Request header enhancement system and method, device, and storage medium
By inserting header enhancement data into the TLS extension field in the HTTP/3 protocol, the coordinated work of the client SDK, telecommunications network and proxy server is used to solve the availability problem of password-free number collection under HTTP/3, and the function of securely obtaining mobile phone numbers under HTTP/3 is realized.
Patent Information
- Application Number
- PCT/CN2024/133287
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-20
- Filing Date
- 2024-11-20
- Publication Date
- 2025-06-26
AI Technical Summary
The existing HTTP/3 protocol cannot implement password-free fetching, resulting in the inability to obtain header enhanced data in the next generation of Internet transmission protocols.
It provides a request header enhancement system, including client SDK, telecommunications network and proxy server, performs pre-authorization requests through QUIC or TCP connection, inserts header enhancement data to the TLS extension field, and performs data transmission and processing in the first stage of the TLS handshake, uses the proxy server cache header to enhance the correspondence between data and access token, and returns the access token to the client SDK to obtain the mobile phone number.
It realizes the use of password-free fetching under HTTP/3, solves the availability problem of HTTP/3 password-free fetching, and ensures the security and integrity of data transmission.
Smart Images

Figure CN2024133287_26062025_PF_FP_ABST
Abstract
Description
A request header enhancement system, method, device and storage medium Technical Field
[0001] The present application relates to the field of data security technology, and in particular to a request header enhancement system, method, device and storage medium. Background Art
[0002] Password-free number retrieval is an authentication method used by carriers based on mobile data networks. It works by identifying user information (such as mobile phone number and IMEI) at the gateway when the user accesses the carrier's network. This information is encrypted and transparently transmitted to the carrier's authentication system via HTTP / HTTPS. The carrier's authentication system then exposes its capabilities and makes them available to third parties for authentication. From HTTP / 1.1 to HTTP / 2, the HTTP protocol has always used TCP as its transport protocol. The latest HTTP / 3 abandons TCP and implements a reliable transport protocol, QUIC, at the application layer based on the UDP protocol. To implement password-free number retrieval under HTTP / 3, it is necessary to obtain header enhancement data under HTTP / 3, which is not currently possible with HTTP / 3. Summary of the Invention
[0003] The present application provides a request header enhancement system, method, device and storage medium for solving the usability problem of password-free number retrieval in the next generation Internet transmission protocol HTTP / 3.
[0004] In view of this, the first aspect of the present application provides a request header enhancement system, including:
[0005] Client SDK, used to initiate a QUIC connection or a TCP connection using a mobile data network to initiate a pre-authorization request;
[0006] The telecommunications network is configured to perform a TLS handshake with the proxy server after receiving the pre-authorization request, and insert header enhancement data into a TLS extension field in the first phase of the TLS handshake;
[0007] The proxy server is used to obtain the header enhancement data in the TLS extension field and forward the header enhancement data as an http request header parameter to the number retrieval server. The number retrieval server caches the correspondence between the header enhancement data and the access token, and returns the corresponding access token to the client SDK, so that the client SDK obtains the mobile phone number in the header enhancement data according to the access token.
[0008] Optionally, the proxy server includes a core module, an HTTP module and an openssl module;
[0009] The Nginx core module is used to obtain the header enhancement data in the TLS extension field, create a shared memory pool, and cache the header enhancement data in the shared memory pool based on the SSL connection or the Nginx connection;
[0010] The HTTP module is used to obtain the cached header enhancement data and use the header enhancement data as an HTTP request header parameter;
[0011] The openssl module is used to remove the TLS extension field inserted into the header enhancement data to restore the original data packet, perform data integrity verification of the TLS protocol, and perform the TLS handshake normally after passing the verification.
[0012] Optionally, the Nginx core module is also used to:
[0013] Register a shared memory pool destruction callback function, and clean up the cached data in the shared memory pool through the shared memory pool destruction callback function.
[0014] Optionally, the HTTP module is further configured to:
[0015] Register a shared memory pool destruction callback function, and clean up the cached data in the shared memory pool through the shared memory pool destruction callback function.
