Security enhancement method, device and equipment for browser certificate verification and storage medium

By introducing a mechanism for repeatedly executing delay parameters and current loop parameters during the browser certificate verification process, the security risks of certificate chain verification in existing technologies are resolved, the accuracy and reliability of verification are improved, and the probability of false positives is reduced.

CN120710808BActive Publication Date: 2025-11-18PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511219616.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-11-18
Estimated Expiration
2045-08-28

AI Technical Summary

Technical Problem

The existing browser certificate verification process has security risks, especially during the HTTPS handshake. Attackers may bypass security checks by manipulating the verification time or forging a single verification result, resulting in a high probability of false positives and failing to effectively ensure the security of the certificate chain.

Method used

By obtaining the initial certificate chain and performing multi-step verification, the verification steps are repeatedly executed using delay parameters and current loop parameters to ensure the consistency of the results of each verification step. This includes obtaining the browser's delay parameters and current loop parameters, and dynamically adjusting the verification process to resist potential timing attacks and random errors.

Benefits of technology

It effectively reduces the probability of false positives, improves the accuracy and security of certificate chain verification, ensures the reliability of browser certificate chain verification, and enhances the ability to resist potential attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120710808B_ABST
    Figure CN120710808B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a security enhancement method, device and storage medium for browser certificate verification, and relate to the technical field of certificate verification. In the certificate verification process of an initial certificate chain, a first verification step, a second verification step, a third verification step and a fourth verification step are performed, and corresponding verification results are obtained. In the case that a security enhancement state is true, a delay parameter and a current cycle parameter of the browser for each verification step are obtained. In the certificate verification process, the corresponding verification step is repeatedly performed based on the delay parameter and the current cycle parameter, and the corresponding verification result is obtained. If all verification results indicate that the verification is passed, an initial security conclusion indicating that the certificate chain is safe is obtained. In the security enhancement state, each verification step is repeatedly performed through the delay parameter and the current cycle parameter, potential timing attacks or accidental errors that may exist in a single verification are effectively resisted, and the accuracy of the certificate chain security verification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of certificate verification technology, and in particular to security enhancement methods, apparatus, devices, and storage media for browser certificate verification. Background Technology

[0002] A CA certificate is a digital certificate issued by a recognized Certificate Authority. During HTTPS communication between a browser and a web server, in the SSL / TLS handshake process, when the web server sends a Certificate message, it sends a CA certificate chain to the browser client for identity verification. This secure verification of the certificate chain during the browser connection process is crucial for a secure connection.

[0003] In related technologies, the CA (Certificate Authority) system constructs a trust chain through root certificates, intermediate certificates, and server certificates. The root CA issues a self-signed root certificate and pre-installs it on the browser client. Intermediate CAs are authorized by the root CA to issue server certificates. After a website applies for a certificate and deploys it to the server, the certificate chain is sent during the HTTPS handshake. The browser uses the pre-installed root certificate to verify the legitimacy of the intermediate and server certificates step by step, and verifies the signature and negotiates the session key using the RSA public key in the server certificate, ultimately establishing an encrypted channel to achieve secure data transmission. However, this verification process still has security risks. Summary of the Invention

[0004] The main objective of this application is to propose a security enhancement method, apparatus, device, and storage medium for browser certificate verification, thereby enhancing the security of browser certificate chain verification.

[0005] To achieve the above objectives, a first aspect of this application proposes a security enhancement method for browser certificate verification, comprising:

[0006] Obtain an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and the server certificate of the target website;

[0007] The certificate verification process begins. In the first verification step, the server certificate undergoes basic verification to obtain a first verification result. In the second verification step, the server certificate is signed and verified using the public key of the intermediate certificate to obtain a second verification result. In the third verification step, the intermediate certificate undergoes basic verification and is signed and verified using the public key of the root certificate to obtain a third verification result. In the fourth verification step, the root certificate is signed and verified to obtain a fourth verification result.

[0008] When the security enhancement state is true, the delay parameters and current loop parameters of the browser for each verification step are obtained. During the certificate verification process, the corresponding verification steps are repeatedly executed based on the delay parameters and the current loop parameters to obtain the corresponding verification results.

[0009] If all the verification results indicate that the verification is successful, an initial security conclusion indicating that the certificate chain is secure is obtained.

[0010] In some embodiments, obtaining the browser's delay parameters for each verification step includes:

[0011] Obtain the browser's verification startup time, hash the verification startup time, truncate the encrypted result into bytes, convert the truncated bytes into an integer, and obtain a startup random number.

[0012] Obtain the execution time of the first execution of each verification step, and generate a random execution number based on the execution time and execution order;

[0013] The delay parameter is obtained based on the start random number and the execution random number.

[0014] In some embodiments, obtaining the delay parameter based on the start random number and the execution random number includes:

[0015] Calculate the XOR result of the start random number and the execution random number to obtain the delayed random number;

[0016] The delay parameter is obtained by performing a modulo operation on the delay random number according to a preset value.

[0017] In some embodiments, the browser's current loop parameters for each verification step are obtained, including:

[0018] Obtain the historical evaluation parameters and historical loop parameters of the verification step;

[0019] If the historical evaluation parameter is greater than or equal to the preset evaluation value, the historical loop parameter is reduced to obtain the current loop parameter; otherwise, within the limit of the maximum loop parameter, the historical loop parameter is increased to obtain the current loop parameter.

[0020] In some embodiments, obtaining the historical evaluation parameters based on historical execution time includes the following steps:

[0021] For each verification step, obtain all execution times of the verification steps in the previous certificate verification, and obtain the corresponding historical execution time based on the corresponding delay parameter and the execution time;

[0022] The total execution time is obtained by summing up all the historical execution times, and the delay impact parameters are determined based on the time interval in which the total execution time falls.

[0023] Based on the ratio of each historical execution time to the total execution time, the proportion of each verification step in the delay impact parameter is determined, and the historical evaluation parameter is obtained.

[0024] In some embodiments, the step of repeatedly executing the corresponding verification steps based on the delay parameter and the current loop parameter to obtain the corresponding verification result includes:

[0025] For each of the verification steps, the expected execution time for each repeated execution is determined based on the current loop parameters and the delay parameters;

[0026] All the expected execution times are sorted in chronological order. If at least two of the expected execution times conflict, the corresponding expected execution times are postponed according to the execution order of the verification steps to update the expected execution times. The expected execution times are used to execute the verification step once.

