File processing method and device, electronic equipment and storage medium
By combining hand vein features with finger vein and palm vein features for dual decryption, the problem of data leakage caused by the low encryption coefficient of single finger vein features is solved, and high data security protection is achieved.
Patent Information
- Application Number
- CN202210244843.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-14
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2042-03-14
AI Technical Summary
Existing encryption and decryption methods based on single finger vein features have low encryption coefficients, making data easily leaked.
The initial decryption is performed by combining hand vein features with finger vein features and palm vein features, and a secondary decryption is performed using icon-based ciphers, which increases the difficulty of decryption.
The dual decryption process significantly increases the difficulty of decryption, ensuring data security and preventing data leakage.
Smart Images

Figure CN114595438B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to computer processing technology, and particularly relate to a file processing method and device, electronic equipment and storage medium. BACKGROUND
[0002] With the development of informatization, the problem of protecting data is particularly prominent, and data security is also increasingly concerned by users. The traditional username and password technology has been difficult to make a breakthrough, and a more secure and reliable authentication method must be used to ensure the security of user data and prevent file leakage.
[0003] At present, the method of encrypting files based on vein features has become a new bio-feature encryption method, which uses near-infrared rays to penetrate the finger to extract vein pattern features for identity recognition, and is a high-precision and high-speed bio-recognition technology. After vein feature recognition, the encrypted data is decrypted.
[0004] In the prior art, data is usually encrypted and decrypted based on single finger vein features. Due to the low encryption coefficient, the data is easily decrypted and leaked. SUMMARY
[0005] Embodiments of the present application provide a file processing method, device, electronic equipment and storage medium to improve the difficulty coefficient of data decryption and achieve the technical effect of ensuring data security.
[0006] In a first aspect, the embodiments of the present application provide a file processing method, which comprises:
[0007] When a file access request is received, a hand vein feature corresponding to a target subject is obtained, wherein the hand vein feature includes a finger vein feature and a palm vein feature;
[0008] If the hand vein feature is consistent with a stored vein feature associated with a target vehicle, a to-be-matched icon password corresponding to the stored vein feature is retrieved;
[0009] If the to-be-verified icon password corresponding to the trigger operation is consistent with the to-be-matched icon password, it is determined that the decryption of a target file corresponding to the file access request is successful, and the target file is displayed.
[0010] In a second aspect, the embodiments of the present application also provide a file processing device, which comprises:
[0011] A hand vein feature acquisition module is configured to acquire a hand vein feature corresponding to a target subject when a file access request is received, wherein the hand vein feature includes a finger vein feature and a palm vein feature;
[0012] The icon password to be matched calling module is configured to call an icon password to be matched corresponding to the stored vein feature if the hand vein feature is consistent with the stored vein feature associated with the target vehicle.
[0013] The target file display module is configured to determine that decryption of a target file corresponding to the file access request is successful and display the target file if the icon password to be verified corresponding to the trigger operation is consistent with the icon password to be matched.
[0014] In a third aspect, an electronic device is provided, and the device includes:
[0015] one or more processors;
[0016] a memory device storing one or more programs,
[0017] When the one or more programs are executed by the one or more processors, the one or more processors implement the file processing method according to any of the embodiments of the present application.
[0018] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program, which, when executed by a processor, implements the file processing method according to any of the embodiments of the present application.
[0019] The technical solution of the embodiments of the present application solves the problem in the prior art that data is encrypted and decrypted based on a single finger vein feature, and the data is easily leaked due to a low encryption coefficient, and achieves preliminary decryption of a file based on a finger vein feature and a palm vein feature. If the hand vein feature is consistent with the stored vein feature associated with the target vehicle, it indicates that the preliminary decryption is successful, and then the icon password to be verified generated based on a user trigger operation is used for secondary decryption of the file. If the icon password to be verified is consistent with the icon password to be matched, it indicates that the secondary decryption is successful. Under the condition that the two decryptions are successful, the file is allowed to be accessed, which greatly increases the decryption difficulty coefficient and achieves the technical effect of ensuring data security. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present application, the drawings needed in the description of the embodiments are briefly introduced as follows. Obviously, the drawings introduced are only a part of the drawings of the present application, and not all the drawings, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.
[0021] Figure 1 A flow chart of a file processing method provided by the first embodiment of the present application;
[0022] Figure 2 A schematic diagram of a file encryption method provided by the second embodiment of the present application;
[0023] Figure 3 A schematic diagram of a file decryption method provided by the second embodiment of the present application;
[0024] Figure 4 A schematic diagram of a file processing method provided by the second embodiment of the present application;
[0025] Figure 5 A structural block diagram of a file processing device provided by the third embodiment of the present application;
[0026] Figure 6 A structural schematic diagram of an electronic device provided by the fourth embodiment of the present application. DETAILED DESCRIPTION
[0027] The present application will be further described in detail below in combination with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, and not to limit the present application. In addition, it should be noted that, in order to facilitate the description, only the parts related to the present application are shown in the drawings, and not all the structures.
