Multi-mechanism anti-replay attack enhanced configuration method and system

Through the triple mechanism of random numbers, timestamps and distributed locks, combined with Redis storage, the problem of insufficient security of the existing anti-replay attack methods is solved, efficient data transmission and system stability are achieved, and data leakage and service interruption caused by replay attacks are prevented.

CN120358070APending Publication Date: 2025-07-22INSPUR COMM INFORMATION SYST (TIANJIN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510678616.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing anti-replay attack methods are inadequate in the face of complex environments and diverse attack methods, and cannot effectively prevent the risk of data leakage and service interruption.

Method used

The triple mechanism of random number + timestamp + distributed lock is adopted. Through the client-server two request mechanism, the server generates random numbers and sets the validity period. Combined with the number of requests for the distributed lock control interface, UUID is introduced as the key, and Redis storage and query are used to realize multi-level request control.

Benefits of technology

Significantly improve system security and attack resistance, reduce the risk of data leakage and service interruption, ensure the integrity and authenticity of data transmission, and be suitable for high concurrency scenarios, providing a safe and reliable service experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358070A_ABST
    Figure CN120358070A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-mechanism anti-replay attack enhanced configuration method and system, and belongs to the technical field of network security, the method realizes anti-replay attack based on a triple mechanism of a random number, a timestamp and a distributed lock, and is realized based on a client-server twice request mechanism, and the method comprises the following steps: a client requests a server and obtains the random number; the server side generates a random number, records the random number through a timestamp, sets the validity period time t of the random number, and then returns the random number to the client side; the server side introduces a service interface into the distributed lock to ensure that the service interface can only request for one time within the time t, and a single user requests for n times at most every day; and the client carries the random number to request the service interface of the server again, and the server controls the access of the service interface according to the setting. According to the invention, the security and anti-attack capability of the system can be improved, the integrity and authenticity of data transmission are ensured, and the risks of data leakage and service interruption caused by replay attacks are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the technical field of network security, and in particular to a multi-mechanism anti-replay attack enhanced configuration method and system. Background Art

[0002] Anti-replay attack is an important technology in the field of network security, which aims to prevent attackers from impersonating users or performing unauthorized operations by intercepting and repeatedly sending legitimate data packets. As network attack methods continue to evolve, anti-replay attack technology is also constantly developing. Commonly used anti-replay attack methods are:

[0003] Timestamp: The principle of the timestamp method is relatively simple, based on the client-server one-time request mechanism. The client directly requests the business interface, and carries the timestamp in the request. When the server receives the client's request, it immediately verifies whether the timestamp is within the allowed range. If it is, the request is legal; if not, it is considered a replay attack, and the server refuses to respond. Although this method reduces the risk of replay attacks to a certain extent, when illegal users intercept the request data and frequently initiate requests within the validity period, they can still access the business interface normally, and the risk of replay attacks still exists.

[0004] Random number: The random number method is also based on the client-server one-time request mechanism. The client generates a random number and carries the random number to request the business interface. The server receives the client's request and records the random number. At the same time, it determines whether the random number has been used. If it has been used, it is considered a replay attack. Although this method alleviates the risk of replay attacks to a certain extent, the server needs to cache a large number of random numbers, occupying cache resources; in addition, if the token is stolen, illegal attackers can access the business interface unlimited times, and the loss will become greater and greater.

[0005] Digital signature: The digital signature method is also based on the client-server one-time request mechanism. When the client requests the service interface, the request data is digitally signed. When the server receives the request, it verifies the legitimacy and integrity of the signature immediately to prevent data tampering and replay attacks. However, this method has high computational overhead and is suitable for high-security scenarios. Summary of the invention

[0006] The technical task of the present invention is to address the above shortcomings and provide a multi-mechanism anti-replay attack enhanced configuration method and system, aiming to solve the shortcomings of the prior art in the anti-replay attack mechanism when facing complex environments and diverse attack methods, and to improve the security and anti-attack capabilities of the system, ensure the integrity and authenticity of data transmission, and effectively reduce the risks of data leakage and service interruption caused by replay attacks.

