File control method and device based on IPFS, equipment and medium

By performing file format checksum security verification in IPFS network, and using hash value calculation and encryption access URLs, single point of failure and security problems of traditional centralized storage systems are solved, efficient file management and access control are achieved, and user experience and system stability are improved.

CN120492413APending Publication Date: 2025-08-15INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Patent Information

Application Number
CN202510530800.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Traditional centralized file storage systems have problems such as risk of single point failure, poor scalability, low data sharing efficiency, weak user control and difficulty in ensuring security and privacy. How to integrate IPFS to achieve efficient file management and access control while ensuring the security and user experience of the system.

Method used

By receiving file upload requests, performing format checksum security verification, uploading the file to the IPFS network, obtaining a hash string as an identifier, building an encrypted access URL and storing metadata, providing preview or download services based on file type, combining hash value calculation and distributed storage technology to ensure file integrity and security.

Benefits of technology

Improves the efficiency and reliability of file storage, reduces the risk of system attacks or data corruption, ensures file integrity and security, and enhances user experience and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120492413A_ABST
    Figure CN120492413A_ABST
Patent Text Reader

Abstract

The invention relates to the field of computer software, in particular to an IPFS-based file control method and device, equipment and a medium, and the method comprises the steps: receiving a file uploading request initiated by a user through a front-end interface; basic information of the file is read, a file format is confirmed, and the file format and a preset type list are verified; performing security and integrity verification on the files passing the verification; if the verification is passed, uploading the file to an IPFS network, and obtaining a hash string returned by the IPFS as a file identifier; constructing an encrypted access URL of the file based on the server address and the hash string, and storing file metadata to a database; and receiving a file access request initiated by a user through the URL, decrypting the URL and verifying the user permission, retrieving the file from the IPFS network according to the hash string, and providing a preview or download service according to the file type. And uploading of file types which do not meet requirements is effectively avoided, and potential safety risks are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer software technology, and in particular to an IPFS-based file control method, apparatus, device, and medium. Background Art

[0002] In today's digital age, data storage and management have become crucial. With the rapid development of the internet, a vast number of files need to be stored and shared, posing numerous challenges to traditional centralized file storage. Traditional centralized file storage systems rely on a single server or data center, creating a single point of failure. If a server fails or is attacked, all files stored on that server may become inaccessible or lost, resulting in significant losses for users.

[0003] Furthermore, centralized storage systems have poor scalability. As data volumes continue to grow, significant hardware resources are required to expand storage capacity, which not only increases costs but also introduces management complexity. Traditional storage methods also have limitations when it comes to data sharing. File sharing typically requires transfer via servers, which results in inefficient transmission. Especially in large-scale data sharing scenarios, users may have to wait a long time to retrieve the files they need. Furthermore, because data is centrally stored on servers, users have limited control over their files, making data security and privacy difficult to guarantee.

[0004] To address these issues, distributed storage technologies have emerged. IPFS (Inter Planetary File System), an emerging distributed file system, offers a new solution for file storage and sharing. As a decentralized storage solution, IPFS provides a more efficient and secure data storage method. By storing files in shards across various nodes in the network, IPFS not only improves data security and reliability but also reduces storage costs. However, how to integrate IPFS to achieve efficient file management and access control while ensuring system security and user experience remains a pressing challenge. Summary of the Invention

[0005] In response to the problem of how to integrate IPFS to achieve efficient file management and access control while ensuring system security and user experience, the present invention provides an IPFS-based file control method, device, equipment and medium.

[0006] In a first aspect, the technical solution of the present invention provides a file control method based on IPFS, comprising the following steps: Receive file upload requests initiated by users through the front-end interface; Read the basic information of the file and confirm the file format, and verify the file format with the preset type list; Verify the security and integrity of files that have passed verification; If the verification is successful, upload the file to the IPFS network and obtain the hash string returned by IPFS as the file identifier; Construct an encrypted access URL for the file based on the server address and hash string, and store the file metadata in the database; Receive file access requests initiated by users through URLs, decrypt the URLs and verify user permissions, retrieve files from the IPFS network based on the hash string, and provide preview or download services based on the file type.

[0007] After a user initiates an upload request, the file is uploaded through format verification and security verification, and can finally be accessed through an encrypted URL, providing an orderly operational framework for file storage and use. The addition of format verification and security and integrity verification steps during the file upload process can effectively prevent files that do not meet requirements or pose security risks from entering the system, reducing the risk of system attacks or data corruption. Storing file metadata in a database facilitates subsequent querying, auditing, and management of file-related information, helping to ensure data compliance and traceability. Based on user access requests, preview or download services are provided based on file type, meeting the diverse needs of users and improving user convenience and satisfaction with the system.

