HTTPS jump verification method and system, electronic equipment and storage medium
By verifying the hash value of the redirected URL during HTTPS jump process and predicting the deep learning model, combined with the consensus mechanism, the risk of malicious attacks during HTTPS jump process is solved, and the security is significantly improved.
Patent Information
- Application Number
- CN202510363943.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-24
AI Technical Summary
Under the HTTPS protocol, there is still a risk of being maliciously attacked during the redirection process, such as man-in-the-middle attacks and phishing attacks. The attacker may intercept or tamper with redirecting information, resulting in the user being redirected to the malicious website.
By verifying the legality of the hash value of the redirected URL, predicting the appropriate redirection path using a deep learning model, and verifying the hash value using a consensus mechanism to ensure the authenticity and immutability of the hash value, thereby preventing malicious attacks.
It effectively prevents malicious attackers from bypassing security verification by forging hash values, improves the security of HTTPS jump protection, and ensures the confidentiality and integrity of user data.
Smart Images

Figure CN120201019A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet technologies, and in particular, to an HTTPS redirection verification method, system, electronic device, and storage medium. Background Art
[0002] With the continuous progress of Internet technologies, network security issues have received increasing attention. In particular, the security of website access has become a core concern for users. As a reliable network transmission protocol, HTTPS (HyperText Transfer Protocol Secure) plays a crucial role. HTTPS uses the SSL / TLS protocol to encrypt data to ensure that during the process of data transmission from the user side to the server, the data will not be stolen or tampered with by a third party. Through this encryption mechanism, HTTPS effectively maintains the confidentiality and integrity of the communication data between the user and the server, providing a more secure website access environment for users, thereby ensuring the security of website access.
[0003] However, although the HTTPS protocol provides strong security protection during data transmission, in actual applications, even under the HTTPS protocol, there are still risks of being maliciously attacked during the website redirection process. These attacks may occur when the user is redirected from the current website to another website, such as man-in-the-middle attacks, phishing attacks, etc. In these attacks, the attacker will intercept or tamper with the redirection information and redirect the user to a malicious website, thereby stealing user information, spreading malware, or conducting other illegal activities. Therefore, how to improve the security of HTTPS redirection protection is an urgent problem to be solved. Summary of the Invention
[0004] The main purpose of this application is to overcome the shortcomings and deficiencies of the prior art, and provide an HTTPS redirection verification method, system, electronic device, and storage medium. By verifying the legitimacy of the hash value of the redirected URL, the authenticity and immutability of the hash value are ensured, effectively preventing the possibility that malicious attackers bypass the security verification by forging the hash value, thereby further improving the security of HTTPS redirection protection.
[0005] To achieve the above objective, this application adopts the following technical solutions:
[0006] In the first aspect, this application provides an HTTPS redirection verification method, including the following steps:
[0007] Obtain the website access request information initiated by the user side;
[0008] Judge the request type of the access request information;
[0009] Determine whether redirection is required according to the request type;
[0010] If redirection is required, input the request information that needs to be redirected into a pre-established deep learning model to obtain a redirected URL with a relative path;
[0011] Perform a hash process on the redirected URL to convert the redirected URL into a hash value with a fixed length;
[0012] Use a consensus mechanism to verify the legality of the hash value with the fixed length;
[0013] If the verification is successful, respond to the access request information for the redirected URL.
[0014] As a preferred technical solution, the request types of the access request information include:
[0015] HTTP requests and HTTPS requests.
[0016] As a preferred technical solution, the determining whether redirection is required according to the request type includes:
[0017] If the request type of the access request information is an HTTPS request, determine whether redirection is required.
[0018] As a preferred technical solution, it further includes:
[0019] If the request type of the access request information is an HTTP request, feedback an error message to the user or redirect the access request information to an HTTPS request.
[0020] As a preferred technical solution, it further includes processing the request that needs to be redirected, including:
[0021] Extract the key features of the request that needs to be redirected; wherein, the key features include: the URL of the request, the method of the request, and the header information of the request;
[0022] Encode the key features to obtain a feature encoding;
[0023] Combine the feature encodings to obtain a feature vector.
