File processing method and device

By setting occlusion files for files and integrating them into encryption keys and ciphertexts, the problem of maliciously obtaining files during storage and transmission is solved, and high security protection of file data is achieved.

CN114546959BActive Publication Date: 2025-05-23GUILIN WEIWANG INTERNET INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210242550.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-11
Publication Date
2025-05-23
Estimated Expiration
2042-03-11

AI Technical Summary

Technical Problem

In the prior art, files are easily maliciously acquired by others during storage and transmission, and there are data security risks when passing passwords.

Method used

Generate the target file by setting up an occlusion file for the original file and integrating it into the file encryption key and the original file ciphertext. Encrypting the file encryption key with a preset key or a preset public key increases the security of file data.

Benefits of technology

It effectively improves the security of file data, increases the difficulty of obtaining original files by others, and prevents the file content from being easily decrypted and obtained.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114546959B_ABST
    Figure CN114546959B_ABST
Patent Text Reader

Abstract

The present invention discloses a file processing method and device, wherein the file processing method comprises: obtaining an original file to be processed; setting a shielding file for the original file; and setting the shielding file on the upper layer of the original file to obtain a target file. According to the technical solution provided by the present invention, the shielding file is used to shield the real file content of the original file, which conveniently ensures the security of file data. If the target file is viewed using the common file viewing method in the prior art without the ability to parse it, then what is viewed is the shielding file set on the upper layer of the original file, and the real file content of the original file cannot be viewed, which increases the difficulty of the original file being obtained by others and effectively improves data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to a file processing method and device. Background Art

[0002] In the prior art, there is a risk that files stored by users in, for example, mobile phones, computers, etc., may be maliciously acquired by others. In addition, when files need to be transferred between users, there is also a risk that files may be maliciously acquired by others. In order to prevent files from being maliciously acquired by others, passwords are usually used to encrypt files. When files need to be transferred to others for use, the set password must be provided to the recipient through verbal notification or other communication methods such as chat tools and emails, so that the recipient can decrypt the received file based on the password and view the content of the file itself. However, whether the password is provided to the recipient through verbal notification or other communication methods, the password can be easily obtained by others, posing a data security risk. Summary of the invention

[0003] In view of the above problems, the present invention is proposed to provide a file processing method, apparatus, computing device and storage medium that overcome the above problems or at least partially solve the above problems.

[0004] According to one aspect of the present invention, there is provided a file processing method, the method comprising:

[0005] Get the original file to be processed;

[0006] Set up a mask file for the original file;

[0007] Set the mask file on top of the original file to get the target file.

[0008] Furthermore, the mask file is set on the upper layer of the original file, and the target file is obtained further including:

[0009] Randomly generate a file encryption key, and use a preset key or a preset public key to encrypt the file encryption key to obtain a key ciphertext;

[0010] Encrypt the original file using the file encryption key to obtain the original file ciphertext;

[0011] The masked file, the key ciphertext and the original file ciphertext are integrated and processed, and the masked file is set on the upper layer of the key ciphertext and the original file ciphertext to obtain the target file.

[0012] Furthermore, there are multiple preset keys or preset public keys, and each preset key or each preset public key has a corresponding key ID;

[0013] Encrypting the file encryption key using a preset key or a preset public key to obtain a key ciphertext further includes:

[0014] For each key ID, the file encryption key is encrypted using a preset key or a preset public key corresponding to the key ID to obtain a key ciphertext corresponding to the key ID.

[0015] Furthermore, the mask file is set on the upper layer of the original file, and the target file is obtained further including:

[0016] Set up file integration template;

[0017] Fill the masked file into the first area of ​​the file integration template, fill the original file or the ciphertext of the original file into the second area of ​​the file integration template, and use the file integration template to set the masked file on the upper layer of the original file or the ciphertext of the original file to obtain the target file;

[0018] Wherein, when there are multiple original files, the original files or the ciphertexts of the original files are filled into the second area of ​​the file integration template in a preset order to obtain a target file; or, when there are multiple original files, each original file or each ciphertext of the original file corresponds to a file integration template, and each file integration template is used to process the corresponding original file or ciphertext of the original file to obtain multiple target files;

[0019] When the second area is filled with the original file ciphertext, the method also includes: filling the key ciphertext into the third area of ​​the file integration template, or filling multiple key IDs and the key ciphertexts corresponding to the multiple key IDs into the third area of ​​the file integration template.

[0020] Furthermore, the file format of the target file corresponds to the file integration template.

[0021] Furthermore, the mask file is set on the upper layer of the original file, and the target file is obtained further including:

[0022] Process the original file to generate the corresponding thumbnail file;

[0023] The mask file is set on the upper layer of the thumbnail file, and the thumbnail file is set on the upper layer of the original file or the ciphertext of the original file to obtain the target file.

[0024] Furthermore, after obtaining the target file, the method further includes:

[0025] Parse the target file and extract the occluded file and the original file from the target file; or parse the target file and extract the occluded file, the original file and the thumbnail file from the target file.

[0026] Furthermore, parsing the target file and extracting the occlusion file and the original file from the target file further includes:

[0027] Parse the target file to determine whether the target file contains the ciphertext of the original file;

[0028] If so, extract the mask file, the key ciphertext and the original file ciphertext from the target file, obtain the preset key or the private key corresponding to the preset public key, use the preset key or the private key corresponding to the preset public key to decrypt the key ciphertext to obtain the file encryption key, and use the file encryption key to decrypt the original file ciphertext to obtain the original file;

[0029] If not, the occlusion file and the original file are extracted from the target file.

