SECURELY STORING AND ACCESSING FILES WITH A WEB APPLICATION

DE502018015913D1Active Publication Date: 2025-07-10BUNDESDRUCKEREI GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502018015913
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2017-12-31
Filing Date
2018-12-20
Publication Date
2025-07-10
Estimated Expiration
2038-12-20

AI Technical Summary

Technical Problem

Existing file storage methods using single cloud storage services risk data loss and lack of user control over data access, require client applications, and are inefficient in data availability and security.

Method used

A method for cryptographically storing files using a web application that encrypts and fragments data across multiple independent storage services, utilizing error correction methods and authorization tokens to ensure security and availability, without requiring client applications.

Benefits of technology

Enhances data security by preventing unauthorized access and data loss, allows flexible access from any device, and improves availability through parallel file fragment transfer and error correction, while reducing operational complexity for users and providers.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for storing a file, a user computer system, a web server computer system and a system comprising a file management server computer system, a web server and at least one user computer system.

[0002] Various methods for storing user data using one or more external storage services are known from the state of the art, e.g.

[0003] "OneDrive," "Dropbox," "Google Drive," and others. These storage services differ in terms of the security of the data stored there (different authentication and encryption methods), data availability, and / or other factors. Some storage services also offer different user agreements with varying scopes of services, which can change over time. Due to the effort involved in registering with each individual storage service, often only a single service is used to store data externally, e.g., for backup purposes.

[0004] However, using only a single service means that all of the user's data is concentrated in one storage service, and there is a risk that all of this data could fall into the hands of unauthorized third parties in the event of a security breach. Furthermore, in this case, the respective storage service provider has full access to all of the user's data, thus losing control over who has access to their personal data.

[0005] Furthermore, the use of corresponding storage services usually requires a client application installed on the user's computer system, through which the user gains access to their data. If the user uses a different computer system that does not have the corresponding client application, problems accessing their data may arise.

[0006] Finally, the aforementioned storage services are generally storage services whose functionality, in addition to other functionalities, such as those of installed applications or web applications, must be integrated into the program sequences of the user's computer system or executed by the user if the user wants to store the data used and / or generated when executing the corresponding applications or web applications.

[0007] WO 2014 / 108183 A1 describes a system and method for storing data, comprising: encoding a file into multiple fragments; retrieving storage configuration data from a data management store, including data associated with multiple remote stores, wherein the storage configuration data comprises an indication of a predefined data transfer size corresponding to each of the remote stores; using the storage configuration data to identify a storage strategy that associates each fragment with a remote store, wherein using the storage configuration data comprises using the indications of the predefined data transfer sizes; packing one or more fragments, each associated with a common remote store according to the storage strategy, to form a data bundle; transmitting the data bundle to the respective common remote store;associated with the fragments in the data bundle, and storing the fragments on the identified remote storage volume.

[0008] US 2005 / 240749 A1 describes a method for storing a data item, which is executed on a computer in a network and comprises identifying available storage resources in the network, collecting information about the availability of data storage capacity in the identified available storage resources, fragmenting the data item according to a fragmentation policy, and distributing resulting data fragments according to a distribution policy among the identified available storage resources. A computer device operable in a network for managing and performing storage of a data item at a remote storage location in the network is further described.The computer device comprises storage space identification means for identifying storage means of the network accessible on the network, storage space availability information collecting means for collecting information about an availability of data storage capacity in the available storage means, fragmentation means for fragmenting the data item according to a fragmentation policy, and distribution means for distributing resulting data fragments according to a distribution policy among the identified available storage means.

[0009] US 2008 / 060085 A1 describes a method in which an electronic file is broken down into multiple fragments. The fragments are randomly assembled into a number of fragment files, which are randomly stored at different locations on one or more storage devices and / or in a network. One or more of the fragments and / or fragment files are encrypted. Instructions for restoring the electronic file from the fragments are generated. The instructions and other information, such as decryption keys, for restoring the electronic file are located in a protected application, which is intentionally disabled until the protected application is dynamically linked to a security module, obtained, for example, from a security service.

[0010] The invention is based on the object of creating an improved method for storing data, as well as a user computer system, a web server computer system and a file management server computer system for this purpose.

[0011] The object underlying the invention is achieved with the features of the independent patent claims. Embodiments of the invention are specified in the dependent claims. The embodiments listed below can be freely combined with one another, provided they are not mutually exclusive.

[0012] Embodiments include a method for cryptographically storing a file using a web application. The web application is executed by a web browser on a user's computer system.

[0013] The procedure includes: Calling the web application from a web server computer system over a network by the web browser on the user computer system, encrypting the file with a cryptographic key on the user computer system by the web application, providing a distribution plan by the web application, wherein the distribution plan comprises instructions for fragmenting the file into a plurality of file fragments using an error correction method and identifiers of a plurality of mutually independent storage services in whose non-volatile storage media the generated file fragments are to be stored, fragmenting the encrypted file on the user computer system by the web application into a plurality of file fragments using the error correction method according to the distribution plan, wherein at least one of the file fragments contains error correction bits,Sending the resulting file fragments by the web application over the network to the storage services identified by the distribution plan, wherein the web server computer system provides an authorization token for each of the storage services as proof of authorization to store the corresponding file fragment.

[0014] Files to be stored securely are encrypted locally in the web browser on the user's client computer system, split into individual fragments and uploaded to independent storage providers.

[0015] Embodiments may have the advantage of enabling data storage using a web application, i.e., without the need to previously install an application or program. This enables flexible access to the corresponding data from any user computer system. The only requirement is a web browser configured to execute the corresponding web application. Embodiments, in particular, enable the use of a user computer system in the form of a mobile, portable telecommunications system. Thus, the stored data can be accessed at any time, regardless of location, even while on the move.

[0016] The user's confidential files are not stored in their entirety with a single third party, such as a single cloud storage provider. Furthermore, the individual file fragments are stored or retained in encrypted form.

[0017] This method can be advantageous because storing file fragments generated using an error correction method in different storage services can increase the availability of the data to be stored. Furthermore, it can also increase the security of the data against unauthorized access by the storage service: Error correction methods generate file fragments that contain correction bits and thus, depending on the proportion of correction bits in the fragments and the number of generated file fragments, allow reconstruction of the original file should one or more of the storage services fail temporarily or permanently. However, none of the storage services can reconstruct the data because no storage service receives all of the file fragments.But even if an unauthorized third party gains access to a majority of the file fragments, the encryption of the fragmented file prevents them from drawing conclusions about the file's content from the file fragments. According to embodiments, the plaintext blocks of the file are encrypted interdependently during symmetric encryption. This prevents an unauthorized third party from being able to decrypt part of the original file from individual fragments, even if they gain access to the symmetric key for decrypting the file.

[0018] For example, symmetric encryption uses a block cipher method such as AES or DES, which is based on iterated block ciphers. The input is processed in multiple rounds, for example. Such a round can comprise three phases: 1. a combination with a round key, 2. a substitution, constructed from S-boxes, for example, to create confusion, and 3. a permutation of the text bits of the file to be encrypted to implement information diffusion, so that the output of an S-box is distributed across multiple S-boxes in the next round and, after further rounds, across the entire text block. Confusion can make the relationship between the encrypted file, i.e. the ciphertext, and the unencrypted file, i.e. the plaintext, more complex.Through diffusion, the information at one point in the plaintext block can be distributed throughout the entire ciphertext block, so that ultimately, every bit of the ciphertext block depends on every bit of the plaintext block. For example, the algorithm used for block-oriented encryption is based on Cipher Block Chaining (CBC), Cipher Feedback (CFB), or Output Feedback (OFB). For example, DES, Camellia, RC2, 3DES, FEAL, RC6, AES, Blowfish, Serpent, IDEA, Twofish, Skipjack, CAST, MARS, TEA, or XTEA are used for symmetric encryption.

[0019] Security against unauthorized access by the storage service operator can be synergistically increased by strictly separating access management by the file management server computer system, in the form of requesting and forwarding authorization tokens, on the one hand, and data management by the individual storage services, on the other. The file management server computer system stores the file fragments directly in the storage services, bypassing the file management server computer system. The file management server computer system therefore does not act as a router, but merely transmits the authorization tokens that allow the user computer system to store the file fragments via the storage services. The file management server computer system therefore has no access to the content of the transferred file fragments.The storage services, in turn, do not have the reference data required to reconstruct the file. This reference data is only accessible to the user's computer system and / or the file management server's computer system. Furthermore, the method can store data externally much faster than conventional methods: in order to have at least a backup copy of a file available externally, a copy of this file previously had to be transferred to an external storage service. In the event of a failure of this external service, the backup copy was lost or at least temporarily unavailable. According to the invention, however, file fragments are stored using multiple storage services. This enables the parallel transfer of the file fragments over the network.By transferring the file fragments in parallel, the entire information content of the file, including the error correction bits, can be transferred within a fraction of the time required to transfer an entire file copy to a single storage service. Furthermore, thanks to the error correction bits, the file is not lost if one of the storage services fails, but can be immediately and automatically reconstructed from the remaining file fragments using the error correction bits and the reference data. This can be particularly relevant for files that must be highly available, for example, as they are essential for a company's ability to function. The fact that the distribution plan is generated for the file can enable fine-grained generation of the distribution plan, optimized for the respective file.

[0020] Furthermore, it allows users to store data in an existing web application in a distributed and cryptographically secured manner—that is, encrypted and fragmented. The user can upload files to storage services while running the web application without having to call additional applications. This reduces the complexity of operation for the user and prevents errors that could potentially compromise the security of the user's personal data.

[0021] The user is able to upload files and access or download them at a later time and, if necessary, at a different location. The files are neither stored by the operator of the web application, nor are the stored files visible to the operator or other third parties. Even the storage services, none of which contain a complete file, are prevented from accessing the data. Thus, the user retains sole control over their data and, in particular, over who may view it.

[0022] This can also be advantageous for the provider of a web application. Since the files are not stored on the web application provider's web server computer system, nor on any other storage system assigned to the provider, the web application provider neither needs to provide the necessary resources to implement its own storage, nor is it required to assume responsibility for data protection when storing the user's corresponding files.

[0023] To fragment and store the file in a distributed manner, a distribution plan is used. This distribution plan provides information about where the individual file fragments for a specific file can be found and how these file fragments are to be reassembled. The distribution plan is uniquely identifiable and assigned to the corresponding file. According to embodiments, the distribution plan is stored and provided in encrypted form. For example, the distribution plan is protected with a personal password or encrypted with a public cryptographic key of an asymmetric key pair. According to embodiments, the distribution plan can also be encrypted with a symmetric password. According to embodiments, the distribution plan can be encrypted with the same cryptographic key as the file or with a different cryptographic key.

[0024] The distribution plan, which is identified, for example, via a link, i.e. a storage address under which the distribution plan can be retrieved, such as a URL, is bound to the file to be saved in the web application. This can be done, for example, by generating reference data that includes an identifier of the file and the corresponding link to the distribution plan. This enables a user to access the distribution plan of their file at a later time and, if necessary, at a different location and to reassemble the corresponding file locally in their web browser so that they receive the original file. The distribution plan ensures, for example, that only storage services that meet predefined minimum security standards are used.

[0025] A Uniform Resource Locator (URL) is an identifier for identifying and locating resources on a network. The URL includes information about an access method or protocol to be used, such as HTTP or FTP, and / or a location on the network where the resource is located.

