A data encryption method based on data content and related device

By configuring preset encryption information and traversing target data to determine encryption rules, the problem of easy omission or error in electronic document encryption in the prior art is solved, and a more flexible, accurate and widely applicable data encryption effect is achieved.

CN111177737BActive Publication Date: 2025-05-16TENCENT CLOUD COMPUTING (BEIJING) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201910760150.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-08-16
Publication Date
2025-05-16
Estimated Expiration
2040-09-26

AI Technical Summary

Technical Problem

The prior art is prone to missing encryption or incorrect encryption in a large number of electronic document scenarios, and cannot perform corresponding encryption for specific file editing content sensitivity levels, which affects the convenience and scope of application of the encryption process.

Method used

By configuring preset encryption information, including preset fields and preset rules, traverse the target data according to the preset fields to obtain identification information, determine the preset rules corresponding to the preset fields, and encrypt the target data.

Benefits of technology

It improves the flexibility and accuracy of the encryption process, avoids the situation of mis-encryption or misencryption of data, and corresponds to different encryption levels according to different identification information, improves the accuracy of data encryption and expands the application scope.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111177737B_ABST
    Figure CN111177737B_ABST
Patent Text Reader

Abstract

The present application discloses a data encryption method and related devices based on data content. The flexibility of the encryption process is improved by configuring the encryption information and the controllability of the configuration process. The data is encrypted according to preset fields to avoid the occurrence of missed encryption or wrong encryption of data in the case of large amounts of data, thereby improving the accuracy of the encryption process. In addition, different encryption levels correspond to different identification information, thereby further improving the accuracy of data encryption and having a wide range of applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data encryption method based on data content and related devices. Background Art

[0002] With the development of computer technology, more and more information is stored in the form of electronic documents. Electronic documents refer to text materials formed by people in social activities, which are carried by chemical magnetic materials such as computer disks, magnetic disks and optical disks. They rely on computer systems for access and can be transmitted on communication networks. They mainly include electronic documents, electronic letters, electronic reports, electronic drawings, etc. However, in order to prevent the contents of some electronic documents involving confidentiality or privacy from being illegally obtained by others during the transmission process, it is necessary to encrypt the electronic documents before transmission.

[0003] Generally, electronic documents are encrypted using driver encryption technology, that is, by filtering different request packets (I / O request packet, IRP), the IRP is sent to different processing logics; in different processing logics, according to the IRP request result, it is determined whether the generated handle needs to be encrypted / decrypted when reading and writing, and the determination result is recorded in the memory to maintain the current handle list.

[0004] However, the encryption information in this configuration encryption process is collected from the server and has nothing to do with the content of the document itself. In scenarios with a large number of documents, encryption is easily missed or incorrectly encrypted, and it is impossible to perform corresponding encryption according to the sensitivity level of specific file editing content, affecting the convenience and scope of application of the encryption process. Summary of the invention

[0005] In view of this, the first aspect of the present application provides a data encryption method based on data content, which can be applied to a data encryption system or program process, and specifically includes: configuring preset encryption information, the encryption information includes preset fields and preset rules, and the preset rules are set based on the encryption level of the preset fields;

[0006] Traversing the target data according to the preset field to obtain identification information, the target data is used to indicate data of a preset operation performed by a user within a preset time period, and the identification information is used to indicate the occurrence of the preset field in the target data;

[0007] A preset rule corresponding to the preset field is determined according to the identification information to encrypt the target data.

[0008] Preferably, in some possible implementations of the present application, identification information of the target data is determined, the identification information including a data type of the target data;

[0009] Matching the preset field with the data type of the target data according to a preset algorithm, wherein the preset algorithm is used to convert the data type of the target data into the data type corresponding to the preset field;

[0010] The matched target data is traversed according to the preset fields.

[0011] Preferably, in some possible implementations of the present application, the identification information further includes a traversal rule, and the traversing the matched target data according to the preset field includes:

[0012] Determine a traversal rule corresponding to the target data according to the identification information, wherein the traversal rule includes a traversal direction, a traversal order or a traversal position;

[0013] The preset fields are traversed in the target data after matching according to the traversal rule.

[0014] Preferably, in some possible implementations of the present application, traversing the target data according to the preset field includes:

[0015] Obtaining the user's operation instructions on the target data within a preset time period;

[0016] If the operation instruction meets the preset condition, the target data is traversed according to the preset field.

