Replay attack defense method and device, equipment and medium

By generating and splicing dynamic tokens of triple random strings, combining risk assessment and encryption technology, the problem of replay attacks in the existing technology is easily tampered with, and efficient data transmission security defense is achieved.

CN120498850APending Publication Date: 2025-08-15INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510824131.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, methods to defend against replay attacks are easily affected by clock synchronization problems, and static tokens are easily tampered with, and attackers can easily perform replay attacks.

Method used

By obtaining the processing request sent by the client, generating and splicing triple random strings, combining risk assessments to generate dynamic tokens, including IP address, account login time and frequency assessments, encrypting using hash, asymmetric encryption or digital signatures, to generate and update tokens in real time.

Benefits of technology

Effectively prevent replay attacks, improve data transmission security and reliability, dynamically adjust security protection levels, save computing resources, and improve defense efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498850A_ABST
    Figure CN120498850A_ABST
Patent Text Reader

Abstract

The invention provides a replay attack defense method. The method can be applied to the technical fields of big data and information security. The method comprises the steps that a processing request sent by a client side is acquired, a processing response is generated, and the processing response comprises a first character string generated by a server for the processing response; and obtaining a second character string generated by the server gateway detecting and processing the response. And obtaining client interface information, and generating a third character string based on the client interface information. And performing risk assessment on the processing request sent by the client, and generating a risk value of the processing request sent by the client. And based on the risk value of the processing request sent by the client, encrypting and splicing the first character string, the second character string and the third character string to generate a first target token. And sending the processing response and the first target token to the client for replay attack defense. The invention further provides a replay attack defense device and equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of big data technology, specifically to the field of information security technology, and in particular to a replay attack defense method, apparatus, device, medium, and program product. Background Art

[0002] With the rapid development of computer technology, enterprises, including banks, have increasingly demanded greater information security. Replay attacks are one of the primary threats to information security. A replay attack occurs when an attacker intercepts and replays previously legitimate communication data in an attempt to perform the same operation again.

[0003] Existing methods for defending against replay attacks typically involve the generation and verification of static tokens and timestamp-based authentication mechanisms. These methods generate a token at the beginning of a request and use it throughout the session. However, if the token is intercepted, the timestamp can be affected by clock synchronization issues and easily tampered with, making it easy for an attacker to launch a replay attack. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a replay attack defense method, apparatus, device, medium, and program product.

[0005] According to a first aspect of the present disclosure, a replay attack defense method is provided, which includes: obtaining a processing request sent by a client and generating a processing response, wherein the processing response includes: a first character string generated by a server for the processing response; obtaining a second character string generated by a server gateway detecting the processing response; obtaining client interface information, and generating a third character string based on the client interface information; performing a risk assessment on the processing request sent by the client and generating a risk value for the processing request sent by the client; based on the risk value of the processing request sent by the client, encrypting and concatenating the first character string, the second character string, and the third character string to generate a first target token; and sending the processing response and the first target token to the client for replay attack defense.

[0006] According to an embodiment of the present disclosure, a risk assessment is performed on the processing request sent by the client to generate a risk value for the processing request sent by the client, including: obtaining the IP address of the processing request sent by the client, and detecting whether the IP address is normal; if the IP address is normal, obtaining the access frequency of the IP address; obtaining the account login time and account login frequency of the processing request sent by the client; and generating the risk value of the processing request sent by the client based on the access frequency of the IP address, the account login time and account login frequency of the processing request sent by the client.

[0007] According to an embodiment of the present disclosure, based on the access frequency of the IP address, the account login time and the account login frequency of the processing request sent by the client, the risk value of the processing request sent by the client is calculated, including: presetting a standard access frequency, calculating the deviation value between the access frequency of the IP address and the standard access frequency, and generating a first deviation value; presetting a standard account login time, calculating the deviation value between the account login time of the processing request sent by the client and the standard account login time, and generating a second deviation value; presetting a standard account login frequency, calculating the deviation value between the account login frequency of the processing request sent by the client and the standard account login frequency, and generating a third deviation value; and performing weighted calculation on the first deviation value, the second deviation value and the third deviation value to generate the risk value of the processing request sent by the client.

[0008] According to an embodiment of the present disclosure, based on the risk value of the processing request sent by the client, the first character string, the second character string, and the third character string are encrypted and concatenated to generate a first target token, including: obtaining the risk value of the processing request sent by the client; if the risk value is less than a preset first risk threshold, concatenating the first character string, the second character string, and the third character string to generate a fourth character string; and hashing the fourth character string to generate the first target token.

[0009] According to an embodiment of the present disclosure, based on the risk value of the processing request sent by the client, the first character string, the second character string, and the third character string are encrypted and concatenated to generate a first target token, including: obtaining the risk value of the processing request sent by the client; if the risk value is greater than or equal to a preset first risk threshold and less than or equal to a preset second risk threshold, concatenating the first character string, the second character string, and the third character string to generate a fifth character string; and asymmetrically encrypting the fifth character string to generate the first target token.

[0010] According to an embodiment of the present disclosure, based on the risk value of the processing request sent by the client, the first character string, the second character string, and the third character string are encrypted and concatenated to generate a first target token, including: obtaining the risk value of the processing request sent by the client; if the risk value is greater than a preset second risk threshold, concatenating the first character string, the second character string, and the third character string to generate a sixth character string; and digitally signing the sixth character string to generate the first target token.