[0016] A second aspect of the present application provides a request header enhancement method, which is applied to any one of the request header enhancement systems described in the first aspect, and the method includes:
[0017] Use the client SDK to initiate a QUIC connection or a TCP connection using a mobile data network to initiate a pre-authorization request.
[0018] After receiving the pre-authorization request, the telecommunications network performs a TLS handshake with the proxy server and inserts header enhancement data into the TLS extension field in the first phase of the TLS handshake;
[0019] Obtain the header enhancement data in the TLS extension field through the proxy server, and forward the header enhancement data as an http request header parameter to the number acquisition server;
[0020] The number acquisition server caches the correspondence between the header enhancement data and the access token, and returns the access token to the client SDK, so that the client SDK obtains the mobile phone number in the header enhancement data according to the access token.
[0021] Optionally, obtaining the header enhancement data in the TLS extension field through the proxy server and forwarding the header enhancement data as an http request header parameter to the number acquisition server includes:
[0022] Obtaining header enhancement data in a TLS extension field through an Nginx core module, creating a shared memory pool, and caching the header enhancement data in the shared memory pool based on an SSL connection or an Nginx connection;
[0023] Obtain the cached header enhancement data through the HTTP module, and use the header enhancement data as an http request header parameter;
[0024] Removing the TLS extension field inserted into the header enhancement data through the openssl module to restore the original data packet, and performing a data integrity check of the TLS protocol. After passing the check, the TLS handshake is performed normally.
[0025] The http request header parameters are forwarded to the number-taking server through the proxy server.
[0026] Optionally, the method further includes:
[0027] A shared memory pool destruction callback function is registered through the Nginx core module, and cached data in the shared memory pool is cleaned up through the shared memory pool destruction callback function.
[0028] Optionally, the method further includes:
[0029] A shared memory pool destruction callback function is registered through the HTTP module, and cached data in the shared memory pool is cleared through the shared memory pool destruction callback function.
[0030] A third aspect of the present application provides an electronic device, the device comprising a processor and a memory;
[0031] The memory is used to store program code and transmit the program code to the processor;
[0032] The processor is used to execute the request header enhancement method described in any one of the second aspects according to the instructions in the program code.
[0033] In a fourth aspect, the present application provides a computer-readable storage medium, which is used to store program code. When the program code is executed by a processor, it implements the request header enhancement method described in any one of the second aspects.
[0034] It can be seen from the above technical solutions that this application has the following advantages:
[0035] The present application provides a request header enhancement system, including: a client SDK, used to use a mobile traffic network to start a QUIC connection or a TCP connection to initiate a pre-authorization request; a telecommunications network, used to perform a TLS handshake with a proxy server after receiving the pre-authorization request, and insert header enhancement data into the TLS extension field in the first phase of the TLS handshake; a proxy server, used to obtain the header enhancement data in the TLS extension field, and forward the header enhancement data as an http request header parameter to a number retrieval server, which caches the correspondence between the header enhancement data and the access token, and returns the access token to the client SDK, so that the client SDK obtains the mobile phone number in the header enhancement data according to the access token.
[0036] In this application, after receiving the pre-authorization request from the client SDK, the telecommunications network performs a TLS handshake with the proxy server and inserts the header enhancement data into the TLS extension field in the first phase of the TLS handshake. The proxy server obtains the header enhancement data from the TLS extension field and forwards it to the number retrieval server as an http request header parameter, thereby realizing the use of password-free number retrieval under HTTP / 3. The number retrieval server returns the corresponding access token to the client SDK, allowing the client SDK to obtain the mobile phone number in the header enhancement data based on the access token, thereby solving the availability problem of password-free number retrieval of the next-generation Internet transmission protocol HTTP / 3. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0038] FIG1 is a schematic structural diagram of a request header enhancement system provided in an embodiment of the present application;
[0039] FIG2 is a flow chart of a QUIC request header enhancement method provided in an embodiment of the present application;
[0040] FIG3 is a flow chart of a TCP request header enhancement method provided in an embodiment of the present application;
[0041] FIG4 is a flow chart of a request header enhancement method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0042] In order to help those skilled in the art better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.
