Service providing system and method for web browser-based data security

The method and system for web browser-based data security address the challenge of unauthorized data theft by determining the operational state of developer tools and using one-time encryption/decryption modules to enhance data security in web browser environments.

JP2025085586AActive Publication Date: 2025-06-05DRM INSIDE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024103523
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-24
Filing Date
2024-06-27
Publication Date
2025-06-05
Estimated Expiration
2044-06-27

AI Technical Summary

Technical Problem

Current web browser environments face challenges in preventing unauthorized data theft, as developer tools can be used to debug encrypted data, exposing encryption keys and compromising data security.

Method used

A method and system for web browser-based data security that involves a registration step where a web browser executes a security script, generates a unique identifier, and transmits it to a web server. The web server sets a start time and determines if the developer tool is operational by measuring the time difference between the start and end times of script requests. If the developer tool is operational, an error page is displayed, and a one-time encryption/decryption module is generated for secure data transfer.

Benefits of technology

This approach effectively prevents unauthorized data theft by accurately determining the operational state of developer tools and generating one-time encryption/decryption modules to enhance data security in web browser environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025085586000001_ABST
    Figure 2025085586000001_ABST
Patent Text Reader

Abstract

To provide a service providing system and method for web browser-based data security capable of enhancing security of data transmitted in web browser environment.SOLUTION: The present disclosure relates to a service providing system and method for security of data based on a web browser, the system and method preventing unauthorized takeover of data by accurately finding out whether development tools provided from a web browser for hacking data, which is transmitted through the web browser are being driven, and the system and method securing security for data by using a one-off encryption / decryption module. The system and method support so that it is possible to accurately find out whether developer tools are being driven through a web server and prevent execution of the developer tool by guiding a hacker to an error page when driving the developer tool, so that safe transmission of data and security of data can be enhanced.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a system and method for providing a service for web browser-based data security, and more particularly, to a system and method for providing a service for web browser-based data security, which accurately determines whether a developer tool provided by a web browser for hacking data transferred through the web browser is operational to prevent unauthorized theft of data and ensures data security by using a one-time encryption / decryption module. [Background technology]

[0002] Currently, anyone can use developer tools in a web browser, and even if the JavaScript corresponding to a program is obfuscated, it can be easily debugged through the developer tools, so it is not easy to transfer data safely in a web browser environment.

[0003] Therefore, no matter how encrypted data is transmitted in the current web browser environment, it is possible to obtain the encryption key through developer tools provided by the web browser, find the decryption mechanism, and then automate this process into a program to replicate large amounts of website data.

[0004] Data security in current data web browsers can be summarized into two points: 1. How to prevent Developer Tools from running or detect when they are running 2. How to securely transmit the key used to decrypt encrypted data

[0005] In the first method, the existing security system checks whether the developer tool can be executed by checking the difference in operating time. That is, when the developer tool is not running, the time it takes for a program to run from the A code area to the B code area is very short, but if the developer tool is running and a breakpoint is set, the time can be extended. Also, if many values ​​are output to the developer tool log, in an environment where the developer tool is not running, the code is not executed and the time is ignored, but when the developer tool is running, the output time is very long, so a difference in program time occurs. Using this principle, we check whether the developer tool is running.

[0006] However, this method has a problem that if a function that checks time in a web browser is hooked to make the time run slowly, the web browser cannot measure time properly, so the method described above can be easily circumvented and is vulnerable to hacking.

[0007] In addition, in the above two methods, the existing security system makes it difficult to effectively and securely transfer data because, when a developer tool is running, the encryption algorithm as well as the decryption key can be analyzed through the program.

[0008] In addition, the encryption and decryption methods used on current sites are usually AES-128-CBC, which can be easily decrypted using a JavaScript encryption library such as CryptoJS if only the algorithm and key are known, making them even more vulnerable to hacking via developer tools. [Prior art documents] [Patent documents]

[0009] [Patent Document 1] Korean Patent No. 10-0890720 Summary of the Invention [Problem to be solved by the invention]

[0010] The present invention aims to improve data security by checking whether a developer tool of a web browser can be operated and verifying whether the developer tool can be operated in a web server that transmits data requiring security to the web browser, and to improve the security of data transmitted in a web browser environment by helping to prevent exposure of the encryption / decryption module by generating and providing a one-time encryption / decryption module every time a program included in a web page is executed in the web browser. [Means for solving the problem]

[0011] A method for providing a service for web browser-based data security according to an embodiment of the present invention includes a registration step in which a web browser of a user terminal executes a security script of a web page received from a web server and transmits identifier registration request information including a unique identifier generated through the security script to the web server; a start setting step in which, when the web server receives the identifier registration request information, a time point at which the identifier registration request information is received is set as a start time point for determining whether to operate a developer tool provided by the web browser for debugging the web page; and a start setting step in which the web browser determines whether to operate the developer tool through the security script. and if the developer tool is not driven, transmitting script request information to the web server for requesting a decryption process script related to a data decryption process; and, when the web server receives the script request information, setting a time point at which the script request information is received as an end time point for determining whether the developer tool is driven and determining whether a time difference between the start time point and the end time point is less than a preset reference setting time; and, when the time difference is equal to or greater than the preset reference setting time, transmitting a non-routine script to the web browser for displaying an error page on the web browser.

