Browser digital content real-time decryption method and system

Through the combination of cloud encryption and WebAssembly decryption engine, the performance bottlenecks and security issues in browser digital copyright management are solved, and efficient and secure digital content decryption is achieved, adapting to network and device changes, improving decryption efficiency, and supporting real-time decryption of high-code rate media streams.

CN120416591APending Publication Date: 2025-08-01浪潮智能终端有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510357696.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing browser digital copyright management methods have performance bottlenecks, security defects, poor compatibility and inability to dynamically respond to network fluctuations or device performance changes, especially in the real-time decryption process of high-code rate media streams, resulting in low execution efficiency of browser-side JavaScript, high CPU usage, insufficient security and poor compatibility.

Method used

The method of combining cloud encryption and WebAssembly decryption engine is adopted, and the encrypted media extension interface EME API is used to verify user permissions through the WebSocket protocol, SIMD parallel decryption is used to dynamically monitor the system load to adjust the number of parallel blocks, and optimize the decryption process in combination with machine learning.

Benefits of technology

It realizes efficient and secure cross-platform digital content decryption, improves decryption efficiency, adapts to network and device changes, protects data from malicious modification, supports real-time decryption of high-code media streams, and reduces CPU usage and playback lag.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416591A_ABST
    Figure CN120416591A_ABST
Patent Text Reader

Abstract

The invention particularly relates to a browser digital content real-time decryption method and system. The browser digital content real-time decryption system comprises a cloud strategy server, a content encryption module, a decryption engine loading and initializing module, an SIMD parallel decryption module and a performance monitoring and adjusting module. According to the browser digital content real-time decryption method and system, cross-platform and transportability design is achieved, data can be protected from being maliciously modified by other programs through a WebAssembly sandbox mechanism, decryption operation can be executed on multiple data blocks at the same time, algorithms are dynamically switched according to scenes, the method and system are suitable for batch decryption of data, and the decryption efficiency is improved. And the decryption efficiency is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital rights management, and particularly relates to a method and system for real-time decryption of digital content in a browser. Background Art

[0002] In today's digital age, the dissemination and use of digital content have become increasingly convenient. However, this has also brought challenges to digital rights protection. Many traditional browser digital rights management methods rely on specific software or hardware, which brings inconvenience to users. At the same time, with the rapid development of the Internet and intelligent devices, people are increasingly inclined to access digital content through devices such as computers or mobile phones. Therefore, a more convenient, efficient and secure digital rights management method is needed. And the existing browser digital content decryption technology has the following problems:

[0003] 1). Performance bottleneck: The execution efficiency of the decryption algorithm by JavaScript on the browser side is low, and it is difficult to support the real-time decryption of high-bitrate media streams, resulting in high CPU occupancy and playback stuttering.

[0004] 2). Security defects: Keys and algorithm logics in the browser environment are easily stolen by reverse engineering or debugging tools. JavaScript code is easily reverse-cracked, and the risk of exposure of the key management logic is high, making it difficult to resist attacks such as memory sniffing and debugging injection.

[0005] 3). Poor compatibility: Deeply bound to the browser, with poor compatibility.

[0006] 4). There are problems such as being unable to dynamically respond to network fluctuations or device performance changes.

[0007] In order to solve the above problems, the present invention proposes a method and system for real-time decryption of digital content in a browser. Summary of the Invention

[0008] The present invention provides a simple and efficient method and system for real-time decryption of digital content in a browser to make up for the defects of the prior art.