[0026] A web application here refers to an application program that comprises machine-readable program instructions that are made available for invocation over a network, such as the Internet, by a computer system, i.e. a web server computer system. The provided program instructions are configured to be invoked by a web browser over the network and executed in the corresponding web browser. In addition, the web application running in the web browser can grant access to one or more services that the web server computer system makes available over the network according to the client-server model. Such a client-server model defines a model for distributing services in a network. The tasks that arise during service execution are performed by programs or computer systems executing programs.Here, a client computer system requests a corresponding service from a server computer system. The server computer system and the client computer system can in particular be two different computer systems that are spatially separated and arranged independently of one another. The server computer system can in particular be a stationary computer system. A client computer system can in particular be a mobile, portable telecommunications device. Here, the server computer system can in particular be configured to simultaneously process and respond to a plurality of requests from a plurality of client computer systems.

[0027] A server computer system refers to a computer system with at least one processor, a memory, and a communications interface for communication over a network, wherein a server program with machine-readable program instructions is stored in the memory. A client computer system refers to a computer system with at least one processor, a memory, and a communications interface for communication over a network, wherein a client program with machine-readable program instructions is stored in the memory. When the program instructions of the client program are executed by the processor of the client computer system, the processor controls the client computer system so that a service request for requesting a service provided by a server computer system is sent to the corresponding server computer system over the network using the communication interface of the client computer system.When the server computer system's processor executes the server program's program instructions, it controls the server computer system so that a service request from a client computer system is received and processed over the network using the server computer system's communication interface. In response to the request, a response is created and sent over the network to the requesting client computer system using the server computer system's communication interface. This implements communication between the server computer system and the client computer system, or between the server program and the client program, so that the client computer system is given access to a service provided by the server computer system.

[0028] The processor of the server computer system executes the program instructions of the server program, while the processor of the client computer system executes the program instructions of the client program. Communication between the client computer system and the server computer system depends on the requested service, which determines which data is exchanged between the two computer systems. The server computer system is ready to respond at any time to contact, i.e., a service request, from a client computer system. In contrast to the client computer system, which requests a service, the server computer system behaves passively and waits for corresponding service requests. The rules of communication for a service, i.e., the format, the calling of the server computer system, the meaning of the data exchanged between the server computer system and the client computer system, etc., are determined by a communication protocol specific to the respective service.

[0029] A service refers to a group of one or more specified tasks that the server computer system offers to perform and which one or more client computer systems can use.

[0030] According to embodiments, in addition to accessing services of the web server computer system according to a client-server model, the web application enables local execution of program instructions and thus functionalities in the web browser on a user computer system. This can be particularly advantageous for cryptographically secure storage of files. If cryptographic program instructions, such as encrypting or decrypting files, are executed locally on the user computer system, this can increase the security of the method. This applies in particular if the cryptographic keys used for encryption or decryption do not leave the user computer system and are stored, for example, in a protected memory area of ​​a memory of the user computer system.

[0031] Furthermore, according to embodiments, corresponding cryptographic keys can be stored on an additional hardware token, for example in a protected memory area of ​​a memory of the hardware token, wherein decryption (possibly also encryption) takes place exclusively on the corresponding hardware token.

[0032] Web applications are not installed locally on the user's computer system, but are executed there. They can also provide access to services that are executed not on the user's computer system, but on the web server computer system. Services are thus centrally provided and executed by the web server computer system, acting as a terminal server. The user's computer system initiates the execution of the program instructions comprised by the service not from local storage, such as a local hard disk, but from the web server computer system. The results of the corresponding data processing during service execution are sent from the web server computer system to the user's local client computer system for display and / or output.For example, a web application provided by a web server computer system is used using a web browser running on the user's client computer system. Communication with the web server computer system and the display of the user interface are carried out by the web browser. Communication protocols for communication over networks, such as the HTTP protocol or HTTPS protocol, are used for communication.

[0033] One advantage of web applications is the ability to install updates. These updates only need to be installed once on the web server computer system and can then be used by the user computer system.

[0034] According to embodiments, when running the web application, the web browser emulates a client application with the corresponding functionality.

[0035] The web application provides the program instructions in the form of software as a service. Software as a Service (SaaS) is a subset of cloud computing, where software and IT infrastructure are hosted by an external IT service provider and can be used by the user as a service. Use requires an internet-enabled computer and an internet connection to the external IT service provider. Access to the software is realized via a web browser.

[0036] According to embodiments, the web server computer system provides a service via the web application, wherein the file to be stored comprises data that is generated and / or used during execution of the service. Embodiments can have the advantage that the secure storage of files can be integrated into an existing web application via which the web server computer system provides services, in particular SaaS. This not only enables data processing by the corresponding services, but also complements secure storage of the used or generated data.

[0037] Consider, for example, any web application that provides certain services to the user. If the provider of the web application also wants to offer the user the ability to upload, download, and manage files for secure storage, certain embodiments allow the use of external storage providers without posing security issues or requiring the provider of the web application to provide its own storage resources.

[0038] To store files securely, all that is necessary is to integrate the appropriate modules for uploading and downloading files into the web application and to address the communication interface for authorizing the upload or download by the web server computer system. The management of reference data, which e.g. identifies the distribution plans assigned to the individual files, takes place in an additional server module of the web server computer system and is supplemented by the reference list for each user on the web server computer system. The reference list contains a reference to a distribution plan for the corresponding file for each user of the web application and their individual files. The modules themselves that upload and download data cannot be bypassed. The references, which contain secrets for accessing the files, must be stored in the web application or the server module.on the web server computer system in such a way that only an authorized user can access them. According to some embodiments, the security of the concept is based on the secure management of the reference lists on the web server computer system. For example, at least parts of the reference data are encrypted and / or can only be retrieved after successful authentication of a requesting user via an end-to-end encrypted data connection.

[0039] According to embodiments, providing the distribution plan comprises generating the distribution plan on the user computer system by the web application. Embodiments may have the advantage that the web application generates a suitable distribution plan based on the data to be stored, e.g., its size.

[0040] According to embodiments, providing the distribution plan comprises receiving the distribution plan on the user computer system by the web application. Embodiments may have the advantage that an existing distribution plan or one generated by the web server computer system or a file management server computer system can be used by the web application. For example, the distribution plan is generated by the file management server computer system in response to a request by the web server computer system and sent to the web application via the web server computer system.

[0041] According to embodiments, the web application communicates directly with the file management server computer system, wherein the web application identifies itself to the file management server computer system as belonging to the web server computer system. Thus, for example, the file management server computer system only knows the web server computer system, which internally assigns the distribution plans to different users.

[0042] According to embodiments, the method further comprises sending the distribution plan from the web application over the network to a file management server computer system for storage. Embodiments may have the advantage that the storage and management of the distribution plans, as well as the management of the authorization tokens, are provided by the file management server computer system, which the web server computer system uses to integrate the file storage function.

[0043] According to embodiments, the method further comprises encrypting the distribution plan. Embodiments may have the advantage that the distribution plans can only be used by owners of a corresponding cryptographic key. For example, this cryptographic key is a symmetric cryptographic key in the case of symmetric encryption or a private cryptographic key in the case of asymmetric encryption with a public cryptographic key.

[0044] According to embodiments, the authorization tokens are received by the web application on the user computer system from the file management server computer system, wherein the received authorization tokens comprise an authorization token from each of the plurality of storage services identified in the distribution plan, which were requested by the file management server computer system at the instigation of the web server computer system and forwarded to the user computer system.

[0045] Embodiments may have the advantage of allowing only an authorized user, i.e. a user authorized by the web server computer system, to save files.

[0046] According to some embodiments, receiving the authorization token requires successful authentication of the web server computer system with the file management server computer system. Embodiments may have the advantage that the web server computer system acts as the responsible entity for storing the files with the file management server computer system. Thus, the user must authenticate themselves with the file management server computer system. In other words, the secure storage of files can be integrated into the web application without the user having to communicate with and / or authenticate themselves with additional servers. In particular, setting up additional user accounts is not necessary. According to some embodiments, a one-time registration with the web server computer system is sufficient.When saving files, the user only needs to authenticate himself later to the web server computer system, which, according to embodiments, takes place, for example, when logging in when calling the web application via the web browser.

[0047] According to embodiments, the web application sends the file fragments to the identified storage services by bypassing the web server computer system and / or the file management server computer system. Embodiments may have the advantage that neither the web server computer system nor the file management server computer system has access to all file fragments.

[0048] According to embodiments, the authorization tokens are embodied as URLs, each of which enables direct read access to a storage location identified by the URL on one of the storage media of one of the storage services. Embodiments may have the advantage of providing easy access to the storage locations for uploading and / or downloading the file fragments, which simultaneously serves as proof of authorization for the corresponding access.

[0049] According to embodiments, the method further comprises creating reference data associated with the file, used to reconstruct the file from the distributed file fragments, and stored by the web server computer system. Embodiments may have the advantage that the distributed files can be managed efficiently using the reference data.

[0050] According to embodiments, the reference data includes: an identifier of the user, an identifier of the file, an identifier of the distribution plan, an identifier of a cryptographic key for decrypting the encrypted file, an identifier of a cryptographic key for decrypting the encrypted distribution plan, a hash value of the complete file, and / or hash values ​​of the stored file fragments. Embodiments may have the advantage that the reference data can associate the distribution plan with the file and / or the user. Furthermore, the reference data can be used to verify the integrity of the file or file fragments based on the hash values. Finally, the reference data can identify everything required to reconstruct a file.Depending on the embodiment, the identifiers also specify the memory addresses at which the identified and required data objects can be found. The hash values ​​used can, for example, be a hash value calculated using an MD5, Sha-1, or Sha-2 hash algorithm. For example, the file is encrypted with a symmetric key, such as a hash value of the file.

[0051] According to embodiments, the file fragment-specific hash values ​​can serve as identifiers of the file fragments. The hash values ​​of the file fragments can be linked to the original file name using a mapping, and the mapping can be included in the reference data along with the original file name. The user computer system encrypts each of the file fragments of the file, using the hash value of the entire original file as a symmetric key. Preferably, strong encryption is used, for example, using AES-256 or AES-512.

[0052] According to embodiments, the reference data is stored by the web server computer system in cryptographically secured form. Embodiments can have the advantage of increasing the security of the method. For example, the reference data is stored in a protected memory area of ​​the memory of the web server computer system. Furthermore, access is granted, for example, only upon successful authentication of a requesting party and / or the corresponding data is transmitted only via a data connection secured by end-to-end encryption.

[0053] According to embodiments, the web application communicates the reference data to a server module for managing reference data, which is executed by a processor of the web server computer system. Embodiments may have the advantage that the functionality of a given web server computer system can be extended to include this management of reference data by means of a corresponding server module.

[0054] According to embodiments, the reference data is stored by the web server computer system in a reference list containing a plurality of reference data for a plurality of files of different users of the web application. Embodiments may have the advantage that the web server computer system can make the web application and / or its services available to a plurality of users, including secure storage of the files of all users.

[0055] According to embodiments, the method further comprises authenticating the user to the web server computer system. Embodiments may have the advantage of ensuring that only an authorized user has access to the securely stored files.

[0056] According to embodiments, one or more modules for distributed storage of the file on the storage services are integrated into the web application, and the encryption, fragmentation, and sending are carried out by executing the modules of the web application in the web browser by a processor of the user's computer system.

[0057] Embodiments may have the advantage that the corresponding modules are executed locally in the web browser on the client computer system. By integrating corresponding modules, any web application can be enabled to enable cryptographically secured data storage. The entire functionality regarding the secure storage of files is based on the modules integrated into the web application. The corresponding functions of the web application are provided, for example, via a library.

[0058] Embodiments enable the integration of secure file storage into an existing web application in the form of corresponding modules as a microservice.

[0059] A microservice is a subprocess of a complex application that is composed or combined into a number of independent processes that communicate with each other using language-independent programming interfaces. The individual microservices or services are largely decoupled and each perform a small subtask. The use of microservices thus enables a modular structure of the application.

