Security verification system and method for web application
The hardware information of the device is obtained through the hardware fingerprint plug-in and generated hardware fingerprints. The secondary authorization verification is carried out in combination with the P12 certificate, which solves the security problem of the web application security verification system in identity identification and achieves higher information security guarantees.
Patent Information
- Application Number
- CN202510758411.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-09
AI Technical Summary
The existing web application security verification system cannot effectively identify the user's identity when the user's account password is leaked or the sessionId/token is intercepted, resulting in low security.
Use the hardware fingerprint plug-in to obtain the device hardware information, generate the hardware fingerprint, and when the authorization verification fails, apply for the P12 certificate to the application server through the proxy server for secondary authorization verification, and combine the hardware fingerprint and the P12 certificate for encryption verification.
Improves the security of web applications, prevents attackers from forging hardware fingerprints, and enhances information security protection, especially when sessions or tokens are intercepted.
Smart Images

Figure CN120281582A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technologies, and particularly to a security verification system and method for web applications. Background Art
[0002] With the development of Internet technologies, web applications have penetrated into all aspects of people's lives and become an indispensable part. However, due to the openness and complexity of web applications, as well as the dynamic changes in the network environment, they face various security threats.
[0003] When facing security threats, conventional security verification is usually based on sessions or tokens. In the case of the leakage of user account passwords, this method cannot achieve identity recognition. In the case where the session ID or token is intercepted, an attacker may operate under a fake user identity. Summary of the Invention
[0004] The main objective of this application is to provide a security verification system and method for web applications, aiming to solve the technical problem of the relatively low security factor in existing web application security verification.
[0005] To achieve the above objective, this application proposes a security verification system for web applications. The system includes: a client, a proxy server, and an application server; The client is used to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails; The client is further used to initiate a certificate request based on the hardware fingerprint, and a request approval process is performed when the administrator receives the certificate request; The client is further used to obtain a second security verification certificate generated based on the hardware fingerprint when the request approval process passes; The proxy server is further used to send a second login request generated based on the second security verification certificate to the application server.
[0006] In one embodiment, the proxy server is further used to send a first login request to the application server; The application server is used to obtain the first login request information in the first login request, and the first login request information includes at least first login information; The application server is further used to perform a login verification based on the first login information; The application server is further used to perform an authorization verification based on the first security verification certificate when the login verification passes.
[0007] In one embodiment, a hardware fingerprint plug-in is installed in the client; The hardware fingerprint plug-in is used to periodically obtain the hardware information of the client and record the information acquisition timestamp when the hardware information is obtained; The hardware fingerprint plug-in is further used to encrypt based on the hardware information of the current time period and the information acquisition timestamp to obtain the hardware fingerprint when receiving the hardware fingerprint request from the client; The hardware fingerprint plug-in is also used to return the hardware fingerprint to the client.
[0008] In one embodiment, the client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0009] In one embodiment, the hardware fingerprint plug-in is further used to apply to the client for hardware information access permission; The hardware fingerprint plug-in is also used to periodically obtain the hardware information of the client when the application is approved.
[0010] In addition, to achieve the above purpose, the present application also proposes a web application security verification method, which is applied to the web application security verification system as described above, and the method includes: When the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint; The client initiates a certificate application request based on the hardware fingerprint, and when the administrator receives the certificate application request, a request approval process is performed; When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint; The proxy server sends a second login request generated based on the second security verification certificate to the application server.
[0011] In one embodiment, when the authorization verification of the first security verification certificate in the first login request fails, the client further includes, before the step of obtaining the hardware fingerprint: The proxy server is further configured to send a first login request to the application server; The application server is configured to obtain first login request information in the first login request, where the first login request information at least includes first login information, and the first login request further includes a first security verification certificate; The application server is further configured to perform login verification based on the first login information; The application server is further configured to perform an authorization check based on the first security check certificate when the login check passes.
