A method and system for browser data storage

By generating and managing 32-bit private keys in the browser, the problem of unavoidable data leakage in the existing technology is solved, and the security and privacy protection of user data in different environments is achieved, reducing the risk of data leakage.

CN119598494BActive Publication Date: 2025-06-24ZIXUN TECHNOLOGY (FUJIAN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411701429.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-06-24
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

The prior art cannot avoid internal personnel data leakage problems when protecting user data, and traditional data storage methods pose data leakage and privacy risks.

Method used

By generating a 32-bit private key in the browser, using a hash algorithm to calculate, and exporting the private key into a PDF file, which is saved by the user. According to the user's choice, the data is encrypted and stored, or uploaded to the server. When the user logs in, decrypts the private key or key to ensure the security of the data.

Benefits of technology

It realizes multi-level data security protection, ensures the security of user data in different environments, reduces the risk of data leakage, enhances users' trust in the system, and provides a secure, flexible and extremely high privacy protection data storage solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119598494B_ABST
    Figure CN119598494B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for browser data storage. The method includes: a user logs in to the browser, obtains user information, device information, and a random string, calculates through a hashing algorithm to obtain a 32-bit private key, and exports it as a PDF file, and the browser does not save or upload the private key; if the user chooses not to associate with the device of the client, the browser encrypts the data with the 32-bit private key and then stores it locally or uploads it to the server; if the user chooses to associate with the device of the client, the browser obtains the device information, calculates with the 32-bit private key through a hashing algorithm to obtain a 32-bit key, and then the browser encrypts the data and then stores it locally or uploads it to the server; two data storage modes of local and cloud synchronization are provided to ensure the security of user data in different environments, and the data can be associated with the device to make the data more secure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a method and system for browser data storage. Background Art

[0002] In the digital age, data security is the primary concern of users and enterprises. With the increasing demand for data storage and transmission, how to protect user data in local and cloud environments has become an important technical challenge. Traditional data storage methods have risks of data leakage and privacy, and during data transmission, network eavesdropping and malicious attacks may occur.

[0003] Common data protection solutions in the industry generally only ensure that malicious users cannot crack the data, but cannot avoid data leakage problems caused by internal personnel. Existing user data stored on disk is basically stored in the database in plain text or encrypted and stored in the cloud, which cannot avoid absolute data leakage. In particular, cases of internal personnel stealing data in companies also occur from time to time, greatly affecting the company's reputation and causing economic losses. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method and system for browser data storage, with two data storage modes of local and cloud synchronization, ensuring the security of user data in different environments, and enabling data to be associated with devices to make the data more secure.

[0005] In a first aspect, the present invention provides a method for browser data storage, including the following steps:

[0006] Step 1: The user logs in to the browser, obtains user information, device information, and a random string, calculates through a hash algorithm to obtain a 32-bit private key, and exports it as a PDF file. The browser does not save or upload the private key.

[0007] Step 2: If the user chooses not to associate the device of the client, the browser encrypts the data with the 32-bit private key, and then stores it locally or uploads it to the server.

[0008] If the user chooses to associate the device of the client, the browser obtains the device information, calculates with the 32-bit private key through a hash algorithm to obtain a 32-bit key, and then the browser encrypts the data and stores it locally or uploads it to the server.

[0009] Step 3: When the user logs in to the browser again, decrypt the data according to whether the device of the client is associated. If the device of the client is not associated, decrypt the data according to the 32-bit private key entered by the user and open the browser. If the device of the client is associated, the browser obtains the device information and the 32-bit private key entered by the user, then calculates a 32-bit key through a hashing algorithm, and decrypts the data with the 32-bit key to open the browser.

[0010] In a second aspect, the present invention provides a browser data storage system, including:

[0011] A key generation module. When the user logs in to the browser, it obtains user information, device information, and a random string, calculates through a hashing algorithm to obtain a 32-bit private key, and exports it as a PDF file. The browser does not save or upload the private key.

[0012] An encrypted storage module. If the user chooses not to associate the device of the client, the browser encrypts the data with the 32-bit private key and then stores it locally or uploads it to the server.

[0013] If the user chooses to associate the device of the client, the browser obtains the device information, calculates with the 32-bit private key through a hashing algorithm to obtain a 32-bit key, then the browser encrypts the data and stores it locally or uploads it to the server.