[0017] Preferably, in some possible implementations of the present application, the preset time period includes a first moment and a second moment, and obtaining the user's operation instruction for the target data within the preset time period includes:

[0018] Acquire the operation frequency of the user at the first moment;

[0019] If the difference between the operation frequency of the user at the second moment and the operation frequency of the first moment meets the start traversal condition, the operation instruction of the user on the target data within a preset time period is obtained according to the difference.

[0020] Preferably, in some possible implementations of the present application, it is characterized in that determining the preset rule corresponding to the preset field according to the identification information to encrypt the target data includes:

[0021] Determining an encryption level of the preset field according to the identification information;

[0022] Determining the preset rule according to the encryption level;

[0023] The target data is encrypted according to the preset rule.

[0024] Preferably, in some possible implementations of the present application, after determining the encryption level of the preset field according to the identification information, the method further includes:

[0025] The correspondence between the preset field and the encryption level is recorded, and the correspondence is used to update the encryption level when the preset field appears again.

[0026] A second aspect of the present application provides another data encryption device, comprising:

[0027] A configuration unit, configured to configure preset encryption information, the encryption information comprising a preset field and a preset rule, the preset rule being set based on an encryption level of the preset field;

[0028] a traversal unit, configured to traverse the target data according to the preset field to obtain identification information, wherein the target data is used to indicate data on which a user performs a preset operation within a preset time period, and the identification information is used to indicate the occurrence of the preset field in the target data;

[0029] An encryption unit is used to determine a preset rule corresponding to the preset field according to the identification information to encrypt the target data.

[0030] Preferably, in some possible implementations of the present application,

[0031] The traversal unit is specifically used to determine the identification information of the target data, where the identification information includes the data type of the target data;

[0032] The traversal unit is specifically used to match the preset field with the data type of the target data according to a preset algorithm, wherein the preset algorithm is used to convert the data type of the target data into a data type corresponding to the preset field;

[0033] The traversal unit is specifically used to traverse the matched target data according to the preset field.

[0034] Preferably, in some possible implementations of the present application, the identification information further includes a traversal rule.

[0035] The traversal unit is specifically used to determine a traversal rule corresponding to the target data according to the identification information, wherein the traversal rule includes a traversal direction, a traversal order or a traversal position;

[0036] The traversal unit is specifically configured to traverse the preset fields in the matched target data according to the traversal rule.

[0037] Preferably, in some possible implementations of the present application,

[0038] The traversal unit is specifically used to obtain the user's operation instructions on the target data within a preset time period;

[0039] The traversal unit is specifically configured to traverse the target data according to the preset field if the operation instruction meets the preset condition.

[0040] Preferably, in some possible implementations of the present application, the preset time period includes a first moment and a second moment, and the traversal unit is specifically used to obtain the operation frequency of the user at the first moment;

[0041] The traversal unit is specifically configured to obtain the user's operation instructions for the target data within a preset time period according to the difference between the user's operation frequency at the second moment and the operation frequency at the first moment if the difference satisfies the start traversal condition.

[0042] Preferably, in some possible implementations of the present application, it is characterized in that:

[0043] The encryption unit is specifically used to determine the encryption level of the preset field according to the identification information;

[0044] The encryption unit is specifically configured to determine the preset rule according to the encryption level;

[0045] The encryption unit is specifically used to encrypt the target data according to the preset rule.

[0046] Preferably, in some possible implementations of the present application,

[0047] The encryption unit is further used to record the corresponding relationship between the preset field and the encryption level, and the corresponding relationship is used to update the encryption level when the preset field appears again.

[0048] The third aspect of the present application provides a computer device, comprising: a memory, a processor and a bus system; the memory is used to store program code; the processor is used to execute the data encryption method described in the first aspect or any one of the first aspects according to the instructions in the program code.

[0049] A fourth aspect of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, which, when executed on a computer, enables the computer to execute the data encryption method described in the first aspect or any one of the first aspects.

