Encryption and Decryption Methods, Systems, Devices, and Storage Media for IPFS Files
The IPFS file encryption method addresses security vulnerabilities by employing high-frequency word indexing and dual encryption, ensuring secure and authorized access to IPFS files.
Patent Information
- Application Number
- CN202210899862.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-28
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-07-28
AI Technical Summary
IPFS files lack encryption during transmission, resulting in security issues. Anyone who holds CID can obtain the file contents and cannot achieve permission control.
Index words are used to replace high-frequency words and perform double encryption, including key encryption of index tables, file shard lists and shard content, combined with smart contract incentive mechanism, file storage and management is carried out through user nodes and service nodes.
It realizes permission control of IPFS files, improves file security and integrity, destroys file readability and integrity, and enhances the stability of storage and backup.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of IPFS networks, and particularly to an encryption and decryption method for IPFS files, as well as a system, device, and computer-readable storage medium applying this method. Background Art
[0002] IPFS (InterPlanetary File System) is one of the most representative distributed data storage systems, dedicated to creating a network transmission protocol for persistent and distributed storage and sharing of files. It utilizes many mature technologies, including: Distributed Hash Tables (DHTs), BitTorrent, version control system Git, Self-Certified Filesystems (SFS), and other technologies.
[0003] However, IPFS has security issues. Native IPFS does not provide file encryption functionality. It does not provide access control at the connection level to restrict untrusted peers from obtaining unauthorized data, that is, any user holding the CID can obtain the corresponding content from the network. However, in actual usage scenarios, files generally have security requirements. Therefore, from a security perspective, there are no completely trusted storage nodes, and the security of files cannot solely rely on trust in the nodes. Summary of the Invention
[0004] To solve the security problem of IPFS files, the main objective of the present invention is to provide an encryption and decryption method, system, device, and storage medium for IPFS files, to achieve permission control of IPFS files and improve the security of IPFS files.
[0005] To achieve the above objective, the present invention provides an encryption method for IPFS files, which includes:
[0006] Obtain the uploaded file and extract the high-frequency words in the uploaded file;
[0007] Establish an index table for the high-frequency words, and replace the high-frequency words in the uploaded file with preset index words to obtain a replacement file;
[0008] Slice the replacement file to obtain a file shard list and file shards;
[0009] Encrypt part of the content of the index table, file shard list, and file shards with a key to obtain an encrypted file;
[0010] Distribute and store the file shards, the encrypted file, and its key.
[0011] Preferably, it further includes deploying user nodes and service nodes in the IPFS network. The user nodes are used to upload or download files, and the service nodes are used to store the file shards of the files. When the user nodes upload files, they pay through a smart contract and register the file information of the uploaded files. The file information includes the character recognition code CID and the file name of the file. A file shard list is created according to the file information.
[0012] Preferably, the file shards are obtained by splitting the uploaded file according to the DAG structure. The file shard list is a list of IDs pointing to each file shard. Through this file shard list, each file shard can be found and downloaded to obtain the complete file.
[0013] Preferably, an index table is established for the high-frequency words, which specifically includes:
[0014] Performing word extraction on the uploaded file and creating a word frequency table;
[0015] Performing binary encoding on the words in the word frequency table;
[0016] Sorting according to the word frequency and encoding value of the words, and creating a high-frequency word table for the words ranked ahead;
[0017] Setting index words for the high-frequency words in the high-frequency word table, and creating an index table according to the corresponding relationship between the high-frequency words and the index words.
[0018] Preferably, the encrypted file is encrypted using a symmetric encryption algorithm. When decrypting, further compare the CID of the decrypted file with the original CID of the encrypted file to verify whether the decryption is successful. Only if the decryption is successful can the file shard list and the index table be obtained.
[0019] Preferably, after restoring and replacing the file, the complete file is further merged, and the CID verification is performed on the complete file and the uploaded file.
[0020] Corresponding to the encryption method of the IPFS file, the present invention also provides a decryption method for the IPFS file, which includes:
[0021] Downloading the encrypted file and decrypting the encrypted file using the key to obtain the decrypted file. The decrypted file includes: a file shard list, an index table, and partial contents of the file shards;
[0022] Obtaining all the file shards of the replaced file according to the file shard list;
[0023] Restoring the replaced file to the original uploaded file according to the index table.
