Function encryption method and system applied to browser and medium
By using AES algorithm and Web Credential Management API in the browser for functional encryption, the problem of the existing technology being unable to realize real-time dynamic configuration and security protection of browser functions is solved, and high security and flexible key management are achieved.
Patent Information
- Application Number
- CN202510238916.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-16
AI Technical Summary
The existing functional encryption methods cannot achieve real-time dynamic configuration and security protection of browser functions, and are insufficient security.
Dynamic encryption and authentication of browser functions are achieved by encrypting passwords using the AES algorithm in the browser, and using the Web Credential Management API and key services for key management and authentication.
Dynamic key management and high security encryption of browser functions are realized, ensuring password security and reasonable access control of functions.
Smart Images

Figure CN120017267A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of Web application programs, and in particular to a method, system and medium for encrypting functions applied to a browser. Background Art
[0002] With the widespread use of Web applications, in applications with complex business levels, it is easy to encounter scenarios where passwords need to be entered for identity authentication or function authorization. When using services, passwords are entered to obtain operation permissions to achieve security management.
[0003] Traditional function management methods include: management using user permissions, management using system certificates, etc. However, there are also inconveniences: dynamic configuration cannot be performed, verification effect before function use cannot be achieved, and certificates have high requirements for service system configuration.
[0004] Patent application CN119449499A discloses a secure two-way authentication method and system. In this method, a request to control an Android terminal is sent to an SRS server through the MOTT protocol on the web front end. When the request is received for the first time, the Android terminal generates a key pair and encrypts the public key and sends it to the SRS server. After receiving the request again and the user agrees, the SP security chip of the Android terminal generates a 32-bit random number as a control token and sends it to the SRS server. The server saves this random number and waits for the operation code. The Web front end uses WebRTC to obtain the screen recording information of the Android terminal, and generates an operation code based on the operation and sends it to the SRS server. After the server receives the operation code, it combines the previously saved random number, encrypts it with the RSA public key, and then sends it to the Android terminal together with the operation code. The Android terminal uses the private key to decrypt the data, and executes the operation code after verifying that the random number matches. The entire process ensures the secure handover of control rights and the security of operations, and effectively improves the security protection capabilities during the communication process. However, this method is applied to the remote control solution, and it is impossible to achieve real-time configuration and security protection of browser functions.
[0005] Patent application CN119442288A discloses a Java bytecode encryption method based on a secure password module, which includes: a key management module pre-stores a one-to-one correspondence between an encrypted service operating environment, a key, and a key identifier; a code encryption module receives a source code package of the current encrypted service operating environment, determines a key identifier, and sends the source code package and the key identifier to the key management module; the key management module retrieves the corresponding key to encrypt the source code package, and returns the encrypted code package to the code encryption module; the code encryption module deploys the encrypted code package to the corresponding terminal; when the terminal encrypted code package needs to be started, the code decryption module sends the encrypted code package to the key management module after passing the trusted authentication; the key management module uses the internal key to decrypt the encrypted code package, and returns the decryption result to the code decryption module. The present invention can improve the security of the code encryption and decryption process. The present invention realizes the function of code tamper-proofing by means of encryption and decryption and key management, and the encryption and decryption and key management cannot be directly applied to the dynamic configuration and security protection of browser functions.
[0006] Patent application CN119383013A discloses a method, device, equipment and storage medium for authenticating a login system, the method comprising: in response to a login password acquisition request, obtaining a current login password, encrypting the current login password to obtain encrypted information; receiving a login password to be authenticated, authenticating the login password to be authenticated based on the current login password, and determining whether to allow the user to log in to the target system according to the authentication result; wherein the login password to be authenticated is obtained by the security server parsing the encrypted information and feeding back after the user forwards the encrypted information to the security server. The embodiment of the present application generates and encrypts a login password locally on a smart device or system, so that the user forwards the encrypted information to the security server for decryption and obtains the login password, thereby improving the convenience of the user logging in to the smart device or system when forgetting the login password under the premise of ensuring security. The present invention is applied to the field of login authentication, but the password encryption of the present invention is implemented on a security server and cannot be dynamically configured in a browser.
