A method for repairing damaged encrypted xlsx files
By generating encrypted information and decryption keys, extracting and parsing data in corrupted encrypted xlsx files, the problem that the existing technology cannot repair corrupted encrypted xlsx files is solved, and data integrity and adaptability are achieved.
Patent Information
- Application Number
- CN202210735161.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-27
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-06-27
AI Technical Summary
The prior art cannot effectively repair corrupted encrypted xlsx files. Even if the encryption password is known, some data will be lost and the adaptability is poor.
By generating encrypted information, decrypting keys and encrypted data streams, obtaining compressed data streams, extracting the xml files and picture files, and parsing and repairing them according to the OOXML standard.
It realizes the repair of encrypted xlsx files with known encryption passwords, adapts to various corruption situations, and ensures data integrity and repair results.
Smart Images

Figure CN115114076B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of data recovery and electronic evidence collection, and relates to a repair method for a damaged encrypted xlsx file. Background Art
[0002] Microsoft Excel is one of the most popular office software. It can conveniently store and perform statistical analysis on a variety of data and is widely used in many fields such as management, statistics, finance, and finance. As the main file format of Microsoft Excel, xlsx sometimes stores some important data, such as bills and bank statements. With the improvement of information security awareness, file encryption protection is becoming more and more common. In electronic data forensics, if the encrypted xlsx file is damaged, even if the encryption password is known, the file content cannot be obtained, and data recovery and electronic forensics will face great difficulties.
[0003] At present, the existing technology for repairing xlsx files is to repair the file structure to a certain extent, which generally has the following disadvantages:
[0004] 1. Knowing the xlsx encryption password, the encrypted xlsx file still cannot be repaired.
[0005] 2. Poor adaptability under different degrees of damage.
[0006] 3. The repaired file will lose some data. Summary of the invention
[0007] In view of the technical problems of the prior art, the present invention provides a method for repairing a damaged encrypted xlsx file: by generating encryption information, a decryption key and an encrypted data stream, obtaining a compressed data stream, and extracting the xml files and image files contained in the compressed data stream.
[0008] The relevant terms and nouns of the present invention are explained as follows:
[0009] Encryption password: The password entered by the user when encrypting the xlsx file. This password is not the key to decrypt the data. The difference between the two is that the password is a string of characters entered by the user, while the key is a string of binary data obtained by converting the password according to specific rules and algorithms.
[0010] Zip file record header: "local file header" in the zip file structure.
[0011] OOXML standard: A technical specification developed by Microsoft for Office 2007 products, which has now become an international document format standard.
[0012] KMP algorithm: A fast string matching algorithm proposed by DEKnuth, JHMorris and VRPratt.
[0013] Inflate algorithm: decompression algorithm of the Deflate compression algorithm.
[0014] The method provided by the present invention comprises the following steps:
[0015] S100: Generate encryption information: retrieve keywords contained in the underlying binary data of the xlsx file, the keywords include a hash algorithm, a hash size, a salt value, and an encryption key value, wherein the underlying binary data of the xlsx file is stored in sectors;
[0016] Obtain the numerical value corresponding to each of the keywords, and decode the numerical values of the salt value and the encryption key value, and use the decoding result as the encrypted information;
[0017] S200: Generate a decryption key: Generate a key required for decryption according to the encrypted information and the encryption password;
[0018] S300: generating an encrypted data stream, including the following steps:
[0019] S301: Read data of the current sector;
[0020] S302: Determine whether there are two or more consecutive bytes with values between 0x00 and 0x0F in the current sector data. If yes, execute step S306; otherwise, execute step S303;
[0021] S303: Read the contents of each byte of the current sector data and count the number of bytes whose contents are values between 0x1F and 0xFF;
[0022] S304: Determine whether the number of values between 0x1F and 0xFF in the content of each byte of the current sector data exceeds a threshold, if yes, execute step S305, otherwise, execute step S306;
[0023] S305: Save current sector data;
[0024] S306: Determine whether all sectors of the underlying binary data of the xlsx file have been read, if yes, execute step S308, otherwise, execute step S307;
[0025] S307: address the next sector and execute step S301;
[0026] S308: splicing the saved sector data into an encrypted data stream in sequence;
[0027] S400: Obtaining a compressed data stream according to the secret key and the encrypted data stream;
[0028] S500: extracting the XML file and the picture file contained in the compressed data stream and appending them to the temporary storage file;
[0029] S600: parsing the XML file extracted in step S500 according to the OOXML standard, deleting the erroneous data in the XML file and constructing the missing XML file;
[0030] S700: According to the OOXML standard, each XML file and each image file are stored in a specified directory structure, and compressed and packaged in zip format, and the suffix of the generated compressed package is changed to xlsx and used as the file after the xlsx file is repaired.
