A file access control method, device, electronic device and storage medium
By encrypting the file and building virtual files, combined with biometric data verification, the problem of data being stolen after user accounts are learned by others is solved, achieving higher file confidentiality and data security.
Patent Information
- Application Number
- CN202210480450.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-05
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-05-05
AI Technical Summary
The prior art cannot effectively solve the problem that confidential data is stolen or read after the same user account is known by others, and the file may still be brute-forced after the authorized user leaves the terminal.
By encrypting the first file, a virtual file with meaningless content is built, and matching verification is used using biometric data to obtain the key to decrypt the file, ensuring that only authorized users can access the encrypted file.
It effectively prevents unauthorized users from obtaining file content by forging biometric data or brute-force cracking, improving the confidentiality and data security of files.
Smart Images

Figure CN114969777B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data security technologies, and in particular, to a file access control method, apparatus, electronic device, and storage medium. Background Art
[0002] In the information age, more attention is paid to the security of information data. In daily life or work, most users store data in terminals, such as storing work files in laptops. For files with privacy requirements, it is hoped that they can have better confidentiality, such as being enabled only for users with permissions, while users without permissions cannot enable them.
[0003] There are various existing methods to improve file confidentiality. For example, photos taken by a camera or stored on a machine are analyzed and processed to extract the facial portrait information in these pictures and store it in an information machine, and corresponding user permissions are assigned to these facial portraits by an administrator. This method cannot solve the problem that the same user account is known by others, resulting in the theft or reading of confidential data; there is also a method of obtaining an application startup instruction, actively obtaining the user's biometric characteristics according to the application startup instruction, and when the obtained user biometric characteristics match the preset biometric characteristics, an encrypted content list and a non-encrypted content list are displayed. Even though this method encrypts the file through biometric identification technology, when the user with permissions leaves the terminal, the file may still be found and brute-forced by other users, and even if the content of the brute-forced file is encrypted, there is still a possibility of being decrypted by other users. Summary of the Invention
[0004] The present disclosure provides a file access control method, apparatus, electronic device, and storage medium to at least solve the above technical problems existing in the prior art.
[0005] On the one hand, the present disclosure provides a file access control method, including: encrypting a first file to obtain an encrypted file;
[0006] Constructing a virtual file according to the first biometric data of a first user, the file index corresponding to the first file, and a second file with meaningless content, and displaying the icon of the virtual file;
[0007] In response to an instruction from a second user to access the virtual file, obtaining the second biometric data of the second user;
[0008] Determining that the second biometric data matches the first biometric data, obtaining the first key corresponding to the first user, opening and displaying the virtual file, and obtaining the second key determined by the second user according to the opened virtual file, and calculating the file index according to the first key and the second key;
[0009] Search for the corresponding encrypted file and the corresponding file attribute information according to the calculated file index;
[0010] After decrypting the found encrypted file, combine it with the file attribute information to obtain the corresponding first file, and display the obtained first file for the second user to access.
[0011] In an implementable manner, the constructing the virtual file includes:
[0012] Calculate the first key according to the first biometric data of the first user;
[0013] Calculate the second key according to the first key and the file index;
[0014] Hide the second key in the file content of the second file according to the preset condition input by the first user to obtain the virtual file.
[0015] In an implementable manner, the calculating the first key according to the first biometric data of the first user includes:
[0016] Obtain multiple biometric data of the same biometric part of the first user, and calculate the first key according to the multiple biometric data.
[0017] In an implementable manner, the encrypting the first file to obtain an encrypted file includes:
[0018] Convert the file content of the first file into a binary format, and encrypt the file content in the binary format using an encryption algorithm to obtain an encrypted file.
[0019] In an implementable manner, after encrypting the first file to obtain an encrypted file, the method further includes:
[0020] Obtain the file attribute information of the first file, store the file attribute information and the encrypted file in a database, so that the database generates a file index corresponding to the encrypted file, and establish an association relationship among the file attribute information, the encrypted file, and the file index.
[0021] On the other hand, the present disclosure provides a device, including:
[0022] A processing module, configured to encrypt a first file to obtain an encrypted file;
[0023] The processing module is further configured to construct a virtual file according to the first biometric data of the first user, the file index corresponding to the first file, and a second file with meaningless content, and display the icon of the virtual file;
[0024] An identification module, configured to obtain second biometric data of the second user in response to an instruction for the second user to access the virtual file;
[0025] The identification module is further configured to determine that the second biometric data matches the first biometric data, obtain a first key corresponding to the first user, open and display the virtual file, and then obtain a second key input by the second user, and calculate a file index according to the first key and the second key;
[0026] A transmission module, configured to find a corresponding encrypted file and corresponding file attribute information according to the calculated file index;
[0027] An analysis module, configured to decrypt the found encrypted file and combine it with the file attribute information to obtain a corresponding first file, and display the obtained first file for the second user to access.