[0027] In some embodiments, after obtaining an initial security conclusion indicating that the certificate chain is secure, if all the verification results indicate that the verification has passed, the method further includes:

[0028] Based on the initial security conclusion, proceed to the critical discrimination step to obtain the redundant variables corresponding to the browser, where the redundant variables are not Boolean.

[0029] If none of the bits in the redundant variables are zero, a fifth verification result indicating that the verification has passed is generated;

[0030] Based on the delay parameters and current loop parameters corresponding to the key discrimination step, the process is repeated to obtain multiple fifth verification results. If each fifth verification result passes, a target security conclusion indicating the security of the certificate chain is generated.

[0031] To achieve the above objectives, a second aspect of this application provides a security enhancement device for browser certificate verification, comprising:

[0032] Certificate chain acquisition module: used to acquire an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and the server certificate of the target website;

[0033] Certificate verification module: Used to enter the certificate verification process. In the first verification step, it performs basic verification on the server certificate to obtain a first verification result. In the second verification step, it uses the public key of the intermediate certificate to perform signature verification on the server certificate to obtain a second verification result. In the third verification step, it performs basic verification on the intermediate certificate and uses the public key of the root certificate to perform signature verification on the intermediate certificate to obtain a third verification result. In the fourth verification step, it performs signature verification on the root certificate to obtain a fourth verification result.

[0034] Security Enhancement Module: When the security enhancement state is true, it obtains the delay parameters and current loop parameters of the browser for each verification step, and repeatedly executes the corresponding verification steps based on the delay parameters and the current loop parameters during the certificate verification process to obtain the corresponding verification result;

[0035] Verification result judgment module: used to obtain an initial security conclusion indicating that the certificate chain is secure if all the verification results indicate that the verification is passed.

[0036] To achieve the above objectives, a third aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described in the first aspect.

[0037] To achieve the above objectives, a fourth aspect of the present application provides a storage medium that stores a computer program, which, when executed by a processor, implements the method described in the first aspect.

[0038] The security enhancement method, apparatus, device, and storage medium for browser certificate verification proposed in this application obtain an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and a server certificate of the target website. The process then proceeds to certificate verification. In the first verification step, basic verification of the server certificate is performed to obtain a first verification result. In the second verification step, the server certificate is signed using the public key of the intermediate certificate to obtain a second verification result. In the third verification step, basic verification of the intermediate certificate is performed, and the intermediate certificate is signed using the public key of the root certificate to obtain a third verification result. In the fourth verification step, the root certificate is signed to obtain a fourth verification result. When the security enhancement state is true, the delay parameters and current loop parameters for each verification step are obtained. During the certificate verification process, the corresponding verification steps are repeatedly executed based on the delay parameters and current loop parameters to obtain corresponding verification results. If all verification results indicate successful verification, an initial security conclusion indicating that the certificate chain is secure is obtained. In the security enhancement state, this application embodiment repeatedly executes each verification step using delay parameters and current loop parameters, thereby effectively resisting potential timing attacks or accidental errors that may exist in a single verification. For example, when attackers attempt to bypass security checks by manipulating verification time or forging single verification results, this repeated verification ensures the reliability of the results through the consistency of multiple verifications, greatly reducing the probability of false positives. Furthermore, only when all verification steps pass can the accuracy of certificate chain security verification be further improved, effectively enhancing the security of browser certificate chain verification. Attached Figure Description

[0039] Figure 1 This is a flowchart of a security enhancement method for browser certificate verification provided in an embodiment of this application.

[0040] Figure 2 This is a flowchart of obtaining the browser's delay parameters for each verification step, provided in an embodiment of this application.

[0041] Figure 3 This is a flowchart provided in an embodiment of the present application for obtaining delay parameters based on starting a random number and executing a random number.

[0042] Figure 4 This is a flowchart of obtaining the current loop parameters of the browser for each verification step, provided in an embodiment of this application.

[0043] Figure 5 This is a flowchart of obtaining historical evaluation parameters based on historical execution time, provided in an embodiment of this application.

[0044] Figure 6This is a flowchart provided in this application embodiment, which repeatedly executes the corresponding verification steps based on the delay parameter and the current loop parameter to obtain the corresponding verification result.

[0045] Figure 7 This is a schematic diagram illustrating the expected execution time provided in the embodiments of this application.

[0046] Figure 8 This is a schematic diagram of the process for obtaining an initial security conclusion indicating that the certificate chain is secure, as provided in an embodiment of this application.

[0047] Figure 9 This is another flowchart of the security enhancement method for browser certificate verification provided in the embodiments of this application.

[0048] Figure 10 This is a structural block diagram of a security enhancement device for browser certificate verification provided in another embodiment of this application.

[0049] Figure 11 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0051] It should be noted that although functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart.

[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0053] A CA certificate is a digital certificate issued by a recognized Certificate Authority. During HTTPS communication between a browser and a web server, in the SSL / TLS handshake process, when the web server sends a Certificate message, it sends a CA certificate chain to the browser client for identity verification. This secure verification of the certificate chain during the browser connection process is crucial for a secure connection.

[0054] In related technologies, the CA (Certificate Authority) system constructs a trust chain through root certificates, intermediate certificates, and server certificates. The root CA issues a self-signed root certificate and pre-installs it on the browser client. Intermediate CAs are authorized by the root CA to issue server certificates. After a website applies for a certificate and deploys it to the server, the certificate chain is sent during the HTTPS handshake. The browser uses the pre-installed root certificate to verify the legitimacy of the intermediate and server certificates step by step, and verifies the signature and negotiates the session key using the RSA public key in the server certificate, ultimately establishing an encrypted channel to achieve secure data transmission. However, this verification process still has security risks.

[0055] Based on this, embodiments of this application provide a security enhancement method, apparatus, device, and storage medium for browser certificate verification. In the enhanced security state, each verification step is repeatedly executed using delay parameters and current loop parameters, effectively resisting potential timing attacks or random errors that may exist in a single verification. For example, if an attacker attempts to bypass security checks by manipulating verification time or forging single verification results, this repeated verification ensures the reliability of the results through the consistency of multiple verifications, greatly reducing the probability of false positives. Furthermore, only when the results of all verification steps are passed can the accuracy of certificate chain security verification be further improved, effectively enhancing the security of browser certificate chain verification.

