Front-end encryption method, system and device and computer readable medium

By executing encryption operations in the WASM module and developing encryption algorithms using Rust and WebAssembly, the existing JavaScript encryption methods are solved and the problem of inefficient execution and vulnerability in front-end applications are achieved, and the encryption speed and security are improved.

CN120234818APending Publication Date: 2025-07-01INSPUR SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510296508.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing JavaScript encryption methods have problems such as low execution efficiency and vulnerability in front-end applications, making it difficult to effectively protect data from tampering.

Method used

By performing encryption operations in the WASM module, using Rust and WebAssembly to develop encryption algorithms, implementing WASM encryption modules, and using the national secret algorithm for encryption and signature verification, improving encryption speed and security.

Benefits of technology

It significantly improves the execution speed of encryption algorithms, reduces the risk of data tampering, increases cracking difficulty, and simplifies the development and maintenance of front-end applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234818A_ABST
    Figure CN120234818A_ABST
Patent Text Reader

Abstract

The invention discloses a front-end encryption method, system and device and a computer readable medium, and relates to the technical field of data encryption. An encryption algorithm is developed based on Rust and WebAssembly, and a WASM encryption module is realized; the method comprises the following steps: compiling an encryption algorithm and an encryption method into a WASM encryption module by using a wass-pack, integrating the WASM encryption module into a front-end application, loading and instantiating the WASM encryption module by using a WASM encryption API (Application Program Interface), and carrying out data encryption processing through the WASM encryption module; according to the invention, the encryption operation is executed in the WASM module, so that the encryption speed and security are improved, and the risk of data tampering in the front-end application is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention discloses a front - end encryption method, system, device and computer - readable medium, which relates to the technical field of data encryption. Background Art

[0002] With the increasing complexity of Web applications, front - end data processing has become more and more important, and there is a risk of data tampering in front - end applications. Existing JavaScript encryption methods have problems of low execution efficiency and are vulnerable to various attacks. Summary of the Invention

[0003] In view of the problems of the prior art, the present invention provides a front - end encryption method, system, device and computer - readable medium, which executes the encryption operation in a WASM module, improves the encryption speed and security, and reduces the risk of data tampering in front - end applications.

[0004] The specific solution proposed by the present invention is as follows:

[0005] The present invention provides a front - end encryption method, which develops an encryption algorithm based on Rust and WebAssembly and implements a WASM encryption module: prepares the Rust and WebAssembly development environments, creates a lib project, and uses the lib project to establish an encryption algorithm and corresponding encryption methods. The encryption methods include: randomly generating two 16 - bit encrypted key values and iv values, encrypting the key values and iv values into an encryption envelope using sec_key; encrypting the data input into the WASM encryption module according to the key values and iv values using the national cipher sm4 algorithm; randomly generating a signature string and a key value, and generating a signature verification string using the hmac algorithm of sm3; encrypting the string using the pub_key of national cipher sm2 for data correctness verification;

[0006] Compiles the encryption algorithm and encryption methods into a WASM encryption module using wasm - pack,

[0007] Integrates the WASM encryption module into the front - end application, and uses the WASM encryption API to load and instantiate the WASM encryption module,

[0008] Performs data encryption processing through the WASM encryption module.

[0009] Further, in the front - end encryption method, the preparation of the Rust and WebAssembly development environments includes: installing the Rust compiler using rustup, installing the wasm32 - unknown - unknown module, installing wasm - pack, installing the wasm - bindgen toolchain, and creating a lib project.

[0010] Furthermore, in the described front-end encryption method, the data encryption process through the WASM encryption module includes:

[0011] Introduce the packaged js through the module of script.

[0012] Call the init method through the WASM encryption module, export the encryption algorithm and encryption method, and pass in parameters. The parameters include the private key sec_key of the encryption envelope, the public key pub_key for signature verification, and the data to be encrypted. After encrypting the data using the encryption algorithm and encryption method, return the data and the signature data to the WASM encryption API.

[0013] The present invention also provides a front-end encryption system, including an algorithm development module, a WASM encryption module, and a loading module.

[0014] The algorithm development module develops an encryption algorithm based on Rust and WebAssembly and implements the WASM encryption module: prepare the Rust and WebAssembly development environments, create a lib project, establish an encryption algorithm and the corresponding encryption method using the lib project. The encryption method includes: randomly generating two 16-bit encrypted key values and iv values, encrypting the key values and iv values into an encryption envelope using sec_key; encrypting the data input to the WASM encryption module according to the key values and iv values using the national cipher sm4 algorithm; randomly generating a signature string and a key value, and generating a signature verification string using the hmac algorithm of sm3; encrypting the string using the pub_key of the national cipher sm2 for data correctness verification.

