A method for extracting data from a damaged encrypted doc document

By decrypting the corrupted encrypted doc document, uncorrupted data is extracted, which solves the problem that the damaged doc document data cannot be extracted in the prior art, and realizes data recovery and loss avoidance.

CN115114089BActive Publication Date: 2025-05-13XLY SALVATIONDATA TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210740250.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-27
Publication Date
2025-05-13
Estimated Expiration
2042-06-27

AI Technical Summary

Technical Problem

The prior art cannot effectively extract data in corrupted encrypted doc documents, resulting in the failure of the damaged doc document to be opened even if the password is known, resulting in data loss.

Method used

By analyzing the storage and encryption methods of the encrypted doc document, the doc document is decrypted and uncorrupted data is extracted. The specific steps include reading the doc document, judging whether it is encrypted, obtaining sector allocation tables and stream files, using RC4 to decrypt the stream files, and finally extracting data.

Benefits of technology

It implements the extraction of data in corrupted encrypted doc documents, solves the problem of data loss, and restores some or all of the doc document data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115114089B_ABST
    Figure CN115114089B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for extracting data from a damaged encrypted doc document, comprising the following steps: S100: reading the doc document and storing it in a memory to extract data; S200: determining whether the doc document is encrypted, if yes, executing step S300, otherwise, ending the process; S300: obtaining a sector allocation table SAT; S400: obtaining a stream file; S500: decrypting the stream file using RC4; S600: extracting data from the doc document using a method for parsing data of a doc document provided by Microsoft. The method provided by the present invention solves the technical problem that there is no method for extracting data from a damaged encrypted doc document in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of electronic evidence collection and data recovery, and relates to a method for extracting data from a doc document, and in particular to a method for extracting data from a damaged encrypted doc document. Background Art

[0002] The suffix doc document (abbreviation: DOC, full name: Document) is a common file extension for computer files. It is also a text document before Microsoft Word 2003, hereinafter referred to as doc document. Since Microsoft Word 2007, the suffix of doc document has been changed to docx.

[0003] doc documents are widely used in life, and encryption of doc documents is a protection mechanism. When a doc document is normal, you only need to enter the correct password file to open it. However, if the doc document is damaged by hackers, deleted by mistake, or damaged during transmission, the doc document cannot be opened even if the password is known, resulting in data loss. Summary of the invention

[0004] In view of the problems in the prior art, the present invention provides a method for extracting data from a damaged encrypted doc document: by parsing the storage mode and encryption mode of the encrypted doc document, the doc document is decrypted, thereby extracting the data stored therein and not damaged. The method provided by the present invention comprises the following steps:

[0005] S100: reading the doc document and storing it in the memory to extract data;

[0006] S200: Determine whether the doc document is encrypted. If yes, execute step S300. Otherwise, end the process. Step S200 includes the following steps:

[0007] S201: Determine whether the search for the doc document is completed. If yes, execute step S206; otherwise, execute step S202:

[0008] S202: Reading the current sector of the doc document stored in the memory;

[0009] S203: Determine whether the data stored in the current sector is a WordDocument stream file of the doc document. If yes, execute step S205; otherwise, execute step S204. The process includes the following steps:

[0010] S2031: Determine whether the content of the first two bytes stored in the current sector is 0xECA5, if yes, execute step S2032, otherwise, execute step S204;

[0011] S2032: address the 0x0A byte of the current sector and read the continuous 2-byte content in little-endian format, and determine whether the 7th bit of the 2-byte content is 1. If yes, execute step S2033; otherwise, execute step S204;

[0012] S2033: address the 0x0E byte of the current sector and read the content of the byte to determine whether the byte content is 0x34. If so, execute step S205; otherwise, execute step S204.

[0013] S204: Determine whether the data stored in the current sector is the 0 / 1 table of the doc document. If yes, execute step S206; otherwise, execute step S205. The process includes the following steps:

[0014] Read the first four bytes stored in the current sector in big-endian format and determine whether it is 0x01000100. If so, execute step S206; otherwise, execute step S205.

[0015] S205: addressing the next sector of the doc document, executing step S201;

[0016] S206: Obtain the first 0x34 bytes of the 0 / 1 table of the doc document;

[0017] S300: Obtaining a sector allocation table SAT;

[0018] S400: Obtaining a stream file;

[0019] S500: Decrypt the stream file using RC4;

[0020] S600: adopting a method for parsing data of a doc document to extract data of the doc document.

