Parameter tamper-proofing method and system, electronic equipment and storage medium

Through the client and interface intercept middleware, the url and data information are spliced in the interface request, and the risk control server is used for signature verification, which solves the problem of coupling business code and security verification logic in the existing technology, improves system scalability and reduces operation and maintenance costs.

CN120354461AActive Publication Date: 2025-07-22小芒电子商务有限责任公司
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202510847011.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-07-22
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

In the existing interface parameter tamper-proof technology, the business code and security verification logic are highly coupled, the system scalability is limited, and the transformation cost of the put into production system is high, and the operation and maintenance are complex.

Method used

The middleware intercepts the client and interface intercepts the url information and data information in the interface request, generates a signature string, and uses the risk control server to perform tamper-proof verification, reducing the coupling between business code and security verification and avoiding separate transformations of each interface.

Benefits of technology

It improves the scalability of the parameter tamper-proof system, reduces the system upgrade cycle and operation and maintenance costs, and realizes non-perception and non-invasive parameter tamper-proof processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354461A_ABST
    Figure CN120354461A_ABST
Patent Text Reader

Abstract

The invention provides a parameter tamper-proofing method and system, electronic equipment and a storage medium, and is applied to the technical field of parameter tamper-proofing, when a client determines that an interface request needs to be subjected to parameter tamper-proofing processing, a result obtained by splicing url information and data information is subjected to tamper-proofing processing to obtain a first signature character string; the risk control server stores signature information generated according to the first signature character string; when the interface interception middleware determines that the interface request needs to be subjected to parameter tamper-proof processing, performing tamper-proof processing on a result obtained by splicing the url information and the data information to obtain a second signature character string; the risk control server performs parameter tamper-proof verification on the second signature character string by using the signature information; and when the interface interception middleware receives the verification information indicating that the verification of the second signature character string is passed, the interface request is sent to the application server, so that the coupling between the service code of the system and the security verification logic can be reduced, and the upgrading period and the operation and maintenance cost of the system are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of parameter anti-tampering, and more specifically, to a parameter anti-tampering method, system, electronic device, and storage medium. Background Art

[0002] With the continuous development of computer technology, during the process of data or request transmission, it is easy to have the problem that the parameters in the data or request are tampered with. Especially for the interface requests of the system, once the parameters in the request are tampered with, the corresponding data of the request cannot be obtained, thus affecting subsequent corresponding business processing. In order to avoid the problem of being tampered with during the request transmission process, parameter anti-tampering processing can be performed on the transmitted request.

[0003] In the existing interface parameter anti-tampering technology, the conventional implementation usually includes the following steps: First, perform dictionary sorting on each parameter in the interface request, so as to generate a signature value sign according to the parameter sequence obtained after sorting. Finally, attach the obtained signature value sign to the end of the request in plain text for transmission verification. However, on the one hand, this method requires implementing parameter extraction and sorting algorithms for each interface in advance, resulting in a high coupling between business code and security verification logic, and limited scalability of the system; on the other hand, for historical systems that have been put into production and do not integrate anti-tampering mechanisms, the transformation process requires code refactoring for each interface at a time, which not only leads to a long system upgrade cycle but also increases the operation and maintenance cost of the system. Summary of the Invention

[0004] In view of this, this application provides a parameter anti-tampering method, system, electronic device, and storage medium, aiming to reduce the coupling between the business code and security verification logic of the system, and reduce the system upgrade cycle and the operation and maintenance cost of the system.

[0005] The first aspect of this application provides a parameter anti-tampering method, which is applied to a parameter anti-tampering system. The parameter anti-tampering system includes a client, a risk control server, an interface interception middleware, and an application server. The client establishes a long connection with the risk control server. The method includes:

[0006] Generating a corresponding interface request by the client according to the target business, where the interface request at least includes url information and data information;

[0007] If the interface request needs to be processed for parameter anti-tampering, splicing the url information and the data information by the client, and performing anti-tampering processing on the spliced result to obtain a first signature string;

[0008] The client transmits the first signature string to the risk control server based on the long connection protocol, enabling the risk control server to generate signature information according to the first signature string and store the signature information.

[0009] The interface interception middleware receives the interface request sent by the client through the interface, and when it is determined that the interface request needs to perform parameter anti-tampering processing, the url information and data information in the interface request are spliced, and anti-tampering processing is performed on the spliced result to obtain a second signature string.

[0010] The risk control server receives the second signature string sent by the interface interception middleware and performs parameter anti-tampering verification on the second signature string using the signature information stored in itself.

[0011] When the interface interception middleware receives the verification information indicating that the second signature string passes the verification feedback from the risk control server, the interface request is sent to the application server, enabling the application server to execute the target service based on the interface request.

[0012] Optionally, the client generates a corresponding interface request according to the target service, including:

[0013] The client generates a corresponding initial interface request according to the interface requested by the target service and determines the request type of the initial interface request.

[0014] If the request type is the target request type, the client obtains the data information related to the target service and generates the interface request corresponding to the target service according to the url information and the data information in the initial interface request.

[0015] If the request type is not the target request type, the client determines the initial interface request as the interface request of the target service.

[0016] Optionally, the client includes an interface interception component, and the method further includes:

[0017] The interface interception component determines whether the interface corresponding to the interface request exists in the pre-set parameter anti-tampering configuration file; wherein, the parameter anti-tampering configuration file is pre-configured by the parameter anti-tampering configuration center in the parameter anti-tampering system.

[0018] If the interface exists in the parameter anti-tampering configuration file, the interface interception component determines that the interface request needs to perform parameter anti-tampering processing.

[0019] If the parameter anti-tampering configuration file does not have the interface, the interface interception component determines that the interface request does not require parameter anti-tampering processing.

[0020] Optionally, the process of splicing the url information and the data information by the client and performing anti-tampering processing on the spliced result to obtain the first signature string includes:

[0021] The interface interception component splices the url information and the data information, and splices the spliced result with a preset salt value to obtain an initial first signature string;

[0022] The interface interception component performs an MD5 operation on the initial first signature string to obtain the first signature string.