[0011] According to an embodiment of the present disclosure, a processing request sent by a client is obtained and a processing response is generated, including: responding to a second target token sent by the client, verifying the second target token, deleting the second target token if the verification is successful, and obtaining the processing request sent by the client, and generating a processing response.

[0012] According to the second aspect of the present disclosure, a replay attack defense device is provided, which includes: a first acquisition module, used to obtain a processing request sent by a client and generate a processing response, wherein the processing response includes: a first character string generated by the server for the processing response; a second acquisition module, used to obtain a second character string generated by the server gateway when detecting the processing response; a first generation module, used to obtain client interface information, and generate a third character string based on the client interface information; a second generation module, used to perform a risk assessment on the processing request sent by the client, and generate a risk value of the processing request sent by the client; a third generation module, used to encrypt and concatenate the first character string, the second character string and the third character string based on the risk value of the processing request sent by the client, and generate a first target token; and a sending module, used to send the processing response and the first target token to the client for replay attack defense.

[0013] According to an embodiment of the present disclosure, the second generation module includes: a third acquisition module, used to obtain the IP address of the processing request sent by the client, and detect whether the IP address is normal; a fourth acquisition module, used to obtain the access frequency of the IP address if the IP address is normal; a fifth acquisition module, used to obtain the account login time and account login frequency of the processing request sent by the client; and a fourth generation module, used to generate a risk value of the processing request sent by the client based on the access frequency of the IP address, the account login time and account login frequency of the processing request sent by the client.

[0014] According to an embodiment of the present disclosure, the fourth generation module includes: a fifth generation module, which is used to preset a standard access frequency, calculate the deviation value between the access frequency of the IP address and the standard access frequency, and generate a first deviation value; a sixth generation module, which is used to preset a standard account login time, calculate the deviation value between the account login time of the processing request sent by the client and the standard account login time, and generate a second deviation value; a seventh generation module, which is used to preset a standard account login frequency, calculate the deviation value between the account login frequency of the processing request sent by the client and the standard account login frequency, and generate a third deviation value; and an eighth generation module, which is used to perform weighted calculation on the first deviation value, the second deviation value and the third deviation value to generate a risk value for the processing request sent by the client.

[0015] According to an embodiment of the present disclosure, the third generation module includes: a sixth acquisition module, used to obtain a risk value of the processing request sent by the client; a ninth generation module, used to concatenate the first character string, the second character string, and the third character string to generate a fourth character string if the risk value is less than a preset first risk threshold; and a tenth generation module, used to hash and encrypt the fourth character string to generate a first target token.

[0016] According to an embodiment of the present disclosure, the third generation module further includes: a seventh acquisition module, used to obtain a risk value of the processing request sent by the client; an eleventh generation module, used to concatenate the first character string, the second character string, and the third character string to generate a fifth character string if the risk value is greater than or equal to a preset first risk threshold and less than or equal to a preset second risk threshold; and a twelfth generation module, used to asymmetrically encrypt the fifth character string to generate a first target token.

[0017] According to an embodiment of the present disclosure, the third generation module further includes: an eighth acquisition module, configured to acquire a risk value of the processing request sent by the client; a thirteenth generation module, configured to concatenate the first character string, the second character string, and the third character string to generate a sixth character string if the risk value is greater than a preset second risk threshold; and a fourteenth generation module, configured to digitally sign the sixth character string to generate a first target token.

[0018] According to a third aspect of the present disclosure, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned replay attack defense method.

[0019] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, on which executable instructions or computer programs are stored. When the instructions or computer programs are executed by a processor, the processor executes the above-mentioned replay attack defense method.

[0020] According to a fifth aspect of the present disclosure, a computer program product is also provided, including a computer program, which implements the above-mentioned replay attack defense method when executed by a processor.

[0021] The present invention ensures the uniqueness of the token by splicing three random strings at the server, gateway and client, so that an attacker cannot carry out a secondary attack by replaying the token after intercepting the token. In addition, the encryption strength can be adaptively enhanced through risk assessment, and the security protection level can be dynamically adjusted. The first target token is sent to the client, which can respond to the recipient's identity authentication, prevent data tampering, and realize the visual strength transmission of the risk level. The token is generated and updated in real time according to the generation of the processing request, which effectively prevents replay attacks. Even if the attacker intercepts the token, it cannot be used to perform malicious operations, and the overall technical effect of improving the security and reliability of data transmission is achieved. In addition, the dynamic adjustment of the security protection level can also achieve the technical effect of lightweight data transmission defense, save computing resources, and improve the efficiency of data defense. It can solve the technical problem in the prior art that once the token is intercepted, the timestamp may be affected by clock synchronization problems and is easily tampered with, and the attacker can easily carry out a replay attack. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0023] Figure 1 The following schematically illustrates an application scenario of the replay attack defense method and apparatus according to an embodiment of the present disclosure;

[0024] Figure 2 The following schematically shows a flow chart of a replay attack defense method according to an embodiment of the present disclosure;

[0025] Figure 3 Schematically illustrates a flow chart for generating a risk value for a processing request sent by a client in a replay attack defense method according to an embodiment of the present disclosure;

