General E-mail encryption and decryption intermediary system and method based on browser plug-in

Through the browser plug-in intermediary system, the existing PKI system management certificate and national secret algorithm are used to solve the interface intrusion, compatibility and security of the existing email encryption plug-in, and achieve cross-platform compatible, easy-to-use and secure email encryption and decryption.

CN120281537APending Publication Date: 2025-07-08XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510443681.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing email encryption plug-in technology has problems such as invasive modification of the email vendor interface, poor cross-platform compatibility, vulnerability to XSS attacks, complex user operations, and the encryption algorithm does not meet my country's standards.

Method used

It uses browser plug-ins as an intermediary, and provides a variety of national secret algorithms through its own PKI system management certificate. The plug-in completes encryption and decryption operations locally to avoid directly modifying the email interface, and uses Service Worker to listen for requests to transmit encrypted emails, building an end-to-end encryption system.

Benefits of technology

It realizes email encryption and decryption with strong cross-platform compatibility, easy to expand, high security, user-friendly, and complies with national secret standards, reducing maintenance costs and XSS attack risks, and simplifying user operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281537A_ABST
    Figure CN120281537A_ABST
Patent Text Reader

Abstract

The invention discloses a general E-mail encryption and decryption intermediary system and method based on a browser plug-in. The system comprises a browser plug-in end and a server end, the browser plug-in end comprises a user account management module, a plug-in encryption module and a plug-in decryption module; the server side comprises a service server, a key generation center (KGC) server, a key management server, a digital certificate authentication center (CA) server and a mail server, and the server side comprises a service server, a key generation center (KGC) server, a key management server, a digital certificate authentication (CA) server and a mail server. According to the method, a browser plug-in is used as an intermediary between a Web-end e-mail system and a mail server, and encryption and decryption operations of mails are assisted to be completed in a zero-intrusive mode; the user operation is simple, and the plug-in can be compatible with most mail manufacturers only through simple adaptation, so that the universality and expansibility of the plug-in are enhanced; the encryption and decryption operations of the mail are carried out locally in the plug-in intermediary, so that the privacy of the user is protected, and the risk of security leakage is reduced; by establishing an own PKI system, the cost of applying for and managing a certificate by a user is reduced, and the usability of an encryption plug-in is improved; and a plurality of optional standard encryption modes suitable for mainstream encryption algorithms in China are provided for users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of email encryption protection, and particularly relates to a general email encryption and decryption mediation system and method based on a browser plugin. Background Art

[0002] Email systems on the Web side usually follow the HTTPS protocol during email transmission to ensure that data transmission between the client and the email server occurs through an encrypted channel, preventing sensitive information from being stolen or tampered with during transmission. However, the emails themselves may still be exposed on the email server, especially in the absence of end-to-end encryption. The email content stored and processed by the email server may become a target for attackers, posing a risk of being leaked or misused.

[0003] There are some problems with the existing technical solutions for email encryption plugins. Some plugins are customized according to specific email manufacturers. By analyzing the writing interface of the manufacturer and reading the text box elements to obtain the email content for encryption, and then covering the original function buttons such as reply and forward in the email interface for decryption. This method belongs to invasive modification, directly changing the structure and function of the original manufacturer's interface. There are significant limitations: First, when the manufacturer updates or modifies the name or category of interface elements, the plugin may not work properly, and developers need to maintain and modify the code in real time, or even recompile the plugin, which significantly increases the maintenance cost. Second, this solution is usually limited to specific email service manufacturers and cannot be used by other email manufacturers, lacking cross-platform compatibility. In addition, if other email manufacturers want to be supported in the future, separate customization is required for each manufacturer to identify and adapt to the interface changes of different manufacturers, with poor scalability and requiring a large amount of development time and resources. There are also some plugins that can be compatible with multiple email manufacturers, but users need to input the text content into the plugin for encryption to obtain the ciphertext, and then copy the ciphertext to the corresponding writing interface, which is very complex to use. Cross-Site Scripting (XSS) attack means that an attacker injects malicious scripts into a web page to obtain users' sensitive data, tamper with page content, or hijack user sessions, etc. For browser plugins, the risk of XSS attack is particularly prominent because plugins usually need to interact with web page content. When the plugin modifies the DOM elements of the browser page, it means that the plugin directly operates on the content and structure of the web page. If there are lax input validations or improper content handling, it may be exploited by malicious scripts. Moreover, most of these encryption plugins use the PGP protocol, and users need to manually apply for, import, and export keys. Most users need to have a certain foundation in cryptography to understand and set the corresponding encryption and decryption operations, which is relatively complex to use, with poor user-friendliness and experience. And this single encryption method does not conform to the mainstream encryption algorithm standards and requirements in our country; furthermore, encryption plugins are generally designed for a specific email manufacturer. By modifying and covering the original interface state of the email manufacturer and injecting the function modules of the plugin to achieve encryption and decryption functions, they have high coupling and poor subsequent maintainability. Once the interface elements of the email manufacturer change, the plugin needs to be re-adapted, and a set of compatible logics need to be rewritten for other email manufacturers. The PGP protocol does not fully adapt to the mainstream encryption algorithm standards and requirements in our country and cannot meet the needs of domestic users.

