Mail encryption transmission method and device, equipment and storage medium
By encrypting the email content and generating an encrypted URI, the problem of confidentiality and size limitations during transmission is solved, and high security and flexible email transmission is achieved.
Patent Information
- Application Number
- CN202510440180.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-06-13
AI Technical Summary
The existing mail transmission system cannot effectively keep the email content confidential, and the email usage experience is affected due to the size limitations during the transmission process.
By encrypting the mail content and generating an encrypted mail content URI, it is stored in the mail storage server and provided only to the mail recipient. The email recipient obtains and decrypts the email content from the server through this URI.
It improves the security of email transmission, removes the size limit during the transmission process, enhances the email usage experience, and realizes fine-grained access control of email content.
Smart Images

Figure CN120151079A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of mail transmission, and particularly to a method, device, equipment and storage medium for encrypted mail transmission. Background Art
[0002] See Figure 1 , the principle of traditional mail transmission is that users use mail clients, such as Microsoft Outlook, Foxmail, etc., or the web version of the mail service to compose the mail content and fill in information such as the mail recipient, and finally send the mail. The mail will pass through a series of Mail Transfer Agents (MTAs) and finally be transmitted to a Mail Delivery Agent (MDA). The Mail Delivery Agent usually caches the mail as an EML format file and sends it to the mail recipient at an opportune time.
[0003] Traditional mail transmission systems have the following two design flaws:
[0004] 1. Lack of confidentiality
[0005] Basic mail services can ensure that mails are finally delivered from the sender to the recipient, but the mails are in plain text throughout the process of passing through a series of MTAs and the final MDA. That is to say, the mails may be intercepted and the content read throughout the transmission process. To solve this problem, mail service providers will apply Transport Layer Security (TLS) during the mail transmission process. However, there is also a hidden security problem here, that is, the encryption key of TLS is in the hands of the mail service provider. That is to say, the mail service provider can decrypt and obtain the mail content during the mail transmission process.
[0006] In addition, users can also choose to encrypt the mail content independently and send the encryption key to the mail recipient by means other than mail. Leaving aside the difficult problem of how to share the encryption key, just the mail content itself is subject to size limitations.
[0007] 2. Size limitation
[0008] Since mail transmission needs to pass through a series of MTAs and the final MDA, considering the limitations of transmission capacity or transmission efficiency, the size of the mail including attachments is usually limited to about 10MB, which greatly affects the mail usage experience.
[0009] For this reason, the applicant has conducted beneficial exploration and research and found a solution to the above problems. The technical solutions to be introduced below are generated under this background. Summary of the Invention
[0010] One of the technical problems to be solved by the present invention is: to provide an email encryption and transmission method that improves the security of email transmission and solves the problem of email size limitation in view of the deficiencies of the prior art.
[0011] Another technical problem to be solved by the present invention is: to provide an email encryption and transmission device for implementing the above email encryption and transmission method.
[0012] A third technical problem to be solved by the present invention is: to provide a computer device for implementing the above email encryption and transmission method.
[0013] A fourth technical problem to be solved by the present invention is: to provide a computer-readable storage medium for implementing the above email encryption and transmission method.
[0014] As an email encryption and transmission method according to the first aspect of the present invention, it includes:
[0015] Obtain the email content edited by the email sender;
[0016] Encrypt the email content, generate an encrypted email content URI for identifying the encrypted email content, and then store the encrypted email content in the email storage server;
[0017] Send an email object containing the encrypted email content URI to the email recipient through the email transmission service; and
[0018] When the email recipient receives the email object, obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object, decrypt the encrypted email content, and then display the decrypted email content.
[0019] In a preferred embodiment of the present invention, the step of encrypting the email content, generating an encrypted email content URI for identifying the encrypted email content, and then storing the encrypted email content in the email storage server includes:
[0020] Generate a random data encryption key required by the symmetric encryption algorithm, encrypt the data encryption key, and add it to the email object;
[0021] Use the data encryption key to encrypt the email content and generate an encrypted email content URI for identifying the encrypted email content;
[0022] Store the encrypted email content in the email storage server and give the email recipient an access permission token to access the encrypted email content on the storage server.