[0056] This application provides a security enhancement method, apparatus, device, and storage medium for browser certificate verification, which are specifically described through the following embodiments. First, the security enhancement method for browser certificate verification in this application embodiment is described.

[0057] The browser certificate verification security enhancement method provided in this application relates to the field of certificate verification technology. This method can be applied to a terminal, a server, or a computer program running on either the terminal or the server. For example, the computer program can be a native program or software module in an operating system; it can be a native application (APP), i.e., a program that needs to be installed in the operating system to run, such as a client that supports browser certificate verification security enhancement, i.e., a program that only needs to be downloaded to the browser environment to run; or it can be a small program that can be embedded in any APP. In short, the above-mentioned computer program can be any form of application, module, or plugin. The terminal communicates with the server via a network. This browser certificate verification security enhancement method can be executed by the terminal or the server, or by the terminal and the server working together.

[0058] In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, or smartwatch, etc. The server can be a standalone server, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms; it can also be a service node in a blockchain system, where the service nodes form a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). The terminal and server can connect via Bluetooth, Universal Serial Bus (USB), or a network, etc., and this embodiment does not impose any limitations.

[0059] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0060] The following describes a security enhancement method for browser certificate verification in an embodiment of this application.

[0061] Figure 1 This is an optional flowchart of the security enhancement method for browser certificate verification provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps 110 to 140. It is also understood that this embodiment... Figure 1 The order of steps 110 to 140 is not specifically limited. The order of steps can be adjusted or some steps can be reduced or added according to actual needs.

[0062] Step 110: Obtain the initial certificate chain.

[0063] In one embodiment, the initial certificate chain includes at least a root certificate, at least one intermediate certificate, and the target website's server certificate. The root certificate is issued by a root certificate authority (CA). The user's computer system or browser obtains the root certificate from the CA and pre-installs it in the browser's client. Simultaneously, the CA creates one or more intermediate certificates, authorizes the intermediate certificate authority, and issues intermediate certificates. An individual or organization applies for a server certificate from an intermediate certificate authority. After accepting the application, the CA creates a certificate file as the server certificate; for example, using an RSA key, it creates a certificate file containing the RSA public key. In some cases, the intermediate certificate and server certificate are packaged together for download by the individual or organization. After the intermediate certificate authority creates the corresponding server certificate, the individual or organization can download the certificate file from the certificate issuing platform and install it on the server. The server then starts its server-side program and loads the server certificate file and the RSA private key. If the browser client accesses the server-side program via HTTPS, the SSL / TLS handshake begins, and the website's server sends the initial certificate chain to the browser client. If the root certificate or intermediate certificate is missing in the initial certificate chain, the browser client completes the initial certificate chain from the local certificate store.

[0064] In one embodiment, this browser certificate verification security enhancement method is applied to a Chromium-based browser.

[0065] Step 120: Enter the certificate verification process. In the first verification step, perform basic verification on the server certificate to obtain the first verification result. In the second verification step, use the public key of the intermediate certificate to perform signature verification on the server certificate to obtain the second verification result. In the third verification step, perform basic verification on the intermediate certificate and use the public key of the root certificate to perform signature verification on the intermediate certificate to obtain the third verification result. In the fourth verification step, perform signature verification on the root certificate to obtain the fourth verification result.

[0066] In one embodiment, the browser client performs certificate verification on the initial certificate chain. The certificate verification process includes at least a first verification step, a second verification step, a third verification step, and a fourth verification step, and each verification step is followed by a corresponding verification result.

[0067] Specifically, the first verification step performs basic verification of the server certificate, validating its legitimacy by judging its inherent validity through built-in certificate information. This step does not involve signature verification and yields the first verification result. Specifically, the first step checks if the server certificate conforms to the X.509 standard format, verifies the correctness of the ASN.1 encoding syntax, and ensures the certificate has not been tampered with, such as by checking for anomalies in the file header or field lengths. Next, it verifies the validity period by comparing the certificate's effective and expiration dates with the current system time. If the current time is outside the validity period, the certificate is deemed invalid. Additionally, it performs subject information matching, verifying that the domain name / IP address in the "Subject" field of the server certificate matches the currently accessed server address (e.g., if the certificate is bound to "www.example.com," but the actual access is to "example.com," it will not match), preventing domain hijacking attacks. It also verifies the compliance of extended fields, checking key extensions such as whether the key usage includes digital signatures and whether the Extended Key Usage includes server authentication. If all the above verifications pass, the first verification result indicates successful verification.

[0068] The second verification step verifies the server certificate's signature. Since the server certificate is signed by an intermediate Certificate Authority (CA), the second verification step verifies the validity of the server certificate's signature using the intermediate certificate's public key, thus obtaining the second verification result. The specific verification process is as follows: First, the signature information, including the signature algorithm and signature value, is obtained from the server certificate. Next, the public key of the intermediate certificate is extracted from the certificate chain; it is typically stored in the "SubjectPublicKeyInfo" field. The certificate body of the server certificate is hashed according to the signature algorithm, and then the signature value of the server certificate is decrypted using the intermediate certificate's public key, yielding the decrypted hash value. The two hash values ​​are compared; if they match, the signature is valid, and the second verification result indicates successful verification; otherwise, it is determined that the server certificate signature is forged.

[0069] The third verification step performs dual verification on the intermediate certificate. As an intermediate link in the trust chain, the intermediate certificate must pass both basic verification and root certificate signature verification to obtain the third verification result. First, the basic verification of the intermediate certificate repeats the logic of the first verification step, checking the intermediate certificate's validity period, format integrity, extended fields, etc. Next, signature verification based on the root certificate is performed. The signature value and certificate body content of the intermediate certificate are extracted, and the signature validity is verified using the root certificate's public key according to the signature algorithm. If the hash value after decryption of the root certificate's public key matches the hash value of the certificate body content of the intermediate certificate, the intermediate certificate signature is valid. If they do not match, it indicates that the intermediate certificate has been tampered with or forged, and the trust chain is broken. Only after both basic verification and signature verification pass will the third verification structure indicate successful verification.