[0008] As a further limitation of the technical solution of the present invention, the steps of uploading a file to the IPFS network and obtaining a hash string returned by IPFS as a file identifier include: Create an IPFS client to upload file contents to the pre-deployed IPFS network; IPFS divides the file into blocks, calculates the hash value of each data block, builds a directed acyclic graph based on the relationship between the data blocks, calculates the root hash value, adds metadata and calculates the final hash value again, encodes the final hash value to obtain the final hash string, and returns the generated hash string to the front end; Get the hash string returned by IPFS as the file identifier.

[0009] IPFS leverages the advantages of distributed storage by performing operations such as file segmentation and constructing directed acyclic graphs (DAGs), improving the efficiency and reliability of file storage. By calculating block, root, and final hash values, it provides a multi-level integrity verification mechanism for files, ensuring they are tamper-proof during storage and transmission. The generated hash string is returned to the frontend, facilitating interaction between the frontend and backend. Users can obtain a unique file identifier on the frontend, enabling further file access and management.

[0010] As a further limitation of the technical solution of the present invention, IPFS processes a file into blocks, calculates a hash value for each data block, constructs a directed acyclic graph based on the relationship between the data blocks, calculates a root hash value, calculates a final hash value again after adding metadata, and encodes the final hash value to obtain a final hash string, including the following steps: Split large files into data blocks of a set size; Calculate the hash value for each data block; Take each data block and its corresponding hash value as a node, and construct a directed acyclic graph based on the sequential relationship between data blocks; Starting from the leaf node of the directed acyclic graph, the hash value of the parent node of each node is calculated step by step until the root hash value of the entire directed acyclic graph is calculated; Based on the root hash value, add the file's metadata and calculate the final hash value again; The final hash value is Base58 encoded to generate a hash string.

[0011] Calculating the root hash value from the leaf nodes upward ensures that the root hash value of the directed acyclic graph accurately reflects the data structure and content of the entire file, improving the accuracy and uniqueness of the hash value. Adding file metadata to the root hash value and recalculating the final hash value ensures that the hash value not only contains file content information but also incorporates metadata, increasing the information content and practicality of the hash value.

[0012] As a further limitation of the technical solution of the present invention, the method further includes: If the hash string cannot be obtained successfully, the file will be marked as failed and put into the retry queue, and the number of retries will be recorded; When the number of retries reaches the preset threshold, it is marked as a final failure, and the failed files are processed regularly through redundant scheduled tasks.

[0013] A retry mechanism and eventual failure marking for file upload failures are implemented. If a hash string cannot be retrieved, the file enters a retry queue. If it still fails after multiple retries, it is marked as a special file. Redundant scheduled tasks are used to regularly process failed files, improving the system's fault tolerance and stability. This avoids data loss caused by accidental file upload failures, ensures file upload reliability, and reduces the need for manual intervention.

[0014] As a further limitation of the technical solution of the present invention, the steps of constructing an encrypted access URL for a file based on a server address and a hash string, and storing the file metadata in a database include: Concatenate the current server address, backend server interface address and hash string to generate the base URL; Securely process the base URL through symmetric encryption or add the hash string to the base URL through digital signature to generate an encrypted URL; The encrypted URL is associated with the file metadata and stored in the database.

[0015] Symmetric encryption of the base URL or digital signature of the hash string effectively prevents URL tampering or forgery, ensuring secure file access. Storing the encrypted URL in a database, along with the file metadata, facilitates unified management of file access rights and related information, improving data management efficiency and accuracy.

[0016] As a further limitation of the technical solution of the present invention, the steps of securely processing the base URL by symmetric encryption or processing the hash string by digital signature and adding it to the base URL to generate the encrypted URL include: Use the key to encrypt the base URL to generate ciphertext, encode the ciphertext with Base64, and concatenate it to the base URL to generate the encrypted URL; or calculate the signature of the hash string and append the signature to the base URL parameters to generate the encrypted URL.

[0017] As a further limitation of the technical solution of the present invention, the step of providing preview or download service according to file type includes: If the file type is image or SVG, the file is written to the response stream and an online preview is provided; If the file type is other than image or SVG, download service will be provided.

[0018] Different services are provided based on file type, including online previews for images and SVG files and downloads for other file types. This meets the needs of users with different file types and improves the user experience. Previews are provided directly for previewable files, reducing unnecessary file downloads and optimizing system resource utilization.