[0009] The present invention is implemented by the following technical solutions:

[0010] A method for real-time decryption of digital content in a browser includes the following steps:

[0011] Step S1, using an encryption algorithm to encrypt media content on a cloud server and generating corresponding keys and licenses;

[0012] Step S2, the client passes through a specific tag <video>Load encrypted media content;

[0013] Step S3: After detecting the encrypted content using the Encrypted Media Extensions (EME) API, trigger a Digital Rights Management (DRM) initialization request;

[0014] Step S4: Download the WebAssembly decryption engine (***.wasm file) and the policy file from the cloud server. Since the WebAssembly decryption engine is in binary format and can run directly in the browser's execution space, initialize the WebAssembly decryption engine through JavaScript code and bind it to the Encrypted Media Extensions (EME) API;

[0015] Step S5: The browser sends an authorization request to the license server via the WebSocket protocol. The authorization request carries the browser instance hash value or device fingerprint for verifying the user's access rights;

[0016] Step S6: After receiving the request, the license server verifies its legitimacy and returns the Content Encryption Key (CEK) for the encrypted content. After decryption, it is injected into the WebAssembly secure memory area;

[0017] Step S7: The WebAssembly decryption engine parses the media stream fragments and chunks them, and uses Single Instruction Multiple Data (SIMD) instructions to decrypt the data chunks in parallel;

[0018] Step S8: The WebAssembly decryption engine dynamically monitors the system load and dynamically adjusts the number of parallel chunks according to the system load;

[0019] Step S9: Output the decrypted media content to the buffer, and decode and render it through the player.

[0020] In step S2, the user opens the browser and accesses a custom-specified website. The browser downloads the web page and parses it to find a specific HTML5 tag <video>, and then parse <source> the tag to obtain the download address, and then download the encrypted media stream from the download address.

[0021] In the step S4, the policy file contains the selection of the decryption algorithm and the key management rule information to ensure that the media content can be processed according to the predefined security policy;

[0022] After the browser downloads the WebAssembly decryption engine (***.wasm file), the WebAssembly.instantiateStreaming method is used to obtain the binary content of the WebAssembly decryption engine; after obtaining the WebAssembly decryption engine, it is instantiated, and the instantiation process includes compiling and initializing the module; after the instantiation is completed, the browser accesses the functions and variables exported by the WebAssembly decryption engine through Javascript.

[0023] In the step S6, the license server generates a license containing the content encryption key, and sends the generated license back to the client after being encrypted;

[0024] The client decrypts the license using the Web Crypto API, extracts the key, and securely stores the extracted key in the isolated memory space of the WebAssembly encryption engine to prevent it from being accessed by other scripts.

[0025] In the step S7, before decryption, the WebAssembly decryption engine parses the media stream shards, identifies the boundaries of each media stream shard, extracts the encrypted metadata, and determines the frame structure within the shard;

[0026] [[ID=2-0]]To make full use of the advantages of the SIMD instruction set, the media stream data is segmented according to the bit width value corresponding to the encryption algorithm in the policy file, and the data of each media stream shard is segmented into several data blocks of a specified size.

[0027] [[ID=?3]]In the step S7, if the cloud server uses the AES encryption algorithm to encrypt the media content, the bit width specified in the policy file is 128 bits;

[0028] The SIMD bit width is 128 bits, and the WebAssembly decryption engine uses the v128 type and related built-in functions to achieve efficient data processing; load 128-bit data blocks from memory with v128.load, and write the processed results back to memory through v128.store;

[0029] For the encrypted content of the AES algorithm, the WebAssembly decryption engine uses the v128.aes_decrypt instruction to perform parallel decryption. It should be noted that there seems to be an error in the "ID=2-0" in the original text. It should probably be "ID=20". This has been corrected in the translation.

[0030] In step S7, the SIMD instruction set includes but is not limited to v128.load, v128.store, and vl28.aes_decrypt, which are used to efficiently perform AES decryption operations.

[0031] In step S8, when the WebAssembly decryption engine decrypts digital content, it monitors the CPU utilization rate, memory usage, and the status of other custom critical resources in real time; according to the results of the real-time monitoring, it dynamically adjusts the number of data blocks processed simultaneously according to the data block adjustment rules recorded in the policy file to balance the relationship between the decryption speed and system stability.