[0012] As an example related to the present invention, the method may further include, after the script providing step, displaying an error page through the non-routine script when the web browser receives the non-routine script.

[0013] As an example related to the present invention, the drive determination step includes a first determination step in which the web browser applies a call confirmation method for confirming a target that called a function or variable to a time function for measuring a time required for execution of the developer tool through the security script, calculates whether a hook occurs in the time function, and determines whether the developer tool is to be driven depending on whether the hook occurs; a second determination step in which the web browser calls a global variable list for the web page, applies the call confirmation method to each of one or more global variables included in the global variable list, and determines whether the developer tool is to be driven depending on whether a global variable that called a time function exists; and and performing at least one of a third determination step of determining that the developer tool is in an unoperated state if the execution time is less than a preset reference time based on the execution time after measuring the execution time, and determining that the developer tool is in an operated state if the execution time is equal to or greater than the preset reference time, and a fourth determination step of checking a size of a window corresponding to the web page through the security script and determining whether the developer tool is operated depending on whether the size of the window is reduced to less than a preset size, and may further include a step of displaying the error page through the security script if the developer tool is in an operated state as a result of the execution.

[0014] As one example related to the present invention, the script providing step may further include a step of the web server generating a key encryption module and a key decryption module corresponding to the unique identifier and generating the decryption processing script corresponding to the unique identifier and transmitting it to the web browser if the time difference is less than a preset reference set time.

[0015] As one embodiment of the present invention, the key encryption module and the key decryption module may each be characterized as being a one-time module.

[0016] As one example related to the present invention, the script providing step may be characterized in that the web server randomly selects one of a plurality of different encryption algorithms and generates the key encryption module and the key decryption module corresponding to the unique identifier based on the selected encryption algorithm.

[0017] As an example according to the present invention, after the script providing step, the web browser transmits data request information for requesting encryption information to the web server through the decryption processing script, and the web server transmits encrypted information encrypted with a random key to the web browser when the web server receives the data request information. The web browser transmits key request information for requesting an encryption key to the web server through the decryption processing script when the web server receives the encryption information. The web server transmits the random key to the web server through the key encryption module when the web server receives the key request information. the web browser may further include a key transmitting step of transmitting a decrypted encryption key to the web browser, a module requesting step of transmitting module request information to the web server through the decryption processing script when the web browser receives the encryption key, for requesting the key decryption module, and a module transmitting step of transmitting a key decryption module corresponding to the module request information to the web browser when the web server receives the module request information, and a decrypting step of the web browser decrypting the encryption key through the key decryption module and decrypting the encrypted information with the decrypted random key.

[0018] As one example related to the present invention, the script providing step may further include a step of the web server setting a different start point for determining whether to operate the developer tool based on a transfer time of the decryption processing script, the data requesting step may further include a step of the web browser determining whether to operate the developer tool through the decryption processing script and transferring the data request information if the developer tool is not operated, and the module transferring step may further include a step of the web server setting a different end point based on a receiving time of the module request information, and transferring the key decryption module to the web browser if a time difference between the different start point and the different end point is less than the preset reference setting time.

[0019] As an example according to the present invention, the data request step includes a fifth determination step in which the web browser applies a call confirmation method for confirming a target that called a function or variable to a time function for measuring a time required for execution of the developer tool through the decryption processing script, calculates whether a hook occurs in the time function, and determines whether the developer tool is to be operated depending on whether the hook occurs; a sixth determination step in which the web browser calls a global variable list for the web page through the decryption processing script, applies the call confirmation method to each of one or more global variables included in the global variable list, and determines whether the developer tool is to be operated depending on whether a global variable that called a time function exists; and a seventh determination step of calculating a required time for executing a different program, determining that the developer tool is not in a running state if the required time for executing the different program is less than a predetermined reference required time, and determining that the developer tool is in a running state if the required time for executing the different program is equal to or more than the predetermined reference required time; and an eighth determination step of checking a size of a window corresponding to the web page through the decoding process script and determining whether the developer tool is in a running state depending on whether the size of the window is reduced to less than a predetermined size, and if the developer tool is in a running state as a result of the execution, displaying the error page through the decoding process script.

