File security processing method, device, equipment and storage medium

By automatically detecting user requests and determining the encryption and decryption strategy based on file feature types, the problems of low file security and low processing efficiency in the prior art are solved, and efficient and automated file security processing is achieved.

CN112329036BActive Publication Date: 2025-05-30PING AN TRUST CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202011213045.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-03
Publication Date
2025-05-30
Estimated Expiration
2040-11-03

AI Technical Summary

Technical Problem

In the information security work of enterprises, the existing technology relies on personnel to actively set password encryption, resulting in low file security and low processing efficiency.

Method used

By detecting the user's business request, recalling the pending internal files, extracting key features of the file, determining the file feature type, determining the encryption and decryption strategy based on the feature type, and automatically performing file security processing.

Benefits of technology

Improve file security and security processing efficiency, reduce human errors, and realize automated file encryption and decryption processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112329036B_ABST
    Figure CN112329036B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of Internet technologies, and discloses a method, apparatus, device and storage medium for file security processing. The method includes: when detecting a service request sent by a user through a service system, retrieving a corresponding internal file to be processed according to the service request instruction; extracting multiple file key features from the internal file to be processed, and determining a file feature type corresponding to the internal file to be processed according to the multiple file key features; determining an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and performing security processing on the internal file to be processed according to the encryption / decryption policy. Since there is no need for manual encryption of files by setting passwords, only the encryption / decryption policy needs to be determined according to the file type, and then the files are automatically subjected to security processing according to the encryption / decryption type, thereby improving the security of the files and the efficiency of file security processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technologies, and in particular, to a method, apparatus, device, and storage medium for file security processing. Background Art

[0002] Enterprise information data is intangible assets, and leakage will cause loss of benefits. Enterprises generally perform some information security controls, such as blocking optical drives, floppy drives, and USB external transfer interfaces, but still cannot stop information leakage. In the process of carrying out enterprise information security work, the most common disposal method is to set passwords for sensitive files, and when accessing these files, passwords are required for access. However, the biggest drawback is that it relies on the initiative of personnel to encrypt actively and consciously. This will result in low file security and reduce the efficiency of file security processing.

[0003] The above content is only used to assist in understanding the technical solution of the present invention, and does not represent an admission that the above content is prior art. Summary of the Invention

[0004] The main object of the present invention is to provide a method, apparatus, device, and storage medium for file security processing, aiming to solve the technical problem of how to improve the security of files and thus improve the efficiency of file security processing.

[0005] To achieve the above object, the present invention provides a method for file security processing, and the method for file security processing includes:

[0006] When detecting a service request sent by a user through a service system, retrieving a corresponding internal file to be processed according to the service request;

[0007] Extracting multiple file key features from the internal file to be processed, and determining a file feature type corresponding to the internal file to be processed according to the multiple file key features;

[0008] Determining an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and performing security processing on the internal file to be processed according to the encryption / decryption policy.

[0009] Optionally, before the step of retrieving a corresponding internal file to be processed according to the service request when detecting a service request sent by a user through a service system, the method further includes:

[0010] Monitoring an interaction interface in the service system, and determining whether there is a cursor sliding operation in the interaction interface according to a monitoring result;

[0011] If there is the cursor sliding operation, generating a cursor sliding trajectory according to the cursor sliding operation;

[0012] Determine the starting coordinates and ending coordinates according to the cursor sliding trajectory, and determine whether the starting coordinates and the ending coordinates are the same;

[0013] When the starting coordinates and the ending coordinates are not the same, determine the cursor trigger area according to the cursor sliding trajectory and the ending coordinates, and detect the detection service request triggered based on the cursor trigger area.

[0014] Optionally, after the step of monitoring the interaction interface in the business system and determining whether there is a cursor sliding operation according to the monitoring result, the following steps are further included:

[0015] If there is no such cursor sliding operation, obtain the file storage path corresponding to the internal file to be processed;

[0016] Generate a service request according to the file storage path.

[0017] Optionally, the step of determining the file feature type corresponding to the internal file to be processed according to multiple file key features includes:

[0018] Respectively determine the feature index values corresponding to multiple file key features to obtain all feature index values;

[0019] Select the target key feature corresponding to the maximum feature index value from all feature index values;

[0020] Determine the file feature type corresponding to the internal file to be processed according to the target key feature.

[0021] Optionally, the step of determining the file feature type corresponding to the internal file to be processed according to the target key feature includes:

[0022] Input the target key feature into the feature classification model to obtain the feature type matching degree and the sample feature type corresponding to the feature type matching degree;

[0023] Determine whether the feature type matching degree is greater than a preset matching threshold;

[0024] When the feature type matching degree is greater than the preset matching threshold, use the sample feature type as the file feature type corresponding to the internal file to be processed.