[0004] The disadvantages of the prior art are mainly as follows:

[0005] 1. Existing technologies modify the original interface of email manufacturers in an intrusive manner. Generally, plugins can only be adapted to specific email manufacturers. When the interface of the manufacturer's email changes, the plugin needs to be modified and adapted again, resulting in poor maintainability and scalability. For example, [WENDLANDT D, PORTNOY S. Mailvelope: A browser extension for end-to-end encrypted webmail [EB / OL]. 2015. https: / / www.eff.org / files / 2015 / 07 / 15 / mailvelope_whitepaper_072015_0.pdf.]

[0006] 2. Existing technologies modify the DOM elements of the original manufacturer in an intrusive manner. Attackers may execute malicious code by forging inputs or manipulating the DOM modifications in browser plugins, stealing users' sensitive data or controlling browser behavior, and thus facing the risk of XSS attacks to a certain extent. For example, [MAHMOUD S K, ALFONSE M, ROUSHDY M I, et al. A comparative analysis of Cross Site Scripting (XSS) detecting and defensive techniques [C] / / 2017 Eighth International Conference on Intelligent Computing and Information Systems (ICICIS). 2017: 36 - 42. DOI: 10.1109 / INTELCIS.2017.8260024.]

[0007] 3. Existing technologies do not provide a management function for user certificates and keys, and users need to manually complete the application or import of certificates, increasing the difficulty of use. For example, [RUOTI S, ANDERSEN J, ZAPPALA D, et al. Why Johnny Still, Still Can’t Encrypt: Evaluating the Usability of a Modern PGP Client [EB / OL]. 2016. https: / / arxiv.org / abs / 1510.08555. arXiv: 1510.08555.]

[0008] 4. Most of the existing technologies use encryption algorithms such as PGP or S / MIME. The encryption algorithm solutions are relatively single and do not meet the standards and requirements of the mainstream encryption algorithms in China; such as [Yuan Feng, Cheng Zhaohui. Review of SM9 Identity-Based Cryptography Algorithm [J]. Journal of Information Security Research, 2016, 2(11): 1008-1027.] Summary of the Invention

[0009] In order to overcome the problems existing in the above-mentioned prior art, the purpose of the present invention is to disclose a general email encryption and decryption mediation system and method based on a browser plugin, which uses the browser plugin as a mediator between the Web email system and the mail server to assist in completing the encryption and decryption operations of emails in a zero-invasive manner; the user operation is simple, and only simple adaptation is required to be compatible with most mail vendors, enhancing the versatility and extensibility of the plugin; the encryption and decryption operations of emails are performed locally on the plugin mediator, protecting user privacy and reducing the risk of security leakage; by establishing its own PKI system, the cost of users applying for and managing certificates is reduced, and the usability of the encryption plugin is increased; multiple optional encryption methods suitable for the standards of the mainstream encryption algorithms in China are provided for users.

[0010] In order to achieve the above purpose, the present invention adopts the following technical solutions:

[0011] A general email encryption and decryption mediation system based on a browser plugin, comprising: a browser plugin end and a server end; the browser plugin end includes a user account management module, a plugin encryption module, and a plugin decryption module;

[0012] The user account management module is responsible for the login, switching, and logout operations of the account, and performs the full life cycle management of the key or digital certificate bound to the account, including generation, storage, use, and destruction;

[0013] The functions of the plug-in encryption module are divided into two stages: email content encryption and ciphertext sending. In the email content encryption stage, the user writes the email content in a unified letter writing interface. After clicking the send button, the browser plug-in reads the email text, signs the plaintext summary, and uses the digital envelope mechanism to encrypt the plaintext content to generate ciphertext information C and signature information S. The ciphertext sending stage is completed by the Service Worker in the background of the browser plug-in: before using the browser plug-in, the user logs in to the corresponding third-party email service provider's Web end. The browser plug-in monitors the request information sent by the third-party email service provider's Web end in real time through the chrome.webRequest.onBeforeRequest interface, and filters out the request information that meets the requirements according to the filtering rules set in the onBeforeRequest interface, extracts the session ID parameter, and uses the parameter to construct and send a request carrying the encrypted email in the plug-in encryption module, and pushes the ciphertext email to the server of the third-party email service provider.

[0014] The functions of the plugin decryption module include ciphertext download and decryption display. In the ciphertext download part, after the user selects the email to be decrypted, the browser plugin listens and filters the requests issued by the user through the chrome.webRequest.onBeforeRequest interface, extracts the session ID and the unique identifier of the email, constructs a download request and obtains the ciphertext email. In the decryption display part, after clicking the "Decrypt" button, the browser plugin decrypts the ciphertext C and verifies the signature S. If the signature verification passes, the plaintext content is displayed on the interface; if the signature verification fails, the user is prompted.

