This technology allows encrypted electronic documents and files sent and received via the cloud to be displayed in a browser without requiring the user to manage (enter) encryption and decryption passwords.

A cloud-based encryption key management system automates encryption and decryption of electronic documents, addressing accidental transmission and malware risks, enhancing security and efficiency in information exchange.

JP2026057765APending Publication Date: 2026-04-03中本 浩
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-24
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

The accidental transmission of encrypted electronic documents and files along with their encryption keys, and the risk of recipients downloading and decrypting them, leading to malware infection.

Method used

A cloud-based encryption key management system that automates encryption on the sender's side and decryption on the recipient's side, using a cryptographic key management function to encrypt documents on the cloud, send them via email or link, and decrypt them using multiple unique keys stored on the cloud, converting them into a browser-viewable format without download.

Benefits of technology

This system enhances security by eliminating the need for key exchange and preventing malware infection, ensuring safer and more efficient information exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026057765000001_ABST
    Figure 2026057765000001_ABST
Patent Text Reader

Abstract

This invention provides a system and method for encrypting and decrypting electronic documents and files on the cloud without sending or receiving encryption keys, and for displaying electronic documents in a browser without downloading them to the user's computer. [Solution] In processing electronic documents, the sending file management function encrypts the electronic documents and files using the encryption key issued by the encryption key management function and multiple unique keys for each receiving side, and transfers the electronic documents and files to the receiving file management function using the link address and session of the encrypted electronic documents and files. If the transferred electronic documents and files are encrypted, the receiving file management function decrypts the encrypted electronic documents and files by referring to the encryption key of the encryption key management function and multiple unique keys for each receiving side, converts the decrypted electronic documents and files into a data format that can be displayed in a browser, and displays them in the browser.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to "encrypted (electronic documents and files)" transmitted and received by e-mail, etc., which encrypts "electronic documents and files" with the "transmission file management function" on the cloud without entering the encryption password (hereinafter referred to as the encryption key), and the receiving side also decrypts "encrypted (electronic documents and files)" with the "received file management function" on the cloud, and converts the combined "electronic documents and files" into a "data format that can be displayed on the browser" with the "received file management function" and displays it on the browser, thereby eliminating the need for sending and receiving the "encryption key" by e-mail and downloading "encrypted (electronic documents and files)".

Background Art

[0002] Conventionally, when sending "electronic documents and files" with high security, it has been common to transmit them as "encrypted (electronic documents and files)" and send the "encryption key" for decrypting the transmitted "encrypted (electronic documents and files)" by e-mail or the like.

[0003] However, there are many troubles in the delivery of (electronic documents and files), such as accidents of mis-sending e-mail or the like, or damage caused by downloading (electronic documents and files) infected with malware or the like to a personal computer and being infected with malware or the like.

[0004] As a measure to prevent mis-sending of e-mail, it seems that a method of sharing cloud storage between the sender and receiver of e-mail and safely delivering "encrypted (electronic documents and files)" is also used, but there is no guarantee that the data and documents in the cloud storage are safe. In addition, when a file is sent from a person who does not share cloud storage, there is also a problem of a failure of infecting the receiver's personal computer with malware or the like by downloading. "Encrypted (electronic documents and files)" is generally downloaded to a personal computer and decrypted, and is vulnerable to countermeasures against malware or the like.

[0005] In this invention, a "cryptographic key management function" is developed as shown in Figure 1. The "cryptographic key management function" stores "cryptographic keys" that are generated from random numbers at regular intervals. Multiple types of "cryptographic keys" are stored, including past ones. The sender of an email uses a "hash (irreversible encryption)" key, which is a combination of the latest key from the "cryptographic key management function" and "multiple unique keys for each recipient," to encrypt electronic documents and files on the cloud. The "encrypted (electronic documents and files)" are sent either as an "attachment to an email" or by sending an email containing a "link address to the file." The recipient of the "encrypted (electronic documents and files)" sends the "email attachment" or "link address to the file" to the "receiving file management function" using a "browser extension" to send the "link address and session." The "receiving file management function" uses the "link address and session" received from the "browser extension" to transfer the "encrypted (electronic documents and files)" to the "receiving file management function." The transmitted encrypted electronic documents and files are matched against a hash key, which is a combination of multiple encryption keys and multiple unique keys for each recipient, stored by the encryption key management function. The encrypted electronic documents and files are then decrypted using the hash key. The decrypted electronic documents and files are then converted into a data format viewable in a browser by the received file management function. The electronic documents and files are displayed in the browser without being downloaded to the recipient's computer.