[0050] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0051] By configuring preset encryption information, the encryption information includes preset fields and preset rules, and the preset rules are set based on the encryption level of the preset fields; then traversing the target data according to the preset fields to obtain identification information, the target data is used to indicate the data for the user to perform preset operations within a preset time period, and the identification information is used to indicate the appearance of the preset fields in the target data; finally, the preset rules corresponding to the preset fields are determined according to the identification information to encrypt the target data. Due to the controllability of the configuration process, the flexibility of the encryption process is improved; and encryption judgment of data is performed according to the preset fields, which avoids the occurrence of data encryption omission or wrong encryption in the case of large amounts of data, and improves the accuracy of the encryption process; in addition, according to different encryption levels corresponding to different identification information, the accuracy of data encryption is further improved and has a wide range of applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0053] Figure 1 It is a network architecture diagram of the operation of the data encryption system;

[0054] Figure 2 It is a framework diagram of the operation process of a data encryption system;

[0055] Figure 3 A flowchart of a data encryption method provided in an embodiment of the present application;

[0056] Figure 4 A flowchart of another data encryption method provided in an embodiment of the present application;

[0057] Figure 5 A flowchart of another data encryption method provided in an embodiment of the present application;

[0058] Figure 6 A schematic diagram of a data encryption interface display provided in an embodiment of the present application;

[0059] Figure 7 A schematic diagram of the structure of a data encryption device provided in an embodiment of the present application;

[0060] Figure 8 A schematic diagram of the structure of another data encryption device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0061] The embodiment of the present application provides a data encryption method based on data content and a related device, which can be applied to a data encryption system, specifically by configuring preset encryption information, the encryption information includes preset fields and preset rules, the preset rules are set based on the encryption level of the preset fields; then traverse the target data according to the preset fields to obtain identification information, the target data is used to indicate the data on which the user performs preset operations within a preset time period, and the identification information is used to indicate the appearance of the preset fields in the target data; finally, the preset rules corresponding to the preset fields are determined according to the identification information to encrypt the target data. Due to the controllability of the configuration process, the flexibility of the encryption process is improved; and the encryption judgment of the data is performed according to the preset fields, which avoids the occurrence of data encryption omission or wrong encryption in the case of a large amount of data, and improves the accuracy of the encryption process; in addition, according to different encryption levels corresponding to different identification information, the accuracy of data encryption is further improved and has a wide range of applications.

[0062] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein, for example. In addition, the terms "including" and "corresponding to" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0063] It should be understood that the data encryption method provided in the present application can be applied to the operation process of the data encryption system. Specifically, the data encryption system can be operated in the following manner: Figure 1 In the network architecture shown in Figure 1 As shown in the figure, it is a network architecture diagram of the data encryption system. As can be seen from the figure, the data encryption system can obtain the encryption information configured by the terminal, and judge according to the user's operation behavior on the terminal-related data, and traverse and identify the data content according to the relevant fields to match the corresponding encryption rules for the target program, and then automatically encrypt the data. It can be understood that Figure 1 A terminal is shown in FIG. 1 . In actual scenarios, more terminal devices may participate in the data encryption process. The specific number depends on the actual scenario and is not limited here. In addition, Figure 1A data encryption system is shown in the figure, but in actual scenarios, multiple data encryption systems may also be involved, especially in scenarios where multiple application data interact. The specific number of servers depends on the actual scenario.

[0064] It can be understood that the above-mentioned data encryption system can run on a personal mobile terminal, can also run on a server, and can also run on a third-party device to provide client experimental data and rapid iteration and trial and error of background strategies to obtain an experimental report; the specific data encryption system can be run in the above-mentioned device in the form of a program, can also be run as a system component in the above-mentioned device, and can also be used as a cloud service program. The specific operation mode depends on the actual scenario and is not limited here.

[0065] With the development of computer technology, more and more information is stored in the form of electronic documents. Electronic documents refer to text materials formed by people in social activities, which are carried by chemical magnetic materials such as computer disks, magnetic disks and optical disks. They rely on computer systems for access and can be transmitted on communication networks. They mainly include electronic documents, electronic letters, electronic reports, electronic drawings, etc. However, in order to prevent the contents of some electronic documents involving confidentiality or privacy from being illegally obtained by others during the transmission process, it is necessary to encrypt the electronic documents before transmission.

[0066] Generally, electronic documents are encrypted using driver encryption technology, that is, by filtering different request packets (I / O request packet, IRP), the IRP is sent to different processing logics; in different processing logics, according to the IRP request result, it is determined whether the generated handle needs to be encrypted / decrypted when reading and writing, and the determination result is recorded in the memory to maintain the current handle list.