[0015] The server side includes a business server, a key generation center (KGC) server, a key management server, a digital certificate authority (CA) server and a mail server; wherein the business server serves as the traffic entrance of the entire server side, processes user requests and realizes the transfer and transmission of requests; the key generation center (KGC) server provides services including system parameter generation and user private key calculation; the key management server provides services including user identity management and key validity query, and provides key application and revocation functions; the CA server provides services including certificate distribution and certificate validity query; the mail server provides services including verification code issuance and mail forwarding; the browser plug-in side and the server side collaborate through a communication interface; ensure that users achieve end-to-end encryption and ensure the stable operation of the entire encrypted email system.

[0016] The third-party email service providers include 163 NetEase Mail and QQ Mail.

[0017] The specific method for the browser plugin side and the server side to cooperate through the communication interface is as follows: The browser plugin side is responsible for front-end interaction, content encryption and decryption operations, and initiates key application, certificate verification, and encrypted email sending requests according to the user's operations on the browser plugin side; the server side provides system parameter generation, user key calculation, certificate distribution and verification, key status query, and email relay services respectively according to the requests, realizing an end-to-end secure email communication system.

[0018] A general email encryption and decryption mediation method based on a browser plugin specifically includes the following steps:

[0019] Step 1, the user installs the browser plugin provided by the mediation system, enters the browser plugin account login interface, and the user directly uses the email account of the third-party email service provider for login and identity verification. After login, the browser plugin side authorization is completed; there is no need to perform additional account registration work;

[0020] Step 2, after the login authorization is completed, the browser plugin side displays an encryption algorithm selection interface for the user. The user selects the traditional national cryptographic algorithm SM2 or SM3 or SM4 based on the certificate or the identity-based national cryptographic SM9 algorithm without a certificate according to personal needs for subsequent email encryption, decryption, and signature work;

[0021] Step 3, when the browser plugin detects the selected encryption type, it first generates a certificate application request locally and sends the request to the CA server; after the CA server detects the user request, it issues an encryption certificate for the user. After the plugin obtains the encryption certificate and verifies that the encryption certificate is accurate, it securely saves the encryption certificate locally to complete the login of the plugin;

[0022] Step 4, after the login of the plugin is completed, ensure that the plugin login account is consistent with the logged-in email account, and then compose and encrypt the email and send the email;

[0023] Step 5, the user receives the email, and uses the browser plugin as an intermediary to assist in downloading and decrypting the email.

[0024] The specific method of step 3 is as follows: When the user selects the traditional national cryptographic algorithm, the browser plug-in generates a certificate application request locally and then submits the request to the CA server; after the CA server detects the user request, it issues an encrypted certificate for the user. After the plug-in obtains the encrypted certificate and verifies that the encrypted certificate is accurate, it securely saves the encrypted certificate locally; when the user selects the SM9 encryption algorithm based on identity, the browser plug-in first sends a request to the KGC server to obtain system parameters and the public key information of the master public key. After the KGC server verifies the user's identity, it returns the system parameters and the master public key stored on the server; then the browser plug-in sends a request to the KGC for the user's private key with the user's unique identity information. After the KGC server generates a private key for the user based on the identity information, it returns it.

[0025] The specific method of step 4 is as follows: Log in to the plug-in, then select the encryption scheme, click the write letter button to enter the write letter interface of the browser plug-in to compose an email. At this time, the browser plug-in automatically generates a symmetric key to encrypt the text and attachment information of the email; the browser plug-in extracts the content of the email from the email composition page and encrypts the email content with the symmetric key just generated. To ensure the security of the symmetric key, the browser plug-in also sequentially queries the public keys of the recipients and encrypts the symmetric key with each recipient's public key. At this time, the encrypted email information C1 and the encrypted session key information C2 are obtained; to ensure the integrity and non-repudiation of the email content, before the symmetric key encrypts the email content, it first signs the email plaintext digest with the private key of the user who logs in to the current browser plug-in. The user's private key is encrypted and stored in the browser by the user's custom setting of the key phrase. The user enters the key phrase to decrypt the private key ciphertext. After loading it into the memory, the private key is used to sign the email plaintext digest to obtain the signature information S. After use, the private key information is destroyed from the memory; then the encryption type selected by the user is filled in the Content-Type field, the encrypted session key information C2 is filled in the keydata field, the encrypted email information C1 is filled in the Ciphertext field, and the signature information S is filled in the Signature field; then the final email content to be sent is assembled in the order of Content-Type, keydata, Signature, and Ciphertext in sequence;

[0026] After successful login on the browser plugin side, the chrome.webRequest.onBeforeRequest interface will be called through the background service to listen in real time for the request information sent by the Web side of the third-party email service provider. The request information that meets the requirements will be filtered out according to the filtering rules set in the onBeforeRequest interface, and the session ID parameter will be extracted from it. Then, the browser plugin side acts as an intermediary to interact with the server of the third-party email service provider on behalf of the Web side of the third-party email service provider, constructs an HTTPS request using the session ID parameter, completes the sending of encrypted emails, and pushes the assembled email content to the server of the third-party email service provider.

[0027] The ciphertext information C2 of the session key is a collection of ciphertexts obtained by encrypting the symmetric key with the public keys of several recipients respectively.