[0019] This application strictly verifies the file format before uploading. By checking the basic information and actual content of the file, it ensures that only files that meet the preset type list can be uploaded to the IPFS network. This effectively prevents malicious or incompatible files from entering the system, improving the security and stability of the system. The uploaded files are verified for security and integrity to ensure that the files have not been tampered with or damaged during transmission and storage. If the verification fails, the file will not be uploaded, thus avoiding potential security risks. When the file upload fails, the system will automatically retry until the preset number of retries is reached. This greatly improves the success rate of file uploads, reduces upload failures due to network fluctuations or other reasons, and enhances the reliability of the system.

[0020] By generating encrypted access URLs, users can only access files through authorized URLs, effectively protecting the privacy and security of files. Furthermore, URL encryption makes file access more flexible and controllable, ensuring that only users with the appropriate permissions can access files. When users access files, the backend performs strict permissions verification to ensure that only authorized users can access the corresponding files. This enables granular access control for files, meeting the diverse access needs of different users.

[0021] In a second aspect, the technical solution of the present invention also provides a file control device based on IPFS, including a request receiving module, a format verification module, a consistency verification module, an upload module, a hash string acquisition module, a URL construction module and an access response module; The request receiving module is used to receive file upload requests initiated by users through the front-end interface; The format verification module is used to read the basic information of the file and confirm the file format, and verify the file format with the preset type list; The consistency verification module is used to verify the security and integrity of files that have passed the verification; The upload module is used to upload the file to the IPFS network if the verification is passed; Hash string acquisition module, used to obtain the hash string returned by IPFS as a file identifier; The URL construction module is used to construct the encrypted access URL of the file based on the server address and hash string, and store the file metadata in the database; The access response module is used to receive file access requests initiated by users through URLs, decrypt the URLs and verify user permissions, retrieve files from the IPFS network based on the hash string, and provide preview or download services based on the file type.

[0022] As a further limitation of the technical solution of the present invention, after IPFS receives a file, it divides the file into blocks, calculates the hash value of each data block, constructs a directed acyclic graph based on the relationship between the data blocks, and then calculates the root hash value, calculates the final hash value again after adding metadata, and encodes the final hash value to obtain the final hash string.

[0023] As a further limitation of the technical solution of the present invention, IPFS divides large files into data blocks of a set size; calculates a hash value for the data of each data block; uses each data block and its corresponding hash value as a node, and constructs a directed acyclic graph based on the sequential relationship between the data blocks; starting from the leaf node of the directed acyclic graph, the hash value of the parent node of each node is calculated step by step upward until the root hash value of the entire directed acyclic graph is calculated; based on the root hash value, the file's metadata is added and the final hash value is calculated again; the final hash value is Base58 encoded to generate a hash string.

[0024] As a further limitation of the technical solution of the present invention, the hash string acquisition module is also used to mark the file as failed and enter the retry queue if the hash string cannot be successfully obtained, and record the number of retries; when the number of retries reaches a preset threshold, it is marked as a final failure, and the failed file is regularly processed through redundant timed tasks.

[0025] As a further limitation of the technical solution of the present invention, the URL construction module includes a basic URL generation unit, an encryption processing unit and a storage execution unit; The basic URL generation unit is used to generate the basic URL by concatenating the current server address, the backend server interface address and the hash string; An encryption processing unit, configured to securely process the base URL using symmetric encryption or to process a hash string using a digital signature and add it to the base URL to generate an encrypted URL; The storage execution unit is used to associate the encrypted URL with the file metadata and store it in a database.

[0026] As a further limitation of the technical solution of the present invention, the encryption processing unit is specifically used to use a key to encrypt the base URL to generate ciphertext, encode the ciphertext with Base64 and then splice it to the base URL to generate an encrypted URL; or, calculate the signature of the hash string, and append the signature to the base URL parameters to generate an encrypted URL.

[0027] As a further limitation of the technical solution of the present invention, the access response module is also used to write the file into the response stream and provide an online preview if the file type is a picture or SVG; if the file type is other than a picture or SVG, a download service is provided.

[0028] In a third aspect, the technical solution of the present invention also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; the memory stores computer program instructions that can be executed by the at least one processor, and the computer program instructions are executed by the at least one processor so that the at least one processor can execute the IPFS-based file control method as described in the first aspect.

[0029] In a fourth aspect, the technical solution of the present invention also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions enable the computer to execute the IPFS-based file control method as described in the first aspect.

[0030] It can be seen from the above technical solutions that the present application has the following advantages: by adopting the IPFS decentralized storage method, once the file is uploaded to the network, it is difficult to be tampered with, thus ensuring the integrity and authenticity of the file. By pre-configuring the file types allowed for upload through the system database, and using cache and other methods to store them in memory in advance for quick verification, it is possible to effectively avoid uploading unsafe or non-compliant file types, reducing potential security risks; for files that fail to successfully obtain the hash string, the system will automatically mark them and enter the retry queue until they are marked as failed after reaching the preset number of retries, which not only improves the success rate of file uploads, but also ensures the stability of the system. Users can directly access files through URLs, and the system supports online preview functions for images and SVG files, which greatly facilitates the user's operating experience; the entire process from file upload, storage to access is reasonably designed, and each link is closely connected, which greatly shortens the file processing time and improves overall efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for the description. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0032] Figure 1 A flowchart of a method provided in an embodiment of the present invention.