[0067] However, the encryption information in this configuration encryption process is collected from the server and has nothing to do with the content of the document itself. In scenarios with a large number of documents, encryption is easily missed or incorrectly encrypted, and it is impossible to perform corresponding encryption according to the sensitivity level of specific file editing content, affecting the convenience and scope of application of the encryption process.

[0068] In order to solve the above problems, this application proposes a data encryption method based on data content, which is applied to Figure 2 The operation process framework of the data encryption system shown in FIG. Figure 2As shown, it is an operation process framework diagram of a data encryption system, which includes the interaction process of the input end, the client end and the application end, wherein relevant preset fields are input through the input end to generate corresponding multiple fields in the monitoring rules of the client end, and the client end determines the recognition process of the application end data by identifying the user's editing process of the application end data, and then performs corresponding encryption operations on the relevant data according to the recognition results and the matching rules configured by the input end.

[0069] It can be understood that although the figure shows an example of three fields, in actual scenarios there may be more or fewer fields configured. In addition, the data on the application side can be in various forms such as documents and pictures, and the quantity can also be multiple. The specific quantity and data type depend on the actual scenario and are not limited here.

[0070] It should be noted that the data encryption method in the present application can also be applied to the process of data decryption, that is, configuring preset decryption information, the decryption information includes preset fields and preset rules, and the preset rules are set based on the decryption level of the preset fields; traversing the target data according to the preset fields to obtain identification information, the target data is used to indicate the data of the user performing preset operations within a preset time period, and the identification information is used to indicate the occurrence of the preset field in the target data; determining the preset rules corresponding to the preset fields according to the identification information to decrypt the target data.

[0071] The following embodiments are described using the encryption process as an example. It is understandable that the decryption process may also be performed by referring to related methods.

[0072] Combined with the above system process, the following will introduce the data encryption method in this application, please refer to Figure 3 , Figure 3 A flowchart of a data encryption method provided in an embodiment of the present application, the embodiment of the present application at least includes the following steps:

[0073] 301. Configure preset encryption information.

[0074] In this embodiment, the encryption information includes a preset field and a preset rule, wherein the preset rule is set based on the encryption level of the preset field.

[0075] It can be understood that the preset fields can be one or more, for example: finance, report, finance, bill and other fields can all be used as preset fields, and the preset rules are different judgment logics set according to different fields. For example: for the preset fields that are sensitive fields such as finance, the corresponding preset rule is that the number of occurrences is less than 3 times; for the preset fields that are related to personal privacy such as travel, the corresponding preset rule is that the number of occurrences is less than 10 times.

[0076] 302. Traverse the target data according to the preset fields to obtain identification information.

[0077] In this embodiment, the target data is used to indicate data of a preset operation performed by a user within a preset time period. The target data can be a document, a picture, or a file type composed of other character sets. Specifically, the target data can be a file or a collection of multiple files. The specific quantity and form depend on the actual scenario.

[0078] In addition, the identification information is used to indicate the occurrence of the preset field in the target data. For example, when the target data is a document and the preset field is "finance", the occurrence of the field "finance" is searched in the document, where the occurrence can be the number of occurrences or the frequency of occurrence within a certain length.

[0079] In a possible scenario, the target data may also be a picture, which may not correspond to the preset field in format. For this scenario, the identification information of the target data may also be determined, and the identification information is used to indicate the data type of the target data; the preset field is matched with the identification information of the target data according to a preset algorithm, and the preset algorithm is generated according to the comparison between the target data and the preset field; the target data is traversed according to the matched preset field. For example: the identification information of the target data indicates that the format of the target data is pdf, and the pdf can be converted to word at this time, and then the converted word file is traversed according to the preset field, where the preset algorithm can be to match the target data with the preset field through a binary stream, that is, if it is a picture or pdf, the OCR recognition engine is called to recognize the text content.

[0080] It can be understood that the matching process between the target data and the preset field can be the conversion of the target data into the format corresponding to the preset field, or the conversion of the preset field into the format of the target data, or the conversion of the target data and the preset field into a third format for matching. The specific conversion method depends on the actual scenario and is not limited here.