[0015] Compile the encryption algorithm and encryption method into a WASM encryption module using wasm-pack.

[0016] Integrate the WASM encryption module into the front-end application. The loading module uses the WASM encryption API to load and instantiate the WASM encryption module.

[0017] The WASM encryption module performs data encryption processing.

[0018] Furthermore, the algorithm development module of the described front-end encryption system prepares the Rust and WebAssembly development environments, including: installing the Rust compiler using rustup, installing the wasm32-unknown-unknown module, installing wasm-pack, installing the wasm-bindgen toolchain, and creating a lib project.

[0019] Further, the WASM encryption module of the front-end encryption system performs data encryption processing, including:

[0020] Introduce the packaged js through the module of script.

[0021] The WASM encryption module calls the init method, exports the encryption algorithm and encryption method, and passes in parameters. The parameters include the private key sec_key of the encryption envelope, the public key pub_key for signature verification, and the data to be encrypted. After encrypting the data using the encryption algorithm and encryption method, the data and the signature data are returned to the WASM encryption API.

[0022] The present invention also provides a front-end encryption device, including: at least one memory and at least one processor;

[0023] The at least one memory is used to store machine-readable programs;

[0024] The at least one processor is used to call the machine-readable program and execute the front-end encryption method described above.

[0025] The present invention also provides a computer-readable medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the processor executes the front-end encryption method described above.

[0026] The advantages of the present invention are:

[0027] The present invention allows the browser to directly execute the code compiled by the underlying language Rust through WASM, thereby significantly improving the execution speed of the encryption algorithm; computationally intensive tasks can be quickly completed in the WASM module, reducing the user waiting time;

[0028] Through WASM, a sandboxed execution environment is provided, making it difficult for malicious scripts to access or modify the data within the WASM module; the encryption logic is encapsulated within the WASM module, reducing the risk of reverse engineering and increasing the difficulty of cracking;

[0029] Through the cross-platform feature natively supported by WASM, the development and maintenance costs of front-end applications can be simplified, ensuring the consistency of encryption functions;

[0030] By integrating the WASM module into an existing front-end project, no complex installation and configuration are required; developers can dynamically load different WASM modules as needed to achieve flexible function expansion. Brief Description of the Drawings

[0031] Figure 1 It is a schematic diagram of the application framework process of the method of the present invention. Detailed Embodiments

[0032] WebAssembly is a portable binary instruction format that can run on browsers and other compilation programming languages.

[0033] Rust is a programming language developed under the leadership of the Mozilla Foundation.

[0034] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, so that those skilled in the art can better understand the present invention and be able to implement it, but the illustrated embodiments are not intended to limit the present invention.

[0035] Embodiment 1

[0036] The present invention provides a front-end encryption method, which develops an encryption algorithm based on Rust and WebAssembly and implements a WASM encryption module: prepare the Rust and WebAssembly development environments and create a lib project. When preparing the Rust and WebAssembly development environments, it may include: installing the Rust compiler using rustup, installing the wasm32-unknown-unknown module, installing wasm-pack, installing the wasm-bindgen toolchain, and creating a lib project. Among them, the wasm32-unknown-unknown module compiles Rust code into a WebAssembly module (Wasm) using wasm32-unknown-unknown. wasm32-unknown-unknown is a target triple supported by the Rust compiler.

[0037] Establish an encryption algorithm and its corresponding encryption method using the lib project. The encryption method includes: randomly generating two 16-bit encrypted key values and iv values, encrypting the key values and iv values into an encryption envelope using sec_key; encrypting the data input into the WASM encryption module using the national cipher sm4 algorithm according to the key values and iv values; randomly generating a signature string and a key value, and generating a signature verification string using the hmac algorithm of sm3; encrypting the string using the pub_key of the national cipher sm2 for data correctness verification;

[0038] Compile the encryption algorithm and encryption method into a WASM encryption module using wasm-pack,

[0039] Integrate the WASM encryption module into the front-end application, and use the WASM encryption API to load and instantiate the WASM encryption module,

[0040] Perform data encryption processing through the WASM encryption module. Among them, performing data encryption processing through the WASM encryption module may include:

[0041] Introduce the packaged JavaScript through the module of the script.

[0042] Call the init method through the WASM encryption module, export the encryption algorithm and encryption method, and pass in parameters, including the private key sec_key of the encryption envelope, the public key pub_key for signature verification, and the data to be encrypted. After encrypting the data using the encryption algorithm and encryption method, return the data and the signed data to the WASM encryption API.