[0025] Optionally, the step of performing security processing on the internal file to be processed according to the encryption and decryption policy includes:

[0026] Obtain the current encryption and decryption state of the internal file to be processed;

[0027] When the current encryption / decryption state is the encryption state, detect whether the user's current operation triggers a file decryption instruction;

[0028] When the user's current operation triggers the file decryption instruction, perform abnormal behavior detection on the user's current operation;

[0029] Judge whether to send the internal file to be processed to an external system according to the abnormal behavior detection result;

[0030] If the internal file to be processed is sent to an external system, perform marking processing on the internal file to be processed according to the file decryption instruction and the encryption / decryption policy to obtain an externally marked file, and send the externally marked file to the external system.

[0031] Optionally, the step of performing marking processing on the internal file to be processed according to the file decryption instruction and the encryption / decryption policy to obtain an externally marked file includes:

[0032] Obtain the identity information of the user;

[0033] Perform instruction response review on the file decryption instruction according to the identity information and obtain the review result;

[0034] When the review result meets the preset verification conditions, obtain the review time corresponding to the internal file to be processed;

[0035] Generate an operation and maintenance log according to the review time, the identity information and the internal file to be processed, and perform marking processing on the internal file to be processed according to the file decryption instruction and the encryption / decryption policy to obtain an externally marked file.

[0036] In addition, to achieve the above object, the present invention also proposes a file security processing device, and the file security processing device includes:

[0037] A receiving module, configured to retrieve a corresponding internal file to be processed according to the service request when detecting a service request sent by a user through a service system;

[0038] A determining module, configured to extract multiple file key features from the internal file to be processed, and determine the file feature type corresponding to the internal file to be processed according to the multiple file key features;

[0039] A processing module, configured to determine an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and perform security processing on the internal file to be processed according to the encryption / decryption policy.

[0040] In addition, to achieve the above object, the present invention further provides a file security processing device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the file security processing method as described above.

[0041] In addition, to achieve the above object, the present invention further provides a computer storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the file security processing method as described above are implemented.

[0042] First, when the present invention detects a service request sent by a user through a service system, it retrieves a corresponding internal file to be processed according to the service request instruction, then extracts multiple file key features from the internal file to be processed, determines the file feature type corresponding to the internal file to be processed according to the multiple file key features, and then determines an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and performs security processing on the internal file to be processed according to the encryption / decryption policy. Since there is no need for manual encryption of files by setting passwords, the present invention only needs to determine the encryption / decryption policy according to the file type, and then automatically performs security processing on the file according to the encryption / decryption type, thereby improving the security of the file and the efficiency of file security processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 is a schematic structural diagram of a file security processing device in a hardware operating environment related to the solution of an embodiment of the present invention;

[0044] Figure 2 is a schematic flowchart of a first embodiment of the file security processing method of the present invention;

[0045] Figure 3 is a schematic flowchart of a second embodiment of the file security processing method of the present invention;

[0046] Figure 4 is a structural block diagram of a first embodiment of the file security processing device of the present invention.

[0047] The realization, functional features, and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0049] Referring to Figure 1 , Figure 1 is a schematic structural diagram of a file security processing device in a hardware operating environment related to the solution of an embodiment of the present invention.

[0050] AsFigure 1 As shown in the figure, the file security processing device may include: a processor 1001, such as a Central Processing Unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to implement connection communication between these components. The user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). Optionally, the user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wireless-Fidelity (WI-FI) interface). The memory 1005 may be a high-speed Random Access Memory (RAM) or a stable Non-Volatile Memory (NVM), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0051] Those skilled in the art can understand that Figure 1 the structure shown in the figure does not constitute a limitation on the file security processing device, and it may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.

[0052] As Figure 1 shown, the memory 1005, as a storage medium, may include an operating system, a data storage module, a network communication module, a user interface module, and a computer program.

[0053] In Figure 1 the file security processing device shown in the figure, the network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with a user; the processor 1001 and the memory 1005 in the file security processing device of the present invention may be provided in the file security processing device. The file security processing device calls the computer program stored in the memory 1005 through the processor 1001 and executes the file security processing method provided in the embodiment of the present invention.

[0054] The embodiment of the present invention provides a file security processing method. Referring to Figure 2 , Figure 2 it is a schematic flowchart of the first embodiment of the file security processing method of the present invention.

[0055] In this embodiment, the file security processing method includes the following steps:

[0056] Step S10: When detecting a service request sent by a user through a service system, retrieve the corresponding internal file to be processed according to the service request.

[0057] It is easy to understand that the execution subject of this embodiment can be a file security processing device with functions such as data processing, network communication, and program operation, or other computer devices with similar functions. This embodiment does not impose any restrictions. In this embodiment, the file security processing device can be an operation and maintenance end that can receive service requests and detect and process service requests.

[0058] It can be understood that the internal file to be processed can be one or more files selected by the user from the service system. Among them, multiple internal files and the like can be stored in the service system.