[0060] For example, the web application includes an encryption module for encrypting files, a fragmentation module for fragmenting files, and a transfer module for transferring or sending the file fragments. According to embodiments, the encryption module is further configured to decrypt files, the fragmentation module is configured to defragment file fragments, and the transfer module is configured to download file fragments.

[0061] For example, the encryption module, the fragmentation module and the transfer module are combined in an upload module, which enables secure storage of files in encrypted and fragmented form on a distributed storage system with independent storage media.

[0062] According to embodiments, the method for downloading the cryptographically secured stored file using the web application executed by the web browser on the user computer system further comprises: Calling the web application from the web server computer system over the network by the web browser on the user computer system, providing the distribution plan of the distributed file by the web application, wherein the distribution plan includes instructions for defragmenting the file from a plurality of file fragments using an error correction method and identifiers of the plurality of independent storage services in whose non-volatile storage media the file fragments are stored, providing an authorization token from each of the storage services of at least a selection of the storage services in whose non-volatile storage media the file fragments are stored, by the web server computer system, wherein the file fragments included in the selection of storage services are sufficient for a complete reconstruction of the file,Downloading the file fragments from the individual storage services using the authorization tokens as credentials for downloading, defragmenting the encrypted file from the file fragments on the user's computer system by the web application using the error correction procedure according to the distribution plan, decrypting the encrypted file with a cryptographic key on the user's computer system by the web application.

[0063] Retrieval of the distributed files occurs via the web browser running on the user's computer system. The file fragments are downloaded from the storage providers, defragmented, and decrypted, resulting in the original file. Embodiments can have the advantage of enabling efficient and secure downloading of the distributed file fragments.

[0064] According to embodiments, the web server computer system provides a service via the web application, and data included in the downloaded file is used in the course of executing the service by the web application. Embodiments may have the advantage that downloading a file or data necessary for the service or in the course of executing the service can be integrated into the web application.

[0065] According to embodiments, providing the distribution plan comprises receiving the distribution plan from the file management server computer system on the user computer system by the web application. According to embodiments, the distribution plan is sent directly from the file management server computer system to the web application or forwarded by the web server computer system.

[0066] According to embodiments, the distribution plan is provided in encrypted form, and the provisioning further includes decrypting the distribution plan on the user computer system by the web application. Embodiments may have the advantage that the distribution plan can be efficiently protected. The cryptographic key for decrypting the distribution plan is, for example, stored locally on the user computer system or provided locally to the user computer system by the user, for example, using a hardware token, if necessary.

[0067] According to embodiments, providing the authorization tokens on the user computer system by the web application comprises receiving the authorization tokens from the file management server computer system, which were requested by the file management server computer system at the instigation of the web server computer system and forwarded to the user computer system. Embodiments can have the advantage that only authorized users can access the distributed file fragments. Furthermore, access is managed by the file management server computer system and must be released or initiated by the web server computer system.

[0068] According to embodiments, receiving the authorization tokens requires successful authentication of the web server computer system to the file management server computer system.

[0069] According to embodiments, the web application downloads the file fragments from the identified storage services by bypassing the web server computer system and / or the file management server computer system. Embodiments may have the advantage that neither the web server computer system nor the file management server computer system gains access to all data fragments necessary for reconstructing the file during the download.

[0070] According to embodiments, the method further comprises receiving reference data associated with the file to be downloaded and used to reconstruct the file from the distributed file fragments from the web server computer system by the web application on the user computer system. Embodiments may have the advantage that the reference data can be used to efficiently manage the download of the files.

[0071] According to some embodiments, downloading the file requires successful authentication of the user with the web server computer system. Some embodiments may have the advantage that only authorized users have access to the distributed file.

[0072] According to embodiments, one or more modules for distributed storage of the file on the storage services are integrated into the web application, and downloading, defragmenting, and decryption are performed by executing the web application modules in the web browser by the processor of the user's computer system. Embodiments can have the advantage that a given web application can be easily extended by the modules to include the functionality of downloading required files. The entire functionality regarding the secure retrieval of files is based on the modules integrated into the web application. The corresponding functions of the web application are provided, for example, via a library. Embodiments thus enable the integration of secure retrieval of files into an existing web application in the form of corresponding modules as a microservice.

[0073] For example, the web application includes a transfer module for transferring or downloading the file fragments, a fragmentation module for defragmenting the file fragments, and an encryption module for decrypting the encrypted file. According to embodiments, the encryption module is further configured to encrypt files, the fragmentation module is configured to fragment files, and the transfer module is configured to upload file fragments.

[0074] For example, the encryption module, the fragmentation module and the transfer module are combined in a download module, which enables secure retrieval of files in encrypted and fragmented form from a distributed storage system with independent storage media.

[0075] According to embodiments, the reference data and / or the distribution plan are stored in encrypted form and the cryptographic keys for decrypting the reference data and / or the distribution plan are provided by a hardware token, the method further comprising: Sending a decryption request from the user computer system to access the decrypted reference data and / or the decrypted distribution plan to the hardware token, Authenticating the user computer system to the hardware token, After successful authentication of the user computer system and if the user to whom the user computer system is assigned has access rights to the decrypted reference data and / or the decrypted distribution plan, Receiving the reference data and / or distribution plan decrypted by the hardware token with the cryptographic key, for example a private cryptographic key.

[0076] According to embodiments, the cryptographic keys for decrypting encrypted data objects, such as the reference data and / or the distribution plan, are stored on the user computer system or on a hardware token in a protected storage area.

[0077] A "protected memory area" is understood here to be an area of ​​an electronic memory to which access, i.e., read or write access, is only possible via a processor of the user's computer system or hardware token. According to embodiments, access from the processor coupled to the memory is only possible if a necessary condition is met. This can be, for example, a cryptographic condition, in particular successful authentication and / or successful authorization verification.

[0078] If cryptographic keys are stored on a standalone, cryptographically secured hardware token, the security of the present method can be further increased. For example, the hardware token is a privatized or personalized chip card that includes a processor and memory, with the private key stored in a protected memory area. For example, the user must authenticate themselves to the hardware token as a prerequisite for using the private key. This can be done using an ID such as a password, a biometric feature, or behavior-based. A biometric feature can be, for example, an acceleration pattern, heart rate, vein pattern, iris pattern, retinal pattern, voice pattern, and / or fingerprint.

[0079] The encrypted file and the user's private key, which is required to decrypt the file, are never stored on the same device. Therefore, even if an attacker manages to gain access to one of the devices, e.g., the user's computer system or the hardware token, they still do not have all the prerequisites for decryption. Decryption of the reference data, or at least the symmetric key, occurs exclusively in the hardware token, without the private key leaving the hardware token.

[0080] In addition, the necessary authentication of the user computer system against the hardware token introduces an additional verification instance into the process, which further increases security.

[0081] For example, the user computer system establishes a secure communication channel, perhaps using end-to-end encryption, with the hardware token and transfers the reference data to be decrypted to it. The reference data is decrypted on the hardware token using the private key in a secure, i.e., cryptographically protected, environment. The decrypted reference data is then transferred to the user computer system using the secure communication channel.

[0082] Storing the user's private key on the hardware token makes the process for secure data storage in the cloud even more secure, as only the owner of the hardware token can decrypt the file and thus has access to the corresponding data. The scalability of attacks on the system or the process is thus reduced, as the user's private key is not protected by the user's computer system, e.g., the operating system software.

[0083] According to embodiments, the file is encrypted with a symmetric key. According to embodiments, the reference data includes the symmetric key. According to embodiments, the symmetric key is encrypted with a public cryptographic key of an asymmetric key pair associated with the user.

[0084] According to embodiments, each of the file fragments of the encrypted file is additionally encrypted with a symmetric key. This symmetric key, with which the file fragments are additionally encrypted, can be the same symmetric key with which the file is encrypted or a different symmetric key. For example, an individual key is generated for each of the file fragments. For example, the generated symmetric keys can each be randomly generated keys or the keys can each be a characteristic value, such as a hash value, of the file fragment to be encrypted with the key. The symmetric key(s) with which the file fragments are each additionally encrypted are also included in the reference data, which is encrypted with the user's public key.The additional encryption of the file fragments can further increase the security of the process.

[0085] According to embodiments, the user computer system is associated with a user. The web server computer system performs an authorization check and initiates a request for the authorization tokens from each of the storage services identified in the distribution plan only if the authorization check shows that the user is authorized to read / write the file.

[0086] Access rights are preferably checked only for the requested write and / or read operation on the file to be written or read. This has the advantage that access control can be implemented very granularly, flexibly, and specifically for individual users, time-wise, and for individual files.

[0087] According to embodiments, the asymmetric key pair assigned to the user is generated by an issuing authority, for example, on a cryptographically secured system, during the personalization of the hardware token and is thereby uniquely assigned to the user. For example, the asymmetric key pair is stored on the hardware token during its production. The assignment to the user can be implemented, for example, by a certificate containing the public key issued by the issuing authority as a certification authority of the PKI or an independent root certification authority.

[0088] The assignment to the user may additionally or alternatively include the transfer of the corresponding public key, for example from the user's computer system, to the file management server computer system and storing it there as part of the user profile of the corresponding user.

[0089] According to embodiments, the file fragments are downloaded in parallel from the storage services by the user's computer system over the network. This can increase the file download speed.

[0090] End-to-end encryption refers to the encryption of a connection between a sender and a receiver, in which the data to be transmitted is encrypted by the sender and only decrypted by the receiver. The encryption of transmitted data thus occurs across all transmission stations, so that intermediate stations cannot gain knowledge of the content of the transmitted data due to the encryption. The connection is cryptographically secured by encryption to prevent spying and / or manipulation of the transmission. A so-called secure messaging method can be used for this purpose. End-to-end encryption, for example, is based on two symmetric cryptographic keys, with a first symmetric key being used to encrypt messages and a second symmetric key being used to authenticate the sender of the message.

[0091] The key for authenticating the sender of the message can, for example, be used to create a message authentication code (MAC). Using a MAC, certainty about the origin of the message can be obtained and its integrity can be verified. MAC algorithms require two input parameters: first, the data to be protected and second, a secret key. From these two, a message authentication code is calculated in the form of a checksum. The sender of a message calculates a MAC for the data to be transmitted in the message and sends the message along with the MAC to the receiver. The receiver calculates the MAC for the received message using its key and compares the calculated MAC with the received MAC.If both values ​​match, it follows that the message was sent by a party that has access to the secret key and the message was not changed during transmission.

[0092] According to embodiments, the web server computer system manages public keys of a plurality of users. If another user of the plurality of users is also to be enabled to access the distributed data, the method further comprises: Providing the public key of the further user to whom access is to be granted by the web application, encrypting the reference data of the file by the web application on the user's computer system, sending the encrypted reference data by the web application to the web server computer system, forwarding the encrypted reference data by the web server computer system to the web application executed by a web browser of a user's computer system of the further user.

[0093] Embodiments can have the advantage that different users can be granted access to the distributed file. This can be advantageous because the web server computer system can centrally manage the public keys of a plurality of users and, by selectively forwarding both the reference data and the public keys to other authorized users, can ensure particularly high protection against unauthorized access. The symmetric key ensures that the file is encrypted and fragmented and stored in the storage media of the individual storage services, and that the upload and download of the file fragments thus only includes encrypted data. Preferably, a different symmetric key is dynamically generated for each individual file.The described combination of a file-specific symmetric key for encrypting and decrypting the file and a user-assigned public key for integrating the symmetric key into the file's reference data can also be advantageous, since encrypting or decrypting large amounts of data using symmetric cryptographic keys is generally significantly more efficient than using an asymmetric cryptographic key pair. The speed aspect is less relevant when encrypting the (relatively small) reference data, so encryption with an asymmetric cryptographic key pair can be used here, enabling the exchange of a key required for decryption without revealing the private key. Instead, the private key is stored locally, protected from unauthorized access.