[0007] Therefore, a method is needed to verify the functional scenarios of browser applications, which requires dynamic verification while maintaining high security.
[0008] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present application, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0009] In order to provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. The summary is not an extensive review, nor is it intended to identify key / critical components or delineate the scope of protection of these embodiments, but rather serves as a prelude to the detailed description that follows.
[0010] The embodiments of the present disclosure provide a function encryption method, system and medium applied to a browser to solve the technical problems that the existing function encryption method cannot be dynamically configured and has poor security.
[0011] In some embodiments, the method includes: step A, registering a password for the function to be encrypted, and then storing the password in a local password manager;
[0012] Step B: Generate and store the AES algorithm for encryption and decryption, and return the AES algorithm to the browser. When the browser needs to use the key, it uses the AES algorithm to encrypt the password to generate the key;
[0013] Step C: When the user accesses a certain function, the browser retrieves the corresponding function password information from the local password manager and uses the AES algorithm to encrypt the function password information to generate a key;
[0014] Step D: The key is transmitted to the key service for authentication. If the authentication is successful, the user is allowed to perform subsequent functions.
[0015] Furthermore, in step A, the browser uses the navigator.credentials.store(object) method of the Web Credential Management API to store the password in the local password manager, where the object value is a JSON object containing the function name, the password corresponding to the function, the user ID, and the AES algorithm used.
[0016] Furthermore, in step A, after the user enters the password of the function to be encrypted in the browser, the browser sends the password to the key service, and the key service queries the information from the database. If the current user group information is queried, it means that the password has been registered for the current function, and the agreed AES algorithm is returned to the browser for the browser to generate the key; if the current user group information is not queried, it means that the user is using the current function for the first time, and the key service stores the current user group information in the database and selects the appropriate AES algorithm and returns it to the browser.
[0017] Furthermore, in step B, when the password is encrypted using the AES algorithm to generate a key, the password, function name, and user ID are associated to generate an independent AES key for each function.
[0018] Furthermore, in step C, the browser automatically calls the navigator.credentials.get() method to obtain the function password information corresponding to the user access function from the local password manager; if the current function stores multiple sets of passwords, the corresponding password information is selected according to the user ID of the current web application.
[0019] Furthermore, in step C, the function password information is encrypted using the AES algorithm as follows: the browser associates the obtained function name, password, user ID, and timestamp to generate plaintext to be encrypted, calls the crypto.subtle.encrypt() method of the Web Crypto API, and uses the AES key to encrypt the plaintext to generate a key.
[0020] Furthermore, the browser transmits the key and plaintext information except the password to the key service for authentication. The authentication process is as follows: after the key service receives the key and plaintext information transmitted by the browser, it retrieves the corresponding password from the database. The key service calls the crypto.subtle.encrypt() method of the Web Crypto API and uses the AES algorithm to encrypt the password and plaintext information retrieved from the database to obtain the target key. The target key is compared with the key transmitted by the browser. If they are consistent, the authentication is passed and the user is allowed to perform subsequent functions; otherwise, access is denied.
[0021] Furthermore, after the user performs a certain function for the first time within a session cycle and passes the authentication, the authentication result is recorded. When the function is used again within the same session cycle, the mediation property is set to silent when executing navigator.credentials.get(). The user no longer registers a password and directly obtains the password from the browser's local password manager. If the user switches browsers or another user uses the browser to perform a function, the stored password information is not allowed to be queried in combination with the user ID, and the user is prompted to enter a custom name and password for password registration authentication.
