WO2025255769A1 - 请求处理的方法、装置、设备和存储介质 - Google Patents

请求处理的方法、装置、设备和存储介质

Info

Publication number
WO2025255769A1
WO2025255769A1 PCT/CN2024/098955 CN2024098955W WO2025255769A1 WO 2025255769 A1 WO2025255769 A1 WO 2025255769A1 CN 2024098955 W CN2024098955 W CN 2024098955W WO 2025255769 A1 WO2025255769 A1 WO 2025255769A1
Authority
WO
WIPO (PCT)
Prior art keywords
target interface
encrypted content
access request
parameters
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2024/098955
Other languages
English (en)
French (fr)
Inventor
张亚鹏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Douyin Vision Co Ltd
Original Assignee
Douyin Vision Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Douyin Vision Co Ltd filed Critical Douyin Vision Co Ltd
Priority to CN202480004287.7A priority Critical patent/CN121532745A/zh
Priority to PCT/CN2024/098955 priority patent/WO2025255769A1/zh
Publication of WO2025255769A1 publication Critical patent/WO2025255769A1/zh
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/30Creation or generation of source code
    • G06F8/33Intelligent editors

Definitions

  • the exemplary embodiments disclosed herein relate generally to the field of computers, and in particular to methods, apparatus, devices and computer-readable storage media for request processing.
  • APIs Application Programming Interfaces
  • a method for request processing includes: receiving an access request for a target interface; obtaining target interface parameters and first encrypted content from the access request; generating second encrypted content by encrypting preset parameters associated with the target interface and the target interface parameters; and processing the access request for the target interface based on a comparison of the first encrypted content and the second encrypted content.
  • a method for request processing includes: obtaining preset parameters associated with a target interface; generating first encrypted content by encrypting the preset parameters and the target interface parameters; and generating an access request for the target interface, the access request including the first encrypted content and the target interface parameters.
  • an apparatus for request processing includes: a request receiving module configured to receive an access request for a target interface; a first acquisition module configured to acquire target interface parameters and first encrypted content from the access request; a first encryption module configured to generate second encrypted content by encrypting preset parameters associated with the target interface and the target interface parameters; and a request processing module configured to...
  • the system compares the first and second encrypted content to process access requests for the target interface.
  • an apparatus for request processing includes: a second acquisition module configured to acquire preset parameters associated with a target interface; a second encryption module configured to generate first encrypted content by encrypting the preset parameters and the target interface parameters; and a request generation module configured to generate an access request for the target interface, the access request including the first encrypted content and the target interface parameters.
  • an electronic device in a fifth aspect of this disclosure, includes at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit. When executed by the at least one processing unit, the instructions cause the device to perform the methods of the first or second aspect.
  • a computer-readable storage medium stores a computer program that can be executed by a processor to implement the methods of the first or second aspect.
  • a computer program product includes computer-executable instructions that, when executed by a processor, implement the method according to a first or second aspect of this disclosure.
  • Figure 1 shows a schematic diagram of an example environment in which embodiments of the present disclosure may be implemented
  • Figure 2 illustrates a flowchart of an example request processing procedure according to some embodiments of the present disclosure
  • FIG. 3A illustrates an example request processing procedure according to some embodiments of the present disclosure. Schematic diagram
  • Figure 3B illustrates a schematic diagram of an example request processing procedure according to some embodiments of the present disclosure
  • Figure 4 illustrates a flowchart of an example request processing procedure according to some embodiments of the present disclosure
  • Figure 5A shows a schematic structural block diagram of an example request processing apparatus according to some embodiments of the present disclosure
  • Figure 5B shows a schematic structural block diagram of an example request processing apparatus according to some embodiments of the present disclosure.
  • Figure 6 shows a block diagram of an electronic device capable of implementing several embodiments of the present disclosure.
  • the term “comprising” and similar terms should be understood as open-ended inclusion, i.e., “including but not limited to”.
  • the term “based on” should be understood as “at least partially based on”.
  • the term “one embodiment” or “the embodiment” should be understood as “at least one embodiment”.
  • the term “some embodiments” should be understood as “at least some embodiments”.
  • Other explicit and implicit definitions may also be included below.
  • the terms “first”, “second”, etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below. Definition.
  • the embodiments of this disclosure may involve user data, data acquisition, and/or use. All of these aspects comply with applicable laws, regulations, and relevant provisions. In the embodiments of this disclosure, all data collection, acquisition, processing, manipulation, forwarding, and use are conducted with the user's knowledge and confirmation. Accordingly, in implementing the embodiments of this disclosure, the type, scope of use, and usage scenarios of any data or information that may be involved should be communicated to the user and their authorization obtained in accordance with relevant laws and regulations through appropriate means. The specific methods of notification and/or authorization may vary depending on the actual situation and application scenario, and the scope of this disclosure is not limited in this respect.
  • any processing of personal information will be carried out only under the premise of legality (such as obtaining the consent of the personal information subject, or being necessary for the performance of a contract), and will only be carried out within the scope stipulated or agreed upon.
  • a user's refusal to process personal information other than that necessary for basic functions will not affect the user's use of basic functions.
  • APIs have a wide range of applications. This has also led to numerous attack methods targeting APIs, causing various serious security incidents, such as data breaches resulting from API attacks.
  • Embodiments of this disclosure propose a request processing scheme. According to this scheme, an access request for a target interface can be received; target interface parameters and first encrypted content can be obtained from the access request; second encrypted content can be generated by encrypting preset parameters associated with the target interface and the target interface parameters; and the access request for the target interface can be processed based on a comparison of the first encrypted content and the second encrypted content.
  • the embodiments of this disclosure can verify the legitimacy of access requests based on the comparison of encrypted content, thereby improving the security of the target interface and avoiding access risks caused by transmitting interface parameters in plaintext.
  • Figure 1 illustrates an example environment 100 in which embodiments of the present disclosure can be implemented.
  • the example environment 100 may include electronic device 110 and server 130.
  • electronic device 110 can use application 120 to present interface 150 for supporting interface interaction.
  • electronic device 110 communicates with server 130 to provide services to application 120.
  • Electronic device 110 can be any type of mobile terminal, fixed terminal, or portable terminal, including mobile phones, desktop computers, laptop computers, notebook computers, netbook computers, tablet computers, media computers, multimedia tablets, personal communication system (PCS) devices, personal navigation devices, personal digital assistants (PDAs), audio/video players, digital cameras/camcorders, positioning devices, television receivers, radio receivers, e-book devices, gaming devices, or any combination thereof, including accessories and peripherals of these devices or any combination thereof.
  • electronic device 110 can also support any type of user-facing interface (such as "wearable" circuitry).
  • server 130 receives an access request for the target interface.
  • the target interface may be associated with obtaining a target service.
  • a target interface may be provided by a model, agent, or bot to support the invocation of corresponding processing capabilities.
  • server 130 obtains the target interface parameters and the first encrypted content from the access request.
  • target interface parameter can be one or more parameters in the access request for the target interface, and this disclosure is not intended to limit the number of target interface parameters.