[0014] A decryption module. When the user logs in to the browser again, decrypt the data according to whether the device of the client is associated. If the device of the client is not associated, decrypt the data according to the 32-bit private key entered by the user and open the browser. If the device of the client is associated, the browser obtains the device information and the 32-bit private key entered by the user, then calculates a 32-bit key through a hashing algorithm, and decrypts the data with the 32-bit key to open the browser.

[0015] One or more technical solutions provided by the present invention have at least the following technical effects or advantages:

[0016] 1. Multi-level data security protection:

[0017] The present invention provides two data storage modes: local and cloud synchronization, ensuring the security of user data in different environments. In the local mode, the data is completely stored on the user's local device, avoiding the security risks brought by network transmission. In the cloud synchronization mode, the data is encrypted before being transmitted to the cloud, ensuring that even if it is intercepted during transmission, the data cannot be interpreted.

[0018] 2. Uniqueness and security of the user's private key:

[0019] The present invention generates a 32-bit user private key and exports it to the user. This private key is not uploaded to the server, nor is it stored in the browser, greatly reducing the risk of the private key being stolen. The uniqueness of the user private key ensures that the data encryption of each user is independent. Even if the private key of a certain user is leaked, it will not affect the data security of other users.

[0020] 3. Extreme privacy protection:

[0021] The private key is only saved by the user himself / herself. This method ensures the absolute privacy of the user data. Users can safely store their data on the server without worrying about the data being accessed by the official or a third party.

[0022] 4. Flexible storage mode selection:

[0023] Users can choose the local mode or the cloud synchronization mode according to their own needs. For users with extremely high requirements for data privacy, they can choose the local mode to ensure that the data does not leave the local device.

[0024] 5. Reducing the risk of data leakage:

[0025] The design of the system takes into account the data leakage problem in the worst case. Even if a malicious user obtains the encrypted data, due to the lack of the private key, the data still cannot be decrypted. This design greatly reduces the risk of data leakage and enhances users' trust in the system.

[0026] 6. User autonomy and sense of responsibility:

[0027] The present invention hands over the management right of the private key to the user, enhancing the user's autonomy in data security.

[0028] Through this data encryption storage system, a secure, flexible and highly privacy-protected data storage solution is provided for users, meeting the high standards of modern users for data security.

[0029] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the following specifically gives the specific embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The following further describes the present invention with reference to the accompanying drawings in conjunction with the embodiments.

[0031] Figure 1 is the flowchart of the method in Embodiment 1 of the present invention;

[0032] Figure 2 is the structural schematic diagram of the system in Embodiment 2 of the present invention. Detailed implementation manners

[0033] By providing a method and system for browser data storage, the embodiments of the present application greatly improve the security of browser data.

[0034] The overall idea of the technical solutions in the embodiments of the present application is as follows:

[0035] The data storage modes include: local storage mode and cloud synchronization mode;

[0036] Local storage mode: In the local storage mode, all user data is stored on the local computer. The local data is protected by encryption technology to prevent the data from being stolen during transmission.

[0037] Cloud synchronization mode: In the cloud synchronization mode, the user data is encrypted and then transmitted to the server.

[0038] User private key generation: On the client side, a 32-bit user private key is generated and exported to the user. The private key is only stored by the user himself / herself.

[0039] Data encryption: The AES-256 encryption is used for all user privacy data by using the user private key + device information. The encryption process is completed locally on the client side to ensure that the data is encrypted before being transmitted to the cloud. Among them: Whether to combine the device information is optional. If the device information is combined for encryption, it is necessary to prevent the data from being unable to be retrieved due to device damage.

[0040] Data decryption: The data can only be decrypted after the user inputs the private key to ensure the privacy and security of the data. If the user chooses to associate the device information, the data can only be decrypted after the user inputs the private key within the client on the same device. If the device is replaced or the private key is incorrect, the data cannot be decrypted.

[0041] When uploading user data to the server: The server includes a business server and an encryption / decryption server; the browser uploads user data, and the browser requires the user to log in with an account and password. The business server stores the account and the corresponding user ID; the business server receives the user data; the business server queries and obtains the corresponding first user ID according to the client, and the business server sends the user data and the first user ID to the encryption / decryption server; the encryption / decryption server generates a first cloud key through the hash algorithm according to the first user ID, encrypts the user data through the AES encryption algorithm with the first cloud key to obtain first encrypted data, and then sends the encrypted data to the business server; the encryption / decryption server deletes the first cloud key and the first user ID; the business server stores the first encrypted data; the browser requests data from the business server, the business server obtains the second encrypted data corresponding to the browser, and sends the second encrypted data and the second user ID corresponding to the browser to the encryption / decryption server; the encryption / decryption server generates a second cloud key through the second user ID, decrypts the second encrypted data with the second cloud key to obtain decrypted data, and sends the decrypted data to the business server, and the business server forwards the decrypted data to the browser.