[0028] The content of the keydata field exists in the form of key-value. When the email of user A is used as keyA, the ciphertext obtained by encrypting the symmetric key with A's public key is used as valueA; when the email of user B is used as keyB, the ciphertext obtained by encrypting the symmetric key with B's public key is used as valueB.

[0029] The specific method of step 5 is as follows: The user receives the encrypted email information and views the email in an unreadable state on the Web side of the third-party email server. At this time, the browser plugin side is used to download and read the email; the user opens the email to be decrypted and then clicks the decryption button; the background service of the browser plugin side has been listening for the request information sent by the Web side of the third-party email service provider, and filters out the eligible HTTPS requests according to the URL matching rules set in the chrome.webRequest.onBeforeRequest interface, extracts the required session ID parameter (SID) and the unique email identifier (mid) using regular expressions, and then obtains the corresponding email download request through the session ID parameter (SID) and the unique email identifier (mid), and downloads the corresponding encrypted email to the local of the plugin side; after receiving the ciphertext information, the encryption type, symmetric key ciphertext, signature information, and email content ciphertext are extracted respectively according to the fields including Content-Type, keydata, Signature, and Ciphertext; the user obtains the corresponding symmetric key ciphertext information value with the email logged in by himself as the key from the keydata; then the user inputs the key phrase set by himself to decrypt the user private key stored on the browser side, and after obtaining the private key, uses the user's private key to decrypt the symmetric key ciphertext value; then uses the symmetric key to decrypt the email content ciphertext to obtain the email plaintext information; and queries the public key of the sender to verify the signature information to ensure that the email has not been damaged during the transmission process.

[0030] Compared with the prior art, the present invention has the following advantages:

[0031] 1. The present invention completes the login process of the plugin by sending a security verification code email from the server side. After successful login, the plugin will obtain the corresponding encryption certificate from the server side according to the password algorithm selected by the user, and verify and securely store the certificate. Compared with the way in the prior art where users need to manually apply for or import certificates, the operation is simpler and the user experience is better.

[0032] 2. In the present invention, the plugin acts as an intermediary between the email Web client and the email server, uniformly performs the encryption operation of the email through a custom writing interface, and constructs an email sending request for email transmission. When receiving an email, the plugin will pull the email content and perform decryption processing. The plugin, as an intermediary, completes the email sending and receiving, encryption and decryption work between the plugin client and the email server, without modifying the email interface or network request, can provide a stable encryption and decryption function, and has strong scalability.

[0033] 3. The plugin does not need to directly modify or inject DOM elements of the original email page, but realizes the function by creating independent pop-ups that are completely isolated from the web page DOM. These pop-ups only run in the plugin environment and have high security. The content of the pop-up is completely controlled by the plugin, which can effectively avoid the risk of XSS attacks caused by web page interaction.

[0034] 4. The plugin provides users with a variety of encryption algorithms and technologies that meet China's information security standards. Users can flexibly switch the encryption and decryption solutions according to actual needs, simplify the encryption process through one-key operation, and ensure the security and compliance of data at the same time.

[0035] 5. The user's private key is encrypted through a custom key phrase and securely stored in the browser. Only when performing encryption and decryption operations, the private key will be decrypted and loaded into memory. After the operation is completed, the private key and related data will be immediately destroyed, so as to maximize the security of the private key storage process and avoid potential leakage risks.

[0036] In summary, the present invention uses a browser plugin as an intermediary between the Web-side email system and the email server to assist in completing the encryption and decryption operations of emails in a non-invasive manner; the user operation is simple, and only simple adaptation is required to be compatible with most email manufacturers, enhancing the versatility and easy expandability of the plugin; the encryption and decryption operations of emails are all carried out locally by the plugin intermediary, protecting user privacy and reducing the risk of security leakage; by establishing its own PKI system, the cost of users applying for and managing certificates is reduced, and the usability of the encryption plugin is increased; a variety of optional encryption methods suitable for China's mainstream encryption algorithms are provided for users. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 This is the overall structure diagram of the present invention.

[0038] Figure 2 This is the flowchart of the encryption plug-in login and authentication in the present invention.

[0039] Figure 3 This is the flowchart of email encryption in the present invention.

[0040] Figure 4 This is the flowchart of email decryption in the present invention.

[0041] Figure 5 This is the login and authentication interface for users.

[0042] Figure 6 The server sends a verification code email to the user and prompts the plug-in side that the verification code has been sent successfully.

[0043] Figure 7 The user views the email box of the third-party email service provider corresponding to the account to obtain the verification code content.

[0044] Figure 8 The user initiates a login and authentication operation to the server, and the server returns a successful login message after verification.

[0045] Figure 9 The user opens the letter-writing interface provided by the browser plug-in side to complete the writing of the email.

[0046] Figure 10 After the user finishes writing the email, the email information content is encrypted and the email is sent.

[0047] Figure 11 The web side of the third-party email service provider corresponding to the recipient receives the encrypted email information but cannot view the content.

[0048] Figure 12 The browser plug-in side downloads the encrypted email selected by the user from the server side of the third-party email service provider to the local of the plug-in side.