[0023] Optionally, the process of the interface interception middleware receiving the interface request sent by the client and, when determining that the interface request requires parameter anti-tampering processing, splicing the url information and the data information in the interface request and performing anti-tampering processing on the spliced result to obtain the second signature string includes:

[0024] The interface interception middleware receives the interface request sent by the client and determines whether the interface request requires parameter anti-tampering processing according to the interface corresponding to the interface request and the pre-set parameter anti-tampering configuration file;

[0025] If the interface request requires parameter anti-tampering processing, the interface interception middleware splices the url information and the data information in the interface request, splices the spliced result with a preset salt value to obtain an initial second signature string, and performs an MD5 operation on the initial second signature string to obtain the second signature string.

[0026] Optionally, the process of the risk control server receiving the second signature string sent by the interface interception middleware and using the signature information stored in itself to perform parameter anti-tampering verification on the second signature string includes:

[0027] The risk control server receives the second signature string sent by the interface interception middleware;

[0028] The risk control server determines whether there is signature information matching the second signature string among the various signature information stored in itself according to the second signature string; among them, the signature information matching the second signature string includes the first signature string identical to the second signature string and the timeout time;

[0029] If there is signature information that matches the second signature string, obtain the current time through the risk control server, and verify the validity of the first signature string based on the current time and the timeout period;

[0030] If the validity verification of the first signature string passes, feedback verification information indicating that the parameter anti-tampering verification of the second signature string passes to the interface interception middleware through the risk control server;

[0031] If the validity verification of the first signature string fails, or there is no signature information that matches the second signature string, feedback verification information indicating that the parameter anti-tampering verification of the second signature string fails to the interface interception middleware through the risk control server.

[0032] Optionally, the method further includes:

[0033] When receiving, through the interface interception middleware, verification information fed back by the risk control server indicating that the parameter anti-tampering verification of the second signature string fails, intercept the interface request, and feedback prompt information indicating that the interface request verification fails to the client.

[0034] A second aspect of the present application provides a parameter anti-tampering system, where the system includes: a client, a risk control server, an interface interception middleware, and an application server, and the client establishes a long connection with the risk control server;

[0035] The client is configured to generate a corresponding interface request according to a target service, where the interface request includes at least url information and data information; if the interface request needs to perform parameter anti-tampering processing, splice the url information and the data information, and perform anti-tampering processing on the spliced result to obtain a first signature string; transmit the first signature string to the risk control server based on the long connection protocol, so that the risk control server generates signature information according to the first signature string and stores the signature information;

[0036] The interface interception middleware is configured to receive the interface request sent by the client, and when it is determined that the interface request needs to perform parameter anti-tampering processing, splice the url information and the data information in the interface request, and perform anti-tampering processing on the spliced result to obtain a second signature string; when receiving verification information fed back by the risk control server indicating that the verification of the second signature string passes, send the interface request to the application server, so that the application server executes the target service based on the interface request;

[0037] The risk control server is configured to receive the second signature string sent by the interface interception middleware, and perform parameter anti-tampering verification on the second signature string by using the signature information stored in itself.

[0038] A third aspect of the present application provides an electronic device, including: a processor and a memory, the processor and the memory are connected by a bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store a program, and the program is used to implement a parameter anti-tampering method provided in the first aspect of the present application.

[0039] A fourth aspect of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and the computer-executable instructions are used to execute a parameter anti-tampering method provided in the first aspect of the present application.

[0040] The present application provides a parameter anti-tampering method, system, electronic device, and storage medium, which are applied to a parameter anti-tampering system. The parameter anti-tampering system includes a client, a risk control server, an interface interception middleware, and an application server. The client establishes a long connection with the risk control server; the client generates a corresponding interface request according to the target service, where the interface request includes at least url information and data information; if the interface request needs to be processed for parameter anti-tampering, the client splices the url information and data information, and performs anti-tampering processing on the spliced result to obtain a first signature string; the client transmits the first signature string to the risk control server based on the long connection protocol, so that the risk control server generates signature information according to the first signature string and stores the signature information; the interface interception middleware receives the interface request sent by the client, and when it is determined that the interface request needs to be processed for parameter anti-tampering, splices the url information and data information in the interface request, and performs anti-tampering processing on the spliced result to obtain a second signature string; the risk control server receives the second signature string sent by the interface interception middleware, and uses the signature information stored by itself to perform parameter anti-tampering verification on the second signature string; when the interface interception middleware receives the verification information indicating that the verification of the second signature string has passed sent by the risk control server, it sends the interface request to the application server, so that the application server executes the target service based on the interface request. It can be seen that in the technical solution provided by the present application, when the client and the interface interception middleware determine that the interface request needs to be processed for parameter anti-tampering, they directly splice the url information and data information in the interface request, and perform anti-tampering processing on the spliced result to obtain the corresponding signature string, without sorting the parameters in the interface request, that is, there is no need to separately implement parameter extraction and sorting for each interface, reducing the coupling between business code and security verification, and improving the scalability of the parameter anti-tampering system; moreover, for a parameter anti-tampering system that has been put into production and does not integrate an anti-tampering mechanism, there is no need to reconstruct the code for each interface, which can effectively reduce the system upgrade cycle and the system operation and maintenance cost. Description of the Drawings

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the provided drawings.

[0042] Figure 1 It is a schematic structural diagram of a parameter anti-tampering system provided by an embodiment of the present application;

[0043] Figure 2Schematic structural diagram of another parameter anti-tampering system provided by an embodiment of the present application;

[0044] Figure 3 Schematic flowchart of a parameter anti-tampering method provided by an embodiment of the present application;

[0045] Figure 4 Example diagram of a parameter anti-tampering method provided by an embodiment of the present application;

[0046] Figure 5 Schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0047] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0048] In the present application, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.

