Anti-leapfrogging processing method and system based on step state marking and sequence verification
By generating step tokens on the server side and establishing status tags in distributed storage, combined with a token decryption and verification mechanism, it solves the front-end dependency risks and status management vulnerabilities in multi-step operations, achieves strict step sequence control and real-time protection, and is suitable for highly sensitive scenarios such as financial transactions.
Patent Information
- Application Number
- CN202510672204.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-09-09
AI Technical Summary
Existing technologies have front-end dependency risks, state management vulnerabilities, lack of real-time verification and potential timing attacks in multi-step operation scenarios, which lead to illegal bypassing of business processes and inconsistent intermediate states, causing serious consequences especially in highly sensitive scenarios such as financial transactions.
By dynamically generating the initial step token on the server side and establishing the step status mark in the distributed storage, combined with the token decryption and verification mechanism, the strict execution of the step sequence and the traceability of the status are ensured, illegal step skipping behavior is blocked, and anti-step skipping logs are recorded to achieve real-time protection and compliance auditing.
It effectively prevents front-end tampering or bypassing of step sequence, ensures a strict progressive relationship of operations, and achieves real-time protection and compliance auditing. It is suitable for highly sensitive scenarios with strict requirements on the operation sequence.
Smart Images

Figure CN120614152A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer software security, and in particular to a method and system for preventing step skipping based on step status marking and sequence verification. Background Art
[0002] Multi-step operation scenarios are common in current Internet applications, such as user registration, order payment, form submission and other key business processes. Existing technical solutions have significant security flaws in step sequence control: First, traditional solutions rely too much on the front-end to control page jump logic. Attackers can modify front-end parameters through developer tools or directly construct API requests to bypass step restrictions, which poses a serious risk of front-end dependence. Secondly, the system lacks a secure step status management mechanism and does not use encrypted storage and two-way verification technology, which makes it possible for malicious users to tamper with the step completion mark, resulting in illegal bypassing of business processes.
[0003] A deeper problem lies in the lack of a server-side atomicity verification mechanism in existing solutions. This can lead to inconsistent intermediate states when users perform concurrent operations, making it impossible to guarantee the strict sequential execution of steps. Furthermore, systems generally neglect monitoring the timing of operations and lack effective time window control measures. This allows attackers to disrupt normal business processes through carefully crafted concurrent requests, creating the risk of timing attacks. These security vulnerabilities can have serious consequences in highly sensitive business scenarios such as financial transactions and identity authentication. Summary of the Invention
[0004] The present application provides an anti-skipping processing method and system based on step status marking and sequence verification, which can solve the technical problems of front-end dependence risks, state management vulnerabilities, lack of real-time verification and hidden dangers of timing attacks in step sequence control in the prior art.
[0005] In a first aspect, the present application provides an anti-step skipping processing method based on step status marking and sequence verification, comprising the following steps: When the user's initial step request is obtained, the server dynamically generates an initial step token and creates a step status mark in the distributed storage; When a subsequent step request is received, sequential verification is performed by decrypting the initial step token; For subsequent step requests that pass sequential verification, the server generates a subsequent step token and updates its status flag; Block the current operation of subsequent step requests that fail sequence verification, record the anti-step skipping log, and perform anti-step skipping operations.
[0006] Furthermore, when the user's initial step request is obtained, the server dynamically generates an initial step token and establishes a step status mark in the distributed storage, specifically including the following steps: When the user's initial step request is obtained, the server extracts the device fingerprint and business serial number data in the current initial step request session, concatenates the timestamp, device fingerprint and business serial number into a new string according to the preset format, and uses the new string and the corresponding step status mark as parameters to generate an initial step token with an anti-tamper mark; Mark the current step status in the distributed storage.