[0070] Finally, the fourth verification step verifies the root certificate's signature. As the starting point of the trust chain, the root certificate's validity is confirmed through self-signature verification, resulting in the fourth verification result. The self-signature verification logic is as follows: the issuer and subject of the root certificate must be completely identical (i.e., the root certificate issues itself); the signature value and certificate body portion of the root certificate are extracted; the signature is verified using the root certificate's own public key; the hash value of the certificate body portion is calculated according to the signature algorithm; the signature value is decrypted using the root certificate's public key; and the two hash values ​​are compared. If they match, the self-signature is valid. It is also necessary to verify whether the root certificate is in the operating system or browser's "trusted root CA list." After all the above verifications pass, the fourth verification result indicates successful verification.

[0071] Understandably, the above describes the four verification steps in the certificate verification process.

[0072] Step 130: When the security enhancement state is true, obtain the delay parameters and current loop parameters of the browser for each verification step. During the certificate verification process, repeat the corresponding verification steps based on the delay parameters and current loop parameters to obtain the corresponding verification results.

[0073] In one embodiment, to enhance security, a parameter is defined in the browser's entry parameters to indicate the security enhancement status. If this parameter is true, such as the command-line parameter `--security-enhanced=1` or the configuration file parameter `security_enhanced:true`, then security enhancement is considered necessary during certificate verification, requiring further verification. If the parameter is false, such as "0", then no further security enhancement is needed. It is understood that the parameter corresponding to the aforementioned security enhancement status can be added to the browser's entry parameters according to actual needs. The browser can implement "dynamic hierarchical protection" during certificate verification, allowing it to switch security policies without modifying the browser's core code, adapting to different security scenarios, such as ordinary user browsing and financial transaction scenarios.

[0074] In one embodiment, reference is made to Figure 2 , Figure 2 This is a flowchart of obtaining the browser's delay parameters for each verification step, provided in an embodiment of this application. Specifically, it includes the following steps:

[0075] Step 210: Obtain the browser's verification startup time, hash and encrypt the verification startup time, truncate the bytes of the encrypted result, convert the truncated bytes into integers, and obtain the startup random number.

[0076] In one embodiment, when the browser enters the certificate verification process, such as when a user initiates an HTTPS request, it records the timestamp corresponding to the system time in milliseconds. For example, a timestamp of 1620000000123 indicates a time of 1620000000 seconds + 123 milliseconds. Then, a hash transformation is performed on the verification start time to eliminate linear correlation between time values. For example, the SHA-256 algorithm can be used to encrypt the timestamp corresponding to the verification start time, resulting in a hash result: hash(1620000000123) = A3B7C9...D2E1. Finally, a fixed length of bytes, such as 16 bytes, is extracted from the hash result and converted into an integer as the start random number. For example, extracting the first 16 bytes yields 0x7F3A9B...2D, corresponding to the decimal start random number R_start.

[0077] As can be seen, the above logic for generating the startup random number ensures randomness. Even if the startup times of two verifications differ by 1 millisecond, the corresponding hash results will be significantly different, preventing attackers from predicting the startup random number through time patterns.

[0078] Step 220: Obtain the execution time of the first execution of each verification step, and generate a random number based on the execution time and execution order.

[0079] In one embodiment, for each verification step, the execution time of its first execution is obtained. For example, the execution time of the first verification step is 1620000001456, the execution time of the second verification step is 1620000002789, and so on. Then, the execution time and execution order are hashed together using the same hash algorithm as the one used to generate the random number, resulting in a corresponding hash result. For example, for the first verification step, its execution order is 1, so the corresponding hash result could be hash(1+1620000001456). The hash result is then truncated and converted into an integer to obtain the corresponding execution random number.

[0080] It can be seen that adding the execution order to the random number calculation process can prevent attackers from cracking the random number pattern based on the verification order.

[0081] Step 230: Obtain the delay parameters based on the start and execution of random numbers.

[0082] In one embodiment, reference is made to Figure 3 , Figure 3 This is a flowchart provided in an embodiment of the present application for obtaining delay parameters based on starting a random number and executing a random number, specifically including the following steps:

[0083] Step 310: Calculate the XOR result of the start random number and the executed random number to obtain the delayed random number.

[0084] Step 320: Perform a modulo operation on the delayed random number according to the preset value to obtain the delay parameter.

[0085] In one embodiment, for each verification step, an XOR operation is performed between the start random number and the execution random number corresponding to that verification step to obtain a delayed random number. The XOR operation ensures that the delayed random number can simultaneously retain the entropy values ​​of the two random numbers, thereby enhancing randomness. Then, the delayed random number is moduloed by a preset value (e.g., 50) to obtain the corresponding delay parameter.

[0086] As can be seen from the above process, the embodiments of this application determine the random number generation and delay parameter calculation by controlling the startup time and the execution time of the verification steps. The generated delay parameters are difficult to predict externally, preventing attackers from cracking the random number pattern by forging time information. Furthermore, by using delay parameters to mask the actual computation time, attackers can also prevent them from inferring the internal logic of certificate verification, such as the key length for signature verification, by monitoring the execution time of each step. For example, in certificate verification on financial websites, adding a random delay of 50-200 milliseconds as a delay parameter to each verification step causes the actual time of different verification steps to fluctuate irregularly. Even if an attacker intercepts network timing data, they will not be able to extract valid information from it, thus ensuring the confidentiality of the certificate verification process.

[0087] Next, refer to Figure 4 , Figure 4 This is a flowchart of obtaining the browser's current loop parameters for each verification step, provided in an embodiment of this application. Specifically, it includes the following steps:

[0088] Step 410: Obtain the historical evaluation parameters and historical loop parameters of the verification step.

[0089] In one embodiment, the historical evaluation parameters can be default values ​​determined based on actual conditions, or they can be dynamically obtained based on historical execution time. (See reference...) Figure 5 , Figure 5 This is a flowchart of obtaining historical evaluation parameters based on historical execution time, provided in an embodiment of this application, including the following steps:

[0090] Step 510: For each verification step, obtain all execution times of the verification steps in the previous certificate verification, and obtain the corresponding historical execution time based on the corresponding delay parameters and execution times.

[0091] In one embodiment, since the verification step requires at least one loop according to the current loop parameters and delay parameters, each verification step has at least one execution time. Therefore, the execution time of each verification step during the previous browser certificate verification process is obtained, including the execution time of the first execution and the execution time of subsequent possible repetitions. For example, in the previous certificate verification process, the third verification step was executed twice, with the first execution taking 150ms and the repetition taking 140ms. Therefore, the execution time of this verification step includes 150ms and 140ms.