[0028] Embodiment one
[0029] Figure 1 A flow chart of a file processing method provided by the first embodiment of the present application, the present embodiment can be applicable to the case of data encryption and decryption, and the method can be executed by the file processing device in the present embodiment, which can be realized in the form of software and / or hardware, and can be realized by an electronic device, which can be a mobile terminal, a PC terminal or a server, etc. The device can be configured in a computing device, and the file processing method provided by the present embodiment specifically includes the following steps:
[0030] S110, when receiving a file access request, acquiring the hand vein features corresponding to the target subject.
[0031] The file access request includes at least one of reading, copying, moving, deleting, and the like of the file data. The file data includes, but is not limited to, vehicle-mounted video data, user basic data, vehicle driving data, Internet of Vehicles data, and the like. The hand vein feature includes a finger vein feature and a palm vein feature.
[0032] In actual application, the file access request can be considered to be received when the user triggers the file access control by using the input device. In order to improve the security of the file, the hand vein feature of the user can be acquired by using the vein scanning device to verify the identity of the user. For example, in the scenario of vehicle data access, if the user triggers the access request of reading the vehicle-mounted video data, the identity of the user needs to be verified at this time. Optionally, prompt information can be displayed on the display screen to prompt the user to move the hand to the vein scanning device. The vein scanning device can be deployed at the vehicle end. Correspondingly, the hand of the user can be scanned by using the vein scanning device to acquire the finger vein feature and the palm vein feature of the hand of the user.
[0033] It should be noted that when the file access request is received, the hand vein feature corresponding to the target subject can also be acquired when the vein scanning device detects that the hand of the user appears in the field of view region. The hand of the user is scanned by the vein scanning device to obtain the hand vein feature.
[0034] Optionally, when the file access request is received, the hand vein feature corresponding to the target subject is acquired, and the method further includes: when the file access request is received, starting the collection device; and when it is detected that the target subject is included in the field of view region of the collection device, collecting the vein of the target subject based on the collection device to obtain the hand vein feature.
[0035] The collection device can be a device with vein feature collection. Optionally, the collection device can be a far-infrared vein recognition instrument. The far-infrared vein recognition instrument uses the characteristic that the human body radiates far-infrared rays to capture the vein distribution image of the hand (back of the hand, back of the finger, palm, and / or wrist) by using an infrared camera with a corresponding wavelength range. After the vein distribution image is normalized, denoised, filtered and enhanced, vein ridge segmentation and / or refined repair, and the like, image preprocessing is performed, feature extraction is performed, and the hand vein feature is obtained. The collection device can also be a near-infrared vein recognition instrument. The near-infrared vein recognition instrument uses the characteristic that the vein blood absorbs near-infrared rays. The hand is irradiated by using near-infrared rays, and the light reflected by the palm is sensed by a sensor. Then, the position of the vein is identified by using the strength of the reflected near-infrared rays, and the hand vein feature is obtained. It should be noted that when the hand vein feature is acquired by the collection device, only the vein feature of the living hand is acquired. When the non-living hand is collected, the vein feature cannot be obtained, and the non-living hand cannot be identified, which can effectively prevent counterfeiting. The field of view region refers to the region that can be captured by the collection device at a certain position.
[0036] Specifically, when the user triggers the file access control, it is considered that the system receives a file access request. Before allowing access, the identity of the user needs to be determined. At this time, the collection device can be started to collect the hand vein features of the target subject to use the hand vein features to represent the user identity for user identity recognition. When it is detected that the target subject is included in the field of view area of the collection device, it is considered that the operation of collecting the vein features of the target subject is triggered, and then the vein features of the target subject are collected by the collection device to obtain the hand vein features.
[0037] It should be noted that when receiving the file access request, the hand vein features corresponding to the target subject can be obtained before the hand vein features of the target subject are obtained. The file data is encrypted based on the hand vein features to obtain an encrypted file, thereby improving the security of the data and effectively increasing the decryption difficulty of the file in subsequent decryption.
[0038] Optionally, before receiving the file access request and obtaining the hand vein features corresponding to the target subject, the method further includes: obtaining a to-be-used file associated with the target vehicle; encrypting the to-be-used file based on the hand vein features corresponding to the target subject to obtain an encrypted file; generating a to-be-processed encrypted image based on the hand vein features and a preset icon identifier; obtaining a to-be-used icon password based on the user triggering operation on the to-be-processed encrypted image; and encrypting the encrypted file based on the to-be-used icon password to obtain an encrypted target file.