[0023] In a preferred embodiment of the present invention, the symmetric encryption algorithm is the Advanced Encryption Standard - Galois / Counter Mode.
[0024] In a preferred embodiment of the present invention, the data encryption key is encrypted by generating a shared key between the email sender and the email receiver using the Elliptic Curve Diffie - Hellman algorithm, and then encrypting the data encryption key using the shared key.
[0025] In a preferred embodiment of the present invention, the email content includes the email body content and / or attachments; when encrypting and storing the email content, it specifically includes:
[0026] Using the data encryption key to encrypt the email body content of the email content, and generating an encrypted email body content URI for identifying the encrypted email body content;
[0027] Storing the encrypted email body content in the email storage server, and giving the email receiver an access permission token to access the encrypted email body content on the storage server;
[0028] Using the data encryption key to encrypt the attachments of the email content, and generating an encrypted attachment URI for identifying the encrypted attachments;
[0029] Storing the encrypted attachments in the email storage server, and giving the email receiver an access permission token to access the encrypted attachments on the storage server.
[0030] In a preferred embodiment of the present invention, when the email is to be sent, if the email sender does not allow the designated email receiver to access the email body content and / or attachments in the email content, then the email receiver is not given the access permission token corresponding to the email body content and / or attachments in the email content.
[0031] In a preferred embodiment of the present invention, when the email has been sent, if the email sender does not allow the designated email receiver to access the email body content and / or attachments in the email content, then the access permission token corresponding to the email body content and / or attachments in the email content for the email receiver is revoked on the storage server.
[0032] In a preferred embodiment of the present invention, obtaining the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object, and decrypting the encrypted email content includes:
[0033] Read the encrypted data encryption key in the mail object, and decrypt the encrypted data encryption key to obtain the data encryption key;
[0034] Read the encrypted mail content URI in the mail object, and obtain the corresponding encrypted mail content from the mail storage server according to the encrypted mail content URI; and
[0035] Use the decrypted data encryption key to decrypt the obtained encrypted mail content.
[0036] In a preferred embodiment of the present invention, the obtaining the corresponding encrypted mail content from the mail storage server according to the encrypted mail content URI includes:
[0037] Verify the access token corresponding to the encrypted mail content URI through the mail storage server;
[0038] If the verification is passed, return the encrypted mail content corresponding to the encrypted mail content URI to the mail recipient;
[0039] If the verification fails, reject returning the encrypted mail content.
[0040] As a mail encryption transmission device according to the second aspect of the present invention, it includes:
[0041] A first email client, which is used to obtain the mail content edited by the mail sender;
[0042] A first encryption and decryption module, which is configured in the first email client, and is used to encrypt the mail content, generate an encrypted mail content URI for identifying the encrypted mail content, and then store the encrypted mail content in the mail storage server;
[0043] A mail transmission service module, which is used to send a mail object containing the encrypted mail content URI to the mail recipient through the mail transmission service; and
[0044] A second email client and a second encryption and decryption module, the second encryption and decryption module is configured in the second email client, the second email client is used to receive the mail object transmitted by the mail transmission service module, and is used to display the decrypted mail content, and the second encryption and decryption module is used to obtain the corresponding encrypted mail content from the mail storage server according to the encrypted mail content URI in the mail object, and decrypt the encrypted mail content.
[0045] A computer device for implementing the above-mentioned email encryption transmission method according to the third aspect of the present invention includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of an email encryption transmission method according to the first aspect of the present invention are implemented.
[0046] A computer-readable storage medium for implementing the above-mentioned email encryption transmission method according to the fourth aspect of the present invention stores a computer program thereon. When the computer program is executed by a processor, the steps of an email encryption transmission method according to the first aspect of the present invention are implemented.