[0094] If multiple users are authorized to access the distributed file, according to embodiments, a separate version of reference data for the one distributed file can be generated for each of these authorized users, wherein the reference data is encrypted by the user computer system that originally stored the file in a distributed manner according to the distribution plan using the public key (encryption key) of the respective user.

[0095] According to embodiments, the authorization tokens are selectively generated only for the access request to download the file fragments and have only temporary validity.

[0096] Embodiments may have the advantage that the file management server computer system does not function as a router, which can ensure the protection of the data from unauthorized access by the file management server computer system. The fact that the authorization tokens are only valid for a limited time can also increase the security of the method. After a preset time, for example, a few seconds, minutes, or days, the authorization token, for example a URL, automatically becomes invalid. The use of authorization URLs also has the advantage that even users who have not registered with the individual storage services can be granted access to the file, since the web server computer system centrally manages the access rights. The owner of the file can specifically specify whether the access rights are read-only and / or also write.This can enormously increase the flexibility and number of application scenarios of the method, since additional users only need to register with the web server computer system in order to view a file, for example. According to some embodiments, this is not even necessary. For example, a further user not registered with the web server computer system could also prove their identity to the web server computer system using their electronic ID card. However, in embodiments in which the key used to encrypt the file is encrypted with the public key of an authorized user computer system, registration may be required for the central deposit of the user computer system's public encryption key.

[0097] Each URL can, for example, consist of a path and other information. The path can, for example, contain an ID of the storage service and a path to the corresponding storage location on the storage service's storage medium. The additional information can, for example, include parameter values ​​that indicate the user's authorization to access the storage location and that are checked by the storage service when the user's computer system accesses the file fragment via the URL.

[0098] According to embodiments, a signing key is stored in a protected storage area of ​​the file management server computer system's memory. The method further comprises: Providing a signature verification key associated with the signing key to each of the storage services, wherein the signature verification key is designed to verify signatures generated with the signing key, signing the authorization tokens with the signing key by the file management server computer system, wherein the authorization tokens are forwarded in signed form to the user computer system, wherein each of the signed authorization tokens enables access to the storage space identified by the respective authorization token on the storage medium of the respective storage service under the condition that the storage service recognizes the signature as valid.

[0099] Embodiments may have the advantage of enabling individual storage services to perform signature verification to increase the security of the data they store. According to embodiments, the authorization tokens are signed both for authorization tokens that allow read access to a file already stored in a distributed manner and for authorization tokens that grant write access to the distributed storage of a file.

[0100] According to embodiments, a minimum trust level is defined, which specifies a minimum degree of reliability for the authentication method by means of which the user's computer system must authenticate itself to the web server computer system in order to be allowed to access the file stored in the storage media of the identified storage services.

[0101] The method further comprises checking by the web server computer system whether the authentication method used to authenticate the user computer system to the web server computer system is sufficiently reliable to meet the minimum trust level specified for the user for the requested access. The web server computer system only initiates the request for the authorization token if the authentication method used to authenticate the user computer system to the web server computer system has a trust level that is at least as high as the specified minimum trust level.

[0102] The minimum trust level can be configured and modified by the user. The minimum trust level specifies a user-defined minimum level of reliability of an authentication procedure by which another user must authenticate to a web server computer system in order to be granted read and / or write access to the files stored in the storage media of the identified storage services. This can be advantageous because it provides the user with configurable and fine-grained (file-level) control over access to this file by other users.For example, the user can prevent a file containing particularly confidential and sensitive information from being viewed by a user who has only authenticated himself to the web server computer system using an authentication method that is relatively easy to crack (e.g. user name and password).

[0103] According to embodiments, the method further comprises: includes determining the expected total size of all file fragments to be generated by the error correction method according to the distribution plan, wherein a storage service is identified for each of the file fragments to be generated, if the determined error correction method would result in the generation of file fragments whose total size does not allow the identification of a sufficient number of storage services which, according to their specifications, meet the requirements in terms of speed and / or security taking into account the total size, automatically determining an alternative error correction method which is configured to generate file fragments whose expected total size is sufficiently small.

[0104] A "word" in the error correction scheme is a group of bits, representing the smallest unit for detecting and, if necessary, correcting an error. Eight bits are often used as the word length. A bit word length results in a fixed amount of data that can be corrected.

[0105] Determining the error correction method to be specified in the distribution plan may involve determining configuration parameters for the error correction method. The configuration parameters may include, for example, a word length W, a number K of file partitions without considering the error correction bits, and / or a number M of file partitions K whose loss is to be compensated for, if necessary, by the information content of the error correction bits. A "file partition" here is an initially generated file fragment that does not yet contain any error correction bits. From these initially generated file partitions, the actual file fragments with the error correction bits can be calculated, which are then transferred to the storage services.

[0106] For example, the file size of the file to be saved could be used to determine the error correction method. The file to be saved could have a file size of "10 MB."

[0107] According to a first example, the number of file partitions K could be "4." This means that the error correction algorithm first divides the file to be saved into four file partitions of 2.5 MB each. The number M of file partitions, whose loss is to be compensated, could be "1." The configuration parameters K=4 and M=1 cause the error correction algorithm to generate a total of five file fragments, each 10 MB / 4 = 2.5 MB in size. In total, an error correction algorithm with the exemplary K = 4, M = 1 configuration would generate 12.5 MB of data from the original 10 MB output file. Four of the file fragments could consist of the file partitions and thus consist purely of file data, while the fifth file fragment could consist entirely of error correction bits.According to a second example, the configuration parameters K = 4 and M = 2 could cause the error correction procedure to generate a total of 6 file fragments, 2 of which consist of error correction bits and 4 of which consist of file partitions. A total of 6*2.5 MB = 15 MB of data is generated from the original file.

[0108] In addition to error correction methods that generate file fragments consisting either of file partitions or pure error correction data, other embodiments can also use error correction methods in which each generated file fragment contains a first portion consisting purely of file data and a second portion consisting of error correction bits. In the first example mentioned above with K = 4 and M = 1 for a 10 MB file, for example, 5 file fragments of 2.5 MB each could be generated, each containing 2.5 MB / 5 = 0.5 MB of error correction bits. In the second example mentioned above with K = 4 and M = 2 for the 10 MB file, for example, 6 file fragments of 2.5 MB each could be generated, each containing (2 * 2.5 Mb) / 6 = 0.83 Mb of error correction bits.

[0109] According to some embodiments, the configuration parameters K and M are preconfigured by default in the web server computer system, but can be dynamically changed depending on file characteristics to achieve an optimized distribution of the file fragments. The dynamic configuration parameters are integrated into the generated distribution plan to further characterize the error correction method identified therein. As the number M of loss-compensable file partitions increases, the availability and reliability of the distributed file is increased. However, if K remains unchanged, the size of the individual file fragments also increases.

[0110] According to some embodiments, the configuration parameters M and / or K of the error correction method specified in the distribution plan are determined such that, as the user's requirements for file availability increase, not only M increases, but also K. As a consequence, the number of file fragments to be generated by the error correction method is also increased in order to keep the size of the individual file fragments approximately constant and to ensure a consistently short transfer time during parallel file fragment uploads. In this case, the number of storage services used for parallel storage of the file fragments and specified in the distribution plan may also need to be increased.

[0111] Embodiments further include a user computer system. The user computer system includes a processor, a network interface for operatively coupling the user computer system to a web server computer system, and a plurality of storage services over a network. The user computer system further includes a storage medium with a web browser executable by the processor. The web browser is configured to perform the following method for cryptographically securing storage of a file using a web application executed by the web browser: Calling the web application from the web server computer system over the network by the web browser on the user computer system, encrypting the file with a cryptographic key on the user computer system by the web application, providing a distribution plan by the web application, wherein the distribution plan includes instructions for fragmenting the file into a plurality of file fragments using an error correction method and identifiers of the plurality of storage services in whose non-volatile storage media the generated file fragments are to be stored, fragmenting the encrypted file on the user computer system by the web application into a plurality of file fragments using the error correction method according to the distribution plan, wherein at least one of the file fragments includes error correction bits,Sending the resulting file fragments by the web application over the network to the storage services identified by the distribution plan, wherein the web server computer system provides an authorization token for each of the storage services as proof of authorization to store the corresponding file fragment.

[0112] The user computer system is configured to execute one or more of the preceding embodiments of the method.

[0113] Embodiments further include a web server computer system. The web server computer system includes a processor and a network interface for operatively coupling the web server computer system to a user computer system. The web server computer system further includes a storage medium with program instructions. The program instructions are configured, when executed by the processor, to send program instructions for executing the web application in a web browser on the user computer system to the user computer system via the network in response to receiving a call to a web application from a web browser of the user computer system via the network. The web application is configured to execute the following method for cryptographically securing the storage of a file: Encrypting the file with a cryptographic key on the user computer system by the web application, providing a distribution plan by the web application, wherein the distribution plan comprises instructions for fragmenting the file into a plurality of file fragments using an error correction method and identifiers of a plurality of storage services in whose non-volatile storage media the generated file fragments are to be stored, fragmenting the encrypted file on the user computer system by the web application into a plurality of file fragments using the error correction method according to the distribution plan, wherein at least one of the file fragments includes error correction bits, sending the resulting file fragments by the web application over the network to the storage services identified by the distribution plan,wherein the web server computer system provides an authorization token for each of the storage services as proof of authorization to store the corresponding file fragment.

[0114] The web server computer system is configured to carry out one or more of the preceding embodiments of the method.

[0115] According to embodiments, the web server computer system is further configured to provide a service via the web application, wherein the file to be stored is generated in the course of executing the service by the web application.

[0116] Embodiments further include a system comprising a file management server computer system, a web server computer system, and at least one user computer system. The file management server computer system comprises a processor and a network interface for operatively coupling the file management server computer system to the web server computer system, to the at least one user computer system, and to a plurality of storage services via a network. The file management server computer system comprises a storage medium with program instructions. The program instructions are configured, when executed by the processor, to execute the following method for cryptographically securing storage of a file: Receiving an authorization request from the web server computer system for storing file fragments of the file over the network in the plurality of storage services according to a distribution plan, wherein the file management server computer system does not provide any of the storage services, In response to receiving the authorization request, requesting an authorization token from each of the plurality of storage services and forwarding the authorization tokens received in response to the request to the at least one user computer system, Storing the distribution plan, wherein the distribution plan comprises instructions for defragmenting the file from a plurality of file fragments using an error correction method and identifiers of the plurality of storage services in whose non-volatile storage media the file fragments are stored.

[0117] The file management server computer system is configured to carry out one or more of the preceding embodiments of the method.

[0118] A "distribution plan" within the meaning of the present invention is a specification that contains at least information about the identity of the storage services via which fragments of a file are to be stored, as well as information that defines an error correction method to be used to generate these file fragments from the said file. A distribution plan can be implemented, for example, as an XML file or a binary file.

[0119] A "file management server" or "file management server computer system" is a computer system that has an interface for communicating with one or more user computer systems and for communicating with multiple storage services in order to grant the one or more user computer systems access rights to storage media managed by these storage services. The file management server computer system does not itself provide a storage service and is preferably separated from the storage services by security measures that ensure that none of these storage services has access to data managed by the file management server computer system, in particular, for example, user profiles and reference data.The file management server computer system may consist of one data processing device or of several data processing devices, in particular computers, which interact and are jointly managed to provide the functionality of the file management server computer system according to the embodiments described above.