[0022] In some embodiments, the system includes a browser module for managing user passwords and encrypting passwords using an AES algorithm when using a function, the browser module including a password registration module, a password management module, and an encryption module;
[0023] The password registration module is used for users to register passwords for the encrypted functions, and sends the passwords registered by users to the key service module for authentication; the key management module uses the Web Credential Management API for key management, including password storage, password acquisition and key generation. The encryption module is used to encrypt the authentication information using the AES algorithm when the user uses the function, generate the key and send it to the key service module for authentication;
[0024] The key service module is used to store passwords, generate AES algorithms, and decrypt and authenticate encrypted ciphertexts. The key service module includes a password storage module, an AES algorithm generation module, and an authentication module. The password storage module is used to save the password for the first use of the function in the database of the key service module. The AES algorithm generation module returns the AES algorithm to the browser. When the browser needs to use the key, it uses the AES algorithm to encrypt the password and generate a key. When the user accesses a certain function, the authentication module authenticates the key generated by the user input or selection of the function password. If the authentication passes, the function is allowed to execute.
[0025] In some embodiments, the storage medium stores program instructions, and when the program instructions are run, they execute the aforementioned function encryption method applied to the browser.
[0026] The function encryption method, system and medium applied to the browser provided by the embodiments of the present disclosure can achieve the following technical effects:
[0027] Ensure password security: Passwords are encrypted and transmitted using the AES encryption algorithm, avoiding security risks during password plain text storage and transmission;
[0028] Dynamic key management: supports dynamic key management for different functions of the page, enhancing the flexibility and security of the system;
[0029] Simplify user operations: Use the Web Credential Management API to automatically fill in passwords, reducing the number of steps required for users.
[0030] Function-level authentication: Encrypted passwords are authenticated through key services to ensure that only authorized users can perform specific functions.
[0031] The above general description and the following description are exemplary and explanatory only and are not intended to limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] One or more embodiments are exemplarily described by corresponding drawings, which do not limit the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements, and the drawings do not constitute a scale limitation, and wherein:
[0033] Figure 1 is a flow chart of the method described in Example 1;
[0034] Figure 2 It is a functional encryption flow chart;
[0035] Figure 3 It is a user operation flow chart;
[0036] Figure 4 is a schematic diagram of the system described in Example 2;
[0037] Figure 5 Schematic diagram of the device described in Example 3. DETAILED DESCRIPTION
[0038] In order to be able to understand the features and technical contents of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure is described in detail below in conjunction with the accompanying drawings. The attached drawings are for reference only and are not used to limit the embodiments of the present disclosure. In the following technical description, for the convenience of explanation, a full understanding of the disclosed embodiments is provided through multiple details. However, one or more embodiments can still be implemented without these details. In other cases, to simplify the drawings, well-known structures and devices can be simplified for display.
[0039] The terms "first", "second", etc. in the embodiments of the present disclosure are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged where appropriate, so as to describe the embodiments of the present disclosure described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions.
[0040] Unless otherwise stated, the term "plurality" means two or more.
[0041] In the embodiment of the present disclosure, the character " / " indicates that the preceding and following objects are in an "or" relationship. For example, A / B indicates: A or B.
[0042] The term "and / or" is a description of the association relationship between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B.
[0043] The term "correspondence" may refer to an association relationship or a binding relationship. The correspondence between A and B means that there is an association relationship or a binding relationship between A and B.
[0044] Example 1
[0045] This embodiment discloses a function encryption method applied to a browser, such as Figure 1 As shown, the method comprises the following steps:
[0046] Step A: The user registers the password of the function to be encrypted in the browser, and then stores the password in the local password manager.
[0047] For example, when a user uses a web application, he needs to set an independent verification password for a specific function (such as payment function, data export function, etc.). The specific implementation is: when the user executes a function that requires user authentication on the page, a pop-up form will pop up for the user to enter independent function authentication information, including a custom name and password.
[0048] In this embodiment, the browser uses the Web Credential Management API to store the password entered by the user in the local password manager. Specifically, the browser calls the navigator.credentials.store() method to store the function name (such as "payment function"), the corresponding password (such as "123456"), the user ID, and the algorithm used (such as "CBC\GCM, etc."). The storage format is: navigator.credentials.store(object), where the object value is a JSON object of the associated stored function name, the password corresponding to the function, the user ID, and the AES algorithm used.
[0049] Step B: The key service generates and stores the AES algorithm for encryption and decryption, and returns the AES algorithm to the browser. When the browser needs to use the key, it uses the AES algorithm to encrypt the password to generate the key. The key service can be an independent server or module responsible for generating and managing symmetric encryption keys.