[0030] Furthermore, the number of preset keys or preset public keys is multiple, and the target file also includes multiple key IDs;

[0031] Obtaining a private key corresponding to a preset key or a preset public key, and decrypting the key ciphertext using the preset key or the private key corresponding to the preset public key to obtain the file encryption key further includes:

[0032] Extract multiple key IDs from the target file, determine the target key ID from the multiple key IDs, and search the key ciphertext corresponding to the target key ID from the key ciphertext;

[0033] Obtain a preset key corresponding to the target key ID or a private key corresponding to a preset public key corresponding to the target key ID, and use the preset key or the private key to decrypt the key ciphertext corresponding to the target key ID to obtain the file encryption key.

[0034] Parse the target file and determine whether the target file contains a thumbnail file;

[0035] If so, a thumbnail file is displayed.

[0036] Furthermore, the method further comprises:

[0037] Display the masked files, original files and / or thumbnail files separately;

[0038] In response to the file editing request, the mask file, the original file and / or the thumbnail file are edited.

[0039] According to another aspect of the present invention, there is provided a file processing device, the device comprising:

[0040] An acquisition module, adapted to acquire an original file to be processed;

[0041] A setting module, suitable for setting a mask file for an original file;

[0042] The file integration module is suitable for setting the mask file on the upper layer of the original file to obtain the target file.

[0043] According to another aspect of the present invention, there is provided a computing device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus;

[0044] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute the operation corresponding to the above-mentioned file processing method.

[0045] According to another aspect of the present invention, a computer storage medium is provided, in which at least one executable instruction is stored, and the executable instruction enables a processor to execute operations corresponding to the above-mentioned file processing method.

[0046] According to the technical solution provided by the present invention, the obstruction file is set on the upper layer of the original file, and the obstruction file is used to obscure the real file content of the original file, thereby conveniently ensuring the security of file data; if the target file is viewed using the common file viewing method in the prior art without the ability to parse it, then what is viewed is the obstruction file set on the upper layer of the original file, and the real file content of the original file cannot be viewed; only by further parsing the target file can the original file be viewed, thereby increasing the difficulty of the original file being obtained by others and effectively improving data security.

[0047] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0049] Figure 1 A schematic diagram showing a flow chart of a file processing method according to Embodiment 1 of the present invention is shown;

[0050] Figure 2 A schematic diagram showing a flow chart of a file processing method according to Embodiment 2 of the present invention;

[0051] Figure 3 It shows a structural block diagram of a file processing device according to a third embodiment of the present invention;

[0052] Figure 4 A schematic diagram of the structure of a computing device according to a fourth embodiment of the present invention is shown. DETAILED DESCRIPTION

[0053] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0054] Figure 1 FIG. 4 is a flow chart showing a method for processing a file according to a first embodiment of the present invention. Figure 1 As shown, the method comprises the following steps:

[0055] Step S101, obtaining the original file to be processed.

[0056] The method can be executed by an integration and analysis program running on a user terminal. The method can be applied to the integration processing of the user's original file to integrate the occlusion file into the upper layer of the original file, thereby obtaining an integrated file, i.e., a target file. After obtaining the target file, the target file can be stored, or the target file can be shared with other users. File sharing can be achieved through social platforms such as WeChat, QQ, Weibo, forums, emails, etc., and technicians in this field can also choose other sharing methods to transmit the target file, which is not specifically limited here.

[0057] In the present invention, the user who provides the original file is called the first user, and the user who obtains the target file is called the second user, wherein the second user and the first user may be different users or the same user. Specifically, in the scenario where the first user provides the target file to other users, the second user is a different user from the first user, and in the scenario where the first user stores the file himself, for example, when the first user wants to save his own file in an integrated manner or transfer the file to himself through WeChat, email, etc., the second user is the same user as the first user, that is, the second user is also the first user.

[0058] When the first user wants to integrate the original files to protect the file data security, the original files to be processed can be obtained from the user terminal or the Internet, etc. The user terminal refers to the user's mobile phone, laptop, personal computer (PC), personal digital assistant (PDA) and other devices with file storage and file transfer functions. The original files may include picture files, audio and video files, document files, etc. Specifically, the document files may include word files, pdf files, txt files, epub (Electronic Publication) files, chat information between users, email text, etc.

[0059] Step S102, setting a mask file for the original file.

[0060] In order to realize the integration of the original file, after obtaining the original file, it is necessary to set an occlusion file for the original file. Specifically, an existing occlusion file can be used as an occlusion file of the original file, for example, an occlusion file is selected for the original file from an occlusion file library containing occlusion files; in addition, the occlusion file can also be generated using the original file. Taking the original file as a picture file as an example, the picture file can be blurred to generate its occlusion file. Taking the original file as an audio and video file as an example, a certain frame of the picture in the audio and video file can be used as its occlusion file. Those skilled in the art can set the file content and file format of the occlusion file according to actual needs, which is not limited here. For example, the occlusion file may include picture files, audio and video files, document files, etc. In practical applications, the occlusion file can specifically be a landscape picture, a cartoon picture, a small video, etc.

[0061] Step S103, setting the mask file on the upper layer of the original file to obtain the target file.

[0062] After obtaining the original file and the mask file, the original file and the mask file can be integrated, and the mask file is set on the upper layer of the original file through integration processing to obtain the target file. In other words, the mask file is used to mask the real file content of the original file, thereby protecting the security of the file data.