[0047] Due to the adoption of the above technical solutions, the beneficial effects of the present invention are as follows:
[0048] 1. The present invention encrypts the email content and stores it in the email storage server, and sends the encrypted email content URI pointing to the encrypted email content to the email recipient through the existing email transmission service. Since only the email recipient can access the encrypted email in the email storage server and decrypt its content, no matter whether the email service provider provides TLS for email transmission confidentiality or the email is intercepted during transmission, the email content will not be leaked, greatly improving the security of email transmission.
[0049] 2. The present invention uses the email storage server to store the encrypted email content. In theory, there is no size limit for the content stored by the storage service, while the user client sends an encrypted email content URI with a limited length (usually several hundred bytes) through the email. This not only solves the problem of email size limitation but also gives the user freedom when writing emails, improving the efficiency of email transmission.
[0050] 3. The present invention can set the access rights of the email body and / or attachments in the email content to allow or not allow the specified email recipient to access the email body and / or attachments in the email content, realizing fine-grained access control of the email content. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0052] Figure 1 is a schematic diagram of the traditional email transmission principle.
[0053] Figure 2It is a schematic flow chart of the email encryption transmission method of the present invention.
[0054] Figure 3 It is a flow chart of encrypting and storing the email content of the present invention.
[0055] Figure 4 It is a flow chart of encrypting and storing the email body content and attachments of the present invention.
[0056] Figure 5 It is a schematic diagram of the email content access control list of the present invention.
[0057] Figure 6 It is a flow chart of decrypting the encrypted email content of the present invention.
[0058] Figure 7 It is a flow chart of obtaining the email content from the email storage server of the present invention.
[0059] Figure 8 It is a flow chart of the email encryption transmission device of the present invention.
[0060] Figure 9 It is the internal structure diagram of the computer device of the present invention. Detailed implementation manners
[0061] In order to make the technical means, creative features, achieved purposes and effects of the present invention easy to understand, the present invention will be further described below with reference to specific diagrams.
[0062] See Figure 2 , what is shown in the figure is an email encryption transmission method, including the following steps:
[0063] Step S10, obtain the email content edited by the email sender.
[0064] Step S20, perform encryption processing on the email content, generate an encrypted email content URI for identifying the encrypted email content, and then store the encrypted email content in the email storage server.
[0065] Step S30, send the email object containing the encrypted email content URI to the email recipient through the email transmission service.
[0066] Step S40, when the email recipient receives the email object, obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object, perform decryption processing on the encrypted email content, and then display the decrypted email content.
[0067] The present invention encrypts the email content and stores it in the email storage server, and sends the encrypted email content URI pointing to the encrypted email content to the email recipient through the existing email transmission service. Since only the email recipient can access the encrypted email in the email storage server and decrypt its content, regardless of whether the email service provider provides TLS for email transmission confidentiality or the email is intercepted during transmission, the email content will not be leaked, greatly improving the security of email transmission. At the same time, the present invention uses the email storage server to store the encrypted email content. In theory, there is no size limit for the content stored by the storage service, while the user client sends an encrypted email content URI with a limited length (usually a few hundred bytes) through the email, thus solving the problem of email size limit and at the same time giving the user freedom when writing emails, improving the efficiency of email transmission.
[0068] See Figure 3 , in step S20, the email content is encrypted, and an encrypted email content URI for identifying the encrypted email content is generated, and then the encrypted email content is stored in the email storage server, including the following steps:
[0069] Step S21, generate a random data encryption key required by the symmetric encryption algorithm, and encrypt the data encryption key and add it to the email object. Considering the one-to-many characteristics of emails, it is relatively convenient to use symmetric encryption technology. Otherwise, if asymmetric encryption technology is used, then the email sender needs to separately use the encryption key of each email recipient to encrypt the email content and upload it to the email storage server, which is undoubtedly very cumbersome. In this embodiment, the symmetric encryption algorithm preferably adopts the Advanced Encryption Standard-Galois / Counter Mode (abbreviated as AES-GCM). AES-GCM uses the data encryption key to encrypt the email content and generates the encrypted email content. Of course, the symmetric encryption algorithm is not limited to the symmetric encryption algorithm in this embodiment, and other symmetric encryption algorithms can also be used.