[0012] In one embodiment, a hardware fingerprint plugin is installed in the client; the method further includes: The hardware fingerprint plugin periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained. When the hardware fingerprint plugin receives a hardware fingerprint request from the client, it encrypts based on the hardware information and the information acquisition timestamp in the current time period to obtain a hardware fingerprint. The hardware fingerprint plugin returns the hardware fingerprint to the client.
[0013] In one embodiment, when the authorization check of the first security check certificate in the first login request fails in the client, the step of obtaining the hardware fingerprint includes: The client is further configured to send a hardware fingerprint request to the hardware fingerprint plugin to obtain a hardware fingerprint when the authorization check of the first security check certificate in the first login request fails.
[0014] Before the step that the hardware fingerprint plugin periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained, the method further includes: The hardware fingerprint plugin applies to the client for hardware information access permission. When the application is approved, the hardware fingerprint plugin periodically obtains the hardware information of the client.
[0015] In addition, to achieve the above object, the present application further provides a security check device for a web application, the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program is configured to implement the steps of the security check method for the web application as described above.
[0016] In addition, to achieve the above object, the present application further provides a storage medium, the storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the security check method for the web application as described above.
[0017] In addition, to achieve the above object, the present application further provides a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps of the security check method for the web application as described above.
[0018] One or more technical solutions proposed by the present application have at least the following technical effects: The security verification system of the web application of the present application includes: a client, a proxy server, and an application server; when the authorization verification of the first security verification certificate in the first login request fails on the client, the hardware fingerprint is obtained; the client initiates a certificate request based on the hardware fingerprint, and when the administrator receives the certificate request, a request approval process is carried out; when the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint; the proxy server sends a second login request generated based on the second security verification certificate to the application server. Since the security verification certificate covers the user's hardware fingerprint, it has natural immunity to common network request attack methods. Even if the attacker obtains the session or token, they still cannot forge the hardware fingerprint. Even if they obtain the hardware fingerprint, they cannot obtain the security verification certificate installed on the user's client. Therefore, there is strong information security protection. At the same time, through the security verification certificate and the proxy server, the certificate content carried by the browser can be directly forwarded to the application server. Since this forwarding only occurs on the application server, the attacker cannot obtain it through external request interception, further improving the security. Brief Description of the Drawings
[0019] The drawings herein are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0020] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0021] Figure 1 It is a schematic diagram of functional modules provided for Embodiment 1 of the security verification method of the web application of the present application; Figure 2 It is a schematic flowchart provided for Embodiment 2 of the security verification method of the web application of the present application; Figure 3 It is a schematic flowchart provided for Embodiment 3 of the security verification method of the web application of the present application; Figure 4 It is a schematic flowchart of the security verification method of the web application in the embodiment of the present application.
[0022] The implementation, functional features, and advantages of the object of the present application will be further described with reference to the embodiments and the drawings. Detailed Embodiments
[0023] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0024] To better understand the technical solutions of the present application, the following will be described in detail in conjunction with the accompanying drawings of the specification and specific implementation manners.
[0025] In some implementation manners, banks often use U shield technology to ensure the security factor, but the cost is too high and it is inconvenient to carry. If the U shield is damaged or accidentally lost, the basic verification operation cannot be completed, and the management cost is relatively high.
[0026] The present application provides a solution, which, compared with other common verification methods, solves the pain points in security verification. While ensuring high security, it achieves good scalability and manageability, greatly improving the user experience.
[0027] Based on this, the embodiments of the present application provide a security verification system for a web application. Refer to Figure 1 , Figure 1 which is a schematic diagram of the function modules provided in the first embodiment of the security verification system for the web application of the present application.