[0063] In this embodiment, the integration of the original file and the masked file can be achieved through the set file integration template. Specifically, the file integration template is provided in the integration parsing program or the file integration template can be generated by the integration parsing program. In step S103, the file integration template can be set, wherein the file integration template includes multiple areas, each area is used to fill different files; the masked file is filled into the first area of ​​the file integration template, the original file is filled into the second area of ​​the file integration template, and then the masked file is set on the upper layer of the original file using the file integration template, so as to obtain the target file.

[0064] Among them, when there are multiple original files, the integration parsing program can be used to batch integrate the multiple original files. In an optional implementation, multiple original files can be batch processed by a file integration template. Specifically, multiple original files can be filled into the second area of ​​the file integration template in a preset order, and the mask file is set on the upper layer of the original file using the file integration template to obtain a target file. That is to say, the second area of ​​a file integration template is filled with multiple original files, and the number of target files obtained is also one, which is equivalent to batch integration of multiple original files. In another optional implementation, a corresponding file integration template can be set for each original file to perform separate operations, and each file integration template is used to process the corresponding original file separately, so as to obtain multiple target files. Specifically, for each original file, the original file is filled into the second area of ​​the corresponding file integration template, and then the mask file is set on the upper layer of the original file using the file integration template to obtain the target file. In this case, each original file can be quickly filled into the second area of ​​the corresponding file integration template in batches. The mask files filled in the first area of ​​each file integration template can be the same mask file or multiple different mask files, which is not limited here. Both of the above methods can conveniently complete batch integration processing of multiple original files.

[0065] In an optional implementation, the original file may not be processed but directly used to generate the target file. In another optional implementation, the original file may be first encrypted to obtain the original file ciphertext (i.e. the encrypted original file), and then the original file ciphertext may be used to generate the target file.

[0066] Optionally, the file format of the target file may correspond to the file integration template. For example, if the file integration template is a template in picture format, then the integrated target file is in picture format; for another example, if the file integration template is a template in pdf format, then the integrated target file is in pdf format.

[0067] If the target file is viewed using the common file viewing method in the prior art without the ability to parse it, then what is viewed is the obstruction file set on the upper layer of the original file in the target file, and the real file content of the original file cannot be viewed; if you want to view the original file in the target file, you need to parse the target file, and the parsing process can be implemented through step S104.

[0068] Step S104, parsing the target file, extracting the occlusion file and the original file from the target file, and displaying the occlusion file and the original file separately.

[0069] After obtaining the target file, the first user can store the target file, or share the target file with the second user. When the second user wants to view the real file content of the original file in the target file, the target file can be parsed through the integrated parsing program, and the obscured file and the original file can be extracted from the target file respectively, thereby achieving effective parsing of the target file and conveniently separating the obscured file and the original file from the target file. In addition, the obscured file and the original file can be displayed separately for users to view.

[0070] Optionally, after the obstruction file and the original file are displayed separately, the second user can also edit the obstruction file and / or the original file. Specifically, in response to the file editing request, the obstruction file and / or the original file are edited. Among them, the integrated parsing program provides a file editing function, for example, circling and outlining the original file, adding text, modifying the file content, etc., replacing the obstruction file, etc. Those skilled in the art can also set other editing operations according to actual needs, which are not limited here.

[0071] According to the file processing method provided by the present embodiment, the obstruction file is set on the upper layer of the original file, and the obstruction file is used to obscure the real file content of the original file, thereby conveniently ensuring the security of file data; if the target file is viewed using the common file viewing method in the prior art without the ability to parse it, then what is viewed is the obstruction file set on the upper layer of the original file, and the real file content of the original file cannot be viewed; only by further parsing the target file can the original file be viewed, thereby increasing the difficulty of the original file being obtained by others and effectively improving data security.

[0072] Figure 2 FIG. 4 shows a flow chart of a file processing method according to Embodiment 2 of the present invention. The method can be executed by an integrated parsing program running on a user terminal. Figure 2 As shown, the method comprises the following steps:

[0073] Step S201, obtaining the original file to be processed.

[0074] Step S202, setting a mask file for the original file.

[0075] Step S203, setting a file integration template.

[0076] A file integration template is provided in the integration and analysis program, or the integration and analysis program can be used to generate a file integration template. The file integration template refers to a template used to integrate the original file and the masked file. The file integration template includes multiple areas, each area is used to fill in different files. Among them, the multiple areas may specifically include a first area, a second area, and a third area. The first area is used to fill in the masked file, and the second area is used to fill in the original file or the original file ciphertext. If the second area is filled with the original file ciphertext, then the third area needs to be filled with encryption information related to the original file ciphertext, such as key ciphertext, key ID, etc. Furthermore, the file integration template also includes other areas for storing other information such as original file summary information, key version information, integration and analysis program version information, etc., for use by the integration and analysis program.

[0077] Step S204, filling the mask file into the first area of ​​the file integration template.

[0078] Step S205, filling the original file into the second area of ​​the file integration template, and using the file integration template to set the mask file on the upper layer of the original file to obtain the target file.

[0079] In this example, the original file can be directly filled into the second area of ​​the file integration template without processing the original file, and then the mask file is set on the upper layer of the original file using the file integration template to obtain the target file. The mask file is used to mask the real file content of the original file, thereby protecting the file data security.

[0080] In addition, the original file may be encrypted first to obtain the original file ciphertext, and then the shielded file and the original file ciphertext may be integrated, and the shielded file may be set on the upper layer of the original file ciphertext to obtain the target file, further improving data security. Specifically, this may be achieved through steps S206 to S208.