[0007] The technical solution adopted by the present invention to solve its technical problem is:

[0008] A method for enhancing the configuration of a multi - mechanism anti - replay attack, which realizes the anti - replay attack based on a triple mechanism of random number + timestamp + distributed lock and is based on a two - request mechanism between the client and the server. The implementation of this method includes the following steps:

[0009] (1) The client requests the server to obtain a random number; the server generates a random number, records the random number through a timestamp, sets the validity period time t of the random number, and then returns the random number to the client;

[0010] (2) The server introduces a distributed lock to the service interface to ensure that the service interface can only be requested once within the time t, and a single user can request at most n times per day, where the value of n is set according to the actual application situation;

[0011] (3) The client carries the random number and requests the server service interface again. The server controls the access of the service interface according to the settings in step (2), thereby enhancing the anti - replay attack.

[0012] By introducing technologies such as random numbers, timestamps, and distributed locks, this method eliminates the risk of the attack window period suffered by the timestamp method to a certain extent, solves the cache problem of the random number method, and has simple calculations. Even if the interface for obtaining random numbers is breached, due to the limit on the number of requests, the scope and loss of the impact after being attacked will be reduced to a certain extent. It can improve the security and anti - attack ability of the system, ensure the integrity and authenticity of data transmission, and effectively reduce the risks of data leakage and service interruption caused by replay attacks.

[0013] Further, the validity period time t is 60s.

[0014] Further, the server generates a random number, and the random number is returned to the client in the form of a graphical verification code;

[0015] To further enhance security, when the server returns the verification code, it also generates a unique UUID and stores it in Redis as the key of the random number; when the client submits the verification code, it needs to carry the UUID at the same time, and the server obtains the corresponding random number from Redis through the UUID for verification.

[0016] This method effectively solves the problem of algorithm cracking that may be caused by front-end random number generation, because the generation and storage of random numbers are completely controlled by the server, avoiding the potential security risks caused by the client generating random numbers. At the same time, by introducing UUID as the key of the random number, the uniqueness and unpredictability of each verification code request is ensured, further enhancing the system's anti-attack ability. In addition, Redis's efficient storage and query mechanism ensures the real-time and reliability of the verification process, and can effectively cope with verification needs in high-concurrency scenarios.

[0017] Furthermore, the graphic verification code is in the form of a combination of letters and numbers, or in the form of integer addition and subtraction.

[0018] Furthermore, the timestamp is used to control the validity period of the random number and is used in combination with Redis; by setting the storage time t of the random number in Redis, replay attacks caused by random number leakage can be effectively prevented.

[0019] This mechanism ensures that the random number automatically expires after a certain period of time. Even if an attacker obtains the random number, he or she cannot use it to perform illegal operations outside the time window, thereby significantly improving system security.

[0020] Furthermore, the distributed lock is used to control the interface time t to prevent repeated requests and the maximum number of requests per day n (set according to actual conditions); the distributed lock is implemented based on Redis, and the user request frequency and number are effectively managed by setting two keys:

[0021] First, key1 is used to record whether the user has initiated a request within time t. Its validity period is set to t to avoid excessive cache data. If a repeated request is detected within time t, the system rejects the request, thereby preventing high-frequency access in a short period of time.

[0022] Secondly, key2 is used to record the number of requests made by users every day, and its validity period is set to 24 hours to ensure accurate statistics and control of the number of requests made every day. In this way, the system can effectively limit the number of requests made by users every day and avoid resource abuse.

[0023] Furthermore, for the distributed lock, in order to further enhance the security of the system, the key design can be expanded to include the user's IP address in the monitoring range:

[0024] If a single IP is detected to initiate requests multiple times within a short period, the system records this IP in the blacklist and filters it at the gateway layer, directly rejecting subsequent requests from this IP. This mechanism can not only effectively prevent malicious attacks and abuse behaviors, but also significantly enhance the stability and security of the system. By combining the distributed lock and IP blacklist strategies, the system can achieve multi-level and multi-dimensional request control, ensure the reasonable allocation and use of resources, and at the same time provide users with a more secure and reliable service experience.

