backend service sends response information indicating request failure to the Web application frontend service.
[0194] S280, send the plaintext of the uniform resource locator and the plaintext of the request body parameters to the microservice for processing the business.
[0195] Exemplarily, when a spring filter component is installed in the Web application backend service, the following method is used to send the plaintext of the uniform resource locator and the plaintext of the request body parameters to the microservice for processing the business:
[0196] Generate a business HTTP request based on the plaintext of the uniform resource locator and the plaintext of the request body parameters;
[0197] Put the business HTTP request back into the filter chain and forward it to the microservice.
[0198] In a feasible design, after generating the response body parameters based on the plaintext of the uniform resource locator and the plaintext of the request body parameters, the microservice sends them to the Web application backend service. The Web application backend service realizes sending the encrypted response body parameters to the Web application frontend service through the following method:
[0199] S290, receive the response body parameters sent by the microservice;
[0200] S2100, if the hypertext transfer protocol request associated with the response body parameters is an encrypted request, encrypt the response body parameters using the symmetric encryption algorithm based on the corresponding symmetric encryption key and symmetric encryption offset;
[0201] S2110, generate a hypertext transfer protocol response, where the hypertext transfer protocol response includes the encrypted response body parameters;
[0202] S2120, send the hypertext transfer protocol response to the Web application frontend service.
[0203] Exemplarily, when a spring filter component is installed in the Web application backend service, S290 to S2120 are implemented based on springfilter.
[0204] In the above example, after the Web application backend service encrypts the response body parameters using a symmetric encryption algorithm, it generates a Hypertext Transfer Protocol response, which can improve the security of the Hypertext Transfer Protocol response.
[0205] Exemplarily, the Web application backend service is also configured with an encryption enable switch to meet the security requirements of different users. If the encryption enable switch indicates encrypting the HTTP response, the Web application backend service executes S290 to S2120; if the encryption enable switch indicates not encrypting the HTTP response, the Web application backend service directly generates an HTTP response based on the plaintext of the response body parameters and then sends it to the Web application frontend service.
[0206] In the above embodiments of the present application, after the Web application backend service receives a Hypertext Transfer Protocol request, it decrypts the authentication parameters of the request through a custom algorithm to obtain a first timestamp and a first request identifier. It determines whether the request is valid based on the first timestamp to ensure the timeliness of the request. It determines whether the request is repeated based on the first request identifier, which can prevent replay attacks and improve the security of data transmission. If the request is not expired and not repeated, it determines a symmetric encryption key based on the authentication parameters, thereby decrypting the request to obtain the plaintext of the Uniform Resource Locator and the plaintext of the request body parameters, so that the microservice can perform corresponding business processing.
[0207] The following combines Figure 3 and the foregoing embodiments to illustrate the method steps for the Web application frontend service to obtain the symmetric encryption offset. In this example, the Web application backend service first generates an application identifier appKey, an asymmetric encryption public key RSA_publicKey, and an asymmetric encryption private key RSA_privateKey of the Web application, and saves the association relationship of the three parameters. It synchronizes appKey and RSA_publicKey to the Web application. The Web application frontend service adds component dependencies for implementing the solution of the present application, and at the same time configures component-related configuration items, including: appKey, RSA publicKey, encryption enable switch, encryption-free path, encryption-free path level, etc. The Web application backend service adds component dependencies for implementing the solution of the present application, and at the same time configures configuration items such as symmetric encryption offset, encryption-free path, and encryption enable switch. The method steps in this example are as follows:
[0208] (1) The Web application frontend service obtains the asymmetric encryption public key and the application identifier corresponding to the Web application.
[0209] (2) The Web application front-end service generates an offset request for obtaining a symmetric encryption offset. Specifically, it encrypts the second string using an asymmetric encryption algorithm. The second string includes the second timestamp corresponding to accessing or refreshing the web page and the second request identifier. It encrypts the third string using a custom algorithm. The third string includes the application identifier and the encrypted second string. The Web application front-end service generates an offset request based on the encrypted third string.