[0081] Step S206: randomly generate a file encryption key, encrypt the file encryption key using a preset key or a preset public key to obtain a key ciphertext, and fill the key ciphertext into the third area of ​​the file integration template.

[0082] A random generation algorithm, current time, etc. can be used for processing to randomly generate a file encryption key, which is a key used to encrypt the original file. Those skilled in the art can set the specific content of the file encryption key according to actual needs, which is not limited here. Considering that if the file encryption key is provided to the second user directly by verbal notification or other communication methods, it is not only inconvenient, but also has data security risks. The file encryption key is easily obtained by others, and then the original file ciphertext can be easily decrypted. In order to solve this problem, the present invention encrypts the file encryption key. Specifically, the second user is required to pre-generate his own preset key or preset public key and the private key corresponding to the preset public key. The preset key or preset public key is used to encrypt the file encryption key, and the preset key or the private key corresponding to the preset public key is used to decrypt the encrypted file encryption key (i.e., the key ciphertext below). Among them, the preset key or preset public key and the private key corresponding to the preset public key can be generated by software or external hardware devices, and the external hardware devices include: devices with key generation functions such as terminal encryption cards, terminal security devices, and terminal password devices. Using external hardware devices to generate preset keys or preset public keys and the private keys corresponding to the preset public keys can effectively improve the security of key or private key storage to prevent them from being easily obtained by others maliciously.

[0083] After generating the preset public key of the second user and the private key corresponding to the preset public key, the preset public key can be made into a personal business card such as a QR code and provided to other users for use, or provided to a server for storage. The server can add the obtained preset public key of the second user as a component of the user information to the user information of the second user, and can publicly display the preset public key to each user, or can only store it in the server without publicly displaying it to the user. The preset key or the private key corresponding to the preset public key can be kept by the second user himself, for example, the preset key or the private key corresponding to the preset public key is generated into a QR code for storage, and when the second user needs to use the preset key or private key, it can be obtained by scanning the code. After obtaining the preset key or private key, it can be calculated by the preset encryption and decryption algorithm. In order to improve the security of the preset key or private key, the preset key or private key can be immediately discarded after the calculation is completed; in addition, the preset key or the private key corresponding to the preset public key can also be stored in the user terminal or external hardware device, or the private key can also not be directly stored, but the related derivative factors used to generate the preset public key and the private key corresponding to the preset public key are stored in the user terminal or external hardware device. The above processing method can help ensure the security of the private key corresponding to the preset public key and increase the difficulty of malicious acquisition by others.

[0084] The preset public key of the second user can be queried from the user information of the second user recorded by the server, and the file encryption key can be encrypted using the queried preset public key to obtain the key ciphertext. Specifically, the preset public key can be used to encrypt the file encryption key according to the asymmetric encryption algorithm to obtain the key ciphertext. After obtaining the key ciphertext, the key ciphertext is filled into the third area of ​​the file integration template. Among them, the asymmetric encryption algorithm can be an RSA algorithm, an SM2 algorithm, an Elgamal algorithm, a backpack algorithm, a Rabin algorithm, a DH algorithm, and an ECC (elliptic curve encryption) algorithm. Those skilled in the art can select the algorithm according to actual needs.

[0085] In a file group transmission scenario, a target file is transmitted to a user group including multiple second users. In this scenario, each second user needs to pre-generate his own preset private key or generate his own preset public key and the private key corresponding to the preset public key. That is to say, there are multiple second users, multiple preset keys or preset public keys, and the second users correspond to the preset keys or preset public keys. In order to facilitate the distinction, each preset key or each preset public key has a corresponding key ID. Then, for each key ID, the preset key or preset public key corresponding to the key ID can be used to encrypt the file encryption key to obtain the key ciphertext corresponding to the key ID. Through this processing method, the key ciphertext corresponding to multiple key IDs can be easily obtained, and then the multiple key IDs and the key ciphertext corresponding to the multiple key IDs are filled into the third area of ​​the file integration template. Among them, there is a corresponding relationship between the key ID, the preset key (or preset public key), the key ciphertext and the second user.

[0086] Step S207: encrypt the original file using the file encryption key to obtain the original file ciphertext, and fill the original file ciphertext into the second area of ​​the file integration template.

[0087] Specifically, the file encryption key can be used to encrypt the original file according to the symmetric encryption algorithm to obtain the original file ciphertext. Among them, the symmetric encryption algorithm can be DES algorithm, 3DES algorithm, SM4 algorithm, TDEA algorithm, Blowfish algorithm, RC5 algorithm and IDEA algorithm. Those skilled in the art can select the algorithm according to actual needs.

[0088] Step S208, using the file integration template to integrate the masked file, the key ciphertext and the original file ciphertext, and setting the masked file on the upper layer of the key ciphertext and the original file ciphertext to obtain the target file.

[0089] After obtaining the masked file, key ciphertext and original file ciphertext, the masked file, key ciphertext and original file ciphertext are integrated using the file integration template, and the masked file is set on the upper layer of the key ciphertext and the original file ciphertext to obtain the target file. In other words, the masked file is used to mask the original file ciphertext. Even if the masked file is successfully separated by others, what can be viewed is the original file ciphertext, and the original file ciphertext must be successfully decrypted to view the original file's true file content, thereby increasing the difficulty for others to obtain the original file's true file content, achieving multiple protections for file data, and effectively improving data security.