[0059] In a specific implementation, the operation and maintenance end can perform request analysis according to the received service request to obtain the corresponding file identifier. Then, the operation and maintenance end can find the corresponding internal file according to the file identifier and use the internal file as the internal file to be processed corresponding to the service request. The file identifier can be file naming or file storage size, etc. This embodiment does not impose any restrictions. Among them, the service request can be a file retrieval instruction sent by the user through the service system or a file sending instruction, etc. This embodiment does not impose any restrictions.

[0060] Further, in order to more accurately determine the service request, before detecting the service request, it is also necessary to monitor the interaction interface in the service system and judge whether there is a cursor sliding operation in the interaction interface according to the monitoring result. When a cursor sliding operation is monitored in the interaction interface, generate a cursor sliding trajectory according to the cursor sliding operation, and determine the starting coordinate and the ending coordinate according to the cursor sliding trajectory. Judge whether the starting coordinate and the ending coordinate are consistent. When the starting coordinate and the ending coordinate are inconsistent, determine the cursor trigger area according to the cursor sliding trajectory and the ending coordinate, and detect the detected service request triggered based on the cursor trigger area.

[0061] It should be understood that the operation and maintenance end can also monitor the operation process of the user clicking on a certain internal file in the service system in real time.

[0062] When the user uses the mouse, the operation and maintenance terminal can receive the cursor trajectory operations generated by the mouse. The operation and maintenance terminal will also obtain the corresponding cursor position in real time when the mouse slides, generate a cursor sliding trajectory based on the moving cursor position, and determine the starting coordinates corresponding to the cursor sliding trajectory and the ending coordinates corresponding to the cursor sliding trajectory. It will judge whether the starting coordinates and the ending coordinates are the same. When the starting coordinates and the ending coordinates are not the same, it will determine the cursor trigger area based on the cursor sliding trajectory and the ending coordinates. Then, it is necessary to judge whether the cursor trigger area corresponding to the ending coordinates can normally click the mouse. When it can normally click the mouse and corresponding operations occur, it will detect the detection service request triggered by the cursor trigger area. When it detects the service request sent by the user through the service system, it will retrieve the corresponding pending internal file in the service system according to the service request.

[0063] Considering the actual application, there may be a situation where the starting coordinates and the ending coordinates of the cursor are the same. When the operation and maintenance terminal detects that the starting coordinates and the ending coordinates are the same, it is necessary to determine the cursor trigger area based on the cursor sliding trajectory and the ending coordinates, and it is also necessary to judge whether the current cursor trigger area can normally click the mouse and corresponding operations occur. When the current cursor trigger area can normally click the mouse and corresponding operations occur, it will select the corresponding pending internal file in the corresponding cursor trigger area in the service system for open status or closed status, etc. Among them, the pending internal file can be one or more files that the user needs to select in the service system, etc.

[0064] Furthermore, when the operation and maintenance terminal does not monitor the cursor sliding operation in the interaction interface corresponding to the service system, it can also determine the service request according to the storage path of the files pre-stored in the service system. That is to say, it can generate a corresponding service request by obtaining the file storage path corresponding to the pending internal file. Then, the operation and maintenance terminal can generate a corresponding service request according to the file storage path.

[0065] It can be understood that the file storage path can be D:\wenjian files\September\New Application, or it can be C:\Program Files(x86), etc. After the operation and maintenance terminal receives the service request, it can obtain the corresponding pending internal file according to the instruction file storage path D:\wenjian files\September\New Application, or it can obtain the corresponding pending internal file according to the instruction file storage path C:\Program Files(x86), etc. This embodiment does not impose any restrictions.

[0066] It should be noted that there may be multiple internal files in the service system, and the operation and maintenance terminal selects the single or multiple pending internal files required by the user from multiple internal files according to the service request.

[0067] When the operation and maintenance terminal monitors a cursor sliding operation in the interaction interface corresponding to the business system, it can directly obtain the corresponding internal file to be processed according to the cursor-triggered operation. When the operation and maintenance terminal does not monitor a cursor sliding operation in the interaction interface corresponding to the business system, the user can directly input the storage path command corresponding to the internal file to be processed in the interaction interface corresponding to the business system, and the operation and maintenance terminal directly obtains the corresponding internal file to be processed according to the storage path command corresponding to the internal file to be processed, etc.

[0068] Step S20: Extract multiple file key features from the internal file to be processed, and determine the file feature type corresponding to the internal file to be processed according to the multiple file key features.

[0069] It can be understood that the step of extracting multiple file key features from the internal file to be processed can be that the operation and maintenance terminal can select keywords with a relatively high number of occurrences, that is, keywords exceeding the preset occurrence threshold, from the internal file to be processed. Then, the operation and maintenance terminal can determine the corresponding key features according to these keywords. Among them, the file key feature is the key feature corresponding to the internal file to be processed, which can be a food text feature or an entertainment data feature, etc.

[0070] Among them, the file feature type is the feature type corresponding to the file to be processed, which can be a food type or an entertainment text type, etc. This embodiment does not impose any restrictions.