[0007] Furthermore, when a subsequent step request is obtained, sequential verification is performed by decrypting the initial step token, specifically including the following steps: When a subsequent step request is obtained, the initial step token corresponding to the user's initial step request is decrypted and the decrypted initial step token is obtained; Verify the validity of the decrypted initial step token; Perform step continuity verification on the initial step token where the token is valid; Perform timestamp verification on subsequent step requests after the step continuity verification passes.
[0008] Furthermore, for the subsequent step request that passes the sequential verification, generating a subsequent step token on the server side and updating its status mark specifically includes the following steps: For subsequent step requests that pass sequential verification, extract key information from the initial step token, including step identifier, timestamp, and device feature data; Based on the key information, the current step identifier, the latest timestamp, and the user session information are embedded, a subsequent step token is generated on the server side, and the step status mark is updated in the distributed storage.
[0009] Furthermore, the current operation of the subsequent step request that fails the sequence verification is blocked, its anti-skipping log is recorded, and an anti-skipping operation is performed, specifically including the following steps: When an abnormal step sequence is detected, key information including operation time, step jump path, and failure reason is extracted based on the business serial number of the current subsequent step request, user session information, and verification results of the subsequent step token; Match key information with preset log templates to generate structured anti-skip logs, including exception type, risk level, trigger conditions, and context data. The anti-skip logs are persistently stored in the anti-skip database and marked as high-risk operation events. According to the exception type and risk level in the anti-skip step log, the corresponding processing strategy is called to perform anti-skip step processing.
[0010] Furthermore, the criteria for determining a high-risk request in the risk level include at least one of the following: Subsequent steps: Token decryption fails or signature verification fails; The time interval between two consecutive subsequent step requests is less than the minimum safety threshold preset by the system; The device fingerprint requested in the current subsequent step does not match the historically bound device; The frequency of abnormal step skipping within the sliding time window exceeds the warning value.
[0011] Furthermore, the method of calling a corresponding processing strategy and executing anti-skipping processing according to the exception type and risk level in the anti-skipping log specifically includes the following steps: For subsequent step requests that illegally skip steps, we first determine whether it is an intentional bypass based on the user's historical behavior model and current session status. If so, we terminate the current operation process and reset the user session. For high-risk requests, the current session is terminated immediately and the anti-jump process is triggered; For medium-risk requests, implement enhanced verification mechanisms and record operation behavior logs; For low-risk requests, only basic token verification is performed and the process is allowed to continue.
[0012] Furthermore, the basic token verification includes three levels of verification: Performs primary validation to check token format validity and expiration time; Perform intermediate verification of the correlation between the token digital signature and the business serial number; Perform advanced verification to simultaneously verify the geographic location trustworthiness of IP addresses while ensuring the atomicity of state updates through distributed locks.
[0013] In a second aspect, the present application provides an anti-step skipping processing system based on step status marking and sequence verification, comprising: The initial token generation and status marking module is used to dynamically generate the initial step token on the server side and establish the step status mark in the distributed storage when obtaining the user's initial step request; A sequence verification module, in communication with the initial step token generation and step status marking module, for performing sequence verification by decrypting the initial step token when a subsequent step request is obtained; A new token generation and status mark update module, in communication with the sequence verification module, for requesting subsequent steps that have passed sequence verification, generating a subsequent step token on the server side and updating its status mark; The anti-step skipping processing module is in communication with the new token generation and status mark updating module, and is used to block the current operation of the subsequent step request that fails the sequence verification, record its anti-step skipping log and perform the anti-step skipping operation.
[0014] Furthermore, the initial token generation and status marking module includes: An initial step token generation unit is configured to, upon receiving an initial step request from a user, extract the device fingerprint and service serial number data from the current initial step request session through the server, concatenate the timestamp, device fingerprint, and service serial number into a new string according to a preset format, and use the new string and the corresponding step status flag as parameters to generate an initial step token carrying a tamper-proof flag; Mark the current step status in the distributed storage.