[0039] The to-be-used file can be understood as a file that needs to be encrypted. The encrypted file refers to a file that needs to be encrypted twice. The preset icon identifier can be understood as a preset, special identifier, for example, the icon identifier can be icon information such as peach blossom, tree, bridge, house, and bird.
[0040] In the embodiment, the file associated with the target vehicle and needed to be encrypted can be determined based on the user demand, and used as the to-be-used file, for example, vehicle-mounted video data, user data, vehicle driving data, etc. The hand vein features corresponding to the target subject can be acquired, and then the feature points of the finger veins and palm veins are taken as the encryption method, the to-be-used file is encrypted based on the encryption method, and the file after preliminary encryption is obtained and taken as the to-be-encrypted file. Further, the to-be-encrypted file can be further encrypted. The image with icon identification can be generated based on the hand vein features and the preset icon identification, for example, each finger vein and palm vein feature point can correspond to a corresponding icon identification, such as feature point A corresponds to peach blossom, feature point B corresponds to bridge, and feature point C corresponds to tree. The corresponding identification can be displayed at a position matched with the hand position in the image based on the positions of A, B and C in the hand, to generate the image with icon identification, that is, the to-be-processed encrypted image. In this way, the distribution of the icon identification in the image can truly represent the distribution of the user's hand vein features. The to-be-processed encrypted image corresponding to each user is unique. The user can select part or all of the vein feature points in the to-be-processed encrypted image by using the input device, as the icon password for encrypting the to-be-encrypted file, that is, the to-be-used icon password, and then the to-be-used icon password can be taken as the encryption method to encrypt the to-be-encrypted file, to obtain the encrypted file as the target file. Subsequently, when accessing the target file, the corresponding decryption needs to be performed first to allow access to the data.
[0041] It should be noted that in the process of encrypting the file based on the hand vein features and the to-be-used icon password to obtain the target file, the hand vein features and the icon password used during encryption can also be associated and stored in the password library, so that when decryption is performed, the input information of the access user can be directly retrieved from the password library for comparison to verify the authenticity of the user.
[0042] S120, if the hand vein features are consistent with the stored vein features associated with the target vehicle, the to-be-matched icon password corresponding to the stored vein features is retrieved.
[0043] In practical applications, when a user triggers a file access request such as reading, copying, moving or deleting a target file, hand vein feature recognition needs to be performed first. At this time, the hand vein feature read by the collection device can be compared with the hand vein feature pre-stored in the password library. If the hand vein feature is consistent with the stored vein feature, it means that the user's identity is preliminarily authenticated successfully. At this time, the icon password associated with the stored vein feature is retrieved from the password library as a to-be-matched icon password, so that the to-be-matched icon password can be compared with the icon information selected by the user on the display screen for secondary identity verification, to increase the decryption difficulty and improve the security of the file. It should be noted that if the hand vein feature is inconsistent with the stored vein feature, it means that the user's identity is preliminarily authenticated unsuccessfully, and there may be a risk of data theft. In order to improve the security of data and effectively reduce the loss, the corresponding warning information can be triggered at this time, for example, the in-vehicle camera can be used to take pictures or record videos in the vehicle to obtain the information of the user accessing the vehicle; or the target device associated with the vehicle owner can be sent a warning prompt.
[0044] Optionally, if the hand vein feature is inconsistent with the stored vein feature associated with the target vehicle, it is determined that the decryption of the target file corresponding to the file access request fails, and the target warning information corresponding to the file access request is determined.
[0045] The target warning information includes, but is not limited to, non-inductive collection information and non-inductive alarm information.
[0046] In practical applications, if the hand vein feature is inconsistent with the stored vein feature in the password library associated with the target vehicle, that is, the hand vein feature is not matched successfully, it is determined that the decryption of the target file corresponding to the file access request fails. At this time, the sound collection sensor in the target vehicle can be triggered to non-inductively collect the sound in the vehicle; the camera collection sensor can be triggered to non-inductively collect the picture in the vehicle; or the alarm sensor in the vehicle can be triggered to upload the alarm information to a third party or the vehicle owner, such as sending the alarm information to the vehicle owner in the form of a short message, a phone call or an email. At this time, the user accessing the file in the vehicle does not know that his / her information has been collected, nor does he / she know that the alarm information has been sent to the vehicle owner, thereby improving the effectiveness of data monitoring.
[0047] It should be noted that after the hand vein feature is matched successfully with the stored vein feature associated with the target vehicle, and the to-be-matched icon password corresponding to the stored vein feature is retrieved, the to-be-matched icon password can be compared with the icon information selected by the user on the display screen for secondary identity verification, to increase the decryption difficulty and improve the security of the file.