[0070] To improve the transmission security of the data encryption key, the data encryption key needs to be encrypted. Specifically, an elliptic curve Diffie-Hellman algorithm (ECDH) can be used to generate a shared key between the email sender and the email recipient, and then use this shared key to encrypt the data encryption key to ensure the security of the data encryption key during transmission. Of course, the encryption algorithm used for the data encryption key is not limited to the encryption algorithm in this embodiment, and other encryption algorithms can also be used.
[0071] Step S22, encrypt the email content using a data encryption key, and generate an encrypted email content URI for identifying the encrypted email content.
[0072] Step S23, store the encrypted email content in the email storage server, and give the email recipient an access permission token to access the encrypted email content on the storage server. When the email storage server receives the encrypted email content, the email storage server will generate a unique URI corresponding to it according to the rules for the encrypted email content, such as {user address} / {email metadata identifier} / {encrypted email identifier}, which is convenient for the email recipient to obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI. In this embodiment, the method for generating the URI can adopt the data storage method disclosed in the patent application for invention CN117494207A, and specifically refer to the content of Embodiment 1 in the specific implementation manner of its specification. Of course, the method for generating the URI is not limited to this embodiment, and other methods for generating the URI can also be adopted as long as the validity and security of the URI can be ensured.
[0073] In step S22, the email content usually includes the email body content and / or attachments, and the email body content or attachments can be encrypted and stored separately, and at the same time, the access rights to the email body content or attachments can be controlled to allow or not allow the specified email recipient to access the email body content and / or attachments. See Figure 4 , when performing the encryption and storage processing on the email content, it specifically includes the following steps:
[0074] Step S221, encrypt the email body content of the email content using a data encryption key, and generate an encrypted email body content URI for identifying the encrypted email body content;
[0075] Step S222, store the encrypted email body content in the email storage server, and give the email recipient an access permission token to access the encrypted email body content on the storage server;
[0076] Step S223, encrypt the attachments of the email content using a data encryption key, and generate an encrypted attachment URI for identifying the encrypted attachments;
[0077] Step S224, store the encrypted attachments in the email storage server, and give the email recipient an access permission token to access the encrypted attachments on the storage server.
[0078] The email recipient can obtain the corresponding email body content and / or attachment from the email storage server according to the encrypted email body content URI and / or the encrypted attachment URI. During the access process, the email storage server needs to verify the access permission token of the email recipient. If the verification is successful, the corresponding encrypted email body content and / or attachment will be returned to the email recipient. If the verification fails, the corresponding encrypted email body content and / or attachment will not be returned to the email recipient. In this way, the present invention realizes fine-grained access control of email content through the access permission token. The email content access control table is as Figure 5 shown.
[0079] In this embodiment, the method for generating the access permission token can adopt the data access method disclosed in the invention patent application CN117494207A. For specific details, refer to the content of Embodiment 3 in the specific implementation manner of its specification. Of course, the method for generating the access permission token is not limited to this embodiment, and other methods for generating the access permission token can also be adopted, as long as the effectiveness and security of the access permission token can be ensured.
[0080] In addition, the email sender can choose to set the access permission of the email body content and / or attachment before or after sending the email. Specifically, before sending the email, if the email sender does not allow the designated email recipient to access the email body content and / or attachment in the email content, the access permission token corresponding to the email body content and / or attachment in the email content will not be given to the email recipient. After sending the email, if the email sender does not allow the designated email recipient to access the email body content and / or attachment in the email content, the access permission token corresponding to the email body content and / or attachment in the email content will be revoked on the storage server for the email recipient.
[0081] See Figure 5 , before sending the email, the email sender can give different access permissions to the email recipient according to the email content. For example, a superior leader sends an email about year-end bonuses to a group. The email body content is the year-end bonus policy that all email recipients can see, while each email recipient can only see their own corresponding attachment. Since the specific amount of the year-end bonus is recorded in the attachment, it is not convenient for non-owners to view. Otherwise, the superior leader needs to send an email with exactly the same email body to each email recipient separately. After sending the email, revoking the permission is similar to the function of some email clients that can recall sent emails, provided that the other party uses an email client that supports the same function and has not opened the email yet. Of course, the time limit for revoking the permission is much longer than that for recalling the email. As long as the email recipient has not downloaded the attachment, revoking the permission can prevent the email recipient from downloading the attachment.