[0049] See Figure 1 , which shows a schematic structural diagram of a parameter anti-tampering system provided by an embodiment of the present application; the parameter anti-tampering system includes a client, a risk control server, an interface interception middleware, and an application server;

[0050] A client, which is used to generate a corresponding interface request according to a target service. Among them, the interface request at least includes uniform resource locator (URL) information and data information; if the interface request needs to perform parameter anti-tampering processing, the URL information and data information are spliced, and the result obtained by splicing is subjected to anti-tampering processing to obtain a first signature string; based on the long connection protocol, the first signature string is transmitted to a risk control server, so that the risk control server generates signature information according to the first signature string and stores the signature information.

[0051] An interface interception middleware, which is used to receive the interface request sent by the client, and when it is determined that the interface request needs to perform parameter anti-tampering processing, splice the URL information and data information in the interface request, and perform anti-tampering processing on the result obtained by splicing to obtain a second signature string; when receiving the verification information indicating that the second signature string passes the verification feedback by the risk control server, send the interface request to the application server, so that the application server executes the target service based on the interface request.

[0052] A risk control server, which is used to receive the second signature string sent by the interface interception middleware and perform parameter anti-tampering verification on the second signature string by using the signature information stored in itself.

[0053] The present application provides a parameter anti-tampering system. The client generates a corresponding interface request according to the target service. Among them, the interface request at least includes url information and data information. If the interface request needs to be processed for parameter anti-tampering, the client splices the url information and data information, and performs anti-tampering processing on the spliced result to obtain a first signature string. The client transmits the first signature string to the risk control server based on the long connection protocol, so that the risk control server generates signature information according to the first signature string and stores the signature information. The interface interception middleware receives the interface request sent by the client, and when it is determined that the interface request needs to be processed for parameter anti-tampering, splices the url information and data information in the interface request, and performs anti-tampering processing on the spliced result to obtain a second signature string. The risk control server receives the second signature string sent by the interface interception middleware, and uses the signature information stored by itself to perform parameter anti-tampering verification on the second signature string. When the interface interception middleware receives the verification information indicating that the second signature string verification has passed sent by the risk control server, it sends the interface request to the application server, so that the application server executes the target service based on the interface request. It can be seen that in the technical solution provided by the present application, when the client and the interface interception middleware determine that the interface request needs to be processed for parameter anti-tampering, they directly splice the url information and data information in the interface request, perform anti-tampering processing on the spliced result to obtain the corresponding signature string, without sorting the parameters in the interface request, that is, there is no need to separately implement parameter extraction and sorting for each interface, reducing the coupling between business code and security verification, and improving the scalability of the parameter anti-tampering system. And for a parameter anti-tampering system that has been put into production and does not integrate an anti-tampering mechanism, there is no need to reconstruct the code for each interface, which can effectively reduce the system upgrade cycle and the system operation and maintenance cost.

[0054] Optionally, the client that generates a corresponding interface request according to the target service is specifically used for:

[0055] Generate a corresponding initial interface request according to the interface requested by the target service, and determine the request type of the initial interface request. If the request type is the target request type, obtain the data information related to the target service, and generate an interface request corresponding to the target service according to the url information and data information in the initial interface request. If the request type is not the target request type, determine the initial interface request as the interface request of the target service.

[0056] Combined with Figure 1 See Figure 2 , the parameter anti-tampering system further includes a parameter anti-tampering configuration center, and the client further includes an application module and an interface interception component;

[0057] An interface interception component is used to determine whether there is an interface corresponding to the interface request in a pre-set parameter anti-tampering configuration file; wherein, the parameter anti-tampering configuration file is pre-configured through a parameter anti-tampering configuration center in a parameter anti-tampering system; if there is an interface in the parameter anti-tampering configuration file, it is determined that the interface request needs to be processed for parameter anti-tampering; if there is no interface in the parameter anti-tampering configuration file, it is determined that the interface request does not need to be processed for parameter anti-tampering.

[0058] Optionally, a client that splices the url information and data information and performs anti-tampering processing on the spliced result to obtain a first signature string is specifically used for:

[0059] Splice the url information and data information through the interface interception component, and splice the spliced result with a preset salt value to obtain an initial first signature string; perform a Message-Digest Algorithm (MD5) operation on the initial first signature string through the interface interception component to obtain the first signature string.

[0060] Optionally, an interface interception component that receives an interface request sent by a client and, when it is determined that the interface request needs to be processed for parameter anti-tampering, splices the url information and data information in the interface request and performs anti-tampering processing on the spliced result to obtain a second signature string is specifically used for:

[0061] Receive the interface request sent by the client, and determine whether the interface request needs to be processed for parameter anti-tampering according to the interface corresponding to the interface request and the pre-set parameter anti-tampering configuration file; if the interface request needs to be processed for parameter anti-tampering, splice the url information and data information in the interface request, and splice the spliced result with a preset salt value to obtain an initial second signature string, and perform an MD5 operation on the initial second signature string to obtain the second signature string.

[0062] Optionally, a risk control server that receives the second signature string sent by the interface interception middleware and performs parameter anti-tampering verification on the second signature string using the signature information stored by itself is specifically used for:

[0063] Receive the second signature string sent by the interface interception middleware through the risk control server;

[0064] Determine whether there is a signature information that matches the second signature string among the signature information stored by itself according to the second signature string; wherein, the signature information that matches the second signature string includes the first signature string that is the same as the second signature string and the timeout time; if there is signature information that matches the second signature string, obtain the current time, and verify the validity of the first signature string according to the current time and the timeout time; if the validity verification of the first signature string passes, feedback verification information indicating that the parameter anti-tampering verification of the second signature string passes to the interface interception middleware; if the validity verification of the first signature string fails, or there is no signature information that matches the second signature string, feedback verification information indicating that the parameter anti-tampering verification of the second signature string fails to the interface interception middleware.

[0065] Optionally, the interface interception middleware is further configured to:

[0066] When receiving the verification information indicating that the parameter anti-tampering verification of the second signature string fails feedback from the risk control server, intercept the interface request and feedback a prompt message indicating that the interface request verification fails to the client.

[0067] Based on the parameter anti-tampering system provided in the embodiment of the present application above, correspondingly, the embodiment of the present application provides a parameter anti-tampering method, as Figure 3 shown, this method is applied to the parameter anti-tampering system, and this method specifically includes the following steps:

[0068] S301: Generate a corresponding interface request according to the target service through the client, where the interface request includes at least url information and data information.