[0031] Preferably, in step 100, a KMP algorithm is used to retrieve keywords contained in the underlying binary data of the xlsx file.
[0032] Preferably, in step 100, Base64 encoding is used to decode the values of the salt value and the encryption key value.
[0033] Preferably, step S200 includes the following steps:
[0034] 201: Perform hash calculation on the value obtained by sequentially concatenating the salt value and the encrypted password, and save the calculation result as the first hash value;
[0035] 202: Perform hash calculation on the concatenated value of the serial number and the first hash value, and save the calculation result as the second hash value, wherein the serial number starts from 0 and increases by 1 each time, and the calculation is repeated N times, and each calculation result overwrites the second hash value, wherein N is 10000;
[0036] 203: Perform hash calculation on the value obtained by sequentially concatenating the second hash value and the filling value, and save the calculation result as the third hash value, wherein the filling value is 0x146E0BE7ABACD0D6;
[0037] 204: Using the third hash value as the secret key and the salt value as the initialization vector, the encrypted key value is decrypted by AES using the CBC mode, and the decryption result is used as the secret key for decrypting the data.
[0038] Preferably, the threshold in step S300 is 80%.
[0039] Preferably, the step S500 includes the following steps:
[0040] S501: Using the KMP algorithm to retrieve a local file header signature in the zip format from the compressed data stream, the value of the local file header signature is 0x0x504b0304, and determining whether the local file header signature is retrieved. If so, executing step S502, otherwise executing step S504;
[0041] S502: Determine whether the data after the local file header signature conforms to the structure of the zip file record header. If yes, execute step S503; otherwise, execute step S501;
[0042] S503: Obtain the byte length of the compressed file data from the zip file record header of the xlsx file, use the Inflate algorithm to decompress the compressed file data after the current zip file record header and before the next zip file record header, and add the decompressed result to the temporary file, the temporary file includes multiple xml files and multiple image files, address the next zip file record header, and execute step S501;
[0043] S504: Check whether the xl / sharedStrings.xml file and the xl / worksheets / sheet*.xml file are missing from the XML file in the temporary file. If yes, execute step S505; otherwise, execute step S600;
[0044] 505: using the KMP algorithm to search the compressed data stream for the missing XML file in step S504, and determining whether it is found. If so, executing step S506; otherwise, executing step S600;
[0045] 506: Check whether the data before the name of the xml file missing in step S505 conforms to the structure of the zip file record header. If yes, execute step S507; otherwise, execute step S505;
[0046] 507: Obtain the byte length of the compressed file data from the zip file record header of the xlsx file, use the Inflate algorithm to decompress the compressed file data after the current zip file record header and before the next zip file record header, and add the decompressed result to the temporary file, and execute step S505.
[0047] The present invention has the following beneficial effects:
[0048] This technology has the following innovations:
[0049] 1. When the encryption password is known, the decryption key can be generated by the password to repair the encrypted xlsx file.
[0050] 2. Aiming at various damage situations of xlsx files, a repair method that adapts to various management structures and stream data damage is proposed.
[0051] 3. Under the OOXML standard, efficiently extract data from xlsx files and ensure data integrity. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 A flow chart of the method provided by the present invention;
[0053] Figure 2 A specific flow chart of generating a decryption key in the method provided by the present invention;
[0054] Figure 3 A specific flow chart of generating an encrypted data stream in the method provided by the present invention;
[0055] Figure 4 A specific flow chart of extracting XML files and picture files contained in a compressed data stream in the method provided by the present invention. DETAILED DESCRIPTION
[0056] Figure 1 The flow chart of the method provided by the present invention is shown. Figure 1 As shown, the method of the present invention comprises the following steps:
[0057] S100: Generate encryption information: Use the KMP algorithm to retrieve keywords contained in the underlying binary data of the xlsx file. The keywords include hash algorithm, hash size, salt value, and encryption key value, wherein the underlying binary data of the xlsx file is stored in sectors;
[0058] Get the value corresponding to each keyword, decode the salt value and encryption key value using Base64 encoding, and use the decoding result as the encrypted information;
[0059] S200: Generate a decryption key: Generate a decryption key based on the encrypted information and the encryption password;
[0060] Figure 2 The specific flow chart of generating a decryption key in the method provided by the present invention is shown as follows: Figure 2 As shown, step S200 includes the following steps:
[0061] 201: Perform hash calculation on the value obtained by sequentially concatenating the salt value and the encrypted password, and save the calculation result as the first hash value;
[0062] 202: Calculate the hash value of the concatenated value of the serial number and the first hash value in sequence, and save the calculation result as the second hash value. The serial number starts from 0 and increments by 1 each time. Repeat the calculation N times, and each calculation result overwrites the second hash value. In this embodiment, N is set to 10,000;
[0063] 203: Calculate the hash value of the concatenated value of the second hash value and the padding value in sequence, and save the calculation result as the third hash value. The padding value is 0x146E0BE7ABACD0D6;
[0064] 204: Use the third hash value as the secret key and the salt value as the initialization vector. Adopt the CBC mode to perform AES decryption on the encrypted key value, and use the decryption result as the secret key of the decrypted data.