[0082] See Figure 6, in step S40, the corresponding encrypted email content is obtained from the email storage server according to the encrypted email content URI in the email object, and the decryption process is performed on the encrypted email content, including the following steps:
[0083] Step S41, read the encrypted data encryption key in the email object, and perform decryption processing on the encrypted data encryption key to obtain the data encryption key;
[0084] Step S42, read the encrypted email content URI in the email object, and obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI;
[0085] Step S43, use the decrypted data encryption key to perform decryption processing on the obtained encrypted email content.
[0086] See Figure 7 , in step S42, obtaining the corresponding encrypted email content from the email storage server according to the encrypted email content URI includes the following steps:
[0087] Step S421, verify the access token corresponding to the encrypted email content URI through the email storage server;
[0088] Step S422, if the verification is passed, return the encrypted email content corresponding to the encrypted email content URI to the email receiver;
[0089] Step S423, if the verification fails, reject the return of the encrypted email content.
[0090] See Figure 8 , what is shown in the figure is an email encryption and transmission device, including a first email client 100, a first encryption and decryption module 200, an email transmission service module 300, a second email client 400, and a second encryption and decryption module 500.
[0091] The first email client 100 is used to obtain the email content edited by the email sender, and it can be configured in the intelligent terminal of the email sender, such as a computer, a mobile phone, a wearable intelligent device, etc.
[0092] The first encryption / decryption module 200 is configured within the first email client 100. It is used to encrypt the email content, generate an encrypted email content URI for identifying the encrypted email content, and then store the encrypted email content in the email storage server 10. In this embodiment, the email storage server 10 can use the storage service disclosed in the patent application for invention CN117494207A. The storage service can ensure that the user himself / herself accesses the personal data on the storage service through dual network token verification. All personal data stored on the storage service is encrypted by the user using his / her own key. Therefore, even if a user's key is stolen, it will only affect the user's personal data on the storage service and will not affect the data security of other users. At the same time, by granting or revoking the permission tokens of other users, the right of other users to access the user's personal data can be granted or revoked.
[0093] The mail transfer service module 300 is used to send the mail object containing the encrypted email content URI to the mail recipient through the mail transfer service, that is, to send the mail object containing the encrypted email content URI generated by the first email client 100 to the second email client 400. In this embodiment, the mail transfer service module 300 can adopt the transmission method as Figure 1 shown. It can use the Simple Mail Transfer Protocol (SMTP for short) to send the mail to the Mail Transfer Agent (MTA), and then according to the routing (DNS), one MTA also uses SMTP to transfer the mail object to the next MTA until the last MDA. And from the MDA to the email client receiving end, the POP3 (Post Office Protocol 3) or the more commonly used IMAP (Internet Mail Access Protocol) protocol is used. Of course, the mail transfer service module 300 is not limited to the mail transfer protocol in this embodiment and can also adopt other mail transfer protocols.
[0094] The second email client 400 can be configured within the intelligent terminal of the mail recipient, such as a computer, a mobile phone, a wearable intelligent device, etc. It is used to receive the mail object transmitted by the mail transfer service module 300 and to display the decrypted email content.
[0095] The second encryption / decryption module 500 is configured within the second email client 400. It is used to obtain the corresponding encrypted email content from the email storage server 10 according to the encrypted email content URI in the mail object and decrypt the encrypted email content.