[0043] QUIC (Quick UDP Internet Connections) is a set of UDP-based transmission protocols launched by Google. It implements the functions of TCP+HTTPS+HTTP / 2, with the goal of ensuring reliability while reducing network latency. Because UDP is a simple transmission protocol, it can get rid of factors such as TCP transmission confirmation and retransmission slow start. Establishing a secure connection only requires one round trip time. It also implements HTTP / 2 multiplexing, header compression and other functions. HTTP / 3 (HyperText Transfer Protocol Version 3) is a new, next-generation Internet transmission protocol. It is the latest version of HTTP that has been developed and released. It uses advanced UDP (User Datagram Protocol) technology to solve the performance issues of HTTP / 2.0 in specific situations. By adopting QUIC technology, HTTP / 3 combines reliability, security and efficiency, fully leveraging the advantages of the UDP protocol to achieve faster network transmission speeds and shorter response times. While the use of password-free numbering has been implemented under HTTP / 1 and HTTP / 2, and has brought convenience, improvements for HTTP / 3 cannot be implemented using existing technologies. In order to solve the availability problem of password-free numbering in the next-generation Internet transmission protocol HTTP / 3, an embodiment of the present application provides a request header enhancement system that supports both QUIC and TCP header enhancement acquisition methods.
[0044] For ease of understanding, please refer to FIG1 . This embodiment of the present application provides a request header enhancement system, including:
[0045] Client SDK, used to initiate a QUIC connection or a TCP connection using a mobile data network to initiate a pre-authorization request;
[0046] Telecom Network, which performs a TLS (Transport Layer Security) handshake with the proxy server after receiving the pre-authorization request and inserts header enhancement data into the TLS extension field during the first phase of the TLS handshake.
[0047] The proxy server is used to obtain the header enhancement data in the TLS extension field and forward the header enhancement data as an http (Hypertext Transfer Protocol) request header parameter to the number retrieval server. The number retrieval server caches the correspondence between the header enhancement data and the access token, and returns the access token to the client SDK, so that the client SDK can obtain the mobile phone number in the header enhancement data based on the access token.
[0048] Furthermore, the proxy server includes a core module, an HTTP module, and an openssl module;
[0049] Nginx core module, used to obtain the header enhancement data in the TLS extension field, create a shared memory pool, and cache the header enhancement data in the shared memory pool based on SSL (Secure Socket Layer) connections or Nginx connections;
[0050] HTTP module, used to obtain cached header enhancement data and use the header enhancement data as HTTP request header parameters;
[0051] The openssl module is used to remove the TLS extension field inserted into the header enhancement data to restore the original data packet, perform data integrity verification of the TLS protocol, and execute the TLS handshake normally after passing the verification.
[0052] Furthermore, Nginx core modules are also used to:
[0053] Register a shared memory pool destruction callback function and use it to clean up the cached data in the shared memory pool.
[0054] Furthermore, the HTTP module is also used to:
[0055] Register a shared memory pool destruction callback function and use it to clean up the cached data in the shared memory pool.
[0056] The request header enhancement system in the embodiment of the present application can support both QUIC and TCP header enhancement acquisition methods. In one embodiment, referring to FIG2 , the process of obtaining QUIC header enhancement data includes:
[0057] The client SDK uses the Wi-Fi switching function to start a QUIC connection using the mobile traffic network to initiate a pre-authorization request;
[0058] After receiving the pre-authorization request, the telecommunications network performs a TLS handshake with the proxy server (NGINX-QUIC server) and inserts header enhancement data into the TLS extension field in the first phase of the TLS handshake (i.e., the Client Hello phase). The TLS extension field inserted with the header enhancement data is an additional TLS custom extension field, which can be specifically identified as a TLS extension custom field within the reserved range of the TLS specification. The header enhancement data includes user information (such as user mobile phone number, IMEI, etc.). The header enhancement data is obtained by processing the user information and transmitted through the header enhancement data, which helps to improve data security. The processing of user information to obtain the header enhancement data can be implemented using existing technologies, and its specific process will not be described in detail here.