[0120] An "authorization token" is a data structure, e.g., a file or a URL, that contains information that grants an entity in possession of this authorization token authorization to access storage areas of external storage media. The external storage media can, for example, be provided by a storage service over a network such as the Internet. According to embodiments, the authorization token can contain both a pointer and an authorization credential. The pointer can, for example, consist of a combination of an IP address of a storage service and a file path of a storage medium managed by this storage service. The authorization credential can, for example, contain one or more data values ​​that identify the owner of the authorization token as having access rights, e.g., a random value generated by the storage service that can be compared to a reference value.The said data values ​​may also include a signature.

[0121] A "storage service" is a service provided via a network that enables one or more user computer systems to send data to the service over the network so that the data can be stored by the storage service on one or more storage media managed by the storage service, and / or that enables the user computer systems to access data already stored by this or another user computer system over the network—e.g., for reading or writing. An individual storage service is preferably technically and organizationally separated from every other storage service. According to embodiments, each of the storage services is configured to receive data from the user computer system over the network via an interface and to store this data on its non-volatile storage medium.

[0122] A "user computer system" is understood below to mean a data processing system, e.g. a desktop PC, a notebook or a smartphone, which is assigned to a user.

[0123] A "hardware token" refers to a portable electronic device that includes a processor for executing program instructions and a memory for storing program instructions. A hardware token is, for example, a telecommunications device, such as a smartphone. Furthermore, the hardware token can be an ID token. The term "ID token" refers to a device, such as a portable electronic device, for example, a USB stick, a chip card, or a document.

[0124] A "document" is understood to mean, in particular, an identification, valuables, or security document, in particular a sovereign document, in particular a paper-based and / or plastic-based document, such as an electronic identification document, in particular a passport, identity card, visa, driver's license, vehicle registration document, vehicle registration certificate, health insurance card, or company ID, or another ID document, a chip card, a means of payment, in particular a banknote, bank card or credit card, a waybill, or other proof of authorization. In particular, the ID token can be a machine-readable travel document, such as those standardized by the International Civil Aviation Organization (ICAO) and / or the BSI.

[0125] According to some embodiments, the ID token does not have its own power supply. Instead, the energy source can be a device for "harvesting" energy, which is transmitted from the terminal to the ID token, such as an RFID antenna.

[0126] A "certificate" here refers to a digital certificate, also known as a public key certificate. Such certificates based on asymmetric key pairs implement a so-called public key infrastructure (PKI). Such a certificate consists of structured data that serves to assign a public key of an asymmetric cryptosystem to an identity, such as a person or a device. A certificate can, for example, contain a public key and be signed. Alternatively, certificates based on zero-knowledge cryptosystems are also possible. For example, the certificate can conform to the X.509 standard or another standard. For example, the certificate is a CV certificate, or Card Verifiable Certificate (CVC). An implementation of such CVCs is specified, for example, in ISO / IEC 7816-8.

[0127] The PKI provides a system for issuing, distributing, and verifying digital certificates. In an asymmetric cryptosystem, a digital certificate serves to confirm the authenticity of a public key and its permissible scope of application and validity. The digital certificate itself is protected by a digital signature, the authenticity of which can be verified using the public key of the certificate issuer. A digital certificate is used to verify the authenticity of the issuer key. In this way, a chain of digital certificates can be established, each of which confirms the authenticity of the public key with which the previous certificate can be verified. Such a chain of certificates forms a so-called validation path or certification path.The participants of the . must ensure the authenticity of the last certificate, the so-called root certificate, and the key certified by this certificate. PKI without another certificate. The root certificate is managed by a so-called root certification authority, on whose authenticity the authenticity of all certificates of the PKI goes back.

[0128] Digital certificates are a proven means of proving authorizations when securing electronic communications using asymmetric cryptographic methods. Certificates are structured data that document the authenticity and / or other properties / authorizations of the owner of a public key (signature verification key) and are confirmed by an independent, trustworthy authority (certification service provider / CSP), generally the certification authority that issued the certificate. Certificates are generally made available to a wide audience to enable them to verify electronic signatures for authenticity and validity.

[0129] A certificate can be associated with an electronic signature if the private key associated with the public key was used to generate the electronic signature to be verified. By making a certificate associated with a public key available to the public, a CSP enables users of asymmetric cryptosystems to associate the public key with an identity, such as a person, an organization, an energy system, or a computer system.

[0130] Asymmetric key pairs are used for a variety of cryptosystems and also play an important role in signing electronic documents. An asymmetric key pair consists of a public key, which is used to encrypt and / or decrypt data and may be passed on to third parties, such as a service provider and / or a central processing unit (CSP), and a private key, which is used to encrypt and / or decrypt data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private key, verify digital signatures on their documents, or authenticate them. A private key allows its owner to decrypt data encrypted with the public key or to create digital signatures for electronic documents.A signature created with a private key can be verified with the corresponding public key.

[0131] Digital signatures are used for secure electronic data exchange, for example, on the Internet, and enable the verification of identities and / or authorizations and the authenticity of the exchanged data. To ensure this, a public key infrastructure is usually required, which confirms the validity of the keys used through certificates.

[0132] The creation of a digital signature, hereinafter referred to simply as a "signature," is a cryptographic process in which an additional data value, referred to as a "signature," is calculated for any data, for example, an electronic document. The signature can, for example, be an encrypted hash value of the electronic document, in particular a hash value encrypted with a private key of a cryptographic key pair associated with a certificate. The special feature of such a signature is that its authorship and affiliation with a specific person or entity can be verified by any third party.

[0133] The term "memory" or "storage medium" refers here to both volatile and non-volatile electronic memories or digital storage media.

[0134] "Non-volatile memory" refers to electronic memory for the permanent storage of data. Non-volatile memory can be configured as non-modifiable memory, also known as read-only memory (ROM), or as modifiable memory, also known as non-volatile memory (NVM). In particular, this can be an EEPROM, such as a flash EEPROM, or flash for short. Non-volatile memory is characterized by the fact that the data stored on it is retained even after the power supply is turned off.

[0135] "Volatile electronic memory" refers to a memory for temporarily storing data, characterized by the fact that all data is lost after the power supply is turned off. In particular, this can be a volatile random-access memory (RAM) or a volatile processor memory.

[0136] A "protected memory area" is understood here to be an area of ​​an electronic memory to which access, i.e., read or write access, is only possible via a processor coupled to the memory. According to embodiments, access by the processor coupled to the memory is only possible if a necessary condition is met. This can be, for example, a cryptographic condition, in particular successful authentication and / or successful authorization verification.

[0137] A "processor" is understood here and below to mean a logic circuit that serves to execute program instructions. The logic circuit can be implemented on one or more discrete components, in particular on a chip. In particular, a "processor" is understood to mean a microprocessor or a microprocessor system comprising multiple processor cores and / or multiple microprocessors.

[0138] A "computer" or "computer system" can be, for example, a personal computer (PC) or a laptop. The computer can include an interface for connecting to the network, which can be a private or public network, in particular the Internet, a power grid, or another communications network. Depending on the embodiment, this connection can also be established via a mobile network.

[0139] An "interface" or "communication interface" is understood here as an interface through which data can be received and sent. The communication interface can be configured as contact-based or contactless. The communication interface can be an internal interface or an external interface, which is connected to an associated device, for example, via a cable or wirelessly.

[0140] A communication interface for wireless communication is a communication interface configured for contactless transmission and reception of data. Communication can be based, for example, on an RFID and / or NFC standard, such as Bluetooth. Furthermore, the communication interface can be configured for communication via a local radio network, for example, on a standard of the IEEE 802.11 family and / or Wi-Fi.

[0141] A "network" is understood here to mean any transmission medium with a connection for communication, in particular a local connection or a local network, in particular a PAN (Personal Area Network), LAN (Local Area Network), a private network, in particular an intranet, and a virtual private network (VPN). A network can be configured entirely or partially as a mobile network. For example, a computer system or mobile device can have a mobile interface for connecting to the mobile network. Furthermore, it can be a public network, such as a MAN (Metropolitan Area Network), WAN (Wide Area Network), GAN (Global Area Network), or the Internet. Depending on the embodiment, this connection can also be established via a mobile network.

[0142] A "program" or "program instructions" is understood here, without limitation, to mean any type of computer program that includes machine-readable instructions for controlling a functionality of the computer.

[0143] A "web browser" is understood here to be a computer program for retrieving and displaying documents and data over a network, in particular for retrieving and displaying web pages on the World Wide Web. For example, any hyperlinks, especially as connections between web pages, can be accessed using a web browser. In addition to HTML pages, web browsers can display various other types of documents, such as images, videos, or text files. A web browser is specifically configured to provide a user interface for web applications.

[0144] A "trust level" is understood below to mean a set of one or more parameter values ​​which indicate a degree of trustworthiness with regard to whether a user who has authenticated himself to the file management server computer system using a user computer system assigned to him is actually who he claims to be by providing his authentication data.

[0145] An "error correction bit" or "parity bit" is a bit that is generated in addition to one or more bits of the actual payload data and may be transmitted to a receiver, and which serves to control the integrity of said one or more bits of the payload data during transmission to the receiver.

[0146] An "error correction technique" is a technique used to detect and correct errors during the storage and transmission of data. An error may also consist of parts of a logically connected data set (e.g., a file) being temporarily or permanently unavailable, e.g., due to the failure of a storage medium that stored these parts. To achieve this, error correction techniques add additional redundancy in the form of additional error correction bits to payload data before it is stored or transmitted. These bits can be used to determine errors and error locations, as well as to reconstruct missing parts of the payload data.

[0147] Embodiments of the invention will be explained in more detail below with reference to the drawings. They show: Figure 1 shows a block diagram with a user computer system, a web server computer system, several storage services and a file management server computer system, Figure 2 shows a block diagram with several user computer systems, a web server computer system, several storage services and a file management server computer system, Figure 3 shows a block diagram of a user computer system, Figure 4 shows a block diagram of a web server computer system, Figure 5 shows a block diagram of a file management server computer system, Figure 6 shows a flow chart of a distributed storage of a file, Figure 7 shows a flow chart of a reading of a distributed stored file, Figure 8 shows a flow chart of a distributed storage of a file, Figure 9 shows a flow chart of a reading of a distributed stored file.

[0148] Elements of the following embodiments that correspond to one another are identified by the same reference numerals.

[0149] Figure 1shows a distributed infrastructure for cryptographically secured storage of files using a web application running on a web browser. The infrastructure comprises a user computer system 104, which includes a web browser for executing a web application. The corresponding web application is provided by a web server computer system 108 for retrieval via a network, such as the Internet, using a web browser. The web application is, for example, an existing web application via which services of the web server computer system 108 can be retrieved according to a client-server protocol.This web application is supplemented by an upload web module for uploading files for storage and a download web module for downloading files for access, which are integrated into the web application and enable it to store and retrieve files in the form of cryptographically secured file fragments F1-F3 in a distributed manner without additional programs.

[0150] For storage, the files are cryptographically secured by being encrypted and fragmented so that no conclusions can be drawn about the data content of the original file based on individual file fragments F1-F3. The fragmentation occurs according to a distribution plan 416, which also identifies the storage services SD1-SD4 on which the file fragments F1-F3 are to be stored. The corresponding distribution plans 416 are stored and managed, for example, by a file management server computer system 130. The corresponding distribution plans 416 can be generated, for example, by the web server computer system or the file management computer system 130. If the necessary information regarding the storage services SD1-SD6 is provided to the user computer system 104, for example via the web application, the user computer system 104 can also create the distribution plan via the web application.

[0151] Web server computer system 108 authenticates itself to file management server computer system 130 using authentication data 109 in order to provide the upload and download functionality to one or more user computer systems 104 via the web application. User 102 does not need to register with file management server computer system 130 or with storage services SD1-SD4. Furthermore, web server computer system 108 manages reference data that links the files to distribution plans 416 and users 102 of user computer systems 102. Using the corresponding reference data, web server computer system 108 can enable user 102 to access the distributed data at any time while executing the web application in the web browser on user computer system 104.