[0096] Each module in the email encryption and transmission device in this embodiment can be implemented in whole or in part by software, hardware, or a combination thereof. The above-mentioned modules can be embedded in the processor of the computer device in hardware form or independent thereof, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0097] See Figure 8 , the email encryption and transmission device of the present invention can adopt the following email encryption and transmission method, which includes the following steps:
[0098] I. Email sending process:
[0099] 1. The email sender can edit the email plain text and / or attachments in the email editing interface of the first email client 100. After editing is completed, it needs to be encrypted by the first encryption and decryption module 200;
[0100] 2. The first encryption and decryption module 200 generates a random data encryption key required by the symmetric encryption algorithm, and then uses this data encryption key to encrypt the email body content;
[0101] 3. Upload the encrypted email body content to the email storage server 10;
[0102] 4. Give the email recipient an access permission token to access the encrypted email content on the email storage server 10;
[0103] 5. Use the data encryption key generated in step 2 to encrypt the attachments;
[0104] 6. Upload the encrypted attachments to the email storage server 10;
[0105] 7. Give the email recipient an access permission token to access the encrypted attachments on the email storage server 10;
[0106] 8. At this time, the content of the email object (body) sent to the email transmission service module 300 has been replaced by the encrypted email body content URI and encrypted attachment URI pointing to the email storage server 10, and the encrypted data encryption key. The encrypted data encryption key is obtained by using the ECDH algorithm to generate a shared key between the email sender and the email recipient, and then using this shared key to encrypt the data encryption key.
[0107] II. Email receiving process:
[0108] 9. The second email client 400 receives the email object sent by the email transmission service module 300;
[0109] 10. The second encryption and decryption module 500 of the second email client 400 reads the encrypted data encryption key within the email object (body), and decrypts it using the ECDH method to obtain the data encryption key;
[0110] 11. The second encryption and decryption module 500 of the second email client 400 reads the encrypted email body content URI within the email object (body), and obtains the encrypted email body content from the email storage server 10;
[0111] 12. Since symmetric encryption technology is used, the encrypted email body content is decrypted using the data encryption key to obtain the plaintext of the email body content;
[0112] 13. The second encryption and decryption module 500 of the second email client 400 reads the encrypted attachment URI within the email object (body), and obtains the encrypted attachment from the email storage server 10;
[0113] 14. Since symmetric encryption technology is used, the encrypted attachment is decrypted using the data encryption key to obtain the original attachment.
[0114] 15. The plaintext of the email body content and the original attachment are displayed on the email display interface of the second email client 400.
[0115] The present invention also provides a computer device for implementing the above-mentioned email encryption transmission method. This computer device can be a server, and its internal structure diagram can be as Figure 9 shown. This computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of this computer device is used to store data such as user information, record information, and files. The network interface of this computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements an above-mentioned email encryption transmission method.
[0116] Those skilled in the art can understand that Figure 9 the structure shown in
[0117] Specifically, the computer device of the present invention includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0118] Step S10: Obtain the email content edited by the email sender;
[0119] Step S20: Encrypt the email content, generate an encrypted email content URI for identifying the encrypted email content, and then store the encrypted email content in the email storage server;
[0120] Step S30: Send an email object containing the encrypted email content URI to the email recipient through the email transmission service;
[0121] Step S40: When the email recipient receives the email object, obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object, decrypt the encrypted email content, and then display the decrypted email content.
[0122] The present invention also provides a computer-readable storage medium for implementing the above email encryption transmission method. A computer program is stored thereon, and when the computer program is executed by a processor, the following steps are implemented:
[0123] Step S10: Obtain the email content edited by the email sender;
[0124] Step S20: Encrypt the email content, generate an encrypted email content URI for identifying the encrypted email content, and then store the encrypted email content in the email storage server;
[0125] Step S30: Send an email object containing the encrypted email content URI to the email recipient through the email transmission service;
[0126] Step S40: When the email recipient receives the email object, obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object, decrypt the encrypted email content, and then display the decrypted email content.
[0127] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0128] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only used to illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for encrypted email transmission, characterized in that: include: Get the email content edited by the email sender; Encrypting the email content, generating an encrypted email content URI for identifying the encrypted email content, and then storing the encrypted email content in an email storage server; Sending the email object containing the encrypted email content URI to the email recipient via an email transmission service; as well as When the mail recipient receives the mail object, he / she obtains the corresponding encrypted mail content from the mail storage server according to the encrypted mail content URI in the mail object, decrypts the encrypted mail content, and then displays the decrypted mail content.