[0028] In an implementable manner, the processing module is further configured to calculate a first key according to the first biometric data of the first user;
[0029] Calculate a second key according to the first key and the file index;
[0030] Hide the second key in the file content of the second file according to the preset condition to obtain the virtual file.
[0031] In an implementable manner, the processing module is further configured to obtain multiple biometric data of the same biometric part of the first user, and calculate the first key according to the multiple biometric data.
[0032] On the other hand, the present disclosure provides an electronic device, including: a memory and a processor, where the memory stores a computer program executable by the processor, and when the processor executes the computer program, the above file access control method is implemented.
[0033] On the other hand, the present disclosure provides a storage medium, characterized in that a computer program is stored on the storage medium, and when the computer program is read and executed, the above file access control method is implemented.
[0034] Based on the above solution, the present disclosure provides a file access control method. After encrypting the first file to obtain an encrypted file, it is stored, and a virtual file with meaningless content is constructed for display. The second biometric data corresponding to the second user accessing the virtual file is obtained and compared with the first biometric data of the stored first user. If they match, the first key is obtained to open the virtual file. If the virtual file is brute-forced or the first biometric data is forged by the wrong second user to open, since the second key is unknown, only meaningless file content can be obtained, ensuring that the first file is not leaked. If the second user is the correct user, after opening the virtual file, the second key can be provided, and the file index is calculated by combining the first key returned due to the matching of biometric data to find the encrypted file. In this way, through two verifications, the access permission of the virtual file can be controlled, improving the security of information data. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 The figure shows a schematic flow diagram of a file access control method provided by an embodiment of the present disclosure;
[0036] Figure 2 The figure shows a schematic diagram of a method for forming an encrypted file provided by an embodiment of the present disclosure;
[0037] Figure 3 The figure shows a schematic diagram of a method for calculating and reverse calculating a file index provided by an embodiment of the present disclosure;
[0038] Figure 4 The figure shows a schematic diagram of a file access control device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0039] To make the objectives, features, and advantages of the present disclosure more obvious and understandable, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present disclosure.
[0040] To improve the security of data information, as Figure 1 shown, an embodiment of the present disclosure provides a file access control method, including:
[0041] Step 101, encrypt the first file to obtain an encrypted file.
[0042] The first file is a file for which the first user wants to control the access permission. For example, it can be a file in the form of a word document, a PDF document, or a TXT document, etc. The above is only an example, and no specific limitation is made here.
[0043] Encrypting the first file may include encrypting the content of the first file and constructing an encrypted file corresponding to the file content of the first file. In one example, after the encrypted file is constructed, it can be stored in a database.
[0044] Step 102: Construct a virtual file according to the first biometric data of the first user, the file index corresponding to the first file, and the second file with meaningless content, and display the icon of the virtual file.
[0045] The first biometric data of the first user is pre-collected and stored in a database, where the first user is the correct user granted access rights to the corresponding document. The first biometric data includes the user's facial features, iris features, fingerprint data, etc., as long as it can be used to identify a unique user, and no specific limitation is made here.
[0046] In the above step 101, when the encrypted file is stored in the database, the database generates a file index corresponding to the encrypted file, which is the file index corresponding to the first file. At the same time, this file index is associated with the file attribute information of the first file.
[0047] Among them, the file content of the second file is meaningless. Meaningless content means that relative to the content of the first file, it can be content presented as garbled characters or public data content that does not need to be hidden.
[0048] After the virtual file is constructed, the icon of the virtual file can be displayed for users to access.
[0049] The virtual file constructed based on the second file with meaningless content enables unauthorized users to only obtain meaningless content and cannot access the first file even if they crack the virtual file by means of forging the first biometric data, etc.
[0050] Step 103: In response to an instruction from the second user to access the virtual file, obtain the second biometric data of the second user.