  • server 130 In box 230, server 130 generates second encrypted content by encrypting preset parameters associated with the target interface and target interface parameters.
  • the preset parameter includes a first string, which may be, for example, a preset string.
  • a preset string may be associated with a target interface; for instance, different interfaces may correspond to different strings.
  • server 130 processes access requests for the target interface based on a comparison of the first encrypted content and the second encrypted content.
  • the server 130 if the server 130 responds to a match between the first encrypted content and the second encrypted content, it indicates that the target interface has not been compromised, the access request is a legitimate access request, and the server can perform the target operation based on the access request.
  • the first encrypted content included in the legitimate access request can be generated by encrypting the target interface parameters and preset parameters.
  • server 130 may reject an access request in response to a mismatch between the first encrypted content and the second encrypted content. When the first encrypted content and the second encrypted content do not match, server 130 may determine that the access request is an illegal access request.
  • the illegitimate access request is constructed based on the first encrypted content and the stolen target interface parameters. It is understood that because the target interface parameters are included in the target interface in plaintext, other users can steal the target interface and modify the target interface parameters to achieve their own needs. For example, a user changes a parameter in the target interface from "Hello" to "How's the weather today?". In this case, if another user constructs an access request based on the modified target interface parameters, the access request received by server 130 will be an illegitimate request.
  • Figure 4 shows a flowchart of an example request processing procedure 400 according to some embodiments of the present disclosure.
  • Procedure 400 may be implemented at electronic device 110.
  • Procedure 400 is described below with reference to Figure 1.
  • electronic device 110 acquires preset parameters associated with the target interface.
  • such a preset parameter may be a preset string that is the same as the preset string used by the server 130 to perform the encryption task mentioned above.
  • electronic device 110 can obtain preset parameters corresponding to the target interface from server 130.
  • electronic device 110 generates first encrypted content by using encrypted preset parameters and target interface parameters.
  • electronic device 110 acquires preset parameters (e.g., preset strings) associated with a target interface and target interface parameters.
  • Electronic device 110 generates first encrypted content by encrypting the preset parameters and target interface parameters.
  • such encryption operations may be performed based on an encryption algorithm.
  • electronic device 110 encrypts a preset string and target interface parameters based on MD5 to obtain an encrypted string (also known as the first encrypted content).
  • electronic device 110 generates an access request for the target interface, the access request including first encrypted content and target interface parameters.
  • such target interface parameters are included in the access request in plaintext.
  • the electronic device 110 may send the access request to the server 130 to access the service corresponding to the target interface.
  • the embodiments of this disclosure can verify the legitimacy of access requests based on the comparison of encrypted content, thereby improving the security of the target interface and avoiding access risks caused by transmitting interface parameters in plaintext.
  • FIG5A shows a schematic structural block diagram of an example apparatus 500A for request processing according to certain embodiments of this disclosure.
  • Apparatus 500A may be implemented as or included in server 130.
  • the various modules/components in apparatus 500A may be implemented by hardware, software, firmware, or any combination thereof.
  • the request processing module 540 is specifically configured to perform a target operation based on the access request in response to a match between the first encrypted content and the second encrypted content; or to reject the access request in response to a mismatch between the first encrypted content and the second encrypted content.
  • the target interface parameters are included in the access request in plaintext.
  • the preset parameters include a first string
  • the first encryption module 530 is specifically configured to obtain the first string associated with the target interface; and to generate a second string by encrypting the first string and the target interface parameters, as the second encrypted content.
  • the modules included in device 500A can be implemented in various ways, including software, hardware, firmware, or any combination thereof.
  • one or more units can be implemented using software and/or firmware, such as machine-executable instructions stored on a storage medium.
  • some or all of the modules in device 500A can be implemented at least partially by one or more hardware logic components.
  • exemplary types of hardware logic components include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
  • the device 500B includes a second acquisition module 550 configured to acquire preset parameters associated with a target interface; a second encryption module 560 configured to generate first encrypted content by encrypting the preset parameters and the target interface parameters; and a request generation module. 570 is configured to generate an access request for the target interface, the access request including first encrypted content and target interface parameters.
  • the target interface parameters are included in the access request in plaintext.
  • Figure 6 shows a block diagram of an electronic device 600 in which one or more embodiments of the present disclosure may be implemented. It should be understood that the electronic device 600 shown in Figure 6 is merely exemplary and should not constitute any limitation on the functionality and scope of the embodiments described herein. The electronic device 600 shown in Figure 6 can be used to implement the electronic device 110 of Figure 1.
  • the electronic device 600 is in the form of a general-purpose electronic device.
  • Components of the electronic device 600 may include, but are not limited to, one or more processors or processing units 610, memory 620, storage device 630, one or more communication units 640, one or more input devices 650, and one or more output devices 660.
  • the processing unit 610 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 620. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing capability of the electronic device 600.
  • Electronic device 600 typically includes multiple computer storage media. Such media can be any accessible media that is accessible to electronic device 600, including but not limited to volatile and non-volatile media, removable and non-removable media.
  • Memory 620 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof.
  • Storage device 630 can be removable or non-removable media and may include machine-readable media such as flash drives, A disk or any other medium that can be used to store information and/or data and can be accessed within an electronic device 600.
  • Electronic device 600 may further include additional removable/non-removable, volatile/non-volatile storage media.
  • disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks may be provided.
  • each drive may be connected to a bus (not shown) via one or more data media interfaces.
  • Memory 620 may include computer program product 625 having one or more program modules configured to perform various methods or actions of various embodiments of the present disclosure.
  • the communication unit 640 enables communication with other electronic devices via a communication medium. Additionally, the functionality of the components of the electronic device 600 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, the electronic device 600 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node.
  • PCs network personal computers
  • a computer-readable storage medium that stores computer-executable instructions thereon, wherein the computer-executable instructions are executed by a processor to implement the methods described above.
  • a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, which are executed by a processor to implement the methods described above.
  • These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions/actions specified in one or more blocks of the flowchart and/or block diagram.
  • These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and/or other device to operate in a particular manner.
  • the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions/actions specified in one or more blocks of the flowchart and/or block diagram.
  • Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions/actions specified in one or more boxes of a flowchart and/or block diagram.
  • each block in the block diagrams and/or flowcharts, and combinations of blocks in the block diagrams and/or flowcharts may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Information Transfer Between Computers (AREA)
  • Storage Device Security (AREA)