[0020] A system for providing a service for web browser-based data security according to an embodiment of the present invention includes a web server and a web browser configured in a user terminal communicating with the web server, the web browser executes a security script of a web page received from the web server, and transmits identifier registration request information including a unique identifier generated through the security script to the web server, the web server sets a time point at which the identifier registration request information is received as a start time point for determining whether to operate a developer tool provided by the web browser for debugging the web page, and the web browser The web server may determine whether the developer tool is to be operated through the security script, and if the developer tool is not to be operated, transmit script request information to the web server for requesting a decryption process script related to a data decryption process. When the web server receives the script request information, the web server sets a time point at which the script request information is received as an end time point for determining whether the developer tool is to be operated, determines whether a time difference between the start time point and the end time point is less than a preset reference time, and if the time difference is equal to or greater than the preset reference time point, transmits to the web browser a non-routine script for displaying an error page in the web browser. Effect of the Invention

[0021] In order to prevent unauthorized theft of data by hooking a script that operates for processing data requiring security on a web page using a developer tool provided in a web browser for debugging the web page, the present invention monitors whether the developer tool is operational through a script included in the web page, and the web server also measures the time required for execution of a program provided on the web page based on information transmitted from the web browser by executing the script, and separately verifies whether the developer tool is operational. Therefore, even when a function for checking whether the script is operational in the developer tool is hooked, it is possible to accurately grasp whether the developer tool is operational through the web server, and when the developer tool is operated, an error page is displayed to block the execution of the developer tool, thereby improving safe data transfer and data security.

[0022] In addition, the present invention generates a one-time encryption / decryption module in a web server every time a program provided through a web page is executed in a web browser to view data requiring security, and then based on the generated one-time encryption / decryption module, encrypts a key required for data encryption and provides it to the web browser, and provides a decryption module for decrypting a key for decrypting encrypted data only when a developer tool is not running. This prevents the encryption / decryption module from being exposed by changing the encryption / decryption module every time a program is executed using the one-time module, and even if it is exposed, security can be easily maintained by using a different encryption / decryption module the next time data is processed, thereby improving the security of data provided on a web basis. [Brief description of the drawings]

[0023] [Figure 1] 1 is a configuration diagram of a service providing system for web browser-based data security according to an embodiment of the present invention. [Diagram 2]4 is a flowchart of a service providing method for web browser-based data security in a service providing system according to an embodiment of the present invention. [Diagram 3] 4 is a flowchart of a service providing method for web browser-based data security in a service providing system according to an embodiment of the present invention. [Figure 4] 11 is an operational flowchart for determining whether or not a developer tool can be driven in the service providing system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0024] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, detailed embodiments of the present invention will be described with reference to the drawings. FIG. 1 is a configuration diagram of a service providing system for web browser-based data security (hereinafter, referred to as a service providing system) according to an embodiment of the present invention.

[0025] As shown in the figure, a service providing system according to an embodiment of the present invention can be configured to include a web browser (11) configured in a user terminal (10) and a web server (20) that communicates with the web browser (11) of the user terminal (10) via a communication network.

[0026] Here, the communication network described in the present invention may include wired / wireless communication networks. Examples of such wireless communication networks include Wireless LAN (WLAN), DLNA (Digital Living Network Alliance), Wibro (Wireless Broadband: Wibro), Wimax (World Interoperability for Microwave Access: Wimax), GSM (Global System for Mobile communication), CDMA (Code Division Multi Access), CDMA2000 (Code Division Multi Access 2000), EV-DO (Enhanced Voice-Data Optimized or Enhanced Voice-Data Only), WCDMA (Wideband CDMA), HSDPA (High Speed ​​Downlink Packet Access), HSUPA (High Speed ​​Uplink Packet Access), IEEE 802.16, Long Term Evolution (LTE), LTE-A (Long Term Evolution-Advanced), and Wireless Mobile Broadband (Wireless Mobile Broadband). These include Wireless Broadband Service (WMBS), 5G mobile communications services, Bluetooth (registered trademark), Long Range LoRa (registered trademark), Radio Frequency Identification (RFID), Infrared Data Association (IrDA), Ultra Wideband (UWB), ZigBee (registered trademark), Near Field Communication (NFC), Ultra Sound Communication (USC), Visible Light Communication (VLC), Wi-Fi, and Wi-Fi Direct (registered trademark).

[0027] Furthermore, examples of wired communication networks include wired LAN (Local Area Network), wired WAN (Wide Area Network), Power Line Communication (PLC), USB communication, Ethernet (registered trademark), serial communication, and optical / coaxial cables.

[0028] In addition, the user terminal (10) described in the present invention may include various terminals such as a smartphone equipped with a communication function, a portable terminal, a mobile terminal, a personal digital assistant (PDA), a personal computer, a notebook computer, a slate PC, a tablet PC, an ultrabook (registered trademark), and the like.

[0029] In addition, the user terminal (10) may include a terminal communication unit for communicating with the web server (20), a terminal storage unit for storing various information, a user input unit for receiving user input, a terminal display unit for displaying various information, and a terminal control unit for performing the overall control function of the user terminal (10).

[0030] Here, the terminal storage unit may include execution data related to the web browser (11), and the terminal control unit may execute the execution data to operate on the web browser (11).

[0031] In addition, the terminal control unit may include a RAM, a ROM, a CPU, a GPU, and a bus, and the RAM, ROM, CPU, GPU, etc. may be connected to each other via a bus, and the terminal communication unit and the terminal storage unit may be configured to be included in the terminal control unit.

[0032] In addition, the web browser (11) described in the present invention may also refer to a terminal control unit in a state in which the web browser (11) is executed, and in this case, the terminal control unit may also be configured as a web browser (11) unit.