[0033] Figure 2 This is a block diagram of a device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0034] In order to make the application objectives, features, and advantages of this application more obvious and easy to understand, the technical solutions protected by this application will be clearly and completely described below using specific embodiments and drawings. Obviously, the embodiments described below are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0035] like Figure 1As shown, an embodiment of the present invention provides a file control method based on IPFS, comprising the following steps: S1: Receives file upload requests initiated by users through the front-end interface; On the front-end interface, design a file selection button and an upload button. When the user clicks the file selection button, selects the file to upload, and then clicks the upload button, the front-end sends a file upload request to the back-end server via AJAX or form submission.

[0036] S2: Read the basic information of the file and confirm the file format, and verify the file format with the preset type list; The backend server uses the corresponding framework to receive the request. After receiving the file, the backend reads the basic file information, such as the file name and size. The file format is confirmed by the file extension or the header information of the file content. A preset list of allowed file types for upload is set up, and the read file format is compared with this list.

[0037] S3: Verify the security and integrity of the files that have passed the verification; You can use a hash algorithm (such as MD5 or SHA-256) to calculate the file's hash value and compare it with the file's own hash value (if any) to verify the file's integrity. Also, use antivirus software or security detection tools to scan the file to ensure it does not contain malicious code.

[0038] S4: If the verification is successful, upload the file to the IPFS network and obtain the hash string returned by IPFS as the file identifier; Use the IPFS client library to upload the file to the IPFS network and get the returned hash string.

[0039] S5: Constructs the encrypted access URL of the file based on the server address and hash string, and stores the file metadata in the database; The base URL is constructed using the server address and the obtained IPFS hash string, which is then encrypted. At the same time, the file's metadata (such as file name, file size, upload time, IPFS hash string, etc.) is stored in the database.

[0040] S6: Receive the file access request initiated by the user through the URL, decrypt the URL and verify the user's permissions, retrieve the file from the IPFS network according to the hash string, and provide preview or download services based on the file type.

[0041] After receiving the user's access request, the backend decrypts the URL and extracts the IPFS hash string. It then verifies the user's permissions (such as whether they are logged in and have permission to access the file). It then uses the IPFS client to retrieve the file from the IPFS network based on the hash string. Depending on the file type, the user is provided with a preview or download service.

[0042] Double verification through file header byte analysis and MIME type validation prevents malicious file uploads. Encrypted URLs combined with database permission verification prevent unauthorized access and URL tampering. The distributed nature of PFS ensures that files cannot be tampered with once stored, safeguarding data integrity. Leveraging the IPFS network to avoid single points of failure, data is sharded and stored across multiple nodes, reducing the risk of data loss. Automatic retries are performed on failed uploads, and redundant tasks regularly repair abnormal files, improving robustness. Previews are automatically provided based on file type, while other types are directly downloaded, simplifying user operations. File access is accelerated through a CDN, and Redis caches frequently accessed data, reducing IPFS search latency. Dynamic load balancing optimizes resource allocation, ensuring stability for large-scale user access. IPFS's distributed storage reduces centralized server bandwidth and hardware costs. Automated processes, from upload verification to failed retries, reduce the need for manual intervention. The list of allowed file types, encryption algorithms, and retry policies can all be flexibly adjusted through database configuration. File metadata is bound to business logic (such as user ID and project number), facilitating scalable application scenarios.

[0043] In some embodiments, step S4 specifically includes: S41: Create an IPFS client to upload file content to the pre-deployed IPFS network; S42: IPFS divides the file into blocks, calculates the hash value of each data block, constructs a directed acyclic graph based on the relationship between the data blocks, calculates the root hash value, adds metadata and calculates the final hash value again, encodes the final hash value to obtain the final hash string, and returns the generated hash string to the front end; S43: Get the hash string returned by IPFS as the file identifier.

[0044] In some embodiments, IPFS processes a file into blocks, calculates a hash value for each data block, constructs a directed acyclic graph based on the relationship between the data blocks, calculates a root hash value, adds metadata, and calculates a final hash value again. The steps of encoding the final hash value to obtain a final hash string include: S421: Split the large file into data blocks of a set size; S422: Calculate a hash value for each data block; S423: Using each data block and its corresponding hash value as a node, a directed acyclic graph is constructed based on the sequential relationship between the data blocks; S424: Starting from the leaf node of the directed acyclic graph, the hash value of the parent node of each node is calculated step by step upward until the root hash value of the entire directed acyclic graph is calculated; S425: Based on the root hash value, add the file metadata and calculate the final hash value again; S426: Base58 encode the final hash value to generate a hash string.