[0071] Suppose the number of occurrences of keywords such as "food", "cooking", and "delicious" in the internal file to be processed is 8 times each, and the preset occurrence threshold is 7 times. Then, the number of occurrences of "food", "cooking", and "delicious" is 8 times each, all of which are greater than the preset occurrence threshold of 7 times. It is determined that the type of the internal file to be processed is a food text feature. Suppose the number of occurrences of keywords such as "entertainment", "star", and "red carpet" in the internal file to be processed is 6 times each, and the preset occurrence threshold is 5 times. Then, the number of occurrences of "entertainment", "star", and "red carpet" is 6 times each, all of which are greater than the preset occurrence threshold of 5 times. It is determined that the type of the internal file to be processed is an entertainment text feature, etc. This example does not impose any restrictions.

[0072] It should be noted that before the operation and maintenance end extracts multiple file key features from the internal file to be processed, it is also necessary to verify the retrieved internal file to be processed. Among them, the specific implementation method of the verification can be to obtain the key features corresponding to multiple internal files in the business system. The key features are single or multiple keywords corresponding to each internal file, etc. Then, the key features of the internal file to be processed are input into the trained convolutional neural network. When the key features of the file to be processed are multiple keywords, the multiple keywords can be fused to obtain the target keyword, that is, the target key feature. Then, the target key feature is compared with the key features corresponding to the internal file one by one. According to the comparison results, multiple internal files to be processed can be selected, or it can be a single internal file to be processed. When multiple internal files to be processed are selected, the user can select the internal file to be processed that he needs from the multiple internal files to be processed, and use the selected internal file to be processed as the internal file to be processed corresponding to the business request, etc. This embodiment is not limited.

[0073] Further, the step of determining the file feature type corresponding to the internal file to be processed according to multiple file key features can be to extract multiple file key features from the internal file to be processed, respectively determine multiple feature index values corresponding to the multiple key features, sort the multiple feature index values to obtain a feature sorting result, and determine the file feature type corresponding to the internal file to be processed according to the feature sorting result. Among them, the step of extracting multiple file key features from the internal file to be processed can be to input the internal file to be processed into a preset feature extraction model to obtain single or multiple file key features. The preset feature extraction model is obtained by training a large number of sample files and sample key features in a convolutional neural network in advance, and then obtaining the trained preset feature extraction model.

[0074] It can be understood that each key feature will have a corresponding feature index value. The feature index value can be the proportional content corresponding to the key feature in the internal file to be processed, which can be 50%, or 70%, etc. Among them, the feature index values corresponding to each key feature in the internal file to be processed may be different or the same.

[0075] In practical applications, the operation and maintenance end can sort the feature index values of the key features from large to small, select the largest feature index value from the sorting results, and then determine the corresponding file feature type according to the largest feature index value. Among them, the larger the feature index value, the greater the proportion of the corresponding feature in the internal file to be processed. On the contrary, the smaller the feature index value, the smaller the proportion of the feature in the internal file to be processed.

[0076] Further, in order to verify the file feature type, the operation and maintenance terminal can input the key feature with the largest feature index value into the feature classification model to obtain the feature type matching degree and the sample feature type corresponding to the feature type matching degree, and determine whether the feature type matching degree is greater than the preset matching threshold. When the feature type matching degree is greater than the preset matching threshold, the sample feature type is used as the file feature type corresponding to the internal file to be processed. Among them, the feature type matching degree can be 80%, or 90%, etc. The sample feature type can be the food type, or the entertainment type, etc. The preset matching threshold can be user-defined, and can be 70%, or 80%, etc. This embodiment does not impose any restrictions.

[0077] It can be understood that the feature classification model is trained through multiple key features and multiple standard feature types. In actual application, inputting the key feature type into the feature classification model can obtain the corresponding feature matching degree and the result of the type to be determined. The feature classification model can also output the result of the type to be determined corresponding to the feature matching degree.

[0078] Suppose the feature matching degree is 89% and the preset matching threshold is 90%. Then the feature matching degree is less than the preset matching threshold, and it is necessary to re-extract the corresponding multiple key features in the internal file to be processed. Suppose the feature type matching degree corresponding to the internal file to be processed is 80%, the sample feature type corresponding to the feature type matching degree of 80% is the food type, the preset matching threshold is 70%, and the feature type matching degree of 80% is greater than the preset matching threshold of 70%. Then the sample feature type - food type is used as the file feature type corresponding to the internal file to be processed, etc. This embodiment does not impose any restrictions.

[0079] Step S30: Determine the encryption and decryption policy according to the file feature type corresponding to the internal file to be processed, and perform security processing on the internal file to be processed according to the encryption and decryption policy.

[0080] It should be noted that the encryption and decryption policy can be user-defined, and can be set as a simple encryption policy, a simple decryption policy, or a marked encryption policy, a marked decryption policy, etc. Among them, the simple encryption policy is to perform explicit security control on the file, such as adding watermarks or identifiers, etc. The marked encryption policy is implicit security control, such as marking identity information and viewing time marks in the file data packet, etc. This embodiment does not impose any restrictions.