[0152] Figure 2shows a distributed infrastructure for storing files, which comprises several user computer systems 104, 162, 168, a web server computer system 108, several storage services SD1-SD6 with corresponding dedicated IT infrastructures 180-192 and storage media SM1-SM6, as well as a file management server computer system 130, each of which is communicatively or operatively connected to one another via a network 178. The system enables automated and dynamic provision of storage resources of the individual storage services, which can each be implemented, for example, as public cloud storage services. The provision is integrated as a functionality in a web application provided by the web server computer system 108 via the network 178. The storage services are preferably selected dynamically based on requirements specified by the web server computer system 108. For example, a minimum level of security is required.Storage services SD1-SD6 that are suitable for storage or are available are stored, for example, in a centrally stored catalog 329 of the web server computer system 108 or the file management server computer system 130.

[0153] For example, the user 102 may be assigned two user computer systems 104, 162, for example a desktop computer and a notebook, each of which has a network interface and a web browser.

[0154] For example, each of the user computer systems 104, 162 includes a specific asymmetric cryptographic key pair 136, 138; 164, 166. The private key 138, 166 is stored securely in the respective user computer system. Copies of the corresponding public keys 136, 164 are transmitted to the web server computer system 108 and centrally managed by it. Furthermore, the file management server computer system 130 can also have copies of the corresponding public keys 136, 164. For example, user 102 is assigned user profile 174, which contains the two public keys 136 and 164. The additional user 160 is assigned user profile 176, which contains public key 170. The private key 172 corresponding to public key 170 is stored securely on the additional user computer system 168.This enables the web server computer system 108, for example, to cryptographically protect reference data by encrypting it with one of the public keys so that only the owner of the associated private key can access it. According to embodiments, a user's private key can also be stored on a mobile, portable hardware token, allowing the user to use it on a plurality of user computer systems 104, 162. If the file management server computer system 130 also has copies of the corresponding public keys, it can, for example, encrypt the distribution plans 416 in a similar manner.

[0155] The two dashed arrows from Figure 2With regard to the file fragments F1 and F2, indicate that the file fragments F1-F4 generated from the file 101 by the error correction method FKV are stored directly, using an authorization token, bypassing the web server computer system 108 and the file management server computer system 130. However, to obtain the authorization tokens issued by the individual storage services, the user computer system 104 must interact with the web server computer system 108 via the web application, which causes the file management server computer system 130 to request the authorization tokens. The web server computer system 108 acts as a central instance for organizing the distributed storage.

[0156] Figure 3shows a block diagram of the user computer system 104. The user computer system 104 includes a user interface 134. The interface may, for example, include a graphical user interface displaying a web browser 106 executing on the user computer system 104. Furthermore, the interface 134 may include input means, such as a keyboard or mouse, that allow the user to access the web application and / or select files for uploading or downloading using the web application. The user can also authenticate themselves to the web server computer system via the user interface 134. For this purpose, the user interface 134 includes, for example, one or more sensors for detecting one or more biometric characteristics of the user 102.The user computer system 104 includes a processor 135 and a non-volatile storage medium 105 on which the web browser 106 is installed for calling and executing web applications 107. The web applications 107 are executed by the web browser, but are not themselves installed on the user computer system 104. The web browser 106 can communicate with the web server computer system 108 via an interface 131; in particular, the web application 107 can be accessed via the interface 131. Furthermore, services can be used. The web application 107 communicates via the interface 131, for example, with a server application 354 installed on the web server computer system 108. In addition, indirect communication with the file management server computer system 130 via the web server computer system 108 is enabled by means of the interfaces 132 and 133.The web application 107 can also provide interfaces 116-128 that define standardized file operations ("CRUD": "CREATE", "READ", "UPDATE", "DELETE") that can be interpreted and executed by each of the storage services. Thus, interfaces 116-128 ultimately represent a uniform interface with a uniform method signature for CRUD operations.

[0157] The web application 108 comprises modules for implementing the storage function. This is, for example, an encryption / decryption module 110, which stores and / or generates, for example, symmetric keys and / or asymmetric keys 136, 138. These keys are used to encrypt or decrypt files, reference data, and / or distribution plans. The symmetric key can, for example, be a hash value of the file 101 to be encrypted, with which the corresponding file can be encrypted before fragmentation and later decrypted. After the symmetric key has been added to the reference data, it is, for example, deleted so that it is only available as part of the reference data. Furthermore, the unencrypted reference data is, for example, deleted after encryption so that it is only available in encrypted form.According to embodiments, module 110 also serves to encrypt and decrypt file fragments of the encrypted file. Furthermore, it manages public key 136. For example, it transmits public key 136 via interface 132 to web server computer system 108 and / or file management computer system 130. Furthermore, encryption / decryption module 110 uses public key 136 to encrypt reference data or at least symmetric keys of the distributed files. Thus, module 110 allows the generation and use of symmetric keys as well as the use and management of public and private keys 136, 138.

[0158] In addition, the web application 107 can include a fragmentation / defragmentation module 111 that can split a file 101 encrypted with the symmetric key by means of the module 110 into several file fragments F1-F4 by applying an error correction method FKV specified in a distribution plan and enrich them with error correction bits. If one or more of the storage services on which file fragments of the file are stored fail, the defragmentation function of the module 111 can regenerate the original file from the remaining file fragments, provided the error correction bits contained in the remaining file fragments are sufficient for this purpose.

[0159] Another module 112, referred to here as the distribution / aggregation module, contains several functionalities used for the distributed and secure storage of the file fragments generated by module 111 in the storage services SD2, SD4-SD6 specified in the distribution plan. For example, module 112 can calculate a hash value of the original file 101. Furthermore, a hash value of each of the generated file fragments F1-F4 can be calculated, which serve as identifiers of the file fragments and are assigned to the original file name of the file using a "mapping." The symmetric key, the hash values, and the mapping can serve as reference data to enable reconstruction of the file from the file fragments. Furthermore, the reference data can include identifiers and paths of the storage services in which the file fragments were stored.Furthermore, the reference data can identify the storage location of the distribution plan for the reconstruction of the corresponding file 101. For example, the reference data 404 of the file 101 generated by a user computer system 104, or at least the symmetric key, is encrypted by a public key 136, which is specifically assigned to the user computer system 104 and thus also to the user 102, and transmitted in encrypted form to the web server computer system 108 via the network 178. If the user computer system 104 is to access the distributed file 101 at a later time, it can receive the reference data from the web server computer system 108 during the execution of the web application 107 and decrypt the encrypted reference data with the symmetric key using the private key 138. The aggregation functionality of the module 112 allows, for example,a reconstruction of the original file 101 from the file fragments F1-F4 using the reference data 440 and the distribution plan 416. The reconstructed file can be decrypted using the module 110 and the symmetric key.

[0160] Figure 4 shows a block diagram of the web server computer system 108. The web server computer system 108 includes a processor 350 and a non-volatile storage medium 352 on which a server application 354 is installed.

[0161] This can be used to manage multiple profiles 356 of web applications 107 or the registered users of web applications 107, for example, web application profile 174 of user 102 or web application profile 176 of user 160. The web application profiles 174, 176 include, for example, public keys 136, 164, 170 assigned to the corresponding users 102, 160. Furthermore, the profiles 356 can include one or more reference data lists 362, 364 in which reference data of the files stored distributed across the web application on the storage services are stored for specific or all users of the web application 107. For example, the reference data 362, 364 are stored on the web server computer system 108 in a cryptographically secured form, such as encrypted and / or with limited access.

[0162] Furthermore, the web server computer system 108 includes, for example, a catalog of all storage services suitable or available for distributed storage.

[0163] The web server computer system 108 provides the web application 107 for retrieval over the network 178 using the interface 132.

[0164] Module 366 of server application 354, for example, is responsible for the central management of access rights and for checking file-related access authorization by other users. A user can verify their authorization to the server application 354 while executing the web application 107 by providing trustworthy proof of their identity, which can be composed of various attributes (name, email address, bank account, residential address, date of birth, nationality, etc.). The authenticity of these attributes can be confirmed with varying levels of effort (e.g., a bank account through a transfer with a transmitted secret in the "Purpose of Payment" field, email through sending an email with a confirmation link, residence or date of birth, or by securely reading the data from an electronic ID card).

[0165] Module 368 manages reference data of a plurality of files, which were used and / or generated during the execution of web application 107, of a plurality of users who have registered with server application 354. Based on the reference data, module 338 can enable users 102, 160 to access the distributed files when using web application 107. Overall, according to embodiments, a flexible solution for secure and highly available data outsourcing using multiple external storage services can be provided. Users can access distributed files using web application 107, provided they have the appropriate authorizations. They do not need to have specific client applications 108 installed to do so.

[0166] Module 370 provides one or more services that can be accessed by users via the web application according to a client-server model.

[0167] Figure 5shows a block diagram of the file management server computer system 130. The file management server computer system 130 comprises a processor 342 and a non-volatile storage medium 302 on which a file management application 304 is installed. This can be used, for example, to manage multiple server profiles 306, for example server profile 171 of the web server computer system 108 as well as further server profiles 173 of other web server computer systems that provide web applications with integrated file storage via the network 178. The web server computer systems can specify configurations 175, 179 for the respective profiles, which of the storage services SD1-SD6 available according to the catalog 329 should be used for storing files and which requirements their IT infrastructures must meet in order for them to be used.

[0168] The file management application 304 can therefore manage the server profiles of several web server computer systems as a central instance and also control and implement the specifications of the web server computer systems regarding the storage services SD1-SD6.

[0169] For example, module 330 of file management application 304 is responsible for centrally managing access rights and for checking file-related access authorization. A web server computer system 108 can authenticate itself to file management application 304 using authentication module 336.

[0170] Module 332 is used to request authorization tokens from the storage services specified in the distribution plan after a web server computer system 108 has proven its authorization to provide access to a file to the file management application 304. The authorization tokens are signed with a signing key 334 of the file management application 304 and sent in signed form to the web server computer system 108, from which a corresponding authorization request for file access was received. The web server computer system 108 then forwards the corresponding authorization tokens to a user computer system, for example, via a web application.

[0171] Module 338 manages distribution plans for a plurality of files generated, for example, by web server computer systems or user computer systems. The distribution plans can be used to identify where the file fragments are stored and how they should be defragmented. Alternatively, module 338 itself can enable dynamic creation and forwarding of distribution plans for the distributed storage of a file 101, wherein the distribution plan specifies an error correction method (FKV) and multiple storage services (SD1-SD6).

[0172] Figures 6A and 6Bshow the process of distributed storage of a file according to one embodiment. In step 400, the user registers with the web server computer system 108 or a service provided by the web server computer system 108. In step 402, a public encryption key 136 is generated and transmitted to the web server computer system 108 via the interface 131 in step 404. The transmission of the public key 136 can occur, for example, during the registration 400 of the user with the web server computer system 108 or thereafter. The user computer system 104 includes, for example, the public cryptographic key 136, i.e., the public encryption key. The associated private key 138, i.e., the private decryption key, is stored in a protected memory area of ​​the user computer system 104 or an additional hardware token.

[0173] In step 406, the web application provided by the web server computer system 108 is accessed via a web browser of the user computer system 104. In step 407, in response to the request from step 406, the user computer system 104 receives program instructions for executing the web application in the web browser on the user computer system 104. In step 408, the user of the user computer system 104 authenticates to the web server computer system 108 using the web application.