[0059] The proxy server obtains the header enhancement data in the TLS extension field and forwards it to the number-retrieval server as an HTTP request header parameter. The number-retrieval server caches the correspondence between the header enhancement data and the access token and returns the access token to the client SDK. The client SDK then obtains the mobile phone number in the header enhancement data based on the access token. Specifically:
[0060] The Nginx core module obtains header enhancement data in the TLS extension field, creates a shared memory pool, and caches the header enhancement data in the shared memory pool based on the SSL connection; the original Nginx core module in the proxy server does not support obtaining header enhancement data in the TLS extension field. The embodiment of the present application improves the Nginx core module, registers an Nginx TLS extension custom field processing callback function in the Nginx core module, obtains header enhancement data corresponding to the TLS extension custom field according to the Nginx connection in the TLS extension custom field processing callback function, so that the improved Nginx core module can support obtaining header enhancement data in the TLS extension custom field, create a shared memory pool, and cache the header enhancement data in the shared memory pool based on the SSL connection;
[0061] The HTTP module obtains the header enhancement data cached in the shared memory pool based on the SSL connection, and uses the header enhancement data as an HTTP request header parameter; the original HTTP module in the proxy server does not support obtaining the header enhancement data cached in the shared memory pool. The embodiment of the present application improves the HTTP module by registering an Nginx http forwarding callback function in the HTTP module, taking out the header enhancement data stored in the Nginx core module, and implementing HTTP forwarding in the form of an http request header;
[0062] The openssl module removes the TLS extension field (i.e., the TLS extension custom field) inserted into the header enhancement data to restore the original data packet, and performs data integrity verification of the TLS protocol. Specifically, it performs MAC verification on the restored original data packet, and executes the TLS handshake normally after passing the verification. The openssl module performs MAC verification on the TLS data packet transmitted by the telecommunications network to prevent data tampering and attacks to ensure data security. The TLS data packet is generated by the first phase (Client Hello) interaction of the TLS protocol. The function of this data packet is for the client to send the supported protocol version and cipher suite to the server. Since the TLS extension custom field inserted into the header enhancement data does not exist in the original http protocol, if the extension field is not deleted, the subsequent steps of the protocol cannot be performed. The embodiment of the present application improves the openssl module so that it can clone the TLS data packet, remove the TLS extension custom field, and restore the original TLS data packet;
[0063] The proxy server forwards the HTTP request header parameters to the number retrieval server. The number retrieval server caches the correspondence between the enhanced header data and the access token and returns the access token to the client SDK, allowing the client SDK to retrieve the mobile phone number in the enhanced header data based on the access token. After the proxy server forwards the HTTP request header parameters to the number retrieval server, the number retrieval server caches the correspondence between the enhanced header data and the access token in the HTTP request header parameters and returns the access token to the client SDK. The client SDK retrieves the mobile phone number in the enhanced header data based on the access token.
[0064] In another embodiment, referring to FIG3 , the process of obtaining the TCP header enhanced data includes:
[0065] The client SDK uses the Wi-Fi switching function to initiate a TCP connection using the mobile data network to initiate a pre-authorization request;
[0066] After receiving the pre-authorization request, the telecom network performs a TLS handshake with the proxy server and inserts the header enhancement data into the TLS extension field in the first phase of the TLS handshake;
[0067] The proxy server obtains the header enhancement data in the TLS extension field and forwards it to the number-retrieval server as an HTTP request header parameter. The number-retrieval server caches the correspondence between the header enhancement data and the access token and returns the access token to the client SDK, allowing the client SDK to obtain the mobile phone number in the header enhancement data based on the access token. Specifically:
[0068] The Nginx core module obtains header enhancement data in the TLS extension field, creates a shared memory pool, and caches the header enhancement data in the shared memory pool based on the Nginx connection; the original Nginx core module in the proxy server does not support obtaining header enhancement data in the TLS extension field. The embodiment of the present application improves the Nginx core module, registers an Nginx TLS extension custom field processing callback function in the Nginx core module, obtains header enhancement data corresponding to the TLS extension custom field according to the Nginx connection in the TLS extension custom field processing callback function, so that the improved Nginx core module can support obtaining header enhancement data in the TLS extension custom field, create a shared memory pool, and cache the header enhancement data in the shared memory pool based on the Nginx connection;
[0069] The Nginx core module registers a shared memory pool destruction callback function, and cleans up the cached data in the shared memory pool through the shared memory pool destruction callback function;
[0070] The HTTP module obtains the cached header enhancement data based on the Nginx connection and uses the header enhancement data as the http request header parameter; the original HTTP module in the proxy server does not support obtaining the cached header enhancement data in the shared memory pool. The embodiment of the present application improves the HTTP module, specifically registers the Nginx http forwarding callback function in the HTTP module, takes out the header enhancement data stored in the Nginx core module, and implements http forwarding in the form of http request header.
