Web application security verification system and method
By obtaining the hardware fingerprint through the client and generating a second security verification certificate, the low security factor problem of the web application security verification system is solved, the security verification of the binding of the hardware fingerprint and the user device is realized, and the information security protection and ease of use are improved.
Patent Information
- Application Number
- CN202510758411.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-06-09
AI Technical Summary
The existing web application security verification system has a low security factor and cannot effectively prevent identity forgery attacks when the sessionId or token is intercepted.
The client obtains the hardware fingerprint, initiates a certificate request, passes the administrator's approval process, generates a second security verification certificate, and sends it to the application server for authorization verification by the proxy server. Combined with the P12 certificate, it is automatically carried in the TLS handshake and the certificate content is forwarded through the proxy server to ensure that the hardware fingerprint is bound to the user device.
It improves information security and has natural immunity against common network request attacks. Attackers cannot forge hardware fingerprints, further enhancing security and ease of use.
Smart Images

Figure CN120281582B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication security technology, and in particular to a security verification system and method for web applications. Background Art
[0002] With the development of Internet technology, web applications have penetrated into every aspect of people's lives and become an indispensable part. However, due to the openness and complexity of web applications, as well as the dynamic changes in the network environment, they face a variety of security threats.
[0003] When facing security threats, conventional security verification is usually based on session or token. This method cannot achieve identity recognition when the user account and password are leaked. If the session ID or token is intercepted, the attacker may impersonate the user to perform operations. Summary of the Invention
[0004] The main purpose of this application is to provide a web application security verification system and method, aiming to solve the technical problem of low security factor of existing web application security verification.
[0005] To achieve the above objectives, the present application proposes a web application security verification system, the system comprising: a client, a proxy server and an application server;
[0006] The client is configured to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails;
[0007] The client is further configured to initiate a certificate application request based on the hardware fingerprint, and to perform a request approval process when the administrator receives the certificate application request;
[0008] The client is further configured to obtain a second security verification certificate generated based on the hardware fingerprint when the request approval process passes;
[0009] The proxy server is further configured to send a second login request generated based on the second security verification certificate to the application server.
[0010] In one embodiment, the proxy server is further configured to send a first login request to the application server;
[0011] The application server is configured to obtain first login request information in the first login request, where the first login request information at least includes first login information;
[0012] The application server is further configured to perform login verification based on the first login information;
[0013] The application server is further configured to perform authorization verification based on the first security verification certificate when the login verification passes.
[0014] In one embodiment, a hardware fingerprint plug-in is installed in the client;
[0015] The hardware fingerprint plug-in is used to periodically obtain the hardware information of the client and record the information acquisition timestamp when the hardware information is obtained;
[0016] The hardware fingerprint plug-in is further configured to, upon receiving a hardware fingerprint request from the client, encrypt the hardware information of the current time period and the information acquisition timestamp to obtain a hardware fingerprint;
[0017] The hardware fingerprint plug-in is further configured to return the hardware fingerprint to the client.
[0018] In one embodiment, the client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0019] In one embodiment, the hardware fingerprint plug-in is further used to apply to the client for hardware information access permission;
[0020] The hardware fingerprint plug-in is further used to periodically obtain the hardware information of the client when the application is approved.
[0021] In addition, to achieve the above-mentioned purpose, the present application also proposes a web application security verification method, which is applied to the web application security verification system as described above, and the method includes:
[0022] When the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint;
[0023] The client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request;
[0024] When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint;
[0025] The proxy server sends a second login request generated based on the second security verification certificate to the application server.
[0026] In one embodiment, when the authorization verification of the first security verification certificate in the first login request fails, the client further includes, before the step of obtaining the hardware fingerprint:
[0027] The proxy server is further configured to send a first login request to the application server;
[0028] The application server is configured to obtain first login request information in the first login request, where the first login request information includes at least first login information and further includes a first security verification certificate;
[0029] The application server is further configured to perform login verification based on the first login information;
[0030] The application server is further configured to perform authorization verification based on the first security verification certificate when the login verification passes.