[0032] The WebAssembly decryption engine introduces a feedback loop and a machine learning mechanism. By recording the changes in performance metrics after each adjustment, it establishes a machine learning model to predict future adjustment behaviors and makes decisions based on this to automatically discover the optimal parallelism settings and other optimization strategies.

[0033] A real-time decryption system for browser digital content for implementing the above method, including a cloud policy server, a content encryption module, a decryption engine loading and initialization module, a SIMD parallel decryption module, and a performance monitoring and adjustment module;

[0034] The cloud policy server: is used to issue update instructions, such as switching algorithms, key rotation, etc., to implement the hot update decryption logic of the WebAssembly decryption engine without restarting the WebAssembly decryption engine;

[0035] The content encryption module: is used to encrypt digital content using an encryption algorithm on the cloud server and generate corresponding keys and licenses;

[0036] The decryption engine loading and initialization module: is used to download the WebAssembly decryption engine (***.wasm file) and the policy file from the cloud server and load and initialize the WebAssembly encryption engine through JavaScript code;

[0037] The SIMD parallel decryption module: is used to slice the media content parsed by the WebAssembly decryption engine, align and block it according to the SIMD bit width, and call the SIMD instructions to decrypt the data blocks in parallel;

[0038] The performance monitoring and adjustment module: is used to dynamically monitor the system load and dynamically adjust the number of parallel blocks according to the data block adjustment rules recorded in the policy file.

[0039] A real-time decryption device for browser digital content, characterized in that it includes a memory and a processor; the memory is used to store computer programs, and the processor is used to implement the above method steps when executing the computer programs.

[0040] A readable storage medium, characterized in that a computer program is stored on the readable storage medium, and the computer program implements the above method steps when executed by a processor.

[0041] The beneficial effects of the present invention are as follows: The real-time decryption method and system for browser digital content achieve cross-platform and portable design. It can not only use the sandbox mechanism of WebAssembly to protect data from being maliciously modified by other programs, but also perform decryption operations on multiple data blocks simultaneously, and dynamically switch algorithms according to the scenario, which is suitable for batch decryption of data and effectively improves the decryption efficiency. Description of the Drawings

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0043] Appendix Figure 1 It is a schematic diagram of the real-time decryption process of the browser digital content of the present invention. Detailed Embodiments

[0044] In order to enable those skilled in the art of the present technology to better understand the technical solutions in the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0045] WebAssembly is a low-level programming language that can run in modern browsers, with characteristics such as high efficiency, security, and portability.

[0046] The real-time decryption method for browser digital content includes the following steps:

[0047] Step S1, encrypt the media content using an encryption algorithm on the cloud server, and generate corresponding keys and licenses;

[0048] Step S2, the client passes through a specific tag <video>Load encrypted media content;

[0049] Step S3: After detecting the encrypted content using the Encrypted Media Extensions (EME) API, trigger a Digital Rights Management (DRM) initialization request;

[0050] Step S4: Download the WebAssembly decryption engine (***.wasm file) and the policy file from the cloud server. Since the WebAssembly decryption engine is in binary format and can run directly within the browser's execution space, initialize the WebAssembly decryption engine through JavaScript code and bind it to the Encrypted Media Extensions (EME) API;

[0051] Step S5: The browser sends an authorization request to the license server via the WebSocket protocol. The authorization request carries the browser instance hash value or device fingerprint for verifying the user's access rights;

[0052] Step S6: After receiving the request, the license server verifies its legitimacy and returns the Content Encryption Key (CEK) for the encrypted content. After decryption, it is injected into the WebAssembly secure memory area;

[0053] Step S7: Divide the media stream into multiple small segments. Each segment contains several frames of data. These segments can be based on time (one segment per second) or based on size (one segment per 5MB). The WebAssembly decryption engine parses the media stream segments and chunks them, and uses Single Instruction Multiple Data (SIMD) instructions to decrypt the data chunks in parallel;

[0054] Step S8: The WebAssembly decryption engine dynamically monitors the system load and adjusts the number of parallel chunks dynamically according to the system load;

[0055] Step S9: Output the decrypted media content to the buffer, and decode and present it through the player.