Abstract

本公开的实施例涉及请求处理的方法、装置、设备和存储介质。在此提出的方法包括:接收针对目标接口的访问请求;从访问请求中获取目标接口参数和第一加密内容;通过加密与目标接口相关联的预设参数和目标接口参数,生成第二加密内容;以及基于第一加密内容和第二加密内容的比较,处理针对目标接口的访问请求。以此方式,本公开的实施例能够基于加密内容的比较来验证访问请求的合法性,从而提高目标接口的安全性,避免由于明文传递接口参数所导致的访问风险。

Description

请求处理的方法、装置、设备和存储介质 技术领域
本公开的示例实施例总体涉及计算机领域,特别地涉及请求处理的方法、装置、设备和计算机可读存储介质。
背景技术
计算机与互联网技术的发展,都离不开背后的应用程序接口(Application Programming Interface,API)的支持,不管是数据还是服务,都是需要通过API来进行交互,这使得API的应用范围十分广泛。因此,API的安全使用成为人们关注的焦点问题。
发明内容
在本公开的第一方面,提供了一种请求处理的方法。该方法包括:接收针对目标接口的访问请求;从访问请求中获取目标接口参数和第一加密内容;通过加密与目标接口相关联的预设参数和目标接口参数,生成第二加密内容;以及基于第一加密内容和第二加密内容的比较,处理针对目标接口的访问请求。
在本公开的第二方面,提供了一种请求处理的方法。该方法包括:获取与目标接口相关联的预设参数;通过加密预设参数和目标接口参数,生成第一加密内容;以及生成针对目标接口的访问请求,访问请求包括第一加密内容和目标接口参数。
在本公开的第三方面,提供了一种用于请求处理的装置。该装置包括:请求接收模块,被配置为接收针对目标接口的访问请求;第一获取模块,被配置为从访问请求中获取目标接口参数和第一加密内容;第一加密模块,被配置为通过加密与目标接口相关联的预设参数和目标接口参数,生成第二加密内容;以及请求处理模块,被配置为基于 第一加密内容和第二加密内容的比较,处理针对目标接口的访问请求。
在本公开的第四方面,提供了一种用于请求处理的装置。该装置包括:第二获取模块,被配置为获取与目标接口相关联的预设参数;第二加密模块,被配置为通过加密预设参数和目标接口参数,生成第一加密内容;以及请求生成模块,被配置为生成针对目标接口的访问请求,访问请求包括第一加密内容和目标接口参数。
在本公开的第五方面,提供了一种电子设备。该设备包括至少一个处理单元;以及至少一个存储器,至少一个存储器被耦合到至少一个处理单元并且存储用于由至少一个处理单元执行的指令。指令在由至少一个处理单元执行时使设备执行第一方面或第二方面的方法。
在本公开的第六方面,提供了一种计算机可读存储介质。该计算机可读存储介质上存储有计算机程序,计算机程序可由处理器执行以实现第一方面或第二方面的方法。
在本公开的第七方面,提供了一种计算机程序产品。该计算机程序产品包括计算机可执行指令,这些指令在被处理器执行时,实现根据本公开的第一方面或第二方面的方法。
应当理解,本内容部分中所描述的内容并非旨在限定本公开的实施例的关键特征或重要特征,也不用于限制本公开的范围。本公开的其他特征将通过以下的描述而变得容易理解。
附图说明
结合附图并参考以下详细说明,本公开各实施例的上述和其他特征、优点及方面将变得更加明显。在附图中,相同或相似的附图标记表示相同或相似的元素,其中:
图1示出了其中可以实施根据本公开的实施例的示例环境的示意图;
图2示出了根据本公开的一些实施例的示例请求处理的过程的流程图;
图3A示出了根据本公开的一些实施例的示例请求处理的过程的 示意图;
图3B示出了根据本公开的一些实施例的示例请求处理的过程的示意图;
图4示出了根据本公开的一些实施例的示例请求处理的过程的流程图;
图5A示出了根据本公开的一些实施例的示例请求处理装置的示意性结构框图;
图5B示出了根据本公开的一些实施例的示例请求处理装置的示意性结构框图;以及
图6示出了能够实施本公开的多个实施例的电子设备的框图。
具体实施方式
下面将参照附图更详细地描述本公开的实施例。虽然附图中示出了本公开的某些实施例,然而应当理解的是,本公开可以通过各种形式来实现,而且不应该被解释为限于这里阐述的实施例,相反,提供这些实施例是为了更加透彻和完整地理解本公开。应当理解的是,本公开的附图及实施例仅用于示例性作用,并非用于限制本公开的保护范围。
需要注意的是,本文中所提供的任何节/子节的标题并不是限制性的。本文通篇描述了各种实施例,并且任何类型的实施例都可以包括在任何节/子节下。此外,在任一节/子节中描述的实施例可以以任何方式与同一节/子节和/或不同节/子节中描述的任何其他实施例相结合。
在本公开的实施例的描述中,术语“包括”及其类似用语应当理解为开放性包含,即“包括但不限于”。术语“基于”应当理解为“至少部分地基于”。术语“一个实施例”或“该实施例”应当理解为“至少一个实施例”。术语“一些实施例”应当理解为“至少一些实施例”。下文还可能包括其他明确的和隐含的定义。术语“第一”、“第二”等可以指代不同的或相同的对象。下文还可能包括其他明确的和隐含 的定义。
本公开的实施例中可能涉及用户的数据、数据的获取和/或使用等。这些方面均遵循相应的法律法规及相关规定。在本公开的实施例中,所有数据的采集、获取、处理、加工、转发、使用等,都是在用户知晓并且确认的前提下进行的。相应地,在实现本公开的各实施例时,均应根据相关法律法规通过适当的方式,将可能所涉及的数据或信息的类型、使用范围、使用场景等告知用户并获得用户的授权。具体的告知和/或授权方式可以根据实际情况和应用场景而变化,本公开的范围在此方面不受限制。