[0043] Embodiment 2

[0044] The present invention also provides a front-end encryption system based on Rust + WebAssembly, including an algorithm development module, a WASM encryption module, and a loading module.

[0045] The algorithm development module develops encryption algorithms based on Rust and WebAssembly and implements the WASM encryption module: prepare the Rust and WebAssembly development environments, create a lib project, and use the lib project to establish encryption algorithms and corresponding encryption methods. The encryption methods include: randomly generating two 16-bit encrypted key values and iv values, encrypting the key values and iv values into an encryption envelope using sec_key; encrypting the data input to the WASM encryption module according to the key values and iv values using the national cipher sm4 algorithm; randomly generating a signature string and a key value, and generating a signature verification string using the hmac algorithm of sm3; encrypting the string using the pub_key of the national cipher sm2 for data correctness verification.

[0046] Use wasm-pack to compile the encryption algorithm and encryption method into a WASM encryption module.

[0047] Integrate the WASM encryption module into the front-end application. The loading module uses the WASM encryption API to load and instantiate the WASM encryption module.

[0048] The WASM encryption module performs data encryption processing.

[0049] Regarding the information interaction and execution process between the modules in the above system, since they are based on the same concept as the method embodiment of the present invention, the specific content can be referred to the description in the method embodiment of the present invention and will not be elaborated here.

[0050] Similarly, the system of the present invention allows the browser to directly execute the code compiled by the underlying language Rust through WASM, thereby significantly improving the execution speed of the encryption algorithm; operation-intensive tasks can be quickly completed in the WASM module, reducing the user waiting time.

[0051] It provides a sandboxed execution environment through WASM, making it difficult for malicious scripts to access or modify the data within the WASM module; the encryption logic is encapsulated within the WASM module, reducing the risk of reverse engineering and increasing the difficulty of cracking;

[0052] Due to the cross-platform nature natively supported by WASM, it can simplify the development and maintenance costs of front-end applications and ensure the consistency of encryption functions;

[0053] By integrating the WASM module into an existing front-end project, no complex installation and configuration are required; developers can dynamically load different WASM modules as needed to achieve flexible function expansion.

[0054] It should be noted that not all steps and modules in the above-mentioned processes and system structures are necessary, and some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structures described in the above-mentioned embodiments can be physical structures or logical structures, that is, some modules may be implemented by the same physical entity, or some modules may be implemented separately by multiple physical entities, or they can be jointly implemented by some components in multiple independent devices.

[0055] Embodiment 3

[0056] The present invention also provides a front-end encryption device, including: at least one memory and at least one processor;

[0057] The at least one memory is used to store machine-readable programs;

[0058] The at least one processor is used to call the machine-readable program and execute the front-end encryption method described above.

[0059] Regarding the content such as the information interaction of the processor and the process of executing the readable program within the above-mentioned device, since it is based on the same concept as the method embodiment of the present invention, the specific content can be referred to the description in the method embodiment of the present invention and will not be elaborated here.

[0060] Similarly, the device of the present invention allows the browser to directly execute the code compiled by the underlying language Rust through WASM, thereby significantly improving the execution speed of the encryption algorithm; computationally intensive tasks can be quickly completed within the WASM module, reducing the user waiting time;

[0061] It provides a sandboxed execution environment through WASM, making it difficult for malicious scripts to access or modify the data within the WASM module; the encryption logic is encapsulated within the WASM module, reducing the risk of reverse engineering and increasing the difficulty of cracking;

[0062] The cross-platform feature natively supported by WASM can simplify the development and maintenance costs of front-end applications and ensure the consistency of encryption functions;

[0063] By integrating the WASM module into an existing front-end project, complex installation and configuration are not required; developers can dynamically load different WASM modules as needed to achieve flexible function expansion.

[0064] Embodiment 4

[0065] The present invention also provides a computer-readable medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the processor is caused to execute the front-end encryption method described above. Specifically, a system or device equipped with a storage medium can be provided, on which software program code for implementing the functions of any one of the above embodiments is stored, and the computer (or CPU or MPU) of the system or device is caused to read and execute the program code stored in the storage medium.

[0066] In this case, the program code read from the storage medium itself can implement the functions of any one of the above embodiments, so the program code and the storage medium storing the program code constitute a part of the present invention.

[0067] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code can be downloaded from a server computer via a communication network.

