A PDF format document encryption method and device and storage medium
By combining data segmentation, reordering, and secondary segmentation encryption methods with preset encryption methods and operation permission settings, the problem of low security of PDF documents is solved, and multi-layer protection of encrypted documents is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XIAMEN YINMO INFORMATION TECH CO LTD
- Filing Date
- 2022-05-11
- Publication Date
- 2026-04-24
AI Technical Summary
Existing PDF documents have low security and cannot effectively protect sensitive information, posing a risk of leakage.
A multi-layered encryption method combining data segmentation, reordering, and secondary segmentation is used to encrypt PDF documents, and protection is provided through preset encryption methods and operation permission settings.
It enhances the security of PDF documents, prevents encryption rules from being easily cracked, avoids data leakage, and achieves dual protection and multiple defenses.
Smart Images

Figure CN114969810B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of document encryption technology, and in particular to a method for encrypting PDF format documents, an apparatus for applying the method, and a computer-readable storage medium. Background Technology
[0002] PDF (Portable Document Format) is a file format developed by Adobe Systems for exchanging files in a way that is independent of applications, operating systems, and hardware. Based on the PostScript language's image model, PDF files guarantee accurate colors and print quality on any printer; that is, PDF faithfully reproduces every character, color, and image of the original document.
[0003] Based on the aforementioned characteristics of PDF, it has become an ideal document format for electronic document distribution and digital information dissemination on the Internet. Therefore, the application of PDF files is increasing in many fields; more and more e-books, product manuals, company announcements, online materials, and emails are beginning to use PDF files.
[0004] However, due to the ease with which electronic documents can be copied, accessed, and transmitted, leaks of confidential documents can cause serious losses. Existing PDF document management systems only provide archiving capabilities and cannot effectively control sensitive files, resulting in low document security. Summary of the Invention
[0005] The main objective of this invention is to provide a method, apparatus, and storage medium for encrypting PDF documents, aiming to solve the technical problem of low security of PDF documents in the prior art.
[0006] To achieve the above objectives, this invention provides a PDF document encryption method, comprising the following steps: obtaining an initial document and segmentation parameters, wherein the initial document is a PDF document; performing data segmentation processing on the initial document based on the segmentation parameters, dividing the data within the initial document into N data blocks, obtaining data block B1, data block B2... data block B... N Where N > 3; Reorder N data blocks. After randomly sorting the N data blocks, save the data blocks according to the random sorting result to generate a reordered document; Perform secondary segmentation on the reordered document to generate a first encrypted document and a second encrypted document; Send the first encrypted document to the server and output the second encrypted document to the specified path.
[0007] Optionally, the splitting parameters include a splitting quantity parameter and a splitting size parameter, and obtaining the splitting parameters means obtaining preset splitting parameters and / or obtaining randomly generated splitting parameters.
[0008] Optionally, the secondary splitting process is specifically: performing data extraction on the re-ordered document; the first encrypted document includes the data content obtained by the data extraction, and the second encrypted document includes the remaining data content after the data extraction.
[0009] Optionally, the data extraction is specifically: performing data extraction according to a data extraction object, a data extraction range, and a data extraction length; the extraction object is all data blocks or part of the data blocks, the data extraction range is the head or tail data of the extraction object, and the data extraction length is less than the total data length of the extraction object.
[0010] Optionally, it further includes pre-encrypting the document according to a preset encryption method. The pre-encryption specifically includes the following steps: obtaining the data length L in the document, randomly dividing the document into multiple source matrices of n*n, where n is the matrix length, and randomly obtaining a row offset d based on the matrix length n, where 1 < d < n, transforming the source matrix into an encrypted matrix according to the row offset d; obtaining an encryption key based on the matrix length n and the row offset d, and performing key encryption on the document.
[0011] Optionally, sending the first encrypted document to the server, and at the same time sending the encryption information to the server; before outputting the second encrypted document to the specified path, adding an encrypted document identifier to the second encrypted document.
[0012] Optionally, the encryption information includes at least one of the document name of the encrypted document, the check code of the encrypted document, the creator id of the encrypted document, the encryption method of the encrypted document, the encryption key of the encrypted document, the size of each data block in the encrypted document, and the serial number of each data block. Corresponding to the aforementioned PDF document encryption method, this invention provides a PDF document encryption device, comprising: a document acquisition module for acquiring an initial document and segmentation parameters, wherein the initial document is a PDF document; and a data segmentation processing module for performing data segmentation processing on the initial document based on the segmentation parameters, dividing the data within the initial document into N data blocks to obtain data block B1, data block B2, ..., data block B1. N Where N > 3; the reordering module is used to reorder N data blocks. After the N data blocks are randomly sorted, the data blocks are saved according to the random sorting result to generate a reordered document; the secondary segmentation module is used to perform secondary segmentation on the reordered document to generate a first encrypted document and a second encrypted document; and sends the first encrypted document to the server and outputs the second encrypted document to the specified path.