[0210] (3) The Web application front-end service sends the offset request to the Web application back-end service, and the Web application back-end service receives the offset request.
[0211] (4) The Web application back-end service decrypts the offset request to obtain the second timestamp and the second request identifier. Specifically, first, it decrypts the offset request using a custom algorithm to obtain the ciphertext of the second string and the application identifier, and then decrypts the ciphertext of the second string according to the asymmetric encryption private key associated with the application identifier to obtain the second timestamp and the second request identifier.
[0212] (5) The Web application back-end service determines that the offset request has not expired based on the second timestamp.
[0213] (6) The Web application back-end service determines that the locally stored request queue does not contain the second request identifier based on the second request identifier.
[0214] (7) The Web application back-end service sends the second request identifier to the storage device, and the storage device receives the second request identifier.
[0215] (8) The storage device determines that the stored request queue does not contain the second request identifier and updates the stored request queue.
[0216] (9) The storage device sends an indication message to the Web application back-end service. The indication message indicates that the storage device does not store a request identifier identical to the second request identifier, and the Web application back-end service receives the indication message.
[0217] (10) The Web application back-end service updates the locally stored request queue.
[0218] (11) The Web application back-end service sends an offset response to the Web application front-end service. The offset response includes the symmetric encryption offset and the offset validity period, and the Web application front-end service receives the offset response.
[0219] (12) The Web application front-end service stores the symmetric encryption offset and sets a timed polling function according to the offset validity period to re-obtain the symmetric encryption offset next time.
[0220] The following is combined with Figure 4And for the foregoing embodiments, the method steps for a Web application front-end service to obtain an HTTP response are illustrated by way of example:
[0221] (1) The Web application front-end service intercepts and obtains the Uniform Resource Locator (URL) and the request body parameters.
[0222] (2) The Web application front-end service encrypts the Uniform Resource Locator and the request body parameters using a symmetric encryption algorithm to generate an HTTP request. Specifically, a custom algorithm is used to encrypt a first string to obtain an authentication parameter. The first string includes a first timestamp and a first request identifier corresponding to the request. The symmetric encryption key is determined based on the authentication parameter, and the Uniform Resource Locator and the request body parameters are encrypted using the symmetric encryption algorithm according to the symmetric encryption key. An HTTP request including the authentication parameter, the encrypted Uniform Resource Locator, and the encrypted request body parameters is generated, where the authentication parameter is located in the request header.
[0223] (3) The Web application front-end service sends the HTTP request to the Web application back-end service, and the Web application back-end service intercepts and obtains the HTTP request.
[0224] (4) The Web application back-end service determines that the HTTP request is an encrypted request.
[0225] (5) The Web application back-end service decrypts the authentication parameter to obtain the first timestamp and the first request identifier.
[0226] (6) The Web application back-end service determines that the request has not expired based on the first timestamp.
[0227] (7) The Web application back-end service determines that the locally stored request queue does not contain the first request identifier based on the first request identifier.
[0228] (8) The Web application back-end service sends the first request identifier to the storage device, and the storage device receives the first request identifier.
[0229] (9) The storage device determines that the stored request queue does not contain the first request identifier and updates the stored request queue.
[0230] (10) The storage device sends an indication message to the Web application back-end service. The indication message indicates that the storage device does not store a request identifier identical to the first request identifier, and the Web application back-end service receives the indication message.
[0231] (11) The Web application back-end service updates the locally stored request queue.
[0232] (12) The Web application back-end service decrypts the request according to the symmetric encryption algorithm to obtain the plaintext of the Uniform Resource Locator and the plaintext of the request body parameters.
[0233] (13) Put the plaintext of the uniform resource locator and the plaintext of the request body parameters back into the filter chain and forward them to the microservice. The microservice receives the plaintext of the uniform resource locator and the plaintext of the request body parameters.
[0234] (14) The microservice performs corresponding business processing according to the plaintext of the uniform resource locator and the plaintext of the request body parameters, and generates response body parameters.
[0235] (15) The microservice sends the response body parameters to the Web application backend service, and the Web application backend service receives the response body parameters.