[0024] As a preferred technical solution, the inputting the request information that needs to be redirected into a pre-established deep learning model to obtain a redirected URL with a relative path includes:
[0025] Use the feature vector as the input of the pre-established deep learning model; wherein, the pre-established deep learning model includes multiple decision trees;
[0026] The decision tree starts from the root node and traverses the feature vectors step by step according to the preset splitting criterion until reaching the leaf node, obtaining multiple prediction results;
[0027] Analyze the multiple prediction results to determine the final prediction result;
[0028] According to the final prediction result, combined with the domain name of the request to be redirected, obtain the complete relative path of the redirect URL.
[0029] As a preferred technical solution, the consensus mechanism is used to verify the legality of the fixed-length hash value, including:
[0030] Transmit the fixed-length hash value to the blockchain network;
[0031] The verification node in the blockchain receives the fixed-length hash value and broadcasts the fixed-length hash value to other verification nodes in the blockchain network;
[0032] Each verification node participating in the verification signs the fixed hash value with its private key to obtain the signed hash value and attaches proof information;
[0033] Broadcast the signed hash value and the proof information to other verification nodes;
[0034] The other verification nodes verify according to the signed hash value and the proof information using the consensus algorithm;
[0035] When the preset consensus ratio is reached, verify that the hash value is legal.
[0036] In a second aspect, the present application provides an HTTPS redirection verification system applied to the above-mentioned HTTPS redirection verification method, including a request information acquisition module, a request type judgment module, a redirection judgment module, a redirection URL generation module, a hash processing module, a verification module, and a response module;
[0037] The request information acquisition module is used to acquire the website access request information initiated by the user terminal;
[0038] The request type judgment module is used to judge the request type of the access request information;
[0039] The redirection judgment module is used to judge whether redirection is required according to the request type;
[0040] The generated redirect URL module is used to input the request information to be redirected into a pre-established deep learning model to obtain a redirect URL with a relative path if redirection is required.
[0041] The hash processing module is used to perform hash processing on the redirect URL and convert the redirect URL into a hash value with a fixed length.
[0042] The verification module is used to verify the legality of the hash value with a fixed length by using a consensus mechanism.
[0043] The response module is used to respond to the access request information of the redirect URL if the verification is successful.
[0044] As a preferred technical solution, the request types of the access request information include:
[0045] HTTP requests and HTTPS requests.
[0046] As a preferred technical solution, the redirect judgment module is specifically used for:
[0047] If the request type of the access request information is an HTTPS request, it is judged whether redirection is required.
[0048] As a preferred technical solution, it further includes:
[0049] If the request type of the access request information is an HTTP request, an error message is fed back to the user or the access request information is redirected to an HTTPS request.
[0050] As a preferred technical solution, it further includes a processing module, and the processing module is used for:
[0051] Extracting the key features of the request to be redirected; wherein, the key features include: the URL of the request, the method of the request, and the header information of the request;
[0052] Encoding the key features to obtain a feature encoding;
[0053] Combining the feature encodings to obtain a feature vector.
[0054] As a preferred technical solution, the generated redirect URL module is specifically used for:
[0055] Using the feature vector as the input of the pre-established deep learning model; wherein, the pre-established deep learning model includes multiple decision trees;
[0056] The decision tree starts from the root node, traverses the feature vectors step by step according to the preset splitting criterion until it reaches the leaf node, and obtains multiple prediction results;
[0057] Analyze the multiple prediction results to determine the final prediction result;
[0058] According to the final prediction result, combined with the domain name of the request that needs to be redirected, obtain the complete relative path redirection URL.
[0059] As a preferred technical solution, the verification module is specifically used for:
[0060] Transmit the fixed-length hash value to the blockchain network;
[0061] The verification node in the blockchain receives the fixed-length hash value and broadcasts the fixed-length hash value to other verification nodes in the blockchain network;
[0062] Each verification node participating in the verification uses its private key to sign the fixed hash value to obtain a signed hash value and attach proof information;
[0063] Broadcast the signed hash value and the proof information to other verification nodes;
[0064] The other verification nodes verify according to the signed hash value and the proof information using the consensus algorithm;
[0065] When the preset consensus ratio is reached, verify that the hash value is legal.
[0066] In a third aspect, the present application provides an electronic device, which includes:
[0067] At least one processor; and a memory communicatively connected to the at least one processor;
[0068] Wherein, the memory stores computer program instructions executable by the at least one processor, and the computer program instructions are executed by the at least one processor so that the at least one processor can execute the described HTTPS jump verification method.