[0028] As Figure 1 shown, in the embodiments of the present application, the security verification system for the web application includes: a client, a proxy server, and an application server; The client is used to obtain a hardware fingerprint when the authorization verification of the first security verification certificate fails in the first login request; The client is further used to initiate a certificate request based on the hardware fingerprint, and perform a request approval process when the administrator receives the certificate request; The client is further used to obtain a second security verification certificate generated based on the hardware fingerprint when the request approval process passes; The proxy server is further used to send a second login request generated based on the second security verification certificate to the application server.
[0029] It should be noted that the above client can be a software program or environment running on the user's device for interacting with the application server. The user client sends requests to the application server through the client and receives and displays the data returned by the application server.
[0030] It should be explained that the above proxy server is also an intermediate server located between the client and the application server. As a communication bridge between the client and the application server, it can receive the requests of the client and forward the requests to the target server.
[0031] It should be noted that the above application server can be a server for processing requests from clients. The application server can receive the requests forwarded by the proxy server, and according to the type and content of the requests, call the corresponding application programs or functional modules for processing, and return the request results obtained from the processing to the client.
[0032] It can be understood that the login request can be a specific type of request sent by the client to the application server, used to let the application server verify the login information provided by the client to determine whether the client user has the permission to access the characteristic system resources or functions. Generally speaking, the login request can include information such as the username and password for authentication. The login request in the embodiments of the present application can also include parameters such as a security verification certificate.
[0033] It should be noted that the "first" and "second" in the embodiments of the present application are only used to distinguish different technical terms, and do not represent that they have different functions or content parameters.
[0034] It should be explained that the above security verification certificate is a certificate used to perform security verification on the login request of the client. This security verification certificate can be used to verify whether the client logging in to the application server is the client of the user.
[0035] In some implementation manners of the embodiments of the present application, since the P12 certificate has good compatibility on multiple browsers and multiple systems, after the user installs it, it can be automatically carried by the browser in the tls handshake, and has good usability. Therefore, the security verification certificate used in the embodiments of the present application can be a P12 certificate. The P12 certificate is a digital certificate based on the public key infrastructure, and it usually can contain one or more encrypted private keys and associated X.509 certificates. The private key is used to sign and decrypt data, while the X.509 certificate is used for authentication, digital signature, and secure communication.
[0036] It should be noted that the above authorization verification can be performed based on the above security verification certificate. When the authorization verification passes, the client is granted login authorization; when the authorization verification fails, the client is not granted login authorization.
[0037] In some implementation manners of the embodiments of the present application, the situations where the above authorization verification fails can include: the security verification certificate is not included in the login request, the security verification certificate of the login request has expired, and the client corresponding to the security verification certificate of the login request is not the user client.
[0038] It should be noted that the hardware fingerprint is obtained by an installable hardware fingerprint plugin written in a front - end development language and adapted to common operating systems such as Mac and Windows. The role of this hardware fingerprint plugin is to collect, analyze, and process the hardware information of the device where the current system is located under the authorization of the user (which can be achieved through the front - end service FE of the client to interact with the user), and generate a unique identification code that can uniquely identify a device. Usually, it can be jointly encrypted by a series of parameters with unique hardware identification such as CPU serial number, hard disk serial number, memory, MAC, etc., and a timestamp. The hardware fingerprint has uniqueness and stability and can be used to identify and distinguish different hardware devices in the digital world. When the authorization verification of the first security verification certificate in the first login request fails, the client can obtain the hardware fingerprint of the device and initiate a certificate request for applying for the security verification certificate based on this hardware fingerprint.
[0039] It can be understood that the above - mentioned administrator can be the client or the management user for the certificate request, and this management user can be responsible for managing the issuance of the security verification certificate.
[0040] In some implementation manners of the embodiments of the present application, the P12 certificate can be issued by a certificate authority or self - signed by an individual or an organization. A self - signed certificate is only trusted by the signer, while a certificate issued by a CA can be trusted by the public. The P12 certificate usually has an extension of.pl2 or.pfx, which are collectively referred to as P12 certificates in this application.