[0033] In addition, the web browser (11) can connect to the web server (20) through the communication unit and communicate with the web server (20), and the description of the communication through the communication unit will be omitted below.

[0034] In addition, the web server (20) may be configured to include a communication unit that communicates with the user terminal (10) or the web browser (11) of the user terminal (10), a storage unit that stores various information, and a control unit that performs the overall control function of the web server (20).

[0035] Here, the storage unit can store data related to the service provided by the web server (20). For example, data such as one or more web pages constituting a website related to the service, various contents constituting the web pages, various algorithms, etc. can be stored in the storage unit.

[0036] In addition, the storage unit can store various modules and script-related data for safely transmitting data requiring security that constitutes the service to the user terminal (10).

[0037] Also, the storage unit may be configured as a DB or may include one or more DBs, and the storage unit may be configured as a separate database server.

[0038] In addition, the control unit performs the overall control function of the web server (20), and the control unit may include a RAM, a ROM, a CPU, a GPU, and a bus, and the RAM, ROM, CPU, GPU, etc. may be connected to each other via the bus.

[0039] The operational configuration of the web server (20) described below may be performed by the control unit configured in the web server (20), and the control unit can communicate with the user terminal (10) or the web browser (11) of the user terminal (10) through the communication unit.

[0040] Based on the above-mentioned configuration, the service providing system according to an embodiment of the present invention prevents a user who does not have the authority to use security data, such as content requiring usage rights provided through a script of a web page provided by the web server (20) in a web browser (11) of a user terminal (10) connected to the web server (20) to use the service of the web server (20), from hooking or hacking the script through a developer tool of the web browser (11) to view the security data. In this manner, the service providing system checks whether the developer tool is operating, and when the developer tool is operating, transmits non-routine data and blocks access to the security data, thereby supporting the secure transmission of security data, which will be described in detail below with reference to the drawings.

[0041] 2 and 3 are flowcharts illustrating a service providing method for data security based on a web browser 11 of a service providing system according to an embodiment of the present invention.

[0042] As shown, a web browser (11) of a user terminal (10) can connect to the web server (20) or a web page provided by the web server (20) and can receive a web page including a security script from the web server (20) in order to use a service provided by the web server (20).

[0043] Also, the web browser (11) can execute the security script included in the web page while loading the web page (S1).

[0044] In addition, the web browser (11) can generate a unique identifier corresponding to the user terminal (10) through the security script, and can generate identifier registration request information including the unique identifier for temporarily registering the unique identifier in the web server (20) through the security script and transmit the generated request information to the web server (20) (S2).

[0045] Here, the security script may be configured in the form of JavaScript, and the security script may generate a unique identifier based on a universally unique identifier (UUID).

[0046] The unique identifier can also be used as an identifier for identifying a session between the web server (20) and the web browser (11).

[0047] In addition, the identifier registration request information may include terminal identification information corresponding to the user terminal (10), and here the terminal identification information may be an IP (internet protocol) corresponding to the user terminal (10).

[0048] In addition, when the web server (20) receives the identifier registration request information, it may temporarily store and register the unique identifier included in the identifier registration request information in a storage unit included in the web server (20), or may temporarily store and register the unique identifier and the terminal identification information in a state of being mutually matched based on the identifier registration request information in the storage unit, and may set the time point at which the identifier registration request information is received as a start time point for determining whether or not to run a developer tool provided in the web browser (11) for editing or debugging the web page (S3).

[0049] Here, the web server (20) can identify the web browser (11) of the user terminal (10) based on the unique identifier or terminal identification information that matches the unique identifier.

[0050] In addition, the developer tool described in the present invention is a tool that is preset in the web browser (11) and is provided to analyze the structure, style, operation, etc. of a web page and to debug the web page, and is provided in various web browsers (11) such as Chrome (registered trademark), Firefox (registered trademark), Edge (registered trademark), etc.

[0051] Also, the web server 20 can match the start time with the unique identifier and temporarily store it in the storage unit.

[0052] In addition, the web browser (11) can determine whether the developer tool is enabled through the security script (S4).

[0053] Here, an embodiment of the web browser 11 for determining whether the developer tool is enabled will be described with reference to FIG.

[0054] Generally, the time required to run a specific program is measured using a time function (or a time-related system function) for measuring the time required to run a developer tool, such as Date.now() or performance.now(), to determine whether or not a developer tool is running. However, if a hacker runs a developer tool and calls a time function, and then redefines the time function by using the developer tool to change the way the time function measures time, the developer tool can be disabled so that it is determined that the developer tool is not running even though it is running. Here, the time function can be included in the security script.

[0055] Therefore, in order to determine whether the developer tool can be operated, the web browser (11) can apply a call confirmation method to the time function through the security script to confirm the object (for example, a variable or a function) that called the time function, and can determine whether the time function can be hooked.