[0026] Figure 4 The flowchart of calculating the risk value of a processing request sent by a client in the replay attack defense method according to an embodiment of the present disclosure is schematically shown;

[0027] Figure 5 Schematically shows a flow chart of generating a first target token by hash encryption in a replay attack defense method according to an embodiment of the present disclosure;

[0028] Figure 6 Schematically shows a flow chart of generating a first target token by asymmetric encryption in a replay attack defense method according to an embodiment of the present disclosure;

[0029] Figure 7 Schematically shows a flow chart of generating a first target token by digital signature in a replay attack defense method according to an embodiment of the present disclosure;

[0030] Figure 8 Schematically shows a structural block diagram of a replay attack defense device according to an embodiment of the present disclosure; and

[0031] Figure 9 A block diagram of an electronic device suitable for implementing a replay attack defense method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0032] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0033] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0034] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0035] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0036] The accompanying drawings illustrate some block diagrams and / or flow charts. It should be understood that some blocks in the block diagrams and / or flow charts, or combinations thereof, may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable control device, so that when executed by the processor, these instructions may create a device for implementing the functions / operations described in the block diagrams and / or flow charts.

[0037] First, let’s explain the technical terms that appear in this article as follows:

[0038] IP address (Internet Protocol Address): The Internet Protocol address is a core component of the Internet Protocol. It is used to uniquely identify and locate devices on the network, ensuring that data can be accurately transmitted to the target device.

[0039] Replay Attack: A network attack in which the attacker intercepts and replays previously legitimate communication data in an attempt to perform the same operation again.

[0040] Token: In security protocols, a string of characters used to verify identity or authorization.

[0041] Gateway: A device in a network used to connect different networks or perform data processing.

[0042] Dynamic Generation: refers to the process of generating information based on real-time data at runtime.

[0043] Multi-Level Token System: A collection of tokens with multiple levels and uses.

[0044] Behavior Analysis: Analyze user behavior patterns to identify normal behavior and potential attack behaviors.

[0045] Dynamic Token Generator: Responsible for calling the multi-level token generator to generate and update tokens in real time in response to network requests.

[0046] Multi-level token generator: manage different levels of tokens, ensuring each token has a specific purpose and validity period.

[0047] Behavioral Analysis Engine: Analyzes client behavior patterns to identify potential replay attacks.

[0048] An embodiment of the present disclosure provides a method for defending against replay attacks, the method comprising: obtaining a processing request sent by a client, generating a processing response, wherein the processing response comprises: a first character string generated by a server for the processing response. Obtaining a second character string generated by a server gateway detecting the processing response. Obtaining client interface information, and generating a third character string based on the client interface information. Performing a risk assessment on the processing request sent by the client, and generating a risk value for the processing request sent by the client. Based on the risk value of the processing request sent by the client, encrypting and concatenating the first character string, the second character string, and the third character string to generate a first target token. And sending the processing response and the first target token to the client to perform replay attack defense.

[0049] According to the embodiment of the present disclosure, the uniqueness of the token is ensured by splicing three random strings at the server, gateway and client, so that an attacker cannot carry out a secondary attack by replaying the token after intercepting the token. In addition, the encryption strength can be adaptively enhanced through risk assessment, and the security protection level can be dynamically adjusted. The first target token is sent to the client, which can respond to the recipient's identity authentication, prevent data tampering, and realize the visual strength transmission of the risk level. The token is generated and updated in real time according to the generation of the processing request, which effectively prevents replay attacks. Even if the attacker intercepts the token, it cannot be used to perform malicious operations, and the overall technical effect of improving the security and reliability of data transmission is achieved. In addition, the dynamic adjustment of the security protection level can also achieve the technical effect of lightweight data transmission defense, save computing resources, and improve the efficiency of data defense. It can solve the technical problem in the prior art that once the token is intercepted, the timestamp may be affected by clock synchronization problems and is easily tampered with, and the attacker can easily carry out a replay attack.

[0050] Figure 1 The following schematically illustrates an application scenario of the replay attack defense method and apparatus according to an embodiment of the present disclosure. Figure 1 The examples shown are merely examples of scenarios in which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but do not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.

[0051] like Figure 1 As shown, the application scenario 100 according to this embodiment may include an application scenario for replay attack defense. A network 104 is used as a medium for providing a communication link between a first terminal device 101, a second terminal device 102, a third terminal device 103, and a server 105. The network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0052] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0053] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0054] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.

[0055] It should be noted that the replay attack defense method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the replay attack defense apparatus provided in the embodiment of the present disclosure can generally be set in the server 105. The replay attack defense method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the replay attack defense apparatus provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.

[0056] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0057] The following will be based on Figure 1 The scene described by Figures 2 to 7 The replay attack defense method of the disclosed embodiment is described in detail. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.

[0058] Figure 2 The flowchart of the replay attack defense method according to the embodiment of the present disclosure is schematically shown.

[0059] like Figure 2 As shown, the method 200 includes steps S201 to S206.

[0060] Step S201: Obtain a processing request sent by a client, and generate a processing response, wherein the processing response includes: a first character string generated by the server for the processing response.

[0061] For example, the server processes the request and returns a response including a first string randomly generated by the server. After obtaining the processing request sent by the client and generating the processing response, the server may also: respond to a second target token sent by the client, verify the second target token, delete the second target token if the verification is successful, obtain the processing request sent by the client, and generate the processing response.