[0015] In addition, to achieve the above objectives, the present invention also provides a computer-readable storage medium storing a PDF format document encryption program, which, when executed by a processor, implements the steps of the PDF format document encryption method described above.
[0016] The beneficial effects of this invention are:
[0017] (1) The PDF document encryption method of the present invention encrypts PDF documents by combining data segmentation processing, reordering and secondary segmentation, thereby improving the security of PDF documents;
[0018] (2) By obtaining the segmentation parameters and performing data segmentation processing based on the segmentation parameters, the security of encrypted documents is further improved by obtaining randomly generated segmentation parameters, which can prevent the encryption rules from being easily cracked and causing the leakage of encrypted document content;
[0019] (3) Data is extracted from the reordered documents through secondary segmentation; the first encrypted document and the second encrypted document are stored separately to avoid the major loss caused by the loss of all data after the encrypted documents are leaked.
[0020] (4) The document is pre-encrypted by a preset encryption method, so that the document readers on the market cannot parse the encrypted document. Only the reader bound by the preset encryption method can parse and view the document, effectively preventing the leakage of encrypted document content;
[0021] (5) By saving the encrypted information, the encrypted information can be checked one by one during decryption. Only after the verification is consistent can the encrypted document be successfully opened, thus playing a dual protection role for the encrypted document.
[0022] (6) By setting operation permissions and operation records for the second encrypted document, operation permissions are set during decryption, which provides multiple protections for the encrypted document; furthermore, by automatically saving user operation records, the creator of the encrypted document can know the relevant information of the document operator or the document operation information, and prevent the theft of document content in a timely manner. Attached Figure Description
[0023] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:
[0024] Figure 1 This is a simplified flowchart of the PDF document encryption method of the present invention;
[0025] Figure 2 This is a schematic diagram of the PDF document encryption method of the present invention;
[0026] Figure 3 This is a schematic diagram of data extraction in the PDF document encryption method of the present invention. Detailed Implementation
[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0028] like Figure 1 As shown, the present invention provides a PDF document encryption method, which includes the following steps: obtaining an initial document and segmentation parameters, wherein the initial document is a PDF document; performing data segmentation processing on the initial document based on the segmentation parameters, dividing the data in the initial document into N data blocks, obtaining data block B1, data block B2... data block B... N Where N > 3; Reorder N data blocks. After randomly sorting the N data blocks, save the data blocks according to the random sorting result to generate a reordered document; Perform secondary segmentation on the reordered document to generate a first encrypted document and a second encrypted document; Send the first encrypted document to the server and output the second encrypted document to the specified path.
[0029] Please refer to Figure 2The PDF document encryption method of the present invention encrypts PDF documents by combining data segmentation processing, reordering, and secondary segmentation, thereby improving the security of PDF documents.
[0030] In this embodiment, the segmentation parameters include the number of segments and the segmentation size. Obtaining the segmentation parameters involves obtaining preset segmentation parameters and / or obtaining randomly generated segmentation parameters.
[0031] Specifically, since the segmentation parameters are divided into segmentation quantity parameters and segmentation size parameters, the methods for obtaining the segmentation parameters are as follows: obtaining the preset segmentation quantity parameter and the preset segmentation size parameter; or obtaining the preset segmentation quantity parameter and obtaining the random segmentation size parameter; or obtaining the random segmentation quantity parameter and obtaining the preset segmentation size parameter; or obtaining the random segmentation quantity parameter and the random segmentation size parameter.
[0032] In this embodiment, the number of segments parameter is used to limit the number of data blocks to be segmented, and the segment size parameter is used to limit the data size of each data block after segmentation.
[0033] This invention further improves the security of encrypted documents by obtaining randomly generated segmentation parameters, which can prevent the encryption rules from being easily cracked and causing the leakage of encrypted document content.
[0034] In this embodiment, the secondary segmentation process specifically involves data extraction from the reordered document; the first encrypted document includes the extracted data content, and the second encrypted document includes the remaining data content after data extraction. Specifically, data extraction is performed based on the data extraction object, the data extraction range, and the data extraction length; the extraction object is all or part of the data blocks, the data extraction range is the header or tail of the extraction object, and the data extraction length is less than the total length of the extracted object's data.