[0041] In practical applications, when the client conducts a TLS handshake with the application server, the P12 certificate can be obtained from the application server.
[0042] In some implementation manners of the embodiments of the present application, when the request approval process passes, the client can obtain the second security verification certificate generated based on the hardware fingerprint. When obtaining the second security verification certificate, the second login request generated based on this second security verification certificate can be sent to the application server through the proxy server for another authorization verification.
[0043] In some implementation manners of the embodiments of the present application, when logging in, the hardware fingerprint can also be used as part of the login information to conduct security verification together with the security verification certificate. Since the security verification certificate also carries the hardware fingerprint, through the comparison and verification of the security verification certificate and the hardware fingerprint, the role of encryption verification can be achieved.
[0044] The security verification system of the web application in the embodiment of the present application includes: a client, a proxy server, and an application server; when the authorization verification of the first security verification certificate in the first login request fails on the client, the client obtains the hardware fingerprint; the client initiates a certificate request based on the hardware fingerprint, and when the administrator receives the certificate request, a request approval process is carried out; when the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint; the proxy server sends a second login request generated based on the second security verification certificate to the application server. Since the security verification certificate covers the user's hardware fingerprint, it has natural immunity to common network request attack methods. Even if the attacker obtains the session or token, they still cannot forge the hardware fingerprint. Even if they obtain the hardware fingerprint, they cannot obtain the security verification certificate installed on the user's client. Therefore, strong information security protection is provided. At the same time, through the security verification certificate and the proxy server, the certificate content carried by the browser can be directly forwarded to the application server. Since this forwarding only occurs on the application server, the attacker cannot obtain it through external request interception, further improving the security.
[0045] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 2 , Figure 2 which is a schematic flow chart provided for the second embodiment of the security verification system of the web application of the present application.
[0046] Refer to Figure 2 In the embodiment of the present application, the proxy server is further configured to send a first login request to the application server; The application server is configured to obtain the first login request information in the first login request, where the first login request information includes at least first login information, and the first login request further includes a first security verification certificate; The application server is further configured to perform a login verification based on the first login information; The application server is further configured to perform an authorization verification based on the first security verification certificate when the login verification passes.
[0047] It should be noted that when the user needs to log in to the application server, a first login request can be sent to the application server through the proxy server. The first login request can include first login request information. The application server can improve security by performing a security verification on the first login information. The first login request information can include first login information (such as username, password, etc.), and the first login request can further include a first security verification certificate.
[0048] In the embodiments of the present application, the above security verification process may include login verification and authorization verification. Specifically, the application server may perform login verification based on the first login information. By performing login verification on the first login information, it can be verified whether the user's login information is correct, such as verifying whether the username and password match. When the login verification passes, it can be further determined based on whether the first security verification certificate is included in the first login request and whether the first security verification certificate is legal, that is, performing authorization verification on the first security verification certificate.
[0049] In some embodiments of the present application, for the authorization verification process of whether the above security verification certificate is legal, it may include timeliness verification and hardware fingerprint verification. Through timeliness verification, it can be determined whether the security verification certificate is within the valid period; through hardware fingerprint verification, it can be determined whether the login request comes from the user device. The user device may be a whitelist device set by the user himself or a whitelist device determined based on the user's frequently used login devices. The embodiments of the present application do not limit this.
[0050] It should be noted that the above valid period may be the same as the timing period for the hardware fingerprint plugin to obtain the hardware information of the client. The embodiments of the present application do not limit this.
[0051] In some embodiments of the present application, the client is further configured to send a hardware fingerprint request to the hardware fingerprint plugin to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0052] It should be noted that the hardware fingerprint may be generated and sent by the hardware fingerprint plugin, or actively obtained by the client when the authorization verification fails. The embodiments of the present application do not limit this.