[0090] Among them, when there are multiple original files or original file ciphertexts, the integration and parsing program can be used to batch integrate and process multiple original files or multiple original file ciphertexts. In an optional implementation, multiple original files or multiple original file ciphertexts can be batch processed by a file integration template. Specifically, multiple original files or multiple original file ciphertexts can be filled into the second area of ​​the file integration template in a preset order, and the file integration template is used to set the mask file on the upper layer of the original file or the original file ciphertext, so as to obtain a target file. In other words, the second area of ​​a file integration template can be filled with multiple original files or multiple original file ciphertexts, and the number of target files obtained is also one, which is equivalent to batch integration processing of multiple original files or multiple original file ciphertexts. In another optional implementation, a corresponding file integration template may be set for each original file or each original file ciphertext to perform separate operations, and each file integration template may be used to process the corresponding original file or original file ciphertext to obtain multiple target files. Specifically, for each original file or each original file ciphertext, the original file or the original file ciphertext is filled into the second area of ​​the corresponding file integration template, and then the file integration template is used to set the mask file on the upper layer of the original file or the original file ciphertext to obtain the target file. In this case, each original file or each original file ciphertext may be quickly filled into the second area of ​​the corresponding file integration template in batches, and the mask file filled in the first area of ​​each file integration template may be the same mask file or multiple different mask files, which is not limited here.

[0091] Optionally, the file format of the target file may correspond to the file integration template.

[0092] Optionally, in order to facilitate file preview, the method may further include: processing the original file to generate a corresponding thumbnail file; setting the mask file in the upper layer of the thumbnail file, and setting the thumbnail file in the upper layer of the original file or the ciphertext of the original file to obtain the target file. Taking the original file as an image file as an example, the image file may be fuzzy processed to generate a thumbnail file; taking the original file as an audio or video file as an example, a certain frame of the audio or video file may be used as a thumbnail file. Specifically, the thumbnail file may be filled into the fourth area of ​​the file integration template.

[0093] If the target file is viewed using the common file viewing method in the prior art without the ability to parse it, then what is viewed is the obstruction file set on the upper layer of the original file or the ciphertext of the original file in the target file, and the real file content of the original file cannot be viewed; if you want to view the original file in the target file, you need to parse the target file, and the parsing process can be implemented through steps S209 to S211.

[0094] Step S209, parse the target file to determine whether the target file contains the ciphertext of the original file; if so, execute step S210; if not, execute step S211.

[0095] After obtaining the target file, the first user can store the target file for his own use, or share the target file with the second user. When the second user wants to view the real file content of the original file in the target file, the target file can be parsed through the integrated parsing program. Considering that if the target file integrates the original file ciphertext, it is necessary to decrypt it step by step to view its real file content. If the target file integrates the original file, the original file can be directly extracted from the target file. Therefore, different methods are used to handle these two situations. Specifically, if the target file contains the original file ciphertext after parsing, it means that the target file encapsulates the encrypted original file and needs to be decrypted, then step S210 is executed; if the target file does not contain the original file ciphertext after parsing, it means that the target file encapsulates the original file and does not need to be decrypted, then step S211 is executed.

[0096] Step S210, extract the obscured file, key ciphertext and original file ciphertext from the target file, obtain the preset key or the private key corresponding to the preset public key, use the preset key or the private key corresponding to the preset public key to decrypt the key ciphertext to obtain the file encryption key, use the file encryption key to decrypt the original file ciphertext to obtain the original file, and display the obscured file and the original file separately.

[0097] The masked file, key ciphertext and original file ciphertext are extracted from the target file respectively. Since the key ciphertext is obtained by encrypting the file encryption key using a preset key or a preset public key according to a preset encryption algorithm, the key ciphertext can be decrypted using a private key corresponding to the preset key or the preset public key to obtain the file encryption key. Specifically, the private key corresponding to the preset key or the preset public key input by the second user can be obtained; or, if the private key corresponding to the preset key or the preset public key is stored in the user terminal or the integrated parsing program, the integrated parsing program can obtain the private key corresponding to the locally stored preset key or the preset public key according to a preset method.

[0098] Since the original file ciphertext is obtained by encrypting the original file using the file encryption key according to the symmetric encryption algorithm, the decrypted file encryption key can be used to decrypt the original file ciphertext according to the inverse algorithm of the symmetric encryption algorithm, thereby quickly obtaining the original file.

[0099] In the file group sending scenario, there are multiple preset keys or preset public keys, and the target file also contains multiple key IDs. In this case, there are also multiple key ciphertexts contained in the target file, that is, each key ID has its corresponding key ciphertext. Then, multiple key IDs can be extracted from the target file, and the target key ID of the current second user can be determined from the multiple key IDs. Then, the key ciphertext corresponding to the target key ID is searched from the key ciphertext, and the preset key corresponding to the target key ID or the private key corresponding to the preset public key corresponding to the target key ID is obtained. The preset key or private key is used to decrypt the key ciphertext corresponding to the target key ID to obtain the file encryption key, and then the file encryption key is used to decrypt the original file ciphertext to obtain the original file. Any second user in the user group can easily determine his own key ID, find the corresponding key ciphertext according to the key ID, and use the private key corresponding to his own preset public key to decrypt the original file ciphertext step by step to obtain the original file. In this way, not only the group data is conveniently sent through encrypted transmission, but any second user in the user group can also easily decrypt the original file ciphertext in the target file. Moreover, the plaintext of the file encryption key is not stored and / or transmitted, which increases the difficulty for the file encryption key to be obtained by others, prevents the original file from being easily obtained by others maliciously, and effectively improves data security.