[0071] The HTTP module registers a shared memory pool destruction callback function and uses the shared memory pool destruction callback function to clean up the cached data in the shared memory pool;
[0072] The openssl module removes the TLS extension field inserted into the header enhancement data to restore the original data packet, and performs data integrity check of the TLS protocol, and executes the TLS handshake normally after passing the check. The openssl module performs MAC check on the TLS data packet transmitted by the telecommunications network to prevent data tampering and attacks to ensure data security. The TLS data packet is generated by the first phase (Client Hello) interaction of the TLS protocol. The function of this data packet is for the client to send the supported protocol version and cipher suite to the server. Since the original http protocol does not have a TLS extension custom field inserted into the header enhancement data, if the extension field is not deleted, the subsequent steps of the protocol cannot be performed. The embodiment of the present application improves the openssl module so that it can clone the TLS data packet, remove the TLS extension custom field, and restore the original TLS data packet;
[0073] The proxy server forwards the HTTP request header parameters to the number retrieval server. The number retrieval server caches the correspondence between the enhanced header data and the access token and returns the access token to the client SDK, allowing the client SDK to retrieve the mobile phone number in the enhanced header data based on the access token. After the proxy server forwards the HTTP request header parameters to the number retrieval server, the number retrieval server caches the correspondence between the enhanced header data and the access token in the HTTP request header parameters and returns the access token to the client SDK. The client SDK retrieves the mobile phone number in the enhanced header data based on the access token.
[0074] When acquiring TCP header enhancement data, TCP connections are reused, causing the header enhancement data to be overwritten and resulting in serialized phone numbers. To avoid this, the present embodiment of the application registers a shared memory pool destruction callback function in the Nginx core module and the HTTP module to clean up the cached data. QUIC, on the other hand, is based on UDP connections, which are stateless and not reused, so there is no need to clean up the cached data.
[0075] The QUIC header enhancement implemented by the NGINX-QUIC server in the embodiment of the present application is an innovative technology within the known scope. The improved NGINX-QUIC server in the embodiment of the present application can simultaneously support TCP header enhancement and the emerging QUIC header enhancement, reducing maintenance costs and expansion costs.
[0076] In an embodiment of the present application, after receiving the pre-authorization request from the client SDK, the telecommunications network performs a TLS handshake with the proxy server and inserts the header enhancement data into the TLS extension field in the first phase of the TLS handshake. The proxy server obtains the header enhancement data from the TLS extension field and forwards it to the number retrieval server as an http request header parameter. The number retrieval server returns the corresponding access token to the client SDK, so that the client SDK obtains the mobile phone number in the header enhancement data according to the access token, realizing the use of password-free number retrieval under HTTP / 3, thereby solving the availability problem of password-free number retrieval of the next-generation Internet transmission protocol HTTP / 3.
[0077] The above is an embodiment of a request header enhancement system provided by the present application, and the following is an embodiment of a request header enhancement method provided by the present application.
[0078] Referring to FIG4 , an embodiment of the present application provides a request header enhancement method, which is applied to the above-mentioned request header enhancement system. The method includes:
[0079] Step 101: Use the mobile traffic network to start a QUIC connection or a TCP connection to initiate a pre-authorization request through the client SDK.
[0080] The request header enhancement method in the embodiment of the present application can realize QUIC request header enhancement and TCP request header enhancement. When implementing QUIC request header enhancement, the client SDK uses the mobile traffic network to start the QUIC connection through the WIFI switching function to initiate a pre-authorization request; when implementing TCP request header enhancement, the client SDK uses the mobile traffic network to start the TCP connection through the WIFI switching function to initiate a pre-authorization request.
[0081] Step 102: After receiving the pre-authorization request, the telecommunications network performs a TLS handshake with the proxy server and inserts header enhancement data into the TLS extension field in the first phase of the TLS handshake.