[0024] Corresponding to the encryption method or decryption method of the IPFS file, the present invention also provides an IPFS file encryption and decryption system, which includes:
[0025] A file transfer module, which is used to obtain an uploaded file, or to download an encrypted file;
[0026] A file processing module, which is used to extract high-frequency words in the uploaded file, establish an index table for the high-frequency words, replace the high-frequency words in the uploaded file with preset index words to obtain a replacement file, and slice the replacement file to obtain a file shard list and file shards; or, obtain all file shards of the replacement file according to the file shard list, and restore the replacement file to the original uploaded file according to the index table;
[0027] A file encryption and decryption module, which is used to perform key encryption on part of the index table, file shard list, and file shards to obtain an encrypted file; or, to decrypt the encrypted file using a key to obtain a decrypted file, and the decrypted file includes: a file shard list, an index table, and part of the content of the file shards;
[0028] A file storage module, which is used to distribute and store the file shards, the encrypted file, and its key.
[0029] In addition, to achieve the above object, the present invention also provides a device, which includes a memory, a processor, and an IPFS file encryption program or decryption program stored on the memory and executable on the processor. When the IPFS file encryption program or decryption program is executed by the processor, the steps of the IPFS file encryption method or decryption method described above are implemented.
[0030] In addition, to achieve the above object, the present invention also provides a computer-readable storage medium, on which an IPFS file encryption program or decryption program is stored. When the IPFS file encryption program or decryption program is executed by a processor, the steps of the IPFS file encryption method or decryption method described above are implemented.
[0031] The beneficial effects of the present invention are:
[0032] (1) The encryption steps of the present invention include double encryption. First, the high-frequency words of the uploaded file are replaced with index words to destroy the readability of the file and achieve the first-level encryption effect; then, on the basis of the first-level encryption result, the file is sliced, and the index table, file shard list, and part of the content of the file shards are encrypted with a key to achieve the second-level encryption effect, so as to realize the permission control of the IPFS file and greatly improve the security of the IPFS file.
[0033] (2) The key encryption object of the present invention is not only the traditional file header content, but especially includes part of the index table and file shards, thereby destroying the readability and integrity of the file and improving the encryption effect.
[0034] (3) In the present invention, the user node uploads the file, the service node stores the file shards, and the smart contract is used to check, incentivize and macro-control the file storage, mobilizing the enthusiasm of the service node to autonomously store and backup the file, so that the IPFS network can provide stable storage and backup services.
[0035] (4) The decryption process of the present invention also includes double verification. The first verification is to verify the decrypted file after decrypting with the key; the second verification is to further verify whether the complete file is correct after restoring the file according to the index table and merging the complete file; thus ensuring the consistency between the decrypted complete file and the original uploaded file. Specific implementation mode
[0036] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0037] The first embodiment (encryption method):
[0038] An encryption method for an IPFS file in this embodiment includes:
[0039] To achieve the above object, the present invention provides an encryption method for an IPFS file, which includes:
[0040] Obtain the uploaded file and extract the high-frequency words in the uploaded file;
[0041] Establish an index table for the high-frequency words, and replace the high-frequency words in the uploaded file with preset index words to obtain a replacement file;
[0042] Slice the replacement file to obtain a file shard list and file shards;
[0043] Perform key encryption on part of the content of the index table, file shard list, and file shards to obtain an encrypted file;
[0044] Distribute and store the file shards, the encrypted file and its key.
[0045] In this embodiment, it further includes deploying user nodes and service nodes in the IPFS network. The user nodes are used to upload files, and the service nodes are used to store file shards of the files. For example, when the IPFS file is less than 256 kb, there is no need to perform file sharding, and the uploaded file is directly stored in a single block; when the IPFS file is relatively large, according to actual requirements, the uploaded file can be split into multiple file shards and stored in more than two blocks respectively.
[0046] When the user node uploads a file, it pays through a smart contract and registers the file information of the uploaded file to incentivize the storage service of the service node; the file information includes the character identification code CID of the file and the file name; a file shard list is created according to the file information. Here, the character identification code CID refers to the hash value corresponding to the content of the completely uploaded file.