[0100] Step S211, extracting the occluded file and the original file from the target file, and displaying the occluded file and the original file separately.

[0101] Considering that the target file may also contain a thumbnail file, the parsing process may also include parsing the thumbnail file. Specifically, the target file is parsed to determine whether the target file contains a thumbnail file; if so, the thumbnail file is extracted from the target file and displayed.

[0102] The following is an introduction to this solution using a specific scenario as an example. Assume that the original file is an audio or video of a person, the thumbnail file is a blurred frame of the audio or video, and the occluded file is an animal picture. Set the occluded file on the upper layer of the thumbnail file, and set the thumbnail file on the upper layer of the original file or the ciphertext of the original file to obtain the target file. If the target file is viewed using the common file viewing method in the prior art without the ability to parse it, then what is viewed is the occluded file, that is, a picture of an animal; if the target file is viewed using an integrated parsing program, the original file or the ciphertext of the original file, as well as the occluded file and the thumbnail file can be viewed. For the ciphertext of the original file, if you want to view the plaintext of the original file, the second user must first use his private key to decrypt the key ciphertext to obtain the file encryption key, and then use the file encryption key to decrypt the ciphertext of the original file to obtain the original file.

[0103] Optionally, the method may further include: in response to a file editing request, editing the obscured file, the original file and / or the thumbnail file. The second user may edit the files contained in the target file according to his / her own needs. If the target file contains two files, the obscured file and the original file, the second user may edit any one of the two files or both of them; if the target file contains three files, the obscured file, the original file and the thumbnail file, the second user may edit any one or more of the three files.

[0104] In addition, considering that picture files or audio and video files may be compressed by third-party software such as WeChat or QQ during the sharing process, the second user may not be able to successfully parse the file after receiving it. Since third-party software usually does not compress files in pdf format, doc format, ppt format, etc., file integration templates in pdf format, doc format, ppt format, etc. can be used to integrate the obscured file and the original file (or the ciphertext of the original file) to obtain the corresponding target file in pdf format, doc format, ppt format, etc. After the second user receives the target file, if he uses the common file viewing method in the prior art to view it, what he sees is the obscured file in the target file in pdf format, doc format, ppt format, etc.; if he uses the integrated parsing program to view it, he can view the true file content of the original file in the target file.

[0105] According to the file processing method provided in this embodiment, the file integration template is used to conveniently and efficiently realize the integration of files, and the masking file is used to mask the original file or the original file ciphertext, so as to conveniently ensure the security of file data, so that the common file viewing method in the prior art can only view the masked file in the target file, but cannot view the real file content of the original file; only by further parsing the target file can the original file be viewed, and if the target file contains the original file ciphertext, it is necessary to use the second user's own preset key or the private key corresponding to the preset public key to complete the decryption of the original file ciphertext step by step to obtain the original file, thereby not only conveniently completing data transmission or data group sending through encrypted transmission, but also the second user can conveniently decrypt the original file ciphertext in the target file, and the plaintext of the file encryption key is not stored and / or transmitted, which increases the difficulty of the file encryption key being obtained by others, so as to prevent the content of the original file from being easily obtained by others maliciously, thereby greatly improving data security.

[0106] Figure 3 FIG. 4 shows a structural block diagram of a file processing device according to Embodiment 3 of the present invention. Figure 3 As shown, the device includes: an acquisition module 310, a setting module 320 and a file integration module 330.

[0107] The acquisition module 310 is adapted to: acquire an original file to be processed.

[0108] The setting module 320 is adapted to set a mask file for the original file.

[0109] The file integration module 330 is adapted to: place the shielding file on an upper layer of the original file to obtain a target file.

[0110] Optionally, the file integration module 330 is further suitable for: randomly generating a file encryption key, encrypting the file encryption key using a preset key or a preset public key to obtain a key ciphertext; encrypting the original file using the file encryption key to obtain an original file ciphertext; integrating the obscured file, the key ciphertext and the original file ciphertext, and setting the obscured file on an upper layer of the key ciphertext and the original file ciphertext to obtain a target file.

[0111] Optionally, there are multiple preset keys or preset public keys, and each preset key or each preset public key has a corresponding key ID. The file integration module 330 is further adapted to: for each key ID, encrypt the file encryption key using the preset key or preset public key corresponding to the key ID to obtain the key ciphertext corresponding to the key ID.

[0112] Optionally, the file integration module 330 is further suitable for: setting a file integration template; filling the masked file into the first area of ​​the file integration template, filling the original file or the original file ciphertext into the second area of ​​the file integration template, and using the file integration template to set the masked file on the upper layer of the original file or the original file ciphertext to obtain a target file; wherein, when there are multiple original files, the original files or the original file ciphertexts are filled into the second area of ​​the file integration template in a preset order to obtain a target file; or, when there are multiple original files, each original file or each original file ciphertext corresponds to a file integration template, and each file integration template is used to process the corresponding original file or original file ciphertext to obtain multiple target files; when the second area is filled with the original file ciphertext, the key ciphertext needs to be filled into the third area of ​​the file integration template, or, multiple key IDs and the key ciphertexts corresponding to the multiple key IDs are filled into the third area of ​​the file integration template.

[0113] Optionally, the file format of the target file corresponds to the file integration template.