[0049] Figure 13 The browser plug-in side decrypts the downloaded email ciphertext and loads the decrypted content onto the letter-reading interface provided by the plug-in side. Detailed implementation manner

[0050] The present invention will be further described in detail below with reference to the accompanying drawings.

[0051] As Figure 1As shown in the figure, a general email encryption and decryption mediation system based on a browser plugin, comprising: a browser plugin side and a server side; the browser plugin side includes a user account management module, a plugin encryption module, and a plugin decryption module;

[0052] The user account management module is responsible for account login, switching, and logout operations, and performs full life cycle management on the key or digital certificate bound to the account, including generation, storage, use, and destruction;

[0053] The function of the plugin encryption module is divided into two stages: email content encryption and ciphertext sending. In the email content encryption stage, the user composes the email content in a unified writing interface. After clicking the send button, the browser plugin reads the email text, performs a digest signature on the plaintext, and uses the digital envelope mechanism to encrypt the plaintext content to generate ciphertext information C and signature information S. In the ciphertext sending stage, it is completed by the Service Worker in the background of the browser plugin: before using the browser plugin, the user first logs in to the Web side of the corresponding third-party email service provider. The browser plugin uses the chrome.webRequest.onBeforeRequest interface to listen for the request information sent by the Web side of the third-party email service provider in real time, filters out the required request information according to the filtering rules set in the onBeforeRequest interface, extracts the session ID parameter, and then constructs and sends a request carrying the encrypted email in the plugin encryption module using this parameter, pushing the ciphertext email to the server of the third-party email service provider;

[0054] The function of the plugin decryption module includes two parts: ciphertext download and decryption display. In the ciphertext download part, after the user selects the email to be decrypted, the browser plugin side listens and filters the requests sent by the user operation through the chrome.webRequest.onBeforeRequest interface, extracts the session ID and the unique email identifier, constructs a download request and obtains the ciphertext email. In the decryption display part, after clicking the "Decrypt" button, the browser plugin decrypts the ciphertext C and verifies the signature S. If the signature verification passes, the plaintext content is displayed on the interface; if the signature verification fails, the user is prompted;

[0055] The server side includes a business server, a Key Generation Center (KGC) server, a key management server, a Certificate Authority (CA) server, and a mail server. Among them, the business server serves as the traffic entrance of the entire server side, processes user requests, and realizes the transfer and delivery of requests. The Key Generation Center (KGC) server provides services including system parameter generation and user private key calculation. The key management server provides services including user identity management and key validity query, and provides functions for key application and revocation. The CA server provides services including certificate distribution and certificate validity query. The mail server provides services including verification code distribution and mail forwarding. The browser plugin side and the server side cooperate through a communication interface to ensure end-to-end encryption for users and guarantee the stable operation of the entire encrypted email system.

[0056] The third-party mail service providers include 163 NetEase Mail and QQ Mail.

[0057] The specific method for the browser plugin side and the server side to cooperate through a communication interface is as follows: The browser plugin side is responsible for front-end interaction, content encryption and decryption operations, and initiates requests for key application, certificate verification, and encrypted mail sending according to the user's operations on the browser plugin side. The server side provides services including system parameter generation, user key calculation, certificate distribution verification, key status query, and mail transfer according to the requests, realizing an end-to-end secure mail communication system.

[0058] A general email encryption and decryption mediation method based on a browser plugin specifically includes the following steps:

[0059] Step 1: The user installs the browser plugin provided by the mediation system, enters the browser plugin account login interface, and directly uses the email account of the third-party mail service provider to log in and authenticate. After logging in, the browser plugin side is authorized. There is no need to perform additional account registration work. This process is realized by sending a verification code to the email account entered by the user during login and entering the email account and verification code on the browser plugin side of this system. The flowchart of plugin login and identity authentication is as attached Figure 2 。

[0060] Step 2: After the login authorization is completed, the browser plugin side displays an encryption algorithm selection interface for the user. The user selects the traditional national cryptographic algorithm SM2 or SM3 or SM4 based on certificates, or selects the identity-based national cryptography SM9 algorithm without certificates for subsequent email encryption, decryption, and signature work.

[0061] Step 3: When the browser plugin detects the encryption type selected by the user, it first generates a certificate application request locally and sends the request to the CA server. After the CA server detects the user request and issues an encryption certificate for the user, and after the plugin obtains the encryption certificate and verifies that the encryption certificate is accurate, it securely saves the encryption certificate locally to complete the login plugin. The specific method is as follows: When the user selects the traditional national cryptography algorithm, the browser plugin generates a certificate application request locally and then submits the request to the CA server. After the CA server detects the user request and issues an encryption certificate for the user, and after the plugin obtains the encryption certificate and verifies that the encryption certificate is accurate, it securely saves the encryption certificate locally. When the user selects the identity-based SM9 encryption algorithm, the browser plugin first sends a request to the KGC server to obtain system parameters and public master key information. After the KGC server verifies the user's identity, it returns the system parameters and public master key stored on the server. Then, the browser plugin sends a request to the KGC for the user's private key, carrying the user's unique identity information (in the design of this system, this identity information is the email account). The KGC server generates a private key for the user based on the identity information and returns it.