[0048] Optionally, after the icon password to be matched corresponding to the stored vein feature is retrieved, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, the method further comprises: displaying an icon image to be decrypted; generating an icon password to be verified based on a triggering operation of the user on the icon image to be decrypted; and determining that decryption of the target file corresponding to the file access request fails and determining target warning information corresponding to the file access request if the icon password to be verified is inconsistent with the icon password to be matched.
[0049] In the icon image to be decrypted, at least one icon identifier is included. The icon password to be verified can be understood as an icon password that needs to be verified.
[0050] In actual application, if the hand vein feature is consistent with the stored vein feature, it indicates that the preliminary decryption is successful, and at this time, an encrypted image with icon identifiers is displayed on the display screen. The encrypted image refers to an image matched with the stored vein feature when the file is encrypted. The user can select at least one icon identifier on the encrypted image by using an input device, and can take the selected icon identifiers as the icon password to be verified, and then verify whether the icon password to be verified is consistent with the icon password to be matched stored in the password library when the file is encrypted. If not, it indicates that the decryption of the target file fails, and at this time, the non-inductive collection device in the target vehicle can be triggered to collect the information in the vehicle, and the collected data information can be taken as the target warning information, thereby effectively protecting the safety of the data.
[0051] It should be noted that, when the target warning information corresponding to the file access request is determined, to prevent the situation of false alarm due to the contingency of decryption failure, the number of decryption failures can be used to determine the warning operation to be performed, and then the corresponding warning information is generated.
[0052] Optionally, determining the target warning information corresponding to the file access request comprises: recording a characteristic attribute value corresponding to the decryption failure of the target file; and determining target warning information corresponding to a preset characteristic threshold if the characteristic attribute value is greater than the preset characteristic threshold.
[0053] It should be noted that, if the hand vein feature is inconsistent with the stored vein feature associated with the target vehicle, the decryption fails. After the decryption fails, the hand vein feature of the target subject is repeatedly acquired until the matching is successful, and then the verification of the icon password is performed. If the icon password to be verified corresponding to the triggering operation is inconsistent with the icon password to be matched, the decryption fails. After the decryption fails, the icon password to be verified is repeatedly acquired until the matching is successful, and then the user is allowed to access the file.
[0054] In actual application, the number of times of decryption failure can be recorded as a characteristic attribute value in the process of decrypting the target file, and when the characteristic attribute value is greater than a preset characteristic threshold, the target early warning information corresponding to the preset characteristic threshold can be determined. For example, if the number of times of hand vein feature matching or icon password matching to be verified fails more than once, at this time, the non-sensing data collection can be performed to generate non-sensing collection information; if the number of times of hand vein feature matching or icon password matching to be verified fails more than twice, at this time, the non-sensing alarm can be performed to generate non-sensing alarm information, and after entering the non-sensing alarm, the vehicle related security level information or data enters the alert state.
[0055] In the embodiment, the user can select at least one icon identifier on the display screen by using the input device, at this time, the selected icon identifier can be used as the icon password to be verified, and then it is verified whether the icon password to be verified is consistent with the icon password to be matched stored in the password library during encryption, if yes, it indicates that the decryption of the target file is successful, the user is allowed to perform the operation corresponding to the file access request on the target file, and the data can be displayed.
[0056] In the embodiment, the user can select at least one icon identifier on the display screen by using the input device, at this time, the selected icon identifier can be used as the icon password to be verified, and then it is verified whether the icon password to be verified is consistent with the icon password to be matched stored in the password library during encryption, if yes, it indicates that the decryption of the target file is successful, the user is allowed to perform the operation corresponding to the file access request on the target file, and the data can be displayed.
[0057] It should be noted that after the decryption is successful, the target file can be given corresponding access permission based on the request parameter in the file access request, so that the target file can be normally accessed based on the access permission.
[0058] Optionally, if the icon password to be verified corresponding to the trigger operation is consistent with the icon password to be matched, it is determined that the decryption of the target file corresponding to the file access request is successful, and the target file is displayed, including: if the icon password to be verified corresponding to the trigger operation is consistent with the icon password to be matched, it is determined that the decryption of the target file corresponding to the file access request is successful, and the access permission corresponding to the target file is determined, and the target file is displayed.
[0059] In actual application, if the icon password to be verified corresponding to the trigger operation is consistent with the icon password to be matched, it is determined that the decryption of the target file corresponding to the file access request is successful, at this time, the file access request can be parsed to obtain the access parameter in the file access request, and the target file is given corresponding access permission, for example, if the access parameter is copy, the access permission is to allow the user to copy the file data, and the accessed target file can also be displayed.