[0069] In the process of specifically executing step S301, when the client detects a regular service with a request server interface behavior during the execution of a regular service, it can use the regular service with the request server interface behavior as the target service, and generate a corresponding interface request according to the request type of the target service, where the interface request includes at least url information and data information.

[0070] It should be noted that the regular services executed by the client may include services such as order placement services and voting services, which are not limited in the embodiment of the present application here.

[0071] Optionally, the process of generating a corresponding interface request by the client according to the target service includes: generating a corresponding initial interface request by the client according to the interface requested by the target service, and determining the request type of the initial interface request; if the request type is the target request type, obtaining the data information related to the target service, and generating an interface request corresponding to the target service according to the url information and data information in the initial interface request; if the request type is not the target request type, determining the initial interface request as the interface request of the target service.

[0072] It should be noted that the request type of the initial interface request of the target service is the request type of the target service. Among them, the initial interface request can be a post request or a Get request. Post and Get refer to the request methods of the http protocol.

[0073] It should also be noted that the target request type can be the Get request type. That is to say, if the initial interface request is a Get request, then it can be considered that the request type of the initial interface request is the Get request type.

[0074] In the embodiments of the present application, it is found through research that in the prior art, if the interface request of the conventional service executed by the client is a Get request, then the data information corresponding to the conventional service is placed in the body, rather than carried by the Get request itself. Therefore, in order to ensure that the interface request of the target service generated by the present application will definitely include the url information and data information, before generating the interface request of the target service, it will first be determined whether the initial interface request of the target service is a Get request. If so, the data information corresponding to the target service can be obtained first, and then an interface request containing the url information and data information can be generated according to the url information in the initial interface request and the obtained data information, so as to ensure that the interface request of the target service generated will definitely include the url information and data information.

[0075] In the actual application process, the client includes an application module and an interface interception component. When the client executes a conventional service and detects a conventional service that requests the server interface, that is, when it detects the current existence of a target service, it can determine the interface requested by the target service through the application module and generate a corresponding initial interface request for the interface; determine the request type of the initial interface request; so that in the case where the request type is the target request type, an interface request corresponding to the target service can be generated according to the url information in the initial interface request and the data information of the target service, and the interface request can be initiated; or, in the case where the request type is not the target request type, directly determine the initial interface request as the interface request of the target service and initiate the interface request.

[0076] S302: Determine at the client end whether the interface request needs to perform parameter anti-tampering processing; if the interface request needs to perform parameter anti-tampering processing, execute step S303.

[0077] In the embodiment of the present application, the parameter anti-tampering system further includes a parameter anti-tampering configuration center. Users can configure multiple interfaces that need to perform parameter anti-tampering judgment through the parameter anti-tampering configuration center, that is, configure multiple interfaces that need to perform parameter anti-tampering. After the configuration center detects the multiple interfaces configured by the user, it can generate a parameter anti-tampering configuration file according to the multiple interfaces configured by the user, and distribute the generated parameter anti-tampering configuration file to the client and the interface interception middleware.

[0078] In the specific process of executing step S302, after the client initiates an interface request corresponding to the target service, it can further determine the interface requested by the target service, that is, determine the interface corresponding to the interface request, and judge whether the interface request needs to perform parameter anti-tampering processing according to the interface and the parameter anti-tampering configuration file distributed by the parameter anti-tampering center; if the interface request needs to perform parameter anti-tampering processing, execute step S303; if the interface request does not need to perform parameter anti-tampering processing, the interface request can be directly sent to the application server, so that the application server can complete the corresponding service request based on the received interface request.

[0079] Optionally, the client includes an interface interception component. The process of determining at the client end whether the interface request needs to perform parameter anti-tampering processing can specifically be: judging whether there is an interface corresponding to the interface request in the pre-set parameter anti-tampering configuration file through the interface interception component; wherein, the parameter anti-tampering configuration file is pre-configured through the parameter anti-tampering configuration center in the parameter anti-tampering system; if there is an interface in the parameter anti-tampering configuration file, it is determined through the interface interception component that the interface request needs to perform parameter anti-tampering processing; if there is no interface in the parameter anti-tampering configuration file, it is determined through the interface interception component that the interface request does not need to perform parameter anti-tampering processing.

[0080] It can be seen that after the client initiates a corresponding interface request through the application module, the interface interception component can use the pre-configured parameter anti-tampering configuration file to identify the interface request that needs to perform parameter anti-tampering processing, avoiding performing parameter anti-tampering processing on each interface request without discrimination, which can not only improve the corresponding processing efficiency, but also save a certain amount of computing resources.

[0081] S303: Concatenate the url information and data information through the client, and perform anti-tampering processing on the concatenated result to obtain a first signature string.

[0082] In the process of specifically executing step S303, when the client determines that the interface request initiated needs to perform parameter anti-tampering processing, it can first extract the url information and data information from the interface request, splice the url information and data information, and perform anti-tampering processing on the obtained splicing result and the preset salt value to obtain the final first signature string.

[0083] Optionally, the process of splicing the url information and data information by the client and performing anti-tampering processing on the obtained splicing result to obtain the first signature string can be specifically as follows: splicing the url information and data information through the interface interception component, and splicing the obtained splicing result with the preset salt value to obtain the initial first signature string; performing an MD5 operation on the initial first signature string through the interface interception component to obtain the first signature string.

[0084] In the embodiment of the present application, the splicing positions of the url information, data information, and preset salt value can be set in advance, so that when the client determines that the interface request initiated needs to perform parameter anti-tampering processing, the interface interception component extracts the url information and data information from the interface request, splices the url information, data information, and preset salt value according to the preset splicing positions to obtain the initial first signature string, and finally performs an MD5 operation on the initial first signature string to obtain the first signature string.

[0085] As an implementation manner of the embodiment of the present application, the preset splicing positions of the url information, data information, and preset salt value can be: the url information is in the first position, the data information is in the second position, and the preset salt value is in the third position; the above is a preferred manner for setting the splicing positions provided by the present application implementation. For the specific setting manner of the splicing positions, it can be set according to the actual application, and the embodiment of the present application does not limit it here.