[0092] Since the delay parameter is used to limit the time difference between the next execution and the previous execution, the corresponding historical execution time can be obtained based on the corresponding delay parameter and execution time. Assuming the total delay parameter for the third verification step is 50ms, the historical execution time is 150ms + 50ms + 140ms = 340ms. In this way, the historical execution time of each execution step in the previous certificate verification process can be obtained.

[0093] Step 520: Accumulate all historical execution times to obtain the total execution time, and determine the delay impact parameters based on the time interval in which the total execution time falls.

[0094] In one embodiment, the historical execution times of all verification steps are summarized to obtain the total time spent on verification-related processes in the previous certificate verification. For example, if the historical execution time of the first verification step is 350ms, the historical execution time of the second verification step is 400ms, the historical execution time of the third verification step is 160ms, and the historical execution time of the fourth verification step is 280ms, then the total execution time can be expressed as: tmax = 350 + 400 + 160 + 280 = 1190ms.

[0095] Then, the latency impact parameter is determined based on the time interval within which the total execution time falls. Multiple execution time intervals and their corresponding latency impact parameters are pre-defined, for example: <500ms corresponds to an impact parameter of 40 points, 500ms~1000ms to 60 points, 1000ms~1500ms to 80 points, and >1500ms to 100 points. Assuming the total execution time is 1190ms, falling within the 500ms~1200ms time interval, the corresponding latency impact parameter is 80 points. A higher latency impact parameter indicates a greater impact of the enhanced security verification strategy on browser access latency.

[0096] Step 530: Based on the ratio of each historical execution time to the total execution time, determine the proportion of each verification step in the delay impact parameter, and obtain the historical evaluation parameters.

[0097] In one embodiment, since different verification steps have different historical execution times, it is necessary to evaluate the proportion of each verification step's impact on the latency impact parameter. Based on the proportion of each historical execution time to the total execution time, the proportion of each verification step in the latency impact parameter is determined, resulting in the historical evaluation parameter. For each verification step, the ratio of its cumulative historical execution time to the total execution time is calculated. For example, if the historical execution time of the first verification step is 350ms and the total execution time is 1190ms, then the proportion of historical execution time to total execution time is 350 / 1190. The historical evaluation parameter calculated based on this proportion is: 80*350 / 1190=23.5.

[0098] Following the above process, the historical evaluation parameters corresponding to each execution step are calculated. It is understood that for the first certificate verification process, the historical evaluation parameters can be default values ​​set based on the actual situation.

[0099] Step 420: If the historical evaluation parameter is greater than or equal to the preset evaluation value, decrease the historical loop parameter to obtain the current loop parameter; otherwise, under the limit of the maximum loop parameter, increase the historical loop parameter to obtain the current loop parameter.

[0100] In one embodiment, for each historical evaluation parameter, if it is greater than or equal to a preset evaluation value (e.g., 30 points), it indicates that the verification step has a high time consumption and a significant impact on efficiency. Therefore, the number of loops can be reduced to shorten the corresponding total execution time. For example, if the historical loop parameter in the previous certificate verification process was 3 times, it can be reduced by 1 time, resulting in a current loop parameter of 2 times. Conversely, if the historical evaluation parameter is less than the preset evaluation value, it indicates that the verification step has a low time consumption and a small impact on efficiency. Therefore, the number of loops can be appropriately increased. For example, if the historical loop parameter was 1 time, it can be increased to 2 times within the maximum loop parameter limit (e.g., a maximum of 3 loops), resulting in a current loop parameter of 2 times. Through this dynamic update of give and take, the total execution time can be kept from increasing significantly, or even reduced, thereby maintaining enhanced security reliability.

[0101] It is understandable that the preset evaluation values ​​for different verification steps can be set according to the actual situation, and the preset evaluation values ​​can be the same or different.

[0102] Based on the above steps, the delay parameters and current loop parameters for each verification step are obtained. Next, the security enhancement process is performed. (Refer to...) Figure 6 , Figure 6 This is a flowchart provided in this application embodiment, which describes the process of repeatedly executing corresponding verification steps based on delay parameters and current loop parameters to obtain corresponding verification results. The flowchart specifically includes the following steps:

[0103] Step 610: For each verification step, determine the expected execution time for each repetition based on the current loop parameters and delay parameters.

[0104] In one embodiment, since each verification step has corresponding current loop parameters and delay parameters, the estimated execution time for each repeated execution can be obtained. For example, the current loop parameter for the first verification step is 3 times, the delay parameter is 50ms, the estimated execution time for the first execution is time 1, and the estimated execution time for one execution is 100ms. Therefore, all the corresponding estimated execution times are: time 1, time 1 + 150ms, and time 1 + 300ms. In this way, the estimated execution time for each repeated execution of each verification step is obtained.

[0105] Step 620: Sort all the expected execution times in chronological order. If at least two expected execution times conflict, postpone the corresponding expected execution times according to the execution order of the verification steps to update the expected execution times.

[0106] In one embodiment, theoretically, the corresponding verification step is executed once at each expected execution time. However, to prevent potential time conflicts, all expected execution times are ordered in chronological order. (Refer to...) Figure 7 , Figure 7 This is a schematic diagram illustrating the expected execution time provided in the embodiments of this application. Figure 7 The diagram illustrates multiple estimated execution times for each of the four verification steps. The length of the rectangles indicates the estimated execution time of that verification step, the distance between the rectangles indicates the delay parameter, and the number of rectangles indicates the current loop parameter. Specifically, the first and fourth verification steps have a current loop parameter of 3, the second verification step has a current loop parameter of 4, and the third verification step has a current loop parameter of 2. Next, all estimated execution times are sorted in chronological order, as follows: Figure 5As shown in the sorting results and conflict illustrations, due to the randomness of the delay parameters and the influence of the estimated execution time, different verification steps may experience time conflicts. This means that when the estimated execution time of some verification steps arrives, other verification steps may not have completed. Therefore, considering the execution order of the verification steps, the estimated execution times can be postponed according to the execution order and estimated execution time. This postponement only needs to ensure that the first execution of each step is in sequence. For example, for the third verification step, regardless of whether the first and second verification steps were executed repeatedly, it can only be executed after at least one second verification step has been completed. Therefore, all estimated execution times are updated to obtain conflict-free estimated execution times, and the corresponding verification step is executed once at each estimated execution time.