本说明书及实施例中方案,如涉及个人信息处理,则均会在具备合法性基础(例如征得个人信息主体同意,或者为履行合同所必需等)的前提下进行处理,且仅会在规定或者约定的范围内进行处理。用户拒绝处理基本功能所需必要信息以外的个人信息,不会影响用户使用基本功能。
计算机与互联网技术的发展,都离不开背后的API支持。因此,API的应用范围十分广泛。由此也导致出现了大量针对API的攻击手段,造成各类严重的安全事件,例如各类API攻击导致的数据泄露等。
本公开的实施例提出了一种请求处理的方案。根据该方案,可以接收针对目标接口的访问请求;从访问请求中获取目标接口参数和第一加密内容;通过加密与目标接口相关联的预设参数和目标接口参数,生成第二加密内容;以及基于第一加密内容和第二加密内容的比较,处理针对目标接口的访问请求。
以此方式,本公开的实施例能够基于加密内容的比较来验证访问请求的合法性,从而提高目标接口的安全性,避免由于明文传递接口参数所导致的访问风险。
以下进一步结合附图来详细描述该方案的各种示例实现。
示例环境
图1示出了本公开的实施例能够在其中实现的示例环境100的示 意图。如图1所示,示例环境100可以包括电子设备110、服务器130。
在该示例环境100中,电子设备110可以运行有支持界面交互的应用120。应用120可以是用于界面交互的任何适当类型应用,其示例可以包括但不限于:浏览器应用、代码编辑类应用或者集成有集成开发环境(IDE)的应用之类的其他适当的应用。用户140可以经由电子设备110和/或其附接设备来与应用120进行交互。
在图1的环境100中,如果应用120处于活动状态,电子设备110可以通过应用120呈现用于支持界面交互的界面150。
在一些实施例中,电子设备110与服务器130通信,以实现对应用120的服务的供应。电子设备110可以是任意类型的移动终端、固定终端或便携式终端,包括移动手机、台式计算机、膝上型计算机、笔记本计算机、上网本计算机、平板计算机、媒体计算机、多媒体平板、个人通信系统(PCS)设备、个人导航设备、个人数字助理(PDA)、音频/视频播放器、数码相机/摄像机、定位设备、电视接收器、无线电广播接收器、电子书设备、游戏设备或者前述各项的任意组合,包括这些设备的配件和外设或者其任意组合。在一些实施例中,电子设备110也能够支持任意类型的针对用户的接口(诸如“可佩戴”电路等)。
服务器130可以是独立的物理服务器,也可以是多个物理服务器构成的服务器集群或者分布式系统,还可以是提供云服务、云数据库、云计算、云函数、云存储、网络服务、云通信、中间件服务、域名服务、安全服务、内容分发网络、以及大数据和人工智能平台等基础云计算服务的云服务器。服务器130例如可以包括计算系统/服务器,诸如大型机、边缘计算节点、云环境中的计算设备,等等。服务器130可以为电子设备110中支持内容呈现的应用120提供后台服务。
服务器130与电子设备110之间可以建立有通信连接。通信连接可以通过有线方式或无线方式建立。通信连接可以包括但不限于蓝牙连接、移动网络连接、通用串行总线连接、无线保真连接等,本公开的实施例在此方面不受限制。在本公开的实施例中,服务器130与电子设备110可以通过二者之间的通信连接实现信令交互。
应当理解,仅出于示例性的目的描述环境100中各个元素的结构和功能,而不暗示对于本公开的范围的任何限制。
示例过程
图2示出了根据本公开的一些实施例的示例请求处理过程200的流程图。过程200可以被实现在服务器130处。下面参考图1描述过程200。
如图2所示,在框210,服务器130接收针对目标接口的访问请求。
在一些实施例中,服务器130接收对目标接口的访问请求,并解析该访问请求内容,执行对应的操作。可以理解的是,服务器130接收的针对目标接口的访问请求可以是合法的访问请求,也可以是非法的访问请求。
在一些实施例中,该目标接口可以与获取目标服务相关联。例如,这样的目标接口可以是由模型、智能体、机器人程序(bot)所提供,以支持调用相应的处理能力。
在框220,服务器130从访问请求中获取目标接口参数和第一加密内容。
在一些实施例中,该访问请求中包括目标接口参数以及第一加密内容。在一些实施例中,目标接口参数可以以明文形式被包括在访问请求中。作为示例,服务器130可以基于访问请求的预设格式来提取目标接口参数和第一加密内容。
可以理解的是,目标接口参数可以是针对目标接口的访问请求中的一个或多个参数,本公开不旨在对目标接口参数的数量进行限制。
在框230,服务器130通过加密与目标接口相关联的预设参数和目标接口参数,生成第二加密内容。
在一些实施例中,该预设参数包括第一字符串,这样的第一字符串例如可以是预设字符串。作为示例,这样的预设字符串可以关联于目标接口,例如,不同的接口例如可以对应于不同的字符串。
在一些实施例中,参考图3A,服务器130可以对第一字符串和目标接口参数执行加密过程,来生成第二字符串,以作为第二加密内容。作为示例,服务器将第一字符串(例如,预设字符串)与目标接口参数通过加密算法(例如,消息摘要算法5(Message-Digest Algorithm 5,MD5)),生成加密字符串(例如,第二字符串),作为第二加密内容。
在框240,服务器130基于第一加密内容和第二加密内容的比较,处理针对目标接口的访问请求。