[0060] The technical scheme of the embodiment, by receiving the file access request, acquiring the finger vein feature and the palm vein feature corresponding to the target subject, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, the stored vein feature corresponding to the to-be-matched icon password is called, if the to-be-verified icon password corresponding to the trigger operation is consistent with the to-be-matched icon password, it is determined that the target file corresponding to the file access request is decrypted successfully, and the target file is displayed, which solves the problem that the data is easily leaked due to the low encryption coefficient in the prior art based on single finger vein feature for data encryption and decryption operation, realizes the preliminary decryption of the file based on the finger vein feature and the palm vein feature, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, it indicates that the preliminary decryption is successful, and then the to-be-verified icon password generated based on the user trigger operation is used for secondary decryption of the file, if the to-be-verified icon password is consistent with the to-be-matched icon password, it indicates that the secondary decryption is successful, and under the condition that the two times of decryption are successful, the file is allowed to be accessed, which greatly increases the decryption difficulty coefficient and achieves the technical effect of ensuring data security.
[0061] Embodiment two
[0062] As an optional embodiment of the above-mentioned embodiment, Figure 2 The schematic diagram of the file encryption method provided by the embodiment two of the application is shown. Specifically, the specific content is described below.
[0063] Referring to Figure 2 The information in the target vehicle that needs to be decrypted can be selected as the to-be-used file based on user demand, and the to-be-used file includes but is not limited to vehicle-mounted video data, user data, vehicle driving data, etc. At this time, the finger vein feature and the palm vein feature of the user are collected, the vein features are input into the hand vein model to generate a first encryption method; at the same time, part or all of the feature points of the finger vein feature and the palm vein feature can also be selected as a second encryption method for the file; the to-be-used file can be encrypted based on the first encryption method to obtain a to-be-encrypted file, and then the to-be-encrypted file is encrypted based on the second encryption method to obtain an encrypted target file. Optionally, the first encryption method and the second encryption method can also be used to encrypt the to-be-used file to obtain a target file with an encrypted data identifier. After the two encryption methods, the encrypted target file can be updated to the to-be-used file, so that the subsequent user needs to decrypt after the update to normally access the file, and the data security is improved. Exemplarily, refer to Figure 3The schematic diagram of the file decryption method can be expressed as follows: when a file access request is received, it is considered that a decryption application is received. The file access request can be an access request for reading, copying, moving, deleting, etc. At this time, the system needs to identify the user's finger vein features and palm vein features, compare them with the vein features in the vein feature library, and obtain the comparison result. If the comparison fails, the number of comparison failures is recorded. If the number of failures exceeds 1, the unconscious data collection is performed. If the number of failures exceeds 2, the unconscious alarm is performed. If the comparison is successful, it means that the collected hand vein features are consistent with the stored vein features in the target vehicle. At this time, the to-be-matched icon password corresponding to the stored vein features can be retrieved, and the to-be-verified icon password corresponding to the user's trigger operation is compared with the to-be-matched icon password to obtain the comparison result. If the comparison fails, the number of comparison failures is recorded. If the number of failures exceeds 1, the unconscious data collection is performed. If the number of failures exceeds 2, the unconscious alarm is performed. After the unconscious alarm, the vehicle-related security level information or data enters the alert state. If the comparison is successful, it means that the to-be-verified icon password is consistent with the to-be-matched icon password, and the target file is decrypted successfully. At this time, the access permission can be given, and the target file can be displayed.
[0064] On the basis of the above-mentioned scheme, for example, see Figure 4 In actual application, the finger vein feature acquisition and palm vein feature acquisition can be performed by using the hand vein feature acquisition module to obtain the hand vein features (finger vein features and palm vein features) corresponding to the target subject. The collected hand vein features can be compared with the vehicle information security system control module to identify and authenticate the hand vein features. If the comparison fails, the target file decryption fails, and the information security defense mechanism is triggered to generate target warning information. If the comparison fails, the target file decryption is successful, and the to-be-matched icon password corresponding to the stored vein features is retrieved. At this time, the user can input the icon password information on the human-computer interaction interface. If the icon password information is inconsistent with the to-be-matched icon password, the target file decryption fails, and the information security defense mechanism is triggered to generate target warning information. If the icon password information is consistent with the to-be-matched icon password, the target file decryption is successful.