[0236] (16) The Web application backend service determines that the HTTP request corresponding to the response body parameters is encrypted, and encrypts the response body parameters using a symmetric encryption algorithm to generate an HTTP response.
[0237] (17) The Web application backend service sends the HTTP response to the Web application frontend service, and the Web application frontend service receives the HTTP response.
[0238] (18) After the Web application frontend service determines that the HTTP request corresponding to the HTTP response is encrypted, it decrypts the HTTP response to obtain the plaintext of the response body parameters.
[0239] (19) The Web application frontend service displays the corresponding data on the page according to the plaintext of the response body parameters.
[0240] As Figure 5 shown, the present application also provides a data encryption and transmission device, including:
[0241] A first information receiving module, configured to intercept and obtain a uniform resource locator and request body parameters;
[0242] A first encryption module, configured to, if the uniform resource locator needs to be encrypted, determine a symmetric encryption key according to an authentication parameter, where the authentication parameter is an encrypted first string, and the first string includes a first timestamp and a first request identifier corresponding to the request;
[0243] The first encryption module is further configured to encrypt the uniform resource locator and the request body parameters using a symmetric encryption algorithm according to the symmetric encryption key and the symmetric encryption offset;
[0244] A request generation module, configured to generate a hypertext transfer protocol request, where the hypertext transfer protocol request includes an authentication parameter, an encrypted uniform resource locator, and an encrypted request body parameter, and the symmetric encryption offset is pre-obtained through an asymmetric encryption public key and an application identifier;
[0245] A first information sending module, configured to send the hypertext transfer protocol request to the Web application backend service.
[0246] In a feasible design, the first information receiving module is further configured to obtain the asymmetric encryption public key and the application identifier corresponding to the Web application;
[0247] After the user first accesses the web page corresponding to the Web application or refreshes the web page, the first encryption module is further configured to encrypt the second string according to the asymmetric encryption public key by using the asymmetric encryption algorithm, where the second string includes the second timestamp and the second request identifier corresponding to the access or refresh of the web page;
[0248] The first encryption module is further configured to encrypt the third string, where the third string includes the encrypted second string and the application identifier;
[0249] The request generation module is further configured to generate an offset request for obtaining the symmetric encryption offset based on the encrypted third string;
[0250] The first information sending module is further configured to send the offset request to the Web application backend service;
[0251] The first information receiving module is further configured to receive the offset response from the Web application backend service, where the offset response includes the symmetric encryption offset, and store the symmetric encryption offset.
[0252] In a feasible design, the offset response further includes an offset validity period, which is used to specify the valid time of the symmetric encryption offset. After the offset validity period expires, the first encryption module is further configured to encrypt a new second string according to the asymmetric encryption public key by using the asymmetric encryption algorithm, where the new second string includes a new second timestamp and a new second request identifier;
[0253] The first encryption module is further configured to encrypt the new third string, where the new third string includes the encrypted new second string and the application identifier;
[0254] The request generation module is further configured to generate a new offset request for obtaining the symmetric encryption offset again, where the new offset request includes the encrypted new third string;
[0255] The first information sending module is further configured to send the new offset request to the Web application backend service;
[0256] The first information receiving module is further configured to receive the new offset response from the Web application backend service, where the new offset response includes the new symmetric encryption offset;
[0257] The first information receiving module is further configured to update the stored symmetric encryption offset to the new symmetric encryption offset.
[0258] In a feasible design, the first encryption module is implemented as follows: according to the symmetric encryption key and the symmetric encryption offset, the uniform resource locator is encrypted using the symmetric encryption algorithm:
[0259] Obtain the configured number of levels n of paths exempt from encryption;
[0260] According to the symmetric encryption key and the symmetric encryption offset, use the symmetric encryption algorithm to encrypt the paths in the uniform resource locator whose levels are greater than n.
[0261] For other implementation manners and effects of the above device, refer to the description in the embodiment of the data encryption transmission method, which will not be elaborated here.