在一些实施例中,服务器130响应于第一加密内容与第二加密内容匹配,则说明目标接口未被盗用,该访问请求为合法的访问请求,并可以根据访问请求执行目标操作。如下文介绍的,合法的访问请求是中所包括的第一加密内容可以是通过加密目标接口参数和预设参数所生成的。
在一些实施例中,响应于第一加密内容与第二加密内容不匹配,服务器130可以拒绝访问请求。在第一加密内容和第二加密内容不匹配时,服务器130可以确定该访问请求为非法的访问请求。
在一些实施例中,该非法的访问请求是基于第一加密内容和被盗用的目标接口参数所构建。可以理解的是,由于目标接口参数以明文形式被包括在目标接口中,所以,其他用户可以盗用目标接口,修改目标接口参数以达到自己的需求。作为示例,用户将目标接口参数中的某一参数由“你好”修改为“今天天气怎么样”。此时,若其他用户基于该修改后的目标接口参数构建访问请求时,服务器130接收到的访问请求为非法请求。
图4示出了根据本公开的一些实施例的示例请求处理过程400的流程图。过程400可以被实现在电子设备110处。下面参考图1描述过程400。
在框410,电子设备110获取与目标接口相关联的预设参数。
在一些实施例中,这样的预设参数可以是一个预设字符串,该预设字符串与上述提到的服务器130执行加密任务的预设字符串相同。 作为示例,电子设备110可以从服务器130获取与目标接口对应的预设参数。
在框420,电子设备110通过加密预设参数和目标接口参数,生成第一加密内容。
在一些实施例中,参考图3B,电子设备110获取与目标接口相关联的预设参数(例如,预设字符串)以及目标接口参数。电子设备110通过加密该预设参数和目标接口参数,生成第一加密内容。
在一些实施例中,这样的加密操作例如可以基于加密算法来执行。作为示例,电子设备110基于MD5将预设字符串与目标接口参数进行加密,得到加密字符串(也称第一加密内容)。
在框430,电子设备110生成针对目标接口的访问请求,访问请求包括第一加密内容和目标接口参数。
在一些实施例中,这样的目标接口参数以明文形式被包括在访问请求中。
在一些实施例中,电子设备110可以基于第一加密内容和目标接口参数构建针对目标接口的访问请求,使得服务器130可以从访问请求中获取目标接口参数和第一加密内容。
进一步地,电子设备110例如可以向服务器130发送该访问请求,以访问目标接口所对应的服务。
以此方式,本公开的实施例能够基于加密内容的比较来验证访问请求的合法性,从而提高目标接口的安全性,避免由于明文传递接口参数所导致的访问风险。
示例装置和设备
本公开的实施例还提供了用于实现上述方法或过程的相应装置。图5A示出了根据本公开的某些实施例的用于请求处理的示例装置500A的示意性结构框图。装置500A可以被实现为或者被包括在服务器130中。装置500A中的各个模块/组件可以由硬件、软件、固件或者它们的任意组合来实现。
如图5A所示,装置500包括请求接收模块510,被配置为接收针对目标接口的访问请求;第一获取模块520,被配置为从访问请求中获取目标接口参数和第一加密内容;第一加密模块530,被配置为通过加密与目标接口相关联的预设参数和目标接口参数,生成第二加密内容;以及请求处理模块540,被配置为基于第一加密内容和第二加密内容的比较,处理针对目标接口的访问请求。
在一些实施例中,请求处理模块540,被具体配置为响应于第一加密内容与第二加密内容匹配,根据访问请求执行目标操作;或响应于第一加密内容与第二加密内容不匹配,拒绝访问请求。
在一些实施例中,目标接口参数以明文形式被包括在访问请求中。
在一些实施例中,预设参数包括第一字符串,并且第一加密模块530,被具体配置为获取与目标接口相关联的第一字符串;以及通过加密第一字符串和目标接口参数,生成第二字符串,以作为第二加密内容。
装置500A中所包括的模块可以利用各种方式来实现,包括软件、硬件、固件或其任意组合。在一些实施例中,一个或多个单元可以使用软件和/或固件来实现,例如存储在存储介质上的机器可执行指令。除了机器可执行指令之外或者作为替代,装置500A中的部分或者全部模块可以至少部分地由一个或多个硬件逻辑组件来实现。作为示例而非限制,可以使用的示范类型的硬件逻辑组件包括现场可编程门阵列(FPGA)、专用集成电路(ASIC)、专用标准品(ASSP)、片上系统(SOC)、复杂可编程逻辑器件(CPLD),等等。
图5B示出了根据本公开的某些实施例的示例请求处理装置500B的示意性结构框图。装置500B可以被实现为或者被包括在电子设备110中。装置500B中的各个模块/组件可以由硬件、软件、固件或者它们的任意组合来实现。
如图5B所示,装置500B包括第二获取模块550,被配置为获取与目标接口相关联的预设参数;第二加密模块560,被配置为通过加密预设参数和目标接口参数,生成第一加密内容;以及请求生成模块 570,被配置为生成针对目标接口的访问请求,访问请求包括第一加密内容和目标接口参数。
在一些实施例中,目标接口参数以明文形式被包括在访问请求中。
装置500B中所包括的模块可以利用各种方式来实现,包括软件、硬件、固件或其任意组合。在一些实施例中,一个或多个单元可以使用软件和/或固件来实现,例如存储在存储介质上的机器可执行指令。除了机器可执行指令之外或者作为替代,装置500B中的部分或者全部模块可以至少部分地由一个或多个硬件逻辑组件来实现。作为示例而非限制,可以使用的示范类型的硬件逻辑组件包括现场可编程门阵列(FPGA)、专用集成电路(ASIC)、专用标准品(ASSP)、片上系统(SOC)、复杂可编程逻辑器件(CPLD),等等。