[0021] Preferably, step S300 includes the following steps:

[0022] S301: Determine whether the search of the doc document is completed, if yes, execute step S400, otherwise, execute step S302;

[0023] S302: Read the current sector of the doc document stored in the memory;

[0024] S303: Divide the current sector into groups of four bytes, and determine whether the byte content of each group increases in sequence and is not greater than the maximum number of sectors of the doc document. If so, it indicates that the data contained in the current sector is a sector allocation table, and step S304 is executed; otherwise, step S305 is executed;

[0025] S304: Using tail addition, the SATIDs are stored in order of size to obtain stream files, which include WordDocument stream files, Data stream files, and 0 / 1 table stream files;

[0026] S305: address the next sector of the doc document and execute step S301.

[0027] Preferably, the step S400 includes the following steps:

[0028] S401: Determine whether the search of the doc document is completed, if yes, execute step S406, otherwise, execute step S402;

[0029] S402: Read the first 0x80 bytes of the current sector of the doc document stored in the memory;

[0030] S403: Determine whether the current sector is a directory entry, if yes, execute step S404, otherwise, execute step S405;

[0031] S404: Read and store the starting SATID of the current stream file and the byte length of the current stream file according to the data structure of the directory entry of the current stream file, wherein the current stream file includes the WordDocument stream file, the Data stream file, and the 0 / 1 table stream file;

[0032] S405: addressing the next sector of the doc document, executing step S401;

[0033] S406: Read the data of the stream file from the doc document according to the starting SATID of the stored stream file and the byte length of the stream file, wherein the current stream file includes the WordDocument stream file, the Data stream file, and the 0 / 1 table stream file.

[0034] Preferably, step S500 includes the following steps:

[0035] S501: Whether the stream file decryption of the doc document is completed, if yes, execute step S600, otherwise, execute step S502;

[0036] S502: Read the current sector of the doc document stored in the memory, record the sector index number of the current sector, and if the current sector is less than 512 bytes, fill the byte content less than 512 bytes with zeros;

[0037] S503: Decrypt the current stream file: Use the 0x34-byte content obtained in step S206, the doc document password and the sector index number to decrypt the current stream file using the RC4 method;

[0038] S504: Store the decrypted file stream back to the current sector to overwrite the original byte content of the current sector, and execute step S501; wherein, for the bytes filled with zeros because the current sector is less than 512 bytes, the corresponding decrypted byte content is used to overwrite the byte content filled with zeros respectively.

[0039] The invention solves the technical problem of the data extraction method of the undamaged encrypted doc document in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 The overall flow chart of the method provided by the present invention;

[0041] Figure 2 A specific flow chart of determining whether a doc document is encrypted in the method provided by the present invention;

[0042] Figure 3 A data structure diagram of a WordDocument stream in an embodiment provided by the present invention;

[0043] Figure 4 A data structure diagram of a table flow in an embodiment provided by the present invention;

[0044] Figure 5 A data structure diagram of a sector allocation table in an embodiment provided by the present invention;

[0045] Figure 6 The present invention provides a specific flow chart for obtaining a stream file in the method provided by the present invention. DETAILED DESCRIPTION

[0046] For ease of explanation, this manual provides the following terms for reference:

[0047] Storage and management of doc documents: Documents with the suffix doc are stored in discontinuous blocks. The size of each block is generally a sector, and the size of the sector is recorded in the first sector. The byte length of the sector is generally 512kb. Each element in the file (such as text, format, etc.) is managed by the stream file, and the stream file is managed by the sector allocation table SAT.

[0048] Encryption and storage of doc files: doc files are encrypted using RC4. Specifically, the doc files are encrypted according to the stream file, and the stream file is divided into blocks of the same byte length for encryption, and the byte length of each block is the same as the byte length of the sector.

[0049] The encrypted doc document only encrypts some key stream files, such as WordDocument stream, data stream, and 0 / 1 table stream. The doc document may store 0Table, 1Table, or both streams. The specific one is managed by the WordDocument stream. These three stream files are also the key information of the doc storage document elements. With them, the data of the complete doc document can be recovered and extracted.