[0015] The beneficial effects of the technical solutions provided in the embodiments of the present application include at least: The server dynamically generates initial step tokens and establishes status markers in distributed storage to ensure the reliability and traceability of the process's starting state. By using a token decryption verification mechanism for subsequent step requests, illegal step skipping behaviors can be effectively identified to prevent front-end tampering or bypassing of step sequences. After verification, a new token is generated and the status mark is updated, forming a closed-loop control chain to ensure a strict progressive relationship between the status of each step; Block and log requests that fail verification, achieving real-time protection while meeting compliance audit requirements. This application effectively solves the problems of traditional front-end control being easily bypassed and state management being unsafe, and is particularly suitable for highly sensitive scenarios such as financial transactions that have strict requirements on the order of operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 A flowchart of an anti-step skipping processing method based on step status marking and sequence verification provided in an embodiment of the present application; Figure 2 This is a functional module block diagram of the anti-step skipping processing system based on step status marking and sequence verification provided in an embodiment of the present application. DETAILED DESCRIPTION
[0017] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0018] The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. The terms "first", "second" and "third" are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit the "first", "second" and "third" to different types.
[0019] In the description of the embodiments of this application, the words "exemplary," "for example," or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary," "for example," or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary," "for example," or "for example" is intended to present the relevant concepts in a concrete manner.
[0020] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, “multiple” refers to two or more than two.
[0021] In some processes described in the embodiments of the present application, multiple operations or steps are included that appear in a specific order. However, it should be understood that these operations or steps may not be performed in the order in which they appear in the embodiments of the present application or may be performed in parallel. The sequence numbers of the operations are only used to distinguish between different operations, and the sequence numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations or steps may be performed in sequence or in parallel, and these operations or steps may be combined.
[0022] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0023] First, as Figure 1 As shown, the present application provides an anti-step skipping processing method based on step status marking and sequence verification, comprising the following steps: Step S1: When the user's initial step request is obtained, the server dynamically generates an initial step token and establishes a step status mark in the distributed storage. By dynamically generating the initial step token on the server and establishing the status mark in the distributed storage, the reliability and traceability of the process starting state are ensured. Step S2: When a subsequent step request is obtained, the initial step token is decrypted to perform sequence verification. By using the token decryption verification mechanism for subsequent step requests, illegal step skipping behavior is effectively identified to prevent front-end tampering or bypassing of the step sequence. Step S3: For subsequent step requests that have passed the sequential verification, a subsequent step token is generated on the server side and its status mark is updated; for subsequent step requests that have passed the verification, a new token is generated and the status mark is updated, forming a closed-loop control chain to ensure a strict progressive relationship between the status of each step Step S4: Block the current operation of subsequent step requests that fail sequence verification, record their anti-skip logs, and perform anti-skip operations. For requests that fail verification, block operations and record logs, achieving both real-time protection and meeting compliance audit requirements. This application effectively solves the problems of traditional front-end control being easily bypassed and state management being unsafe, and is particularly suitable for highly sensitive scenarios such as financial transactions that have strict requirements on the order of operations.
[0024] In this application, in a financial transaction scenario, the initial step request is the first step operation request initiated by the user in a multi-step business process, specifically entering the transfer amount, recipient information, etc.
[0025] In this application, in a financial transaction scenario, subsequent step requests are usually key operations involving funds, identity or contracts, such as payment, verification, signing, etc.
[0026] In this application, step status marking refers to a technical means of digitally identifying and tracking the completion status and sequence relationship of each step in a multi-step business process through an encrypted token mechanism.
[0027] In one embodiment, step S1: when the user's initial step request is obtained, the server dynamically generates an initial step token and establishes a step status mark in the distributed storage, specifically including the following steps: Step S11: When the user's initial step request is obtained, the server extracts the device fingerprint and business serial number data in the current initial step request session, concatenates the timestamp, device fingerprint, and business serial number into a new string payload using String.injoin(), String.join(), or a custom method according to the preset format. The new string and the corresponding step status mark are used as parameters to generate an initial step token with an anti-tamper mark, marked as steptoken1; Step S12: Mark the step status of the current step in the distributed storage.