[0081] Optionally, the above process of traversing the target data according to preset fields can be based on certain traversal rules, and the traversal rules may include traversal direction, traversal order or traversal position; specifically, taking the target data as a document as an example, the traversal direction may indicate the order of traversal, i.e., reverse order, sequential order or random order, and the traversal order may indicate the priority arrangement of the traversal process, for example: traverse the title first, then traverse the summary, etc., and the traversal position is used to indicate the start and end nodes of the traversal, that is, which segment the traversal process starts from or ends the traversal process at a certain segment.

[0082] Optionally, the user's operation process can be monitored intermittently, for example, obtaining the user's operation instructions for the target data within a preset time period; if the operation instructions meet the preset conditions, traversing the target data according to the preset fields. For example: if the user's operation information for a certain file obtained within the preset time period includes opening and closing, it can be considered that the user has completed editing the file and can perform traversal operations.

[0083] Specifically, the above-mentioned preset time period includes a first moment and a second moment, and the user's operation frequency at the first moment is first obtained; if the difference between the user's operation frequency at the second moment and the operation frequency at the first moment meets the start traversal condition, the user's operation instructions for the target data in the preset time period are obtained according to the difference. For example: the user's operation frequency at the first moment is 50 mouse clicks per minute, and the operation frequency at the second moment is 5 mouse clicks per minute. At this time, the difference between the first moment and the second moment is large, indicating that the user has completed editing this part, and then the target data is started to be traversed.

[0084] 303. Determine a preset rule corresponding to the preset field according to the identification information to encrypt the target data.

[0085] In this embodiment, the specific encryption process may be to determine the encryption level of the preset field based on the identification information; then classify the target data according to the encryption level, and the classification results correspond to different preset rules; finally, encrypt the target data according to the preset rules.

[0086] Optionally, after the encryption operation is completed, the correspondence between the preset field and the encryption level can be recorded, and the correspondence is used to update the encryption level when the preset field appears again. For example: during the encryption process of a document whose preset field is "Finance", the corresponding encryption level is high, which indicates that the preset rule is that if "Finance" appears in the title of the document, it is listed as an encrypted file. In the encrypted document of the next document, it is first determined whether the title contains "Finance", and then the other contents in the document are traversed according to the preset to obtain the recognition result.

[0087] In combination with the above embodiments, it can be known that by configuring preset encryption information, the encryption information includes preset fields and preset rules, and the preset rules are set based on the encryption level of the preset fields; then the target data is traversed according to the preset fields to obtain identification information, the target data is used to indicate the data for the user to perform preset operations within a preset time period, and the identification information is used to indicate the appearance of the preset fields in the target data; finally, the preset rules corresponding to the preset fields are determined according to the identification information to encrypt the target data. Due to the controllability of the configuration process, the flexibility of the encryption process is improved; and the encryption judgment of the data is performed according to the preset fields, which avoids the occurrence of data encryption omission or wrong encryption in the case of a large amount of data, and improves the accuracy of the encryption process; in addition, different encryption levels correspond to different identification information, which further improves the accuracy of data encryption and has a wide range of applications.

[0088] Since the configuration process of the preset fields involves the interaction process between multiple modules in the data encryption system; the following is an explanation of the scenario with reference to the accompanying drawings, such as Figure 4 As shown, Figure 4 A flowchart of another data encryption method provided in an embodiment of the present application, the embodiment of the present application at least includes the following steps:

[0089] 401. Configure preset fields on the web page.

[0090] In this embodiment, the preset field may be one or more fields, for example, fields such as finance, report, financial, and bill can all be used as preset fields.

[0091] 402. Configure preset rules on the web page.

[0092] In this embodiment, the preset rules and the preset fields have a corresponding relationship, that is, the preset rules are different judgment logics set according to different fields. For example: for the preset fields that are sensitive fields such as finance, the corresponding preset rule is that the number of occurrences is less than 3 times; for the preset fields that are fields involving personal privacy such as travel, the corresponding preset rule is that the number of occurrences is less than 10 times.

[0093] 403. The web page confirms the encryption information.

[0094] In this embodiment, the above preset rules and preset fields, as well as the corresponding relationship between the two, are packaged and sent to the client.

[0095] 404. The web page sends encrypted information to the client.

[0096] 405. The client parses the encrypted information.

[0097] In this embodiment, the client can obtain the preset fields and preset rules based on the encrypted information. For example, the client can recognize that the engine has received the preset rules based on the encrypted information and load the preset field "finance" into the matching items.