[0262] As Figure 6 shown, the present application also provides a data encryption transmission device, including:
[0263] A second information receiving module, configured to intercept and obtain a Hypertext Transfer Protocol request from the front-end service of the Web application;
[0264] A decryption module, configured to, if the Hypertext Transfer Protocol request is an encrypted request, decrypt the authentication parameter of the Hypertext Transfer Protocol request to obtain a first string, where the first string includes a first timestamp corresponding to the request and a first request identifier;
[0265] A verification module, configured to determine whether the Hypertext Transfer Protocol request has expired according to the first timestamp;
[0266] The verification module is further configured to determine whether the Hypertext Transfer Protocol request is a duplicate request according to the first request identifier;
[0267] The verification module is further configured to store the first request identifier if the Hypertext Transfer Protocol request has not expired and is not a duplicate request;
[0268] The decryption module is further configured to determine the symmetric encryption key according to the authentication parameter;
[0269] The decryption module is further configured to decrypt the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the uniform resource locator and the plaintext of the request body parameters, and the symmetric encryption offset is pre-synchronized to the front-end service of the Web application through the asymmetric encryption public key and the application identifier;
[0270] A second information sending module, configured to send the plaintext of the uniform resource locator and the plaintext of the request body parameters to the microservice for processing the service.
[0271] In a feasible design, the device further includes a response generation module. Among them, the second information receiving module is further configured to receive an offset request from the Web application front-end service. The offset request is used to obtain a symmetric encryption offset, and the offset request includes the ciphertext of a third string.
[0272] The decryption module is further configured to decrypt the ciphertext of the third string to obtain the ciphertext of the second string and the application identifier.
[0273] The decryption module is further configured to determine the asymmetric encryption private key associated with the application identifier according to the application identifier.
[0274] The decryption module is further configured to decrypt the ciphertext of the second string based on the asymmetric encryption private key to obtain the plaintext of the second string. The plaintext of the second string includes the second timestamp and the second request identifier corresponding to accessing or refreshing the web page.
[0275] The verification module is further configured to determine whether the offset request has expired according to the second timestamp.
[0276] The verification module is further configured to determine whether the offset request is a duplicate request according to the second request identifier.
[0277] The verification module is further configured to store the first request identifier if the offset request has not expired and is not a duplicate request.
[0278] The response generation module is further configured to generate an offset response, and the offset response includes a symmetric encryption offset.
[0279] The second information sending module is further configured to send the offset response to the Web application front-end service.
[0280] In a feasible design, the decryption module is implemented in the following manner: decrypt the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the Uniform Resource Locator and the plaintext of the request body parameters.
[0281] If the Hypertext Transfer Protocol request includes an application identifier, determine the symmetric encryption offset associated with the application identifier according to the application identifier.
[0282] Decrypt the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plaintext of the Uniform Resource Locator and the plaintext of the request body parameters.
[0283] In a feasible design, the device further includes a second encryption module. Among them,
[0284] The second information receiving module is further configured to receive the response body parameters sent by the microservice.
[0285] If the Hypertext Transfer Protocol request associated with the response body parameter is an encrypted request, the second encryption module is used to encrypt the response body parameter using a symmetric encryption algorithm according to the corresponding symmetric encryption key and symmetric encryption offset;
[0286] The response generation module is further used to generate a Hypertext Transfer Protocol response, and the Hypertext Transfer Protocol response includes the encrypted response body parameter;
[0287] The second information sending module is further used to send the Hypertext Transfer Protocol response to the Web application front-end service.
[0288] For other implementation manners and effects of the above device, refer to the description in the embodiment of the data encryption transmission method, which will not be elaborated here.
[0289] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present application. In addition, the above-disclosed specific details are only for the purposes of illustration and facilitating understanding, rather than limitations. The above details do not limit the present application to necessarily adopt the above specific details for implementation.
[0290] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps is not strictly limited in order, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily have to be executed at the same moment, but can be executed at different moments. Their execution order does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0291] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present application are only illustrative examples, and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The word "or" and "and" used here refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used here refers to the phrase "such as but not limited to", and can be used interchangeably with each other.