[0028] In one embodiment, step S2: when a subsequent step request is obtained, sequential verification is performed by decrypting the initial step token, specifically including the following steps: Step S21: When a subsequent step request is received, the initial step token corresponding to the user's initial step request is decrypted and the decrypted initial step token is obtained. Multi-dimensional security verification is achieved by decrypting the initial step token, effectively ensuring the strict sequential execution of the business process; Step S22: Verify the validity of the decrypted initial step token to identify forged or expired illegal tokens and block unauthorized access; Step S23: Verify the continuity of the initial step token for which the token is valid, and ensure that the user must follow the preset process step by step to prevent key steps from being skipped; Step S24: Perform timestamp verification on subsequent step requests after the step continuity verification is passed to detect and prevent replay attacks and ensure that each step request is completed within the valid time window. If it exceeds 120S, the error "Operation step has timed out" will continue to be reported.
[0029] In one embodiment, step S3: for subsequent step requests that pass sequential verification, generating a subsequent step token on the server side, marked as steptoken2, and updating its status flag, specifically includes the following steps: Step S31: For subsequent step requests that have passed sequential verification, extract key information from the initial step token, including step identifier, timestamp, and device feature data; Step S32: Based on the key information, embed the current step identifier, the latest timestamp and the user session information, generate a subsequent step token on the server side, and update the step status mark in the distributed storage.
[0030] Based on step S31-step S32, subsequent tokens are generated by extracting key information from the initial step token and embedding the current step feature data to ensure compliance with the strict progressive relationship of step continuity verification; the server updates the status mark in the distributed storage in real time, which not only prevents token forgery but also ensures state consistency. At the same time, through dynamic binding of session features, a strong association between the operator identity and the steps is achieved, effectively blocking man-in-the-middle attacks and concurrent timing tampering.
[0031] In one embodiment, step S4: blocking the current operation requested by the subsequent step that fails the sequence verification, recording the anti-step skipping log, and performing the anti-step skipping operation, specifically includes the following steps: Step S41: When a step sequence anomaly is detected, key information including operation time, step jump path, and failure reason is extracted based on the business serial number of the current subsequent step request, user session information, and verification result of the subsequent step token; Step S42: Match key information with a preset log template to generate a structured anti-skip log containing the exception type, risk level, trigger condition, and context data. The anti-skip log is persistently stored in the anti-skip database and marked as a high-risk operation event. Step S43: According to the exception type and risk level in the anti-step skipping log, the corresponding processing strategy is called to perform anti-step skipping processing.
[0032] Based on steps S41 to S43, accurate identification and interception of illegal step-jumping behaviors are achieved by detecting abnormalities in the step sequence in real time and extracting key information. The system automatically generates a structured log to record the complete context of the abnormal operation, including the specific jump path and the reason for failure, providing a traceable basis for preventing step-jumping. By associating the log with the risk level and triggering the corresponding processing strategy, a closed-loop protection mechanism from abnormality detection to automatic disposal is formed. This design not only effectively blocks the current illegal operations, but also supports post-analysis and policy optimization through persistently stored log data, while meeting the regulatory provisions on leaving traces of high-risk operations in compliance requirements. The deep integration of exception handling and logging enhances the system's proactive defense capabilities and ensures the integrity and security of business processes.
[0033] In one embodiment, in step S42, the criteria for determining a high-risk request in the risk level include at least one of the following: A: The token decryption fails or the signature verification fails in the subsequent steps; B: The time interval between two consecutive subsequent step requests is less than the system preset minimum safety threshold; C: The device fingerprint requested in the current subsequent step does not match the historically bound device; D: The abnormal skipping frequency within the sliding time window exceeds the warning value.