[0081] Further, the method of determining the encryption and decryption policy according to the file feature type corresponding to the internal file to be processed can be understood as that there is a one-to-one mapping relationship or a one-to-many mapping relationship between the file feature type and the encryption and decryption policy in the mapping relationship table. Furthermore, the corresponding encryption and decryption policy can be found according to the file feature type. Among them, the mapping relationship table is constructed according to multiple file feature types and multiple encryption and decryption policies.

[0082] In this embodiment, assuming that the file feature type is a food feature, the corresponding encryption and decryption policies can be a simple encryption policy or a simple decryption policy. Assuming that the file feature type is an entertainment feature, the corresponding encryption and decryption policies can be a tagged encryption policy or a tagged decryption policy, etc., and this embodiment does not impose any restrictions.

[0083] Among them, the encryption and decryption policies need to be determined not only according to the file feature type of the internal file to be processed, but also according to the current state of the internal file to be processed to further determine the corresponding encryption policy or decryption policy, etc., and this embodiment does not impose any restrictions.

[0084] It can be understood that if the current usage state of the internal file to be processed is an unencrypted state, the internal file to be processed is encrypted according to the encryption and decryption policy. That is, when the current usage state of the internal file to be processed is unencrypted and the user needs to view the file, the corresponding encryption and decryption policy is found according to the type of the file, so that the encryption and decryption program automatically encrypts the file according to the encryption and decryption policy (background silent encryption, the user is unaware), and at the same time does not hinder the normal operation and use of the application program. When it is detected that the user opens an encrypted file, the encryption and decryption program automatically decrypts the file (background silent decryption, the user is unaware), and at the same time does not hinder the normal operation and use of the application program. At the same time, a policy can also be set to regularly scan the files in the client and automatically execute the encryption action on the unencrypted files without affecting the normal operation of the application program, etc., and this embodiment does not impose any restrictions.

[0085] In this embodiment, assuming that the current state of the internal file to be processed is an unencrypted state, the corresponding encryption and decryption policy - simple encryption policy is selected according to the file feature type - food type, and the internal file to be processed is encrypted according to the simple encryption policy; assuming that the current state of the internal file to be processed is an encrypted state and the file feature type of the internal file to be processed is a food type, the corresponding encryption and decryption policy - simple decryption policy is selected according to the file feature type - food type, and the internal file to be processed is decrypted according to the simple decryption policy; assuming that the current state of the internal file to be processed is an unencrypted state and the file feature type of the internal file to be processed is an entertainment type, the corresponding encryption and decryption policy - tagged encryption policy is selected according to the file feature type - entertainment type, and the internal file to be processed is encrypted according to the tagged encryption policy, etc., and this embodiment does not impose any restrictions.

[0086] In this embodiment, when a service request sent by a user through a service system is detected first, the corresponding internal file to be processed is retrieved according to the service request instruction. Then, multiple file key features are extracted from the internal file to be processed, and the file feature type corresponding to the internal file to be processed is determined according to the multiple file key features. After that, an encryption / decryption policy is determined according to the file feature type corresponding to the internal file to be processed, and the internal file to be processed is securely processed according to the encryption / decryption policy. Since there is no need for manual encryption of files by setting passwords, in this embodiment, only the encryption / decryption policy needs to be determined according to the file type, and then the file is automatically and securely processed according to the encryption / decryption type, thereby improving the security of the file and the efficiency of file security processing.

[0087] Reference Figure 3 , Figure 3 is a schematic flowchart of the second embodiment of the file security processing method of the present invention.

[0088] Based on the above first embodiment, in this embodiment, step S30 further includes:

[0089] Step S301: Determine an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and obtain the current encryption / decryption state of the internal file to be processed.

[0090] It can be understood that different file feature types corresponding to the internal file to be processed have different corresponding encryption / decryption policies.

[0091] According to the file feature type corresponding to the internal file to be processed, the corresponding encryption / decryption policy can be found from the encryption / decryption mapping relationship table. The relationship between the file feature type and the encryption / decryption policy in the encryption / decryption mapping relationship table can be a one-to-one relationship, or a many-to-one relationship, etc., which is not limited in this embodiment.

[0092] In this embodiment, assuming that the file feature type is the food type, the encryption / decryption policy corresponding to the food type in the encryption / decryption mapping relationship table can be a simple encryption / decryption policy, or a marked encryption / decryption policy, etc., which is not limited in this embodiment.

[0093] Step S302: When the current encryption / decryption state is the encryption state, detect whether the current operation of the user triggers a file decryption instruction.

[0094] It should be noted that the file decryption instruction is a file decryption request for the user to open the internal file to be processed.