[0114] Optionally, the file integration module 330 is further adapted to: process the original file to generate a corresponding thumbnail file; set the mask file on the upper layer of the thumbnail file, and set the thumbnail file on the upper layer of the original file or the ciphertext of the original file to obtain the target file.

[0115] Optionally, the device further includes: a parsing module 340, adapted to parse the target file and extract the occluded file and the original file from the target file; or parse the target file and extract the occluded file, the original file and the thumbnail file from the target file.

[0116] Optionally, the parsing module 340 is further suitable for: parsing the target file to determine whether the target file contains the original file ciphertext; if so, extracting the obscured file, the key ciphertext and the original file ciphertext from the target file, obtaining the preset key or the private key corresponding to the preset public key, using the preset key or the private key corresponding to the preset public key to decrypt the key ciphertext to obtain the file encryption key, and using the file encryption key to decrypt the original file ciphertext to obtain the original file; if not, extracting the obscured file and the original file from the target file.

[0117] Optionally, there are multiple preset keys or preset public keys, and the target file also includes multiple key IDs. The parsing module 340 is further adapted to: extract multiple key IDs from the target file, determine the target key ID from the multiple key IDs, search for the key ciphertext corresponding to the target key ID from the key ciphertext; obtain the preset key corresponding to the target key ID or the private key corresponding to the preset public key corresponding to the target key ID, and use the preset key or private key to decrypt the key ciphertext corresponding to the target key ID to obtain the file encryption key.

[0118] Optionally, the device further includes: an editing module 350, adapted to display the obscured file, the original file and / or the thumbnail file separately; and edit the obscured file, the original file and / or the thumbnail file in response to a file editing request.

[0119] According to the file processing device provided by the present embodiment, the file integration template is used to conveniently and efficiently realize the integration of files, and the masking file is used to mask the original file or the ciphertext of the original file, so as to conveniently ensure the security of file data, so that the common file viewing method in the prior art can only view the masked file in the target file, but cannot view the real file content of the original file; only by further parsing the target file can the original file be viewed, and if the target file contains the ciphertext of the original file, it is necessary to use the second user's own preset key or the private key corresponding to the preset public key to complete the decryption of the original file ciphertext step by step to obtain the original file, thereby not only conveniently completing data transmission or data group sending through encrypted transmission, but also the second user can conveniently decrypt the original file ciphertext in the target file, and the plaintext of the file encryption key is not stored and / or transmitted, which increases the difficulty of the file encryption key being obtained by others, so as to prevent the content of the original file from being easily obtained by others maliciously, thereby greatly improving data security.

[0120] The present invention also provides a non-volatile computer storage medium, which stores at least one executable instruction, and the executable instruction can execute the file processing method in any of the above method embodiments.

[0121] Figure 4 A schematic diagram of the structure of a computing device according to Embodiment 4 of the present invention is shown. The specific embodiment of the present invention does not limit the specific implementation of the computing device.

[0122] like Figure 4 As shown, the computing device may include: a processor (processor) 402 , a communications interface (Communications Interface) 404 , a memory (memory) 406 , and a communication bus 408 .

[0123] in:

[0124] The processor 402 , the communication interface 404 , and the memory 406 communicate with each other via a communication bus 408 .

[0125] The communication interface 404 is used to communicate with other devices such as clients or other servers.

[0126] The processor 402 is used to execute the program 410, and specifically can execute the relevant steps in the above-mentioned file processing method embodiment.

[0127] Specifically, the program 410 may include program codes, which include computer operation instructions.

[0128] The processor 402 may be a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention. The one or more processors included in the computing device may be processors of the same type, such as one or more CPUs; or processors of different types, such as one or more CPUs and one or more ASICs.

[0129] The memory 406 is used to store the program 410. The memory 406 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0130] The program 410 can be specifically used to enable the processor 402 to execute the file processing method in any of the above method embodiments. The specific implementation of each step in the program 410 can refer to the corresponding descriptions in the corresponding steps and units in the above file processing embodiments, which will not be repeated here. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the above-described devices and modules can refer to the corresponding process description in the above method embodiments, which will not be repeated here.

[0131] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious that the structure required for constructing such systems. In addition, the present invention is not directed to any specific programming language either. It should be understood that various programming languages ​​can be utilized to realize the content of the present invention described herein, and the description of the above specific languages ​​is for disclosing the best mode of the present invention.

[0132] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.

[0133] Similarly, it should be understood that in order to streamline the present disclosure and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the intention that the claimed invention requires more features than those expressly recited in each claim. Rather, as reflected in the claims, inventive aspects lie in less than all of the features of the individual embodiments previously disclosed. Therefore, the claims that follow the detailed description are hereby expressly incorporated into the detailed description, with each claim itself serving as a separate embodiment of the present invention.

[0134] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition they may be divided into a plurality of submodules or subunits or subcomponents. Except that at least some of such features and / or processes or units are mutually exclusive, all features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed in this manner may be combined in any combination. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.

[0135] In addition, those skilled in the art will appreciate that, although some embodiments described herein include certain features included in other embodiments but not other features, the combination of features of different embodiments is meant to be within the scope of the present invention and form different embodiments. For example, in the claims, any one of the claimed embodiments may be used in any combination.

[0136] The various component embodiments of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the embodiments of the present invention. The present invention can also be implemented as a device or apparatus program (e.g., computer program and computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0137] It should be noted that the above embodiments illustrate the present invention rather than limit it, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation on the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "one" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising a number of different elements and by means of a suitably programmed computer. In a unit claim enumerating a number of devices, several of these devices may be embodied by the same hardware item. The use of the words first, second, and third, etc., does not indicate any order. These words may be interpreted as names.