[0045] In some embodiments, the method further comprises: If the hash string cannot be obtained successfully, the file will be marked as failed and put into the retry queue, and the number of retries will be recorded; When the number of retries reaches the preset threshold, it is marked as a final failure, and the failed files are processed regularly through redundant scheduled tasks.

[0046] In some embodiments, S5 specifically includes: S51: Concatenate the current server address, the backend server interface address, and the hash string to generate a basic URL; S52: Securely process the base URL through symmetric encryption or process the hash string through digital signature and add it to the base URL to generate an encrypted URL; specifically, it includes: using the key to encrypt the base URL to generate ciphertext, encoding the ciphertext with Base64 and then splicing it to the base URL to generate the encrypted URL; or, calculating the signature of the hash string, and appending the signature to the base URL parameters to generate the encrypted URL.

[0047] S53: The encrypted URL is associated with the file metadata and stored in a database.

[0048] It should be noted that the steps for providing preview or download services based on file types include: If the file type is image or SVG, the file is written to the response stream and an online preview is provided; If the file type is other than image or SVG, download service will be provided.

[0049] The verification file format further includes caching a preset list of allowed upload file types in memory to improve verification efficiency. The file metadata includes the encrypted URL, real file name, upload time, file size, operating user, associated business data, IPFS hash string, and original file type.

[0050] Use TLS / SSL protocols to encrypt communications between clients and servers, or use AES to encrypt files before uploading. Performance optimizations further include: using Redis to cache frequently accessed file metadata; employing CDN to accelerate file distribution; and dynamically adjusting load balancing strategies to cope with high-concurrency scenarios.

[0051] In order to solve the problems of traditional file storage, confusion in file upload types, file acquisition methods, etc., the present invention proposes a file control method based on IPFS, which includes: file upload and control, file IPFS storage, file information storage, file access, file security and performance optimization, etc.

[0052] File upload and control: users select files and initiate upload requests through the front-end interface. After receiving the upload request, the back-end server first reads the basic information of the file, including but not limited to the file name, file size, and preliminary MIME type. Relying solely on the MIME type may not be enough to accurately identify the true type of the file, so it is necessary to further check the first few bytes of the file content to confirm its true format. The system database pre-configures the file types allowed for upload and stores them in memory in advance through caching and other means to verify whether the file format meets the requirements. If the file type does not meet the requirements, an error message is returned to the front-end, prompting the user to upload again. File IPFS storage: For files that pass type verification, an IPFS client is created to upload their content to the pre-deployed IPFS network. After storage is complete, IPFS returns a unique hash string (dividing the file into blocks, taking the hash of each block, constructing a directed acyclic graph of the hash, then calculating the root hash, adding metadata (such as the file name) and calculating the hash again, and Base58 encoding the hash string to obtain the final hash) as the identifier of the file. This hash string is used to locate the file in the IPFS network and serves as the basis for subsequent queries and access. At the same time, the hash string is monitored to see if it returns successfully. If it fails, the file is marked and entered into the retry queue. The number of retries is recorded. If the number of failures reaches the preset number, it is marked as failed. The system has redundant timed tasks and regularly processes failed files. File information storage is based on the current server address and a specific backend interface address (the backend server interface address, which changes according to the project deployment environment). The file access URL is constructed in combination with the IPFS hash string. URL access is controlled through encryption, and the encrypted URL, real file name, upload time, file size, operating user, related business data (data related to the business itself can be stored according to business needs), the corresponding IPFS hash string, and the original type of the file are saved in the database. The specific database address is in the code configuration and can be switched according to actual needs.

[0053] File access, users access files through URLs. After receiving the URL, the backend first decrypts it and verifies the user's access rights. If passed, the original file name and file type are obtained based on the hash string. Then, the byte array of the file is retrieved from the IPFS network based on the hash string (which is actually the reverse of file storage). A temporary file is created locally based on the original file name and file type, and the byte array is written to the temporary file. The file type is determined. If it is a picture or SVG type, the response header file is set to the corresponding type, and the local temporary file is written to the response file stream. After success, the temporary file is deleted. File security and performance optimization: During the file upload and download stages, measures must be taken to protect data security, such as encrypted transmission and identity authentication. Additional security policies should be implemented for sensitive files. For scenarios involving large file uploads and downloads, overall system performance can be improved by reducing duplicate data retrieval through caching mechanisms, accelerating file distribution through CDN, and optimizing database query efficiency. Especially in high-concurrency scenarios, a reasonable load balancing strategy and distributed architecture design should be adopted. Additional security policies should be implemented for sensitive files, such as using the TLS / SSL protocol to encrypt communications between the client and server or using AES to encrypt files before uploading. Caching mechanisms should use Redis to store file metadata for access. As for a reasonable load strategy, it should be dynamically adjusted based on the actual usage scenario.