[0062] By using the technical means of deleting the token immediately after verification, the technical effect of eliminating the possibility of replay attacks is achieved, further improving the security of data transmission.

[0063] Step S202: Acquire a second character string generated by the server gateway detecting the processing response.

[0064] For example, the gateway layer may intercept the response sent by the server for detection and randomly generate a second string.

[0065] Step S203: Acquire client interface information, and generate a third character string based on the client interface information.

[0066] For example, the client interface may be called to randomly generate a third character string.

[0067] Step S204: perform risk assessment on the processing request sent by the client to generate a risk value of the processing request sent by the client.

[0068] Figure 3 The flowchart of generating a risk value of a processing request sent by a client in a replay attack defense method according to an embodiment of the present disclosure is schematically shown.

[0069] like Figure 3 As shown, the method 300 includes steps S301 to S304.

[0070] Step S301: Obtain the IP address of the processing request sent by the client, and check whether the IP address is normal.

[0071] For example, the IP reputation database can be analyzed to perform the following operations: Verify whether the source IP address of the request is on a blacklist of known attacker IP addresses. Check whether the IP address has a history of bad behavior, such as a history of significant suspicious activity or association with fraud. If the IP address is not on the blacklist and has no history of bad behavior, the IP address is considered normal. If the IP address is on the blacklist or has a history of bad behavior, the IP address is considered abnormal.

[0072] Step S302: If the IP address is normal, obtain the access frequency of the IP address.

[0073] For example, if the IP address is normal, the number of requests from the same IP address within a specific time window can be counted. This specific time window can be set to 1 minute or another duration. If the IP address is abnormal, the client's processing request is directly determined to be high-risk data.

[0074] Step S303: Acquire the account login time and account login frequency of the processing request sent by the client.

[0075] For example, in addition to obtaining the user's login time and frequency, it is also possible to obtain the user's transaction pattern, such as the range of transfer amounts and the transfer target account, or the user's login location and device identification.

[0076] Step S304: generating a risk value of the processing request sent by the client based on the access frequency of the IP address, the account login time and the account login frequency of the processing request sent by the client.

[0077] Figure 4 The flowchart of calculating the risk value of a processing request sent by a client in the replay attack defense method according to an embodiment of the present disclosure is schematically shown.

[0078] like Figure 4 As shown, the method 400 includes steps S401 to S404.

[0079] Step S401: preset a standard access frequency, calculate a deviation between the access frequency of the IP address and the standard access frequency, and generate a first deviation value.

[0080] For example, if the access frequency of the IP address is less than or equal to a preset threshold, the first deviation value is 0. If the access frequency of the IP address is greater than the preset threshold, the difference between the access frequency of the IP address and the standard access frequency can be calculated, and the difference between the access frequency of the IP address and the standard access frequency can be divided by the standard access frequency to generate the first deviation value.

[0081] Step S402: preset a standard account login time, calculate a deviation value between the account login time of the processing request sent by the client and the standard account login time, and generate a second deviation value.

[0082] For example, if the account login time of the processing request sent by the client is within the preset time threshold, the second deviation value is 0. If the account login time of the processing request sent by the client is not within the preset time threshold, the absolute value of the difference between the account login time of the processing request sent by the client and the standard account login time can be calculated, and the absolute value of the difference between the account login time of the processing request sent by the client and the standard account login time can be divided by the standard account login time to generate the second deviation value.

[0083] Step S403: preset a standard account login frequency, calculate a deviation value between the account login frequency of the processing request sent by the client and the standard account login frequency, and generate a third deviation value.

[0084] For example, if the account login frequency of the processing request sent by the client is less than or equal to a preset threshold, the third deviation value is 0. If the account login frequency of the processing request sent by the client is greater than the preset threshold, the difference between the account login frequency of the processing request sent by the client and the standard account login frequency can be calculated, and the difference between the account login frequency of the processing request sent by the client and the standard account login frequency can be divided by the standard account login frequency to generate the third deviation value.

[0085] Step S404: Perform weighted calculation on the first deviation value, the second deviation value, and the third deviation value to generate a risk value of the processing request sent by the client.

[0086] For example, according to business needs, the first deviation value weight, the second deviation value weight and the third deviation value weight are preset, the product of the first deviation value and the first deviation value weight is calculated to generate the first association value, the product of the second deviation value and the second deviation value weight is calculated to generate the second association value, the product of the third deviation value and the third deviation value weight is calculated to generate the third association value, the sum of the first association value, the second association value and the third association value is calculated to generate the risk value of the processing request sent by the client.

[0087] The multi-dimensional deviation weighting mechanism allows for dynamic risk assessment in combination with application scenarios, further improving the accuracy of risk values. By calculating the risk value of client-sent processing requests through IP address detection, IP address access frequency, account login time, and account login frequency, the accuracy and reliability of risk values are improved.

[0088] Return to reference Figure 2 In step S205, based on the risk value of the processing request sent by the client, the first character string, the second character string and the third character string are encrypted and concatenated to generate a first target token.

[0089] For example, the risk level corresponding to the risk value can be preset, and the corresponding risk level can be determined based on the risk value of the processing request sent by the client. The corresponding risk strategy is adopted to encrypt and splice the first character string, the second character string and the third character string to generate a first target token.