[0051] In one example, when the second user triggers a virtual file, an instruction for accessing the virtual file may be generated. In response to this instruction, the biometric collection module is awakened to obtain the second biometric data of the second user for comparison with the first biometric data in the database. For example, a camera or an image sensor may be installed on the device for displaying the virtual file as the biometric collection module for collecting images, and a connection between the virtual file and the biometric collection module is established. When the virtual file is triggered, the camera or the image sensor captures a facial photo of the second user, and the second biometric data is extracted from the facial photo. If the first biometric data corresponding to the first user stored in the database is for the iris feature part, then the iris feature data of the second user is extracted from the captured facial photo. As another example, a touchpad or a sound collection device may be installed on the device for displaying the virtual file as the biometric collection module for collecting fingerprints or voices, and a connection between the virtual file and the biometric collection module is established. When the virtual file is triggered, the touchpad and the sound collection device are activated and can be used to collect the fingerprints or voices of the second user, which are directly used as the second biometric data, or the second biometric data is extracted from the collected fingerprints or voices. Specifically, it should be determined according to actual needs, and only examples are given here without specific limitations. In addition, it should be emphasized that the ways to trigger the virtual file include but are not limited to single-click, double-click, touch, or voice interaction, etc.
[0052] Step 104, determine that the second biometric data matches the first biometric data, obtain the first key corresponding to the first user, open and display the virtual file, and obtain the second key determined by the second user according to the opened virtual file. Calculate the file index according to the first key and the second key.
[0053] In one example, in response to the instruction for accessing the virtual file, the second biometric data of the second user is obtained and compared with the first biometric data in the database. If the comparison is correct, that is, they match, it indicates that the second user is an authorized user, or the second user forged the first biometric data. Then, the virtual file is opened and displayed. At this time, even if the second user forged the first biometric data to crack the virtual file, the file content they see is still meaningless, ensuring that the first file is not leaked. If the comparison is incorrect, the virtual file is not opened.
[0054] In the present disclosure, after the biometric data match is successful, only the virtual file is opened. To open the first file, two keys need to be obtained:
[0055] In one example, the first key is associated with the first user, and the first key associated with the first user can be recorded in the database. Then, when the biometric data comparison is correct, obtain the user information corresponding to the correctly compared first biometric data (i.e., the information of the first user). For example, if the nth iris feature data is correctly compared, obtain the user information corresponding to the nth iris feature data, assumed to be Zhang San. Query the corresponding first key through Zhang San and return the first key. Among them, the first key can be pre-stored in the database and has been associated with the first user.
[0056] In one example, the second key is hidden in a virtual file. If the second user is the correct user, the second key can be found from the file content of the virtual file, that is, the correct user has a way to find the second key.
[0057] After obtaining the first key and the second key, the file index of the encrypted file can be calculated to find the encrypted file.
[0058] If the second key is incorrect, the correct file index cannot be calculated by combining the first key with the incorrect second key, so the encrypted file cannot be found.
[0059] Step 105: Find the corresponding encrypted file and the corresponding file attribute information according to the calculated file index.
[0060] In one example, the corresponding encrypted file and the associated file attribute information can be found from the database according to the file index.
[0061] Step 106: After decrypting the found encrypted file, combine it with the file attribute information to obtain the corresponding first file, and display the obtained first file for the second user to access.
[0062] In one example, decrypting the found encrypted file can obtain the file content of the first file. Combine the file content with the corresponding file attribute information to obtain the first file, and then save it in the original position of the first file to avoid possible problems that the file attribute information may change due to storage after encryption. For example, compared with the original first file, the modification time in the file attribute information of the restored first file can also remain unchanged.
[0063] The present disclosure encrypts a first file to obtain an encrypted file and then stores it, constructs a virtual file with meaningless content for display, obtains second biometric data corresponding to a second user accessing the virtual file, and compares it with the first biometric data of the stored first user. If they match, the first key is obtained to open the virtual file. If the virtual file is brute-forced or the first biometric data is forged by the wrong second user to open it, the second key cannot be known due to the unknown preset conditions, and only meaningless file content can be obtained, ensuring that the first file is not leaked. If the second user is the correct user, after opening the virtual file, the second key can be derived according to the preset conditions known in advance, and the file index can be calculated by combining the first key returned due to the matching of biometric data to search for the encrypted file. In this way, through two verifications, the access permission of the virtual file can be controlled, and the security of information data can be improved.
[0064] In one example, step 101, encrypting the first file to obtain an encrypted file includes: converting the file content of the first file into a binary format, and using an encryption algorithm to encrypt the file content in binary format to obtain an encrypted file.