[0086] For example, assume that the splicing positions of the pre-set url information, data information, and preset salt value are as follows: the url information is in the first position, the data information is in the second position, and the preset salt value is in the third position; when the client determines that the interface request to be initiated requires parameter anti-tampering operations, the url information extracted from the interface request by the interface interception component is 'https: / / www.mgtv.com?a=1&b=2', and the data information is: '{"c":1,"d":2}'; if the preset salt value is'mgtv123', then the url information, data information, and preset salt value are spliced according to the preset splicing positions, and the obtained initial first signature string is orign_str = 'https: / / www.mgtv.com?a=1&b=2{"c":1,"d":2}mgtv123'; finally, the MD5 operation is performed on the initial first signature string to obtain the final first signature string.

[0087] In the embodiments of the present application, it has been found through research that the current parameter anti-tampering method is to sort the various parameters in the interface request. However, sorting the various parameters may insert the parameters in the url information into the data information, and insert the parameters in the data information into the url information. For example, if there is a goods_id parameter in the url information, using this method may pass the goods_id parameter of the url information into the data information. Moreover, for different languages, different sorting results may occur for the same key, which not only easily leads to subsequent signature verification failures, but also is not standardized for some client interface requests. And once the parameters of the url information are placed in the data information, it may also affect the business logic, resulting in bugs in the subsequent corresponding business processing.

[0088] Therefore, when the client provided by the present application determines that the initiated interface request needs to perform parameter anti-tampering operations, the interface interception component splices the url information and the data information, and splices the obtained result with a preset salt value to obtain an initial first signature string. Finally, the interface interception component performs an MD5 operation on the initial first signature string to obtain the first signature string, without sorting the url information and the data information, so that the original url information and data information will not be disrupted. This can not only avoid signature verification failures to a certain extent, but also avoid affecting the business logic, thereby avoiding bugs in the subsequent business processing. It can be seen that by adopting the technical solution provided by the present application, there is no need to separately implement parameter extraction and sorting for each interface in advance, that is, there is no need to transform the existing interface logic, reducing the low coupling between the business code and the security verification logic, and improving the scalability of the system. On the other hand, for historical systems that have been put into production and do not integrate anti-tampering mechanisms, there is no need to perform code refactoring for each interface, which can effectively shorten the system upgrade cycle and reduce the system operation and maintenance costs. In short, the technical solution provided by the present application can complete the corresponding parameter anti-tampering processing without perception, intrusion, and low risk.

[0089] S304: The client transmits the first signature string to the risk control server based on the long connection protocol, so that the risk control server generates signature information according to the first signature string and stores the signature information.

[0090] In the specific process of executing step S304, after the client generates the first signature string of the interface request through the interface interception component, it can transmit the first signature string to the risk control server through the long connection protocol, so that the risk control server stores the received first signature string in the key-value middleware in the form of key-value pairs. That is to say, after the risk control server receives the first signature string transmitted by the client, it can generate signature information according to the first signature string and the timeout time, and store the generated signature information in the key-value middleware.

[0091] It should be noted that the signature information includes the key-value pair generated according to the first signature string and the preset timeout time. For example, if the first signature string is "sign_str", the key-value pair generated according to the first signature string can be key = sign_str, value = 1.

[0092] It should also be noted that the timeout time can be 5 seconds, 6 seconds, etc., and can be set according to the actual application. In this embodiment of the present application, it is not limited.

[0093] In the embodiments of the present application, the interface interception middleware can effectively hide the first signature string to be transmitted by transmitting it in the long connection protocol manner, and transmitting it in the long connection protocol manner can also add logic such as the encryption verification of the long connection itself, thereby increasing the security of data transmission. Configuring the preset timeout time on the generated key-value pair can be effectively used for subsequent parameter anti-tampering verification, ensuring that a signature information can only be successfully verified once within the timeout time.

[0094] It should be noted that the encryption verification logic of the long connection itself can be account and key verification, which is not limited in the embodiments of the present application.

[0095] S305: Receive the interface request sent by the client through the interface interception middleware, and when it is determined that the interface request needs to be processed for parameter anti-tampering, splice the url information and data information in the interface request, and perform anti-tampering processing on the spliced result to obtain the second signature string.

[0096] In the specific process of executing step S305, when the client sends the first signature string corresponding to the interface request to the risk control server, it can send the interface request to the interface interception middleware, so that after the interface interception middleware receives the interface request sent by the client, it can judge whether the interface request needs to be processed for parameter anti-tampering according to the parameter anti-tampering configuration file sent by the parameter anti-tampering configuration center. If it is necessary, continue to perform parameter anti-tampering processing on the interface request; if not, it can first output the corresponding prompt information to enable the user to further manually confirm the interface request; when receiving the user's confirmation that the interface request is accurate, forward the interface request to the application server; when receiving the user's confirmation that there is a problem with the interface request, intercept the interface request to avoid forwarding the interface request to the application server, and feedback the information that the interface request fails to the client.

[0097] Optionally, the process of receiving the interface request sent by the client through the interface interception middleware, and when it is determined that the interface request needs to be processed for parameter anti-tampering, splicing the url information and data information in the interface request, and performing anti-tampering processing on the spliced result to obtain the second signature string can be specifically: receiving the interface request sent by the client through the interface interception middleware, and judging whether the interface request needs to be processed for parameter anti-tampering according to the interface corresponding to the interface request and the preset parameter anti-tampering configuration file; if the interface request needs to be processed for parameter anti-tampering, splice the url information and data information in the interface request, splice the spliced result with the preset salt value to obtain the initial second signature string, and perform the MD5 operation on the initial second signature string to obtain the second signature string.

[0098] In some embodiments, the interface interception middleware may determine whether the parameter anti-tampering configuration file has an interface corresponding to the interface request; if the parameter anti-tampering configuration file has the interface, it is determined that the interface request needs to be processed for parameter anti-tampering; if the parameter anti-tampering configuration file does not have the interface, it is determined that the interface request does not need to be processed for parameter anti-tampering.