[0069] In a fourth aspect, the present application provides a computer-readable storage medium storing a program, and when the program is executed by a processor, the described HTTPS jump verification method is implemented.
[0070] In summary, compared with the prior art, the effective effects brought by the technical solution provided by the present application at least include:
[0071] This application proposes an HTTPS redirection verification method, which obtains the website access request information initiated by the client; determines the request type of the access request information; based on the request type, determines whether redirection is required; if redirection is required, inputs the request information to be redirected into a pre-established deep learning model to obtain a redirection URL with a relative path; performs a hash process on the redirection URL to convert the redirection URL into a hash value with a fixed length; uses a consensus mechanism to verify the legality of the hash value with the fixed length; if the verification is successful, responds to the access request information of the redirection URL. Through the deep learning model, this application can accurately predict an appropriate redirection path, thus avoiding security risks caused by incorrect redirection; at the same time, using the consensus mechanism to verify the legality of the hash value of the redirection URL ensures the authenticity and immutability of the hash value, effectively preventing the possibility of malicious attackers bypassing security verification by forging hash values, thereby further enhancing the security of HTTPS redirection protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] In order to more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0073] Figure 1 It is a flowchart of an HTTPS redirection verification method provided by an embodiment of this application;
[0074] Figure 2 It is a flowchart of processing a request to be redirected provided by an embodiment of this application;
[0075] Figure 3 It is a flowchart of obtaining a redirection URL with a relative path provided by an embodiment of this application;
[0076] Figure 4 It is a flowchart of verifying the legality of a hash value with a fixed length provided by an embodiment of this application;
[0077] Figure 5 It is a block diagram of an HTTPS redirection verification system provided by an embodiment of this application;
[0078] Figure 6 It is a structural diagram of an electronic device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0079] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.
[0080] In this application, the mention of "embodiment" means that the specific features, structures or characteristics described in combination with the embodiment can be included in at least one embodiment of this application. The appearance of this phrase at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described in this application can be combined with other embodiments.
[0081] In the current Internet environment, the HTTPS protocol has become the cornerstone for ensuring the security of website access. It encrypts the transmitted data, effectively preventing the theft and tampering of data during the transmission process. However, although the HTTPS protocol provides strong security protection during the data transmission process, in actual applications, even under the HTTPS protocol, there is still a risk of being maliciously attacked during the website redirection process. These attacks may occur when the user is redirected from the current website to other websites, such as man-in-the-middle attacks, phishing attacks, etc. In these attacks, the attacker will intercept or tamper with the redirection information and redirect the user to a malicious website, thereby stealing user information, spreading malware or conducting other illegal activities.
[0082] To solve the above problems, this application provides an HTTPS redirection verification method. Through a deep learning model, it can accurately predict the appropriate redirection path, thus avoiding the security risks caused by incorrect redirection. At the same time, a consensus mechanism is used to verify the legality of the hash value of the redirection URL, ensuring the authenticity and immutability of the hash value, effectively preventing the possibility of malicious attackers bypassing the security verification by forging the hash value, thereby further enhancing the security of HTTPS redirection protection.
[0083] The following will describe in detail the technical solutions provided by the embodiments in this application with reference to the accompanying drawings.
[0084] Please refer to Figure 1 , in an embodiment of this application, an HTTPS redirection verification method is provided, including the following steps:
[0085] S1. Obtain the website access request information initiated by the user terminal.
[0086] Further, when a user enters a URL in the browser address bar or clicks on a link, the browser sends an access request message to the target server. The access request message includes a request method, such as GET, POST, PUT, DELETE, etc., indicating the type of operation the client wishes to perform, the request URL (Uniform Resource Locator), the request body, and the request headers.
[0087] S2. Determine the request type of the access request message.
[0088] Further, determining the request type of the access request message means determining whether the access request message is an HTTP request or an HTTPS request. Among them, HTTP (HyperText Transfer Protocol) is an application layer protocol for distributed, collaborative, hypermedia information systems. It allows the transfer of hypertext and other content between a client (such as a browser) and a server. HTTPS (HTTP Secure), on the other hand, is a secure version of HTTP. It adds an SSL / TLS protocol layer on top of HTTP to encrypt the communication data between the client and the server, ensuring the security of data transmission.