[0065] The technical scheme of the embodiment is characterized in that when a file access request is received, the finger vein feature and the palm vein feature corresponding to a target subject are acquired, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, the to-be-matched icon password corresponding to the stored vein feature is called, if the to-be-verified icon password corresponding to the trigger operation is consistent with the to-be-matched icon password, it is determined that the target file corresponding to the file access request is successfully decrypted, and the target file is displayed, thereby solving the problem that in the prior art, data is encrypted and decrypted based on a single finger vein feature, and due to a low encryption coefficient, data is easily leaked, realizing preliminary decryption of a file based on a finger vein feature and a palm vein feature, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, it is indicated that the preliminary decryption is successful, and then the to-be-verified icon password generated based on a user trigger operation is used to perform secondary decryption of the file, if the to-be-verified icon password is consistent with the to-be-matched icon password, it is indicated that the secondary decryption is successful, and under the condition that the two times of decryption are successful, the file is allowed to be accessed, greatly increasing a decryption difficulty coefficient, and achieving the technical effect of guaranteeing data security.
[0066] Embodiment three
[0067] Figure 5 A structural block diagram of a file processing device provided in the embodiment three of the application. The device comprises a hand vein feature acquisition module 510, a to-be-matched icon password calling module 520, and a target file display module 530.
[0068] The hand vein feature acquisition module 510 is configured to acquire a hand vein feature corresponding to a target subject when a file access request is received, wherein the hand vein feature comprises a finger vein feature and a palm vein feature.
[0069] The technical scheme of the embodiment is that when a file access request is received, the finger vein feature and the palm vein feature corresponding to the target subject are acquired, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, the to-be-matched icon password corresponding to the stored vein feature is called, if the to-be-verified icon password corresponding to the trigger operation is consistent with the to-be-matched icon password, it is determined that the target file corresponding to the file access request is decrypted successfully, and the target file is displayed, thereby solving the problem that in the prior art, a single finger vein feature is used to perform encryption and decryption operations on data, and due to a low encryption coefficient, data is easily leaked, realizing preliminary decryption of a file based on a finger vein feature and a palm vein feature, if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, it is indicated that the preliminary decryption is successful, and then the to-be-verified icon password generated based on a user trigger operation is used to perform secondary decryption of the file, if the to-be-verified icon password is consistent with the to-be-matched icon password, it is indicated that the secondary decryption is successful, and under the condition that the two times of decryption are successful, the file is allowed to be accessed, greatly increasing a decryption difficulty coefficient, and achieving the technical effect of guaranteeing data security.
[0070] On the basis of the above device, optionally, the hand vein feature acquisition module 510 comprises an acquisition device starting unit and a hand vein feature acquisition unit.
[0071] The acquisition device starting unit is configured to start the acquisition device when a file access request is received.
[0072] The hand vein feature acquisition unit is configured to perform vein acquisition on the target subject based on the acquisition device when it is detected that the target subject is included in the field of view region of the acquisition device, and obtain a hand vein feature.
[0073] On the basis of the above device, optionally, the device further comprises a file encryption module, wherein the file encryption module comprises a to-be-used file acquisition unit, a to-be-processed encrypted image generation unit, a to-be-used icon password acquisition unit, and a target file acquisition unit.
[0074] The to-be-used file acquisition unit is configured to acquire a to-be-used file associated with a target vehicle.
[0075] The to-be-processed encrypted image generation unit is configured to encrypt the to-be-used file based on a hand vein feature corresponding to a target subject, and obtain a to-be-encrypted file; and generate a to-be-processed encrypted image based on the hand vein feature and a preset icon identifier.
[0076] The to-be-used icon password acquisition unit is configured to obtain a to-be-used icon password based on a user trigger operation on the to-be-processed encrypted image.
[0077] The target file acquisition unit is configured to encrypt the to-be-encrypted file based on the to-be-used icon password to obtain an encrypted target file.
[0078] On the basis of the device, optionally, the device further includes a first target early warning information determination module.
[0079] The first target early warning information determination module is configured to determine that decryption of the target file corresponding to the file access request fails and determine target early warning information corresponding to the file access request if the hand vein feature is inconsistent with the stored vein feature associated with the target vehicle.
[0080] On the basis of the device, optionally, the device further includes a second target early warning information determination module, wherein the second target early warning information determination module includes a to-be-decrypted icon image display unit, a to-be-verified icon password generation unit, and a target early warning information determination unit.
[0081] The to-be-decrypted icon image display unit is configured to display a to-be-decrypted icon image, wherein the to-be-decrypted icon image includes at least one icon identifier.
[0082] The to-be-verified icon password generation unit is configured to generate a to-be-verified icon password based on a triggering operation of a user on the to-be-decrypted icon image.
[0083] The target early warning information determination unit is configured to determine that decryption of the target file corresponding to the file access request fails and determine target early warning information corresponding to the file access request if the to-be-verified icon password is inconsistent with the to-be-matched icon password.
[0084] On the basis of the device, optionally, the first target early warning information determination module or the second target early warning information determination module includes a feature attribute value recording unit and a target early warning information determination unit.
[0085] The feature attribute value recording unit is configured to record a feature attribute value corresponding to the target file decryption failure.