[0054] like Figure 2 As shown, an embodiment of the present invention further provides a file control device based on IPFS, including a request receiving module, a format verification module, a consistency verification module, an upload module, a hash string acquisition module, a URL construction module and an access response module; The request receiving module is used to receive file upload requests initiated by users through the front-end interface; The front-end interface provides a file selection box and an upload button. When the user clicks the file selection box to select a file to upload and then clicks the upload button, the front-end sends the file data to the back-end server via an HTTP POST request. The back-end server uses a web framework (such as Flask or Django in Python) to listen on a specified interface address and receive the file upload request from the front-end. The request receiving module parses the request, extracts the file data, and prepares it for subsequent processing.

[0055] The format verification module is used to read the basic information of the file and confirm the file format, and verify the file format with the preset type list; After receiving the file data, this module first reads the basic file information, such as the file name and size. It also analyzes the first few bytes of the file content to determine the file's true format, ensuring that the file type and MIME type match. For example, for image files, the module checks whether the file header conforms to the characteristics of formats such as JPEG and PNG. The module then compares the read file format with a preset list of allowed file types. If the file format is in the allowed list, the file passes the format check; otherwise, an error message is returned to the front-end, indicating that the uploaded file format is not allowed.

[0056] The consistency verification module is used to verify the security and integrity of files that have passed the verification; Use security detection tools to scan files for security threats. For example, you can integrate an open-source antivirus engine to perform real-time file scanning. Calculate the file's hash value using a hash algorithm (such as SHA-256) and compare it with the file's native hash value. If the two match, the file's integrity is verified. Otherwise, the file is assumed to have been tampered with during transmission and an error message is returned.

[0057] The upload module is used to upload the file to the IPFS network if the verification is passed; After verification, the upload module creates an IPFS client instance and connects to the pre-deployed IPFS network. The file data is uploaded to the IPFS network through the IPFS client. After the IPFS network receives the file, it processes it into blocks.

[0058] Hash string acquisition module, used to obtain the hash string returned by IPFS as a file identifier; IPFS divides large files into data blocks of a set size (e.g., 256KB) and calculates a hash value for each block. Each block and its corresponding hash value is then used as a node to construct a directed acyclic graph (DAG) based on the sequential relationship between the blocks. Starting from the leaf nodes of the DAG, the hash value of each node's parent is calculated upwards until the root hash value of the entire DAG is calculated. Based on the root hash value, the file's metadata (such as file name and size) is added, and the final hash value is calculated again. Finally, the final hash value is Base58-encoded to generate the final hash string.

[0059] The hash string acquisition module obtains the hash string generated by the IPFS client as a file identifier. If the hash string cannot be obtained successfully, the file is marked as failed and added to the retry queue, and the number of retries is recorded. When the number of retries reaches a preset threshold (for example, 3), it is marked as a final failure and these failed files are regularly processed through redundant scheduled tasks, such as notifying an administrator for manual intervention.

[0060] The URL construction module is used to construct the encrypted access URL of the file based on the server address and hash string, and store the file metadata in the database; Concatenate the current server address, the backend server interface address, and the obtained IPFS hash string to generate the base URL. For example, http: / / example.com / api / file / <ipfs_hash> There are two encryption methods to choose from. One is to use a key to symmetrically encrypt the base URL, encode the generated ciphertext in Base64, and then concatenate it to the base URL to generate the encrypted URL; the other is to calculate the signature of the hash string and append the signature to the base URL parameter to generate the encrypted URL. Associate the encrypted URL with the file's metadata (such as file name, file size, upload time, IPFS hash string, etc.) and store it in a database. The database can use a relational database (such as MySQL) or a non-relational database (such as MongoDB).

[0061] The access response module is used to receive file access requests initiated by users through URLs, decrypt the URLs and verify user permissions, retrieve files from the IPFS network based on the hash string, and provide preview or download services based on the file type.

[0062] Receives file access requests from users via encrypted URLs, decrypts the URL, and extracts the IPFS hash string. Verifies user permissions, such as whether the user is logged in and has permission to access the file. If the permission check fails, returns an error message to the user. Based on the extracted hash string, retrieves the file from the IPFS network. If the file type is an image or SVG, writes the file content to the response stream and provides an online preview on the front-end page. If the file type is other than an image or SVG, provides a download service and sends the file as an attachment to the user.