[0034] In one embodiment, step S43: invoking a corresponding processing strategy and executing anti-step skipping processing based on the exception type and risk level in the anti-step skipping log specifically includes the following steps: For subsequent step requests that illegally skip steps, we first determine whether it is an intentional bypass based on the user's historical behavior model and current session status. If so, we terminate the current operation process and reset the user session. For high-risk requests, the current session is terminated immediately and the anti-jump process is triggered; For medium-risk requests, implement enhanced verification mechanisms and record operation behavior logs; For low-risk requests, only basic token verification is performed and the process is allowed to continue; the basic token verification includes three levels of verification: primary verification to check the validity of the token format and expiration time; intermediate verification of the association between the token digital signature and the business serial number; and advanced verification to synchronously verify the geographic location credibility of the IP address while ensuring the atomicity of state updates through distributed locks.
[0035] This application implements security enhancements for multi-step requests through dynamic token binding. Specifically, it uses a three-tuple binding mechanism of device fingerprint, IP address, and timestamp. When a user initiates a step request, the system extracts the current device's unique fingerprint identifier (such as device ID or browser features), the real-time network IP address, and a timestamp accurate to milliseconds. These elements are encrypted and combined with the business serial number before being embedded into the step token. Each time the token is verified, the server decrypts and verifies the consistency of these three elements. If a device replacement, IP mutation, or timestamp anomaly (such as time reversal) is detected, the process is immediately terminated and a security alert is triggered. This application implements a distributed lock mechanism through Redis's SETNX (Set if Not Exists) command combined with an expiration time. The specific implementation process is as follows: When a user initiates a step update request, the system uses the business serial number as the key and attempts to obtain a distributed lock through the SETNX command. If the return is successful, the lock expiration time is set (such as 30 seconds) to ensure that only the current request can modify the step status mark in Redis during the lock holding period; the lock is released immediately after the status update is completed. If an exception occurs, the atomicity of the lock release is guaranteed by a Lua script. At the same time, the Redlock algorithm is used to enhance the reliability of locks in cross-node scenarios to prevent lock failures caused by Redis master-slave switching, thereby strictly ensuring the atomicity and consistency of step status updates; This application implements abnormal behavior monitoring through a sliding time window algorithm. Specifically, the system maintains a time-ordered operation queue for each user session in the Redis cache. When a continuous step jump request is detected, the frequency of the jump operation within a unit time window (e.g., 30 seconds) is calculated in real time. If the frequency exceeds a preset threshold (e.g., 5 times / window), the risk control rules are triggered, automatically freezing the current session and generating a security alert. This mechanism uses a funnel algorithm for traffic shaping and a LRU strategy to automatically clear expired records. This ensures real-time blocking of high-frequency abnormal requests while avoiding the risk of memory overflow.
[0036] Second, as Figure 2As shown, the present application provides an anti-skipping processing system based on step status marking and sequential verification, including an initial token generation and status marking module 100, a sequential verification module 200, a new token generation and status marking update module 300 and an anti-skipping processing module 400; the initial token generation and status marking module 100 is used to dynamically generate an initial step token on the server side when obtaining the user's initial step request, and establish a step status mark in the distributed storage; the sequential verification module 200 is communicated with the initial step token generation and step status marking module 100, and is used to perform sequential verification by decrypting the initial step token when obtaining a subsequent step request; the new token generation and status marking update module 300 is communicated with the sequential verification module 200, and is used to generate a subsequent step token on the server side and update its status mark for the subsequent step request that passes the sequential verification; the anti-skipping processing module 400 is communicated with the new token generation and status marking update module 300, and is used to block the current operation of the subsequent step request that fails the sequential verification, record its anti-skipping log and perform anti-skipping operation.
[0037] In one embodiment, the initial token generation and status marking module includes: An initial step token generation unit is configured to, upon receiving an initial step request from a user, extract the device fingerprint and service serial number data from the current initial step request session through the server, concatenate the timestamp, device fingerprint, and service serial number into a new string according to a preset format, and use the new string and the corresponding step status flag as parameters to generate an initial step token carrying a tamper-proof flag; Mark the current step status in the distributed storage.