[0089] Specifically, determining the request type of the access request message means determining whether the access request message is an HTTP request or an HTTPS request can be done by checking the protocol part of the URL (complete resource locator); when the browser initiates a request, on the server side, a web server (such as Apache, Nginx, etc.) will parse the URL and extract the protocol part when it receives the request. This URL contains the protocol part (such as http: / / or https: / / ); thus, it can be determined whether the access request message is an HTTP request or an HTTPS request.
[0090] It can also be determined whether the request type of the access request message is an HTTP request or an HTTPS request by whether TLS / SSL encryption is used, that is, by checking whether a TLS / SSL connection is successfully established during the incoming handshake process; if the handshake is successful, the request is considered an HTTPS request; otherwise, it is an HTTP request.
[0091] S3. According to the request type, determine whether redirection is needed.
[0092] Further, if the request type of the access request message is an HTTPS request, then determine whether redirection is needed.
[0093] Among them, redirection refers to the process of redirecting various network requests to other locations, that is, used to transfer a user from one URL (Uniform Resource Locator) to another URL.
[0094] You can judge by whether the URL path ends with a slash. When the URL path accessed by the user does not end with a slash (for example, `https: / / example.com / page`), redirection is required. In addition, you can also use predefined rules to determine whether redirection is required.
[0095] In an embodiment of the present application, if the request type of the access request information is an HTTP request, an error message is fed back to the user or the access request information is redirected to an HTTPS request.
[0096] S4. If redirection is required, the request information that needs to be redirected is input into a pre-established deep learning model to obtain a redirection URL with a relative path.
[0097] For further information, see Figure 2 , further comprising processing the request that needs to be redirected, the steps comprising:
[0098] S41.1. Extract key features of the request that needs to be redirected; wherein the key features include: requested URL, requested method, and requested header information;
[0099] Furthermore, the URL of the HTTPS request needs to be redirected, including the domain name, path, query parameters, etc., to understand the key to the user's access target. Among them, the path reflects the specific resource or page the user is trying to access, and the query parameters contain the user's search keywords, filter conditions or other important information.
[0100] The request method, such as GET, POST, PUT, DELETE, etc., indicates the user's intention to operate on the resource. For example, the GET method is usually used to request data, while the POST method is used to submit data.
[0101] The request header information includes User-Agent, Referer, Cookies, Accept, etc.
[0102] Among them, User-Agent contains information such as the user's browser type, version, and operating system, which helps to identify the user's device type and browser compatibility.
[0103] Referer (referring page) indicates the URL of the request source, that is, the page from which the user linked. It is helpful for analyzing user behavior paths and preventing malicious requests.
[0104] Cookies contain user session information, preferences, etc., which help maintain user login status or personalized content recommendations.
[0105] Accept (the type of content accepted) indicates the MIME types that the client can handle, which helps to determine the content format that the user expects to receive.
[0106] S41.2. Encode the key features to obtain feature encodings.
[0107] Encoding each key feature is to convert it into a format that the subsequent model can understand; it involves converting text features (such as URLs, header information) into numerical vectors. For the requested URL, a hash function or a custom encoding scheme based on the URL structure can be used to convert the URL into a fixed-length digital vector. For the request method, one-hot encoding or a simple digital mapping (such as GET = 0, POST = 1) can be used for conversion. For the header information, in the form of key-value pairs, each header field can be encoded and then combined into a longer vector; for complex header field values (such as User-Agent strings), further processing is required, such as word segmentation, word embedding, etc.
[0108] S41.3. Combine the feature encodings to obtain a feature vector.
[0109] Furthermore, please refer to Figure 3 , input the request information that needs to be redirected into a pre-established deep learning model to obtain the redirected URL of the relative path, and its steps include:
[0110] S42.1. Use the feature vector as the input of the pre-established deep learning model; wherein, the pre-established deep learning model includes multiple decision trees;
[0111] Specifically, the deep learning model in the embodiments of the present application uses a random forest model. By using the feature vector as the input, the model can utilize the branch structure of the decision tree to traverse and evaluate each dimension of the feature vector step by step, so as to make more accurate predictions.
[0112] S42.2. The decision tree starts from the root node and traverses the feature vector step by step according to the preset splitting criterion until it reaches the leaf node, obtaining multiple prediction results.