[0031] In one embodiment, a hardware fingerprint plug-in is installed in the client; and the method further includes:
[0032] The hardware fingerprint plug-in periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained;
[0033] When the hardware fingerprint plug-in receives the hardware fingerprint request from the client, it encrypts the hardware information of the current time period and the information acquisition timestamp to obtain the hardware fingerprint;
[0034] The hardware fingerprint plug-in returns the hardware fingerprint to the client.
[0035] In one embodiment, when the authorization verification of the first security verification certificate in the first login request fails, the step of obtaining the hardware fingerprint by the client includes:
[0036] The client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0037] In one embodiment, before the step of the hardware fingerprint plug-in periodically acquiring the hardware information of the client and recording the information acquisition timestamp when acquiring the hardware information, the step further includes:
[0038] The hardware fingerprint plug-in applies to the client for hardware information access permission;
[0039] When the application is approved, the hardware fingerprint plug-in periodically obtains the hardware information of the client.
[0040] In addition, to achieve the above-mentioned purpose, the present application also proposes a security verification device for a web application, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the web application security verification method as described above.
[0041] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, the steps of the web application security verification method described above are implemented.
[0042] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the web application security verification method as described above.
[0043] One or more technical solutions proposed in this application have at least the following technical effects:
[0044] The security verification system of the web application of the present application includes: a client, a proxy server and an application server; when the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint; the client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request; when the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint; the proxy server sends the second login request generated based on the second security verification certificate to the application server. Since the security verification certificate includes the user's hardware fingerprint, it has natural immunity against common network request attacks. Even if the attacker obtains the session or token, the hardware fingerprint cannot be forged. Even if the hardware fingerprint is obtained, the security verification certificate installed on the user's client cannot be obtained, so there is a strong information security guarantee. At the same time, through the security verification certificate and the proxy server, the certificate content carried by the browser can be directly forwarded to the application server. Since this forwarding only occurs on the application server, the attacker cannot obtain it through external request interception, further improving security. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0046] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0047] Figure 1A schematic diagram of the functional modules provided in Example 1 of the web application security verification method of this application;
[0048] Figure 2 A flowchart of the second embodiment of the web application security verification method provided in this application;
[0049] Figure 3 A flowchart of the third embodiment of the web application security verification method provided in this application;
[0050] Figure 4 This is a flowchart of a security verification method for a web application according to an embodiment of the present application.
[0051] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0052] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0053] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0054] In some implementations, banks often use U-shield technology to ensure security, but the cost is too high and it is inconvenient to carry. If the U-shield is damaged or accidentally lost, basic verification operations cannot be completed, and the management cost is high.
[0055] This application provides a solution that, compared with other common verification methods, solves the pain points of security verification. While ensuring high security, it achieves good scalability and manageability, greatly improving the user experience.
[0056] Based on this, the embodiment of the present application provides a security verification system for a web application, referring to Figure 1 , Figure 1 This is a schematic diagram of the functional modules provided in Example 1 of the security verification system for web applications of this application.
[0057] like Figure 1 As shown, in the embodiment of the present application, the security verification system of the web application includes: a client, a proxy server and an application server;
[0058] The client is configured to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails;
[0059] The client is further configured to initiate a certificate application request based on the hardware fingerprint, and to perform a request approval process when the administrator receives the certificate application request;
[0060] The client is further configured to obtain a second security verification certificate generated based on the hardware fingerprint when the request approval process passes;
[0061] The proxy server is further configured to send a second login request generated based on the second security verification certificate to the application server.
[0062] It should be noted that the above-mentioned client can be a software program or environment running on the user's user device for interacting with the application server. The user client sends a request to the application server through the client and receives and displays the data returned by the application server.
[0063] It should be explained that the above-mentioned proxy server is an intermediate server located between the client and the application server. It serves as a communication bridge between the client and the application server, can receive the client's request, and forward the request to the target server.
[0064] It should be noted that the application server can be a server for processing client requests. The application server can receive requests forwarded by the proxy server, and based on the type and content of the request, call the corresponding application or functional module to process it, and return the processed request results to the client.
[0065] It is understood that a login request may be a specific type of request sent by a client to an application server, which is used to allow the application server to verify the login information provided by the client to determine whether the client user has permission to access feature system resources or functions. Generally speaking, a login request may include information used for identity authentication, such as a username and password. In embodiments of the present application, the login request may also include parameters such as a security verification certificate.