[0050] In this embodiment, the process of the key service generating the AES algorithm is as follows:
[0051] The browser sends the password and other function authentication information filled in the password registration page to the key service. The key service queries the information from the database. If the current user group information is queried, it means that the current function has registered the password, and returns the agreed AES algorithm to the browser for the browser to generate the key. If the current user group information is not queried, it means that the user is using the current function for the first time. The authentication service will store the current user group information in the database and select the appropriate AES algorithm to return to the client. The selected AES algorithm is related to the encryption function supported by the browser, and the list of algorithms supported by the browser will be returned to the browser. The AES algorithm is an Advanced Encryption Standard algorithm, which is a common symmetric encryption algorithm that uses the same key for encryption and decryption. Commonly used AES algorithms include: AES-CBC, AES-GCM and other mode methods. In this embodiment, the corresponding AES algorithm is returned according to the encryption function supported by the browser. The key service can store passwords through a database (such as MySql, MongoDB) or a file system.
[0052] In this embodiment, when the browser uses the AES algorithm to encrypt the password to generate a key, the password, function name, and user ID are associated to generate an independent AES key for each function. For example, key A is generated for the "payment function" and key B is generated for the "data export function".
[0053] Step C: The browser manages the user group password and the AES algorithm through the Web Credential Management API; when the user accesses a certain function, the browser retrieves the corresponding function password information from the local password manager and uses the AES algorithm to encrypt the function password information to generate a key.
[0054] In this embodiment, the browser automatically calls the navigator.credentials.get() method to obtain the corresponding function password information from the local password manager. When the user uses a specific function, the browser retrieves the corresponding password from the local password manager. For example, when the user clicks the "payment function" button, the browser automatically obtains the password "123456" corresponding to the "payment function". If the current function stores multiple sets of passwords, the corresponding password information is selected according to the user ID of the current web application.
[0055] The browser uses the AES algorithm to encrypt the authentication information and generate encrypted ciphertext. Specifically, the browser associates the obtained function name, password, user ID, timestamp and other information to generate the plaintext to be encrypted, calls the crypto.subtle.encrypt() method of the WebCrypto API, and uses the AES key obtained from the key service to encrypt the plaintext.
[0056] The browser transmits the encrypted ciphertext and plaintext information except the password to the key service for authentication.
[0057] Step D: The key is transmitted to the key service for authentication. If the authentication is successful, the user is allowed to perform subsequent functions.
[0058] The browser transmits the key and plaintext information except the password to the key service for authentication. The authentication process is as follows: after the key service receives the key and plaintext information transmitted by the browser, it retrieves the corresponding password from the database. The key service calls the crypto.subtle.encrypt() method of the Web Crypto API and uses the AES algorithm to encrypt the password and plaintext information retrieved from the database to obtain the target key. The target key is compared with the key transmitted by the browser. If they are consistent, the authentication is successful and the user is allowed to perform subsequent functions; otherwise, access is denied. After the authentication is successful, the key service returns an authentication success signal to the browser, and the browser allows the user to perform the corresponding function; for example, the user can use the "payment function" to complete the payment operation.
[0059] After a user passes the authentication for the first time when executing a certain function within a session cycle, the authentication result is recorded. When the function is used again within the same session cycle, the mediation property is set to silent when executing navigator.credentials.get(). The user no longer registers a password and directly obtains the password from the browser's local password manager. If the user switches browsers or another user uses the browser to execute a function, the stored password information is not allowed to be queried in combination with the user ID. A pop-up window prompts the user to enter a custom name and password for password registration authentication and to authenticate again. After authentication, the operation is allowed.