[0174] In order to store a specific file in a distributed manner, a decentralized storage operation is required to access or integrate multiple storage services. In step 410, such a storage operation for storing a file distributed across multiple storage services is initiated by the user or the user's computer system. In step 410, for example, a symmetric key is generated to encrypt the file to be stored in a distributed manner. In step 418, the file is encrypted with the generated key. Encryption is performed, for example, with a hash value of file 101, which serves as a symmetric cryptographic key.

[0175] However, for storage on the storage services, no direct authentication with the individual storage services or the file management server computer system is performed by the user computer system 104. Rather, the user computer system 104 only authenticates itself to the web server computer system 108 in step 408. According to embodiments, the authentication can also occur when calling the web application.

[0176] In step 412, the web server computer system 108 automatically identifies the identity and number of storage services to be used to store file fragments of the file 101 to be saved. Furthermore, the web server computer system 108 identifies an error correction method for fragmenting the file to be saved. Furthermore, it is checked that the error correction method distributes the file into file fragments in such a way that requirements regarding the availability of the file are met. In general, the higher the proportion of error correction bits per file fragment, the larger the amount of data to be transmitted over the network and the greater the redundancy of the transmitted data, but also the higher the availability of the file despite a possible failure of one or more of the storage services.

[0177] In step 414, the web server computer system 108 generates a distribution plan that includes identifiers of the determined storage services as well as instructions for implementing the determined error correction method (e.g., configuration data of the error correction method). The distribution plan is transmitted to the user computer system 104 via the network in step 416. Alternatively, in some embodiments, the distribution plan can also be created by the user computer system 104. In step 418, the user computer system 104 encrypts the file 101 and, using the error correction method specified in the distribution plan, generates several file fragments F1-F4 of the encrypted file in step 418. According to embodiments, the individual file fragments can each be additionally encrypted with the same or a further symmetric key.

[0178] In order to be able to save the generated file fragments, the web server computer system 108 sends an authorization request to the file management server computer system 130 in step 420. This authorization request includes a query as to whether the web server computer system 108 is authorized to access the storage services or their storage media specified in the distribution plan for writing purposes in order to save the file fragments there. In response to receiving the authorization request, the file management server computer system 130 checks in step 422 whether the web server computer system 108 is authorized for the requested write operation.If this is the case and the web server computer system 108 has also successfully authenticated itself to the file management server computer system 130, the file management server computer system 130 requests authorization tokens from the storage services SD1-SD& specified in the distribution plan and in the authorization request via the network in step 424. The authorization tokens can be configured, for example, as URLs 428. In response to receiving the request, the individual storage services SD1-SD& generate URLs for accessing a storage area of ​​storage media of the respective storage services in step 426 and send the URLs to the file management server computer system 130 in step 428. The file management server computer system 130 signs the received URLs in step 430 and forwards them in signed form 432, for example, via the web server computer system 108, to the user computer system 104.

[0179] The user computer system uses the signed URLs to directly write to the memory areas of the individual storage services specified in the URLs and to store the file fragments F1-F4 directly in the storage media of said storage services SD1-SD6 over the network, bypassing the file management server computer system 130 in step 434. However, in step 436, the individual storage services perform a signature verification of the signed URLs using a signature verification key that forms an asymmetric cryptographic key pair with the signing key 334 of the file management server computer system 130. For example, file fragments are only stored in step 438 if the verification shows that the signature of the URL is valid.

[0180] In step 440, the symmetric cryptographic key used to encrypt the file is added to reference data for the distributed file 101 and sent to the web server computer system 108 for storage. The reference data may further include information about the user, the file, the key used for cryptographic security, and / or the location of the distribution plan. The reference data is stored, for example, in encrypted form by the web server computer system 108. Likewise, the distribution plan identified by the reference data is stored, for example, in encrypted form by the file management computer system 130.

[0181] The Figures 7A and 7Bshow a flowchart of a read access of a user computer system 104 of another user 160 to the distributed stored file 101. In step 500, the web application provided by the web server computer system 108 is called or requested via a web browser of the user computer system 104. In step 502, in response to the request from step 500, the user computer system 104 receives program instructions for executing the web application in the web browser on the user computer system 104. In step 504, the user of the user computer system 104 authenticates himself to the web server computer system 108 using the web application.

[0182] During the execution of the web application, the need arises to access a distributed file 101. This process, i.e., initiating a read access, is represented as read operation 506. In order to be able to access the file 101 for reading, the user computer system 104 receives, in step 508, reference data 440 from the web server computer system 108, which is associated with the file 101 to be read. Furthermore, the user computer system 104 and / or the web server computer system 108 analyzes the reference data 440 in step 510. If necessary, the user computer system 104 makes at least a portion of the decrypted reference data 440 available to the web server computer system 108 for this purpose.

[0183] In step 512, the web server computer system 108 sends an authorization request to the file management server computer system 130. This authorization request includes a query as to whether the web server computer system 108 is authorized to read the storage services specified in the distribution plan or their storage media in order to download the file fragments from there. In response to receiving the authorization request, the file management server computer system 130 checks in step 514 whether the web server computer system 108 is authorized for the requested write operation. If this is the case and the web server computer system 108 has also successfully authenticated itself to the file management server computer system 130, the file management server computer system 130 requests authorization tokens SD1-SD& from the storage services specified in the distribution plan and in the authorization request over the network in step 516.The authorization tokens can be configured, for example, as URLs 520. In response to receiving the request, the individual storage services SD1-SD& generate URLs for accessing a storage area of ​​storage media of the respective storage services in step 426 and send the URLs to the file management server computer system 130 in step 520. The file management server computer system 130 signs the received URLs in step 522 and forwards them in signed form to the user computer system 104 in step 524, for example, via the web server computer system 108.

[0184] The signed authorization tokens 524 enable the user computer system 104 to perform direct read access 526 to the storage media of the respective storage services using the signed URLs. Read access is only permitted by the respective storage services, for example, if a signature verification using the signature verification key 441 in step 528 by the respective storage services reveals that the signature of the authorization tokens is valid. In this case, the storage services grant permission to read the respective stored file fragments in step 530. The file fragments are transmitted directly to the user computer system 104 via the network in step 532.

[0185] In step 534, the received file fragments are assembled into the original encrypted file 101 by the web application running in the web browser on the user computer system 104. If the individual file fragments 530 are each additionally encrypted, they are decrypted before assembly or reconstruction using corresponding keys that, for example, identify the reference data. Furthermore, the reconstructed file 101 is finally decrypted by the user computer system 104 using the corresponding symmetric key.

[0186] Figure 8shows a method for storing a file 101 using multiple storage services over a network using a web application executed in a web browser. In step 600, the corresponding web application is called by a web server computer system 108 using the web browser over a network, such as the Internet, and executed in the web browser on the user computer system 104. In a first step 602, a distribution plan for fragmenting and distributing the file 101 is received by the web application. In step 604, the web application generates a symmetric key 139 for encrypting the file 101 to be stored. In step 606, the file 101 is encrypted with the symmetric key 139.In step 608, the web application on the user computer system 104 performs an error correction process specified in the distribution plan and generates file fragments to be stored in multiple storage services according to the distribution plan. To this end, in step 610, the web application initiates an authorization request through the web server computer system 108 to a file management computer system 130 regarding the storage of the file 101 using the storage services specified in the distribution plan 416. In response to receiving the authorization request, the file management computer system 130 requests an authorization token from each of the storage services in which a file fragment is to be stored. In step 612, the file management computer system forwards the authorization tokens via the web server computer system 108 to the user computer system 104.According to some embodiments, the authorization tokens are additionally signed by the file management computer system 130 before forwarding. In step 614, the user computer system 104 uses the authorization tokens to verify its authorization to write the file fragments to the individual storage services and, after successfully verifying authorization, stores the generated file fragments in the storage media of the corresponding storage services, bypassing the web server computer system 108 and the file management server computer system 130. In step 616, the user computer system 104 creates reference data for the distributed file and encrypts it with a public key 136, which forms an asymmetric cryptographic key pair with a private key 138 stored in a protected memory area of ​​a hardware token.The reference data is sent in step 618 from the user computer system 104 to the web server computer system 108 for storage via the web application.

[0187] Figure 9shows a method for reconstructing a file 101 stored distributed across multiple storage services over a network using a web application executed in a web browser. In step 700, the corresponding web application is accessed by a web server computer system 108 via the web browser over a network, such as the Internet, and executed in the web browser on the user computer system 104. In step 702, the web application initiates an authorization request from the web server computer system 108 to the file management server computer system 130 regarding access to the file 101 stored distributed using the storage services specified in the distribution plan 416. In response to receiving the authorization request, the file management server computer system 130 requests an authorization token from each of the storage services in which a file fragment is stored.In step 704, the file management server computer system 130 forwards the authorization tokens to the web application via the web server computer system 108. According to some embodiments, the authorization tokens are additionally signed by the file management server computer system 130 before forwarding. In step 706, the user computer system 104 or the web application uses the authorization tokens to verify its authorization to download the file fragments to the individual storage services. After successfully verifying the corresponding authorization, they receive the stored file fragments from the storage media of the individual storage services, bypassing the web server computer system 108 and the file management server computer system 130.According to embodiments, in step 708, the web application receives additional encrypted reference data from the web server computer system 108 for reconstructing the distributed file 101. In the case of the encrypted reference data, for example, at least the symmetric key included therein is encrypted using an asymmetric encryption method. In step 710, the web application decrypts the reference data. In step 712, the web application executes an error correction method on the user computer system 104, which is specified in the distribution plan, and reconstructs the encrypted file 101 from the file fragments. In step 714, the encrypted file 101 is decrypted using the corresponding symmetric key. List of reference symbols

[0188] F1-F4 File fragments FKV Error correction method SD1-SD6 Storage services SM1-SM6 Storage media 180-192 IT infrastructure of storage services 101 File 102 User 104 User computer system 105 Storage medium 106 Web browser 107 Web application 108 Web server computer system 109 Authentication data 110 Encryption / decryption module 111 (De-)fragmentation module 112 Distribution / aggregation module 113 Service module 114 Upload module 115 Download module 116-128 Standardized interfaces 130 File management server computer system 131 Interface 132 Interface 133 Interface 134 User interface 135 Processor 136 Public key 138 Private key 160 User 162 User computer system 164 Public key 166 private key 168 user computer system 170 public key 171 server profile 172 private key 173 server profile 174 user profile 175 configuration 176 user profile 177 distribution plans 178 network 179 configuration 302 storage medium 304 file management application 306 directorymultiple user profiles 329Storage service catalog 330Authorization management module 332Authorization token management module 334Signing key 336User authentication module 338Distribution plan management module 342Processor 350Processor 352Storage medium 354Server application 356Multiple user profile directory 362Reference data list 364Reference data list 366User authentication module 368Reference data management module 370Service provisioning module 400-406Steps 407Web application 408-414Steps 416Distribution plan 418Authorization request 422Step 424URL request 426Step 428Authorization token 430Step 432Signed authorization token 434Transmitted file fragments 436-438Steps 440Reference data 441Signature verification key 500-510Steps 512Authorization request 514Step 520Authorization token 522Steps 524Signed authorization token 524Read access 526-530Steps 532Transmitted file fragments 534Step600-618 steps 700-714 steps

Claims

1. A method for cryptographically secure storing of a file (101) using a web application (107) executed by a web browser (106) on a user computer system (104, 162, 168) of a user (102, 160), the method comprising - invoking the web application (107) from a web server computer system (108) over a network (178) by the web browser (106) on the user computer system (104, 162, 168), - encrypting the file (101) with a cryptographic key locally on the user computer system (104, 162, 168) using the web application (107), - providing a distribution plan (177, 416) by the web application (107), wherein the distribution plan (177, 416) comprises instructions for fragmenting the file (101) into a plurality of file fragments (F1-F4) by means of an error correction method (ECM) and identifiers of a plurality of mutually independent storage services (SS1-SS6) in whose non-volatile storage media (SM1-SM6) the generated file fragments (F1-F4) are to be stored, characterized in that - the encrypted file (101) is fragmented on the user computer system (104, 162, 168) by the web application (107) into a plurality of file fragments (F1-F4) by the error correction method (ECM) according to the distribution plan (177, 416), wherein at least one of the file fragments (F1-F4) includes error correction bits, - the resulting file fragments (F1-F4) are sent by the web application (107) over the network (178) to the storage services (SS1-SS6) identified by the distribution plan (177, 416), wherein an authorization token is provided by the web server computer system (108) for each of the storage services (SS1-SS6) as proof of authorization to store the corresponding file fragment (F1-F4).