[0063] Users upload files through the front-end interface. The request receiving module receives the request and passes it to the format verification module. The format verification module verifies the file format and passes it to the consistency verification module for security and integrity verification. Once verified, the upload module uploads the file to the IPFS network. The hash string acquisition module obtains the hash string returned by IPFS. The URL construction module constructs an encrypted access URL based on the hash string and stores the file metadata. When a user accesses a file through the URL, the access response module performs decryption and permission verification, and then provides preview or download services based on the file type. Throughout this process, the hash string acquisition module retries any files that fail to upload, ensuring system stability and reliability.

[0064] Reading the basic information of the file further includes: analyzing the actual format of the file through the header bytes of the file content to ensure that the file type is consistent with the MIME type.

[0065] In some embodiments, after IPFS receives a file, it divides the file into blocks, calculates the hash value of each data block, constructs a directed acyclic graph based on the relationship between the data blocks, and then calculates the root hash value, calculates the final hash value again after adding metadata, and encodes the final hash value to obtain the final hash string.

[0066] In some embodiments, IPFS divides large files into data blocks of a set size; calculates a hash value for the data of each data block; uses each data block and its corresponding hash value as a node, and constructs a directed acyclic graph based on the sequential relationship between the data blocks; starting from the leaf node of the directed acyclic graph, the hash value of the parent node of each node is calculated step by step upward until the root hash value of the entire directed acyclic graph is calculated; based on the root hash value, the metadata of the file is added, and the final hash value is calculated again; the final hash value is Base58 encoded to generate a hash string.

[0067] In some embodiments, the hash string acquisition module is also used to mark the file as failed and enter the retry queue if the hash string cannot be successfully obtained, and record the number of retries; when the number of retries reaches a preset threshold, it is marked as a final failure, and the failed file is regularly processed through redundant timed tasks.

[0068] In some embodiments, the URL construction module includes a basic URL generation unit, an encryption processing unit, and a storage execution unit; The basic URL generation unit is used to generate the basic URL by concatenating the current server address, the backend server interface address and the hash string; An encryption processing unit, configured to securely process the base URL using symmetric encryption or to process a hash string using a digital signature and add it to the base URL to generate an encrypted URL; The storage execution unit is used to associate the encrypted URL with the file metadata and store it in a database.

[0069] In some embodiments, the encryption processing unit is specifically used to use a key to encrypt the base URL to generate a ciphertext, encode the ciphertext with Base64 and then splice it to the base URL to generate an encrypted URL; or, calculate a signature for the hash string, and append the signature to the base URL parameters to generate an encrypted URL.

[0070] In some embodiments, the access response module is further used to write the file into the response stream and provide an online preview if the file type is a picture or SVG; if the file type is other than a picture or SVG, provide a download service.

[0071] An embodiment of the present invention further provides an electronic device comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus. The communication bus can be used to transmit information between the electronic device and a sensor. The processor can call logic instructions in the memory to execute the following method: S1: receiving a file upload request initiated by a user through a front-end interface; S2: reading basic information of the file and confirming the file format, and verifying the file format against a preset type list; S3: performing security and integrity verification on files that pass the verification; S4: if the verification passes, uploading the file to the IPFS network and obtaining a hash string returned by IPFS as a file identifier; S5: constructing an encrypted access URL for the file based on the server address and the hash string, and storing the file metadata in a database; S6: receiving a file access request initiated by a user via a URL, decrypting the URL and verifying user permissions, retrieving the file from the IPFS network based on the hash string, and providing preview or download services based on the file type.

[0072] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.

[0073] An embodiment of the present invention provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions enable a computer to execute the method provided by the above method embodiment, for example, including: S1: receiving a file upload request initiated by a user through a front-end interface; S2: reading the basic information of the file and confirming the file format, and verifying the file format with a preset type list; S3: performing security and integrity verification on the file that passes the verification; S4: if the verification passes, uploading the file to the IPFS network, and obtaining the hash string returned by IPFS as a file identifier; S5: constructing an encrypted access URL for the file based on the server address and the hash string, and storing the file metadata in a database; S6: receiving a file access request initiated by the user through a URL, decrypting the URL and verifying the user's permissions, retrieving the file from the IPFS network according to the hash string, and providing preview or download services based on the file type.

[0074] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A file control method based on IPFS, characterized in that: The following steps are involved: Receive file upload requests initiated by users through the front-end interface; Read the basic information of the file and confirm the file format, and verify the file format with the preset type list; Verify the security and integrity of files that have passed verification; If the verification is successful, upload the file to the IPFS network and obtain the hash string returned by IPFS as the file identifier; Construct an encrypted access URL for the file based on the server address and hash string, and store the file metadata in the database; Receive file access requests initiated by users through URLs, decrypt the URLs and verify user permissions, retrieve files from the IPFS network based on the hash string, and provide preview or download services based on the file type.