[0050] WordDocument stream: After parsing, it is found that the encryption starts from the start address of the stream file and is offset 0x40 backward. The encrypted message includes management information, such as the byte length of the stream file, the version information of the doc document, whether the doc document is encrypted, and whether to use table 0 (0Table) or table 1 (1Table). The WordDocument stream can be addressed according to the start SATID of the stream file and the byte length of the stream file.

[0051] Data stream: This stream is fully encrypted. The data stream can be addressed based on the starting SATID of the stream file and the byte length of the stream file.

[0052] 0 / 1 Table Stream (0 / 1Table Stream): Starts with hexadecimal "01000100", and the 0x30 bytes thereafter are the decryption key value, including the salt value. The 0x30 bytes are not the content of the stream file itself, but will participate in the decryption process. The 0 / 1 Table Stream (0 / 1Table Stream) can be addressed based on the starting SATID of the stream file and the byte length of the stream file.

[0053] Figure 1 The overall flow chart of the method provided by the present invention is shown. Figure 1 As shown, the method of the present invention comprises the following steps:

[0054] S100: reading the doc document and storing it in the memory to extract data;

[0055] S200: Determine whether the doc document is encrypted, if yes, execute step S300, otherwise, end the process;

[0056] Figure 2 The specific flow chart of determining whether a doc document is encrypted in the method provided by the present invention is shown. Figure 2 As shown, step S200 includes the following steps:

[0057] S201: Determine whether the search for the doc document is completed. If yes, execute step S206. Otherwise, execute step S202:

[0058] S202: Read the current sector of the doc document stored in the memory;

[0059] S203: Determine whether the data stored in the current sector is a WordDocument stream file of a doc document. If yes, execute step S205; otherwise, execute step S204. The process includes the following steps:

[0060] S2031: Determine whether the content of the first two bytes stored in the current sector is 0xECA5, if yes, execute step S2032, otherwise, execute step S204;

[0061] Figure 3 FIG. 4 shows a data structure diagram of a WordDocument stream in an embodiment of the present invention; Figure 3 As shown, the first two bytes of the WordDocument stream are 0xECA5.

[0062] S2032: address the 0x0A byte of the current sector and read the continuous 2-byte content in little-endian format, and determine whether the 7th bit of the 2-byte content is 1. If yes, execute step S2033; otherwise, execute step S204;

[0063] like Figure 3 As shown, the content of the continuous 2 bytes starting from the 0x0A byte of the WordDocument stream in the little-endian format is 0x53F8, which is converted to binary as 0101001111111000. It can be seen that the 7th bit is 1.

[0064] S2033: address the 0x0E byte of the current sector and read the content of the byte to determine whether the content of the byte is 0x34. If yes, execute step S205; otherwise, execute step S204.

[0065] like Figure 3 As shown, the 0x0E byte of the current sector reads the byte content as 0x34.

[0066] S204: Determine whether the data stored in the current sector is the 0 / 1 table of the doc document. If yes, execute step S206; otherwise, execute step S205. The process includes the following steps:

[0067] Read the first four bytes stored in the current sector in big-endian format and determine whether it is 0x01000100. If so, execute step S206; otherwise, execute step S205.

[0068] Figure 4FIG. 1 shows a data structure diagram of a table flow in an embodiment provided by the present invention. Figure 4 As shown, the content of the first four bytes shown in the rectangular box is 0x01000100, and the process executes step S206.

[0069] S205: addressing the next sector of the doc document, executing step S201;

[0070] S206: Get the first 0x34 bytes of the 0 / 1 table of the doc document;

[0071] like Figure 4 As shown, the first four bytes shown in the shorter rectangle are 0x01000100, the 0x04th to 0x13th bytes shown in the black thick underline are the salt value salt, the 0x14th to 0x23th bytes shown in the black thin underline are the password verification input value, and the 0x24th to 0x33th bytes shown in the longer rectangle are the password verification output value. The password verification input value and the password verification output value are used to determine whether a password is correct when it is entered.

[0072] Specifically, the password verification input value is input together with the password as a parameter. After passing the verification algorithm, a value will be output. If this value is the same as the password verification output value, it means that the password is correct.