[0047] The file shards are obtained by splitting the uploaded file according to the DAG structure. The full name of DAG is Directed Acyclic Graph, which is called a directed acyclic graph in Chinese. "Directed" means having a direction, specifically the same direction, and "acyclic" means that it cannot form a closed loop. The IPFS network uses a directed acyclic graph (DAG) as the data structure for storage. Each node in this directed acyclic graph has a unique identifier, that is, the node CID, which refers to the hash value corresponding to the content of the node.
[0048] The file shard list is a list of IDs pointing to each file shard. Through this file shard list, each file shard can be found and downloaded to obtain the complete file.
[0049] In this embodiment, creating an index table for the high-frequency words specifically includes:
[0050] Performing word extraction on the uploaded file and creating a word frequency table;
[0051] Performing binary encoding on the words in the word frequency table;
[0052] Sorting according to the word frequency and encoding values of the words, and creating a high-frequency word table for the words ranked in the front;
[0053] Setting index words for the high-frequency words in the high-frequency word table, and creating an index table according to the corresponding relationship between the high-frequency words and the index words.
[0054] Among them, sorting according to the word frequency and encoding value of words can be to assign weights to the word frequency and encoding value respectively, and then perform weighted sorting on the two; or, it can also be to sort according to the word frequency first, and then further sort the words with the same word frequency by the encoding value. The index words preferably use words, numbers or symbols that are different or non-repetitive from the uploaded file.
[0055] In this embodiment, the encrypted file is encrypted using a symmetric encryption algorithm. The symmetric encryption algorithm, also known as single-key encryption, is an encryption method using a single-key cryptosystem. The same key can be used for both encryption and decryption of information.
[0056] In this embodiment, in the encrypted file, the index table refers to the index table of the complete file, the file shard list refers to the ID list of the complete file, and the partial content of the file shard refers to the partial content of the file shard included in the current encrypted file, rather than the partial content of each file shard of the complete file. The partial content of this file shard will be split from the remaining content of this file shard, that is, a part of the content of the sharded file is stored in the encrypted file, and the remaining content does not need to be encrypted and is directly stored in the service node.
[0057] In this embodiment, distributing and storing the file shard, the encrypted file and its key means that each storage service node will store more than one file shard in the complete file, and the encrypted file corresponding to the more than one file shard. The key is not stored in this service node, but is stored in other transmission methods.
[0058] Second Embodiment (Decryption Method):
[0059] Corresponding to the encryption method of the IPFS file, this embodiment also provides a decryption method for the IPFS file, which includes:
[0060] Download the encrypted file and decrypt the encrypted file using the key to obtain the decrypted file; the decrypted file includes: a file shard list, an index table, and partial content of the file shard;
[0061] Obtain all file shards of the replacement file according to the file shard list;
[0062] Restore the replacement file to the original uploaded file according to the index table.
[0063] In this embodiment, it also includes deploying user nodes and service nodes in the IPFS network. The user nodes are used to download files. The file shard list is an ID list pointing to each file shard. Through this file shard list, each file shard can be found and downloaded to obtain the complete file.
[0064] In this embodiment, the encrypted file is encrypted using a symmetric encryption algorithm. When decrypting, the CID of the decrypted file is further compared with the original CID of the encrypted file (the CID here refers to the hash value corresponding to the content stored in the current service node) to verify whether the decryption is successful. Only when the decryption is successful can the file shard list and the index table be obtained.
[0065] In this embodiment, after restoring and replacing the file, the complete file is further merged, and the CID of the complete file and the uploaded file is verified (the CID here refers to the hash value of the complete file content).
[0066] The remaining content and method of this embodiment are basically similar to those of the first embodiment, and will not be elaborated here.
[0067] Third Embodiment (Encryption and Decryption System):
[0068] Corresponding to the encryption method or decryption method of the IPFS file, this embodiment also provides an IPFS file encryption and decryption system, which includes:
[0069] A file transfer module, which is used to obtain the uploaded file or to download the encrypted file;
[0070] A file processing module, which is used to extract the high-frequency words in the uploaded file, establish an index table for the high-frequency words, replace the high-frequency words in the uploaded file with preset index words to obtain a replacement file, and slice the replacement file to obtain a file shard list and file shards; or, obtain all the file shards of the replacement file according to the file shard list, and restore the replacement file to the original uploaded file according to the index table;
[0071] A file encryption and decryption module, which is used to encrypt the index table, file shard list, and part of the content of the file shards with a key to obtain an encrypted file; or, is used to decrypt the encrypted file with a key to obtain a decrypted file, and the decrypted file includes: a file shard list, an index table, and part of the content of the file shards;
[0072] A file storage module, which is used to distribute and store the file shards, the encrypted file, and its key.