[0107] Step 140: If all verification results indicate that the verification has passed, an initial security conclusion indicating that the certificate chain is secure is obtained.

[0108] In one embodiment, if all verification results indicate that the verification passed, an initial security conclusion indicating that the certificate chain is secure is obtained. Since there may be multiple verification results for each verification operation, it is very difficult for an attacker to manipulate all verification results simultaneously, which greatly increases the difficulty of the attack.

[0109] In one embodiment, reference is made to Figure 8 , Figure 8 This is a schematic diagram of the process for obtaining an initial security conclusion indicating that the certificate chain is secure, as provided in an embodiment of this application.

[0110] The process checks the security enhancement status. If it's false, the browser's certificate verification process proceeds normally, executing each verification step once. If the security enhancement status is true, the enhanced verification process begins; otherwise, the normal verification process resumes. For each verification step, at least one delay is applied using the delay parameters and the current loop parameters, and the verification result generated each time is saved. After all verification processes are completed, all verification results are compared. If all verification results indicate successful verification, an initial security conclusion indicating a secure certificate chain is reached.

[0111] In one embodiment, after obtaining an initial security conclusion indicating that the certificate chain is secure, further enhancement operations can be performed. (See also...) Figure 9 , Figure 9 This is another flowchart of the security enhancement method for browser certificate verification provided in the embodiments of this application, which further includes the following steps:

[0112] Step 910: Based on the initial security conclusion, proceed to the critical discrimination step and obtain the redundant variables corresponding to the browser.

[0113] In one embodiment, the browser can also perform a centralized processing operation as a key judgment step. This processing, as a final step after the initial certificate verification passes, is located in the HandleVerifyResult() function. This function contains a judgment process similar to ssl_config_.ignore_certificate_errors. Because the judgment implementation is relatively simple, it is easily modified by side-channel attacks, thereby bypassing the browser's verification operation and rendering the security verification operation invalid. This is because ssl_config_.ignore_certificate_errors is only a Boolean variable with a simple value of 0 or 1, used to represent false or true. Therefore, during browser operation, an attacker can modify the running state of the code in memory through electromagnetic or simple voltage attacks, or modify the code state in other malicious ways, or the device running the browser itself is in an environment of interference, easily changing it from 0 to 1, thus changing the state from false to true.

[0114] For example, if a fake website exists, before the browser reaches the check on ssl_config_.ignore_certificate_errors, it can easily detect certificate errors during the various trusted certificate verification operations. The browser needs to inform the user that the current website certificate is invalid. However, when the browser reaches the check on ssl_config_.ignore_certificate_errors, due to a side-channel attack, the value of this check becomes non-zero, i.e., true. At this point, the browser will ignore the various certificate errors detected earlier, causing the user to be unable to detect the fake website.

[0115] The above analysis reveals that the main reason for the security issues in this critical discrimination step lies in the overly simplistic definition of the corresponding Boolean variable. Therefore, this embodiment of the application sets this Boolean variable as a redundant variable. This redundant variable is not a Boolean type variable; the reverse redundancy definition increases the difficulty of the attack. Taking `ssl_config_.ignore_certificate_errors` as an example, its corresponding redundant variable does not use Boolean values ​​like false / true, but is defined as a 64-bit or 32-bit value. Taking the 64-bit definition as an example, the redundant variable corresponding to `ssl_config_.ignore_certificate_errors` is 0xFFFFFFFFFFFFFFFF. In this case, if any bit is not 0, it is false; otherwise, it is true. This greatly increases the difficulty for attackers, requiring them to use a side channel to make the runtime state all zeros, which is extremely difficult.

[0116] It is understandable that the enhanced security state can also use redundant variables, but non-Boolean values ​​can be used. This embodiment does not limit this.

[0117] Step 920: If any bit in the redundant variable is not zero, generate a fifth verification result indicating that the verification has passed.

[0118] In one embodiment, if any bit in the redundant variable is not zero, the result is true, and a fifth verification result indicating that the verification has passed is generated.

[0119] Step 930: Based on the delay parameters corresponding to the key discrimination step and the current loop parameters, repeat the process to obtain multiple fifth verification results. If each fifth verification result passes, generate a target security conclusion indicating the security of the certificate chain.

[0120] In one embodiment, the delay parameters and current loop parameters corresponding to the key discrimination steps are obtained by repeating the verification steps. The process is repeated to obtain multiple fifth verification results. If each fifth verification result passes, a target security conclusion indicating the security of the certificate chain is generated.

[0121] As described above, the core of this browser certificate verification security enhancement process in this application embodiment lies in the following two points. First, the verification steps and key judgment steps during the certificate verification process are randomly repeated, with multiple judgments and checks, making it impossible for attackers to align the timing and thus hindering side-channel attacks to modify the state of key variables. Second, redundant variables obtained by increasing the bit width make it difficult or impossible for attackers to accurately modify the corresponding results, greatly increasing the difficulty for attackers to modify multiple bits simultaneously. This effectively reduces the likelihood of a successful attack without altering the original functionality.

[0122] The technical solution provided in this application obtains an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and a server certificate of the target website. It then enters a certificate verification process. In the first verification step, basic verification of the server certificate is performed to obtain a first verification result. In the second verification step, the public key of the intermediate certificate is used to perform signature verification of the server certificate, obtaining a second verification result. In the third verification step, basic verification of the intermediate certificate is performed, and the public key of the root certificate is used to perform signature verification of the intermediate certificate, obtaining a third verification result. In the fourth verification step, the root certificate is signed to obtain a fourth verification result. When the security enhancement state is true, the delay parameters and current loop parameters for each verification step are obtained from the browser. During the certificate verification process, the corresponding verification steps are repeatedly executed based on the delay parameters and current loop parameters to obtain the corresponding verification results. If all verification results indicate successful verification, an initial security conclusion indicating that the certificate chain is secure is obtained. In the security enhancement state, this application embodiment repeatedly executes each verification step using delay parameters and current loop parameters, thereby effectively resisting potential timing attacks or accidental errors that may exist in a single verification. For example, when attackers attempt to bypass security checks by manipulating verification time or forging single verification results, this repeated verification ensures the reliability of the results through the consistency of multiple verifications, greatly reducing the probability of false positives. Furthermore, only when all verification steps pass can the accuracy of certificate chain security verification be further improved, effectively enhancing the security of browser certificate chain verification.