[0113] Further, each decision tree represents a possible decision path; these decision trees start from the root node and traverse the feature vector step by step according to the preset splitting criterion (such as Gini impurity, information gain, etc.); during the traversal process, the model will select the corresponding branch according to the value of the feature vector until it reaches the leaf node.
[0114] A leaf node is the end point of a decision tree and contains the final prediction result of the model for the current request. Since the model contains multiple decision trees, multiple prediction results will be obtained. These prediction results will vary due to the different structures and splitting criteria of the decision trees. Together, they constitute a preliminary estimate of the final prediction result, that is, a preliminary estimate of the relative path to which the model should redirect for the current request.
[0115] S42.3. Analyze the multiple prediction results to determine the final prediction result.
[0116] After obtaining multiple prediction results, it is necessary to analyze and integrate these results to determine the final prediction result (the relative path to redirect to). Specifically, it involves weighted averaging, voting, or other forms of aggregation operations on the prediction results. Through these operations, the uncertainty and bias in the prediction results of a single decision tree can be eliminated, and the accuracy and stability of the final prediction result can be improved.
[0117] S42.4. According to the final prediction result, combined with the domain name of the request to be redirected, obtain the redirected URL of the complete relative path.
[0118] After determining the final prediction result, it is necessary to combine the domain name of the request to be redirected to generate the redirected URL of the complete relative path. Specifically, the redirected URL of the complete relative path will be returned as a response to the client browser to guide the user to access the new resource location.
[0119] S5. Perform a hash process on the redirected URL to convert the redirected URL into a hash value of a fixed length.
[0120] Furthermore, in the embodiments of the present application, in order to ensure the security and integrity of the redirected URL and facilitate subsequent processing and verification, a hash process will be performed on the redirected URL.
[0121] The hash process, also known as the hashing process, is a process of converting data of any length into a hash value of a fixed length (or called a digest, hash value). The purposes of performing the hash process in the present application include:
[0122] Data integrity verification: The hash value can be used as a unique and fixed identifier to verify whether the redirected URL has been tampered with during transmission or storage. If the hash value of the original redirected URL does not match the stored or received hash value, it can be inferred that the data may have been tampered with during transmission.
[0123] Secure Storage and Transmission: By converting the redirect URL into a hash value, the amount of data stored and transmitted can be reduced, while enhancing data security. Hash values are generally much shorter than the original data and it is difficult to reverse-engineer the original data from the hash value, thus protecting the privacy of the redirect URL to a certain extent.
[0124] Efficient Retrieval: In large databases or distributed systems, using hash values enables quick retrieval and location of specific redirect URLs. Hash values provide a fast indexing method, allowing the system to find the target record without having to traverse the entire dataset.
[0125] Specifically, select a hash algorithm, which includes SHA-256, MD5, SHA-1, etc.; then, use the hash algorithm to calculate the input redirect URL to obtain a hash value of a fixed length (involving a series of mathematical operations such as bit operations, addition, XOR, etc. to ensure the uniqueness and unpredictability of the hash value).
[0126] S6. Use a consensus mechanism to verify the legitimacy of the hash value of the fixed length.
[0127] Further, please refer to Figure 4 and use a consensus mechanism to verify the legitimacy of the hash value of the fixed length, the steps of which include:
[0128] S61. Transmit the hash value of the fixed length to the blockchain network.
[0129] S62. The verification nodes in the blockchain receive the hash value of the fixed length and broadcast the hash value of the fixed length to other verification nodes in the blockchain network.
[0130] Further, once a verification node receives the hash value, it immediately broadcasts this value to all other verification nodes in the network; this is achieved through the peer-to-peer (P2P) communication protocol in the blockchain network to ensure that each node can obtain the latest data in a timely manner; in addition, during the broadcast process, all verification nodes will update their local databases or states to ensure data consistency across the network.
[0131] S63. Each verification node participating in the verification uses its private key to sign the fixed hash value to obtain a signed hash value and attaches proof information.
[0132] Each verification node will use its own private key to digitally sign the received hash value to ensure the authenticity and immutability of the signature. In addition to the signature, the verification node will also attach some additional proof information such as a timestamp, node ID, signature algorithm, etc. to further enhance the credibility and traceability of the signature.