[0062] Step 4, after the plug-in login is completed, ensure that the plug-in login account is the same as the logged-in email account. Then, compose and encrypt the email and send the email. The specific method is as follows: Log in to the plug-in, then select the encryption scheme, click the write email button to enter the email composition interface of the browser plug-in to compose the email. At this time, the browser plug-in automatically generates a symmetric key to encrypt the text and attachment information of the email. The browser plug-in extracts the content of the email from the email composition page and encrypts the email content using the symmetric key just generated. To ensure the security of the symmetric key, the browser plug-in also sequentially queries the public keys of the recipients and encrypts the symmetric key using the public key of each recipient. At this time, the encrypted email content information C1 and the encrypted session key information C2 (C2 is a collection of ciphertexts obtained by encrypting the symmetric key with the public keys of several recipients) are obtained. To ensure the integrity and non-repudiation of the email content, before the symmetric key encrypts the email content, the private key of the user logged in to the current browser plug-in is first used to sign the email plaintext digest. The user's private key is encrypted and stored in the browser by the user's custom setting of the key phrase. The user enters the key phrase to decrypt the private key ciphertext. After loading it into the memory, the private key is used to sign the email plaintext digest to obtain the signature information S. After use, the private key information is destroyed from the memory. Then, fill in the selected encryption type in the Content-Type field, fill in the encrypted session key information C2 in the keydata field (the content of the keydata field exists in the form of key-value. When the email of user A is used as keyA, the ciphertext obtained by encrypting the symmetric key with A's public key is used as valueA; when the email of user B is used as keyB, the ciphertext obtained by encrypting the symmetric key with B's public key is used as valueB), fill in the encrypted email content information C1 in the Ciphertext field, and fill in the signature information S in the Signature field. Then, assemble the final email content to be sent in the order of Content-Type, keydata, Signature, and Ciphertext. The flowchart of email encryption is shown in the appendix Figure 3 as follows.

[0063] Because before logging into the browser plug-in of the system, you need to log in to the corresponding third-party email service provider's Web end first, after the browser plug-in logs in successfully, it will call the chrome.webRequest.onBeforeRequest interface through the background service to monitor the request information sent by the third-party email service provider's Web end in real time, filter out the request information that meets the requirements according to the filtering rules set in the onBeforeRequest interface, and extract the session ID parameter; then the browser plug-in acts as an intermediary to interact with the third-party email service provider's server on behalf of the third-party email service provider's Web end, use the session ID parameter to construct an HTTPS request, complete the sending of encrypted emails, and push the assembled email content to the third-party email service provider's server.

[0064] Step 5, the user receives the email, and uses the browser plug-in as an intermediary to assist in downloading and decrypting the email; the specific method is: the user receives the encrypted email information, and checks the email on the third-party email server web side and finds that the email is in an unreadable state. At this time, the browser plug-in is used to download and read the email; the user opens the email to be decrypted, and then clicks the decryption button; the background service of the browser plug-in has been monitoring the request information sent by the third-party email service provider's web side, and filters out the HTTPS requests that meet the requirements according to the URL matching rules set by the chrome.webRequest.onBeforeRequest interface, and uses regular expressions to extract the required session ID parameter (SID) and email unique identifier (mid), and then uses the session ID parameter (SID) and email unique identifier The plugin obtains the corresponding email download request through the browser, and downloads the encrypted email to the local plug-in. After receiving the ciphertext information, the plugin extracts the encryption type, symmetric key ciphertext, signature information, and email content ciphertext according to the Content-Type, keydata, Signature, and Ciphertext fields. The user uses the mailbox he logged in as the key in keydata to obtain the corresponding symmetric key ciphertext information value. The user then enters the key phrase he set to decrypt the user's private key stored on the browser. After obtaining the private key, the user uses the user's private key to decrypt the symmetric key ciphertext value. The symmetric key is then used to decrypt the email content ciphertext to obtain the email plaintext information. The sender's public key is then queried to verify the signature information to ensure that the email has not been damaged during transmission. The email decryption flow chart is as follows: Figure 4 shown.

[0065] The effect of the present invention can be further verified by the following experiments:

[0066] The present invention initiates a verification code login request (such asFigure 5 As shown in [figure], after receiving the request, the server generates a verification code and sends it to the user's email (such as Figure 6 , Figure 7 As shown in [figure]). After the user enters the verification code to complete login and identity authentication (such as Figure 8 As shown in [figure]), the user can use all the functions provided by the plugin. This login process does not require the user to register an account separately on the plugin side. The user only needs to log in with a third-party email account, which is simple to operate and user-friendly.

[0067] After identity authentication, the user can independently select the traditional national cryptography algorithms (SM2 / SM3 / SM4) or the SM9 algorithm based on identity identification according to the plugin prompts. The system will automatically complete the generation and management of keys or certificates according to the user's selection, eliminating the need for manual configuration operations, significantly reducing the usage threshold, and improving usability. At the same time, the system fully supports national cryptography algorithms, complies with national cryptographic standards, and enhances the compliance and practicality of the solution.