[0123] This application also provides a security enhancement device for browser certificate verification, which can implement the above-described security enhancement method for browser certificate verification, as described above. Figure 10 The device includes:

[0124] Certificate Chain Acquisition Module 1010: Used to acquire the initial certificate chain, which includes at least the root certificate, at least one intermediate certificate, and the server certificate of the target website.

[0125] Certificate verification module 1020: Used to enter the certificate verification process. In the first verification step, it performs basic verification on the server certificate and obtains the first verification result. In the second verification step, it uses the public key of the intermediate certificate to perform signature verification on the server certificate and obtains the second verification result. In the third verification step, it performs basic verification on the intermediate certificate and uses the public key of the root certificate to perform signature verification on the intermediate certificate and obtains the third verification result. In the fourth verification step, it performs signature verification on the root certificate and obtains the fourth verification result.

[0126] Security Enhancement Module 1030: When the security enhancement state is true, it obtains the delay parameters and current loop parameters for each verification step from the browser. During the certificate verification process, it repeatedly executes the corresponding verification steps based on the delay parameters and current loop parameters to obtain the corresponding verification results.

[0127] Verification result judgment module 1040: If all verification results indicate that the verification has passed, an initial security conclusion indicating that the certificate chain is secure is obtained.

[0128] In some embodiments, obtaining the browser's delay parameters for each verification step includes:

[0129] Obtain the browser's verification startup time, hash and encrypt the verification startup time, truncate the bytes of the encrypted result, convert the truncated bytes into an integer, and obtain the startup random number;

[0130] Obtain the execution time of the first execution of each verification step, and generate a random execution number based on the execution time and execution order;

[0131] The delay parameter is obtained based on the start and execution of random numbers.

[0132] In some embodiments, the delay parameter is obtained based on the start random number and the execution random number, including:

[0133] Calculate the XOR result of the start random number and the executed random number to obtain the delayed random number;

[0134] The delay parameters are obtained by performing a modulo operation on the delayed random number according to a preset value.

[0135] In some embodiments, the browser's current loop parameters for each verification step are obtained, including:

[0136] Obtain historical evaluation parameters and historical loop parameters for the verification steps;

[0137] If the historical evaluation parameter is greater than or equal to the preset evaluation value, decrease the historical loop parameter to obtain the current loop parameter; otherwise, within the limit of the maximum loop parameter, increase the historical loop parameter to obtain the current loop parameter.

[0138] In some embodiments, historical evaluation parameters are obtained based on historical execution times, including the following steps:

[0139] For each verification step, obtain all execution times of the verification steps in the previous certificate verification, and obtain the corresponding historical execution time based on the corresponding delay parameters and execution times;

[0140] The total execution time is obtained by summing up all historical execution times, and the delay impact parameters are determined based on the time interval in which the total execution time falls.

[0141] Based on the proportion of each historical execution time to the total execution time, the proportion of each verification step in the delay impact parameter is determined, and the historical evaluation parameters are obtained.

[0142] In some embodiments, the corresponding verification steps are repeatedly executed based on the delay parameter and the current loop parameter to obtain the corresponding verification result, including:

[0143] For each verification step, the expected execution time for each repetition is determined based on the current loop parameters and delay parameters;

[0144] All expected execution times are sorted in chronological order. If at least two expected execution times conflict, the corresponding expected execution times are postponed according to the execution order of the verification steps to update the expected execution times. The expected execution times are used to execute one verification step.

[0145] In some embodiments, after obtaining an initial security conclusion indicating that the certificate chain is secure, if all verification results indicate that the verification has passed, the method further includes:

[0146] Based on the initial security conclusion, proceed to the critical discrimination step and obtain the redundant variables corresponding to the browser. The redundant variables are not Boolean.

[0147] If none of the bits in the redundant variable is zero, generate a fifth verification result indicating that the verification has passed;

[0148] Based on the delay parameters corresponding to the key discrimination steps and the current loop parameters, the process is repeated to obtain multiple fifth verification results. If each fifth verification result passes, a target security conclusion indicating the security of the certificate chain is generated.

[0149] The specific implementation of the security enhancement device for browser certificate verification in this embodiment is basically the same as the specific implementation of the security enhancement method for browser certificate verification described above, and will not be repeated here.

[0150] This application also provides an electronic device, including:

[0151] At least one memory;

[0152] At least one processor;

[0153] At least one program;

[0154] The program is stored in a memory, and the processor executes the at least one program to implement the security enhancement method for browser certificate verification described above. The electronic device can be any smart terminal, including mobile phones, tablets, personal digital assistants (PDAs), and in-vehicle computers.

[0155] Please see Figure 11 , Figure 11 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes:

[0156] The processor 1101 can be implemented using a general-purpose central processing unit (CPU), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0157] The memory 1102 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1102 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1102, and the processor 1101 calls and executes the security enhancement method for browser certificate verification in the embodiments of this application.

[0158] Input / output interface 1103 is used to implement information input and output;

[0159] The communication interface 1104 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0160] Bus 1105 transmits information between various components of the device (e.g., processor 1101, memory 1102, input / output interface 1103, and communication interface 1104);

[0161] The processor 1101, memory 1102, input / output interface 1103 and communication interface 1104 are connected to each other within the device via bus 1105.

[0162] This application embodiment also provides a storage medium that stores a computer program, which, when executed by a processor, implements the aforementioned security enhancement method for browser certificate verification.