[0068] In addition, it should be clear that not only can the functions of any one of the above embodiments be implemented by executing the program code read by the computer, but also by causing an operating system or the like operating on the computer based on the instructions of the program code to complete part or all of the actual operations.

[0069] In addition, it can be understood that the program code read from the storage medium is written into the memory provided in an expansion board inserted into the computer or into the memory provided in an expansion unit connected to the computer, and then based on the instructions of the program code, the CPU or the like installed on the expansion board or the expansion unit is caused to execute part and all of the actual operations, thereby implementing the functions of any one of the above embodiments.

[0070] The above-described embodiments are only preferred embodiments given to fully illustrate the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or transformations made by those skilled in the art of this technology on the basis of the present invention are all within the protection scope of the present invention. The protection scope of the present invention shall be subject to the claims.

Claims

1. A front-end encryption method, characterized in that Develop encryption algorithms based on Rust and WebAssembly, and implement WASM encryption modules: Prepare Rust and WebAssembly development environments, create a lib project, and use the lib project to establish encryption algorithms and corresponding encryption methods. The encryption methods include: randomly generating two 16-bit encrypted key values ​​and iv values, and using sec_key to encrypt the key value and iv value into an encrypted envelope; using the national secret sm4 algorithm to encrypt the data input into the WASM encryption module according to the key value and iv value; randomly generating signature strings and key values, and using the sm3 hmac algorithm to generate signature verification strings; using the national secret sm2 pub_key to encrypt strings for data correctness verification; Use wasm-pack to compile the encryption algorithm and encryption method into a WASM encryption module. Integrate the WASM encryption module into the front-end application, use the WASM encryption API to load and instantiate the WASM encryption module, Data encryption is performed through the WASM encryption module.

2. A front-end encryption method according to claim 1, characterized in that The preparation of Rust and WebAssembly development environment includes: installing the Rust compiler using rustup, installing the wasm32-unknown-unknown module, installing wasm-pack, installing the wasm-bindgen tool chain, and creating a lib project.

3. A front-end encryption method according to claim 1, characterized in that The data encryption process is performed by the WASM encryption module, including: Import the packaged js through the script module. The init method is called through the WASM encryption module, and the encryption algorithm and encryption method are exported. The parameters are passed in, including the private key sec_key of the encrypted envelope, the public key pub_key for signature verification, and the data to be encrypted. After the data is encrypted using the encryption algorithm and encryption method, the data and signature data are returned to the WASM encryption API.

4. A front-end encryption system, characterized in that Including algorithm development module, WASM encryption module and loading module, The algorithm development module develops encryption algorithms based on Rust and WebAssembly, and implements the WASM encryption module: prepare the Rust and WebAssembly development environment, create a lib project, and use the lib project to establish the encryption algorithm and the corresponding encryption method. The encryption method includes: randomly generating two 16-bit encrypted key values ​​and iv values, and using sec_key to encrypt the key value and iv value into an encrypted envelope; using the national secret sm4 algorithm to encrypt the data input into the WASM encryption module according to the key value and iv value; randomly generating a signature string and a key value, and using the sm3 hmac algorithm to generate a signature verification string; using the national secret sm2 pub_key to encrypt the string for data correctness verification; Use wasm-pack to compile the encryption algorithm and encryption method into a WASM encryption module. Integrate the WASM encryption module into the front-end application. The loading module uses the WASM encryption API to load and instantiate the WASM encryption module. The WASM encryption module performs data encryption processing.

5. A front-end encryption system according to claim 4, characterized in that The algorithm development module prepares the Rust and WebAssembly development environment, including: installing the Rust compiler using rustup, installing the wasm32-unknown-unknown module, installing wasm-pack, installing the wasm-bindgen tool chain, and creating a lib project.

6. A front-end encryption system according to claim 4, characterized in that The WASM encryption module performs data encryption processing, including: Import the packaged js through the script module. The WASM encryption module calls the init method, exports the encryption algorithm and encryption method, and passes in parameters, including the private key sec_key of the encrypted envelope, the public key pub_key for signature verification, and the data to be encrypted. After encrypting the data using the encryption algorithm and encryption method, the data and signature data are returned to the WASM encryption API.

7. A front-end encryption device, characterized in that include: at least one memory and at least one processor; The at least one memory is used to store a machine-readable program; The at least one processor is used to call the machine-readable program to execute a front-end encryption method according to any one of claims 1 to 3.

8. A computer readable medium, characterized in that The computer-readable medium stores computer instructions, which, when executed by a processor, enable the processor to execute a front-end encryption method as described in any one of claims 1 to 3.