[0025] The present invention also claims to protect a multi-mechanism replay attack prevention enhanced configuration system, including:

[0026] A random number generation module, which is used to achieve: the client requests the server, the server generates a random number and records the random number through a timestamp, sets the validity period time t of the random number, and then returns the random number to the client;

[0027] A distributed lock setting module, which is used to achieve: the server introduces a distributed lock to the service interface to ensure that the service interface can only be requested once within the time t, and a single user can request at most n times per day;

[0028] A verification module, which is used to achieve: when the client carries the random number and requests the service interface of the server again, the server controls the access of the service interface according to the settings of the distributed lock setting module;

[0029] This system specifically realizes replay attack prevention through the above multi-mechanism replay attack prevention enhanced configuration method.

[0030] The present invention also claims to protect a multi-mechanism replay attack prevention enhanced configuration device, including: at least one memory and at least one processor;

[0031] The at least one memory is used to store machine-readable programs;

[0032] The at least one processor is used to call the machine-readable program to implement the above method.

[0033] The present invention also claims to protect a computer-readable medium, on which computer instructions are stored, and when the computer instructions are executed by a processor, the above method is implemented.

[0034] Compared with the prior art, a multi-mechanism replay attack prevention enhanced configuration method and system of the present invention have the following beneficial effects:

[0035] The present invention realizes an enhanced configuration for preventing replay attacks based on a triple mechanism of random number + timestamp + distributed lock. By introducing random numbers and timestamps, it effectively prevents the repeated submission of requests, ensuring the uniqueness and timeliness of each request. The distributed lock mechanism further enhances the system's concurrent processing ability, avoiding data conflicts and replay attacks in high-concurrency scenarios. Practical applications show that this mechanism not only successfully intercepts malicious attacks but also significantly reduces the system's false positive rate and improves the user experience. In addition, the implementation of this mechanism has no obvious impact on the system performance, and the average response time remains at the millisecond level. This method for preventing replay attacks provides a strong guarantee for system security and has broad application prospects and promotion value. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is a schematic diagram of the principle of the method for enhancing the configuration of preventing replay attacks with multiple mechanisms provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] The present invention will be further described below with reference to the drawings and specific embodiments.

[0038] A method for enhancing the configuration of preventing replay attacks with multiple mechanisms, which realizes the prevention of replay attacks based on a triple mechanism of random number + timestamp + distributed lock and is based on a two-request mechanism between the client and the server.

[0039] The implementation of this method includes the following steps:

[0040] 1. The client requests the server to obtain a random number. The server generates a random number and records it with a timestamp, controls the validity period of the random number to be 60s, and then returns the random number to the client.

[0041] 2. The server introduces a distributed lock to the business interface to ensure that the business interface can only be requested once within 60s, and a single user can request at most n times per day, where n can be set according to the actual situation.

[0042] 3. The client carries the random number and requests the server business interface again. The server controls the access to the business interface according to the settings in the above steps, thereby enhancing the prevention of replay attacks.

[0043] Replay Attack Protection is a security mechanism used to prevent attackers from impersonating legitimate users or performing unauthorized operations by intercepting and replaying legitimate data packets (such as requests, messages, or tokens). This method proposes a triple mechanism of random number + timestamp + distributed lock for enhancing the configuration of replay attack protection, further improving the security of the system and the integrity of data, and effectively protecting sensitive information from the threat of such attacks. Through two request-responses between the client and the server, a combined condition of random number, timestamp, and distributed lock is formed to enhance replay attack protection and improve the security of the system and the integrity of data. To a certain extent, it eliminates the risk of the attack window period suffered by the timestamp method, solves the cache problem of the random number method, and has simple calculation. Even if the interface for obtaining random numbers is breached, due to the limit of the number of requests, the scope and loss of the impact after being attacked are reduced to a certain extent.

[0044] Combined with the attached Figure 1 As shown, the specific implementation method of this method is as follows:

[0045] I. Random number generation.

[0046] This method adopts the strategy of generating random numbers on the server side, and the random numbers are returned to the client in the form of graphic verification codes. The graphic verification code can be in various forms, such as a combination of letters and numbers. In this embodiment, a simple integer addition and subtraction is adopted.