[0042] Embodiment 1

[0043] As Figure 1 shown, this embodiment provides a method for storing browser data, including the following steps:

[0044] Step 1: The user logs in to the browser, obtains user information, device information, and a random string, calculates through the hash algorithm to obtain a 32-bit private key, and exports it as a PDF file. The browser does not save or upload the private key.

[0045] Step 2: If the user chooses not to associate with the device of the client, the browser encrypts the data with the 32-bit private key, and then stores it locally or uploads it to the server.

[0046] If the user chooses to associate with the device of the client, the browser obtains the device information, calculates with the 32-bit private key through the hash algorithm to obtain a 32-bit key, and then the browser encrypts the data and stores it locally or uploads it to the server.

[0047] Step 3: When the user logs in to the browser again, decrypt the data according to whether the device of the client is associated. If the device of the client is not associated, decrypt the data using the 32-bit private key entered by the user and open the browser. If the device of the client is associated, the browser obtains the device information and the 32-bit private key entered by the user, then calculates a 32-bit key through a hashing algorithm, decrypts the data using the 32-bit key, and opens the browser. When the user data is stored on the server, the browser needs to obtain it from the server and then decrypt it using the private key or the key.

[0048] In this embodiment, preferably, step 1 is specifically as follows: The user logs in to the browser, obtains the user information, device information, and a random string, calculates through the sha1 algorithm to obtain a 32-bit private key, and exports it as a PDF file for the user to store. The browser does not save or upload the private key. The user information is the user ID. The device information includes the ID of the CPU, the hard disk ID, the motherboard ID, and the system unique identifier, and calculates through the sha1 algorithm to obtain a 32-bit string. The random string is a 32-bit string generated by a random algorithm.

[0049] In this embodiment, preferably, step 2 is specifically as follows: If the user chooses not to associate the device of the client, the browser encrypts the data using the 32-bit private key with the AES-256 encryption algorithm and then stores it locally or uploads it to the server.

[0050] If the user chooses to associate the device of the client, the browser obtains the device information, calculates with the 32-bit private key through the hashing algorithm to obtain a 32-bit key, and then the browser encrypts the data using the AES-256 encryption algorithm and then stores it locally or uploads it to the server.

[0051] In this embodiment, preferably, step 3 is specifically as follows: When the user logs in to the browser again, decrypt the data according to whether the device of the client is associated. If the device of the client is not associated, decrypt the data using the 32-bit private key entered by the user with the AES-256 encryption algorithm. If the decryption is successful, open the browser. If the decryption fails, do not open the browser. If the device of the client is associated, the browser obtains the device information and the 32-bit private key entered by the user, then calculates a 32-bit key through the hashing algorithm, decrypts the data using the 32-bit key with the AES-256 encryption algorithm. If the decryption is successful, open the browser. If the decryption fails, do not open the browser.

[0052] In this embodiment, preferably, the uploading to the server specifically includes: a service server, a storage server, and an encryption and decryption server; the browser uploads user data, and the service server receives the user data; the service server queries and obtains the corresponding first user ID according to the browser, and the service server sends the user data and the first user ID to the encryption and decryption server; the encryption and decryption server obtains the first cloud secret key from the storage server according to the first user ID. If it does not exist, the encryption and decryption server generates a random string of a set length through a random algorithm, generates a first cloud key through a hash algorithm according to the first user ID and the random string, encrypts the user data through the AES encryption algorithm with the first cloud key to obtain first encrypted data, encrypts the user data with the first cloud secret key by the encryption and decryption server to obtain encrypted data, and then sends the encrypted data to the service server; if it exists, the encryption and decryption server encrypts the user data with the first cloud secret key to obtain encrypted data, and then sends the encrypted data to the service server; the encryption and decryption server sends the first cloud key and the first user ID to the storage server for storage; the service server stores the first encrypted data; the browser requests data from the service server, the service server obtains the corresponding second encrypted data of the browser, and sends the second encrypted data and the corresponding second user ID of the browser to the encryption and decryption server; the encryption and decryption server obtains the second cloud key from the storage server according to the second user ID, decrypts the second encrypted data with the second cloud key to obtain decrypted data, and sends the decrypted data to the service server, and the service server forwards the decrypted data to the browser.