[0090] When the risk value is less than the preset first risk threshold, a simpler hash function is generally used for encryption to generate a low-risk standard operational-level token, which is generally used for daily, low-risk operations, and a longer first validity period is set.

[0091] Figure 5 The flowchart of generating a first target token by hash encryption in the replay attack defense method according to an embodiment of the present disclosure is schematically shown.

[0092] like Figure 5 As shown, the method 500 includes steps S501 to S503.

[0093] Step S501: Obtain the risk value of the processing request sent by the client.

[0094] Step S502: If the risk value is less than a preset first risk threshold, concatenate the first character string, the second character string, and the third character string to generate a fourth character string.

[0095] For example, the first character string, the second character string, and the third character string may be concatenated to generate a fourth character string.

[0096] Step S503: Perform hash encryption on the fourth character string to generate a first target token.

[0097] Through risk stratification processing, lightweight hash encryption is enabled only for low-risk requests, avoiding resource waste, improving computing efficiency, and ensuring the security of data transmission.

[0098] When the risk value is greater than or equal to the preset first risk threshold and less than or equal to the preset second risk threshold, a more complex asymmetric encryption function is generally used to encrypt the token, generating a medium-risk transaction-level token that may require additional user verification. This is generally used for operations involving sensitive data or high-value operations, and is set with a second validity period that is shorter than the first validity period.

[0099] Figure 6 The flowchart of generating a first target token by asymmetric encryption in the replay attack defense method according to an embodiment of the present disclosure is schematically shown.

[0100] like Figure 6 As shown, the method 600 includes steps S601 to S603.

[0101] Step S601: Obtain the risk value of the processing request sent by the client.

[0102] Step S602: If the risk value is greater than or equal to a preset first risk threshold and less than or equal to a preset second risk threshold, concatenate the first character string, the second character string, and the third character string to generate a fifth character string.

[0103] Step S603: Asymmetrically encrypt the fifth character string to generate a first target token.

[0104] By accurately matching asymmetric encryption algorithms with risk intervals, an optimal balance between security strength and performance loss is achieved, resolving the contradiction between insufficient hash encryption strength and waste of asymmetric encryption algorithm resources in risk scenarios.

[0105] When the risk value exceeds a preset second risk threshold, a high-risk security token is generated, typically using a more complex digital signature for encryption or a cryptographic envelope mechanism combining an encryption algorithm with a digital signature. This can trigger additional security measures, such as secondary verification or complete request blocking. This is typically used for critical operations requiring the highest level of security, and is typically set with a third validity period that is shorter than the second validity period.

[0106] Figure 7 The flowchart of generating a first target token by digital signature in the replay attack defense method according to an embodiment of the present disclosure is schematically shown.

[0107] like Figure 7 As shown, the method 700 includes steps S701 to S703.

[0108] Step S701: Obtain the risk value of the processing request sent by the client.

[0109] Step S702: If the risk value is greater than a preset second risk threshold, concatenate the first character string, the second character string, and the third character string to generate a sixth character string.

[0110] Step S703: Digitally sign the sixth character string to generate a first target token.

[0111] Through the technical means of risk triggering and digital signatures, digital signatures are applied to high-risk data transmission, achieving the technical effect of improving the utilization of computing resources.

[0112] pass Figure 5 、 Figure 6 and Figure 7 It can be seen that different encryption methods with stepped levels formed according to risk values and risk thresholds facilitate dynamic adjustment of resource allocation and achieve the technical effect of improving computing efficiency.

[0113] In addition, when generating the first target token as mentioned above, token parameters can also be added. The token parameters generally include: user information including user ID, account status, etc.; request information including request type, target URL, request timestamp, etc.; environmental information including client IP address, user agent, device fingerprint, etc.; and dynamic information including current timestamp, random number generator output, etc.

[0114] Return to reference Figure 2In step S206, the processing response and the first target token are sent to the client for replay attack defense.

[0115] In one disclosed embodiment, the following process steps are disclosed: client → gateway layer → server: In response to a user action, the client sends an HTTP / HTTPS request containing a randomly generated string 1. The gateway layer intercepts the client request, generates string 2, and calls a server API to obtain string 3 from the server. The behavior analysis engine evaluates the request frequency and pattern. The dynamic token generator calls a multi-level token generator based on the request content and behavioral analysis results to generate a level in the multi-level token. Specifically, the concatenation of strings 1, 2, and 3 (for example) is encrypted according to the level to generate token A. The gateway layer injects token A into the request and forwards the request to the server. After receiving the request, the server verifies the validity of token A. If valid, it cancels token A; if invalid, it discards the request. The client is the source of the network request. The gateway layer intercepts the request and interacts with the dynamic token generator and behavior analysis engine. The server receives the request with the token and performs verification.