2. The file control method based on IPFS according to claim 1, characterized in that: The steps to upload a file to the IPFS network and obtain the hash string returned by IPFS as the file identifier include: Create an IPFS client to upload file contents to the pre-deployed IPFS network; IPFS divides the file into blocks, calculates the hash value of each data block, builds a directed acyclic graph based on the relationship between the data blocks, calculates the root hash value, adds metadata and calculates the final hash value again, encodes the final hash value to obtain the final hash string, and returns the generated hash string to the front end; Get the hash string returned by IPFS as the file identifier.

3. The file control method based on IPFS according to claim 2, characterized in that: IPFS divides files into blocks, calculates the hash value of each data block, constructs a directed acyclic graph based on the relationship between the data blocks, calculates the root hash value, adds metadata and calculates the final hash value again, and encodes the final hash value to obtain the final hash string. The steps include: Split large files into data blocks of a set size; Calculate the hash value for each data block; Take each data block and its corresponding hash value as a node, and construct a directed acyclic graph based on the sequential relationship between data blocks; Starting from the leaf node of the directed acyclic graph, the hash value of the parent node of each node is calculated step by step until the root hash value of the entire directed acyclic graph is calculated; Based on the root hash value, add the file's metadata and calculate the final hash value again; The final hash value is Base58 encoded to generate a hash string.

4. The file control method based on IPFS according to claim 3, characterized in that: The method further includes: If the hash string cannot be obtained successfully, the file will be marked as failed and put into the retry queue, and the number of retries will be recorded; When the number of retries reaches the preset threshold, it is marked as a final failure, and the failed files are processed regularly through redundant scheduled tasks.

5. The file control method based on IPFS according to claim 4, characterized in that: The steps of constructing an encrypted access URL for a file based on the server address and hash string and storing the file metadata in a database include: Concatenate the current server address, backend server interface address and hash string to generate the base URL; Securely process the base URL through symmetric encryption or add the hash string to the base URL through digital signature to generate an encrypted URL; The encrypted URL is associated with the file metadata and stored in the database.

6. The file control method based on IPFS according to claim 5, characterized in that: The steps to securely process the base URL through symmetric encryption or add the hash string to the base URL through digital signature are as follows: Use the key to encrypt the base URL to generate ciphertext, encode the ciphertext with Base64, and concatenate it to the base URL to generate the encrypted URL; or calculate the signature of the hash string and append the signature to the base URL parameters to generate the encrypted URL.

7. The file control method based on IPFS according to claim 6, characterized in that: The steps to provide preview or download services based on file type include: If the file type is image or SVG, the file is written to the response stream and an online preview is provided; If the file type is other than image or SVG, download service will be provided.

8. A file control device based on IPFS, characterized in that: It includes request receiving module, format checking module, consistency verification module, upload module, hash string acquisition module, URL construction module and access response module; The request receiving module is used to receive file upload requests initiated by users through the front-end interface; The format verification module is used to read the basic information of the file and confirm the file format, and verify the file format with the preset type list; The consistency verification module is used to verify the security and integrity of files that have passed the verification; The upload module is used to upload the file to the IPFS network if the verification is passed; Hash string acquisition module, used to obtain the hash string returned by IPFS as a file identifier; The URL construction module is used to construct the encrypted access URL of the file based on the server address and hash string, and store the file metadata in the database; The access response module is used to receive file access requests initiated by users through URLs, decrypt the URLs and verify user permissions, retrieve files from the IPFS network based on the hash string, and provide preview or download services based on the file type.

9. An electronic device, characterized in that: The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; the memory stores computer program instructions that can be executed by the at least one processor, and the computer program instructions are executed by the at least one processor to enable the at least one processor to execute the IPFS-based file control method as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium, characterized in that The non-transitory computer-readable storage medium stores computer instructions, which enable the computer to execute the IPFS-based file control method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Link-stealing-prevention method and system for media files and server

    CN104009989A

  • File uploading method and device

    CN107707679A

  • E-mail receiving and sending method based on block chain

    CN112272155A

  • Distributed cloud storage method and device based on IPFS and storage medium

    CN113535648A

  • Database access method and device

    CN116484338A

Cited By

  • Work meeting picture uploading control method and system based on image similarity detection

    CN120910298A

  • File data analysis platform

    CN121636449A

  • Method for enhancing IPFS data transmission security based on RISC-V trusted execution environment

    CN121907512A