[0073] The encryption and decryption system of this embodiment deploys user nodes and service nodes in the IPFS network. The user nodes are used to upload or download files, and the service nodes are used to store file shards of the files. Moreover, a smart contract is deployed in the blockchain network to incentivize file storage through the smart contract. The smart contract includes a storage mechanism and an incentive mechanism. The service nodes obtain the file list uploaded by the user nodes through the smart contract, determine whether to store the file shards of the files and the storage quantity according to the storage mechanism, and obtain corresponding benefits according to the incentive mechanism.
[0074] Service nodes: All service nodes form a service node network, which provides storage and backup services externally.
[0075] User nodes: The entry for users to use the services of the service node network.
[0076] Smart contract: It inspects, incentivizes, and macro-regulates the storage services of the service node network.
[0077] The present invention also provides a device, which includes a memory, a processor, and an encryption program or a decryption program of an IPFS file stored on the memory and executable on the processor. When the encryption program or the decryption program of the IPFS file is executed by the processor, it implements the steps of the encryption method of the IPFS file described in the first embodiment above or the decryption method described in the second embodiment. This device includes the encryption and decryption system of the IPFS file described in the third embodiment. Correspondingly, it can execute the technical solutions of the methods shown in the first embodiment and the second embodiment. The implementation principle and technical effects are similar. For details, reference can be made to the relevant records in the above embodiments, and details will not be repeated here.
[0078] The embodiment of the present invention also provides a computer-readable storage medium, on which an encryption program or a decryption program of an IPFS file is stored. When the encryption program or the decryption program of the IPFS file is executed by a processor, it implements the steps of the encryption method or the decryption method of the IPFS file described above. This computer-readable storage medium can be the computer-readable storage medium included in the memory in the above embodiment; it can also exist independently and be a computer-readable storage medium not assembled into the device. At least one instruction is stored in this computer-readable storage medium, and the instruction is loaded and executed by the processor to implement the encryption method of the IPFS file described in the first embodiment or the decryption method of the IPFS file described in the second embodiment. The computer-readable storage medium can be a read-only memory, a disk, or an optical disc, etc.
[0079] It should be noted that the various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the system embodiments, device embodiments, and storage medium embodiments, since they are basically similar to the method embodiments, they are described relatively simply. For the relevant parts, reference can be made to the corresponding descriptions in the method embodiments.
[0080] Also, in this document, the term "including", "comprising", or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or device that includes a series of elements includes not only those elements but also other elements not expressly listed, or elements that are inherent to such process, method, article, or device. Without further limitation, an element defined by the phrase "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device that includes the element.
[0081] The above description shows and describes the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, and should not be regarded as excluding other embodiments. Instead, it can be used in various other combinations, modifications, and environments, and can be changed within the scope of the inventive concept of this document through the above teachings or the technology or knowledge in the relevant field. Any changes and variations made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.
Claims
1. An encryption method for IPFS files, characterized in that, including: Obtain the uploaded file and extract the high-frequency words in the uploaded file; Create an index table for the high-frequency words, and replace the high-frequency words in the uploaded file with preset index words to obtain a replacement file; specifically including: Extract words from the uploaded file and create a word frequency table; Perform binary encoding on the words in the word frequency table; Sort according to the word frequency and encoding value of the words, and create a high-frequency word table for the words ranked ahead; Set index words for the high-frequency words in the high-frequency word table, and create an index table according to the corresponding relationship between the high-frequency words and the index words; Slice the replacement file to obtain a file shard list and file shards; the file shards are obtained by slicing the uploaded file according to the DAG structure; the file shard list is a list of IDs pointing to each file shard, and each file shard can be found and downloaded through this file shard list to obtain the complete file; Perform secret key encryption on part of the content of the index table, file shard list, and file shards to obtain an encrypted file; Distribute and store the file shards, the encrypted file, and its secret key; In the encrypted file, the index table refers to the index table of the complete file, the file shard list refers to the ID list of the complete file, and the partial content of the file shards refers to the partial content of the file shards included in the current encrypted file. This partial content of the file shards will be split from the remaining content of the file shards, that is, a part of the content of the sharded file is stored in the encrypted file, and the remaining content is directly stored in the service node without encryption.