[0099] It should be noted that when the interface interception middleware receives an interface request, it can first use the pre-configured parameter anti-tampering configuration file to identify whether the currently received interface request needs parameter anti-tampering processing, avoiding performing parameter anti-tampering processing on each interface request without discrimination. This can not only improve the corresponding processing efficiency but also save certain computing resources; however, since the premise for the interface interception middleware to receive the interface request sent by the client is that the client believes that the interface request needs to be processed for parameter anti-tampering, therefore, normally the interface requests received by the interface interception middleware also need to be processed for parameter anti-tampering. At this time, if the interface interception middleware believes that the received interface request does not need to be processed for parameter anti-tampering, then it is possible that the received interface request has changed. To further ensure the accuracy of the parameter anti-tampering processing judgment, corresponding prompt information can be output to intervene in the corresponding manual confirmation to avoid misintercepting correct interface requests and thus affecting the subsequent processing of the target service.

[0100] It should also be noted that by accessing the interface middleware in this application, the interface requests that need to be processed for parameter anti-tampering can be flexibly managed. When a bug occurs in the parameter anti-tampering logic, the corresponding parameter anti-tampering logic can be temporarily taken off the shelf without modifying the overall business processing logic, that is, avoiding affecting the corresponding business logic and thus avoiding bugs in the execution of business processing.

[0101] In the embodiments of this application, when the interface interception middleware determines that the interface request needs to be processed for parameter anti-tampering, it can splice the url information, data information, and preset salt value in the interface request according to the preset splicing position to obtain the initial second signature string, and perform an MD5 operation on the initial second signature string to obtain the final second signature string.

[0102] It should be noted that the preset salt value and splicing position involved in the process of the interface interception middleware performing parameter anti-tampering processing on the interface request are the same as those involved in the process of the client performing parameter anti-tampering processing on the interface request.

[0103] S306: Receive the second signature string sent by the interface interception middleware through the risk control server, and perform parameter anti-tampering verification on the second signature string using the signature information stored in itself.

[0104] During the specific execution of step S306, after obtaining the second signature string of the interface request, the interface interception middleware may send the second signature string of the interface request to the risk control server. After receiving the second signature string of the interface request, the risk control server uses the first signature string and timeout in each signature information stored in itself to perform parameter anti-tampering verification on the second signature string. If the verification passes, it feedbacks verification information indicating that the second signature string passes the verification to the interface interception middleware. If the verification fails, it feedbacks verification information indicating that the second signature string fails the verification to the interface interception middleware.

[0105] Optionally, the process of obtaining the signature information of the interface request from the risk control server through the interface interception middleware and performing parameter anti-tampering verification on the interface request using the signature information and the second signature string can be specifically as follows: The risk control server receives the second signature string sent by the interface interception middleware. The risk control server determines whether there is signature information that matches the second signature string among the signature information stored in itself according to the second signature string. Among them, the signature information that matches the second signature string includes the first signature string and timeout that are the same as the second signature string. If there is signature information that matches the second signature string, the risk control server obtains the current time and verifies the validity of the first signature string according to the current time and the timeout. If the validity verification of the first signature string passes, the risk control server feedbacks verification information indicating that the parameter anti-tampering verification of the second signature string passes to the interface interception middleware. If the validity verification of the first signature string fails, or there is no signature information that matches the second signature string, the risk control server feedbacks verification information indicating that the parameter anti-tampering verification of the second signature string fails to the interface interception middleware.

[0106] In some embodiments, after receiving the second signature string sent by the interface interception middleware, the risk control server may search in the [key-value middleware] with Key = the second signature string to find whether there is a first signature string that is the same as the second signature string. If it exists, the signature information corresponding to the first signature string that is the same as the second signature string can be determined as the signature information that matches the second signature string. The risk control server obtains the current time and the storage time when the signature string is stored, and calculates the time difference between the current time and the storage time. It judges whether the time difference is greater than the timeout in the signature information that matches the second signature string. If it is not greater, it is determined that the parameter anti-tampering verification of the second signature string passes. If it is greater, or there is no first signature string that is the same as the second signature string, it can be determined that the parameter anti-tampering verification of the second signature string fails.

[0107] Further, in the embodiments of the present application, when the risk control server determines that the parameter anti-tampering verification of the second signature string passes, it may delete the signature information matching the second signature string from the

key-value middleware

[0108] S307: Determine through the interface interception middleware whether the verification information fed back by the risk control server indicates that the parameter anti-tampering verification of the second signature string passes; if so, execute step S308; if not, execute step S309.

[0109] S308: Send the interface request to the application server through the interface interception middleware, so that the application server executes the target service based on the interface request.

[0110] In the specific process of executing step S308, when the risk control server determines that the parameter anti-tampering verification of the second signature string of the interface request sent by the interface interception middleware passes, it feeds back verification information indicating that the second signature string verification passes to the interface interception middleware, so that when the interface interception middleware receives the verification information, it forwards the complete interface request to the application server, enabling the application server to complete the corresponding service according to the received interface request.

[0111] For example, when the target service corresponding to the interface request is placing an order, after receiving the interface request, the application server can complete the corresponding order request logic, thereby completing the corresponding order service.

[0112] In the embodiments of the present application, through research, it is found that in the existing parameter anti-tampering processing, after obtaining the corresponding signature string, the signature string will be placed at the end of the url information as a new parameter, so as to directly send the interface request carrying the signature string to the server. However, when using this method for parameter anti-tampering processing and the business intrusion is relatively large, bugs may occur, resulting in the situation where the server fails in the corresponding service processing based on the received interface request; in the present application, the obtained first signature string is sent to the risk control server for storage separately, and the complete interface request is sent to the interface interception middleware for parameter anti-tampering processing and parameter anti-tampering verification. When the parameter anti-tampering verification passes, the complete interface request is also forwarded to the server. In this way, even if the business intrusion volume is large, bugs will not occur due to changes in the received interface request, and the situation of service processing failure can be reduced to a certain extent.

[0113] S309: Intercept the interface request through the interface interception middleware and feedback a prompt message indicating that the interface request verification fails to the client.