[0006] [Patent Document 1] Patent No. 2017-5996154 [Patent Document 2] Patent No. 2017-6219950 [Patent Document 2] Patent No. 2018-073423 [Overview of the Initiative] [Problems that the invention aims to solve]

[0007] The problems we aim to solve are: the accidental transmission of encrypted electronic documents and files along with their encryption keys; and the problem of recipients downloading and decrypting encrypted electronic documents and files to their computers, leading to infection by malicious malware. [Means for solving the problem]

[0008] In this invention, the encryption key for "encryption (electronic documents and files)" is managed by the "encryption key management function," and encryption is performed by the cloud's "transmitted file management function." The receiving side decrypts the "encryption (electronic documents and files)" by using the cloud's "received file management function," which is linked to the "encryption key management function" and "multiple unique keys for each receiving side," converts it into a "data format that can be displayed in a browser," and allows it to be viewed in a browser. There is no need to download the "encryption (electronic documents and files)" to the receiving computer, thus resolving issues such as malware. [Effects of the Invention]

[0009] The electronic document processing technology according to the present invention automates the encryption of "electronic documents and files" on the email sender's side and the decryption of "encrypted electronic documents and files" on the email recipient's side via a cloud-based "sending file management function" and "receiving file management function," which utilize "encryption keys" issued by an "encryption key management function" and "multiple unique keys for each recipient." This eliminates the need for the sender and receiver of "encrypted electronic documents and files" to send, receive, or input "encryption keys." This simultaneously solves the problems of email misdelivery and the recipient's computer being infected with malware sent using "encrypted electronic documents and files." As a result, the exchange of information using "encrypted electronic documents and files" becomes safer and smoother, leading to increased business efficiency. It also offers the advantage of eliminating the need for viewing software on the user's computer. [Brief explanation of the drawing]

[0010] [Figure 1]This flowchart shows how the "Transmit File Management Function" encrypts "electronic documents and files" using the "encryption key" generated by the "encryption key management function" and "multiple unique keys for each recipient," and then transmits the "encrypted (electronic documents and files)." The "Received File Management Function" decrypts the received "encrypted (electronic documents and files)" using the "encryption key" managed by the "encryption key management function" and "multiple unique keys for each recipient," converts it into a "data format that can be displayed in a browser," and allows viewing. [Figure 2] This diagram illustrates the relationship between the "encryption key" generated by the "encryption key management function" and "multiple unique keys for each recipient" (keys specific to each recipient), showing how hashed keys used for encryption are generated separately for each recipient. [Modes for carrying out the invention]

[0011] Figure 1 is an operation flowchart of the software of the present invention, showing that 1001 prepares and starts sending (electronic documents and files), and 1002 encrypts (electronic documents and files).

[0012] 1002 (electronic documents and files) are encrypted 1006 using 1005 ("encryption key" and "multiple unique keys for each recipient"), which are managed by 1004 "encryption key management function" 1003 "transmitted file management function".

[0013] 1007 Encrypt (electronic documents and files) and send 1008 to the cloud.

[0014] 1009 Receiving, decrypting, and displaying encrypted (electronic documents and files). 1010 Obtaining the 1011 "link address and session" of the 1008 encrypted (electronic documents and files) in the cloud via the "browser extension".

[0015] 1013 Sends the 1011 "Link Address and Session" of the 1008 Cloud encryption (electronic documents and files) obtained to the "Received File Management Function".