[0065] The encryption algorithm includes the SHA256 encryption algorithm, which is only used for listing here and is not specifically limited. As long as it can implement the encryption means.
[0066] In one example, after converting the file content of the first file into binary, as Figure 2 shown, shuffle and reorder the order of the binary format, and then insert different blocks at intervals. The blocks can be meaningless garbled characters to obtain the encrypted file content. The encryption means here is only for example and is not specifically limited.
[0067] Encrypting the content of the first file improves the information security of the file.
[0068] In one example, after encrypting the first file to obtain an encrypted file, it further includes:
[0069] Obtaining the file attribute information of the first file, and storing the file attribute information and the encrypted file in a database, so that the database generates a file index corresponding to the encrypted file, and establishes an association relationship among the file attribute information, the encrypted file, and the file index.
[0070] In one example, it is also necessary to obtain the file attribute information of the first file, and store the file attribute information and the encrypted file in the database, so that the database generates a file index corresponding to the encrypted file, and establishes an association relationship among the file attribute information, the encrypted file, and the file index. It should be understood that the encrypted file is obtained by encrypting the first file, so the file index corresponding to the encrypted file is the file index that can be used to obtain the corresponding first file accordingly.
[0071] In one example, obtaining the file attribute information of the first file includes obtaining the file name, creation date, and readability of the first file, etc.
[0072] In one example, in step 102, the process of constructing the virtual file includes:
[0073] Calculating a first secret key according to the first biometric data of the first user;
[0074] Calculating a second secret key according to the first secret key and the file index;
[0075] Hiding the second secret key in the file content of the second file according to the preset condition input by the first user to obtain the virtual file.
[0076] Among them, the first secret key can be calculated in advance according to the first biometric data, stored in the database, and an associated relationship is established with the user information of the first user.
[0077] In one example, as Figure 3 shown, according to the first secret key and the file index (generated when the encrypted file is stored in the database), the second secret key can be calculated. The calculation method can be permutation, arithmetic operations of addition, subtraction, multiplication, and division, or splitting, etc., as long as the reverse calculation can be realized again. In this way, it can be ensured that the file index is calculated by the first secret key and the second secret key in step 104. It should be understood that the plus sign in the figure does not represent the addition operation, but only refers to using the first secret key and the file index or using the second secret key and the first secret key.
[0078] Hiding the second secret key in the file content of the second file according to the preset condition. The preset condition is the rule or calculation method for obtaining the second secret key, that is, the preset condition corresponds to the method when the second secret key is hidden in the virtual file and is only known to the first user. It should be understood that when constructing the virtual file, the preset condition for hiding the second secret key is input by the first user.
[0079] The preset conditions include, but are not limited to: the second key is superimposed on the virtual file according to a certain rule, or inserted at intervals in the text of a certain row and a certain column in a certain way. If the second user is the correct user, they will necessarily know, or can know from the first user, the preset conditions. As long as the second key is obtained by processing the content of the virtual file according to the preset conditions known in advance, or the second key is found from the content of the virtual file. Or extract the content of the second file to form an ordered form, and superimpose it in the frequency domain or hide it somewhere in the text by means of digital watermarking to construct the virtual file. If the second user is the correct user, they will necessarily know, or can know from the first user, the preset conditions, and input the preset conditions so that the device installed with the virtual file can directly obtain the second key according to the preset conditions. Specifically, no specific limitation is made here. The virtual file is saved according to the original path of the first file.
[0080] It should be understood that the preset conditions are only informed to users with access rights to the document. Therefore, through the calculation and hiding of the second key, the virtual file is further encrypted. Even if there is a situation where an incorrect second user forges biometric data to achieve a match to open the virtual file, as long as the second user does not know the above-mentioned preset conditions, they will not be able to obtain the second key due to not knowing the preset conditions, and thus will not be able to calculate the file index to find the encrypted file, further improving security.
[0081] In one example, in step 102, calculating the first key according to the first biometric data of the first user includes: obtaining multiple pieces of first biometric data of the same biometric part of the first user, and calculating the first key according to the multiple pieces of first biometric data.
[0082] Among them, the first key can be the checksum of multiple pieces of biometric data, or other calculation methods, which are not specifically limited here. For example, 5 times of iris feature data of the user can be collected, the 5 times of iris feature data are stored in the database, and the first key is calculated from the 5 times of iris feature data, and the obtained first key is also stored in the database. The 5 times of iris feature data and the first key are associated through user information.