[0056] In step S2, the user opens the browser and accesses a custom-specified website. The browser downloads the web page and parses it to find a specific HTML5 tag <video>, and then parse <source> the tag to obtain the download address, and then download the encrypted media stream from the download address.

[0057] In step S4, the policy file contains the selection of the decryption algorithm and the key management rule information to ensure that the media content can be processed according to the predefined security policy;

[0058] After the browser downloads the WebAssembly decryption engine (***.wasm file), the binary content of the WebAssembly decryption engine is obtained through the WebAssembly.instantiateStreaming method; after obtaining the WebAssembly decryption engine, it is then instantiated, and the instantiation process includes compiling and initializing the module; after the instantiation is completed, the browser accesses the functions and variables exported by the WebAssembly decryption engine through Javascript.

[0059] In step S6, the license server generates a license containing the content encryption key, and sends the generated license back to the client after encryption;

[0060] The client decrypts the license using the Web Crypto API, extracts the key, and securely stores the extracted key in the isolated memory space of the WebAssembly encryption engine to prevent it from being accessed by other scripts.

[0061] In step S7, before decryption, the WebAssembly decryption engine parses the media stream shards, identifies the boundaries of each media stream shard, extracts the encrypted metadata, and determines the frame structure within the shard;

[0062] In order to make full use of the advantages of the SIMD instruction set, the media stream data is segmented according to the bit width value corresponding to the encryption algorithm in the policy file, and the data of each media stream shard is segmented into several data blocks of a specified size.

[0063] In step S7, if the cloud server uses the AES encryption algorithm to encrypt the media content, 128-bit width is a natural choice because the AES standard supports key lengths of 128 bits, 192 bits, and 256 bits, and 128 bits is the most commonly used key length. The bit width specified in the policy file is 128 bits; in this way, it can be ensured that a complete AES block can be processed each time the SIMD instruction is called.

[0064] The SIMD bit width is 128 bits. The WebAssembly decryption engine uses the v128 type and related built-in functions to achieve efficient data processing; it loads a 128-bit data block from memory using v128.load and writes the processed result back to memory through v128.store;

[0065] For the encrypted content of the AES algorithm, the WebAssembly decryption engine uses the v128.aes_decrypt instruction to perform parallel decryption. This instruction can process multiple AES blocks within a single CPU cycle, greatly improving the processing speed.

[0066] The WebAssembly decryption engine uses multi-threaded parallel processing technology to further improve the decryption efficiency; for 4K / 8K high-bitrate media streams, within the capabilities allowed by the client device, multiple worker threads are created, and each thread is responsible for processing a part of the media stream shard, thereby significantly reducing the total decryption time.

[0067] In step S7, the SIMD instruction set includes but is not limited to v128.load, v128.store, and vl28.aes_decrypt, which are used to efficiently perform AES decryption operations.

[0068] In step S8, when the WebAssembly decryption engine decrypts digital content, it monitors the CPU utilization, memory usage, and the status of other custom critical resources in real time; according to the results of the real-time monitoring, it dynamically adjusts the number of data blocks processed simultaneously according to the data block adjustment rules recorded in the policy file;

[0069] In low-load situations, increase the number of data blocks processed in parallel to fully utilize the available computing resources; while in high-load or resource-constrained situations, reduce the parallelism to avoid over-occupying system resources and affecting other applications. This adaptive mechanism can effectively balance the relationship between decryption speed and system stability.

[0070] The WebAssembly decryption engine introduces a feedback loop and a machine learning mechanism. By recording the changes in performance metrics after each adjustment, it builds a machine learning model to predict future adjustment behaviors and makes better decisions accordingly. Through learning a large amount of actual operation data, it automatically discovers the optimal parallelism settings and other optimization strategies.