[0114] During the specific execution of step 309, when the risk control server determines that the parameter anti-tampering verification of the second signature string fails, it sends verification information indicating that the signature string verification fails to the interface interception middleware. So that when the interface interception middleware receives this verification information, it intercepts the corresponding interface request, preventing the interface request from being transmitted to the application server. At the same time, it can also feedback a prompt message indicating that the interface request verification fails to the client, enabling the user of the client to promptly learn that the interface request verification fails and promptly perform corresponding processing to avoid affecting the corresponding business processing progress.

[0115] This application provides a parameter anti-tampering method, which is applied to a parameter anti-tampering system. The parameter anti-tampering system includes a client, a risk control server, an interface interception middleware, and an application server. The client has a long connection with the risk control server; the client generates a corresponding interface request according to the target business, where the interface request includes at least url information and data information; if the interface request needs to be processed for parameter anti-tampering, the client splices the url information and data information, and performs anti-tampering processing on the spliced result to obtain a first signature string; the client transmits the first signature string to the risk control server based on the long connection protocol, so that the risk control server generates signature information according to the first signature string and stores the signature information; the interface interception middleware receives the interface request sent by the client, and when it determines that the interface request needs to be processed for parameter anti-tampering, it splices the url information and data information in the interface request, and performs anti-tampering processing on the spliced result to obtain a second signature string; the risk control server receives the second signature string sent by the interface interception middleware, and uses the signature information stored by itself to perform parameter anti-tampering verification on the second signature string; when the interface interception middleware receives the verification information feedback by the risk control server indicating that the second signature string verification passes, it sends the interface request to the application server, enabling the application server to execute the target business based on the interface request. It can be seen that in the technical solution provided by this application, when the client and the interface interception middleware determine that the interface request needs to be processed for parameter anti-tampering, they directly splice the url information and data information in the interface request, perform anti-tampering processing on the spliced result to obtain the corresponding signature string, without sorting the parameters in the interface request, that is, there is no need to separately implement parameter extraction and sorting for each interface, reducing the coupling between business code and security verification, and improving the scalability of the parameter anti-tampering system; moreover, for a parameter anti-tampering system that has been put into production and has not integrated an anti-tampering mechanism, there is no need to reconstruct the code for each interface, which can effectively reduce the system upgrade cycle and the system operation and maintenance cost.

[0116] To better understand the parameter anti-tampering method provided by this application, the following is an illustrative explanation, such asFigure 4 as shown

[0117] For example, the user pre-configures the corresponding parameter anti-tampering configuration file through the parameter anti-tampering configuration center, and distributes the parameter anti-tampering configuration file to the client and the interface interception middleware simultaneously through the parameter anti-tampering configuration center.

[0118] When the client detects the existence of a target service, it can initiate an interface request for the target service through the application module, that is, generate an initial interface request for the interface requested by the target service through the application module. Among them, the request type of the initial interface request is the post request type; the initial interface request is directly used as the interface request for the target service.

[0119] The client intercepts the interface request through the interface interception component and performs parameter anti-tampering processing on the interface request, that is, judges whether the interface corresponding to the interface request is included in the parameter anti-tampering configuration file; if it is included, it is determined that the interface request needs to be processed for parameter anti-tampering. According to the pre-set splicing position, the url information, data information and preset salt value in the interface request are spliced to obtain an initial first signature string, and the MD5 operation is performed on the initial first signature string to obtain a first signature string. Finally, the first signature string is sent to the risk control server through the long link protocol.

[0120] The risk control server generates signature information based on the received first signature string and the timeout time, and stores the signature information in the key-value middleware.

[0121] The client sends the interface request to the interface interception middleware through the interface interception component.

[0122] The interface interception middleware performs parameter anti-tampering processing on the interface request sent by the client, that is, judges whether the interface corresponding to the interface request is included in the parameter anti-tampering configuration file; if it is included, it is determined that the interface request needs to be processed for parameter anti-tampering. According to the pre-set splicing position, the url information, data information and preset salt value in the interface request are spliced to obtain an initial second signature string, and the MD5 operation is performed on the initial second signature string to obtain a second signature string. Finally, the second signature string is sent to the risk control server.

[0123] The risk control server (including long connections) performs parameter anti-tampering verification on the second signature string, that is, determines whether there is a first signature string in each signature information stored by itself that is the same as the second signature string; if it exists, determines the signature information corresponding to the first signature string that is the same as the second signature string as the signature information matching the second signature string; determines whether the timeout time in the signature information is greater than the time difference, where the time difference is the difference between the current time of the risk control server and the time when the signature information is stored; if it is not greater, determines that the parameter anti-tampering verification of the second signature string passes, and feeds back verification information indicating that the second signature string passes the verification to the interface interception middleware.

[0124] When the interface interception middleware receives the verification information indicating that the second signature string passes the verification, it sends an interface request to the application server, so that the application server performs corresponding business processing according to the interface request.

[0125] This application also provides a storage medium, in which program instructions are stored, and when the program instructions are loaded and executed by a processor, any of the above parameter anti-tampering method embodiments is implemented.

[0126] This application also provides an electronic device, as Figure 5 shown, the device includes a processor 501 and a memory 502, and the processor and the memory are connected through a bus; program instructions are stored in the memory; the processor calls the program instructions in the memory to execute any of the above parameter anti-tampering method embodiments.

[0127] The processor in this article can be the CPU of the terminal, or, is the MCU integrated in the terminal, or, can also be the combination of the CPU and the MCU. Moreover, the processor contains a kernel, and the corresponding program is retrieved from the memory by the kernel, and one or more kernels can be set.

[0128] The memory may include non-permanent memory in the computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one memory chip.

[0129] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for a system or system embodiment, since it is basically similar to a method embodiment, the description is relatively simple, and reference can be made to the corresponding part of the method embodiment for relevant content. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.