[0053] In some embodiments of the present application, the application server may obtain the hardware fingerprint carried in the current login request and perform authorization verification on the security verification certificate information forwarded by the proxy server. If the authorization verification fails, the user may initiate a certificate request carrying the hardware fingerprint. When the administrator receives the certificate request, the administrator may approve the user's certificate request. When the approval of the certificate request passes, the user may input the certificate password. Through the hardware fingerprint and the certificate password input by the user, a security verification certificate may be generated. At this time, a corresponding relationship of user - hardware fingerprint - certificate will be formed. The user may obtain the generated security verification certificate and download it to the client of the current login request. When downloading and installing the security verification certificate, the certificate password input during the pre - application needs to be input, and the installation can continue only when the password verification is correct.
[0054] It should be noted that when the security verification certificate is installed, since the certificate pre-matched with the server has been installed, the browser can pop up a certificate selection window at this time. After selecting the security verification certificate of the corresponding user, a second login request is initiated again. When the username and password in the second login request pass the verification, the authorization verification of user-hardware fingerprint-certificate can be performed, and successful login can be achieved when the authorization verification is completed.
[0055] In some embodiments of the embodiments of the present application, when successfully logged in, subsequent requests will follow the above security verification process, except that the user information is carried by the token in the request.
[0056] In some embodiments of the embodiments of the present application, when the security verification certificate is installed, the browser can be restarted. After restarting the browser, a certificate selection window pops up again for certificate selection.
[0057] The embodiment of the present application sends a first login request to the application server through the proxy server; the application server obtains the first login request information in the first login request, and the first login request information includes at least the first login information; the application server performs login verification based on the first login information; when the login verification passes, the application server performs authorization verification based on the first security verification certificate. Since it is necessary to bind the hardware fingerprint of the user device and the user when the client applies for the security verification certificate to the application server, it ensures the correspondence of one person, one machine, and one code. By borrowing the built-in security mechanism of the browser, the P12 certificate is obtained during the tls handshake encryption, and the proxy server forwards the encrypted content of the certificate. Through the comparison and verification of the certificate and the hardware fingerprint, the role of encryption verification is played.
[0058] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the content that is the same as or similar to the above-mentioned embodiment one and / or embodiment two can be referred to the above introduction, and will not be elaborated hereinafter. On this basis, please refer to Figure 3 , Figure 3 which is the flow schematic diagram provided by the third embodiment of the security verification system of the web application of the present application.
[0059] In the embodiment of the present application, a hardware fingerprint plugin is installed in the client; The hardware fingerprint plugin is used to regularly obtain the hardware information of the client and record the information acquisition timestamp when the hardware information is obtained; The hardware fingerprint plugin is further used to encrypt based on the hardware information and the information acquisition timestamp in the current time period when receiving the hardware fingerprint request of the client to obtain a hardware fingerprint; The hardware fingerprint plugin is further used to return the hardware fingerprint to the client.
[0060] It should be noted that in the embodiments of the present application, an installable hardware fingerprint plugin is used to bypass the browser. With the user's authorization, the hardware information of the user device is obtained, and encryption is performed in cooperation with the timestamp. Since the timestamp is carried, it ensures that each encrypted hardware fingerprint has a validity period and cannot be used for a long time. When the client applies for a P12 certificate from the application server, it needs to be bound to the current hardware fingerprint and the user, thereby generating a one-to-one correspondence of one person, one device, and one code. Through the built-in security mechanism of the browser, the P12 certificate is obtained during the tls handshake encryption, and the proxy server forwards the encrypted content of the certificate. Through the comparison and verification of the certificate and the hardware fingerprint, the role of encryption verification is achieved.
[0061] It should be explained that since the P12 certificate contains the hardware fingerprint of the user, it has natural immunity to common network request attack methods. Even if the attacker obtains the session or token, they still cannot forge the hardware fingerprint. Even if they obtain the hardware fingerprint, they cannot obtain the P12 certificate installed on the user's client. Therefore, strong information security protection is provided. At the same time, since the P12 certificate is used, through proxy services such as nginx, the certificate content carried by the browser is directly forwarded to the application server. Since this forwarding only occurs on the application server, attackers cannot obtain it through external request interception, further improving security. In addition, the P12 certificate has good compatibility on various browsers and various systems. After the user installs it, the browser can automatically carry it during the tls handshake, with good usability.