[0056] Here, the toString() method can be used as the call confirmation method, and the web browser (11) applies the call confirmation method to the time function as 'time function name.toString()', such as 'performance.now.toString()' through a security script, and if the execution result of applying the call confirmation method to the time function is not output as a preset constant value such as 'function now(){[native code]}' and the content of the call including the variable that called the time function is output, it can be determined that the time function has been hooked.

[0057] Here, the web browser (11) may apply a call confirmation method to the time function through the security script, and if the variable or function that called the time function as a result of the execution is not a pre-registered variable or function, it may determine that the time function has been hooked.

[0058] As a result, the web browser (11) determines whether a hook has occurred in the time function based on the result of applying the call confirmation method in the time function through the security script, and if a hook has occurred in the time function as a result of the determination, it can determine that the developer tool is running (S41, S42).

[0059] However, other than redefining the time function as mentioned above, there are various ways to hook the time function, and it is difficult to prevent all hooking methods. However, if the time function is not hooked, even if it is operated, the time function must be called once after all. Therefore, it is possible to determine whether the developer tool is running by checking whether a hacker has set the time function of the security script as a global variable using the developer tool.

[0060] Therefore, the web browser (11) may call (create) a global variable list for the web page or security script before starting a specific program included in the web page through the security script, and may apply the call confirmation method to each of one or more global variables included in the global variable list to determine whether or not to operate the developer tool depending on whether or not there is a global variable that has called a time function.

[0061] As an example, when the web browser (11) confirms a call of a time function, such as 'var hackedData=Data.now()', as a result of applying the call confirmation method to any one of the one or more global variables, it can determine that there is an attempt to hook the time function through setting the global variable of the time function, and determine that the developer tool is in an operational state.

[0062] Thus, the web browser (11) can determine that the developer tool is in an operating state if there is a global variable that has called a time function as a result of applying the call confirmation method to one or more global variables included in the global variable list (S43, S44).

[0063] Here, the web browser (11) applies a call confirmation method to the global variable through the security script, and if the global variable that called the time function as a result of the execution is not a pre-registered variable, it can determine that the time function has been hooked and that the developer tool is in an operating state.

[0064] In addition to the above-mentioned methods, the web browser (11) can measure the time required to execute a program included in the web page through the security script, and determine whether or not to run the developer tool based on the measured execution time (S45, S46).

[0065] Here, the web browser (11) can check the execution time required through a time function included in the security script.

[0066] As an example, the web browser (11) may calculate the time required to execute a specific program from code area A to code area B included in the web page through the security script, and if the time required to execute the program is less than a reference time preset in the security script, the web browser (11) may determine that the developer tool is not running.

[0067] Here, the web browser (11) checks the size of the window corresponding to the web page through the security script, and if the size of the window decreases below a preset size, it can determine that the developer tool is in an operating state (S47, S48).

[0068] That is, the web browser (11) can make the above-mentioned determination by utilizing the fact that the window size becomes smaller when the developer tool is running.

[0069] As described above, when the web browser (11) determines through the security script that the developer tool is not running on the user terminal (10), it can generate and transmit script request information to request a decryption processing script related to the data decryption processing to the web server (20) (S6).

[0070] Alternatively, the web browser (11) may determine that the developer tool is in an operating state if the time required for execution of the program through the security script is equal to or greater than a preset reference time.

[0071] Thus, when the web browser (11) determines that the developer tool is in operation, it can display an error page preset through the security script via the user terminal (10) (S5).

[0072] Here, when the web browser (11) determines that the developer tool is in an operational state, it can connect to an error page, which is a web page preset through the security script, and receive and display the error page from the web server (20).

[0073] In addition, when the web server (20) receives the script request information from the web browser (11), the web server (20) can set the time point at which the script request information is received as an end time point for determining whether or not to operate the developer tool.

[0074] Also, the web server 20 can store the end time in the storage unit by matching the unique identifier according to the script request information.

[0075] Here, the web server (20) may determine the start time as the start time of execution of the specific program for determining whether the developer tool is to be driven, and may determine the end time as the completion time of execution of the specific program.

[0076] In addition, the web server (20) can calculate the time difference between the start time and the end time matched with the unique identifier and determine whether the time difference is less than a preset reference time (or a reference setting time) (S7).

[0077] In addition, if the time difference is equal to or greater than a preset reference time (reference setting time), the web server (20) determines that the developer tool is running in the web browser (11) and can transfer a non-stationary script to the web browser (11) to cause an error page to be displayed in the web browser (11) (S10).

[0078] Thus, when the web browser (11) receives the non-stationary script from the web server (20), the web browser (11) can execute the non-stationary script to display an error page on the display unit of the user terminal (10) (S11).

[0079] Here, the web browser (11) can also connect to the error page by executing the non-stationary script and display the error page.

[0080] In addition, if the time difference is less than a preset reference time (reference setting time), the web server (20) determines that the developer tool is not running in the web browser (11) and can generate a key encryption module and a key decryption module corresponding to the unique identifier according to the script request information (S8).

[0081] Here, the web server (20) can randomly select one of a plurality of different encryption algorithms (or encryption / decryption algorithms) that are preset, and generate the key encryption module and key decryption module corresponding to the unique identifier based on the selected encryption algorithm.