[0095] Among them, the current operation triggering the file decryption instruction can be triggering the file decryption instruction through the cursor, or triggering the file decryption instruction by inputting a command, etc., which is not limited in this embodiment.

[0096] Step S303: When the current operation of the user triggers the file decryption instruction, perform abnormal behavior detection on the current operation of the user.

[0097] The abnormal behavior detection can set the mouse click operation when sending to an external system for the user, or can be a special command input operation for the user, etc. When the current operation of the user triggers the file decryption instruction, it can be determined whether the user is viewing the file normally or needs to send the file to the outside according to the number of times the user clicks the mouse or enters a special command.

[0098] When the user clicks to view the file, the operation and maintenance terminal also needs to further check whether there is any abnormal behavior in the current operation of the user according to the number of times the mouse is clicked or the special instruction received.

[0099] Step S304: Determine whether to send the internal file to be processed to an external system according to the abnormal behavior detection result.

[0100] The external system can be a mobile terminal or a third-party system, etc., and this embodiment does not limit it.

[0101] In practical applications, assume that when the user is viewing the file normally, after viewing the file, the operation and maintenance terminal determines whether the user clicks the mouse multiple times or enters a special command. If 1 mouse click can be understood as closing the file, and when the mouse is clicked continuously 3 times, it proves that the user needs to send the file to an external system. Among them, multiple clicks or entering special commands can be set by the user, and this embodiment does not limit it.

[0102] Step S305: If the internal file to be processed is sent to an external system, perform marking processing on the internal file to be processed according to the file decryption instruction and the encryption and decryption policy to obtain an externally marked file, and send the externally marked file to the external system.

[0103] It should be noted that the operation and maintenance terminal can also perform encryption and decryption operations on the internal file to be processed, perform encryption and decryption control on the externally transmitted file, and control the external transmission of the file, etc.

[0104] It can be understood that the encryption and decryption policy can be set by the user, can be a simple encryption and decryption policy, can also be a marked encryption and decryption policy and an important encryption and decryption policy, etc. Among them, the simple encryption and decryption policy can be the company mark and the document date file marking process, the marked encryption and decryption policy can be the company mark, the document date and the document sender name file marking process, the important encryption and decryption policy can be the company mark, the document date, the document sender name and the recipient name file marking process, etc., and this embodiment does not limit it.

[0105] It should be noted that the steps of marking the internal file to be processed according to the file decryption instruction and the encryption and decryption strategy to obtain the external marked file can be to obtain the user's identity information, and to review the instruction response to the file decryption instruction according to the identity information. That is to say, the operation and maintenance end can determine whether the user is qualified to send the file decryption instruction according to the user's identity information, and obtain the review result when the user is qualified to send the file decryption instruction. When the review result meets the preset verification condition, the review time corresponding to the internal file to be processed is obtained, and the operation and maintenance log is generated according to the review time, the identity information and the internal file to be processed, and the internal file to be processed is marked according to the file decryption instruction and the encryption and decryption strategy to obtain the external marked file. Among them, the preset verification condition can be understood as the user's identity information having the qualification to send the file decryption instruction. The user's identity information can be the user's employee number and name, etc., which is not limited in this embodiment.

[0106] Assuming that the type of the internal file to be processed is a food type, the encryption and decryption strategy for the food type can be a simple encryption and decryption strategy, that is, the company mark and the date of issue are processed for the internal file to be processed according to the file decryption instruction and the simple encryption and decryption strategy, and then the external mark file is obtained and sent to the external system, that is, the decrypted file can be transmitted externally and used normally by an external computer or terminal device. If the file is transmitted externally without passing the decryption strategy of the operation and maintenance end, the external terminal will not be able to view and use it normally, and when the decryption is successful, the operation and maintenance end will record the person requesting decryption and the file requested to be decrypted to form an operation and maintenance log for audit and reference, etc., and this embodiment does not limit it.

[0107] In this embodiment, the encryption and decryption strategy is first determined according to the file feature type corresponding to the internal file to be processed, and the current encryption and decryption status of the internal file to be processed is obtained. When the current encryption and decryption status is the encryption state, it is detected whether the user's current operation triggers the file decryption instruction. When the user's current operation triggers the file decryption instruction, the user's current operation is detected for abnormal behavior, and according to the abnormal behavior detection result, it is determined whether to send the internal file to be processed to the external system. If the internal file to be processed is sent to the external system, the internal file to be processed is marked according to the file decryption instruction and the encryption and decryption strategy to obtain an external marked file, and the external marked file is sent to the external system. Compared with the prior art, it is still necessary to manually label the files for marking, while in this implementation, the internal file to be processed is marked according to the file decryption instruction and the encryption and decryption strategy to obtain an external marked file, thereby improving file processing efficiency and user experience, and further ensuring the security of transmitted files.

[0108] Reference Figure 4 , Figure 4This is the structural block diagram of the first embodiment of the file security processing device of the present invention.