[0047] To further enhance security, when the server returns the verification code, it also generates a unique UUID and stores it in Redis as the key of the random number. When the client submits the verification code, it needs to carry the UUID at the same time. The server obtains the corresponding random number from Redis through the UUID for verification. This method effectively solves the problem of algorithm cracking that may be caused by generating random numbers on the front end, because the generation and storage of random numbers are completely controlled by the server, avoiding potential security risks brought by generating random numbers on the client. At the same time, by introducing UUID as the key of the random number, the uniqueness and unpredictability of each verification code request are ensured, further enhancing the anti-attack ability of the system. In addition, the efficient storage and query mechanism of Redis ensures the real-time and reliability of the verification process and can effectively meet the verification requirements in high-concurrency scenarios.

[0048] II. Timestamp control.

[0049] The timestamp mainly controls the valid time of the random number and is used in combination with Redis.

[0050] By setting the storage time of random numbers in Redis to 60 seconds, replay attacks caused by random number leaks can be effectively prevented. This mechanism ensures that random numbers automatically expire after a certain period of time. Even if an attacker obtains a random number, he cannot use it to perform illegal operations outside the time window, thus significantly improving system security.

[0051] 3. Distributed lock.

[0052] The distributed lock mainly controls the interface to prevent repeated requests within 60 seconds and the maximum number of requests per day n (set according to actual conditions). The distributed lock is implemented based on Redis, and two keys are set to effectively manage the frequency and number of user requests.

[0053] First, key1 is used to record whether the user has initiated a request within 60 seconds. Its validity period is set to 60 seconds to avoid caching too much data. If a repeated request is detected within 60 seconds, the system can reject the request, thereby preventing high-frequency access in a short period of time.

[0054] Secondly, key2 is used to record the number of requests made by users every day, and its validity period is set to 24 hours to ensure accurate statistics and control of the number of requests made every day. In this way, the system can effectively limit the number of requests made by users every day and avoid resource abuse.

[0055] In addition, in order to further enhance the security of the system, the key design can be expanded to include the user's IP address in the monitoring range. If a single IP is detected to initiate multiple requests in a short period of time, the system can record the IP in the blacklist and filter it at the gateway layer, directly rejecting subsequent requests from the IP. This mechanism can not only effectively prevent malicious attacks and abuse, but also significantly improve the stability and security of the system. By combining distributed locks and IP blacklist strategies, the system can achieve multi-level and multi-dimensional request control, ensure the rational allocation and use of resources, and provide users with a safer and more reliable service experience.

[0056] The experimental results show that the triple mechanism of random number + timestamp + distributed lock to prevent replay attacks significantly improves the security of the system. By testing 100,000 simulated requests, divided into 10 groups of requests, the system successfully intercepted all replay attacks. The combination of random numbers and timestamps effectively prevents repeated submission of requests, while the distributed lock mechanism ensures data consistency in high-concurrency scenarios. The experiment also shows that the mechanism performs particularly well in the face of large-scale distributed attacks, and can quickly identify and block abnormal requests to ensure the stable operation of the system. Overall, the experimental results verify the efficiency and reliability of the mechanism in practical applications, providing a strong guarantee for system security.

[0057] This method has been successfully implemented in the content publishing functions of multiple applications, significantly enhancing the security of the system.

[0058] An embodiment of the present invention also provides a multiple - mechanism replay - attack - prevention enhanced configuration system, including:

[0059] 1. A random number generation module, which is used to achieve: The client requests the server, the server generates a random number and records the random number through a timestamp, sets the validity period of the random number to 60s, and then returns the random number to the client.

[0060] This system adopts the strategy of the server generating random numbers. The random number is returned to the client in the form of a graphical verification code. The graphical verification code can be in various forms, such as a combination of letters and numbers. In this embodiment, a simple integer addition and subtraction is adopted.

[0061] To further enhance security, when the server returns the verification code, it also generates a unique UUID and stores it as the key of the random number in Redis. When the client submits the verification code, it needs to carry the UUID at the same time. The server obtains the corresponding random number from Redis through the UUID for verification. This method effectively solves the problem of algorithm cracking that may be caused by the generation of random numbers on the front - end, because the generation and storage of random numbers are completely controlled by the server, avoiding potential security risks caused by the client generating random numbers. At the same time, by introducing UUID as the key of the random number, the uniqueness and unpredictability of each verification code request are ensured, further enhancing the anti - attack ability of the system. In addition, the efficient storage and query mechanism of Redis ensures the real - time nature and reliability of the verification process, and can effectively meet the verification requirements in high - concurrency scenarios.