[0062] In some embodiments of the embodiments of the present application, when the hardware fingerprint plugin is installed, the hardware fingerprint plugin can be started to apply to the user for access rights to the hardware information. After the user confirms and passes, the hardware fingerprint plugin will start and be minimized to the background of the user system. The hardware fingerprint plugin can open a specified port to wait for application calls and periodically obtain the hardware information of the user device where the client is located. That is, the hardware fingerprint plugin is also used to apply to the client for access rights to the hardware information; the hardware fingerprint plugin is also used to periodically obtain the hardware information of the client when the application is passed.
[0063] It should be noted that when the user opens the browser, since the application server enables the certificate verification mode, if the corresponding P12 certificate of the currently accessed application server is installed, the browser will pop up a certificate selection window for the user. The client application can obtain the hardware fingerprint request of the current client through the specified port and the plugin periodically.
[0064] In some implementations of the embodiments of the present application, when the hardware fingerprint plug-in obtains a hardware fingerprint request, it can asymmetrically encrypt the current user's hardware information and the timestamp of the current request to generate a hardware fingerprint, and return the result to the client.
[0065] In the embodiment of the present application, a hardware fingerprint plug-in is installed in the client; the hardware fingerprint plug-in periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained; when the hardware fingerprint plug-in receives the hardware fingerprint request from the client, it encrypts the hardware information and the information acquisition timestamp of the current time period to obtain the hardware fingerprint; the hardware fingerprint plug-in returns the hardware fingerprint to the client. Since the hardware fingerprint information carries a timestamp, it is guaranteed that the hardware fingerprint after each encryption cannot be used all the time; at the same time, since the hardware fingerprint is used for security verification, it has a natural immunity against common network request attacks, and the attacker cannot forge the hardware fingerprint even if he obtains the session or token. Even if the hardware fingerprint is obtained, the P12 certificate installed on the user client cannot be obtained, so there is a strong information security guarantee.
[0066] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the security verification method of the web application of the present application. More simple transformations based on this technical concept are all within the protection scope of the present application.
[0067] The present application also provides a web application security verification method, which is used in the web application security verification system as described above. Figure 4 , Figure 4 The following is a flow chart of a method for verifying the security of a web application according to an embodiment of the present application. The method for verifying the security of a web application includes: Step S10, when the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint; Step S20, the client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request; Step S30, when the request approval process is passed, the client obtains a second security verification certificate generated based on the hardware fingerprint; Step S40: The proxy server sends a second login request generated based on the second security verification certificate to the application server.
[0068] In some implementations of the embodiments of the present application, when the authorization verification of the first security verification certificate in the first login request fails, before the step of obtaining the hardware fingerprint, the client further includes: The proxy server is further configured to send a first login request to the application server; The application server is configured to obtain first login request information in the first login request, where the first login request information at least includes first login information, and the first login request further includes a first security verification certificate; The application server is further configured to perform a login verification based on the first login information; The application server is further configured to perform an authorization verification based on the first security verification certificate when the login verification is passed.
[0069] In some embodiments of the embodiments of the present application, a hardware fingerprint plugin is installed in the client; the method further includes: The hardware fingerprint plugin periodically obtains hardware information of the client and records an information acquisition timestamp when the hardware information is obtained; When the hardware fingerprint plugin receives a hardware fingerprint request from the client, it encrypts based on the hardware information and the information acquisition timestamp in the current time period to obtain a hardware fingerprint; The hardware fingerprint plugin returns the hardware fingerprint to the client.