[0082] After receiving the pre-authorization request, Telecom Network performs a TLS handshake with the proxy server and inserts header enhancement data into the TLS extension field in the first phase of the TLS handshake (i.e., the Client Hello phase).
[0083] Step 103: Obtain the header enhancement data in the TLS extension field through the proxy server, and forward the header enhancement data as an http request header parameter to the number acquisition server.
[0084] The proxy server includes a core module, an HTTP module, and an OpenSSL module.
[0085] When implementing QUIC request header enhancement, the Nginx core module obtains the header enhancement data in the TLS extension field, creates a shared memory pool, and caches the header enhancement data in the shared memory pool based on the SSL connection; the HTTP module obtains the header enhancement data cached in the shared memory pool based on the SSL connection, and uses the header enhancement data as the http request header parameter; the original data packet is restored by removing the TLS extension field inserted into the header enhancement data, and the TLS protocol data integrity check is performed. After passing the check, the TLS handshake is executed normally, and the proxy server forwards the http request header parameters to the number retrieval server.
[0086] When implementing TCP request header enhancement, the Nginx core module retrieves the header enhancement data from the TLS extension field, creates a shared memory pool, and caches the header enhancement data in the shared memory pool based on the Nginx connection. The HTTP module retrieves the cached header enhancement data based on the Nginx connection and uses it as the HTTP request header parameter. The OpenSSL module removes the TLS extension field inserted into the header enhancement data to restore the original data packet. A TLS data integrity check is then performed. Once the check passes, the TLS handshake proceeds normally, and the proxy server forwards the HTTP request header parameters to the number retrieval server.
[0087] Furthermore, when implementing TCP request header enhancement, the Nginx core module will also register a shared memory pool destruction callback function, and clean up the cached data in the shared memory pool through the shared memory pool destruction callback function.
[0088] Furthermore, when implementing TCP request header enhancement, the HTTP module will also register a shared memory pool destruction callback function, and clean up the cached data in the shared memory pool through the shared memory pool destruction callback function.
[0089] Step 104: The number acquisition server caches the correspondence between the header enhancement data and the access token, and returns the access token to the client SDK, so that the client SDK obtains the mobile phone number in the header enhancement data according to the access token.
[0090] After the proxy server forwards the http request header parameters to the number retrieval server, the number retrieval server caches the correspondence between the header enhanced data in the http request header parameters and the access token, and returns the access token to the client SDK. The client SDK obtains the mobile phone number in the header enhanced data based on the access token.
[0091] In an embodiment of the present application, after receiving the pre-authorization request from the client SDK, the telecommunications network performs a TLS handshake with the proxy server and inserts header enhancement data into the TLS extension field in the first phase of the TLS handshake. The proxy server obtains the header enhancement data from the TLS extension field and forwards it to the number retrieval server as an http request header parameter, thereby realizing the use of password-free number retrieval under HTTP / 3. The number retrieval server returns the corresponding access token to the client SDK, allowing the client SDK to obtain the mobile phone number in the header enhancement data based on the access token, thereby solving the availability problem of password-free number retrieval of the next-generation Internet transmission protocol HTTP / 3.
[0092] An embodiment of the present application further provides an electronic device, the device including a processor and a memory;
[0093] The memory is used to store program codes and transmit the program codes to the processor;
[0094] The processor is configured to execute the request header enhancement method in the aforementioned method embodiment according to instructions in the program code.
[0095] An embodiment of the present application also provides a computer-readable storage medium, which is used to store program code. When the program code is executed by a processor, the request header enhancement method in the aforementioned method embodiment is implemented.
[0096] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0097] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0098] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0099] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0100] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0101] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for executing all or part of the steps of the method described in each embodiment of the present application through a computer device (which can be a personal computer, server, or network device, etc.). The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (English full name: Read-Only Memory, English abbreviation: ROM), random access memory (English full name: Random Access Memory, English abbreviation: RAM), disk or optical disk and other media that can store program code.