[0066] It should be noted that the "first" and "second" in the embodiments of the present application are only used to distinguish between different technical terms and do not mean that they have different functions or content parameters.
[0067] It should be explained that the above security verification certificate is a certificate used to perform security verification on the client's login request. The security verification certificate can be used to verify whether the client logging into the application server is the user's client.
[0068] In some implementations of the present application, since P12 certificates are compatible with multiple browsers and systems, users only need to install them, and the browser will automatically carry them in the TLS handshake, making them very easy to use. Therefore, the security verification certificate used in the present application can be a P12 certificate. A P12 certificate is a digital certificate based on public key infrastructure, which typically contains one or more encrypted private keys and an associated X.509 certificate. Private keys are used to sign and decrypt data, while X.509 certificates are used for identity authentication, digital signatures, and secure communications.
[0069] It should be noted that the above authorization verification can be performed based on the above security verification certificate. When the authorization verification passes, the client is granted login authorization; when the authorization verification fails, the client is not granted login authorization.
[0070] In some implementations of the embodiments of the present application, the situations where the above authorization verification fails may include: the security verification certificate is not included in the login request, the security verification certificate of the login request has expired, and the client corresponding to the security verification certificate of the login request is not the user client.
[0071] It should be noted that the hardware fingerprint is an installable hardware fingerprint plug-in written in a front-end development language that is compatible with common operating systems such as Mac and Windows. The function of the hardware fingerprint plug-in is to collect, analyze and process the hardware information of the device where the current system is located with the user's authorization (it can interact with the user through the client's front-end service FE), and generate a set of unique identification codes that can uniquely identify a device. It can usually be a series of parameters that uniquely identify the hardware, such as the CPU serial number, hard disk serial number, memory, Mac, and a timestamp. The hardware fingerprint is unique and stable and can be used to identify and distinguish different hardware devices in the digital world. When the authorization check of the first security verification certificate of the first login request fails, the client can obtain the hardware fingerprint of the device and initiate a certificate request for the security verification certificate based on the hardware fingerprint.
[0072] It is understandable that the administrator may be a client for applying for a certificate or a management user who is responsible for managing the issuance of security verification certificates.
[0073] In some implementations of the present invention, a P12 certificate can be issued by a certificate authority or self-signed by an individual or organization. A self-signed certificate is trusted only by the signer, while a certificate issued by a CA can be trusted by the public. P12 certificates typically have a .pl2 or .pfx extension and are collectively referred to as P12 certificates in this application.
[0074] In actual applications, when the client performs a TLS handshake with the application server, the P12 certificate can be obtained from the application server.
[0075] In some implementations of the present application, when the request approval process passes, the client can obtain a second security verification certificate generated based on the hardware fingerprint. Upon obtaining the second security verification certificate, the proxy server can send a second login request generated based on the second security verification certificate to the application server for another authorization verification.
[0076] In some implementations of the present application, the hardware fingerprint can be used as part of the login information for security verification along with the security verification certificate during login. Since the security verification certificate also contains the hardware fingerprint, the comparison and verification of the security verification certificate and the hardware fingerprint can serve as an encryption verification.
[0077] The web application security verification system of the embodiment of the present application includes: a client, a proxy server, and an application server. When the client fails the authorization verification of the first security verification certificate in the first login request, the client obtains the hardware fingerprint. The client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request. When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint. The proxy server sends the second login request generated based on the second security verification certificate to the application server. Because the security verification certificate includes the user's hardware fingerprint, it is naturally immune to common network request attacks. Even if an attacker obtains a session or token, the hardware fingerprint cannot be forged. Even if the hardware fingerprint is obtained, the security verification certificate installed on the user's client cannot be obtained, thus providing strong information security protection. At the same time, through the security verification certificate and proxy server, the certificate content carried by the browser can be directly forwarded to the application server. Since this forwarding occurs only on the application server, attackers cannot obtain it through external request interception, further improving security.
[0078] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 2 , Figure 2 This is a flow chart of the second embodiment of the security verification system for web applications of this application.