[0133] S64. Broadcast the hash value of the signature and the proof information to other verification nodes.
[0134] After completing the signature and attaching the proof information, the verification node broadcasts this data to other nodes in the network again; this ensures that each node can obtain the complete signature and proof information.
[0135] S65. The other verification nodes use the consensus algorithm to verify according to the hash value of the signature and the proof information.
[0136] The verification node will use the predefined consensus algorithm (Proof of Stake, PoS) in the blockchain network to verify the signature and proof information, aiming to ensure that all nodes can reach an agreement on the legality of the data. Among them, the verification process includes steps such as checking the validity of the signature, verifying the authenticity of the proof information, and ensuring that the hash value has not been tampered with.
[0137] S66. When the preset consensus ratio is reached, verify that the hash value is legal.
[0138] Specifically, in the blockchain network, a preset consensus ratio (such as 51%, 75%, etc.) will be set to determine when a certain data or transaction can be considered legal.
[0139] Once the preset consensus ratio is reached, it means that enough verification nodes recognize the legality of the hash value; at this time, the entire network will update its state and regard the hash value as verified data.
[0140] S7. If the verification is successful, respond to the access request information for the redirected URL.
[0141] Furthermore, once the legality verification of the hash value is successful, its internal state or cache will be updated to record that the redirected URL is now verified as legal. At this time, respond to the access request information for the redirected URL, pointing to the actual resource to be accessed. If the verification fails, a response message containing an error status code (such as 403 Forbidden, 404 Not Found, or 500 Internal Server Error) will be sent to the user's browser to reject the redirect request.
[0142] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be adopted in other sequences or simultaneously.
[0143] Based on the same idea as one of the HTTPS redirection verification methods in the above embodiments, the present application also provides an HTTPS redirection verification system, which can be used to execute the above-mentioned HTTPS redirection verification method. For the sake of convenience of description, in the structural schematic diagram of an embodiment of the HTTPS redirection verification system, only the parts related to the embodiments of the present application are shown. Those skilled in the art can understand that the illustrated structure does not constitute a limitation on the system, and it may include more or fewer components than those illustrated, or combine certain components, or have different component arrangements.
[0144] Please refer to Figure 5 , in another embodiment of the present application, an HTTPS redirection verification system is provided. The system includes a request information acquisition module 101, a request type judgment module 102, a redirection judgment module 103, a redirection URL generation module 104, a hash processing module 105, a verification module 106, and a response module 107;
[0145] The request information acquisition module 101 is used to acquire the website access request information initiated by the user terminal;
[0146] The request type judgment module 102 is used to judge the request type of the access request information;
[0147] The redirection judgment module 103 is used to judge whether redirection is required according to the request type;
[0148] The redirection URL generation module 104 is used to input the request information that needs to be redirected into a pre-established deep learning model if redirection is required, and obtain a redirection URL with a relative path;
[0149] The hash processing module 105 is used to perform hash processing on the redirection URL and convert the redirection URL into a hash value with a fixed length;
[0150] The verification module 106 is used to verify the legality of the hash value with a fixed length by using a consensus mechanism;
[0151] The response module 107 is used to respond to the access request information of the redirection URL if the verification is successful.
[0152] As a preferred technical solution, the request types of the access request information include: HTTP requests and HTTPS requests.
[0153] As a preferred technical solution, the redirection judgment module 103 is specifically used for:
[0154] If the request type of the access request information is an HTTPS request, it is determined whether redirection is required.
[0155] As a preferred technical solution, it further includes:
[0156] When the request type of the access request information is an HTTP request, an error message is fed back to the user or the access request information is redirected to an HTTPS request.
[0157] As a preferred technical solution, it further includes a processing module, and the processing module is used for:
[0158] Extract the key features of the request that needs to be redirected; wherein, the key features include: the URL of the request, the method of the request, and the header information of the request;
[0159] Encode the key features to obtain a feature encoding;
[0160] Combine the feature encodings to obtain a feature vector.
[0161] As a preferred technical solution, the redirect URL generation module 104 is specifically used for:
[0162] Use the feature vector as the input of the pre-established deep learning model; wherein, the pre-established deep learning model includes multiple decision trees;
[0163] The decision tree starts from the root node and traverses the feature vector step by step according to the preset splitting criterion until it reaches the leaf node, obtaining multiple prediction results;
[0164] Analyze the multiple prediction results to determine the final prediction result;
[0165] According to the final prediction result, combined with the domain name of the request that needs to be redirected, obtain the complete relative path of the redirect URL.