[0102] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A request header enhancement system, characterized in that: include: Client SDK, used to start a QUIC connection or a TCP connection using a mobile traffic network to initiate a pre-authorization request; The telecommunications network is used to perform a TLS handshake with the proxy server after receiving the pre-authorization request, and insert header enhancement data into a TLS extension field in the first phase of the TLS handshake; The proxy server is used to obtain the header enhancement data in the TLS extension field and forward the header enhancement data as an http request header parameter to the number-taking server. The number-taking server caches the correspondence between the header enhancement data and the access token, and returns the corresponding access token to the client SDK, so that the client SDK obtains the mobile phone number in the header enhancement data according to the access token.
2. The request header enhancement system according to claim 1, characterized in that: The proxy server comprises a core module, an HTTP module and an openssl module; The Nginx core module is used to obtain the header enhancement data in the TLS extension field, create a shared memory pool, and cache the header enhancement data in the shared memory pool based on the SSL connection or the Nginx connection; The HTTP module is used to obtain the cached header enhancement data and use the header enhancement data as an http request header parameter; The openssl module is used to remove the TLS extension field inserted into the header enhancement data to restore the original data packet, and perform data integrity verification of the TLS protocol, and perform the TLS handshake normally after passing the verification.
3. The request header enhancement system according to claim 2, characterized in that: The Nginx core module is also used to: A shared memory pool destruction callback function is registered, and cached data in the shared memory pool is cleaned up through the shared memory pool destruction callback function.
4. The request header enhancement system according to claim 2, characterized in that: The HTTP module is also used to: A shared memory pool destruction callback function is registered, and cached data in the shared memory pool is cleaned up through the shared memory pool destruction callback function.
5. A request header enhancement method, characterized in that: The request header enhancement system according to any one of claims 1 to 4, wherein the method comprises: Use the client SDK to start a QUIC connection or a TCP connection using a mobile traffic network to initiate a pre-authorization request; After receiving the pre-authorization request, the telecommunications network performs a TLS handshake with the proxy server and inserts header enhancement data into the TLS extension field in the first phase of the TLS handshake; Obtain the header enhancement data in the TLS extension field through the proxy server, and forward the header enhancement data as an http request header parameter to the number acquisition server; The corresponding relationship between the number-taking server cache header and the access token is enhanced, and the access token is returned. The access token is given to the client SDK, so that the client SDK can obtain the mobile phone number in the header enhanced data based on the access token.
6. The request header enhancement method according to claim 5, characterized in that: The step of obtaining the header enhancement data in the TLS extension field through the proxy server and forwarding the header enhancement data as an http request header parameter to the number acquisition server includes: Obtaining header enhancement data in a TLS extension field through an Nginx core module, creating a shared memory pool, and caching the header enhancement data in the shared memory pool based on an SSL connection or an Nginx connection; Obtain the cached header enhancement data through the HTTP module, and use the header enhancement data as an http request header parameter; Removing the TLS extension field inserted into the header enhancement data through the openssl module to restore the original data packet, and performing a data integrity check of the TLS protocol, and performing a TLS handshake normally after passing the check; The http request header parameters are forwarded to the number-taking server through the proxy server.
7. The request header enhancement method according to claim 6, characterized in that: The method further comprises: The shared memory pool destruction callback function is registered through the Nginx core module, and the cached data in the shared memory pool is cleaned up through the shared memory pool destruction callback function.
8. The request header enhancement method according to claim 6, characterized in that: The method further comprises: A shared memory pool destruction callback function is registered through the HTTP module, and cached data in the shared memory pool is cleaned up through the shared memory pool destruction callback function.
9. An electronic device, characterized in that: The device comprises a processor and a memory; The memory is used to store program codes and transmit the program codes to the processor; The processor is used to execute the request header enhancement method described in any one of claims 5-8 according to the instructions in the program code.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store program code, and when the program code is executed by a processor, the request header enhancement method according to any one of claims 5 to 8 is implemented.
Citation Information
Patent Citations
User information transmission method, device and system and computer readable storage medium
CN110858834A
Equipment anonymous identifier acquisition method and device, storage medium and computer equipment
CN115696314A
Network method, device and equipment based on TLS man-in-the-middle technology and storage medium
CN116366720A
Data transmission method and device, server and storage medium
CN116939057A
Request header enhancement system, method and device and storage medium
CN117729025A