[0071] This browser digital content real-time decryption system, used to implement the above method, includes a cloud policy server, a content encryption module, a decryption engine loading and initialization module, a SIMD parallel decryption module, and a performance monitoring and adjustment module;

[0072] The cloud policy server: It is used to issue update instructions, such as switching algorithms, key rotation, etc., to implement the hot update decryption logic of the WebAssembly decryption engine without restarting the WebAssembly decryption engine;

[0073] The content encryption module: It is used to encrypt digital content using an encryption algorithm on the cloud server and generate corresponding keys and licenses;

[0074] The decryption engine loading and initialization module: It is used to download the WebAssembly decryption engine (***.wasm file) and policy files from the cloud server and load and initialize the WebAssembly encryption engine through JavaScript code;

[0075] The SIMD parallel decryption module: It is used to fragment the media content parsed by the WebAssembly decryption engine, align and block it according to the SIMD bit width, and call SIMD instructions to decrypt data blocks in parallel;

[0076] The performance monitoring and adjustment module: It is used to dynamically monitor the system load and dynamically adjust the number of parallel blocks according to the data block adjustment rules recorded in the policy file.

[0077] The WebAssembly decryption engine does not need to be installed in advance. When there is a decryption requirement, it can be downloaded from the cloud server in real time and loaded.

[0078] The SIMD parallel decryption module further includes multi-thread support to further accelerate the decryption process.

[0079] The real-time decryption system architecture of this browser digital content adopts a layered design, including:

[0080] The core layer (WebAssembly decryption engine): It is responsible for executing decryption algorithms, key management, and policy parsing; Develop decryption algorithms using the C++ language, and then compile them into the WebAssembly decryption engine, and use its execution efficiency close to native code to complete the real-time decryption of digital content.

[0081] The interface layer (browser interaction): Interact with the browser through the Encrypted Media Extensions API (EME API), receive encrypted data and output decrypted data to the buffer; Use the JavaScript Glue layer interface to implement the interaction between the browser and the WebAssembly decryption engine.

[0082] The policy control layer (cloud management): It is responsible for monitoring the real-time status of the device and issuing dynamic policies.

[0083] The encryption and content distribution process of the cloud policy server is as follows:

[0084] (1) The server uses an encryption algorithm to encrypt media stream shards and generate a content encryption key (CEK).

[0085] (2) The CEK is encrypted with the license server's public key and embedded in the video metadata.

[0086] (3) Bind device fingerprints, such as browser instance hash values or device TEE chip IDs, etc.

[0087] Client browser decryption process:

[0088] (1) The browser detects the encrypted stream and loads the WebAssembly decryption engine through the Encrypted Media Extensions API (EME API).

[0089] (2) Apply for authorization from the license server, decrypt the CEK, and inject it into the WebAssembly decryption engine's memory.

[0090] (3) Use SIMD instructions to decrypt the encrypted data.

[0091] (4) Dynamically monitor performance and trigger degradation or upgrade strategies (such as switching to a low-complexity SIMD algorithm).

[0092] This browser digital content real-time decryption device includes a memory and a processor; the memory is used to store computer programs, and the processor is used to implement the above method steps when executing the computer programs.

[0093] A computer program is stored on this readable storage medium, and when the computer program is executed by a processor, the above method steps are implemented.

[0094] Compared with the prior art, this browser digital content real-time decryption method and system have the following characteristics

[0095] First, the use of the SIMD instruction set improves the decryption efficiency.