[0109] As Figure 4 shown, the file security processing device proposed in the embodiment of the present invention includes:

[0110] A receiving module 4001, configured to, when detecting a service request sent by a user through a service system, retrieve a corresponding internal file to be processed according to the service request instruction;

[0111] A determining module 4002, configured to extract multiple file key features from the internal file to be processed, and determine the file feature type corresponding to the internal file to be processed according to the multiple file key features;

[0112] A processing module 4003, configured to determine an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and perform security processing on the internal file to be processed according to the encryption / decryption policy.

[0113] In this embodiment, first, when detecting a service request sent by a user through a service system, retrieve a corresponding internal file to be processed according to the service request instruction, then extract multiple file key features from the internal file to be processed, determine the file feature type corresponding to the internal file to be processed according to the multiple file key features, then determine an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and perform security processing on the internal file to be processed according to the encryption / decryption policy. Since there is no need for manual encryption of files by setting passwords, this embodiment only needs to determine the encryption / decryption policy according to the file type, and then automatically perform security processing on the file according to the encryption / decryption type, thereby improving the security of the file and the efficiency of file security processing.

[0114] Further, the receiving module 4001 is further configured to monitor an interaction interface in the service system, and determine whether there is a cursor sliding operation in the interaction interface according to the monitoring result;

[0115] The receiving module 4001 is further configured to generate a cursor sliding trajectory according to the cursor sliding operation when there is the cursor sliding operation;

[0116] The receiving module 4001 is further configured to determine a starting coordinate and an ending coordinate according to the cursor sliding trajectory, and determine whether the starting coordinate and the ending coordinate are the same;

[0117] The receiving module 4001 is further configured to, when the starting coordinate and the ending coordinate are not the same, determine a cursor trigger area according to the cursor sliding trajectory and the ending coordinate, and detect a detection service request triggered based on the cursor trigger area.

[0118] Further, the receiving module 4001 is further configured to obtain the file storage path corresponding to the internal file to be processed when there is no cursor sliding operation;

[0119] The receiving module 4001 is further configured to generate a service request according to the file storage path.

[0120] Further, the determining module 4002 is further configured to respectively determine the characteristic index values corresponding to a plurality of the file key characteristics to obtain all the characteristic index values;

[0121] The determining module 4002 is further configured to select the target key characteristic corresponding to the maximum characteristic index value from all the characteristic index values;

[0122] The determining module 4002 is further configured to determine the file characteristic type corresponding to the internal file to be processed according to the target key characteristic.

[0123] Further, the determining module 4002 is further configured to input the target key characteristic into a feature classification model to obtain a feature type matching degree and the sample feature type corresponding to the feature type matching degree;

[0124] The determining module 4002 is further configured to determine whether the feature type matching degree is greater than a preset matching threshold;

[0125] The determining module 4002 is further configured to use the sample feature type as the file characteristic type corresponding to the internal file to be processed when the feature type matching degree is greater than the preset matching threshold.

[0126] Further, the processing module 4003 is further configured to obtain the current encryption and decryption state of the internal file to be processed;

[0127] The processing module 4003 is further configured to detect whether the current user operation triggers a file decryption instruction when the current encryption and decryption state is an encrypted state;

[0128] The processing module 4003 is further configured to perform abnormal behavior detection on the current user operation when the current user operation triggers the file decryption instruction;

[0129] The processing module 4003 is further configured to determine whether to send the internal file to be processed to an external system according to the abnormal behavior detection result;

[0130] The processing module 4003 is further configured to, when sending the internal file to be processed to an external system, perform marking processing on the internal file to be processed according to the file decryption instruction and the encryption and decryption policy to obtain an externally marked file, and send the externally marked file to the external system.

[0131] Further, the processing module 4003 is further configured to obtain the identity information of the user;

[0132] The processing module 4003 is further configured to perform an instruction response review on the file decryption instruction according to the identity information, and obtain a review result;

[0133] The processing module 4003 is further configured to obtain the review time corresponding to the internal file to be processed when the review result meets a preset verification condition;

[0134] The processing module 4003 is further configured to generate an operation and maintenance log according to the review time, the identity information, and the internal file to be processed, and perform a marking process on the internal file to be processed according to the file decryption instruction and the encryption and decryption policy, so as to obtain an externally marked file.

[0135] Other embodiments or specific implementation manners of the file security processing device of the present invention may refer to the above method embodiments, and will not be described herein again.

[0136] It should be noted that in this article, the terms "including", "comprising" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not expressly listed, or elements inherent to such process, method, article or system. Without further limitation, an element defined by the phrase "including a..." does not exclude the existence of additional identical elements in the process, method, article or system including the element.

[0137] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.

[0138] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation manner. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as a read-only memory / random access memory, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0139] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present invention.