Claims

1. A file processing method, It is characterized in that The method comprises: Get the original file to be processed; Setting a mask file for the original file; The shielding file is set on the upper layer of the original file or the ciphertext of the original file to obtain the target file; wherein the ciphertext of the original file is obtained by encrypting the original file; Parsing the target file to determine whether the target file contains the ciphertext of the original file; If so, extract the masked file, the key ciphertext and the original file ciphertext from the target file, obtain the preset key or the private key corresponding to the preset public key, use the preset key or the private key corresponding to the preset public key to decrypt the key ciphertext to obtain the file encryption key, and use the file encryption key to decrypt the original file ciphertext to obtain the original file; If not, extracting the mask file and the original file from the target file; The number of the preset keys or the preset public keys is multiple, and the target file further includes multiple key IDs; obtaining the private key corresponding to the preset key or the preset public key, and using the private key corresponding to the preset key or the preset public key to decrypt the key ciphertext to obtain the file encryption key further includes: Extracting multiple key IDs from the target file, determining a target key ID from the multiple key IDs, and searching for a key ciphertext corresponding to the target key ID from the key ciphertext; Obtain a preset key corresponding to the target key ID or a private key corresponding to a preset public key corresponding to the target key ID, and use the preset key or the private key to decrypt the key ciphertext corresponding to the target key ID to obtain a file encryption key.

2. The method according to claim 1, It is characterized in that The shielding file is set on the upper layer of the original file or the ciphertext of the original file, and obtaining the target file further comprises: Randomly generate a file encryption key, and use a preset key or a preset public key to encrypt the file encryption key to obtain a key ciphertext; Encrypting the original file using the file encryption key to obtain the original file ciphertext; The obscured file, the key ciphertext and the original file ciphertext are integrated and processed, and the obscured file is set on an upper layer of the key ciphertext and the original file ciphertext to obtain a target file.

3. The method according to claim 2, It is characterized in that There are multiple preset keys or preset public keys, and each preset key or each preset public key has a corresponding key ID; The step of encrypting the file encryption key with a preset key or a preset public key to obtain a key ciphertext further includes: For each key ID, the file encryption key is encrypted using a preset key or a preset public key corresponding to the key ID to obtain a key ciphertext corresponding to the key ID.

4. The method according to any one of claims 1 to 3, It is characterized in that The shielding file is set on the upper layer of the original file or the ciphertext of the original file, and obtaining the target file further comprises: Set up file integration template; Fill the masked file into the first area of ​​the file integration template, fill the original file or the ciphertext of the original file into the second area of ​​the file integration template, and use the file integration template to set the masked file on the upper layer of the original file or the ciphertext of the original file to obtain the target file; Wherein, when there are multiple original files, the original files or the ciphertexts of the original files are filled into the second area of ​​the file integration template in a preset order to obtain a target file; or, when there are multiple original files, each original file or each ciphertext of the original file corresponds to a file integration template, and each file integration template is used to process the corresponding original file or ciphertext of the original file to obtain multiple target files; When the second area is filled with the original file ciphertext, the method also includes: filling the key ciphertext into the third area of ​​the file integration template, or filling multiple key IDs and the key ciphertexts corresponding to the multiple key IDs into the third area of ​​the file integration template.

5. The method according to any one of claims 1 to 3, It is characterized in that The step of setting the shielding file on the upper layer of the original file or the ciphertext of the original file to obtain the target file further comprises: Processing the original file to generate a corresponding thumbnail file; The shielded file is set on the upper layer of the thumbnail file, and the thumbnail file is set on the upper layer of the original file or the ciphertext of the original file to obtain the target file.

6. The method according to claim 5, It is characterized in that The method further comprises: The target file is parsed, and a thumbnail file is extracted from the target file.

7. The method according to any one of claims 1 to 3, It is characterized in that The method further comprises: The obscured file, the original file and / or the thumbnail file are displayed separately; In response to the file editing request, the mask file, the original file and / or the thumbnail file are edited.

8. A file processing device, It is characterized in that The device comprises: An acquisition module, adapted to acquire an original file to be processed; A setting module, adapted to set a mask file for the original file; A file integration module, adapted to set the mask file on an upper layer of the original file or the ciphertext of the original file to obtain a target file; wherein the ciphertext of the original file is obtained by encrypting the original file; a parsing module, adapted to parse the target file, and determine whether the target file contains the original file ciphertext; if so, extract the obscured file, the key ciphertext, and the original file ciphertext from the target file, obtain a preset key or a private key corresponding to a preset public key, use the preset key or the private key corresponding to the preset public key to decrypt the key ciphertext to obtain a file encryption key, and use the file encryption key to decrypt the original file ciphertext to obtain the original file; if not, extract the obscured file and the original file from the target file; Wherein, the number of the preset keys or the preset public keys is multiple, and the target file also contains multiple key IDs; the parsing module is further adapted to: Extracting multiple key IDs from the target file, determining a target key ID from the multiple key IDs, and searching for a key ciphertext corresponding to the target key ID from the key ciphertext; Obtain a preset key corresponding to the target key ID or a private key corresponding to a preset public key corresponding to the target key ID, and use the preset key or the private key to decrypt the key ciphertext corresponding to the target key ID to obtain a file encryption key.

Citation Information

Patent Citations

  • Method for data security transmission and key exchange

    CN103618607A

  • Image display method and terminal

    CN103970501A