[0079] Reference Figure 2 In an embodiment of the present application, the proxy server is further configured to send a first login request to the application server;
[0080] The application server is configured to obtain first login request information in the first login request, where the first login request information includes at least first login information and further includes a first security verification certificate;
[0081] The application server is further configured to perform login verification based on the first login information;
[0082] The application server is further configured to perform authorization verification based on the first security verification certificate when the login verification passes.
[0083] It should be noted that when a user needs to log in to an application server, a first login request can be sent to the application server via a proxy server. The first login request can include first login request information. The application server can improve security by performing a security verification on the first login information. The first login request information can include the first login information (such as a user name and password) and can also include a first security verification certificate.
[0084] In an embodiment of the present application, the above-mentioned security verification process may include login verification and authorization verification. Specifically, the application server may perform login verification based on the first login information. By performing login verification on the first login information, it is possible to verify whether the user's login information is correct, such as verifying whether the username and password match. When the login verification passes, it is possible to further perform authorization verification on the first security verification certificate based on whether the first login request includes a first security verification certificate and whether the first security verification certificate is legal.
[0085] In some implementations of the present application, the authorization verification process for verifying the legitimacy of the security verification certificate may include a timeliness check and a hardware fingerprint check. The timeliness check can determine whether the security verification certificate is within its validity period; the hardware fingerprint check can determine whether the login request originated from a user device. The user device may be a user-defined whitelist device or a whitelist device determined based on the user's frequently used login devices, and the present application does not impose any restrictions on this.
[0086] It should be noted that the above-mentioned effective period can be the same as the timing period for the hardware fingerprint plug-in to obtain the hardware information of the client, and the embodiment of the present application does not limit this.
[0087] In some implementations of the embodiments of the present application, the client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0088] It should be noted that the hardware fingerprint can be generated by the hardware fingerprint plug-in and then issued, or it can be actively obtained by the client when the authorization verification fails. This embodiment of the present application does not limit this.
[0089] In some implementations of the embodiments of the present application, the application server can obtain the hardware fingerprint carried in the current login request, and the security verification certificate information carried by the proxy server for authorization verification. If the authorization verification fails, the user can initiate a certificate application request carrying the hardware fingerprint. When the administrator receives the certificate application request, he can approve the user's certificate application request. When the certificate application request is approved, the user can enter the certificate password. A security verification certificate can be generated based on the hardware fingerprint and the certificate password entered by the user. At this time, the security verification certificate will form a corresponding relationship between user-hardware fingerprint-certificate. The user can obtain the generated security verification certificate and download it to the client of the current login request. When downloading and installing the security verification certificate, you need to enter the certificate password entered in advance during the application, and the installation can continue only when the password verification is correct.
[0090] It should be noted that when the security verification certificate is installed, since the pre-matched certificate for the server has already been installed, the browser will display a certificate selection window. After selecting the corresponding user's security verification certificate, a second login request can be re-initiated. If the username and password of the second login request are verified, a user-hardware fingerprint-certificate authorization verification can be performed. Once the authorization verification is completed, the login is successful.
[0091] In some implementations of the embodiments of the present application, upon successful login, subsequent requests will follow the above-mentioned security verification process, except that the user information is carried by the token in the request.
[0092] In some implementations of the embodiments of the present application, when the security verification certificate is installed, the browser can be restarted. After the browser is restarted, a certificate selection window pops up for certificate selection.
[0093] In the embodiment of the present application, a first login request is sent to an application server through a proxy server; the application server obtains the first login request information in the first login request, and the first login request information includes at least the first login information; the application server performs login verification based on the first login information; when the login verification is passed, the application server performs authorization verification based on the first security verification certificate. Since the client needs to bind the hardware fingerprint of the user device and the user when applying for the security verification certificate from the application server, the correspondence between one person, one machine and one code is guaranteed. By borrowing the browser's own security mechanism, the P12 certificate is obtained in the tls handshake encryption, and the certificate encrypted content is forwarded by the proxy server. Through the comparison and verification of the certificate and the hardware fingerprint, the role of encryption verification is played.
[0094] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the first embodiment and / or the second embodiment can be referred to the above introduction and will not be described in detail later. Figure 3 , Figure 3 This is a flowchart of the third embodiment of the security verification system for web applications of this application.