[0035] Please refer to Figure 3 Preferably, the data extraction target is a portion of the data blocks, the data extraction range is the tail data of each data block, and the data extraction length is 300 bytes. It should be noted that, for ease of illustration, the extraction length of the extraction target is a uniform length here, but data extraction can also be performed randomly based on the total data length of each data segment.
[0036] This invention extracts data from reordered documents through a two-stage segmentation process; and stores the first encrypted document and the second encrypted document separately to avoid the significant loss caused by the complete loss of data after the encrypted document is leaked.
[0037] Preferably, when acquiring the initial document, it is preprocessed, and the preprocessing at least includes deleting the document header and the document footer. The document header and the document footer are fixed-format strings used to identify that the document is a PDF. By deleting the document header and the document footer, unnecessary data is reduced, and the subsequent encryption workload is alleviated.
[0038] In this embodiment, it further includes pre-encrypting the document according to a preset encryption method. The pre-encryption specifically includes the following steps: acquiring the data length L in the document, randomly dividing the document into multiple source matrices of n*n, where n is the matrix length, and randomly acquiring a row offset d based on the matrix length n, where 1 < d < n, and transforming the source matrix into an encrypted matrix according to the row offset d; acquiring an encryption key based on the matrix length n and the row offset d and performing key encryption on the document, where the key structure is: matrix length n + row offset d.
[0039] In this embodiment, transforming the source matrix into an encrypted matrix according to the row offset d is specifically that if i + d + j < n, A i,j = R i+d+j,j , if i + d + j ≥ n, A i,j = R i+d+j-n,j . Where i represents the row of the matrix, and 0 ≤ i ≤ n; j represents the column of the matrix, and 0 ≤ j ≤ n; A represents the source matrix, and R represents the encrypted matrix.
[0040] In this embodiment, the document is at least one of the initial document, the re-ordered document, the first encrypted document, and the second encrypted document. That is, the pre-encryption is performed before the data segmentation processing of the initial document based on the segmentation parameter, or after the generation of the re-ordered document, or after the secondary segmentation processing.
[0041] The present invention pre-encrypts the document through a preset encryption method, so that the document readers on the market cannot parse the encrypted document, and it can only be parsed and viewed through the reader bound by this encryption method, effectively preventing the leakage of the content of the encrypted document and improving the security of the encrypted document.
[0042] Preferably, before outputting the second encrypted document to the specified path, an encrypted document identifier is added to the second encrypted document. Specifically, the second encrypted document is a.zpdf format document, and the encrypted document identifier is a.zpdf format document identifier. Since the.zpdf format needs to be opened through its bound reader, it can further improve the security of the encrypted document.
[0043] In this embodiment, the first encrypted document is sent to the server, along with the encrypted information. The encrypted information includes at least one of the following: the document name of the encrypted document, the verification code of the encrypted document, the creator ID (Identity document) of the encrypted document, the encryption method of the encrypted document, the encryption key of the encrypted document, the size of each data block in the encrypted document, and the sequence number of each data block.
[0044] Preferably, the verification code is the MD5 message-digest algorithm, a widely used cryptographic hash function that produces a 128-bit (16-byte) hash value to ensure the integrity and consistency of transmitted information.
[0045] In this embodiment, MD5 is used by the server to identify documents and match the corresponding first encrypted document. When a user opens a second document locally, the MD5 hash of this document is automatically calculated and sent to the server. The server verifies the encrypted information to determine whether the user can decrypt the document and obtain the corresponding first encrypted document.
[0046] This invention saves encrypted information and verifies the encrypted information one by one during decryption. Only after the verification is consistent can the encrypted document be successfully opened, thus providing a dual protection for the encrypted document.
[0047] Furthermore, when the second encrypted document is output to the specified path, operation permissions and operation log settings are configured for the second encrypted document: the operation permissions are set to allow access to and configuration of the encrypted document by personnel and / or time permissions for accessing and configuring the encrypted document and / or printing permissions for the printing device.
[0048] Specifically, user permissions are set through user ID authorization, and the user ID is recorded. Authorized users can view and configure encrypted documents. Time permissions are set through preset time ranges, such as 8:00-17:00 (24-hour clock), during which encrypted documents can only be viewed and configured. Printing device permissions are set by authorizing the MAC address of a specified printing device, and only the printing device is authorized to print encrypted documents.
[0049] The operation log is set to automatically save user operation logs; the user operation log should include at least: document operator ID, opening time, closing time, document operator successfully opened the document, document operator failed to open the document, document printing time, printing device name, and number of copies printed.