[0166] As a preferred technical solution, the verification module 106 is specifically used for:
[0167] Transmit the fixed-length hash value to the blockchain network;
[0168] The verification node in the blockchain receives the fixed-length hash value and broadcasts the fixed-length hash value to other verification nodes in the blockchain network;
[0169] Each participating verification node signs the fixed hash value with its private key to obtain a signed hash value and attaches proof information;
[0170] Broadcast the hash value of the signature and the proof information to other verification nodes;
[0171] Based on the hash value of the signature and the proof information, the other verification nodes perform verification using a consensus algorithm;
[0172] When the preset consensus ratio is reached, verify that the hash value is legal.
[0173] It should be noted that an HTTPS jump verification system of the present application corresponds one-to-one with an HTTPS jump verification method of the present application. The technical features and beneficial effects described in the embodiments of the above HTTPS jump verification method are applicable to the embodiments of an HTTPS jump verification system. For specific content, refer to the description in the method embodiments of the present application, which will not be elaborated here. This is hereby declared.
[0174] In addition, in the implementation manner of an HTTPS jump verification system in the above embodiments, the logical division of each program module is only an example. In practical applications, according to needs, for example, considering the configuration requirements of the corresponding hardware or the convenience of software implementation, the above functions can be assigned to different program modules to complete, that is, the internal structure of the HTTPS jump verification system is divided into different program modules to complete all or part of the functions described above.
[0175] Please refer to Figure 6 , in another embodiment, an electronic device for implementing an HTTPS jump verification method is provided, including a processor, a memory, and a bus, and may further include a computer program stored in the memory and executable on the processor.
[0176] Exemplarily, in this embodiment, the computer program may be divided into one or more modules. The one or more modules are stored in the memory and executed by the processor to complete the present application. The one or more module elements may be a series of computer program instruction segments capable of performing specific functions, and this instruction segment is used to describe the execution process of the computer program in the device.
[0177] The electronic device may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The device may include, but is not limited to, a processor and a memory.
[0178] In some embodiments, the processor may be composed of an integrated circuit. For example, it may be composed of a single packaged integrated circuit, or may be composed of multiple packaged integrated circuits with the same or different functions, including one or more central processing units (CPUs), and may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the device, connecting all components of the entire device through various interfaces and circuits; by running or executing programs or modules stored in the memory, and calling data stored in the memory, to perform various functions of the electronic device and process data.
[0179] The memory can be used to store the computer programs and / or modules. The processor realizes various functions of the device by running or executing the computer programs and / or modules stored in the memory, and calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; in addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one magnetic disk storage device, flash device, or other volatile solid-state storage devices.
[0180] Among them, in some embodiments, the memory may be an internal storage unit of the electronic device, such as the mobile hard disk of the electronic device. In some other embodiments, the memory may also be an external storage device of the electronic device, such as a plug-in mobile hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the electronic device. Further, the memory may also include both the internal storage unit of the electronic device and the external storage device. The memory can be used not only to store application software installed on the electronic device and various types of data, such as the code of an HTTPS jump verification program, etc., but also to temporarily store data that has been output or will be output.
[0181] Figure 6 Only the electronic device with components is shown. Those skilled in the art can understand that Figure 6 The shown structure does not constitute a limitation on the electronic device, and it may include fewer or more components than shown, or combine some components, or have different component arrangements.
[0182] An HTTPS jump verification program stored in the memory of the electronic device is a combination of multiple instructions. When running in the processor, it can achieve:
[0183] Obtain the website access request information initiated by the client;
[0184] Judge the request type of the access request information;
[0185] Judge whether redirection is needed according to the request type;
[0186] If redirection is needed, input the request information that needs to be redirected into a pre-established deep learning model to obtain the redirected URL of the relative path;
[0187] Perform hash processing on the redirected URL to convert the redirected URL into a hash value of a fixed length;
[0188] Use a consensus mechanism to verify the legality of the hash value of the fixed length;
[0189] If the verification is successful, respond to the access request information of the redirected URL.