[0073] S300: Obtaining a sector allocation table SAT. Step S300 includes the following steps:

[0074] S301: Determine whether the search for the doc document is completed, if yes, execute step S400, otherwise, execute step S302;

[0075] S302: Read the current sector of the doc document stored in the memory;

[0076] S303: Divide the current sector into groups of four bytes, and determine whether the byte content of each group increases in sequence and is not greater than the maximum number of sectors of the doc document. If so, it indicates that the data contained in the current sector is a sector allocation table, and step S304 is executed; otherwise, step S305 is executed;

[0077] It is worth noting that some special values ​​of SATID are defined as follows:

[0078] 0xFFFFFFFF: indicates that a free sector may exist in the file but is not part of any stream; 0xFFFFFFFE: indicates the last SATID in the SATID chain; 0xFFFFFFFD: indicates that the sector corresponding to this SID is used by the sector allocation table SAT; 0xFFFFFFFC: indicates that the sector corresponding to this SID is used by the master sector allocation table MSAT.

[0079] Figure 5 FIG. 2 shows a data structure diagram of a sector allocation table in an embodiment provided by the present invention. Figure 5 As shown, the byte contents of each group of four bytes increase in sequence, indicating that the data contained in the current sector is the sector allocation table.

[0080] S304: Using the tail addition method, the SATIDs are stored in order of size to obtain stream files, which include WordDocument stream files, Data stream files, and 0 / 1 table stream files;

[0081] S305: Address the next sector of the doc document and execute step S301.

[0082] S400: Obtain a stream file.

[0083] Figure 6 FIG. 2 shows a specific flow chart of obtaining a stream file in the method provided by the present invention. Figure 6 As shown, step S400 includes the following steps:

[0084] S401: Determine whether the search for the doc document is completed, if yes, execute step S406, otherwise, execute step S402;

[0085] S402: Read the first 0x80 bytes of the current sector of the doc document stored in the memory;

[0086] S403: Determine whether the current sector is a directory entry. If yes, execute step S404. Otherwise, execute step S405. The data structure diagram of the directory entry of 0x80 bytes is shown in Table 1 below. It is required to determine whether the content of the first 0x80 bytes of the current sector strictly conforms to the data structure of Table 1. If yes, execute step S404.

[0087] Table 1: Data structure of directory entry

[0088] It should be understood that the current stream files include WordDocument stream files, Data stream files, and 0 / 1 table stream files. In the 0x80-byte directory entry, the first 64 bytes are the names of the stream files, which can be used to distinguish the three.

[0089]

[0090] Different stream files.

[0091] S404: Read and store the starting SATID of the current stream file and the byte length of the current stream file according to the data structure of the directory entry of the current stream file, wherein the current stream file includes the WordDocument stream file, the Data stream file, and the 0 / 1 table stream file;

[0092] S405: addressing the next sector of the doc document, executing step S401;

[0093] S406: Read the data of the stream file from the doc document according to the starting SATID of the stored stream file and the byte length of the stream file, wherein the current stream file includes the WordDocument stream file, the Data stream file, and the 0 / 1 table stream file.

[0094] S500: Decrypt the stream file using RC4; Step S500 includes the following steps:

[0095] S501: Is the stream file decryption of the doc document completed? If yes, execute step S600; otherwise, execute step S502;

[0096] S502: Read the current sector of the doc document stored in the memory, record the sector index number of the current sector, and if the current sector is less than 512 bytes, fill the byte content less than 512 bytes with zeros;

[0097] For example, the index number of each stream file is used for different stream files, all of which start with 0 and increase in sequence.

[0098] S503: Decrypt the current stream file: Use the 0x34-byte content, doc document password and sector index number obtained in step S206 to decrypt the current stream file using RC4;

[0099] S504: Store the decrypted file stream back to the current sector to overwrite the original byte content of the current sector, and execute step S501; wherein, for the bytes filled with zeros because the current sector is less than 512 bytes, the corresponding decrypted byte content is used to overwrite the byte content filled with zeros respectively.

[0100] S600: extracting data from the doc document using a method for parsing data from the doc document. The method in this step is a well-known technique and will not be described in detail here. For specific methods, please refer to the Microsoft official website.

[0101] The method provided by the present invention solves the technical problem of the data extraction method of the undamaged encrypted doc document in the prior art.

[0102] It should be understood that the present invention is not limited to the above examples. For those skilled in the art, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.