[0038] Among them, the functional implementation of each module in the above-mentioned anti-skipping processing system based on step status marking and sequence verification corresponds to the steps in the above-mentioned anti-skipping processing method embodiment based on step status marking and sequence verification, and their functions and implementation processes will not be repeated here one by one.
[0039] On the third aspect, an embodiment of the present application provides an anti-skipping processing device based on step status marking and sequence verification. The anti-skipping processing device based on step status marking and sequence verification can be a personal computer (PC), a laptop computer, a server, or other device with data processing capabilities.
[0040] Communication interfaces include input / output (I / O) interfaces, physical interfaces, and logical interfaces. These interfaces interconnect components within the anti-skipping processing device based on step status marking and sequence verification, as well as interfaces that interconnect the anti-skipping processing device based on step status marking and sequence verification with other devices (such as other computing devices or user devices). Physical interfaces can be Ethernet, fiber, or ATM interfaces; user devices can be displays or keyboards.
[0041] The memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.
[0042] The processor may be a general-purpose processor that can call a step-skipping prevention processing program based on step status marking and sequence verification stored in a memory and execute the step-skipping prevention processing method based on step status marking and sequence verification provided in the embodiments of the present application. For example, the general-purpose processor may be a central processing unit (CPU). The method executed when the step-skipping prevention processing program based on step status marking and sequence verification is called can be referred to in the various embodiments of the step-skipping prevention processing method based on step status marking and sequence verification of the present application, and will not be further described here.
[0043] In a fourth aspect, an embodiment of the present application also provides a readable storage medium.
[0044] The readable storage medium of the present application stores an anti-skipping processing program based on step status marking and sequence verification, wherein when the anti-skipping processing program based on step status marking and sequence verification is executed by the processor, the steps of the anti-skipping processing method based on step status marking and sequence verification as described above are implemented.
[0045] Among them, the method implemented when the anti-skipping processing program based on step status marking and sequence verification is executed can refer to the various embodiments of the anti-skipping processing method based on step status marking and sequence verification in this application, and will not be repeated here.
[0046] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0047] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, or the part that contributes to the existing technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above and includes a number of instructions for enabling a terminal device to execute the methods described in each embodiment of this application.
[0048] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A method for preventing step skipping based on step status marking and sequence verification, characterized in that: The following steps are involved: When the user's initial step request is obtained, the server dynamically generates an initial step token and creates a step status mark in the distributed storage; When a subsequent step request is received, sequential verification is performed by decrypting the initial step token; For subsequent step requests that pass sequential verification, the server generates a subsequent step token and updates its status flag; Block the current operation of subsequent step requests that fail sequence verification, record the anti-step skipping log, and perform anti-step skipping operations.
2. The anti-step skipping processing method based on step status marking and sequence verification according to claim 1, characterized in that: When the user's initial step request is obtained, the server dynamically generates an initial step token and establishes a step status mark in the distributed storage, specifically including the following steps: When the user's initial step request is obtained, the server extracts the device fingerprint and business serial number data in the current initial step request session, concatenates the timestamp, device fingerprint and business serial number into a new string according to the preset format, and uses the new string and the corresponding step status mark as parameters to generate an initial step token with an anti-tamper mark; Mark the current step status in the distributed storage.
3. The anti-step skipping processing method based on step status marking and sequence verification according to claim 1, characterized in that: When a subsequent step request is obtained, sequential verification is performed by decrypting the initial step token, specifically including the following steps: When a subsequent step request is obtained, the initial step token corresponding to the user's initial step request is decrypted and the decrypted initial step token is obtained; Verify the validity of the decrypted initial step token; Perform step continuity verification on the initial step token where the token is valid; Perform timestamp verification on subsequent step requests after the step continuity verification passes.