[0068] The user edits the email content in the unified email writing interface provided by the browser plugin (such as Figure 9 As shown in [figure]). After completion of editing, the user clicks the "Send" button. The plugin will automatically encrypt the email content and send the encrypted email to the server of the third-party email service provider (such as Figure 10 As shown in [figure]). The recipient receives the encrypted email on the Web side of the third-party email service provider but cannot directly view the email content (such as Figure 11 As shown in [figure]) and needs to use the decryption function provided by the plugin to read it.

[0069] When the user selects the email to be decrypted and clicks the "Decrypt" button in the plugin, the plugin will download the encrypted email from the email service provider's server to the local (such as Figure 12 As shown in [figure]) and perform the decryption operation locally, rendering the decrypted plaintext content to the email reading interface provided by the plugin (such as Figure 13 As shown in [figure]).

[0070] During the entire email encryption and decryption process, the system provides the user with a unified email writing and reading interface, without modifying the DOM structure of the third-party email service provider's Web side, achieving non-intrusive access of the plugin to the email platform, with good platform adaptability and high maintainability.

Claims

1. A general email encryption and decryption mediation system based on a browser plugin, characterized in that Including: A browser plugin side and a server side; the browser plugin side includes a user account management module, a plugin encryption module, and a plugin decryption module; The user account management module is responsible for account login, switching, and logout operations, and performs full life cycle management on the secret key or digital certificate bound to the account, including generation, storage, use, and destruction; The function of the plugin encryption module is divided into two stages: email content encryption and ciphertext sending: in the email content encryption stage, the user composes the email content in a unified writing interface. After clicking the send button, the browser plugin reads the email text, performs a digest signature on the plaintext, and uses the digital envelope mechanism to encrypt the plaintext content to generate ciphertext information C and signature information S; The ciphertext sending stage is completed by the Service Worker in the background of the browser plugin: before using the browser plugin, the user logs in to the Web side of the corresponding third-party email service provider. The browser plugin uses the chrome.webRequest.onBeforeRequest interface to listen for the request information sent by the third-party email service provider's Web side in real time, filters out the required request information according to the filtering rules set in the onBeforeRequest interface, extracts the session ID parameter therein, and then constructs and sends a request carrying the encrypted email in the plugin encryption module by using this parameter, pushing the ciphertext email to the server of the third-party email service provider; The function of the plugin decryption module includes two parts: ciphertext download and decryption display: in the ciphertext download part, after the user selects the email to be decrypted, the browser plugin side listens for and filters the requests sent by the user operation through the chrome.webRequest.onBeforeRequest interface, extracts the session ID and the unique email identifier, constructs a download request and obtains the ciphertext email; In the decryption display part, after clicking the "Decrypt" button, the browser plugin decrypts the ciphertext C and verifies the signature S. If the signature verification passes, the plaintext content is displayed on the interface; if the signature verification fails, the user is prompted; The server side includes a business server, a Key Generation Center (KGC) server, a key management server, a Certificate Authority (CA) server, and an email server; among them, the business server serves as the traffic entrance of the entire server side, processes user requests and realizes the transfer and delivery of requests; the Key Generation Center (KGC) server provides services including system parameter generation and user private key calculation; the key management server provides services including user identity identification management, key validity query, and provides key application and revocation functions; the CA server provides services including certificate distribution and certificate validity query; the email server provides services including verification code distribution and email forwarding; the browser plugin side and the server side cooperate through a communication interface; ensuring that users achieve end-to-end encryption and guaranteeing the stable operation of the entire encrypted email system.

2. The general email encryption and decryption mediation system based on browser plug-in according to claim 1, characterized in that The third-party email service providers include 163 NetEase Mail and QQ Mail.

3. The general email encryption and decryption mediation system based on browser plug-in according to claim 1, characterized in that, The specific method for the browser plugin side and the server side to achieve collaboration through the communication interface is as follows: The browser plugin side is responsible for front-end interaction, content encryption and decryption operations, and initiates key application, certificate verification, and encrypted email sending requests according to the user's operations on the browser plugin side; the server side provides services including system parameter generation, user key calculation, certificate distribution and verification, key status query, and email relay respectively according to the requests, to implement an end-to-end secure email communication system.

4. A general method for encrypting and decrypting emails based on browser plugins, characterized in that, Specifically, it includes the following steps: Step 1, the user installs the browser plugin provided by the intermediary system, enters the browser plugin account login interface, and the user directly uses the email account of the third-party email service provider for login and identity verification. After login, the authorization of the browser plugin side is completed; there is no need to perform additional account registration work; Step 2, after the login authorization is completed, the browser plugin side displays an encryption algorithm selection interface for the user. The user selects the traditional national cryptographic algorithm SM2 or SM3 or SM4 based on the certificate, or selects the identity-based national cryptographic SM9 algorithm without a certificate for subsequent email encryption, decryption, and signature work; Step 3, the browser plugin monitors the selected encryption type, first generates a certificate application request locally, and sends the request to the CA server; after the CA server monitors the user's request, it issues an encryption certificate for the user. After the plugin obtains the encryption certificate and verifies that the encryption certificate is accurate, it securely saves the encryption certificate locally to complete the login of the plugin; Step 4, after the login of the plugin is completed, ensure that the plugin login account is consistent with the logged-in email account. Then, compose and encrypt an email and send the email; Step 5, the user receives the email, and uses the browser plugin as an intermediary to assist in downloading and decrypting the email.