[0163] Memory, as a non-transitory storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0164] The security enhancement method, apparatus, device, and storage medium for browser certificate verification proposed in this application obtain an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and a server certificate of the target website. The certificate verification process then begins. In the first verification step, basic verification of the server certificate is performed to obtain a first verification result. In the second verification step, the server certificate is signed using the public key of the intermediate certificate to obtain a second verification result. In the third verification step, basic verification of the intermediate certificate is performed, and the intermediate certificate is signed using the public key of the root certificate to obtain a third verification result. In the fourth verification step, the root certificate is signed to obtain a fourth verification result. When the security enhancement state is true, the browser obtains the delay parameters and current loop parameters for each verification step. During the certificate verification process, the corresponding verification steps are repeatedly executed based on the delay parameters and current loop parameters to obtain the corresponding verification results. If all verification results indicate successful verification, an initial security conclusion indicating that the certificate chain is secure is obtained. In the security enhancement state, this application embodiment repeatedly executes each verification step using delay parameters and current loop parameters, thereby effectively resisting potential timing attacks or accidental errors that may exist in a single verification. For example, when attackers attempt to bypass security checks by manipulating verification time or forging single verification results, this repeated verification ensures the reliability of the results through the consistency of multiple verifications, greatly reducing the probability of false positives. Furthermore, only when all verification steps pass can the accuracy of certificate chain security verification be further improved, effectively enhancing the security of browser certificate chain verification.

[0165] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0166] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0167] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0168] Those skilled in the art will understand that all or some of the steps, functional modules / units in the systems and devices disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data used can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0169] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0170] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0171] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, the functional units in the various embodiments of this application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.

[0172] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0173] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A security enhancement method for browser certificate verification, characterized in that, include: Obtain an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and the server certificate of the target website; The certificate verification process begins. In the first verification step, the server certificate undergoes basic verification to obtain a first verification result. In the second verification step, the server certificate is signed and verified using the public key of the intermediate certificate to obtain a second verification result. In the third verification step, the intermediate certificate undergoes basic verification and is signed and verified using the public key of the root certificate to obtain a third verification result. In the fourth verification step, the root certificate is signed and verified to obtain a fourth verification result. When the security enhancement state is true, the delay parameters and current loop parameters of the browser for each verification step are obtained. During the certificate verification process, the corresponding verification steps are repeatedly executed based on the delay parameters and the current loop parameters to obtain the corresponding verification results. If all the verification results indicate that the verification has passed, an initial security conclusion indicating that the certificate chain is secure is obtained; Obtaining delay parameters for each verification step from the browser includes: obtaining the browser's verification startup time; hashing and encrypting the verification startup time; truncating the encrypted result into bytes; converting the truncated bytes into integers to obtain a startup random number; obtaining the execution time of the first execution of each verification step; generating an execution random number based on the execution time and execution order; calculating the XOR result of the startup random number and the execution random number to obtain a delay random number; and performing a modulo operation on the delay random number according to a preset value to obtain a delay parameter.

2. The security enhancement method for browser certificate verification according to claim 1, characterized in that, Obtain the browser's current loop parameters for each verification step, including: Obtain the historical evaluation parameters and historical loop parameters of the verification step; If the historical evaluation parameter is greater than or equal to the preset evaluation value, the historical loop parameter is reduced to obtain the current loop parameter; otherwise, within the limit of the maximum loop parameter, the historical loop parameter is increased to obtain the current loop parameter.

3. The security enhancement method for browser certificate verification according to claim 2, characterized in that, The historical evaluation parameters are obtained based on the historical execution time, including the following steps: For each verification step, obtain all execution times of the verification steps in the previous certificate verification, and obtain the corresponding historical execution time based on the corresponding delay parameter and the execution time; The total execution time is obtained by summing up all the historical execution times, and the delay impact parameters are determined based on the time interval in which the total execution time falls. Based on the ratio of each historical execution time to the total execution time, the proportion of each verification step in the delay impact parameter is determined, and the historical evaluation parameter is obtained.

4. The security enhancement method for browser certificate verification according to claim 1, characterized in that, The process of repeatedly executing the corresponding verification steps based on the delay parameter and the current loop parameter to obtain the corresponding verification result includes: For each of the verification steps, the expected execution time for each repeated execution is determined based on the current loop parameters and the delay parameters; All the expected execution times are sorted in chronological order. If at least two of the expected execution times conflict, the corresponding expected execution times are postponed according to the execution order of the verification steps to update the expected execution times. The expected execution times are used to execute the verification step once.

5. The security enhancement method for browser certificate verification according to claim 1, characterized in that, After obtaining an initial security conclusion indicating that the certificate chain is secure, if all the verification results indicate that the verification has passed, the method further includes: Based on the initial security conclusion, proceed to the critical discrimination step to obtain the redundant variables corresponding to the browser, where the redundant variables are not Boolean. If none of the bits in the redundant variables are zero, a fifth verification result indicating that the verification has passed is generated; Based on the delay parameters and current loop parameters corresponding to the key discrimination step, the process is repeated to obtain multiple fifth verification results. If each fifth verification result passes, a target security conclusion indicating the security of the certificate chain is generated.

6. A security enhancement device for browser certificate verification, characterized in that, include: Certificate chain acquisition module: used to acquire an initial certificate chain, which includes at least a root certificate, at least one intermediate certificate, and the server certificate of the target website; Certificate verification module: Used to enter the certificate verification process. In the first verification step, it performs basic verification on the server certificate to obtain a first verification result. In the second verification step, it uses the public key of the intermediate certificate to perform signature verification on the server certificate to obtain a second verification result. In the third verification step, it performs basic verification on the intermediate certificate and uses the public key of the root certificate to perform signature verification on the intermediate certificate to obtain a third verification result. In the fourth verification step, it performs signature verification on the root certificate to obtain a fourth verification result. Security Enhancement Module: When the security enhancement state is true, it obtains the delay parameters and current loop parameters of the browser for each verification step, and repeatedly executes the corresponding verification steps based on the delay parameters and the current loop parameters during the certificate verification process to obtain the corresponding verification result; Verification result judgment module: used to obtain an initial security conclusion indicating that the certificate chain is secure if all the verification results indicate that the verification is passed; Obtaining delay parameters for each verification step from the browser includes: obtaining the browser's verification startup time; hashing and encrypting the verification startup time; truncating the encrypted result into bytes; converting the truncated bytes into integers to obtain a startup random number; obtaining the execution time of the first execution of each verification step; generating an execution random number based on the execution time and execution order; calculating the XOR result of the startup random number and the execution random number to obtain a delay random number; and performing a modulo operation on the delay random number according to a preset value to obtain a delay parameter.

7. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the security enhancement method for browser certificate verification as described in any one of claims 1 to 5.

8. A storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the security enhancement method for browser certificate verification as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method for receiving a confidential time information

    CN101589348A

  • A mining method and device based on block chain, a mining machine and a block chain system

    CN109255614A