[0082] Also, the web server (20) can transmit the decryption processing script corresponding to the unique identifier to the web browser (11) corresponding to the unique identifier according to the script request information (S9).

[0083] Here, the web server (20) can generate the decryption processing script based on at least one of the key encryption module and the key decryption module, or can extract a decryption processing script pre-stored in the storage unit and provide it to the web browser (11).

[0084] Also, the web server 20 can match the decryption script with the unique identifier and store it in the storage unit.

[0085] In addition, the web server (20) can set a different start point for determining whether or not to operate the developer tool based on the transfer time of the decryption processing script in the web browser (11) by matching it with the unique identifier, and can store the different start point in the storage unit by matching it with the unique identifier (S9).

[0086] In addition, the web server (20) can generate the key encryption module and the key decryption module as a one-time module and store the key encryption module and the key decryption module in the storage unit by matching them with the unique identifier.

[0087] Meanwhile, when the web browser (11) receives the decryption processing script from the web server (20), the web browser (11) can execute the decryption processing script.

[0088] Also, the web browser (11) can transmit data request information for requesting encrypted information to the web server (20) through the decryption processing script.

[0089] In addition, before transmitting the data request information, the web browser (11) determines whether the developer tool is operational through the decoding processing script (S12), and if the developer tool is not operational, the web browser (11) transmits the data request information (S14).

[0090] Here, the method by which the web browser (11) determines whether or not to operate the developer tool through the decryption processing script may be the same as the method by which the web browser (11) determines whether or not to operate the developer tool through the security script shown in FIG. 4 (S41 to S48).

[0091] As an example, the web browser (11) may apply a call confirmation method to the time function through the decryption processing script to determine whether the time function is hooked, and if the time function is hooked, it may determine that the developer tool is running.

[0092] In addition, the web browser (11) calls (generates) a global variable list for the web page or the decryption processing script through the decryption processing script before executing a different program described below by the decryption processing script, and if there is a global variable that has called a time function as a result of applying the call confirmation method to each of one or more global variables included in the global variable list, it can determine that the developer tool is in an operating state.

[0093] In addition, the web browser (11) can execute different programs included in the web page according to the decryption processing script and check the time required for executing the different programs.

[0094] Here, the web browser (11) can check the execution time required through a time function included in the decryption processing script.

[0095] In addition, the web browser (11) can determine that the developer tool is running (in a running state) if the execution time corresponding to the different program is equal to or longer than a preset reference required time, and can determine that the developer tool is in a non-running state if the execution time corresponding to the different program is shorter than the preset reference required time.

[0096] Here, the web browser (11) checks the size of the window corresponding to the web page through the decoding process script, and if the size of the window is reduced to less than a preset size, it can determine that the developer tool is in an operating state.

[0097] In addition, the web browser (11) may, as a result of determining whether the developer tool is operational through the decoding processing script, connect to a preset error page according to the decoding processing script and display the corresponding error page if the developer tool is operational (S13).

[0098] Meanwhile, when the web server 20 receives the data request information from the web browser 11, it can transmit encrypted information encrypted with a random key to the web browser 11 (S15).

[0099] Here, the encrypted information may be information obtained by encrypting the contents provided by the web server 20 using the random key.

[0100] Also, the web server 20 can match the random key with the unique identifier and temporarily store it in the storage unit.

[0101] In addition, when the web browser (11) receives encrypted information from the web server (20), it can transmit key request information to request an encryption key from the web server (20) through the decryption processing script (S16).

[0102] Here, the key request information may include the unique identifier or a script ID set in the decryption processing script.

[0103] Accordingly, when the web server (20) receives the key request information, it extracts a key encryption module corresponding to the key request information from the storage unit, extracts a random key corresponding to the key request information from the storage unit, and then encrypts the random key through the extracted key encryption module to generate an encryption key and transmits it to the web browser (11) (S17).

[0104] As an example, the web server (20) may extract from the storage unit a key encryption module that matches a unique identifier according to the key request information, extract from the storage unit a random key that matches a unique identifier according to the key request information, and then encrypt the extracted random key with the extracted key encryption module to generate an encryption key.

[0105] In addition, when the web browser (11) receives the encryption key, it can generate module request information for requesting the key decryption module through the decryption processing script and transmit the module request information to the web server (20) (S18).

[0106] Thus, when the web server (20) receives the module request information from the web browser (11) of the user terminal (10), it can match and set a different end time based on the time of receiving the module request information with the unique identifier.

[0107] Here, the module request information may include a unique identifier, and the web server (20) may set the time of receiving the module request information as the different end time, match the unique identifier according to the module request information, and store the different end time in the storage unit.

[0108] In addition, the web server (20) may determine whether to run a developer tool in the web browser depending on whether the time difference between the different start points and the different end points is less than the preset reference time (reference setting time) (S19).

[0109] Accordingly, if the time difference between the different start points and the different end points is less than the preset reference time (reference set time), the web server (20) determines that the developer tool is not running in the user terminal (10) and can transfer the key decryption module matching the unique identifier to the web browser (11) (S20).