[0070] In some embodiments of the embodiments of the present application, when the authorization verification of the first security verification certificate in the first login request by the client fails, the step of obtaining a hardware fingerprint includes: The client is further configured to send a hardware fingerprint request to the hardware fingerprint plugin to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0071] Before the step where the hardware fingerprint plugin periodically obtains hardware information of the client and records an information acquisition timestamp when the hardware information is obtained, the method further includes: The hardware fingerprint plugin applies to the client for hardware information access permission; When the application is approved, the hardware fingerprint plugin periodically obtains hardware information of the client.
[0072] The security verification method of the web application provided by the present application adopts the security verification system of the web application in the above embodiments, which can solve the technical problem of the low security factor of the existing web application security verification. Compared with the prior art, the beneficial effects of the security verification method of the web application provided by the present application are the same as those of the security verification system of the web application provided by the above embodiments, and other technical features in the security verification method of the web application are the same as those disclosed in the above embodiment system, and will not be elaborated here.
[0073] The present application provides a security verification device for a web application. The security verification device for a web application includes: at least one processor; and a memory communicatively connected to the at least one processor. Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the security verification method for a web application in Embodiment 1 above.
[0074] The security verification device for a web application in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description: tablet computers), PMPs (Portable Media Player: portable multimedia players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. The security verification device for a web application as described above is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0075] In the embodiments of the present application, the security verification device for a web application may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) or a program loaded from a storage device into a random access memory (RAM: Random Access Memory). In the RAM, various programs and data required for the operation of the security verification device for a web application are also stored. The processing device, the ROM, and the RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus. Generally, the following systems may be connected to the I / O interface: input devices including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; storage devices including, for example, magnetic tapes, hard disks, etc.; and communication devices. The communication device may allow the security verification device for a web application to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a security verification device for a web application having various systems, it should be understood that it is not required to implement or have all the systems shown. Instead, more or fewer systems may be implemented or had.
[0076] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0077] The security verification device for a web application provided by the present application adopts the security verification method for a web application in the above-mentioned embodiment, and can solve the technical problem of the relatively low security factor of the existing web application security verification. Compared with the prior art, the beneficial effects of the security verification device for a web application provided by the present application are the same as those of the security verification method for a web application provided by the above-mentioned embodiment, and other technical features in the security verification device for a web application are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.
[0078] It should be understood that each part disclosed in the present application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0079] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0080] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the security verification method for a web application in the above-mentioned embodiment.
[0081] The computer-readable storage medium provided by the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0082] The above computer-readable storage medium may be included in the security verification device of the web application; or it may exist independently without being assembled into the security verification device of the web application.
[0083] The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the security verification device of the web application, the security verification device of the web application is caused to: When the authorization verification of the first security verification certificate in the first login request fails for the client, obtain the hardware fingerprint; The client initiates a certificate request based on the hardware fingerprint, and when the administrator receives the certificate request, a request approval process is carried out; When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint; The proxy server sends a second login request generated based on the second security verification certificate to the application server.
[0084] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN: Local Area Network) or a wide area network (WAN: Wide Area Network), or it can be connected to an external computer (for example, by connecting through an Internet service provider using the Internet).
[0085] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of the code, and this module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0086] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0087] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the above-mentioned security verification method of the web application, and can solve the technical problem of the low security factor of the existing web application security verification. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the security verification method of the web application provided in the above embodiments, and will not be elaborated here.
[0088] The present application also provides a computer program product, including a computer program which, when executed by a processor, implements the steps of the security verification method for a web application as described above.
[0089] The computer program product provided by the present application can solve the technical problem of the low security factor in the existing security verification of web applications. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the security verification method for a web application provided in the above embodiment, and will not be elaborated here.
[0090] The above are only some embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.