4. The anti-step skipping processing method based on step status marking and sequence verification according to claim 1, characterized in that: For subsequent step requests that pass the sequential verification, the server generates a subsequent step token and updates its status mark, specifically including the following steps: For subsequent step requests that pass sequential verification, extract key information from the initial step token, including step identifier, timestamp, and device feature data; Based on the key information, the current step identifier, the latest timestamp, and the user session information are embedded, a subsequent step token is generated on the server side, and the step status mark is updated in the distributed storage.
5. The anti-step skipping processing method based on step status marking and sequence verification according to claim 1, characterized in that: The blocking sequence fails to verify the current operation of the subsequent step request, records the anti-skipping log and performs the anti-skipping operation, specifically including the following steps: When an abnormal step sequence is detected, key information including operation time, step jump path, and failure reason is extracted based on the business serial number of the current subsequent step request, user session information, and verification results of the subsequent step token; Match key information with preset log templates to generate structured anti-skip logs, including exception type, risk level, trigger conditions, and context data. The anti-skip logs are persistently stored in the anti-skip database and marked as high-risk operation events. According to the exception type and risk level in the anti-skip step log, the corresponding processing strategy is called to perform anti-skip step processing.
6. The anti-step skipping processing method based on step status marking and sequence verification according to claim 5, characterized in that: The criteria for determining a high-risk request in the risk level include at least one of the following: Subsequent steps: Token decryption fails or signature verification fails; The time interval between two consecutive subsequent step requests is less than the minimum safety threshold preset by the system; The device fingerprint requested in the current subsequent step does not match the historically bound device; The frequency of abnormal step skipping within the sliding time window exceeds the warning value.
7. The anti-step skipping processing method based on step status marking and sequence verification according to claim 5, characterized in that: According to the exception type and risk level in the anti-skip step log, the corresponding processing strategy is called to perform anti-skip step processing, which specifically includes the following steps: For subsequent step requests that illegally skip steps, we first determine whether it is an intentional bypass based on the user's historical behavior model and current session status. If so, we terminate the current operation process and reset the user session. For high-risk requests, the current session is terminated immediately and the anti-jump process is triggered; For medium-risk requests, implement enhanced verification mechanisms and record operation behavior logs; For low-risk requests, only basic token verification is performed and the process is allowed to continue.
8. The anti-step skipping processing method according to claim 7, characterized in that: The basic token verification includes three levels of verification: Performs primary validation to check token format validity and expiration time; Perform intermediate verification of the correlation between the token digital signature and the business serial number; Perform advanced verification to simultaneously verify the geographic location trustworthiness of IP addresses while ensuring the atomicity of state updates through distributed locks.
9. An anti-step skipping processing system based on step status marking and sequence verification, characterized in that: include: The initial token generation and status marking module is used to dynamically generate the initial step token on the server side and establish the step status mark in the distributed storage when obtaining the user's initial step request; A sequence verification module, in communication with the initial step token generation and step status marking module, for performing sequence verification by decrypting the initial step token when a subsequent step request is obtained; A new token generation and status mark update module, in communication with the sequence verification module, for requesting subsequent steps that have passed sequence verification, generating a subsequent step token on the server side and updating its status mark; The anti-step skipping processing module is in communication with the new token generation and status mark updating module, and is used to block the current operation of the subsequent step request that fails the sequence verification, record its anti-step skipping log and perform the anti-step skipping operation.
10. The anti-step skipping processing system based on step status marking and sequence verification according to claim 9, characterized in that: The initial token generation and status marking module includes: An initial step token generation unit is configured to, upon receiving an initial step request from a user, extract the device fingerprint and service serial number data from the current initial step request session through the server, concatenate the timestamp, device fingerprint, and service serial number into a new string according to a preset format, and use the new string and the corresponding step status flag as parameters to generate an initial step token carrying a tamper-proof flag; The new string and the corresponding business serial number are generated, and the step status of the current step is marked in the distributed storage.