[0110] Here, the web server (20) can extract a key decryption module matching a unique identifier according to the module request information from the storage unit and transmit the key decryption module to the web browser (11).

[0111] Alternatively, the web server (20) may determine that the developer tool is in an operational state on the user terminal (10) if the time difference between the different start points and the different end points is equal to or greater than the preset reference time (reference setting time).

[0112] Accordingly, when the developer tool is running in the web browser (11) of the user terminal (10), the web server (20) can transfer an error page pre-stored in the storage unit to the web browser (11) or transfer a non-stationary decoding module to the web browser (11) (S22).

[0113] Here, the web browser (11) that receives the error page or the non-stationary decryption module can either display the error page or operate in such a way that the encryption key cannot be decrypted by the non-stationary decryption module (S23).

[0114] Meanwhile, when the web browser (11) receives the key decryption module from the web server (20), it can obtain the random key by decrypting the encryption key based on the key decryption module.

[0115] In addition, the web browser (11) can decrypt the encrypted information using the acquired random key and provide (display) it (S21).

[0116] In addition, when the session connection between the web server (20) and the web browser (11) is terminated, the web server (20) can delete the unique identifier and all information stored by matching with the unique identifier in the storage unit.

[0117] As described above, in order to prevent unauthorized theft of data by hooking a script that operates to process data requiring security on a web page using a developer tool provided in the web browser (11) for debugging the web page, the present invention monitors whether the developer tool is operational through a script included in the web page, and the web server (20) also measures the time required to execute a program provided on the web page based on information transmitted from the web browser (11) by executing the script, and separately verifies whether the developer tool is operational. Even when a function for checking whether the script is operational in the developer tool is hooked, the present invention supports accurate determination of whether the developer tool is operational through the web server (20). When the developer tool is operated, an error page is displayed and the execution of the developer tool is blocked, thereby improving safe data transfer and data security.

[0118] In addition, the present invention generates a one-time encryption / decryption module in the web server (20) every time a program provided through a web page for viewing data requiring security is executed in the web browser (11), and based on the generated one-time encryption / decryption module, encrypts a key required for data encryption and provides it to the web browser (11). Also, a decryption module is provided for decrypting the key for decrypting the encrypted data only when the developer tool is not running, and the encryption / decryption module is changed every time a program is executed using the one-time module, preventing the encryption / decryption module from being exposed. Even if the encryption / decryption module is exposed, a different encryption / decryption module can be used the next time data is processed to easily maintain security, thereby improving the security of data provided on the web.

[0119] The components described in the embodiments of the present invention may be implemented using one or more general-purpose or special-purpose computers, such as hardware, such as a memory, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a Field Programmable Gate Array (FPGA), a programmable logic unit (PLU), a microprocessor, software including a command set, or a combination thereof, or any other device capable of executing and responding to instructions.

[0120] The various devices and components described herein may be implemented using hardware circuits (e.g., CMOS-based logic circuits), firmware, software, or a combination thereof, including, for example, using transistors, logic gates, and electronic circuits in various electrical configurations.

[0121] The above contents should be modifiable and changed by a person having ordinary skill in the art to which the present invention belongs, without departing from the essential characteristics of the present invention. Therefore, the embodiments disclosed in the present invention are for illustration purposes, not for limiting the technical phenomena of the present invention, and the scope of the technical phenomena of the present invention is not limited by such embodiments. The scope of protection of the present invention should be interpreted according to the following claims, and all technical phenomena within the scope equivalent thereto should be interpreted as being included in the scope of the present invention. [Explanation of symbols]

[0122] 10: User terminal 11: Web browser 20: Web server

Claims

1. a registration step in which a web browser of the user terminal executes a security script of the web page received from the web server and transmits, to the web server, identifier registration request information including the unique identifier generated through the security script; an initiation setting step of setting a time point when the web server receives the identifier registration request information as a start time point for determining whether to operate a developer tool provided by the web browser for debugging the web page, when the web server receives the identifier registration request information; a drive determining step of determining whether the developer tool is driven through the security script by the web browser, and if the developer tool is not driven, transmitting script request information for requesting a decryption script related to a data decryption process to the web server; a verification step of setting a time point when the web server receives the script request information as an end time point for determining whether the developer tool is to be driven, and determining whether a time difference between the start time point and the end time point is less than a preset reference time; and and transmitting, to the web browser, a non-stationary script for displaying an error page on the web browser when the time difference is equal to or greater than a preset reference time, the web server. A method for providing a service for web browser-based data security.

2. After providing the script, The method further includes the step of displaying an error page through the non-routine script when the web browser receives the non-routine script. The method for providing a service for web browser-based data security according to claim 1.