2. The decryption method corresponding to the encryption method of an IPFS file according to claim 1, wherein, including: Download the encrypted file and decrypt the encrypted file using the secret key to obtain a decrypted file; The decrypted file includes: a file shard list, an index table, and partial content of the file shards; Obtain all file shards of the replacement file according to the file shard list; Restore the replacement file to the original uploaded file according to the index table.
3. The encryption method of the IPFS file according to claim 1 or the decryption method of the IPFS file according to claim 2, characterized in that, It also includes deploying user nodes and service nodes in the IPFS network. The user nodes are used to upload or download files, and the service nodes are used to store the file shards; when the user node uploads a file, it pays through a smart contract and registers the file information of the uploaded file; the file information includes the character recognition code CID and file name of the file. Create the file shard list according to the file information.
4. The decryption method of the IPFS file according to claim 2, wherein The encrypted file is encrypted using a symmetric encryption algorithm. When decrypting, further compare the CID of the decrypted file with the original CID of the encrypted file to verify whether the decryption is successful; only if the decryption is successful can the file shard list and index table be obtained.
5. The decryption method of the IPFS file according to claim 2, characterized in that, After restoring the replacement file, further merge the complete file and perform CID verification on the complete file and the uploaded file.
6. An encryption and decryption system for IPFS files, characterized in that, including: A file transfer module for obtaining the uploaded file or for downloading the encrypted file; A file processing module, which is used to extract high-frequency words from the uploaded file, establish an index table for the high-frequency words, replace the high-frequency words in the uploaded file with preset index words to obtain a replacement file, and slice the replacement file to obtain a file shard list and file shards; or, obtain all file shards of the replacement file according to the file shard list, and restore the replacement file to the original uploaded file according to the index table; A file encryption and decryption module, which is used to perform key encryption on part of the content of the index table, file shard list, and file shards to obtain an encrypted file; Or, it is used to decrypt the encrypted file with a key to obtain a decrypted file, and the decrypted file includes: a file shard list, an index table, and part of the content of the file shards; A file storage module, which is used to distribute and store the file shards, the encrypted file and its key; In the encrypted file, the index table refers to the index table of the complete file, the file shard list refers to the ID list of the complete file, and part of the content of the file shards refers to part of the content of the file shards included in the current encrypted file. This part of the content of the file shard will be split from the remaining content of the file shard, that is, part of the content of the sharded file is stored in the encrypted file, and the remaining content does not need to be encrypted and is directly stored in the service node; Establishing an index table for the high-frequency words specifically includes: Performing word extraction on the uploaded file and creating a word frequency table; Performing binary encoding on the words in the word frequency table; Sorting according to the word frequency and encoding value of the words, and creating a high-frequency word table for the words sorted in the front; Setting index words for the high-frequency words in the high-frequency word table, and creating an index table according to the corresponding relationship between the high-frequency words and the index words; The file shards are obtained by slicing the uploaded file according to the DAG structure; the file shard list is an ID list pointing to each file shard, and each file shard can be found and downloaded through this file shard list to obtain a complete file.
7. A device, characterized in that, The device includes a memory, a processor, and an encryption program or decryption program of the IPFS file stored on the memory and executable on the processor. When the encryption program or decryption program of the IPFS file is executed by the processor, the steps of the IPFS file encryption method or decryption method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium, characterized in that, An encryption program or decryption program of the IPFS file is stored on the computer-readable storage medium. When the encryption program or decryption program of the IPFS file is executed by the processor, the steps of the IPFS file encryption method or decryption method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
File storage method and system based block chain and IPFS protocol, terminal and storage medium
CN110099114A
Data storage and reading method, system and device based on IPFS and medium
CN110781155A
Data file storage and extraction method based on IPFS
CN113434094A