[0065] S300: Generate an encrypted data stream.
[0066] Figure 3 The specific flowchart of generating the encrypted data stream in the method provided by the present invention is shown. As Figure 3 shown, step S300 includes the following steps:
[0067] S301: Read the data of the current sector;
[0068] S302: Determine whether there are two or more consecutive byte contents in the current sector data that are values between 0x00 and 0x0F. If so, execute step S306; otherwise, execute step S303;
[0069] S303: Read the content of each byte of the current sector data and count the number of values between 0x1F and 0xFF in the byte content;
[0070] S304: Determine whether the number of values between 0x1F and 0xFF in the content of each byte of the current sector data exceeds the threshold of 80%. If so, execute step S305; otherwise, execute step S306;
[0071] S305: Save the current sector data;
[0072] S306: Determine whether all sectors of the underlying binary data of the xlsx file have been read. If so, execute step S308; otherwise, execute step S307;
[0073] S307: Address the next sector and execute step S301;
[0074] S308: Concatenate the saved sector data in sequence to form an encrypted data stream;
[0075] S400: Obtain a compressed data stream according to the secret key and the encrypted data stream;
[0076] S500: extracting the XML file and the picture file contained in the compressed data stream and appending them to the temporary storage file;
[0077] Figure 4 The specific flow chart of extracting the XML file and the picture file contained in the compressed data stream in the method provided by the present invention is shown. Figure 4 As shown, step S500 includes the following steps:
[0078] S501: Use the KMP algorithm to retrieve the local file header signature in the zip format in the compressed data stream. The value of the local file header signature is 0x0x504b0304. Determine whether the local file header signature is retrieved. If yes, execute step S502. Otherwise, execute step S504.
[0079] S502: Determine whether the data after the local file header signature conforms to the structure of the zip file record header. If yes, execute step S503; otherwise, execute step S501;
[0080] S503: Obtain the byte length of the compressed file data from the zip file record header of the xlsx file, use the Inflate algorithm to decompress the compressed file data after the current zip file record header and before the next zip file record header, and add the decompressed result tail to the temporary file, the temporary file includes multiple XML files and multiple image files, address the next zip file record header, and execute step S501;
[0081] S504: Check whether the xl / sharedStrings.xml file and the xl / worksheets / sheet*.xml file are missing from the XML file in the temporary file. If yes, execute step S505; otherwise, execute step S600;
[0082] 505: Use the KMP algorithm to search the compressed data stream for the missing XML file in step S504, and determine whether it is found. If so, execute step S506; otherwise, execute step S600;
[0083] 506: Check whether the data before the name of the xml file missing in step S505 conforms to the structure of the zip file record header. If yes, execute step S507; otherwise, execute step S505;
[0084] 507: Obtain the byte length of the compressed file data from the zip file record header of the xlsx file, use the Inflate algorithm to decompress the compressed file data after the current zip file record header and before the next zip file record header, and add the decompressed result to the temporary file, and execute step S505.
[0085] S600: parsing the XML file extracted in step S500 according to the OOXML standard, deleting the erroneous data in the XML file and constructing the missing XML file;
[0086] S700: According to the OOXML standard, each XML file and each image file are stored in the specified directory structure, and compressed and packaged in zip format, and the suffix of the generated compressed package is changed to xlsx and used as the file after the xlsx file is repaired.
[0087] The method provided by the present invention solves the technical problem that there is no method for repairing damaged encrypted xlsx files in the prior art.
[0088] It should be understood that the present invention is not limited to the above examples. For those skilled in the art, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.