5. The general email encryption and decryption mediation method based on a browser plug-in according to claim 4, characterized in that, The specific method of the said Step 3 is as follows: When the user selects the traditional national cryptographic algorithm, the browser plugin side generates a certificate application request locally, and then submits the request to the CA server; after the CA server monitors the user's request, it issues an encryption certificate for the user. After the plugin obtains the encryption certificate and verifies that the encryption certificate is accurate, it securely saves the encryption certificate locally; when the user selects the identity-based SM9 encryption algorithm, the browser plugin side first sends a request to the KGC server to obtain system parameters and public master key information. After the KGC server verifies the user's identity, it returns the system parameters and public master key stored on the server; then the browser plugin side sends a request to the KGC for the user's private key carrying the user's unique identity information, and the KGC server generates a private key for the user according to the identity information and returns it.

6. The general e-mail encryption and decryption mediation method based on browser plug-in according to claim 4, characterized in that The specific method of step 4 is as follows: Log in to the plugin, then select the encryption scheme, click the write email button to enter the email writing interface of the browser plugin to compose an email. At this time, the browser plugin automatically generates a symmetric key to encrypt the text and attachment information of the email; the browser plugin extracts the content of the email from the email writing page and encrypts the email content with the symmetric key just generated. To ensure the security of the symmetric key, the browser plugin also sequentially queries the public keys of the recipients and encrypts the symmetric key with each recipient's public key. At this time, the encrypted email content information C1 and the encrypted session key information C2 are obtained; to ensure the integrity and non-repudiation of the email content, before the symmetric key encrypts the email content, first use the private key of the user who logs in to the current browser plugin to sign the email plaintext digest. The user's private key is encrypted and stored in the browser by the user's custom setting of the key phrase. The user enters the key phrase to decrypt the private key ciphertext, loads it into the memory, and then uses the private key to sign the email plaintext digest to obtain the signature information S. After use, the private key information is destroyed from the memory; then fill in the selected encryption type into the Content-Type field, fill in the encrypted session key information C2 into the keydata field, fill in the encrypted email content information C1 into the Ciphertext field, and fill in the signature information S into the Signature field; then assemble the final email content to be sent in the order of Content-Type, keydata, Signature, and Ciphertext in sequence. After the browser plugin logs in successfully, it will call the chrome.webRequest.onBeforeRequest interface through the background service to listen for the request information sent by the Web side of the third-party email service provider in real time, screen out the request information that meets the requirements according to the filtering rules set in the onBeforeRequest interface, and extract the session ID parameter therein; then the browser plugin acts as an intermediary to interact with the server of the third-party email service provider on behalf of the Web side of the third-party email service provider, constructs an HTTPS request using the session ID parameter, completes the sending of the encrypted email, and pushes the assembled email content to the server of the third-party email service provider.

7. A general email encryption and decryption mediation method based on a browser plugin according to claim 6, characterized in that, The encrypted session key information C2 is a collection of ciphertexts obtained by encrypting the symmetric key with the public keys of several recipients respectively.

8. A general email encryption and decryption mediation method based on a browser plugin according to claim 6, characterized in that, The content of the keydata field exists in the form of key-value. When the email address of user A is used as keyA, the ciphertext obtained by encrypting the symmetric key with A's public key is used as valueA; when the email address of user B is used as keyB, the ciphertext obtained by encrypting the symmetric key with B's public key is used as valueB.

9. A general email encryption and decryption mediation method based on a browser plugin according to claim 4, characterized in that, The specific method of step 5 is as follows: When the user receives the encrypted email information and views the email in an unreadable state on the web side of the third-party email server, the browser plugin side is used to download and read the email at this time; the user opens the email to be decrypted and then clicks the decryption button; the background service of the browser plugin side has been listening to the request information sent by the web side of the third-party email service provider, and filters out the eligible HTTPS requests according to the URL matching rules set by the chrome.webRequest.onBeforeRequest interface, uses regular expressions to extract the required session ID parameter (SID) and the email unique identifier (mid), and then obtains the corresponding email download request through the session ID parameter (SID) and the email unique identifier (mid), and downloads the corresponding encrypted email to the local of the plugin side; after receiving the ciphertext information, the encryption type, the symmetric key ciphertext, the signature information, and the email content ciphertext are respectively extracted according to the fields including Content-Type, keydata, Signature, and Ciphertext; the user uses the email logged in by himself as the key in keydata to obtain the corresponding symmetric key ciphertext information value; then the user inputs the key phrase set by himself to decrypt the user private key stored on the browser side, and after obtaining the private key, the user's private key is used to decrypt the symmetric key ciphertext value; Then the symmetric key is used to decrypt the email content ciphertext to obtain the email plaintext information; And query the public key of the sender to verify the signature information to ensure that the email has not been damaged during the transmission process.