Claims

1. A method for extracting data from a damaged encrypted doc document, characterized in that The following steps are involved: S100: reading the doc document and storing it in the memory to extract data; S200: Determine whether the doc document is encrypted. If yes, execute step S300. Otherwise, end the process. Step S200 includes the following steps: S201: Determine whether the search of the doc document is completed. If yes, execute step S206. Otherwise, execute step S202: S202: Reading the current sector of the doc document stored in the memory; S203: Determine whether the data stored in the current sector is a WordDocument stream file of the doc document. If yes, execute step S205; otherwise, execute step S204. The process includes the following steps: S2031: Determine whether the content of the first two bytes stored in the current sector is 0xECA5, if yes, execute step S2032, otherwise, execute step S204; S2032: address the 0x0A byte of the current sector and read the continuous 2-byte content in little-endian format, and determine whether the 7th bit of the 2-byte content is 1. If yes, execute step S2033; otherwise, execute step S204; S2033: address the 0x0E byte of the current sector and read the content of the byte to determine whether the content of the byte is 0x34. If yes, execute step S205; otherwise, execute step S204. S204: Determine whether the data stored in the current sector is the 0 / 1 table of the doc document. If yes, execute step S206; otherwise, execute step S205; including the following steps: Read the first four bytes stored in the current sector in big-endian format and determine whether it is 0x01000100. If so, execute step S206; otherwise, execute step S205. S205: addressing the next sector of the doc document, executing step S201; S206: Obtain the first 0x34 bytes of the 0 / 1 table of the doc document; S300: Obtaining a sector allocation table SAT; S400: Obtaining a stream file; S500: Decrypt the stream file using RC4; S600: adopting a method for parsing data of a doc document to extract data of the doc document.

2. The method for extracting data from a damaged encrypted doc document according to claim 1, characterized in that: Step S300 includes the following steps: S301: Determine whether the search of the doc document is completed, if yes, execute step S400, otherwise, execute step S302; S302: Read the current sector of the doc document stored in the memory; S303: Divide the current sector into groups of four bytes, and determine whether the byte content of each group increases in sequence and is not greater than the maximum number of sectors of the doc document. If so, it indicates that the data contained in the current sector is a sector allocation table, and step S304 is executed; otherwise, step S305 is executed; S304: Using tail addition, the SAT IDs are stored in order of size to obtain stream files, which include WordDocument stream files, Data stream files, and 0 / 1 table stream files; S305: address the next sector of the doc document and execute step S301.

3. The method for extracting data from a damaged encrypted doc document according to claim 1, characterized in that: The step S400 includes the following steps: S401: Determine whether the search of the doc document is completed, if yes, execute step S406, otherwise, execute step S402; S402: Read the first 0x80 bytes of the current sector of the doc document stored in the memory; S403: Determine whether the current sector is a directory entry, if yes, execute step S404, otherwise, execute step S405; S404: Read and store the starting SATID of the current stream file and the byte length of the current stream file according to the data structure of the directory entry of the current stream file, wherein the current stream file includes the WordDocument stream file, the Data stream file, and the 0 / 1 table stream file; S405: addressing the next sector of the doc document, executing step S401; S406: Reading data of the stream file from the doc document according to the starting SAT ID of the stored stream file and the byte length of the stream file, wherein the current stream file includes a WordDocument stream file, a Data stream file, and a 0 / 1 table stream file.

4. The method for extracting data from a damaged encrypted doc document according to claim 1, characterized in that: Step S500 includes the following steps: S501: Whether the stream file decryption of the doc document is completed, if yes, execute step S600, otherwise, execute step S502; S502: Read the current sector of the doc document stored in the memory, record the sector index number of the current sector, and if the current sector is less than 512 bytes, fill the byte content less than 512 bytes with zeros; S503: Decrypt the current stream file: Use the 0x34-byte content obtained in step S206, the doc document password and the sector index number to decrypt the current stream file using the RC4 method; S504: Store the decrypted file stream back to the current sector to overwrite the original byte content of the current sector, and execute step S501; wherein, for the bytes filled with zeros because the current sector is less than 512 bytes, the corresponding decrypted byte content is used to overwrite the byte content filled with zeros respectively.

Citation Information

Patent Citations

  • Method of repairing damage document

    CN106681969A

  • Injured word file restoring method

    CN1710545A