图6示出了其中可以实施本公开的一个或多个实施例的电子设备600的框图。应当理解,图6所示出的电子设备600仅仅是示例性的,而不应当构成对本文所描述的实施例的功能和范围的任何限制。图6所示出的电子设备600可以用于实现图1的电子设备110。
如图6所示,电子设备600是通用电子设备的形式。电子设备600的组件可以包括但不限于一个或多个处理器或处理单元610、存储器620、存储设备630、一个或多个通信单元640、一个或多个输入设备650以及一个或多个输出设备660。处理单元610可以是实际或虚拟处理器并且能够根据存储器620中存储的程序来执行各种处理。在多处理器系统中,多个处理单元并行执行计算机可执行指令,以提高电子设备600的并行处理能力。
电子设备600通常包括多个计算机存储介质。这样的介质可以是电子设备600可访问的任何可以获取的介质,包括但不限于易失性和非易失性介质、可拆卸和不可拆卸介质。存储器620可以是易失性存储器(例如寄存器、高速缓存、随机访问存储器(RAM))、非易失性存储器(例如,只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、闪存)或它们的某种组合。存储设备630可以是可拆卸或不可拆卸的介质,并且可以包括机器可读介质,诸如闪存驱动、 磁盘或者任何其他介质,其可以能够用于存储信息和/或数据并且可以在电子设备600内被访问。
电子设备600可以进一步包括另外的可拆卸/不可拆卸、易失性/非易失性存储介质。尽管未在图6中示出,可以提供用于从可拆卸、非易失性磁盘(例如“软盘”)进行读取或写入的磁盘驱动和用于从可拆卸、非易失性光盘进行读取或写入的光盘驱动。在这些情况中,每个驱动可以由一个或多个数据介质接口被连接至总线(未示出)。存储器620可以包括计算机程序产品625,其具有一个或多个程序模块,这些程序模块被配置为执行本公开的各种实施例的各种方法或动作。
通信单元640实现通过通信介质与其他电子设备进行通信。附加地,电子设备600的组件的功能可以以单个计算集群或多个计算机器来实现,这些计算机器能够通过通信连接进行通信。因此,电子设备600可以使用与一个或多个其他服务器、网络个人计算机(PC)或者另一个网络节点的逻辑连接来在联网环境中进行操作。
输入设备650可以是一个或多个输入设备,例如鼠标、键盘、追踪球等。输出设备660可以是一个或多个输出设备,例如显示器、扬声器、打印机等。电子设备600还可以根据需要通过通信单元640与一个或多个外部设备(未示出)进行通信,外部设备诸如存储设备、显示设备等,与一个或多个使得用户与电子设备600交互的设备进行通信,或者与使得电子设备600与一个或多个其他电子设备通信的任何设备(例如,网卡、调制解调器等)进行通信。这样的通信可以经由输入/输出(I/O)接口(未示出)来执行。
根据本公开的示例性实现方式,提供了一种计算机可读存储介质,其上存储有计算机可执行指令,其中计算机可执行指令被处理器执行以实现上文描述的方法。根据本公开的示例性实现方式,还提供了一种计算机程序产品,计算机程序产品被有形地存储在非瞬态计算机可读介质上并且包括计算机可执行指令,而计算机可执行指令被处理器执行以实现上文描述的方法。
这里参照根据本公开实现的方法、装置、设备和计算机程序产品的流程图和/或框图描述了本公开的各个方面。应当理解,流程图和/或框图的每个方框以及流程图和/或框图中各方框的组合,都可以由计算机可读程序指令实现。
这些计算机可读程序指令可以提供给通用计算机、专用计算机或其他可编程数据处理装置的处理单元,从而生产出一种机器,使得这些指令在通过计算机或其他可编程数据处理装置的处理单元执行时,产生了实现流程图和/或框图中的一个或多个方框中规定的功能/动作的装置。也可以把这些计算机可读程序指令存储在计算机可读存储介质中,这些指令使得计算机、可编程数据处理装置和/或其他设备以特定方式工作,从而,存储有指令的计算机可读介质则包括一个制造品,其包括实现流程图和/或框图中的一个或多个方框中规定的功能/动作的各个方面的指令。
可以把计算机可读程序指令加载到计算机、其他可编程数据处理装置、或其他设备上,使得在计算机、其他可编程数据处理装置或其他设备上执行一系列操作步骤,以产生计算机实现的过程,从而使得在计算机、其他可编程数据处理装置、或其他设备上执行的指令实现流程图和/或框图中的一个或多个方框中规定的功能/动作。
附图中的流程图和框图显示了根据本公开的多个实现的系统、方法和计算机程序产品的可能实现的体系架构、功能和操作。在这点上,流程图或框图中的每个方框可以代表一个模块、程序段或指令的一部分,模块、程序段或指令的一部分包含一个或多个用于实现规定的逻辑功能的可执行指令。在有些作为替换的实现中,方框中所标注的功能也可以以不同于附图中所标注的顺序发生。例如,两个连续的方框实际上可以基本并行地执行,它们有时也可以按相反的顺序执行,这依所涉及的功能而定。也要注意的是,框图和/或流程图中的每个方框、以及框图和/或流程图中的方框的组合,可以用执行规定的功能或动作的专用的基于硬件的系统来实现,或者可以用专用硬件与计算机指令的组合来实现。
以上已经描述了本公开的各实现,上述说明是示例性的,并非穷尽性的,并且也不限于所公开的各实现。在不偏离所说明的各实现的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。本文中所用术语的选择,旨在最好地解释各实现的原理、实际应用或对市场中的技术的改进,或者使本技术领域的其他普通技术人员能理解本文公开的各个实现方式。