[0190] Correspondingly, the present application also provides a computer-readable storage medium. The computer-readable storage medium includes a stored computer program. Among them, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute an HTTPS jump verification method as described in any one of the above embodiments.
[0191] The computer program includes computer program code, which may be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, removable hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), flash memory, removable hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disk, and so on.
[0192] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0193] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0194] The above embodiments are preferred embodiments of the present application, but the embodiments of the present application are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications made without departing from the spirit and principle of the present application shall be equivalent replacement methods and are all included in the protection scope of the present application.
Claims
1. A HTTPS jump verification method, characterized in that: The steps include: Obtain website access request information initiated by the user; Determining a request type of the access request information; Determine whether redirection is required according to the request type; If redirection is required, the request information to be redirected is input into the pre-established deep learning model to obtain the redirection URL of the relative path; Performing hash processing on the redirection URL to convert the redirection URL into a hash value of fixed length; A consensus mechanism is used to verify the legitimacy of the fixed-length hash value; If the verification is successful, a response is made to the access request information of the redirection URL.
2. According to claim 1, a HTTPS jump verification method is characterized in that: The request type of the access request information includes: HTTP requests and HTTPS requests.
3. According to claim 2, a HTTPS jump verification method is characterized in that: The determining whether redirection is required according to the request type includes: If the request type of the access request information is an HTTPS request, it is determined whether redirection is required.
4. According to claim 2, a HTTPS jump verification method is characterized in that: Also includes: If the request type of the access request information is an HTTP request, an error message is fed back to the user or the access request information is redirected to an HTTPS request.
5. According to claim 1, a HTTPS jump verification method is characterized in that: The method further includes processing the request that needs to be redirected, including: Extracting key features of the request that needs to be redirected; wherein the key features include: requested URL, requested method, and requested header information; Encoding the key features to obtain feature codes; The feature codes are combined to obtain a feature vector.
6. According to claim 5, a HTTPS jump verification method is characterized in that: The request information to be redirected is input into a pre-established deep learning model to obtain a redirection URL of a relative path, including: Using the feature vector as input of the pre-established deep learning model; wherein the pre-established deep learning model includes a plurality of decision trees; The decision tree starts from the root node and traverses the feature vector level by level according to the preset splitting criterion until it reaches the leaf node to obtain multiple prediction results; Analyze the multiple prediction results to determine a final prediction result; According to the final prediction result, combined with the domain name of the request that needs to be redirected, a redirection URL with a complete relative path is obtained.
7. According to claim 1, a HTTPS jump verification method is characterized in that: The consensus mechanism is used to verify the legitimacy of the fixed-length hash value, including: Transmitting the fixed-length hash value to the blockchain network; The verification node in the blockchain receives the fixed-length hash value and broadcasts the fixed-length hash value to other verification nodes in the blockchain network; Each verification node participating in the verification signs the fixed hash value using a private key to obtain a signed hash value and attaches proof information; Broadcasting the hash value of the signature and the certification information to other verification nodes; The other verification nodes perform verification using a consensus algorithm based on the hash value of the signature and the proof information; When the preset consensus ratio is reached, the hash value is verified to be legal.
8. An HTTPS jump verification system, characterized in that: It includes a request information acquisition module, a request type judgment module, a redirection judgment module, a redirection URL generation module, a hash processing module, a verification module and a response module; The request information acquisition module is used to acquire website access request information initiated by the user terminal; The request type determination module is used to determine the request type of the access request information; The redirection determination module is used to determine whether redirection is required according to the request type; The module for generating a redirection URL is used to input the request information to be redirected into a pre-established deep learning model if redirection is required, and obtain a redirection URL of a relative path; The hash processing module is used to perform hash processing on the redirection URL to convert the redirection URL into a hash value of fixed length; The verification module is used to verify the legitimacy of the fixed-length hash value using a consensus mechanism; The response module is used to respond to the access request information of the redirection URL if the verification is successful.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores computer program instructions that can be executed by the at least one processor, and the computer program instructions are executed by the at least one processor so that the at least one processor can execute an HTTPS protection verification method as described in any one of claims 1-7.
10. A computer-readable storage medium storing a program, characterized in that: When the program is executed by the processor, an HTTPS jump verification method as described in any one of claims 1-7 is implemented.