[0060] The method described in this embodiment is completed by the cooperation of the client web page, browser, server (key service) and database. From the perspective of each participant, the implementation process of this method is as follows: Figure 2 As shown, the following steps are included:
[0061] 1. The user executes a function on the client web page to determine whether the current browser is used for the first time;
[0062] 2. If it is the first time to use, set the encryption password in the browser;
[0063] 3. The encrypted password is sent to the key service, which determines the password encryption algorithm and saves the password in the database;
[0064] 4. Save the password and encryption algorithm on the browser side, and the browser searches for the password previously set by the current user. If the current browser is not used for the first time, the browser directly searches for the password previously set by the current user;
[0065] 5. After the browser searches for the password previously set by the current user, it determines whether the browser has saved the password. If so, it generates a key based on the password and encryption algorithm for authentication. The authentication process is to compare the key generated by the password and algorithm stored in the database with the key returned by the client. If the comparison is consistent, the authentication is successful and the function is executed. If the authentication fails or the browser does not save the password, the user is prompted to enter the password and repeat steps 3 to 5.
[0066] This method uses the Web Credential Management API to automatically fill in passwords, reducing the number of steps required by the user. Figure 3 As shown, the user operation process when executing this method is:
[0067] 1. The user executes the function and determines whether it is the first time for the user to use the current function. If so, execute step 2; if not, execute step 3;
[0068] 2. The user enters the verification password for the current business scenario and performs function-user-password registration;
[0069] 3. Determine whether the current browser has stored the password and it is valid. If so, authenticate the password. If not, the user enters the verification password and then authenticates the password;
[0070] 4. After the password authentication is passed, the Service / Client / Minio functions are executed.
[0071] Example 2
[0072] This embodiment discloses a function encryption system applied to a browser, such as Figure 4 As shown, the system includes a browser module for managing user passwords and encrypting passwords using an AES algorithm when using functions. The browser module includes a password registration module, a password management module and an encryption module.
[0073] The password registration module is used for users to register passwords for functions to be encrypted, and sends the passwords registered by users to the key service module for authentication.
[0074] The key management module uses the Web Credential Management API for key management, including password storage, password acquisition, and key generation. Password storage is when the browser calls the navigator.credentials.store() method to associate and store the function name (such as "payment function"), the corresponding password (such as "123456"), the user ID, and the algorithm used (such as "CBC\GCM, etc."). The storage format is: navigator.credentials.store(object), where the object value is a JSON object of the associated stored function name, the password corresponding to the function, the user ID, and the AES algorithm used. Password acquisition is when the user accesses a certain function, the browser automatically calls the navigator.credentials.get() method to obtain the corresponding function password information from the local password manager. Key generation is when the browser needs to use the key, it uses the AES algorithm to encrypt the password to generate a key.
[0075] The encryption module is used to encrypt the authentication information using the AES algorithm when the user uses the function, generate a key and send it to the key service module for authentication. The browser associates the function name, password, user ID, timestamp and other information obtained to generate the plaintext to be encrypted, calls the crypto.subtle.encrypt() method of the Web Crypto API, and uses the AES key obtained from the key service to encrypt the plaintext to generate the key.
[0076] The key service module is used to store passwords, generate AES algorithms, and decrypt and authenticate encrypted ciphertexts. The key service module includes a password storage module, an AES algorithm generation module, and an authentication module. The password storage module is used to save the password for the first use of the function in the database of the key service module, and the AES algorithm generation module returns the AES algorithm to the browser. If the current function has a registered password, the agreed AES algorithm will be returned to the browser for key generation. If the user uses the current function for the first time, the authentication service will store the current user group information in the database and select the appropriate AES algorithm to return to the client. The selected AES algorithm is related to the encryption function supported by the browser, and the list of supported algorithms will be returned to the browser. When the browser needs to use the key, it uses the AES algorithm to encrypt the password to generate a key; when the user accesses a certain function, the authentication module authenticates the key generated by the user input or selection of the function password, and allows the function to be executed if the authentication passes. The authentication process is as follows: the browser uses the Web Crypto Api to call the system function to encrypt the user group's custom name, password, and user ID to generate a key. The encryption algorithm used is the algorithm that the Crypto system first supports in the stored algorithm list. The encrypted key A, user information, authentication time, etc. are sent to the authentication module of the key service. The authentication module takes out the stored password from the database and encrypts it to generate key B in combination with the user and time information returned by the browser; compare key A and key B. If the two keys are the same, this function verification passes.