[0062] The timestamp mainly controls the valid time of the random number and is used in combination with Redis. By setting the storage time of the random number in Redis to 60 seconds, it can effectively prevent replay attacks caused by random number leakage. This mechanism ensures that the random number automatically expires after a certain time. Even if an attacker obtains the random number, they cannot use the random number for illegal operations outside the time window, thus significantly enhancing the security of the system.

[0063] 2. A distributed lock setting module, which is used to achieve: The server introduces a distributed lock into the business interface to ensure that the business interface can only be requested once within 60s, and a single user can request at most n times per day.

[0064] The distributed lock mainly controls that the interface cannot be repeatedly requested within 60s and the maximum number of requests per day n (set according to the actual situation). The implementation of the distributed lock is based on Redis, and two keys are set to effectively manage the user request frequency and number.

[0065] First, key1 is used to record whether the user has initiated a request within 60 seconds. Its validity period is set to 60 seconds to avoid excessive cached data. If a duplicate request is detected within 60 seconds, the system can reject the request to prevent high-frequency access within a short period.

[0066] Secondly, key2 is used to record the number of requests made by the user per day. Its validity period is set to 24 hours to ensure accurate statistics and control of the daily request count. In this way, the system can effectively limit the daily request volume of users and avoid resource abuse.

[0067] In addition, to further enhance the security of the system, the design of the key can be extended to include the user's IP address in the monitoring scope. If it is detected that a single IP has initiated multiple requests within a short period, the system can record this IP in the blacklist and filter it at the gateway layer, directly rejecting subsequent requests from this IP. This mechanism can not only effectively prevent malicious attacks and abuse behaviors but also significantly improve the stability and security of the system. By combining the distributed lock and the IP blacklist strategy, the system can achieve multi-level and multi-dimensional request control, ensuring the reasonable allocation and use of resources while providing a more secure and reliable service experience for users.

[0068] 3. Verification module, which is used to implement: when the client requests the service-side business interface again with a random number, the service side controls the access to the business interface according to the settings of the distributed lock setting module.

[0069] This system specifically realizes anti-replay attack through the multiple-mechanism anti-replay attack enhancement configuration method described in the above embodiments. The implementation process is as follows:

[0070] 1. The client requests the service side to obtain a random number. The service side generates a random number and records the random number through a timestamp, controlling the validity period of the random number to be 60s, and then returns the random number to the client.

[0071] 2. The service side introduces a distributed lock to the business interface to ensure that the business interface can only be requested once within 60s, and a single user can request at most n times per day, where n can be set according to the actual situation.

[0072] 3. The client requests the service-side business interface again with the random number. The service side controls the access to the business interface according to the settings in the above steps, thereby enhancing the anti-replay attack.

[0073] An embodiment of the present invention also provides a multiple-mechanism anti-replay attack enhancement configuration device, including: at least one memory and at least one processor;

[0074] The at least one memory is used to store machine-readable programs;

[0075] The at least one processor is configured to call the machine-readable program to implement the multi-mechanism replay attack prevention enhancement configuration method described in the above embodiments.

[0076] An embodiment of the present invention further provides a computer-readable medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the multi-mechanism replay attack prevention enhancement configuration method described in the above embodiments is implemented. Specifically, a system or device equipped with a storage medium can be provided, on which software program code for implementing the functions of any one of the above embodiments is stored, and the computer (or CPU or MPU) of the system or device is caused to read and execute the program code stored in the storage medium.

[0077] In this case, the program code read from the storage medium itself can implement the functions of any one of the above embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of the present invention.

[0078] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, the program code can be downloaded from a server computer via a communication network.

[0079] In addition, it should be clear that not only can the functions of any one of the above embodiments be implemented by executing the program code read by the computer, but also by causing an operating system or the like operating on the computer based on the instructions of the program code to complete part or all of the actual operations.

[0080] In addition, it can be understood that the program code read from the storage medium is written into a memory provided in an expansion board inserted into the computer or a memory provided in an expansion unit connected to the computer, and then based on the instructions of the program code, a CPU or the like installed on the expansion board or the expansion unit is caused to execute part and all of the actual operations, thereby implementing the functions of any one of the above embodiments.