[0130] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0131] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0132] The above is only the preferred embodiment of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A parameter anti-tampering method, characterized in that Applied to a parameter anti-tampering system, the parameter anti-tampering system includes a client, a risk control server, an interface interception middleware, and an application server. The client establishes a long connection with the risk control server. The method includes: Generating, by the client, a corresponding interface request according to a target service, where the interface request includes at least url information and data information; If the interface request needs to be processed for parameter anti-tampering, splicing, by the client, the url information and the data information, and performing anti-tampering processing on the spliced result to obtain a first signature string; Transmitting, by the client, the first signature string to the risk control server based on the long connection protocol, so that the risk control server generates signature information according to the first signature string and stores the signature information; Receiving, by the interface interception middleware, the interface request sent by the client, and when determining that the interface request needs to be processed for parameter anti-tampering, splicing the url information and the data information in the interface request, and performing anti-tampering processing on the spliced result to obtain a second signature string; Receiving, by the risk control server, the second signature string sent by the interface interception middleware, and performing parameter anti-tampering verification on the second signature string by using the signature information stored by itself; When receiving, by the interface interception middleware, verification information indicating that the second signature string passes the verification sent by the risk control server, sending the interface request to the application server, so that the application server executes the target service based on the interface request.

2. The method according to claim 1, wherein The generating, by the client, a corresponding interface request according to a target service includes: Generating, by the client, a corresponding initial interface request according to the interface requested by the target service, and determining the request type of the initial interface request; If the request type is a target request type, obtaining, by the client, data information related to the target service, and generating, according to the url information and the data information in the initial interface request, an interface request corresponding to the target service; If the request type is not the target request type, determining, by the client, the initial interface request as the interface request of the target service.

3. The method according to claim 1, wherein The client includes an interface interception component, and the method further includes: Judging, by the interface interception component, whether an interface corresponding to the interface request exists in a pre-set parameter anti-tampering configuration file; where the parameter anti-tampering configuration file is pre-configured by a parameter anti-tampering configuration center in the parameter anti-tampering system; If the interface exists in the parameter anti-tampering configuration file, determining, by the interface interception component, that the interface request needs to be processed for parameter anti-tampering; If the interface does not exist in the parameter anti-tampering configuration file, determining, by the interface interception component, that the interface request does not need to be processed for parameter anti-tampering.

4. The method according to claim 3, wherein The splicing, by the client, the url information and the data information, and performing anti-tampering processing on the spliced result to obtain a first signature string includes: The interface interception component splices the url information and the data information, and splices the obtained result with a preset salt value to obtain an initial first signature string; The interface interception component performs an MD5 operation on the initial first signature string to obtain a first signature string.

5. The method according to claim 1, characterized in that, The interface interception middleware receives the interface request sent by the client, and when it is determined that the interface request needs to perform parameter anti-tampering processing, it splices the url information and the data information in the interface request, and performs anti-tampering processing on the obtained result to obtain a second signature string, including: The interface interception middleware receives the interface request sent by the client, and determines whether the interface request needs to perform parameter anti-tampering processing according to the interface corresponding to the interface request and a preset parameter anti-tampering configuration file; If the interface request needs to perform parameter anti-tampering processing, the interface interception middleware splices the url information and the data information in the interface request, and splices the obtained result with a preset salt value to obtain an initial second signature string, and performs an MD5 operation on the initial second signature string to obtain a second signature string.

6. The method according to claim 1, wherein The risk control server receives the second signature string sent by the interface interception middleware, and uses the signature information stored in itself to perform parameter anti-tampering verification on the second signature string, including: The risk control server receives the second signature string sent by the interface interception middleware; The risk control server determines whether there is signature information matching the second signature string among the signature information stored in itself according to the second signature string; among them, the signature information matching the second signature string includes a first signature string identical to the second signature string and a timeout; If there is signature information matching the second signature string, the risk control server obtains the current time, and verifies the validity of the first signature string according to the current time and the timeout; If the validity verification of the first signature string passes, the risk control server feeds back verification information indicating that the parameter anti-tampering verification of the second signature string passes to the interface interception middleware; If the validity verification of the first signature string fails, or there is no signature information matching the second signature string, the risk control server feeds back verification information indicating that the parameter anti-tampering verification of the second signature string fails to the interface interception middleware.

7. The method according to claim 1, wherein The method further includes: When the interface interception middleware receives the verification information indicating that the parameter anti-tampering verification of the second signature string fails fed back by the risk control server, it intercepts the interface request and feeds back a prompt message indicating that the interface request verification fails to the client.

8. A parameter anti-tampering system, characterized in that, The system includes: a client, a risk control server, an interface interception middleware, and an application server, and the client establishes a long connection with the risk control server; The client is used to generate a corresponding interface request according to the target service. Among them, the interface request at least includes url information and data information; if the interface request needs to perform parameter anti-tampering processing, the url information and the data information are spliced, and the result obtained by splicing is subjected to anti-tampering processing to obtain a first signature string; based on the long connection protocol, the first signature string is transmitted to the risk control server, so that the risk control server generates signature information according to the first signature string and stores the signature information. The interface interception middleware is used to receive the interface request sent by the client, and when it is determined that the interface request needs to perform parameter anti-tampering processing, the url information and the data information in the interface request are spliced, and the result obtained by splicing is subjected to anti-tampering processing to obtain a second signature string; when receiving the verification information indicating that the second signature string passes the verification feedback by the risk control server, the interface request is sent to the application server, so that the application server executes the target service based on the interface request. The risk control server is used to receive the second signature string sent by the interface interception middleware, and perform parameter anti-tampering verification on the second signature string by using the signature information stored in itself.

9. An electronic device, characterized in that, Comprising: A processor and a memory, the processor and the memory are connected by a bus; wherein, the processor is used to call and execute the program stored in the memory. The memory is used to store a program, and the program is used to implement a parameter anti-tampering method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to execute a parameter anti-tampering method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • REST security system based on signature mechanism

    CN103095731A

  • Application version verification method, device, computer device, and storage medium

    CN109254921A

  • Web interface design method for preventing request message from being tampered, attacked and replayed

    CN111447195A

  • Method and system for integrity check vulnerability security protection

    CN112699374A

  • Anti-refreshing method and system for http interface, and related equipment

    CN115567200A