[0077] The system described in this embodiment implements the functional encryption method described in Example 1 through a browser module and a key service module.
[0078] Example 3
[0079] Combination Figure 5 As shown, the embodiment of the present disclosure provides a function encryption device 300 applied to a browser, including a processor (processor) 304 and a memory (memory) 301. Optionally, the device may also include a communication interface (Communication Interface) 302 and a bus 303. Among them, the processor 304, the communication interface 302, and the memory 301 can communicate with each other through the bus 303. The communication interface 302 can be used for information transmission. The processor 304 can call the logic instructions in the memory 301 to execute the function encryption method applied to the browser of the above-mentioned embodiment 1.
[0080] In addition, the logic instructions in the memory 301 described above can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product.
[0081] The memory 301 is a computer-readable storage medium that can be used to store software programs and computer executable programs, such as program instructions / modules corresponding to the method in the embodiment of the present disclosure. The processor 304 executes the function application and data processing by running the program instructions / modules stored in the memory 301, that is, the function encryption method applied to the browser in the above embodiment is implemented.
[0082] The memory 301 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and an application required for at least one function; the data storage area may store data created according to the use of the terminal device, etc. In addition, the memory 301 may include a high-speed random access memory and may also include a non-volatile memory.
[0083] Example 4
[0084] The disclosed embodiment provides a product (e.g., a computer, a mobile phone, etc.) 100, including: a product body, and the above-mentioned functional encryption device 300 applied to a browser. The functional encryption device 300 applied to the browser is installed in the product body. The installation relationship described here is not limited to placement inside the product, but also includes installation connections with other components of the product, including but not limited to physical connections, electrical connections, or signal transmission connections. It can be understood by those skilled in the art that the functional encryption device 300 applied to the browser can be adapted to a feasible product body, thereby realizing other feasible embodiments.
[0085] Example 5
[0086] An embodiment of the present disclosure provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to execute the above-mentioned function encryption method applied to a browser.
[0087] The computer-readable storage medium mentioned above may be a transient computer-readable storage medium or a non-transitory computer-readable storage medium.
[0088] The technical solution of the embodiment of the present disclosure can be embodied in the form of a software product, which is stored in a storage medium and includes one or more instructions for enabling a computer device (which may be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in the embodiment of the present disclosure. The aforementioned storage medium may be a non-transient storage medium, including: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes, or a transient storage medium.
[0089] The above description and accompanying drawings fully illustrate the embodiments of the present disclosure so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The embodiments represent possible changes only. Unless explicitly required, separate components and functions are optional, and the order of operation may vary. The parts and features of some embodiments may be included in or replace the parts and features of other embodiments. Moreover, the words used in this application are only used to describe the embodiments and are not used to limit the scope of protection. As used in the description in the text, unless the context clearly indicates, the singular forms of "a", "an" and "the" are intended to include plural forms as well. Similarly, the term "and / or" as used in this application refers to any and all possible combinations of listings containing one or more associated ones. In addition, when used in the present application, the term "comprise" and its variants "comprises" and / or comprising refer to the presence of stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical elements in the process, method or device comprising the elements. In this article, each embodiment may focus on the differences from other embodiments, and the same and similar parts between the embodiments may refer to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, then the relevant parts can refer to the description of the method part.
[0090] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software may depend on the specific application and design constraints of the technical solution. The technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present disclosure. The technicians may clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.
[0091] In the embodiments disclosed herein, the disclosed methods and products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units can be only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to implement this embodiment. In addition, each functional unit in the embodiment of the present disclosure may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit.
Claims
1. A function encryption method applied to a browser, characterized in that: include: Step A: Register the password for the function to be encrypted, and then store the password in the local password manager; Step B: Generate and store the AES algorithm for encryption and decryption, and return the AES algorithm to the browser. When the browser needs to use the key, it uses the AES algorithm to encrypt the password to generate the key; Step C: When the user accesses a certain function, the browser retrieves the corresponding function password information from the local password manager and uses the AES algorithm to encrypt the function password information to generate a key; Step D: The key is transmitted to the key service for authentication. If the authentication is successful, the user is allowed to perform subsequent functions.