[0098] 406. The client sends encrypted information to the application.

[0099] In this embodiment, the encrypted information is used to instruct the application to start an identification thread regarding target data.

[0100] 407. The application determines the interface API of the target data.

[0101] In this embodiment, there may be multiple target data, and then they are recorded corresponding to their editing interfaces respectively.

[0102] 408. The application adds preset fields.

[0103] In this embodiment, the added preset fields are associated with the target data, that is, different preset fields can be added to different target data.

[0104] 409. The application matches the preset field to the target data editing path.

[0105] In this embodiment, the purpose of matching the preset field to the target data editing path is to monitor the editing process of the target data.

[0106] 410. The application sends the target data path to the client.

[0107] 411. The client determines whether the target data path is detected.

[0108] In this embodiment, the target data path is the corresponding relationship between the target data and the preset field, that is, according to which preset field the target data is monitored.

[0109] 412. The client scans the target data path.

[0110] In this embodiment, the target data path is scanned in order to obtain a corresponding recognition result, that is, the occurrence of a preset field.

[0111] 413. The client determines the encryption rule.

[0112] In this embodiment, the corresponding encryption rule is determined according to the occurrence of the preset field to encrypt the target data.

[0113] It is understandable that after the client determines the encryption rule, the encryption process of the target data specifically includes when to start the encryption thread and the encryption judgment logic. Figure 5 As shown, Figure 5 A flowchart of another data encryption method provided in an embodiment of the present application, the embodiment of the present application at least includes the following steps:

[0114] 501. Determine whether the operation information of the target data meets a preset condition.

[0115] In this embodiment, the operation information meets the preset condition when double-clicking the word document, monitoring the open file interface of the program winword.exe, and after the exe editing ends and the process exits, the monitoring service program receives the word exit notification, that is, the operation information meets the preset condition.

[0116] 502. Classify the target data.

[0117] In this embodiment, the target data that is determined to contain the preset field is divided into the monitoring group, and the target data that does not contain the preset field is divided into the waiting group.

[0118] 503. Determine whether the target data is classified.

[0119] 504. Determine whether the target data is encrypted data.

[0120] In this embodiment, steps 503-504 are used to determine the corresponding encryption rules based on the identification information of the target data; that is, the encryption process can be to determine the encryption level of the preset field based on the identification information; then classify the target data according to the encryption level, and the classification results correspond to different preset rules; finally, encrypt the target data according to the preset rules.

[0121] 505. Traverse the target data again to determine whether to classify.

[0122] 506. Determine whether the target data is encrypted.

[0123] In this embodiment, steps 505-506 are used to prevent misdetection or missed detection of target data, that is, to re-determine the classification and whether the preset field is included.

[0124] 507. Call the encryption interface to encrypt the target data.

[0125] In this embodiment, the confidentiality level of the target data can be read in the application end, and the target data can be encrypted or decrypted according to the level. After encryption, the file will be accompanied by a lock icon, and after decryption, it will become a normal document icon.

[0126] In one possible display method, the following may be used: Figure 6 The display method described above is used to display the above embodiment. Figure 6A schematic diagram of a data encryption interface provided in an embodiment of the present application. The interface may include keywords (preset fields), minimum number of occurrences (preset rules) and related traversal rules, wherein the example in the diagram shows that for the preset field "finance", the preset rule is that the minimum number of occurrences is 1, and the number of occurrences of "finance" in the body-full text, file name, email title or email body is traversed, and then click Finish to perform the judgment logic of the above data encryption.

[0127] In order to better implement the above solution of the embodiment of the present application, the following also provides related devices for implementing the above solution. Figure 7 , Figure 7 The data encryption device 700 is a schematic diagram of the structure of the data encryption device provided in the embodiment of the present application. The data encryption device 700 includes:

[0128] A configuration unit 701 is used to configure preset encryption information, wherein the encryption information includes a preset field and a preset rule, and the preset rule is set based on the encryption level of the preset field;

[0129] A traversal unit 702 is used to traverse the target data according to the preset field to obtain identification information, wherein the target data is used to indicate data for performing a preset operation by a user within a preset time period, and the identification information is used to indicate the occurrence of the preset field in the target data;

[0130] The encryption unit 703 is used to determine the preset rule corresponding to the preset field according to the identification information, so as to encrypt the target data.