[0096] The binary format of the WebAssembly decryption engine is close to native code, and its execution speed is 10 - 20 times faster than JavaScript. It is suitable for processing compute-intensive tasks, and the SIMD technology further improves the data processing efficiency. The server encrypts digital content using corresponding algorithms according to the client's SIMD parallel computing ability. After receiving the encrypted digital content, the client browser can use a single SIMD instruction to perform decryption operations on multiple data blocks simultaneously according to the algorithm rules agreed with the server, which is suitable for batch decryption of data and effectively improves the decryption efficiency. The core algorithm is as follows:

[0097] Algorithm parallelization transformation: Align and partition the data to be decrypted according to the SIMD bit width to eliminate redundant calculations;

[0098] Instruction set optimization: Use the WebAssembly SIMD instruction set to replace scalar operations to reduce the instruction cycle;

[0099] Dynamic bit width switching: Select the SIMD bit width according to the device performance. For example, 64 bits are used for low-end devices and 128 bits are used for high-end devices. During the decryption process, the device system load is monitored in real time, and the server is notified to adjust the encryption algorithm in real time, realizing the dynamic adjustment of the SIMD bit width.

[0100] Second, a security enhancement mechanism is implemented.

[0101] Use the "sandbox mechanism" of WebAssembly to run the decryption engine in an independent and isolated sandbox environment, which can protect data from being maliciously modified by other programs. At the same time, the decryption engine cannot access memory addresses outside its running boundary. This mechanism ensures that the decryption engine cannot directly access the resources of the host system, such as the file system, network interface, etc. All accesses to external resources need to be implemented by calling the APIs provided by the host system through JavaScript.

[0102] Multi-algorithm compatible architecture design: Multiple symmetric and asymmetric algorithms are integrated in the decryption engine, and the algorithms can be dynamically switched according to the scenario.

[0103] Anti-reverse engineering design: Obfuscate the WebAssembly binary, such as control flow flattening and instruction replacement, to increase the difficulty of reverse engineering.

[0104] Third, cross-platform and portability designs are implemented.

[0105] Utilize the platform-independent feature of the WebAssembly decryption engine's binary format. Only one set of decryption engines needs to be developed and deployed to the browsers of different devices without the need for adaptation for different platforms.

[0106] The embodiments described above are only one of the specific implementation manners of the present invention. The general changes and substitutions made by those skilled in the art within the scope of the technical solution of the present invention should be included in the protection scope of the present invention.< / video> < / video> < / video> < / video>

Claims

1. A real-time decryption method for browser digital content, characterized in that: It includes the following steps: Step S1, encrypt the media content using an encryption algorithm on the cloud server, and generate the corresponding key and license; Step S2, the client passes through a specific tag <video>Load the encrypted media content;< / video> Step S3, after detecting the encrypted content using the Encrypted Media Extensions (EME) API, trigger a Digital Rights Management (DRM) initialization request; Step S4, download the WebAssembly decryption engine and policy file from the cloud server, initialize the WebAssembly decryption engine through JavaScript code, and bind it to the Encrypted Media Extensions (EME) API; Step S5, the browser sends an authorization request to the license server through the WebSocket protocol of the network socket. The authorization request carries the browser instance hash value or device fingerprint to verify the user's access permission; Step S6, after receiving the request, the license server verifies its legality and returns the encrypted Content Encryption Key (CEK), which is decrypted and injected into the WebAssembly secure memory area; Step S7, the WebAssembly decryption engine parses the media stream shards and chunks them, and uses Single Instruction Multiple Data (SIMD) instructions to decrypt the data chunks in parallel; Step S8, the WebAssembly decryption engine dynamically monitors the system load and dynamically adjusts the number of parallel chunks according to the system load; Step S9, output the decrypted media content to the buffer, and decode and present it through the player.

2. The real-time decryption method of browser digital content according to claim 1, wherein: In the step S2, the user opens a browser and accesses a custom-specified website. The browser downloads the web page and parses it to find a specific tag HTML5 <video>, and then parse <source> the tag to obtain the download address, and then download the encrypted media stream from the download address.< / video> 3. The real-time decryption method of browser digital content according to claim 1, characterized in that: In step S4, the policy file contains data chunk adjustment rules, the selection of decryption algorithms, and key management rule information to ensure that the media content can be processed according to the predefined security policy; After the browser downloads the WebAssembly decryption engine, it uses the WebAssembly.instantiateStreaming method to obtain the binary content of the WebAssembly decryption engine; after obtaining the WebAssembly decryption engine, it performs instantiation processing. The instantiation process includes compiling and initializing the module; after instantiation is completed, the browser accesses the functions and variables exported by the WebAssembly decryption engine through JavaScript.