2. The method for encrypted email transmission according to claim 1, wherein: The step of encrypting the email content, generating an encrypted email content URI for identifying the encrypted email content, and then storing the encrypted email content in an email storage server includes: Generate a random data encryption key required by a symmetric encryption algorithm, encrypt the data encryption key, and then add it into the email object; Encrypting the email content using the data encryption key and generating an encrypted email content URI for identifying the encrypted email content; The encrypted email content is stored in the email storage server, and the email recipient is given an access rights token to access the encrypted email content on the storage server.
3. The method for encrypted email transmission according to claim 2, characterized in that: The symmetric encryption algorithm is Advanced Encryption Standard-Galois / Counter Mode.
4. The method for encrypted email transmission as claimed in claim 2, characterized in that: The data encryption key is encrypted by using the elliptic curve Diffie-Hellman algorithm to generate a shared key between the email sender and the email receiver, and then the shared key is used to encrypt the data encryption key.
5. The method for encrypted email transmission as claimed in claim 2, characterized in that: The email content includes the email body content and / or attachments; when the email content is encrypted and stored, it specifically includes: Encrypting the email body content of the email content using the data encryption key, and generating an encrypted email body content URI for identifying the encrypted email body content; The encrypted email body content is stored in the email storage server, and the email recipient is given an access rights token to access the encrypted email body content on the storage server; Encrypting the attachment of the email content using the data encryption key, and generating an encrypted attachment URI for identifying the encrypted attachment; The encrypted attachment is stored in the mail storage server, and the mail recipient is given an access rights token for accessing the encrypted attachment on the storage server.
6. The method for encrypted email transmission as claimed in claim 5, characterized in that: Before sending an email, if the email sender does not allow the designated email recipient to access the email body content and / or attachments in the email content, the email recipient will not be given the access permission token corresponding to the email body content and / or attachments in the email content.
7. The method for encrypted email transmission according to claim 5, characterized in that: After the email is sent, if the email sender does not allow the specified email recipient to access the email body content and / or attachments in the email content, the email recipient's access permission token corresponding to the email body content and / or attachments in the email content will be revoked on the storage server.
8. The method for encrypted email transmission according to any one of claims 2 to 7, characterized in that: The step of obtaining the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object and decrypting the encrypted email content includes: Reading the encrypted data encryption key in the email object, and decrypting the encrypted data encryption key to obtain the data encryption key; Reading the encrypted email content URI in the email object, and acquiring the corresponding encrypted email content from the email storage server according to the encrypted email content URI; and The encrypted email content is decrypted using the decrypted data encryption key.
9. The method for encrypted email transmission as claimed in claim 8, characterized in that: The obtaining the corresponding encrypted email content from the email storage server according to the encrypted email content URI includes: Verifying the access permission token corresponding to the encrypted email content URI through the email storage server; If the verification is successful, the encrypted email content corresponding to the encrypted email content URI is returned to the email recipient; If the verification fails, the encrypted email content will be rejected.
10. An encrypted mail transmission device, characterized in that: include: A first email client, wherein the first email client is used to obtain email content edited by an email sender; A first encryption and decryption module, which is configured in the first email client and is used to encrypt the email content, generate an encrypted email content URI for identifying the encrypted email content, and then store the encrypted email content in the email storage server; An email transmission service module, the email transmission service module is used to send the email object containing the encrypted email content URI to the email recipient through the email transmission service; as well as A second email client and a second encryption and decryption module, wherein the second encryption and decryption module is configured in the second email client, the second email client is used to receive the email object transmitted by the email transmission service module, and is used to display the decrypted email content, and the second encryption and decryption module is used to obtain the corresponding encrypted email content from the email storage server according to the encrypted email content URI in the email object, and decrypt the encrypted email content.
11. A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method for encrypted email transmission according to any one of claims 1 to 9 when executing the computer program.
12. A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method for encrypted email transmission according to any one of claims 1 to 9.
Citation Information
Patent Citations
Data storage method and device, data access method and device, equipment and storage medium
CN117494207A
Cited By
Mail data security method and system based on identification public key password
CN121547309A