[0081] The present invention has been described in detail above with reference to the drawings and preferred embodiments. However, the present invention is not limited to these disclosed embodiments. Based on the above multiple embodiments, those skilled in the art can know that code review means in different above embodiments can be combined to obtain more embodiments of the present invention, and these embodiments are also within the protection scope of the present invention.

Claims

1. A method for enhancing the configuration of a multi - mechanism anti - replay attack, characterized in that, This method implements anti-replay attack based on the triple mechanism of random number + timestamp + distributed lock, and is implemented based on the client-server double request mechanism. The implementation of this method includes the following steps: (1) The client requests the server to obtain a random number; the server generates a random number and records it with a timestamp, sets a validity period t for the random number, and then returns the random number to the client; (2) The server introduces a distributed lock into the service interface to ensure that the service interface can only be requested once within a time period t, and a single user can request it at most n times per day, where n is set according to the actual application situation; (3) The client carries the random number and requests the service interface of the server again. The server controls the access to the service interface according to the setting of step (2), thereby enhancing the protection against replay attacks.

2. The enhanced configuration method for preventing replay attacks with multiple mechanisms according to claim 1, wherein, The validity period t is 60s.

3. A method for enhancing the configuration of a multi-mechanism anti-replay attack according to claim 1, characterized in that The server generates a random number, which is returned to the client in the form of a graphic verification code; When the server returns the verification code, it generates a unique UUID and stores it in Redis as a random number key. When the client submits the verification code, it needs to carry the UUID at the same time. The server obtains the corresponding random number from Redis through the UUID for verification.

4. A method for enhancing the configuration of a multi - mechanism anti - replay attack according to claim 3, characterized in that, The graphic verification code is in the form of a combination of letters and numbers, or in the form of integer addition and subtraction.

5. A method for enhancing the configuration of a multi-mechanism anti-replay attack according to claim 1, characterized in that, The timestamp is used to control the validity period of the random number and is used in conjunction with Redis. By setting the storage time t of the random number in Redis, replay attacks caused by random number leakage can be prevented.

6. A method for enhancing the configuration of a multi - mechanism anti - replay attack according to claim 1 or 5, characterized in that, The distributed lock is used to control the interface to not repeat requests within the time t, and the maximum number of requests per day is n; the distributed lock is implemented based on Redis, and the user request frequency and number are effectively managed by setting two keys: First, key1 is used to record whether the user has initiated a request within time t, and its validity period is set to t; if a repeated request is detected within time t, the system rejects the request, thereby preventing high-frequency access in a short period of time; Secondly, key2 is used to record the number of requests made by users every day, and its validity period is set to 24 hours to ensure accurate statistics and control of the number of requests made every day.

7. A method for enhancing the configuration of a multi-mechanism anti-replay attack according to claim 6, characterized in that, For the distributed lock, the key design is extended to include the user's IP address in the monitoring scope: If a single IP is detected to have initiated multiple requests within a short period of time, the system will record the IP in the blacklist and filter it at the gateway layer, directly rejecting subsequent requests from the IP.

8. A multiple - mechanism anti - replay attack enhanced configuration system, characterized in that, include: The random number generation module is used to implement: the client requests the server, the server generates a random number and records the random number through a timestamp, sets the validity period t of the random number, and then returns the random number to the client; The distributed lock setting module is used to implement: the server introduces the business interface into the distributed lock to ensure that the business interface can only be requested once within a time period of t, and a single user can request at most n times per day; The verification module is used to realize: when the client carries a random number to request the server's business interface again, the server controls the access to the business interface according to the settings of the distributed lock setting module; The system specifically implements replay attack prevention through the multi - mechanism replay attack prevention enhancement configuration method described in any one of claims 1 to 7.

9. A multi-mechanism anti-replay attack enhanced configuration device, characterized in that It includes: At least one memory and at least one processor; The at least one memory is used for storing machine - readable programs; The at least one processor is used for calling the machine - readable programs to implement the method described in any one of claims 1 to 7.

10. A computer-readable medium, characterized in that, Computer instructions are stored on the computer - readable medium, and when the computer instructions are executed by a processor, the method described in any one of claims 1 to 7 is implemented.