Claims
1. A method for repairing damaged encrypted xlsx files. Features The following steps are involved: S100: Generate encryption information: retrieve keywords contained in the underlying binary data of the xlsx file, the keywords include a hash algorithm, a hash size, a salt value, and an encryption key value, wherein the underlying binary data of the xlsx file is stored in sectors; Obtain the numerical value corresponding to each of the keywords, and decode the numerical values of the salt value and the encryption key value, and use the decoding result as the encrypted information; S200: Generate a decryption key: Generate a key required for decryption according to the encrypted information and the encryption password; S300: generating an encrypted data stream, including the following steps: S301: Read data of the current sector; S302: Determine whether there are two or more consecutive bytes with values between 0x00 and 0x0F in the current sector data. If yes, execute step S306; otherwise, execute step S303; S303: Read the contents of each byte of the current sector data and count the number of bytes whose contents are values between 0x1F and 0xFF; S304: Determine whether the number of values between 0x1F and 0xFF in the content of each byte of the current sector data exceeds a threshold, if yes, execute step S305, otherwise, execute step S306; S305: Save current sector data; S306: Determine whether all sectors of the underlying binary data of the xlsx file have been read, if yes, execute step S308, otherwise, execute step S307; S307: address the next sector and execute step S301; S308: splicing the saved sector data into an encrypted data stream in sequence; S400: Obtaining a compressed data stream according to the secret key and the encrypted data stream; S500: extracting the XML file and the picture file contained in the compressed data stream and appending them to the temporary storage file; S600: parsing the XML file extracted in step S500 according to the OOXML standard, deleting the erroneous data in the XML file and constructing the missing XML file; S700: According to the OOXML standard, each XML file and each image file are stored in a specified directory structure, and compressed and packaged in zip format, and the suffix of the generated compressed package is changed to xlsx and used as the file after the xlsx file is repaired.
2. A method for repairing a damaged encrypted xlsx file according to claim 1, It is characterized in that In the step S100, the KMP algorithm is used to retrieve keywords contained in the underlying binary data of the xlsx file.
3. A method for repairing a damaged encrypted xlsx file according to claim 1, It is characterized in that In the step S100, the values of the salt value and the encryption key value are decoded using Base64 encoding.
4. A method for repairing a damaged encrypted xlsx file according to claim 1, It is characterized in that Step S200 includes the following steps:
201. Perform hash calculation on the concatenated value of the salt value and the encrypted password, and save the calculation result as the first hash value; 202. Perform hash calculation on the concatenated value of the serial number and the first hash value, and save the calculation result as the second hash value, wherein the serial number starts from 0 and increases by 1 each time, and the calculation is repeated N times, and each calculation result covers the second hash value, wherein N is 10000; 203. Perform hash calculation on the value obtained by sequentially concatenating the second hash value and the filling value, and save the calculation result as the third hash value, wherein the filling value is 0x146E0BE7ABACD0D6; 204. Using the third hash value as the secret key and the salt value as the initialization vector, the encrypted key value is decrypted by AES using the CBC mode, and the decryption result is used as the secret key for decrypting the data.
5. A method for repairing a damaged encrypted xlsx file according to claim 1, It is characterized in that The threshold in step S300 is 80%.
6. A method for repairing a damaged encrypted xlsx file according to claim 1, It is characterized in that The step S500 includes the following steps: S501: Using the KMP algorithm to retrieve a local file header signature in the zip format from the compressed data stream, the value of the local file header signature is 0x0x504b0304, and determining whether the local file header signature is retrieved. If so, executing step S502, otherwise executing step S504; S502: Determine whether the data after the local file header signature conforms to the structure of the zip file record header. If yes, execute step S503; otherwise, execute step S501; S503: Obtain the byte length of the compressed file data from the zip file record header of the xlsx file, use the Inflate algorithm to decompress the compressed file data after the current zip file record header and before the next zip file record header, and add the decompressed result to the temporary file, the temporary file includes multiple xml files and multiple image files, address the next zip file record header, and execute step S501; S504: Check whether the xl / sharedStrings.xml file and the xl / worksheets / sheet*.xml file are missing from the XML file in the temporary file. If yes, execute step S505; otherwise, execute step S600; S505: Using the KMP algorithm to search the compressed data stream for the missing XML file described in step S504, and determining whether it is found. If so, executing step S506, otherwise, executing step S600; S506: Check whether the data before the name of the xml file missing in step S505 conforms to the structure of the zip file record header. If yes, execute step S507; otherwise, execute step S505; S507: Obtain the byte length of the compressed file data from the zip file record header of the xlsx file, use the Inflate algorithm to decompress the compressed file data after the current zip file record header and before the next zip file record header, and add the decompressed result to the temporary file, and execute step S505.
Citation Information
Patent Citations
Data reorganization and restoration method for Microsoft EXCEL file
CN112069130A
One-to-one key document compression encryption and decryption security tool implementation method
CN114417365A