[0053] Based on the same inventive concept, the present application also provides a system corresponding to the method in Embodiment 1, as detailed in Embodiment 2.

[0054] Embodiment 2

[0055] As Figure 2 shown, in this embodiment, a system for storing browser data is provided, including:

[0056] A secret key obtaining module, when the user logs in to the browser, obtains user information, device information, and a random string, calculates through a hash algorithm to obtain a 32-bit private key, and exports it as a PDF file, and the browser does not save or upload the private key;

[0057] An encrypted storage module, if the user chooses not to associate with the device of the client, the browser encrypts the data with the 32-bit private key, and then stores it locally or uploads it to the server;

[0058] If the user selects the device associated with the client, the browser obtains the device information and calculates it with the 32-bit private key through a hashing algorithm to obtain a 32-bit key. Then the browser encrypts the data and stores it locally or uploads it to the server.

[0059] Decryption module. When the user logs in to the browser again, it decrypts according to whether there is a device associated with the client. If there is no device associated with the client, it decrypts the data with the 32-bit private key entered by the user and opens the browser. If there is a device associated with the client, the browser obtains the device information and the 32-bit private key entered by the user, then calculates a 32-bit key through a hashing algorithm and decrypts the data with the 32-bit key to open the browser.

[0060] In this embodiment, preferably, the key generation module is specifically as follows: When the user logs in to the browser, it obtains the user information, device information, and a random string, calculates through the sha1 algorithm to obtain a 32-bit private key, and exports it as a PDF file for the user to store. The browser does not save or upload the private key. The user information is the user ID. The device information includes the ID of the CPU, the hard disk ID, the motherboard ID, and the system unique identifier, and calculates a 32-bit string through the sha1 algorithm. The random string is a 32-bit string generated by a random algorithm.

[0061] In this embodiment, preferably, the encryption and storage module is specifically as follows: If the user selects not to associate the device with the client, the browser encrypts the data with the 32-bit private key using the AES-256 encryption algorithm and then stores it locally or uploads it to the server.

[0062] If the user selects the device associated with the client, the browser obtains the device information and calculates it with the 32-bit private key through a hashing algorithm to obtain a 32-bit key. Then the browser encrypts the data using the AES-256 encryption algorithm and stores it locally or uploads it to the server.

[0063] In this embodiment, preferably, the decryption module is specifically as follows: When the user logs in to the browser again, it decrypts according to whether there is a device associated with the client. If there is no device associated with the client, it decrypts the data with the 32-bit private key entered by the user using the AES-256 encryption algorithm. If the decryption is successful, it opens the browser. If the decryption fails, it does not open the browser. If there is a device associated with the client, the browser obtains the device information and the 32-bit private key entered by the user, then calculates a 32-bit key through a hashing algorithm and decrypts the data with the 32-bit key using the AES-256 encryption algorithm. If the decryption is successful, it opens the browser. If the decryption fails, it does not open the browser.

[0064] In this embodiment, preferably, the uploading to the server specifically includes: a service server, a storage server, and an encryption / decryption server; the browser uploads user data, and the service server receives the user data; the service server queries and obtains the corresponding first user ID according to the browser, and the service server sends the user data and the first user ID to the encryption / decryption server; the encryption / decryption server obtains the first cloud secret key from the storage server according to the first user ID. If it does not exist, the encryption / decryption server generates a random string of a set length through a random algorithm, generates a first cloud key through a hash algorithm according to the first user ID and the random string, encrypts the user data through the AES encryption algorithm with the first cloud key to obtain first encrypted data, encrypts the user data with the first cloud secret key by the encryption / decryption server to obtain encrypted data, and then sends the encrypted data to the service server; if it exists, the encryption / decryption server encrypts the user data with the first cloud secret key to obtain encrypted data, and then sends the encrypted data to the service server; the encryption / decryption server sends the first cloud key and the first user ID to the storage server for storage; the service server stores the first encrypted data; the browser requests data from the service server, the service server obtains the corresponding second encrypted data of the browser, and sends the second encrypted data and the corresponding second user ID of the browser to the encryption / decryption server; the encryption / decryption server obtains the second cloud key from the storage server according to the second user ID, decrypts the second encrypted data with the second cloud key to obtain decrypted data, sends the decrypted data to the service server, and the service server forwards the decrypted data to the browser.

[0065] Since the system introduced in the second embodiment of the present invention is the system adopted for implementing the method in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the system, so it will not be elaborated here. Any system adopted by the method in the first embodiment of the present invention falls within the scope of protection of the present invention.