[0116] In one disclosed embodiment, the process steps from server to gateway layer to client are disclosed: the server processes the request and returns a response, which includes string 4 randomly generated by the server. The gateway layer intercepts the response sent by the server, generates string 5, and calls the client API to obtain string 6. The dynamic token generator calls the multi-level token generator to encrypt the concatenation of strings 4, 5, and 6 (for example) according to the level determined in the request step, generating token B. The gateway layer injects token B into the response and forwards it to the client. The client receives the response with token B, parses it, and verifies its validity. If valid, it continues interacting with the user; if not, it abandons the process. Within the same session, after processing the response, the client sends a request with token B based on user input. The gateway layer verifies token B and, if valid, approves it. The server verifies token B and, if valid and within the same session, includes it in the response. If the gateway layer finds a problem with token B, it either discards it or sends a request back to the server with a warning message, at the server's discretion. If Token B is retained within a session, you can continue to add strings or increase the number of times to prevent Token B from always existing. For example, if the number of times reaches a threshold or the behavioral analysis risk level increases, it can be deregistered and regenerated. Regardless of whether it is within the same session, the client verifies that Token B is valid and deregisters it. The above request steps are repeated based on the user's operation.

[0117] In one disclosed embodiment, a dynamic token generator generates a token based on behavioral analysis results. Specifically, the steps include: a user logs in through the user interface of a bank's online banking system by entering their username and password. After successfully logging in, the user selects the transfer function and enters the necessary transfer information, such as the payee and the transfer amount. The client application encapsulates the transfer information entered by the user into an HTTP request and prepares to send it. The client sends the HTTP request, which is transmitted over the user's network to the bank's gateway layer. As the first line of defense, the gateway layer intercepts all incoming HTTP requests and checks whether they comply with the bank's communication protocols and security standards. A behavioral analysis engine is activated and begins collecting data related to the client request. This includes the client's IP address, the HTTP request method and path, and the request timestamp. The behavioral analysis engine connects to an IP reputation database and performs the following operations: verifying whether the source IP address of the request is on a blacklist of known attacker IP addresses; checking whether the IP address has a history of negative activity, such as a high level of suspicious activity or association with fraud; and evaluating request frequency, counting the number of requests from the same IP address within a specific time window (e.g., one minute). Compare requests with a baseline of normal user requests to identify any abnormal behavior. For each user account, the behavioral analysis engine establishes and maintains a behavioral baseline, including: the user's login time and frequency; the user's transaction patterns, such as the range of transfer amounts and the destination account; and the user's login location and device. The behavioral analysis engine uses machine learning algorithms, such as anomaly detection models, to identify behavior that significantly deviates from the user's baseline. If the detected request frequency significantly exceeds normal levels, the system may flag it as a potential automated attack attempt. The behavioral analysis engine is also responsible for real-time blacklist updates, including: updating the IP address blacklist based on recent security events and intelligence; and adding newly identified malicious IP addresses or behavior patterns to the blacklist. For each request, the behavioral analysis engine calculates a risk score, taking into account factors such as the IP address's reputation; the deviation of the request frequency from the normal baseline; and its consistency with the user's baseline behavior. Based on the risk score, the behavioral analysis engine provides the following decision support: If the risk score is below the set threshold, the request is allowed to proceed normally. If the risk score is above the threshold, the request is marked as suspicious and may trigger additional security measures, such as secondary verification or manual review. When suspicious behavior is detected, the behavior analysis engine sends the behavior analysis results to the dynamic token generator, and the dynamic token generator can generate a token based on the behavior analysis results.

[0118] Through the disclosed embodiments, the method effectively prevents replay attacks by generating and updating tokens in real time. Even if an attacker intercepts the token, he cannot use it to perform malicious operations. In addition, the multi-level token system provides layered security protection for transactions at different levels, ensuring high security for critical transactions, while providing moderate security verification for routine operations, thereby balancing security and convenience. The introduction of the behavioral analysis engine further enhances the adaptability of the system. It can dynamically adjust security policies based on real-time network behavior and historical data, and effectively respond to evolving network threats. Overall, the technical solution of the present invention provides a more secure and reliable execution environment for online transactions through its innovative dynamic and multi-level security measures, enhances user trust, and meets industry compliance requirements, bringing operational efficiency improvements and cost savings to financial institutions.

[0119] Figure 8 The structure block diagram of the replay attack defense device according to an embodiment of the present disclosure is schematically shown.

[0120] like Figure 8 As shown, the apparatus 800 includes: a first acquisition module 801 , a second acquisition module 802 , a first generation module 803 , a second generation module 804 , a third generation module 805 and a sending module 806 .

[0121] The first acquisition module 801 is used to acquire the processing request sent by the client and generate a processing response, wherein the processing response includes: a first string generated by the server for the processing response. In one embodiment, the first acquisition module 801 can be used to execute step S201 described above, which will not be repeated here.

[0122] The second acquisition module 802 is configured to acquire a second character string generated by the server gateway detecting the processing response. In one embodiment, the second acquisition module 802 may be configured to execute the aforementioned step S202, which will not be described in detail herein.

[0123] The first generating module 803 is configured to obtain client interface information and generate a third character string based on the client interface information. In one embodiment, the first generating module 803 may be configured to execute step S203 described above, which will not be described in detail herein.

[0124] The second generating module 804 is configured to perform a risk assessment on the processing request sent by the client and generate a risk value for the processing request sent by the client. In one embodiment, the second generating module 804 may be configured to execute step S204 described above.

[0125] The second generating module 804 includes: a third acquiring module, a fourth acquiring module, a fifth acquiring module and a fourth generating module.