2. The method of claim 1, wherein the web server computer system (108) provides a service via the web application (107), wherein the file (101) to be stored comprises data generated and / or used in the course of executing the service, and / or wherein the providing of the distribution plan (177, 416) comprises generating the distribution plan (177, 416) on the user computer system (104, 162, 168) by the web application (107) or receiving the distribution plan (177, 416) on the user computer system (104, 162, 168) by the web application (107), and / or wherein the method further comprises sending the distribution plan (177, 416) from the web application (107) over the network (178) to a file management server computer system (130) for storage, and / or wherein the method further comprising encrypting the distribution plan (177, 416).

3. The method of any one of the preceding claims, wherein the authorization tokens are received by the web application (107) on the user computer system (104, 162, 168) from the file management server computer system (130), wherein the received authorization tokens comprise an authorization token of each of the plurality of storage services (SS1-SS6) identified in the distribution plan (177, 416), which were requested by the file management server computer system (130) on command of the web server computer system (108) and forwarded to the user computer system (104, 162, 168).

4. The method of claim 3, wherein the receiving of the authorization tokens requires successful authentication of the web server computer system (108) against the file management server computer system (130).

5. The method of any one of the preceding claims, wherein the sending of the file fragments (F1-F4) by the web application (107) to the identified storage services (SS1-SS6) is performed bypassing the web server computer system (108) and / or the file management server computer system (130), and / or wherein the authorization tokens are implemented as URLs each enabling direct read access to a storage location identified by the URL on one of the storage media (SM1-SM6) of one of the storage services (SS1-SS6).

6. The method of any one of the preceding claims, wherein the method further comprises creating reference data, which are associated with the file (101), serve to reconstruct the file (101) from the distributedly stored file fragments (F1-F4) and are stored by the web server computer system (108).

7. The method of claim 6, wherein the reference data comprises: an identifier of the user (102, 160), an identifier of the file (101), an identifier of the distribution plan (177, 416), an identifier of a cryptographic key for decrypting the encrypted file (101), an identifier of a cryptographic key (138, 166, 172) for decrypting the encrypted distribution plan (177, 416), a hash value of the complete file (101) and / or hash values of the stored file fragments (F1-F4), and / or wherein the reference data is stored by the web server computer system (108) in a cryptographically secure form, and / or wherein the web application (107) communicates the reference data to a server module (368) for managing reference data, which is executed by a processor (350) of the web server computer system (108), and / or wherein the reference data is stored by the web server computer system (108) in a reference list comprising a plurality of reference data for a plurality of files of different users (102, 160) of the web application (107).

8. The method of any of the preceding claims, wherein the method further comprises authenticating the user (102, 160) against the web server computer system (108), and / or wherein one or more modules (110, 111, 113) for a distributed storage of the file (101) on the storage services (SS1-SS6) are integrated into the web application (107), and wherein the encryption, fragmentation and transmission are performed by executing the modules (110, 111, 113) of the web application (107) in the web browser (106) by a processor (135) of the user computer system (104, 162, 168).

9. The method of any one of the preceding claims, wherein the method for downloading the cryptographically secured stored file (101) using the web application (107) executed by the web browser (106) on the user computer system (104, 162, 168) further comprises: - invoking the web application (107) from the web server computer system (108) over the network (178) by the web browser (106) on the user computer system (104, 162, 168), - providing the distribution plan (177, 416) of the distributedly stored file (101) by the web application (107), wherein the distribution plan (177, 416) comprises instructions for defragmenting the file (101) from a plurality of file fragments (F1-F4) by means of an error correction method (ECM) and identifiers of the plurality of mutually independent storage services (SS1-SS6) in whose non-volatile storage media (SM1-SM6) the file fragments (F1-F4) are stored, - providing by the web server computer system (108) an authorization token of each of the storage services of at least a selection of the storage services (SS1-SS6) in whose non-volatile storage media (SM1-SM6) the file fragments (F1-F4) are stored, wherein the file fragments (F1-F4) included in the selection of the storage services (SS1-SS6) are sufficient for a complete reconstruction of the file (101), - downloading the file fragments (F1-F4) from the individual storage services using the authorization tokens as proof of authorization for downloading, - defragmenting the encrypted file (101) from the file fragments (F1-F4) on the user computer system (104, 162, 168) by the web application (107) using the error correction method (ECM) in accordance with the distribution plan (177, 416), - decrypting the encrypted file (101) with a cryptographic key on the user computer system (104, 162, 168) by the web application.

10. The method of claim 9, wherein the web server computer system (108) provides a service via the web application (107), and wherein data included in the downloaded file (101) is used in the course of execution of the service by the web application (107), and / or wherein the providing of the distribution plan (177, 416) comprises receiving the distribution plan (177, 416) from the file management server computer system (130) on the user computer system (104, 162, 168) by the web application (107), wherein the distribution plan (177, 416) is provided in encrypted form, and the providing further comprises decrypting the distribution plan (177, 416) on the user computer system (104, 162, 168) by the web application (107), wherein the providing of the authorization tokens on the user computer system (104, 162, 168) by the web application (107) comprises receiving the authorization tokens from the file management server computer system (130), which were requested by the file management server computer system (130) on command of the web server computer system (108) and forwarded to the user computer system (104, 162, 168), wherein receiving the authorization tokens requires successful authentication of the web server computer system (108) against the file management server computer system (130), and / or wherein the downloading of the file fragments (F1-F4) by the web application (107) from the identified storage services (SS1-SS6) is performed bypassing the web server computer system (108) and / or the file management server computer system (130), and / or wherein the method further comprises receiving reference data associated with the file (101) to be downloaded and serving to reconstruct the file (101) from the distributedly stored file fragments (F1-F4), from the web server computer system (108) by the web application (107) on the user computer system (104, 162, 168), and / or wherein the downloading of the file (101) requires successful authentication of the user (102, 160) against the web server computer system (108), and / or wherein one or more modules (110, 111, 113) for a distributed storage of the file (101) on the storage services (SS1-SS6) are integrated into the web application (107), and wherein the downloading, defragmentation and decryption are performed by executing the modules (110, 111, 113) of the web application (107) in the web browser (106) by the processor (135) of the user computer system (104, 162, 168).

11. A user computer system (104, 162, 168) comprising a processor (135), a network interface (131) for operatively coupling the user computer system (104, 162, 168) to a web server computer system (108) and a plurality of storage services (SS1-SS6) over a network (178), wherein the user computer system (104, 162, 168) comprises a storage medium (105) having a web browser (106) executable by the processor (135), wherein the web browser (106) is configured to execute the following method for cryptographically secure storing of a file (101) using a web application (107) executed by the web browser (106): - invoking the web application (107) from the web server computer system (108) over the network (178) by the web browser (106) on the user computer system (104, 162, 168), - encrypting the file (101) with a cryptographic key locally on the user computer system (104, 162, 168) using the web application (107), - providing a distribution plan (177, 416) by the web application (107), wherein the distribution plan (177, 416) comprises instructions for fragmenting the file (101) into a plurality of file fragments (F1-F4) by means of an error correction method (ECM) and identifiers of the plurality of storage services (SS1-SS6) in whose non-volatile storage media (SM1-SM6) the generated file fragments (F1-F4) are to be stored, characterized in that - the encrypted file (101) is fragmented on the user computer system (104, 162, 168) by the web application (107) into a plurality of file fragments (F1-F4) by the error correction method (ECM) according to the distribution plan (177, 416), wherein at least one of the file fragments (F1-F4) includes error correction bits, - the resulting file fragments (F1-F4) are sent by the web application (107) over the network (178) to the storage services (SS1-SS6) identified by the distribution plan (177, 416), wherein an authorization token is provided by the web server computer system (108) for each of the storage services (SS1-SS6) as proof of authorization to store the corresponding file fragment (F1-F4).

12. A web server computer system (108) comprising a processor (350), a network interface (132) for operatively coupling the web server computer system (108) to a user computer system (104, 162, 168), wherein the web server computer system (108) comprises a storage medium (352) containing program instructions, wherein the program instructions are configured, when executed by the processor (350), to send program instructions for executing the web application (107) in a web browser (106) on the user computer system (104, 162, 168) over the network (178) to the user computer system (104, 162, 168) in response to receiving an invocation of a web application (107) from a web browser (106) on the user computer system (104, 162, 168) over the network (178), wherein the web application (107) is configured to perform the following method for cryptographically secure storing of a file (101): - encrypting the file (101) with a cryptographic key locally on the user computer system (104, 162, 168) using the web application (107), - providing a distribution plan (177, 416) by the web application (107), wherein the distribution plan (177, 416) comprises instructions for fragmenting the file (101) into a plurality of file fragments (F1-F4) by means of an error correction method (ECM) and identifiers of a plurality of storage services (SS1-SS6) in whose non-volatile storage media (SM1-SM6) the generated file fragments (F1-F4) are to be stored, characterized in that - the encrypted file (101) is fragmented on the user computer system (104, 162, 168) by the web application (107) into a plurality of file fragments (F1-F4) by the error correction method (ECM) according to the distribution plan (177, 416), wherein at least one of the file fragments (F1-F4) includes error correction bits, - the resulting file fragments (F1-F4) are sent by the web application (107) over the network (178) to the storage services (SS1-SS6) identified by the distribution plan (177, 416), wherein an authorization token is provided by the web server computer system (108) for each of the storage services (SS1-SS6) as proof of authorization to store the corresponding file fragment (F1-F4).

13. The web server computer system of claim 12, wherein the web server computer system (108) is further configured to provide a service via the web application (107), wherein the file (101) to be stored is generated in a course of execution of the service by the web application (107).

14. A system comprising a file management server computer system (130), a web server computer system (108) according to any one of claims 12 or 13, and at least one user computer system (104, 162, 168) according to claim 11, wherein the file management server computer system (130) comprises a processor (342), a network interface (133) for operatively coupling the file management server computer system (130) to the web server computer system (108), to the at least one user computer system (104, 162, 168) and to a plurality of storage services (SS1-SS6) over a network (178), and a storage medium (302) having program instructions, wherein the program instructions are configured, when executed by the processor (342), to perform the following method for cryptographically secure storing of a file (101): - receiving an authorization request from the web server computer system (108) to store file fragments (F1-F4) of the file (101) over the network (178) in the plurality of storage services (SS1-SS6) according to a distribution plan (177, 416), wherein the file management server computer system (130) does not provide any of the storage services (SS1-SS6), - in response to receiving the authorization request, requesting an authorization token from each of the multiple storage services (SS1-SS6) and forwarding the authorization tokens received in response to the request to the at least one user computer system (104, 162, 168), - storing the distribution plan (177, 416), wherein the distribution plan (177, 416) comprises instructions for defragmenting the file (101) from a plurality of file fragments (F1-F4) by means of an error correction method (ECM) and identifiers of the plurality of storage services (SS1-SS6) in whose non-volatile storage media (SM1-SM6) the file fragments (F1-F4) are stored.