Claims

1. A file security processing method, characterized in that, the file security processing method includes: When detecting a service request sent by a user through a service system, retrieving a corresponding internal file to be processed according to the service request; Extracting multiple file key features from the internal file to be processed, and determining the file feature type corresponding to the internal file to be processed according to the multiple file key features; Determining an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and performing security processing on the internal file to be processed according to the encryption / decryption policy; Before the step of retrieving a corresponding internal file to be processed according to the service request when detecting a service request sent by a user through a service system, it further includes: Monitoring an interaction interface in the service system, and judging whether there is a cursor sliding operation in the interaction interface according to the monitoring result; If there is the cursor sliding operation, generating a cursor sliding trajectory according to the cursor sliding operation; Determining a starting coordinate and an ending coordinate according to the cursor sliding trajectory, and judging whether the starting coordinate and the ending coordinate are consistent; When the starting coordinate and the ending coordinate are inconsistent, determining a cursor trigger area according to the cursor sliding trajectory and the ending coordinate, and detecting a detected service request triggered based on the cursor trigger area.

2. The method according to claim 1, characterized in that, After the step of monitoring an interaction interface in the service system and judging whether there is a cursor sliding operation in the interaction interface according to the monitoring result, it further includes: If there is no such cursor sliding operation, obtaining the file storage path corresponding to the internal file to be processed; Generating a service request according to the file storage path.

3. The method according to claim 2, characterized in that, The step of determining the file feature type corresponding to the internal file to be processed according to the multiple file key features includes; Respectively determining the feature index values corresponding to the multiple file key features to obtain all feature index values; Selecting the target key feature corresponding to the maximum feature index value from all the feature index values; Determining the file feature type corresponding to the internal file to be processed according to the target key feature.

4. The method according to claim 3, characterized in that, The step of determining the file feature type corresponding to the internal file to be processed according to the target key feature includes: Inputting the target key feature into a feature classification model to obtain a feature type matching degree and a sample feature type corresponding to the feature type matching degree; Judging whether the feature type matching degree is greater than a preset matching threshold; When the feature type matching degree is greater than the preset matching threshold, using the sample feature type as the file feature type corresponding to the internal file to be processed.

5. The method according to any one of claims 1-4, characterized in that, The step of performing security processing on the internal file to be processed according to the encryption / decryption policy includes: Obtaining the current encryption / decryption state of the internal file to be processed; When the current encryption / decryption state is the encryption state, detect whether the current operation of the user triggers a file decryption instruction; When the current operation of the user triggers the file decryption instruction, perform abnormal behavior detection on the current operation of the user; Judge whether to send the internal file to be processed to an external system according to the abnormal behavior detection result; If the internal file to be processed is sent to an external system, perform marking processing on the internal file to be processed according to the file decryption instruction and the encryption / decryption policy to obtain an externally marked file, and send the externally marked file to the external system.

6. The method according to claim 5, wherein, the step of performing marking processing on the internal file to be processed according to the file decryption instruction and the encryption / decryption policy to obtain an externally marked file includes: obtain the identity information of the user; perform instruction response review on the file decryption instruction according to the identity information and obtain the review result; when the review result meets the preset verification condition, obtain the review time corresponding to the internal file to be processed; generate an operation and maintenance log according to the review time, the identity information and the internal file to be processed, and perform marking processing on the internal file to be processed according to the file decryption instruction and the encryption / decryption policy to obtain an externally marked file.

7. A file security processing device, wherein, the file security processing device includes: a receiving module, configured to, when detecting a service request sent by a user through a service system, retrieve a corresponding internal file to be processed according to the service request instruction; a determining module, configured to extract multiple file key features from the internal file to be processed, and determine the file feature type corresponding to the internal file to be processed according to the multiple file key features; a processing module, configured to determine an encryption / decryption policy according to the file feature type corresponding to the internal file to be processed, and perform security processing on the internal file to be processed according to the encryption / decryption policy; the receiving module is further configured to monitor an interaction interface in the service system, and judge whether there is a cursor sliding operation in the interaction interface according to the monitoring result; the receiving module is further configured to, if there is the cursor sliding operation, generate a cursor sliding trajectory according to the cursor sliding operation; the receiving module is further configured to determine a starting coordinate and an ending coordinate according to the cursor sliding trajectory, and judge whether the starting coordinate and the ending coordinate are the same; the receiving module is further configured to, when the starting coordinate and the ending coordinate are not the same, determine a cursor trigger area according to the cursor sliding trajectory and the ending coordinate, and detect a detection service request triggered based on the cursor trigger area.

8. A file security processing device, wherein, the file security processing device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the computer program is executed by the processor, the steps of the file security processing method according to any one of claims 1 to 6 are implemented.

9. A computer storage medium, wherein, A computer program is stored on the computer storage medium, and when the computer program is executed by a processor, the steps of the file security processing method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Cursor positioning method and apparatus and terminal

    CN105138256A

  • A text classification method based on similarity matching

    CN109033212A

  • File control method and device, electronic equipment and storage medium

    CN111241565A

  • File processing method and device, equipment and storage medium

    CN111339543A