[0126] The third acquisition module is used to obtain the IP address of the processing request sent by the client and detect whether the IP address is normal. In one embodiment, the third acquisition module can be used to execute step S301 described above, which will not be repeated here.

[0127] The fourth acquisition module is configured to acquire the access frequency of the IP address if the IP address is normal. In one embodiment, the fourth acquisition module may be configured to execute step S302 described above, which will not be described in detail herein.

[0128] The fifth acquisition module is used to acquire the account login time and account login frequency of the processing request sent by the client. In one embodiment, the fifth acquisition module can be used to execute step S303 described above, which will not be repeated here.

[0129] The fourth generating module is configured to generate a risk value for the processing request sent by the client based on the access frequency of the IP address, the account login time and the account login frequency of the processing request sent by the client. In one embodiment, the fourth generating module can be configured to execute step S304 described above.

[0130] The fourth generation module includes: a fifth generation module, a sixth generation module, a seventh generation module and an eighth generation module.

[0131] The fifth generating module is configured to preset a standard access frequency, calculate a deviation between the access frequency of the IP address and the standard access frequency, and generate a first deviation value. In one embodiment, the fifth generating module may be configured to execute step S401 described above, which will not be described in detail herein.

[0132] The sixth generation module is configured to preset a standard account login time, calculate a deviation between the account login time of the processing request sent by the client and the standard account login time, and generate a second deviation value. In one embodiment, the sixth generation module can be configured to execute step S402 described above and will not be further described here.

[0133] The seventh generation module is configured to preset a standard account login frequency, calculate a deviation between the account login frequency of the processing request sent by the client and the standard account login frequency, and generate a third deviation value. In one embodiment, the seventh generation module can be configured to execute step S403 described above and will not be further described herein.

[0134] The eighth generating module is configured to perform weighted calculation on the first deviation value, the second deviation value, and the third deviation value to generate a risk value for the processing request sent by the client. In one embodiment, the eighth generating module may be configured to execute step S404 described above, which will not be described in detail here.

[0135] The third generation module 805 is configured to encrypt and concatenate the first string, the second string, and the third string based on the risk value of the processing request sent by the client to generate a first target token. In one embodiment, the third generation module 805 can be configured to execute step S205 described above.

[0136] The third generating module 805 includes: a sixth acquiring module, a ninth generating module and a tenth generating module.

[0137] The sixth acquisition module is configured to acquire the risk value of the processing request sent by the client. In one embodiment, the sixth acquisition module may be configured to execute step S501 described above, which will not be described in detail here.

[0138] The ninth generating module is configured to concatenate the first character string, the second character string, and the third character string to generate a fourth character string if the risk value is less than a preset first risk threshold. In one embodiment, the ninth generating module may be configured to execute step S502 described above and will not be further described herein.

[0139] The tenth generating module is configured to perform hash encryption on the fourth character string to generate a first target token. In one embodiment, the tenth generating module may be configured to execute step S503 described above, which will not be described in detail herein.

[0140] The third generating module 805 further includes: a seventh acquiring module, an eleventh generating module and a twelfth generating module.

[0141] The seventh acquisition module is configured to acquire the risk value of the processing request sent by the client. In one embodiment, the seventh acquisition module may be configured to execute step S601 described above, which will not be described in detail here.

[0142] The eleventh generation module is configured to concatenate the first character string, the second character string, and the third character string to generate a fifth character string if the risk value is greater than or equal to a preset first risk threshold and less than or equal to a preset second risk threshold. In one embodiment, the eleventh generation module may be configured to execute step S602 described above and will not be further described here.

[0143] The twelfth generating module is configured to perform asymmetrical encryption on the fifth character string to generate a first target token. In one embodiment, the twelfth generating module may be configured to execute step S603 described above, which will not be described in detail herein.

[0144] The third generating module 805 further includes: an eighth acquiring module, a thirteenth generating module and a fourteenth generating module.

[0145] The eighth acquisition module is configured to acquire the risk value of the processing request sent by the client. In one embodiment, the eighth acquisition module may be configured to execute step S701 described above, which will not be described in detail here.

[0146] The thirteenth generating module is configured to concatenate the first character string, the second character string, and the third character string to generate a sixth character string if the risk value is greater than a preset second risk threshold. In one embodiment, the thirteenth generating module may be configured to execute step S702 described above and will not be further described herein.

[0147] The fourteenth generating module is configured to digitally sign the sixth character string to generate a first target token. In one embodiment, the fourteenth generating module may be configured to execute step S703 described above, which will not be described in detail herein.

[0148] The sending module 806 is configured to send the processing response and the first target token to the client for replay attack defense. In one embodiment, the sending module 806 can be configured to execute step S206 described above, which will not be described in detail here.

[0149] According to embodiments of the present disclosure, any multiple modules among the first acquisition module 801, the second acquisition module 802, the first generation module 803, the second generation module 804, the third generation module 805, and the sending module 806 can be combined into a single module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present disclosure, at least one of the first acquisition module 801, the second acquisition module 802, the first generation module 803, the second generation module 804, the third generation module 805, and the sending module 806 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or can be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or can be implemented in any one of the three implementation methods of software, hardware, and firmware, or any appropriate combination of any of these. Alternatively, at least one of the first acquisition module 801, the second acquisition module 802, the first generation module 803, the second generation module 804, the third generation module 805 and the sending module 806 can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding function can be performed.