[0095] In the embodiment of the present application, a hardware fingerprint plug-in is installed in the client;
[0096] The hardware fingerprint plug-in is used to periodically obtain the hardware information of the client and record the information acquisition timestamp when the hardware information is obtained;
[0097] The hardware fingerprint plug-in is further configured to, upon receiving a hardware fingerprint request from the client, encrypt the hardware information of the current time period and the information acquisition timestamp to obtain a hardware fingerprint;
[0098] The hardware fingerprint plug-in is further configured to return the hardware fingerprint to the client.
[0099] It should be noted that the embodiment of the present application uses an installable hardware fingerprint plug-in to skip the browser, obtain the hardware information of the user's device with the user's authorization, and encrypt it in conjunction with the timestamp. Because it carries a timestamp, it ensures that the hardware fingerprint after each encryption has a validity period and cannot be used for a long time; when the client applies for a P12 certificate from the application server, it needs to be bound to the current hardware fingerprint and user, and then generate a correspondence between one person, one machine, and one code. By leveraging the browser's own security mechanism, the P12 certificate is obtained in the tls handshake encryption, and the certificate encrypted content is forwarded by the proxy server. Through the comparison and verification of the certificate and the hardware fingerprint, it plays the role of encryption verification.
[0100] It should be explained that, because the P12 certificate includes the user's hardware fingerprint, it has a natural immunity to common network request attacks. Even if the attacker obtains the session or token, he still cannot forge the hardware fingerprint. Even if the hardware fingerprint is obtained, the P12 certificate installed on the user's client cannot be obtained, so there is a strong information security guarantee. At the same time, because the P12 certificate is used, the certificate content carried by the browser is forwarded directly to the application server through proxy services such as nginx. Since this forwarding only occurs on the application server, the attacker cannot obtain it through external request interception, and security is further improved. In addition, the P12 certificate has good compatibility on multiple browsers and multiple systems. After the user installs it, the browser will automatically carry it in the TLS handshake, which has good ease of use.
[0101] In some implementations of the embodiments of the present application, after the hardware fingerprint plug-in is installed, the hardware fingerprint plug-in can be started so that it can apply to the user for access rights to hardware information. After the user confirms and approves, the hardware fingerprint plug-in will be started and minimized to the user system background. The hardware fingerprint plug-in can open a designated port to wait for application calls and periodically obtain the hardware information of the user device where the client is located. In other words, the hardware fingerprint plug-in is also used to apply to the client for access rights to hardware information; the hardware fingerprint plug-in is also used to periodically obtain the hardware information of the client when the application is approved.
[0102] It should be noted that when a user opens a browser, since the application server has enabled certificate verification mode, if the corresponding P12 certificate of the currently accessed application server is installed, the browser will pop up a certificate selection window for the user. The client application can obtain the current client's hardware fingerprint request by periodically downloading the plug-in through the specified port.
[0103] In some implementations of the embodiments of the present application, when the hardware fingerprint plug-in obtains a hardware fingerprint request, it can asymmetrically encrypt the current user's hardware information and the timestamp of the current request to generate a hardware fingerprint, and return the result to the client.
[0104] In the embodiment of the present application, a hardware fingerprint plug-in is installed in the client; the hardware fingerprint plug-in periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained; when the hardware fingerprint plug-in receives the hardware fingerprint request from the client, it encrypts the hardware information based on the current time period and the information acquisition timestamp to obtain the hardware fingerprint; the hardware fingerprint plug-in returns the hardware fingerprint to the client. Since the hardware fingerprint information carries a timestamp, it ensures that the hardware fingerprint after each encryption cannot be used all the time; at the same time, since the hardware fingerprint is used for security verification, it has natural immunity against common network request attacks. Even if the attacker obtains the session or token, he still cannot forge the hardware fingerprint. Even if the hardware fingerprint is obtained, the P12 certificate installed on the user client cannot be obtained, so there is a strong information security guarantee.
[0105] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the security verification method of the web application of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.
[0106] This application also provides a web application security verification method, which is used in the web application security verification system as described above. Figure 4 , Figure 4 This is a flow chart of a method for verifying the security of a web application according to an embodiment of the present application. The method for verifying the security of a web application includes:
[0107] Step S10: When the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint;
[0108] Step S20: The client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request;
[0109] Step S30: When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint;
[0110] In step S40 , the proxy server sends a second login request generated based on the second security verification certificate to the application server.