Claims (11)

  1. 一种请求处理方法,包括:
    接收针对目标接口的访问请求;
    从所述访问请求中获取目标接口参数和第一加密内容;
    通过加密与所述目标接口相关联的预设参数和所述目标接口参数,生成第二加密内容;以及
    基于所述第一加密内容和所述第二加密内容的比较,处理针对所述目标接口的所述访问请求。
  2. 根据权利要求1所述的方法,其中基于所述第一加密内容和所述第二加密内容的比较处理针对所述目标接口的所述访问请求,包括:
    响应于所述第一加密内容与所述第二加密内容匹配,根据所述访问请求执行目标操作;或
    响应于所述第一加密内容与所述第二加密内容不匹配,拒绝所述访问请求。
  3. 根据权利要求1所述的方法,其中所述目标接口参数以明文形式被包括在所述访问请求中。
  4. 根据权利要求1所述的方法,其中所述预设参数包括第一字符串,并且通过加密与所述目标接口相关联的预设参数和所述目标接口参数生成第二加密内容包括:
    获取与所述目标接口相关联的所述第一字符串;以及
    通过加密所述第一字符串和所述目标接口参数,生成第二字符串,以作为所述第二加密内容。
  5. 一种请求处理方法,包括:
    获取与目标接口相关联的预设参数;
    通过加密所述预设参数和目标接口参数,生成第一加密内容;以及
    生成针对所述目标接口的访问请求,所述访问请求包括所述第一 加密内容和所述目标接口参数。
  6. 根据权利要求5所述的方法,其中所述目标接口参数以明文形式被包括在所述访问请求中。
  7. 一种用于请求处理的装置,包括:
    请求接收模块,被配置为接收针对目标接口的访问请求;
    第一获取模块,被配置为从所述访问请求中获取目标接口参数和第一加密内容;
    第一加密模块,被配置为通过加密与所述目标接口相关联的预设参数和所述目标接口参数,生成第二加密内容;以及
    请求处理模块,被配置为基于所述第一加密内容和所述第二加密内容的比较,处理针对所述目标接口的所述访问请求。
  8. 一种用于请求处理的装置,包括:
    第二获取模块,被配置为获取与目标接口相关联的预设参数;
    第二加密模块,被配置为通过加密所述预设参数和目标接口参数,生成第一加密内容;以及
    请求生成模块,被配置为生成针对所述目标接口的访问请求,所述访问请求包括所述第一加密内容和所述目标接口参数。
  9. 一种电子设备,包括:
    至少一个处理单元;以及
    至少一个存储器,所述至少一个存储器被耦合到所述至少一个处理单元并且存储用于由所述至少一个处理单元执行的指令,所述指令在由所述至少一个处理单元执行时使所述电子设备执行根据权利要求1至4或5至6中任一项所述的方法。
  10. 一种计算机可读存储介质,其上存储有计算机程序,所述计算机程序可由处理器执行以实现根据权利要求1至4或5至6中任一项所述的方法。
  11. 一种计算机程序产品,包括计算机可执行指令,其中所述计算机可执行指令在被处理器执行时实现根据权利要求1至4或5至6中任一项所述的方法。
PCT/CN2024/098955 2024-06-13 2024-06-13 请求处理的方法、装置、设备和存储介质 Pending WO2025255769A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202480004287.7A CN121532745A (zh) 2024-06-13 2024-06-13 请求处理的方法、装置、设备和存储介质
PCT/CN2024/098955 WO2025255769A1 (zh) 2024-06-13 2024-06-13 请求处理的方法、装置、设备和存储介质