4. The real-time decryption method of browser digital content according to claim 1, characterized in that: In step S6, the license server generates a license containing the content encryption key, and sends the generated license back to the client after encryption; The client uses the Web Crypto API to decrypt the license, extracts the key, and securely stores the extracted key in the isolated memory space of the WebAssembly encryption engine to prevent it from being accessed by other scripts.

5. The real-time decryption method of browser digital content according to claim 3, characterized in that: In step S7, before decryption, the WebAssembly decryption engine parses the media stream shards, identifies the boundaries of each media stream shard, extracts the encrypted metadata, and determines the frame structure within the shard; To make full use of the advantages of the SIMD instruction set, the media stream data is segmented according to the bit width value corresponding to the encryption algorithm in the policy file, and the data of each media stream shard is segmented into several data chunks of a specified size.

6. The browser digital content real-time decryption method according to claim 5, characterized in that: In step S7, if the cloud server uses the AES encryption algorithm to encrypt the media content, the bit width specified in the policy file is 128 bits; The SIMD instruction set includes but is not limited to v128.load, v128.store, and vl28.aes_decrypt, which are used to perform AES decryption operations; The SIMD bit width is 128 bits. The WebAssembly decryption engine implements data processing through the v128 type and related built-in functions; 128-bit data blocks are loaded from memory using v128.load, and the processed results are written back to memory through v128.store; For the encrypted content of the AES algorithm, the WebAssembly decryption engine uses the v128.aes_decrypt instruction to perform parallel decryption.

7. The browser digital content real-time decryption method according to claim 3, characterized in that: In step S8, when the WebAssembly decryption engine decrypts digital content, it monitors the CPU utilization rate, memory usage, and the status of other custom critical resources in real time; according to the results of the real-time monitoring, it dynamically adjusts the number of data blocks processed simultaneously according to the data block adjustment rules recorded in the policy file to balance the relationship between the decryption speed and system stability; The WebAssembly decryption engine introduces a feedback loop and a machine learning mechanism. By recording the changes in performance metrics after each adjustment, it establishes a machine learning model to predict future adjustment behaviors and makes decisions based on this to automatically discover the optimal parallelism settings and optimization strategies.

8. A real-time decryption system for browser digital content, characterized in that: For implementing the method described in any one of claims 1 to 7, it includes a cloud policy server, a content encryption module, a decryption engine loading and initialization module, a SIMD parallel decryption module, and a performance monitoring and adjustment module; The cloud policy server: is used to issue update instructions, such as switching algorithms, key rotation, etc., to implement the hot update decryption logic of the WebAssembly decryption engine without restarting the WebAssembly decryption engine; The content encryption module: is used to encrypt digital content using an encryption algorithm on the cloud server and generate corresponding keys and licenses; The decryption engine loading and initialization module: is used to download the WebAssembly decryption engine and the policy file from the cloud server and load and initialize the WebAssembly encryption engine through JavaScript code; The SIMD parallel decryption module: is used to slice the media content parsed by the WebAssembly decryption engine, align and block it according to the SIMD bit width, and call SIMD instructions to decrypt data blocks in parallel; The performance monitoring and adjustment module: is used to dynamically monitor the system load and dynamically adjust the number of parallel blocks according to the data block adjustment rules recorded in the policy file.

9. A real-time decryption device for browser digital content, characterized in that: It includes a memory and a processor; the memory is used to store a computer program, and the processor is used to implement the method steps described in any one of claims 1 to 7 when executing the computer program.

10. A readable storage medium, characterized in that: A computer program is stored on the readable storage medium, and when the computer program is executed by the processor, it implements the method steps described in any one of claims 1 to 7.