[0111] In some implementations of the embodiments of the present application, when the authorization verification of the first security verification certificate in the first login request fails, the client further includes, before the step of obtaining the hardware fingerprint:
[0112] The proxy server is further configured to send a first login request to the application server;
[0113] The application server is configured to obtain first login request information in the first login request, where the first login request information includes at least first login information and further includes a first security verification certificate;
[0114] The application server is further configured to perform login verification based on the first login information;
[0115] The application server is further configured to perform authorization verification based on the first security verification certificate when the login verification passes.
[0116] In some implementations of the embodiments of the present application, a hardware fingerprint plug-in is installed in the client; and the method further includes:
[0117] The hardware fingerprint plug-in periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained;
[0118] When the hardware fingerprint plug-in receives the hardware fingerprint request from the client, it encrypts the hardware information of the current time period and the information acquisition timestamp to obtain the hardware fingerprint;
[0119] The hardware fingerprint plug-in returns the hardware fingerprint to the client.
[0120] In some implementations of the embodiments of the present application, when the authorization verification of the first security verification certificate in the first login request fails, the step of obtaining the hardware fingerprint by the client includes:
[0121] The client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
[0122] In some implementations of the embodiments of the present application, before the step of the hardware fingerprint plug-in periodically acquiring the hardware information of the client and recording the information acquisition timestamp when acquiring the hardware information, the method further includes:
[0123] The hardware fingerprint plug-in applies to the client for hardware information access permission;
[0124] When the application is approved, the hardware fingerprint plug-in periodically obtains the hardware information of the client.
[0125] The web application security verification method provided in this application, utilizing the web application security verification system described in the aforementioned embodiments, can address the technical issue of low security factors in existing web application security verification systems. Compared to existing technologies, the web application security verification method provided in this application achieves the same beneficial effects as the web application security verification system described in the aforementioned embodiments. Other technical features of the web application security verification method are the same as those disclosed in the aforementioned embodiments and are not further elaborated here.
[0126] The present application provides a web application security verification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the web application security verification method of the above-mentioned embodiment 1.
[0127] The web application security verification device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. The web application security verification device described above is merely an example and should not limit the functionality or scope of use of the embodiments of the present application.
[0128] In embodiments of the present application, a web application security verification device may include a processing device (e.g., a central processing unit (CPU), a graphics processing unit (GPU), etc.) that can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or programs loaded from a storage device into random access memory (RAM). The RAM also stores various programs and data required for the operation of the web application security verification device. The processing device, ROM, and RAM are interconnected via a bus. An input / output (I / O) interface is also connected to the bus. Typically, the following systems may be connected to the I / O interface: input devices such as a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices such as magnetic tape, hard disk, etc.; and communication devices. The communication devices may enable the web application security verification device to communicate with other devices wirelessly or wired to exchange data. While the figures illustrate a web application security verification device with various systems, it should be understood that implementation or inclusion of all of the illustrated systems is not required. More or fewer systems may alternatively be implemented or included.
[0129] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0130] The web application security verification device provided by this application utilizes the web application security verification method of the aforementioned embodiment, thereby resolving the technical issue of low security factors in existing web application security verification. Compared to the prior art, the web application security verification device provided by this application achieves the same beneficial effects as the web application security verification method of the aforementioned embodiment. Other technical features of this web application security verification device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0131] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0132] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0133] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, wherein the computer-readable program instructions are used to execute the security verification method for a web application in the above-mentioned embodiment.
[0134] The computer-readable storage medium provided herein may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including, but not limited to, wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0135] The computer-readable storage medium may be included in the security verification device for the web application; or may exist independently without being assembled into the security verification device for the web application.
[0136] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the web application security verification device, the web application security verification device:
[0137] When the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint;
[0138] The client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request;
[0139] When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint;
[0140] The proxy server sends a second login request generated based on the second security verification certificate to the application server.
[0141] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0142] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0143] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0144] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned web application security verification method. This computer-readable storage medium can address the technical issue of low security factors in existing web application security verification. Compared to existing technologies, the beneficial effects of the computer-readable storage medium provided in this application are similar to those of the web application security verification method provided in the aforementioned embodiments, and are not further elaborated here.