[0083] If the user information is Zhang San, then the 5 times of iris feature data all correspond to Zhang San, and the first key can be stored separately in the database, corresponding to Zhang San. By verifying the correct iris feature data, the corresponding first key can be found through Zhang San.
[0084] By obtaining multiple pieces of first biometric data of the same biometric part for storage, the accuracy of the matching of the second biometric data provided by the second user can be improved.
[0085] In one example, taking electronic devices such as notebooks, tablets, and mobile phones as the hosting entities, the present disclosure also provides a framework capable of executing the above method, including:
[0086] A front end, a back end, and a database.
[0087] The front end collects the first biometric data input by the first user, selects the first file to be hidden from the desktop position and places it in a specified position, and then sends it to the back end for processing.
[0088] The back end receives the first biometric data provided by the front end, processes the first biometric data to obtain a first secret key, transmits the first biometric data and the first secret key to the database for storage, and associates the first biometric data and the first secret key through the user information of the first user.
[0089] The back end also receives the first file provided by the front end, extracts the file content and file attribute information of the first file, converts and encrypts the file content to obtain an encrypted file, and transmits the encrypted file and the file attribute information to the database, so that the database associates and stores the encrypted file and the file attribute information, and generates a file index corresponding to the encrypted file and the file attribute information.
[0090] The back end is also used to calculate the file index and the first secret key to generate a second secret key, hide the second secret key in a second file with meaningless content under a preset condition to construct a virtual file, and transmit the virtual file to the original storage position of the first file on the front end, and return the preset condition to the first user on the front end.
[0091] The back end is also used to respond to the instruction for accessing the virtual file. When the second user triggers the virtual file on the front end, the back end collects the biometric data of the second user and compares it with the biometric data of the first user in the database until the comparison is correctly judged to match. Then, it obtains the user information of the first user corresponding to the correctly matched biometric data, obtains the corresponding first secret key, and opens the virtual file to obtain the second secret key determined by the second user according to the virtual file. According to the first secret key and the second secret key, it calculates the file index, obtains the encrypted file and the file attribute information from the database, decrypts the encrypted file and combines it with the file attribute information to obtain the first file; if the comparison is not correct, the virtual file is not opened.
[0092] An embodiment of the present disclosure also provides a file access control device, as Figure 4 shown. This device is applied to the back end and includes:
[0093] A processing module 10, configured to encrypt the first file to obtain an encrypted file;
[0094] The processing module 10 is further configured to construct a virtual file according to the first biometric data of the first user, the file index corresponding to the first file, and a second file with meaningless content, and display the icon of the virtual file;
[0095] The processing module 10 is further configured to calculate a first key according to the first biometric data of the first user;
[0096] Calculate a second key according to the first key and the file index;
[0097] Hide the second key in the file content of the second file according to the preset condition input by the first user to obtain the virtual file;
[0098] The processing module 10 is further configured to obtain multiple biometric data of the same biometric part of the first user, and calculate the first key according to the multiple biometric data;
[0099] The processing module 10 is further configured to convert the file content of the first file into a binary format, and encrypt the file content in the binary format using an encryption algorithm to obtain an encrypted file;
[0100] The recognition module 20 is configured to, in response to an instruction from a second user to access the virtual file, obtain the second biometric data of the second user;
[0101] The recognition module 20 is further configured to determine that the second biometric data matches the first biometric data, obtain the first key corresponding to the first user, open and display the virtual file, and obtain the second key determined by the second user according to the virtual file, and calculate the file index according to the first key and the second key;
[0102] The recognition module 20 is further configured to obtain the file attribute information of the first file, store the file attribute information and the encrypted file in a database, so that the database generates a file index corresponding to the encrypted file, and establish an association relationship among the file attribute information, the encrypted file, and the file index;
[0103] The transmission module 30 is configured to search for the corresponding encrypted file and the corresponding file attribute information according to the calculated file index.
[0104] The analysis module 40 is configured to decrypt the retrieved encrypted file and combine it with the file attribute information to obtain the corresponding first file, and display the obtained first file for the second user to access.
[0105] The present disclosure also provides a computer-readable storage medium storing a computer program for executing the file access control method of the present disclosure.
[0106] On the other hand, the present disclosure also provides an electronic device, comprising:
[0107] a processor;
[0108] a memory for storing executable instructions of the processor;
[0109] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the file access control method of the present disclosure.