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2024/098955 WO2025255769A1 (zh) 2024-06-13 2024-06-13 请求处理的方法、装置、设备和存储介质

Publications (1)

Publication Number Publication Date
WO2025255769A1 true WO2025255769A1 (zh) 2025-12-18

Family

ID=98049908

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/098955 Pending WO2025255769A1 (zh) 2024-06-13 2024-06-13 请求处理的方法、装置、设备和存储介质

Country Status (2)

Country Link
CN (1) CN121532745A (zh)
WO (1) WO2025255769A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108881184A (zh) * 2018-05-30 2018-11-23 努比亚技术有限公司 访问请求处理方法、终端、服务器及计算机可读存储介质
CN109255246A (zh) * 2018-08-14 2019-01-22 平安普惠企业管理有限公司 接口参数加密方法、装置、计算机设备及存储介质
CN114389847A (zh) * 2021-12-15 2022-04-22 北京达佳互联信息技术有限公司 访问请求加密方法、装置、电子设备及存储介质
US20220272089A1 (en) * 2021-02-22 2022-08-25 Arris Enterprises Llc Device-independent authentication based on an authentication parameter and a policy

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108881184A (zh) * 2018-05-30 2018-11-23 努比亚技术有限公司 访问请求处理方法、终端、服务器及计算机可读存储介质
CN109255246A (zh) * 2018-08-14 2019-01-22 平安普惠企业管理有限公司 接口参数加密方法、装置、计算机设备及存储介质
US20220272089A1 (en) * 2021-02-22 2022-08-25 Arris Enterprises Llc Device-independent authentication based on an authentication parameter and a policy
CN114389847A (zh) * 2021-12-15 2022-04-22 北京达佳互联信息技术有限公司 访问请求加密方法、装置、电子设备及存储介质

Also Published As

Publication number Publication date
CN121532745A (zh) 2026-02-13

Similar Documents

Publication Publication Date Title
CN107689869B (zh) 用户口令管理的方法和服务器
US10911438B2 (en) Secure detection and management of compromised credentials using a salt and a set model
US11295014B2 (en) TPM-based secure multiparty computing system using a non-bypassable gateway
US12401630B2 (en) Zero-trust distributed data sharing
US9654479B2 (en) Private discovery of electronic devices
US11159309B2 (en) Obtaining quorum approval to perform an operation with a cryptographic item of a key management system
CN113346998A (zh) 密钥更新及文件共享方法、装置、设备、计算机存储介质
CN111783140A (zh) 请求响应方法及装置、电子设备及计算机可读存储介质
CN120979705A (zh) 增强大模型应用数据安全的方法、装置、设备和存储介质
US12355878B2 (en) Secret management in distributed systems through onboarding
US20250036813A1 (en) Managing threats to data storage in distributed environments
CN110020040A (zh) 查询数据的方法、装置和系统
US11645103B2 (en) Method and system for securing the movement of virtual machines between hosts
US12204767B2 (en) System and method for managing data storage to identify undesired data modification
US12328402B2 (en) Securing data transactions through a distributed ledger system
US20250045435A1 (en) Revocation of vouchers for onboarding data processing systems
WO2025255769A1 (zh) 请求处理的方法、装置、设备和存储介质
US12254109B2 (en) System and method for data access management using encryption based on data sensitivity levels
US12475217B2 (en) System and method for cryptographic security through process diversity
US12126731B2 (en) System and method for securing host devices
JP2022141962A (ja) データの照会と書き込み方法、装置、電子機器、読み取り可能な記憶媒体およびコンピュータプログラム
CN119622760B (zh) 用于数据处理的方法、装置、设备和存储介质
US20250038989A1 (en) Securing access of storage array services
CN114117388A (zh) 设备注册方法、设备注册装置、电子设备以及存储介质
US20260005837A1 (en) Secure authorization of the helm chart

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24942944

Country of ref document: EP

Kind code of ref document: A1