[0086] The target early warning information determination unit is configured to determine target early warning information corresponding to the preset feature threshold if the feature attribute value is greater than the preset feature threshold.
[0087] On the basis of the device, optionally, the target file display module 530 includes a target file display unit.
[0088] The target file display unit is configured to determine that the target file corresponding to the file access request has been successfully decrypted if the password of the icon to be verified corresponding to the trigger operation matches the password of the icon to be matched, and to determine the access permissions corresponding to the target file and display the target file.
[0089] The file processing apparatus provided in the embodiments of the present invention can execute the file processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0090] It is worth noting that the various units and modules included in the above-mentioned device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of the present invention.
[0091] Example 4
[0092] Figure 6 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Figure 6 A block diagram is shown of an exemplary electronic device 60 suitable for implementing embodiments of the present invention. Figure 6 The electronic device 60 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0093] like Figure 6 As shown, the electronic device 60 is presented in the form of a general-purpose computing device. The components of the electronic device 60 may include, but are not limited to: one or more processors or processing units 601, system memory 602, and bus 603 connecting different system components (including system memory 602 and processing unit 601).
[0094] Bus 603 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0095] Electronic device 60 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 60, including volatile and non-volatile media, removable and non-removable media.
[0096] System memory 602 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 604 and / or cache memory 605. Electronic device 60 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 606 can be provided for reading from and writing to a non-removable, non-volatile magnetic media (not shown and typically called a "hard drive"). Figure 6 Although not shown, a magnetic disk drive can also be utilized in some embodiments to read from and write to a removable, non-volatile magnetic disk (e.g., a "floppy disk"), and an optical disk drive can be utilized in some embodiments to read from and write to a removable, non-volatile optical disk (e.g., a CD-ROM, DVD-ROM or other optical media). Figure 6 Although not shown, a magnetic disk drive can also be utilized in some embodiments to read from and write to a removable, non-volatile magnetic disk (e.g., a "floppy disk"), and an optical disk drive can be utilized in some embodiments to read from and write to a removable, non-volatile optical disk (e.g., a CD-ROM, DVD-ROM or other optical media).
[0097] Program / utility 608 having a set (at least one) of program modules 607 can be stored in, for example, memory 602 by way of example, and not limiting, the programs can include an operating system, one or more application programs, other program modules, and program data, each of or some combination of which can include implementation of the network environment as described herein. Programs 607 generally carry out the functions and / or methodologies of embodiments of the application as described herein.
[0098] Electronic device 60 can also communicate with one or more external devices 609 such as a keyboard or pointing device, a display 610, etc.; one or more devices that enable a user to interact with electronic device 60; and / or one or more devices that enable electronic device 60 to communicate with one or more other computing devices. Such communication can be via input / output (I / O) interfaces 611. Similarly, such communication can be via network adapter 612, which can be any device or means Figure 6 Other hardware and / or software modules that can be used in conjunction with electronic device 60 can also be employed in some embodiments, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.
[0099] The processing unit 601 performs various function applications and data processing by running programs stored in the system memory 602, such as implementing the file processing method provided by the embodiments of the present application.
[0100] Embodiment five
[0101] The embodiment five of the present application further provides a storage medium containing computer executable instructions, which are used for executing a file processing method when executed by a computer processor. The method comprises the following steps:
[0102] When receiving a file access request, a hand vein feature corresponding to a target subject is acquired, wherein the hand vein feature comprises a finger vein feature and a palm vein feature;
[0103] If the hand vein feature is consistent with a stored vein feature associated with a target vehicle, a to-be-matched icon password corresponding to the stored vein feature is called;
[0104] If a to-be-verified icon password corresponding to a trigger operation is consistent with the to-be-matched icon password, it is determined that decryption of a target file corresponding to the file access request is successful, and the target file is displayed.
[0105] The computer storage medium of the embodiment of the present application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium may, for example, be but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component.
[0106] A computer readable signal medium can include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium can be any computer readable medium that can be involved in
[0107] The computer readable program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0108] Computer program code for carrying out operations of embodiments of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0109] Note that the foregoing are merely preferred embodiments and the principles of the present application. It will be understood by those skilled in the art that the present application is not limited to the specific embodiments described herein, and that various obvious changes, modifications and substitutions can be made to the present application without departing from the scope of the present application. Therefore, although the present application has been described in detail with reference to the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the claims.