[0150] Figure 9A block diagram of an electronic device suitable for implementing a replay attack defense method according to an embodiment of the present disclosure is schematically shown.

[0151] like Figure 9 As shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage unit 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present disclosure.

[0152] Various programs and data required for the operation of the electronic device 900 are stored in the RAM 903. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in the one or more memories.

[0153] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input section 906 including a keyboard, a mouse, etc.; an output section 907 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and speakers; a storage section 908 including a hard disk; and a communication section 909 including a network interface card such as a LAN card or a modem. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. Removable media 911, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 910 as needed, so that computer programs read from the removable media can be installed in the storage section 908 as needed.

[0154] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.

[0155] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above, and / or one or more memories other than ROM 902 and RAM 903.

[0156] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to enable the computer system to implement the replay attack defense method provided by the embodiments of the present disclosure.

[0157] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the processor 901 executes the computer program. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0158] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 909, and / or installed from a removable medium 911. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0159] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from a removable medium 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0160] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0161] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0162] Those skilled in the art will appreciate that the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways, even if such combinations and / or couplings are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or couplings are intended to fall within the scope of this disclosure.

[0163] The embodiments of the present disclosure are described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be used in combination to advantage. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A replay attack defense method, characterized in that: The method includes: Obtaining a processing request sent by a client, and generating a processing response, wherein the processing response includes: a first character string generated by the server for the processing response; Obtaining a second character string generated by the server gateway detecting the processing response; Acquire client interface information, and generate a third character string based on the client interface information; Performing a risk assessment on the processing request sent by the client to generate a risk value for the processing request sent by the client; Based on the risk value of the processing request sent by the client, encrypt and concatenate the first character string, the second character string, and the third character string to generate a first target token; and The processing response and the first target token are sent to the client for replay attack defense.

2. The method according to claim 1, characterized in that Performing a risk assessment on the processing request sent by the client to generate a risk value for the processing request sent by the client includes: Obtain the IP address of the processing request sent by the client, and check whether the IP address is normal; If the IP address is normal, obtaining the access frequency of the IP address; Obtaining the account login time and account login frequency of the processing request sent by the client; and A risk value of the processing request sent by the client is generated based on the access frequency of the IP address, the account login time and the account login frequency of the processing request sent by the client.

3. The method according to claim 2, characterized in that Calculating a risk value of the processing request sent by the client based on the access frequency of the IP address, the account login time and the account login frequency of the processing request sent by the client, including: Preset a standard access frequency, calculate the deviation between the access frequency of the IP address and the standard access frequency, and generate a first deviation value; Preset a standard account login time, calculate the deviation between the account login time of the processing request sent by the client and the standard account login time, and generate a second deviation value; Preset a standard account login frequency, calculate a deviation between the account login frequency of the processing request sent by the client and the standard account login frequency, and generate a third deviation value; and A weighted calculation is performed on the first deviation value, the second deviation value, and the third deviation value to generate a risk value of the processing request sent by the client.

4. The method according to any one of claims 1 to 3, characterized in that Based on the risk value of the processing request sent by the client, encrypting and concatenating the first character string, the second character string, and the third character string to generate a first target token, including: Obtaining a risk value of the processing request sent by the client; If the risk value is less than a preset first risk threshold, concatenating the first character string, the second character string, and the third character string to generate a fourth character string; and The fourth character string is hashed and encrypted to generate a first target token.

5. The method according to any one of claims 1 to 3, characterized in that Based on the risk value of the processing request sent by the client, encrypting and concatenating the first character string, the second character string, and the third character string to generate a first target token, including: Obtaining a risk value of the processing request sent by the client; If the risk value is greater than or equal to a preset first risk threshold and less than or equal to a preset second risk threshold, concatenating the first character string, the second character string, and the third character string to generate a fifth character string; and Asymmetrically encrypt the fifth character string to generate a first target token.

6. The method according to any one of claims 1 to 3, characterized in that Based on the risk value of the processing request sent by the client, encrypting and concatenating the first character string, the second character string, and the third character string to generate a first target token, including: Obtaining a risk value of the processing request sent by the client; If the risk value is greater than a preset second risk threshold, concatenating the first character string, the second character string, and the third character string to generate a sixth character string; and The sixth character string is digitally signed to generate a first target token.

7. The method according to any one of claims 1 to 3, characterized in that Get the processing request sent by the client and generate a processing response, including: In response to the second target token sent by the client, the second target token is verified. If the verification is successful, the second target token is deleted and the processing request sent by the client is obtained, and a processing response is generated.

8. A replay attack defense device, characterized in that: The device includes: A first acquisition module is configured to acquire a processing request sent by a client and generate a processing response, wherein the processing response includes: a first character string generated by the server for the processing response; A second acquisition module is used to acquire a second character string generated by the server gateway detecting the processing response; A first generating module is configured to obtain client interface information and generate a third character string based on the client interface information; A second generating module is configured to perform a risk assessment on the processing request sent by the client and generate a risk value for the processing request sent by the client; a third generating module, configured to encrypt and concatenate the first character string, the second character string, and the third character string based on the risk value of the processing request sent by the client to generate a first target token; and The sending module is used to send the processing response and the first target token to the client to perform replay attack defense.

9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, The method further comprises the step of executing the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.