[0131] Preferably, in some possible implementations of the present application,

[0132] The traversal unit 702 is specifically used to determine the identification information of the target data, where the identification information includes the data type of the target data;

[0133] The traversal unit 702 is specifically used to match the preset field with the data type of the target data according to a preset algorithm, wherein the preset algorithm is used to convert the data type of the target data into the data type corresponding to the preset field;

[0134] The traversal unit 702 is specifically configured to traverse the matched target data according to the preset fields.

[0135] Preferably, in some possible implementations of the present application, the identification information further includes a traversal rule.

[0136] The traversal unit 702 is specifically configured to determine a traversal rule corresponding to the target data according to the identification information, wherein the traversal rule includes a traversal direction, a traversal order or a traversal position;

[0137] The traversal unit 702 is specifically configured to traverse the preset fields in the matched target data according to the traversal rule.

[0138] Preferably, in some possible implementations of the present application,

[0139] The traversal unit 702 is specifically used to obtain the user's operation instructions on the target data within a preset time period;

[0140] The traversal unit 702 is specifically configured to traverse the target data according to the preset fields if the operation instruction meets the preset conditions.

[0141] Preferably, in some possible implementations of the present application, the preset time period includes a first moment and a second moment, and the traversal unit 702 is specifically used to obtain the operation frequency of the user at the first moment;

[0142] The traversal unit 702 is specifically configured to obtain the user's operation instructions for the target data within a preset time period according to the difference between the user's operation frequency at the second moment and the operation frequency at the first moment if the difference satisfies the start traversal condition.

[0143] Preferably, in some possible implementations of the present application, it is characterized in that:

[0144] The encryption unit 703 is specifically configured to determine the encryption level of the preset field according to the identification information;

[0145] The encryption unit 703 is specifically configured to determine the preset rule according to the encryption level;

[0146] The encryption unit 703 is specifically configured to encrypt the target data according to the preset rule.

[0147] Preferably, in some possible implementations of the present application,

[0148] The encryption unit 703 is further used to record the corresponding relationship between the preset field and the encryption level, and the corresponding relationship is used to update the encryption level when the preset field appears again.

[0149] By configuring preset encryption information, the encryption information includes preset fields and preset rules, and the preset rules are set based on the encryption level of the preset fields; then traversing the target data according to the preset fields to obtain identification information, the target data is used to indicate the data for the user to perform preset operations within a preset time period, and the identification information is used to indicate the appearance of the preset fields in the target data; finally, the preset rules corresponding to the preset fields are determined according to the identification information to encrypt the target data. Due to the controllability of the configuration process, the flexibility of the encryption process is improved; and encryption judgment of data is performed according to the preset fields, which avoids the occurrence of data encryption omission or wrong encryption in the case of large amounts of data, and improves the accuracy of the encryption process; in addition, according to different encryption levels corresponding to different identification information, the accuracy of data encryption is further improved and has a wide range of applications.

[0150] The present application also provides a data encryption device. Figure 8 , Figure 8 8 is a schematic diagram of the structure of another data encryption device provided in an embodiment of the present application. The data encryption device 800 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPU) 822 (for example, one or more processors) and a memory 832, and one or more storage media 830 (for example, one or more mass storage devices) storing application programs 842 or data 844. Among them, the memory 832 and the storage medium 830 may be temporary storage or permanent storage. The program stored in the storage medium 830 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations in the data encryption device. Furthermore, the central processing unit 822 may be configured to communicate with the storage medium 830 to execute a series of instruction operations in the storage medium 830 on the data encryption device 800.

[0151] The data encryption device 800 may also include one or more power supplies 826, one or more wired or wireless network interfaces 850, one or more input and output interfaces 858, and / or one or more operating systems 841, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0152] The steps performed by the data encryption device in the above embodiment can be based on the Figure 8 The data encryption device structure shown.

[0153] The present application also provides a computer-readable storage medium in which data encryption instructions are stored. When the computer-readable storage medium is run on a computer, the computer executes the above-mentioned Figures 2 to 6 The illustrated embodiment describes the steps performed by the data encryption device in the method.

[0154] The present application also provides a computer program product including data encryption instructions, which, when executed on a computer, enables the computer to execute the above-mentioned Figures 2 to 6 The illustrated embodiment describes the steps performed by the data encryption device in the method.