[0066] The technical solutions provided in the embodiments of the present application at least have the following technical effects or advantages:

[0067] This embodiment provides ways of local data storage and cloud data storage to ensure the security of browser data; and if the user encrypts data by associating with hardware information, the data can only be decrypted and used on this hardware, and cannot be decrypted on other hardware, which greatly ensures the security of the data.

[0068] Although the specific embodiments of the present invention have been described above, those skilled in the art should understand that the specific embodiments we described are illustrative rather than used to limit the scope of the present invention. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present invention should be covered by the scope protected by the claims of the present invention.

Claims

1. A method for storing browser data, characterized in that: The steps include: Step 1: The user logs in to the browser, obtains user information, device information and a random string, calculates through a hash algorithm, obtains a 32-bit private key, and exports it as a PDF file. The browser does not save or upload the private key; Step 2: If the user chooses not to associate the client device, the browser encrypts the data using a 32-bit private key and then stores it locally or uploads it to the server. If the user chooses to associate a client device, the browser obtains the device information and calculates it with the 32-bit private key through a hash algorithm to obtain a 32-bit key. The browser then encrypts the data and stores it locally or uploads it to the server. The upload to the server specifically includes a business server, a storage server, and an encryption and decryption server. The browser uploads user data, and the business server receives the user data. The business server queries and obtains the corresponding first user ID according to the browser, and sends the user data and the first user ID to the encryption and decryption server; the encryption and decryption server obtains the first cloud key from the storage server according to the first user ID. If it does not exist, the encryption and decryption server generates a random string of a set length through a random algorithm, generates a first cloud key through a hash algorithm according to the first user ID and the random string, encrypts the user data through the AES encryption algorithm through the first cloud key to obtain first encrypted data, and the encryption and decryption server encrypts the user data through the first cloud key to obtain encrypted data, and then sends the encrypted data to the business server; if it exists, the encryption and decryption server encrypts the user data through the first cloud key to obtain encrypted data, and then sends the encrypted data to the business server; Step 3. When the user logs in to the browser again, decryption is performed based on whether the device is associated with the client. If there is no device associated with the client, the data is decrypted based on the 32-bit private key entered by the user and the browser is opened. If there is a device associated with the client, the browser obtains the device information and the 32-bit private key entered by the user, and then calculates the 32-bit key through the hash algorithm, decrypts the data using the 32-bit key, and opens the browser.

2. A method for storing browser data according to claim 1, characterized in that: The step 1 is specifically as follows: the user logs in to the browser, obtains user information, device information and a random string, calculates through the sha1 algorithm, obtains a 32-bit private key, and exports it as a PDF file. The PDF file is used for user storage. The browser does not save or upload the private key. The user information is the user ID. The device information includes: CPU ID, hard disk ID, motherboard ID and system unique identifier, which are calculated through the sha1 algorithm to obtain a 32-bit string; the random string is a 32-bit string generated by a random algorithm.

3. A method for storing browser data according to claim 1, characterized in that: The step 2 is specifically as follows: if the user chooses not to associate the client device, the browser encrypts the data using the AES-256 encryption algorithm with a 32-bit private key, and then stores it locally or uploads it to the server; If the user chooses to associate the client's device, the browser obtains the device information and calculates it with the 32-bit private key through a hash algorithm to obtain a 32-bit key. The browser then uses the AES-256 encryption algorithm to encrypt the data, and then stores it locally or uploads it to the server.

4. A method for storing browser data according to claim 1, characterized in that: The step 3 is specifically as follows: when the user logs in to the browser again, decryption is performed based on whether the device of the client is associated. If there is no device associated with the client, the data is decrypted using the AES-256 encryption algorithm based on the 32-bit private key input by the user. If the decryption is successful, the browser is opened; if the decryption fails, the browser is not opened; if there is a device associated with the client, the browser obtains the device information and the 32-bit private key input by the user, and then calculates the 32-bit key through the hash algorithm, and decrypts the data using the AES-256 encryption algorithm using the 32-bit key. If the decryption is successful, the browser is opened; if the decryption fails, the browser is not opened.

5. A method for storing browser data according to claim 1, characterized in that: The uploading to the server also includes: the encryption and decryption server sends the first cloud key and the first user ID to the storage server for storage; the business server stores the first encrypted data; the browser requests data from the business server, the business server obtains the second encrypted data corresponding to the browser, and sends the second encrypted data and the second user ID corresponding to the browser to the encryption and decryption server; the encryption and decryption server obtains the second cloud key from the storage server according to the second user ID, decrypts the second encrypted data by using the second cloud key to obtain decrypted data, sends the decrypted data to the business server, and the business server forwards the decrypted data to the browser.