[0016] The "Received File Management Function" receives the 1007 encryption (electronic documents and files) of the cloud using the 1011 "Link Address and Session" of the 1007 encryption (electronic documents and files).

[0017] The 1013 "Received File Management Function" decrypts the 1007 encryption (electronic documents and files) using the "Hash" key generated by 1005 ("Encryption Key" and "Multiple Unique Keys for Each Receiver Side") obtained from the 1004 "Encryption Key Management Function" to obtain the 1002 (electronic documents and files).

[0018] The 1004 (electronic documents and files) are converted into the 1014 "Data Format Displayable on Browser" by the 1013 "Received File Management Function" and viewed.

[0019] The 1015 "Data Format Displayable on Browser" is displayed on the Internet browser.

Industrial Applicability

[0020] The present invention ensures security, improves profits and productivity by preventing information leakage and protecting the personal computer from malware, etc., for organizations and individuals that perform reliable exchange and collection of (electronic documents and files) using the Internet.

Explanation of Signs

[0021] 1001 Preparation for encryption (electronic documents and files) and start of transmission. 1002 (Electronic documents and files). 1003 "Transmission File Management Function" that encrypts and transfers (electronic documents and files) in the cloud.<s 1004 "Encryption Key Management Function" that generates the "Encryption Key". 1005 ("Encryption Key" and "Multiple Unique Keys for Each Receiver Side"). 1006 Encryption process performed by the "Transmission File Management Function" in the cloud. 1007 Encrypted (electronic documents and files). 1008 Encrypted data (electronic documents and files) that were transferred. 1009 Start of receiving encrypted (electronic documents and files). 1010 A browser extension that retrieves and manipulates information from encrypted (electronic documents and files) that have been transferred. 1011 Link address and session of the transferred encrypted (electronic documents and files). 1012 Decryption process using the "Received File Management Function". 1013 A function that decrypts encrypted electronic documents and files in the cloud and converts them into a data format that can be displayed in a browser. 1014 The "Received File Management Function" converts (electronic documents and files) into a "data format that can be displayed in a browser". 1015. Display electronic documents and files in the browser.

Claims

1. A "cryptography key management function" is installed in the cloud, and the "cryptography keys" that are generated and stored at arbitrary intervals are shared between the "sending file management function" and the "receiving file management function".

2. The cloud's "Sending File Management Function" receives the "encryption key" from the "encryption key management function," combines it with "multiple unique keys for each recipient," and encrypts the data using the "hashed" key. This process encrypts (electronic documents and files) without requiring the user to input the "encryption key," and a hashed key is generated for each recipient using "multiple unique keys for each recipient."

3. The cloud's "received file management function" receives the "encryption key" from the "encryption key management function," combines it with "multiple unique keys for each recipient," and decrypts the encrypted data using the resulting hashed key. This mechanism allows for the decryption of encrypted data (electronic documents and files) without requiring the user to input the "encryption key."

4. This system works by obtaining the "link address and session" of the transferred (electronic documents and files) via an add-on function installed in the computer's browser, and then using that information to retrieve the transferred (electronic documents and files) using the cloud's "received file management function."

5. The "Received File Management Function" converts acquired electronic documents and files into a format viewable in a browser, allowing them to be displayed in the browser. This eliminates the need to download electronic documents and files to the computer, thus preventing malware and other problems.

6. Even if cloud-based electronic documents and files contain malware, the majority are in formats that run on Windows or macOS, making it highly unlikely they would execute on the cloud's operating system, thus preventing any impact on the system.

7. Even if encrypted electronic documents and files are leaked, they can be decrypted using a hash key that combines the encryption key and multiple unique keys specific to the recipient. Therefore, unless the receiving file management function is analyzed and the encryption key and multiple unique keys specific to the recipient are obtained, it will not be possible to view the electronic documents and files.

8. The functions for encrypting and decrypting (electronic documents and files) are located in a separate area, and the storage areas for "encryption keys" and "multiple unique keys for each recipient" are also separate. This makes it difficult to analyze the system as a target for cyberattacks, thus achieving robust security.