[0155] The present application also provides a data encryption system, which may include: Figure 7 The data encryption device in the described embodiment, or Figure 8 A data encryption device is described.

[0156] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0157] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0158] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0159] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0160] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a data encryption device, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.

[0161] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A data encryption method based on data content, characterized in that: include: Configuring preset encryption information, the encryption information includes preset fields and preset rules, the preset rules are set based on the encryption level of the preset fields, including: the web page configures the preset fields and preset rules, packages the preset rules and preset fields, and the correspondence between the two to determine the encryption information, the web page sends the encrypted information to the client, and the client sends the encrypted information to the application, the preset rules include the minimum number of occurrences of the preset field in at least two types of content in the full text of the body, the file name, the email title or the email body; The application end determines the interface API of the target data, adds the preset field, matches the preset field to the target data editing path, the client scans the target data path, and the client monitors the editing process of the target data. The preset time period includes a first moment and a second moment, and the user's operation frequency at the first moment is obtained; if the difference between the user's operation frequency at the second moment and the operation frequency at the first moment meets the start traversal condition, the target data is traversed according to the preset field to obtain identification information, the target data is used to indicate the data of the user's preset operation within the preset time period, and the identification information is used to indicate the appearance of the preset field in the target data; The target data is encrypted according to the identification information and the preset rules corresponding to the preset fields.

2. The method according to claim 1, characterized in that The traversing the target data according to the preset field includes: Determine identification information of the target data, where the identification information includes a data type of the target data; Matching the preset field with the data type of the target data according to a preset algorithm, wherein the preset algorithm is used to convert the data type of the target data into the data type corresponding to the preset field; The matched target data is traversed according to the preset fields.

3. The method according to claim 2, characterized in that The identification information also includes a traversal rule, and the traversal of the matched target data according to the preset field includes: Determine a traversal rule corresponding to the target data according to the identification information, wherein the traversal rule includes a traversal direction, a traversal order or a traversal position; The preset fields are traversed in the target data after matching according to the traversal rule.

4. The method according to claim 1, characterized in that: The traversing the target data according to the preset field includes: Obtaining the user's operation instructions on the target data within a preset time period; If the operation instruction meets the preset condition, the target data is traversed according to the preset field.

5. The method according to claim 4, characterized in that The preset time period includes a first moment and a second moment, and obtaining the user's operation instruction for the target data within the preset time period includes: Acquire the operation frequency of the user at the first moment; If the difference between the operation frequency of the user at the second moment and the operation frequency of the first moment meets the start traversal condition, the operation instruction of the user on the target data within a preset time period is obtained according to the difference.

6. The method according to claim 1, characterized in that The method further comprises: The correspondence between the preset field and the encryption level is recorded, and the correspondence is used to update the encryption level when the preset field appears again.

7. A data encryption device based on data content, characterized in that: include: A configuration unit, configured to configure preset encryption information, the encryption information includes preset fields and preset rules, the preset rules are set based on the encryption level of the preset fields, including: the web page configures the preset fields and the preset rules, packages the preset rules and the preset fields, and the correspondence between the two to determine the encryption information, the web page sends the encrypted information to the client, and the client sends the encrypted information to the application, the preset rules include the minimum number of occurrences of the preset field in at least two types of content in the full text of the body, the file name, the email title or the email body; A traversal unit, used for the application end to determine the interface API of the target data, add the preset field, match the preset field to the target data editing path, the client scans the target data path, the client monitors the editing process of the target data, the preset time period includes a first moment and a second moment, and the user's operation frequency at the first moment is obtained; if the difference between the user's operation frequency at the second moment and the operation frequency at the first moment meets the start traversal condition, the target data is traversed according to the preset field to obtain identification information, the target data is used to indicate the data of the user's preset operation within the preset time period, and the identification information is used to indicate the appearance of the preset field in the target data; The encryption unit is used to encrypt the target data according to the preset rules corresponding to the identification information and the preset fields.

8. A computer device, characterized in that: The computer device comprises a processor and a memory: The memory is used to store program codes; the processor is used to execute the data encryption method according to any one of claims 1 to 6 according to instructions in the program codes.

9. A computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium, and when the computer-readable storage medium is executed on a computer, the computer executes the data encryption method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Improved large file encryption method

    CN107135062A