3. The drive determination step includes: The web browser, a first determination step of applying a call confirmation method for confirming a target that called a function or variable to a time function for measuring a time required for execution of the developer tool through the security script, calculating whether a hook occurs in the time function, and determining whether the developer tool is to be operated based on whether the hook occurs; a second determination step of calling a global variable list for the web page, applying the call confirmation method to each of one or more global variables included in the global variable list, and determining whether or not to operate the developer tool depending on whether or not there is a global variable that has called a time function; a third determination step of determining, based on the execution time required for measuring the execution time required for a specific program included in the web page through the security script, that the developer tool is in an inactive state if the execution time required for the specific program is less than a preset reference time required for the specific program, and determining, based on the execution time required for the specific program, that the developer tool is in an active state if the execution time required for the specific program is equal to or greater than the preset reference time required for the specific program; and and a fourth determination step of determining whether the developer tool is to be operated based on whether the size of the window corresponding to the web page is reduced to a size less than a preset size through the security script, and performing at least one determination step, and if the developer tool is in an operating state as a result of the determination step, displaying the error page through the security script. The method for providing a service for web browser-based data security according to claim 1.

4. The script providing step includes: The method further includes the step of: when the time difference is less than a preset reference time, the web server generates a key encryption module and a key decryption module corresponding to the unique identifier, and generates the decryption processing script corresponding to the unique identifier and transmits the decryption processing script to the web browser. The method for providing a service for web browser-based data security according to claim 1.

5. The key encryption module and the key decryption module are each a one-time module. The method for providing a service for web browser-based data security according to claim 4.

6. The script providing step includes: The web server randomly selects one of a plurality of different encryption algorithms, and generates the key encryption module and the key decryption module corresponding to the unique identifier based on the selected encryption algorithm. The method for providing a service for web browser-based data security according to claim 4.

7. After providing the script, a data request step of the web browser transmitting data request information for requesting encrypted information to the web server through the decryption processing script; an encrypted information transmitting step of transmitting encrypted information encrypted by a random key to the web browser when the web server receives the data request information; a key request step of transmitting key request information for requesting an encryption key to the web server via the decryption processing script when the web browser receives the encryption information; a key transmitting step of transmitting an encryption key obtained by encrypting the random key through the key encryption module to the web browser when the web server receives the key request information; a module request step of transmitting module request information for requesting the key decryption module through the decryption processing script to the web server when the web browser receives the encryption key; a module transmission step of transmitting a key decryption module corresponding to the module request information to the web browser when the web server receives the module request information; and and a decryption step of the web browser decrypting the encryption key through the key decryption module and decrypting the encrypted information with the decrypted random key. The method for providing a service for web browser-based data security according to claim 4.

8. The script providing step includes: The method further includes setting a different start point for determining whether to run the developer tool based on a transfer point of the decryption processing script, the web server; The data request step includes: The web browser may further include determining whether the developer tool is running through the decoding process script, and transmitting the data request information if the developer tool is not running, The module transfer step includes: The method further includes a step of: the web server sets a different end time based on a time point at which the module request information is received, and transmits the key decryption module to the web browser if a time difference between the different start time and the different end time is less than the preset reference set time. The method for providing a service for web browser-based data security according to claim 7.

9. The data request step includes: The web browser, a fifth determination step of applying a call confirmation method for confirming a target that called a function or variable to a time function for measuring a time required for executing the developer tool through the decryption processing script, calculating whether a hook occurs in the time function, and determining whether the developer tool is to be operated based on whether the hook occurs; a sixth determination step of calling a global variable list for the web page through the decoding process script, applying the call confirmation method to each of one or more global variables included in the global variable list, and determining whether or not to operate the developer tool depending on whether or not there is a global variable that has called a time function; a seventh determination step of calculating a time required for executing a different program included in the web page through the decoding process script, determining that the developer tool is in an inactive state if the time required for executing the different program is less than a preset reference time, and determining that the developer tool is in an active state if the time required for executing the different program is equal to or greater than the preset reference time; and and an eighth determination step of checking a size of a window corresponding to the web page through the decoding process script and determining whether the developer tool is to be operated depending on whether the size of the window is reduced to less than a preset size. If the developer tool is in an operating state as a result of the determination step, the method further includes a step of displaying the error page through the decoding process script. The method for providing a service for web browser-based data security according to claim 8.

10. A web server; and a web browser configured on a user terminal that communicates with the web server, the web browser executes a security script of the web page received from the web server, and transmits identifier registration request information including the unique identifier generated through the security script to the web server; When the web server receives the identifier registration request information, the web server sets a time point when the identifier registration request information is received as a start time point for determining whether to operate a developer tool provided by the web browser for debugging the web page, The web browser determines whether the developer tool is operated through the security script, and if the developer tool is not operated, transmits script request information for requesting a decryption processing script related to a data decryption processing to the web server; When the web server receives the script request information, the web server sets a time point when the script request information is received as an end time point for determining whether the developer tool is to be operated, determines whether a time difference between the start time point and the end time point is less than a preset reference time, and transmits a non-routine script to the web browser to display an error page on the web browser if the time difference is equal to or greater than the preset reference time. A service provision system for web browser-based data security.

Citation Information

Patent Citations

  • Method for Selectively Encrypting Web Contents and Computer-Readable Recording Medium Where Program Executing the Same Method

    KR100890720B1