2. The function encryption method applied to a browser according to claim 1, characterized in that: In step A, the browser uses the navigator.credentials.store(object) method of the Web Credential Management API to store the password in the local password manager. The object value is a JSON object containing the function name, the password corresponding to the function, the user ID, and the AES algorithm used.
3. The function encryption method applied to a browser according to claim 1, characterized in that: In step A, after the user enters the password of the function to be encrypted in the browser, the browser sends the password to the key service. The key service queries the database for information. If the current user group information is found, it means that the password has been registered for the current function, and the agreed AES algorithm is returned to the browser for key generation. If the current user group information is not found, it means that the user is using the current function for the first time. The key service stores the current user group information in the database and selects the appropriate AES algorithm and returns it to the browser.
4. The function encryption method applied to a browser according to claim 1, characterized in that: In step B, when the password is encrypted using the AES algorithm to generate a key, the password, function name, and user ID are associated to generate an independent AES key for each function.
5. The function encryption method applied to a browser according to claim 1, characterized in that: In step C, the browser automatically calls the navigator.credentials.get() method to obtain the function password information corresponding to the user access function from the local password manager; if the current function stores multiple sets of passwords, the corresponding password information is selected according to the user ID of the current web application.
6. The function encryption method applied to a browser according to claim 1, characterized in that: In step C, the method of using the AES algorithm to encrypt the function password information is as follows: the browser associates the obtained function name, password, user ID, and timestamp to generate the plaintext to be encrypted, calls the crypto.subtle.encrypt() method of the Web Crypto API, and uses the AES key to encrypt the plaintext to generate a key.
7. The function encryption method applied to a browser according to claim 6, characterized in that: The browser transmits the key and plaintext information except the password to the key service for authentication. The authentication process is as follows: after the key service receives the key and plaintext information transmitted by the browser, it retrieves the corresponding password from the database. The key service calls the crypto.subtle.encrypt() method of the Web Crypto API and uses the AES algorithm to encrypt the password and plaintext information retrieved from the database to obtain the target key. The target key is compared with the key transmitted by the browser. If they are consistent, the authentication is passed and the user is allowed to perform subsequent functions; otherwise, access is denied.
8. The function encryption method applied to a browser according to claim 1, characterized in that: After a user passes the authentication for the first time when executing a certain function within a session cycle, the authentication result is recorded. When the function is used again within the same session cycle, the mediation property is set to silent when executing navigator.credentials.get(). The user no longer registers a password and directly obtains the password from the browser's local password manager. If the user switches browsers or another user uses the browser to execute a function, the stored password information is not allowed to be queried in combination with the user ID, and the user is prompted to enter a custom name and password for password registration authentication.
9. A functional encryption system applied to a browser, characterized in that: include: The browser module is used to manage user passwords and encrypt passwords using the AES algorithm when using the function. The browser module includes a password registration module, a password management module, and an encryption module; The password registration module is used for users to register passwords for the encrypted functions, and sends the passwords registered by users to the key service module for authentication; the key management module uses the Web Credential Management API for key management, including password storage, password acquisition and key generation. The encryption module is used to encrypt the authentication information using the AES algorithm when the user uses the function, generate the key and send it to the key service module for authentication; The key service module is used to store passwords, generate AES algorithms, and decrypt and authenticate encrypted ciphertexts. The key service module includes a password storage module, an AES algorithm generation module, and an authentication module. The password storage module is used to save the password for the first use of the function in the database of the key service module. The AES algorithm generation module returns the AES algorithm to the browser. When the browser needs to use the key, it uses the AES algorithm to encrypt the password to generate a key. When the user accesses a certain function, the authentication module authenticates the key generated by the user input or selection of the function password. If the authentication passes, the function is allowed to execute.
10. A storage medium storing program instructions, characterized in that: When the program instructions are run, they execute the function encryption method applied to a browser as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Method, device and equipment for authenticating login system and storage medium
CN119383013A
Java byte code encryption method based on security password module
CN119442288A
Secure bidirectional authentication method and system
CN119449499A