[0050] This invention provides multiple layers of protection for encrypted documents by setting operation permissions and operation records for the second encrypted document and applying operation permissions during decryption. Furthermore, by automatically saving user operation records, the creator of the encrypted document can obtain information about the document operator or document operation information, thus preventing the theft of document content in a timely manner.
[0051] Specifically, when using a bound reader for document parsing, the specific steps are as follows:
[0052] Users log in and obtain a second encrypted document. It should be noted that users can log in via verification code or QR code scanning, and obtaining the second encrypted document here only refers to acquiring the resource; it does not mean that users can directly open or view the document.
[0053] The user sends their user ID, and operation permissions are verified. It's important to note that permission verification can be multi-layered. For example, first, personnel permissions are verified to confirm if the user is authorized to view and configure the encrypted document. If this verification passes, time permissions are further verified to confirm if the user is within the preset time range for viewing and configuring the encrypted document. If not, even a user with verified personnel permissions cannot view or configure the encrypted document. Of course, multi-layered verification requires that at least two types of operation permissions are set for the second encrypted document when it is output to the specified path.
[0054] If the user passes the operation permission verification, the reader retrieves the first encrypted document and its encryption information from the server. The reader automatically reads and decrypts the file based on the encryption information and adds the content of the first encrypted document to the second encrypted document.
[0055] Similarly, when a user prints an encrypted document, the MAC address of the printing device needs to be verified. If the verification fails, the printing function will not be enabled.
[0056] The present invention also provides a PDF document encryption device, comprising: a document acquisition module for acquiring an initial document and segmentation parameters, wherein the initial document is a PDF document; and a data segmentation processing module for performing data segmentation processing on the initial document based on the segmentation parameters, dividing the data in the initial document into N data blocks to obtain data block B1, data block B2, ..., data block B1. N Where N > 3; the reordering module is used to reorder N data blocks. After the N data blocks are randomly sorted, the data blocks are saved according to the random sorting result to generate a reordered document; the secondary segmentation module is used to perform secondary segmentation on the reordered document to generate a first encrypted document and a second encrypted document; and sends the first encrypted document to the server and outputs the second encrypted document to the specified path.
[0057] Furthermore, the PDF format document encryption device further includes:
[0058] A preprocessing module for preprocessing the initial document, where the preprocessing at least includes deleting the file header and file tail of the initial document;
[0059] A pre-encryption module for pre-encrypting the document according to a preset encryption method, which specifically includes the following steps: obtaining the data length L in the document, randomly dividing the document into multiple source matrices of n*n, where n is the matrix length, and randomly obtaining a row offset d based on the matrix length n, where 1 < d < n, and transforming the source matrix into an encrypted matrix according to the row offset d; obtaining an encryption key based on the matrix length n and the row offset d and performing key encryption on the document;
[0060] A server setting module for setting operation permissions and operation records for the second encrypted document.
[0061] In addition, to achieve the above object, the present invention also provides a computer-readable storage medium, on which a PDF format document encryption program is stored. When the PDF format document encryption program is executed by a processor, the steps of the PDF format document encryption method as described above are implemented.
[0062] The computer-readable storage medium may be the computer-readable storage medium included in the memory in the above embodiment; or it may exist alone and be a computer-readable storage medium not assembled into the device. At least one instruction is stored in the computer-readable storage medium, and the instruction is loaded and executed by the processor to implement Figure 1 the PDF format document encryption method shown. The computer-readable storage medium may be a read-only memory, a disk or an optical disc, etc.
[0063] It should be noted that the various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device embodiments and the storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0064] Furthermore, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0065] The foregoing description illustrates and describes preferred embodiments of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the inventive concept by means of the foregoing teachings or techniques or knowledge in related fields. Any modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.