[0292] It should also be noted that in the devices, equipment, and methods of the present application, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations shall be regarded as equivalent solutions of the present application.
[0293] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0294] The above description has been given for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A data encryption transmission method, characterized in that: Applied to Web application front-end services, the method includes: Intercept and obtain the uniform resource locator and request body parameters; If the uniform resource locator needs to be encrypted, determine the symmetric encryption key according to the authentication parameter, the authentication parameter is an encrypted first string, and the first string includes a first timestamp and a first request identifier corresponding to the request; Encrypting the uniform resource locator and the request body parameter using a symmetric encryption algorithm according to the symmetric encryption key and the symmetric encryption offset, wherein the symmetric encryption offset is pre-acquired by an asymmetric encryption public key and an application identifier; Generate a hypertext transfer protocol request, wherein the hypertext transfer protocol request includes the authentication parameter, the encrypted uniform resource locator and the encrypted request body parameter; Send the Hypertext Transfer Protocol request to the Web application backend service.
2. The method according to claim 1, characterized in that Before encrypting the uniform resource locator and the request body parameter using a symmetric encryption algorithm according to the symmetric encryption key and the symmetric encryption offset, the step of pre-acquiring the symmetric encryption offset includes: Obtain the asymmetric encryption public key and application identifier corresponding to the Web application; After the user visits the webpage corresponding to the Web application for the first time or refreshes the webpage, encrypting a second string using an asymmetric encryption algorithm according to the asymmetric encryption public key, wherein the second string includes a second timestamp and a second request identifier corresponding to the access or refresh of the webpage; Encrypting a third character string, wherein the third character string includes the encrypted second character string and the application identifier; Generate an offset request for obtaining a symmetric encryption offset based on the encrypted third character string; Sending the offset request to the Web application backend service; Receiving an offset response from the Web application backend service, the offset response including a symmetric encryption offset; The symmetric encryption offset is stored.
3. The method according to claim 2, characterized in that The offset response also includes an offset validity period, and the offset validity period is used to specify the validity period of the symmetric encryption offset. The method also includes: After the validity period of the offset expires, re-encrypting a new second string using an asymmetric encryption algorithm based on the asymmetric encryption public key, wherein the new second string includes a new second timestamp and a new second request identifier; Encrypting a new third character string, wherein the new third character string includes the encrypted new second character string and the application identifier; Generate again a new offset request for obtaining the symmetric encryption offset, wherein the new offset request includes the encrypted new third character string; Sending the new offset request to the Web application backend service; Receiving a new offset response from the Web application backend service, wherein the new offset response includes a new symmetric encryption offset; The stored symmetric encryption offset is updated to the new symmetric encryption offset.
4. The method according to any one of claims 1 to 3, characterized in that Encrypting the uniform resource locator using a symmetric encryption algorithm according to the symmetric encryption key and the symmetric encryption offset includes: Get the configured encryption-free path level n; According to the symmetric encryption key and the symmetric encryption offset, a symmetric encryption algorithm is used to encrypt the path with a level greater than n in the uniform resource locator.
5. A data encryption transmission method, characterized in that: Applied to Web application backend services, the method includes: Intercept and obtain Hypertext Transfer Protocol requests from Web application front-end services; If the hypertext transfer protocol request is an encrypted request, decrypt the authentication parameter of the hypertext transfer protocol request to obtain a first character string, wherein the first character string includes a first timestamp and a first request identifier corresponding to the request; Determining whether the hypertext transfer protocol request has expired according to the first timestamp; Determining, according to the first request identifier, whether the hypertext transfer protocol request is a repeated request; If the hypertext transfer protocol request has not expired and is not a repeated request, storing the first request identifier; determining a symmetric encryption key based on the authentication parameters; Decrypting the Hypertext Transfer Protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plain text of the Uniform Resource Locator and the plain text of the request body parameters, wherein the symmetric encryption offset is pre-synchronized to the Web application front-end service through the asymmetric encryption public key and the application identifier; The plain text of the uniform resource locator and the plain text of the request body parameters are sent to the microservice that processes the business.