Claims
1. A file processing method characterized by, The method comprises the following steps: When a file access request is received, a hand vein feature corresponding to a target subject is acquired, wherein the hand vein feature comprises a finger vein feature and a palm vein feature; If the hand vein feature is consistent with a stored vein feature associated with a target vehicle, a to-be-matched icon password corresponding to the stored vein feature is retrieved; If a to-be-verified icon password corresponding to a trigger operation is consistent with the to-be-matched icon password, it is determined that decryption of a target file corresponding to the file access request is successful, and the target file is displayed; Before the step of acquiring the hand vein feature corresponding to the target subject when the file access request is received, the method further comprises the following steps: A to-be-used file associated with the target vehicle is acquired; Feature points of the finger vein and the palm vein in the hand vein feature corresponding to the target subject are taken as an encryption method, and the to-be-used file is encrypted based on the encryption method to obtain an encrypted file; and a to-be-processed encrypted image is generated based on the hand vein feature and a preset icon identifier; each feature point of the finger vein and the palm vein corresponds to a corresponding icon identifier; A to-be-used icon password is obtained based on a trigger operation of a user on the to-be-processed encrypted image; The to-be-encrypted file is encrypted based on the to-be-used icon password to obtain an encrypted target file.
2. The method of claim 1, wherein, The step of acquiring the hand vein feature corresponding to the target subject when the file access request is received further comprises the following steps: When the file access request is received, a collection device is started; When it is detected that the target subject is included in a field of view region of the collection device, the target subject is collected based on the collection device to obtain a hand vein feature.
3. The method of claim 1, wherein, The method further comprises the following steps: If the hand vein feature is inconsistent with the stored vein feature associated with the target vehicle, it is determined that decryption of the target file corresponding to the file access request fails, and target warning information corresponding to the file access request is determined; wherein the target warning information comprises non-inductive collection information and non-inductive alarm information.
4. The method of claim 1, wherein, After the step of retrieving the to-be-matched icon password corresponding to the stored vein feature if the hand vein feature is consistent with the stored vein feature associated with the target vehicle, the method further comprises the following steps: A to-be-decrypted icon image is displayed; wherein the to-be-decrypted icon image comprises at least one icon identifier; A to-be-verified icon password is generated based on a trigger operation of a user on the to-be-decrypted icon image; If the to-be-verified icon password is inconsistent with the to-be-matched icon password, it is determined that decryption of the target file corresponding to the file access request fails, and target warning information corresponding to the file access request is determined.
5. The method according to claim 3 or 4, characterized in that, The step of determining the target warning information corresponding to the file access request comprises the following steps: A feature attribute value corresponding to the decryption failure of the target file is recorded; If the feature attribute value is greater than a preset feature threshold value, target warning information corresponding to the preset feature threshold value is determined.
6. The method of claim 1, wherein, The step of determining that decryption of the target file corresponding to the file access request is successful if the to-be-verified icon password corresponding to the trigger operation is consistent with the to-be-matched icon password, and displaying the target file, comprises the following steps: If the icon password to be verified corresponding to the trigger operation is consistent with the icon password to be matched, it is determined that decryption of a target file corresponding to the file access request is successful, access permission corresponding to the target file is determined, and the target file is displayed.
7. A file processing apparatus characterized by comprising: Comprise: A hand vein feature acquisition module is configured to acquire a hand vein feature corresponding to a target subject when a file access request is received, wherein the hand vein feature comprises a finger vein feature and a palm vein feature; A to-be-matched icon password calling module is configured to call a to-be-matched icon password corresponding to a stored vein feature associated with a target vehicle if the hand vein feature is consistent with the stored vein feature; A target file display module is configured to determine that decryption of a target file corresponding to the file access request is successful if a to-be-verified icon password corresponding to a trigger operation is consistent with the to-be-matched icon password, and display the target file; The device further comprises a file encryption module, wherein the file encryption module comprises a to-be-used file acquisition unit, a to-be-processed encrypted image generation unit, a to-be-used icon password acquisition unit, and a target file acquisition unit; The to-be-used file acquisition unit is configured to acquire a to-be-used file associated with a target vehicle; The to-be-processed encrypted image generation unit is configured to use feature points of finger veins and palm veins in a hand vein feature corresponding to a target subject as an encryption method, encrypt the to-be-used file based on the encryption method to obtain an encrypted file, and generate a to-be-processed encrypted image based on the hand vein feature and a preset icon identifier, wherein each feature point of a finger vein and a palm vein corresponds to a corresponding icon identifier; The to-be-used icon password acquisition unit is configured to obtain a to-be-used icon password based on a trigger operation of a user on the to-be-processed encrypted image; The target file acquisition unit is configured to encrypt the encrypted file based on the to-be-used icon password to obtain an encrypted target file.
8. An electronic device, comprising: The device comprises: One or more processors; A storage device configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the file processing method of any one of claims 1-6.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the file processing method of any one of claims 1-6.
Citation Information
Patent Citations
Vein identification technology-based data security protection method and system
CN103455744A
Face login method and device, computer equipment and storage medium
CN110532744A