[0110] In addition to the above methods and devices, embodiments of the present application may also be computer program products, which include computer program instructions that, when run on a processor, cause the processor to execute the steps in the methods according to various embodiments of the present application described in the "Exemplary Methods" section above of this specification.
[0111] The computer program products may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present application. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The programming code may be executed entirely on a user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0112] Furthermore, embodiments of the present application may also be computer-readable storage media storing computer program instructions that, when run on a processor, cause the processor to execute the steps in the methods according to various embodiments of the present application described in the "Exemplary Methods" section above of this specification.
[0113] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0114] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present application. In addition, the above-disclosed specific details are only for the purpose of illustration and facilitating understanding, rather than limitations. These details do not limit the present application to necessarily adopt the above specific details for implementation.
[0115] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present application are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with them. The word "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0116] It should also be noted that in the devices, equipment, and methods of the present application, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations shall be regarded as equivalent solutions of the present application.
[0117] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be very apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0118] The foregoing description has been presented for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.
Claims
1. A file access control method, characterized in that, Including: Encrypting the first file to obtain an encrypted file; Constructing a virtual file based on the first biometric data of the first user, the file index corresponding to the first file, and a second file with meaningless content, and displaying the icon of the virtual file; In response to an instruction from a second user to access the virtual file, obtaining the second biometric data of the second user; Determining that the second biometric data matches the first biometric data, obtaining the first key corresponding to the first user, opening and displaying the virtual file, and obtaining the second key determined by the second user based on the opened virtual file, and calculating the file index according to the first key and the second key; Searching for the corresponding encrypted file and the corresponding file attribute information according to the calculated file index; Decrypting the found encrypted file and combining it with the file attribute information to obtain the corresponding first file, and displaying the obtained first file for the second user to access.
2. The file access control method according to claim 1, wherein The constructing of the virtual file includes: Calculating a first key according to the first biometric data of the first user; Calculating a second key according to the first key and the file index; Hiding the second key in the file content of the second file according to a preset condition input by the first user to obtain the virtual file.
3. The file access control method according to claim 2, wherein The calculating of the first key according to the first biometric data of the first user includes: Obtaining multiple biometric data of the same biometric part of the first user, and calculating the first key according to the multiple biometric data.
4. The file access control method according to any one of claims 1 to 3, characterized in that, The encrypting of the first file to obtain an encrypted file includes: Converting the file content of the first file into a binary format, and encrypting the file content in binary format using an encryption algorithm to obtain an encrypted file.
5. The file access control method according to claim 1, characterized in that After encrypting the first file to obtain an encrypted file, the method further includes: Obtaining the file attribute information of the first file, and storing the file attribute information and the encrypted file in a database, so that the database generates a file index corresponding to the encrypted file, and establishing an association relationship among the file attribute information, the encrypted file, and the file index.
6. A file access control device, characterized in that, Including: A processing module for encrypting the first file to obtain an encrypted file; The processing module is further configured to construct a virtual file based on the first biometric data of the first user, the file index corresponding to the first file, and a second file with meaningless content, and display the icon of the virtual file; An identification module for obtaining the second biometric data of the second user in response to an instruction from the second user to access the virtual file; The identification module is further configured to determine that the second biometric data matches the first biometric data, obtain the first key corresponding to the first user, open and display the virtual file, and obtain the second key determined by the second user based on the virtual file, and calculate the file index according to the first key and the second key; A transmission module for searching for the corresponding encrypted file and the corresponding file attribute information according to the calculated file index; An analysis module, configured to decrypt the found encrypted file and combine it with the file attribute information to obtain a corresponding first file, and display the obtained first file for the second user to access.
7. The file access control device according to claim 6, wherein the processing module is further configured to calculate a first key according to the first biometric data of the first user; calculate a second key according to the first key and the file index; hide the second key in the file content of the second file according to a preset condition to obtain the virtual file, and return the preset condition to the first user.
8. The file access control device according to claim 7, wherein the processing module is further configured to obtain multiple biometric data of the same biometric part of the first user, and calculate the first key according to the multiple biometric data.
9. An electronic device, characterized in that, Comprising: a memory and a processor, the memory stores a computer program executable by the processor, and when the processor executes the computer program, the file access control method according to any one of claims 1-5 above is implemented.
10. A storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is read and executed, the file access control method according to any one of claims 1-5 above is implemented.
Citation Information
Patent Citations
Method and device for disguising hidden ciphertext
CN111131008A
Encrypted source code file processing method and device, computer equipment and storage medium
CN111177749A