6. The method according to claim 5, characterized in that The step of pre-synchronizing the symmetric encryption offset to the Web application front-end service comprises: Receiving an offset request from the Web application front-end service, the offset request being used to obtain a symmetric encryption offset, the offset request including a ciphertext of a third character string; Decrypting the ciphertext of the third character string to obtain the ciphertext of the second character string and an application identifier; According to the application identifier, determining an asymmetric encryption private key associated with the application identifier; Decrypting the ciphertext of the second character string according to the asymmetric encryption private key to obtain the plaintext of the second character string, where the plaintext of the second character string includes a second timestamp and a second request identifier corresponding to accessing or refreshing the web page; Determining whether the offset request is expired according to the second timestamp; Determining, according to the second request identifier, whether the offset request is a repeated request; If the offset request has not expired and is not a repeated request, storing the first request identifier; generating an offset response, the offset response comprising a symmetric encryption offset; Send the offset response to the Web application front-end service.
7. The method according to claim 5 or 6, characterized in that: The step of decrypting the hypertext transfer protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plain text of the uniform resource locator and the plain text of the request body parameter includes: If the hypertext transfer protocol request includes an application identifier, determining a symmetric encryption offset associated with the application identifier according to the application identifier; The hypertext transfer protocol request is decrypted according to the symmetric encryption key and the symmetric encryption offset to obtain the plain text of the uniform resource locator and the plain text of the request body parameter.
8. The method according to claim 5 or 6, characterized in that: The method further comprises: Receive response body parameters sent by the microservice; If the hypertext transfer protocol request associated with the response body parameter is an encrypted request, encrypt the response body parameter using a symmetric encryption algorithm according to a corresponding symmetric encryption key and a symmetric encryption offset; generating a hypertext transfer protocol response, wherein the hypertext transfer protocol response includes the encrypted response body parameters; Send the Hypertext Transfer Protocol response to the Web application front-end service.
9. A data encryption transmission device, characterized in that: include: A first information receiving module, used for intercepting and obtaining a uniform resource locator and request body parameters; a first encryption module, configured to determine a symmetric encryption key according to an authentication parameter if the uniform resource locator needs to be encrypted, wherein the authentication parameter is an encrypted first character string, and the first character string includes a first timestamp and a first request identifier corresponding to the request; The first encryption module is further used to encrypt the uniform resource locator and the request body parameter using a symmetric encryption algorithm according to the symmetric encryption key and the symmetric encryption offset, and the symmetric encryption offset is pre-acquired by the asymmetric encryption public key and the application identifier; A request generation module, used for generating a hypertext transfer protocol request, wherein the hypertext transfer protocol request includes the authentication parameter, the encrypted uniform resource locator and the encrypted request body parameter; The first information sending module is used to send the hypertext transfer protocol request to the Web application backend service.
10. A data encryption transmission device, characterized in that: include: The second information receiving module is used to intercept and obtain the hypertext transfer protocol request from the Web application front-end service; a decryption module, configured to decrypt the authentication parameter of the hypertext transfer protocol request to obtain a first character string if the hypertext transfer protocol request is an encrypted request, wherein the first character string includes a first timestamp and a first request identifier corresponding to the request; A verification module, configured to determine whether the hypertext transfer protocol request has expired according to the first timestamp; The verification module is further used to determine whether the hypertext transfer protocol request is a repeated request according to the first request identifier; The verification module is further configured to store the first request identifier if the hypertext transfer protocol request has not expired and is not a repeated request; The decryption module is also used to determine the symmetric encryption key according to the authentication parameters; The decryption module is also used to decrypt the hypertext transfer protocol request according to the symmetric encryption key and the symmetric encryption offset to obtain the plain text of the uniform resource locator and the plain text of the request body parameter, and the symmetric encryption offset is pre-synchronized to the Web application front-end service through the asymmetric encryption public key and the application identifier; The second information sending module is used to send the plain text of the uniform resource locator and the plain text of the request body parameter to the microservice processing the business.