[0145] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned web application security verification method when executed by a processor.
[0146] The computer program product provided in this application can solve the technical problem of low security coefficients in existing web application security verification. Compared with the existing technology, the beneficial effects of the computer program product provided in this application are the same as those of the web application security verification method provided in the above embodiment, and will not be elaborated here.
[0147] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A web application security verification system, characterized in that: The system includes: a client, a proxy server and an application server; The proxy server is further configured to send a first login request to the application server; The application server is configured to obtain first login request information in the first login request, where the first login request information at least includes first login information; The application server is further configured to perform login verification based on the first login information; The application server is further configured to perform authorization verification based on the first security verification certificate when the login verification passes; the authorization verification includes timeliness verification and hardware fingerprint verification; The client is configured to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails; The client is further configured to initiate a certificate application request based on the hardware fingerprint, and to perform a request approval process when the administrator receives the certificate application request; The client is further configured to obtain a second security verification certificate generated based on the hardware fingerprint when the request approval process passes; The proxy server is further configured to send a second login request generated based on the second security verification certificate to the application server; A hardware fingerprint plug-in is installed in the client; The hardware fingerprint plug-in is used to periodically obtain the hardware information of the client and record the information acquisition timestamp when the hardware information is obtained; The hardware fingerprint plug-in is further configured to, upon receiving a hardware fingerprint request from the client, encrypt the hardware information of the current time period and the information acquisition timestamp to obtain a hardware fingerprint; the information acquisition timestamp is also used for timeliness verification; The hardware fingerprint plug-in is further configured to return the hardware fingerprint to the client.
2. The web application security verification system according to claim 1, wherein: The client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
3. The web application security verification system according to claim 1, wherein: The hardware fingerprint plug-in is further used to apply for hardware information access rights from the client; The hardware fingerprint plug-in is further used to periodically obtain the hardware information of the client when the application is approved.
4. A web application security verification method, characterized in that: The method is applied to the web application security verification system according to any one of claims 1 to 3, and the method includes: When the authorization verification of the first security verification certificate in the first login request fails, the client obtains the hardware fingerprint; The client initiates a certificate application request based on the hardware fingerprint, and the administrator performs a request approval process when receiving the certificate application request; When the request approval process passes, the client obtains a second security verification certificate generated based on the hardware fingerprint; The proxy server sends a second login request generated based on the second security verification certificate to the application server; When the authorization verification of the first security verification certificate in the first login request fails, the client further includes, before the step of obtaining the hardware fingerprint: The proxy server is further configured to send a first login request to the application server; The application server is configured to obtain first login request information in the first login request, where the first login request information includes at least first login information and further includes a first security verification certificate; The application server is further configured to perform login verification based on the first login information; The application server is further configured to perform authorization verification based on the first security verification certificate when the login verification passes; the authorization verification includes timeliness verification and hardware fingerprint verification; A hardware fingerprint plug-in is installed in the client; The method further comprises: The hardware fingerprint plug-in periodically obtains the hardware information of the client and records the information acquisition timestamp when the hardware information is obtained; When the hardware fingerprint plug-in receives the hardware fingerprint request from the client, it encrypts the hardware information of the current time period and the information acquisition timestamp to obtain the hardware fingerprint; the information acquisition timestamp is also used for timeliness verification; The hardware fingerprint plug-in returns the hardware fingerprint to the client.
5. The web application security verification method according to claim 4, wherein: When the client fails to pass the authorization verification of the first security verification certificate in the first login request, the step of obtaining the hardware fingerprint includes: The client is further configured to send a hardware fingerprint request to the hardware fingerprint plug-in to obtain a hardware fingerprint when the authorization verification of the first security verification certificate in the first login request fails.
6. The web application security verification method according to claim 5, wherein: Before the step of the hardware fingerprint plug-in periodically acquiring the hardware information of the client and recording the information acquisition timestamp when acquiring the hardware information, the method further includes: The hardware fingerprint plug-in applies to the client for hardware information access permission; When the application is approved, the hardware fingerprint plug-in periodically obtains the hardware information of the client.
Citation Information
Patent Citations
Method and system for enhancing data security of computer system
CN112434270A
Communication security protection method, server and system for intelligent cabin
CN113162921A