6. A system for storing browser data, characterized in that: include: Get the secret key module. The user logs in to the browser, obtains user information, device information and a random string, calculates through a hash algorithm, obtains a 32-bit private key, and exports it as a PDF file. The browser does not save or upload the private key. Encrypted storage module: if the user chooses not to associate the client device, the browser will encrypt the data using a 32-bit private key and then store it locally or upload it to the server. If the user chooses to associate a client device, the browser obtains the device information and calculates it with the 32-bit private key through a hash algorithm to obtain a 32-bit key. The browser then encrypts the data and stores it locally or uploads it to the server. The upload to the server specifically includes a business server, a storage server, and an encryption and decryption server. The browser uploads user data, and the business server receives the user data. The business server queries and obtains the corresponding first user ID according to the browser, and sends the user data and the first user ID to the encryption and decryption server; the encryption and decryption server obtains the first cloud key from the storage server according to the first user ID. If it does not exist, the encryption and decryption server generates a random string of a set length through a random algorithm, generates a first cloud key through a hash algorithm according to the first user ID and the random string, encrypts the user data through the AES encryption algorithm through the first cloud key to obtain first encrypted data, and the encryption and decryption server encrypts the user data through the first cloud key to obtain encrypted data, and then sends the encrypted data to the business server; if it exists, the encryption and decryption server encrypts the user data through the first cloud key to obtain encrypted data, and then sends the encrypted data to the business server; Decryption module: when the user logs in to the browser again, decryption is performed based on whether the device is associated with the client. If there is no device associated with the client, the data is decrypted based on the 32-bit private key entered by the user and the browser is opened. If there is a device associated with the client, the browser obtains the device information and the 32-bit private key entered by the user, and then calculates the 32-bit key through the hash algorithm, decrypts the data through the 32-bit key, and opens the browser.

7. A browser data storage system according to claim 6, characterized in that: The secret key obtaining module is specifically as follows: the user logs in to the browser, obtains user information, device information and a random string, calculates through the sha1 algorithm, obtains a 32-bit private key, and exports it as a PDF file. The PDF file is used for user storage. The browser does not save or upload the private key. The user information is the user ID, and the device information includes: CPU ID, hard disk ID, motherboard ID and system unique identifier, which are calculated through the sha1 algorithm to obtain a 32-bit string; the random string is a 32-bit string generated by a random algorithm.

8. A browser data storage system according to claim 6, characterized in that: The encryption storage module is specifically as follows: if the user chooses not to associate the client device, the browser uses the AES-256 encryption algorithm with a 32-bit private key to encrypt the data, and then stores it locally or uploads it to the server; If the user chooses to associate the client's device, the browser obtains the device information and calculates it with the 32-bit private key through a hash algorithm to obtain a 32-bit key. The browser then uses the AES-256 encryption algorithm to encrypt the data, and then stores it locally or uploads it to the server.

9. A browser data storage system according to claim 6, characterized in that: The decryption module is specifically as follows: when the user logs in to the browser again, decryption is performed based on whether the client device is associated. If there is no device associated with the client, the data is decrypted using the AES-256 encryption algorithm based on the 32-bit private key input by the user. If the decryption is successful, the browser is opened; if the decryption fails, the browser is not opened; if there is a device associated with the client, the browser obtains the device information and the 32-bit private key input by the user, and then calculates the 32-bit key through the hash algorithm, and decrypts the data using the AES-256 encryption algorithm through the 32-bit key. If the decryption is successful, the browser is opened; if the decryption fails, the browser is not opened.

10. A browser data storage system according to claim 6, characterized in that: The uploading to the server also includes: the encryption and decryption server sends the first cloud key and the first user ID to the storage server for storage; the business server stores the first encrypted data; the browser requests data from the business server, the business server obtains the second encrypted data corresponding to the browser, and sends the second encrypted data and the second user ID corresponding to the browser to the encryption and decryption server; the encryption and decryption server obtains the second cloud key from the storage server according to the second user ID, decrypts the second encrypted data by using the second cloud key to obtain decrypted data, sends the decrypted data to the business server, and the business server forwards the decrypted data to the browser.

Citation Information

Patent Citations

  • Data interaction management method and device, terminal equipment and storage medium

    CN116996287A

  • Data storage method and device based on browser BS architecture

    CN118445020A