Claims
1. A security verification system for web applications, characterized in that, The system includes: a client, a proxy server, and an application server; The client is configured to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails; The client is further configured to initiate a certificate request based on the hardware fingerprint, and perform a request approval process when the administrator receives the certificate request; The client is further configured to obtain a second security verification certificate generated based on the hardware fingerprint when the request approval process passes; The proxy server is further configured to send a second login request generated based on the second security verification certificate to the application server.
2. The security verification system for a web application according to claim 1, wherein The proxy server is further configured to send a first login request to the application server; The application server is configured to obtain the first login request information in the first login request, and the first login request information includes at least first login information; The application server is further configured to perform a login verification based on the first login information; The application server is further configured to perform an authorization verification based on the first security verification certificate when the login verification passes.
3. The security verification system for a web application according to claim 2, wherein A hardware fingerprint plugin is installed in the client; The hardware fingerprint plugin is configured to periodically obtain the hardware information of the client and record the information acquisition timestamp when the hardware information is obtained; The hardware fingerprint plugin is further configured to encrypt based on the hardware information and the information acquisition timestamp in the current time period to obtain a hardware fingerprint when receiving a hardware fingerprint request from the client; The hardware fingerprint plugin is further configured to return the hardware fingerprint to the client.
4. The security verification system for a web application according to claim 3, wherein, The client is further configured to send a hardware fingerprint request to the hardware fingerprint plugin to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
5. The security verification system for a web application according to claim 3, characterized in that, The hardware fingerprint plugin is further configured to apply for hardware information access rights from the client; The hardware fingerprint plugin is further configured to periodically obtain the hardware information of the client when the application is approved.
6. A security verification method for a web application, characterized in that, The method is applied to the security verification system for a web application according to any one of claims 1-5, and the method includes: The client obtains a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails; The client initiates a certificate request based on the hardware fingerprint, and performs a request approval process when the administrator receives the certificate request; The client obtains a second security verification certificate generated based on the hardware fingerprint when the request approval process passes; The proxy server sends a second login request generated based on the second security verification certificate to the application server.
7. The security verification method for a web application according to claim 6, wherein, Before the step that the client obtains a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails, the method further includes: The proxy server is further configured to send a first login request to the application server; The application server is configured to obtain first login request information in the first login request, where the first login request information includes at least first login information, and the first login request further includes a first security verification certificate; The application server is further configured to perform a login verification based on the first login information; The application server is further configured to, when the login verification is passed, perform an authorization verification based on the first security verification certificate.
8. The security verification method for a web application as claimed in claim 7, wherein, A hardware fingerprint plugin is installed in the client; The method further includes: The hardware fingerprint plugin periodically obtains hardware information of the client and records an information acquisition timestamp when the hardware information is obtained; When the hardware fingerprint plugin receives a hardware fingerprint request from the client, it encrypts based on the hardware information and the information acquisition timestamp in the current time period to obtain a hardware fingerprint; The hardware fingerprint plugin returns the hardware fingerprint to the client.
9. The security verification method of the web application according to claim 8, characterized in that, When the authorization verification of the first security verification certificate in the first login request by the client fails, the steps of obtaining the hardware fingerprint include: The client is further configured to, when the authorization verification of the first security verification certificate in the first login request fails, send a hardware fingerprint request to the hardware fingerprint plugin to obtain a hardware fingerprint.
10. The security verification method of the web application according to claim 8, wherein Before the step where the hardware fingerprint plugin periodically obtains hardware information of the client and records an information acquisition timestamp when the hardware information is obtained, it further includes: The hardware fingerprint plugin applies to the client for hardware information access permission; When the application is approved, the hardware fingerprint plugin periodically obtains hardware information of the client.
Citation Information
Patent Citations
User certificate obtaining method and device and terminal equipment
CN112311766A
Method and system for enhancing data security of computer system
CN112434270A
Security authentication method and related equipment
CN112491776A
Communication security protection method, server and system for intelligent cabin
CN113162921A
Data communication method and device, electronic equipment and storage medium
CN113672897A