Claims
1. A method for encrypting PDF format documents, characterized in that, Includes the following steps: Obtain the initial document and segmentation parameters. The initial document is a PDF document. While obtaining the initial document, preprocess it, including at least deleting the beginning and end of the file. Obtain the segmentation parameters by obtaining preset segmentation parameters and / or randomly generated segmentation parameters, including the number of segments and the segmentation size. Based on the segmentation parameters, the initial document is segmented into N data blocks, resulting in data block B1, data block B2, ..., data block B. N Where N > 3; Reorder N data blocks. After randomly sorting the N data blocks, save the data blocks according to the random sorting result and generate a reordered document. The reordered document is split twice to generate a first encrypted document and a second encrypted document; the first encrypted document is sent to the server and the second encrypted document is output to the specified path; The secondary segmentation process specifically involves: extracting data from the reordered document; a first encrypted document includes the extracted data content, and a second encrypted document includes the remaining data content after data extraction; the data extraction specifically involves extracting data based on the data extraction object, the data extraction range, and the data extraction length; the extraction object is all data blocks or a portion of data blocks, the data extraction range is the header or tail data of the extraction object, and the data extraction length is less than the total length of the data in the extraction object; The first encrypted document is sent to the server along with its encryption information. Before outputting the second encrypted document to the specified path, an encryption document identifier is added to the second encrypted document. The second encrypted document is in ".zpdf" format, and the encryption document identifier is also in ".zpdf" format. ".zpdf" format documents need to be opened using their associated reader. The encryption information includes at least one of the following: the document name, the verification code, the creator ID, the encryption method, the encryption key, the size of each data block within the encrypted document, and the sequence number of each data block. It also includes pre-encrypting the document according to a preset encryption method, where the document is at least one of the following: an initial document, a reordered document, a first encrypted document, or a second encrypted document; the pre-encryption specifically includes the following steps: Obtain the data length L within the document, and randomly divide the document into multiple n*n source matrices, where n is the length of the matrix. ; Based on the matrix length n, a row offset d is randomly obtained, where, The source matrix is transformed into an encryption matrix based on the row offset d; Based on the matrix length n and row offset d, the encryption key is obtained to encrypt the document.
2. The PDF document encryption method according to claim 1, characterized in that: When outputting the second encrypted document to a specified path, set operation permissions and operation logs for the second encrypted document: The operation permissions are set to allow for setting permissions for personnel to view and configure encrypted documents and / or time permissions to view and configure encrypted documents and / or printing permissions for printing devices; The operation log is set to automatically save user operation logs; the user operation log should include at least: document operator ID, opening time, closing time, document operator successfully opened the document, document operator failed to open the document, document printing time, printing device name, and number of copies printed.
3. A PDF document encryption device, characterized in that, include: The document acquisition module is used to acquire the initial document and segmentation parameters. The initial document is a PDF document. Obtaining segmentation parameters involves obtaining preset segmentation parameters and / or randomly generated segmentation parameters. Segmentation parameters include segmentation quantity parameters and segmentation size parameters. The data segmentation module is used to segment the initial document based on segmentation parameters, dividing the data in the initial document into N data blocks, resulting in data block B1, data block B2... data block B... N Where N > 3; The reordering module is used to reorder N data blocks. After the N data blocks are randomly sorted, the data blocks are saved according to the random sorting result, and a reordered document is generated. The secondary segmentation processing module is used to perform secondary segmentation processing on the reordered document to generate a first encrypted document and a second encrypted document; and sends the first encrypted document to the server and outputs the second encrypted document to the specified path; The secondary segmentation process specifically involves: extracting data from the reordered document; a first encrypted document includes the extracted data content, and a second encrypted document includes the remaining data content after data extraction; the data extraction specifically involves extracting data based on the data extraction object, the data extraction range, and the data extraction length; the extraction object is all data blocks or a portion of data blocks, the data extraction range is the header or tail data of the extraction object, and the data extraction length is less than the total length of the data in the extraction object; The first encrypted document is sent to the server along with its encryption information. Before outputting the second encrypted document to the specified path, an encryption document identifier is added to the second encrypted document. The second encrypted document is in ".zpdf" format, and the encryption document identifier is also in ".zpdf" format. ".zpdf" format documents need to be opened using their associated reader. The encryption information includes at least one of the following: the document name, the verification code, the creator ID, the encryption method, the encryption key, the size of each data block within the encrypted document, and the sequence number of each data block. It also includes: a preprocessing module for preprocessing the initial document, which includes at least deleting the file header and file footer of the initial document; The pre-encryption module is used to pre-encrypt a document according to a preset encryption method. The document is at least one of the following: an initial document, a reordered document, a first encrypted document, and a second encrypted document. The pre-encryption specifically includes the following steps: obtaining the data length L within the document; randomly dividing the document into multiple n*n source matrices, where n is the matrix length; and... The row offset d is randomly obtained based on the matrix length n, where, The source matrix is transformed into an encryption matrix based on the row offset d; the encryption key is obtained based on the matrix length n and the row offset d to encrypt the document.
4. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a PDF document encryption program, which, when executed by a processor, implements the steps of the PDF document encryption method as described in claim 1 or 2.
Citation Information
Patent Citations
Encryption method and encryption system for electronic documents
CN102404120A
File breaking encryption-based file security protection method
CN103346998A
Encryption method for onion network system consensus file
CN112242898A
File storage method and device and server
CN113032357A
File encryption method and device and file decryption method
CN114329546A