File Secure Transmission Method and Device

By receiving and verifying the digital signature and MD5 verification of the summary information of the file to be uploaded during the uploading of online banking files, the problem of inefficient file upload in the existing technology is solved, and safe and efficient file transfer is achieved.

CN115801279BActive Publication Date: 2025-07-29INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211506004.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-29
Publication Date
2025-07-29
Estimated Expiration
2042-11-29

AI Technical Summary

Technical Problem

In the prior art, there is a problem of inefficiency in the uploading process of files, especially in online banking, users need to enter a u-shield password for each file to sign, resulting in inefficient uploading.

Method used

By receiving the summary information of the file to be uploaded sent by the user, the digital signature of the U-shield program is preset, and after the signature verification is performed, the multiple files to be uploaded are MD5 checked, and the digital signature of the U-shield program is performed one by one after the MD5 check is passed.

Benefits of technology

While ensuring file transfer security, it improves file transfer efficiency, reduces the number of times users enter u shield passwords, and improves the efficiency of the upload process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801279B_ABST
    Figure CN115801279B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method and device for secure file transmission, which can be used in the financial field. The method includes: receiving the summary information of files to be uploaded sent by a user, where the summary information of files to be uploaded is digitally signed by a preset U shield program; performing signature verification on the summary information of files to be uploaded, and performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtaining multiple files to be uploaded in the list of files to be uploaded and performing signature verification on the multiple files to be uploaded, where the multiple files to be uploaded are individually digitally signed by a preset U shield program; the present application can improve the file transmission efficiency while ensuring the security of file transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security and can also be used in the financial field. Specifically, it relates to a method and device for secure file transmission. Background Art

[0002] For the remittance service provided by online banking based on the B / S structure to customers, customers are often required to provide background information for the remittance. When the online banking system of commercial banks uploads customers' transaction background information, generally, when users use the relevant functions of online banking and select the file to be uploaded on the page, the human-computer interaction module of online banking will use the U shield to sign the uploaded file. After the signing is completed, the online banking page will upload the file to the file upload server through the file upload client program in the C / S mode, and the file upload server will verify the signature of the received file to ensure the integrity and authenticity of the file uploaded by customers on the external network.

[0003] In the existing file upload processing mode, during the human-computer interaction of online banking, after the user selects a file on the web page of online banking and before uploading, the file signature operation will trigger the password input module of the U shield, and the user needs to input the U shield password before performing the signature. The main disadvantages of the whole process are as follows:

[0004] (1) The file upload goes through two stages. The traditional upload method focuses on signing in the stage from the browser to the server, while ignoring the stage from the local disk to the browser.

[0005] (2) Users often upload more than one file. In this process, for each file uploaded, the user needs to input the password once. That is, the one-time-password upload mode makes the user's efficiency low when using it. Summary of the Invention

[0006] In view of the problems in the prior art, this application provides a method and device for secure file transmission, which can improve the file transmission efficiency while ensuring the security of file transmission.

[0007] To solve at least one of the above problems, this application provides the following technical solutions:

[0008] In a first aspect, this application provides a method for secure file transmission, including:

[0009] Receiving the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program;

[0010] Performing signature verification on the summary information of files to be uploaded, and performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes;

[0011] If the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded. Among them, the multiple files to be uploaded have been digitally signed one by one through a preset USB key program.

[0012] Further, the performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes includes:

[0013] Calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded before the signature verification. Among them, the multiple files to be uploaded are selected by the user;

[0014] After the signature verification passes, calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded again, and numerically compare the MD5 values before and after.

[0015] Further, the performing signature verification on the summary information of the files to be uploaded includes:

[0016] Check the information consistency between the summary information of the files to be uploaded and the list of signatures to be verified;

[0017] If the information consistency check passes, perform signature verification on the summary information of the files to be uploaded according to a preset key.

[0018] Further, the performing signature verification on the multiple files to be uploaded includes:

[0019] Call the server component of a third-party financial certification center to perform signature verification on the multiple files to be uploaded one by one;

[0020] After the signature verification passes, store the corresponding uploaded file in a specified directory.

[0021] Further, after the numerical comparison of the MD5 values before and after, it includes:

[0022] Judge whether the MD5 values before and after are numerically consistent;

[0023] If so, determine that the MD5 verification passes, otherwise report an error and terminate the signature.

[0024] Further, the checking the information consistency between the summary information of the files to be uploaded and the list of signatures to be verified includes:

[0025] Perform an operation to check the consistency of the total number and / or total size of the files in the summary information of the files to be uploaded and the list of signatures to be verified.

[0026] In a second aspect, the present application provides a file secure transmission device, including:

[0027] A summary information receiving module, configured to receive the summary information of files to be uploaded sent by a user, wherein the summary information of files to be uploaded is digitally signed by a preset U shield program;

[0028] A summary information verification module, configured to perform signature verification on the summary information of files to be uploaded, and perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes;

[0029] A multi-file verification module, configured to, if the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, wherein the multiple files to be uploaded are digitally signed one by one by a preset U shield program.

[0030] Further, the summary information verification module includes:

[0031] An MD5 calculation unit, configured to calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded before the signature verification, wherein the multiple files to be uploaded are selected by the user;

[0032] An MD5 comparison unit, configured to calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded again after the signature verification passes, and perform numerical comparison on the MD5 values before and after.

[0033] Further, the summary information verification module includes:

[0034] An information consistency checking unit, configured to perform information consistency checking on the summary information of files to be uploaded and a linked list to be verified for signature;

[0035] A signature verification unit, configured to, if the information consistency checking passes, perform signature verification on the summary information of files to be uploaded according to a preset key.

[0036] Further, the multi-file verification module includes:

[0037] A third-party verification unit, configured to call the server component of a third-party financial certification center to perform signature verification on the multiple files to be uploaded one by one;

[0038] A file storage unit, configured to store the corresponding uploaded file in a specified directory after the signature verification passes.

[0039] In a third aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of the file secure transmission method are implemented.

[0040] Fourthly, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the file secure transmission method are implemented.

[0041] Fifthly, the present application provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the file secure transmission method are implemented.

[0042] As can be seen from the above technical solutions, the present application provides a file secure transmission method and apparatus. By receiving the summary information of files to be uploaded sent by a user, wherein the summary information of files to be uploaded is digitally signed by a preset U shield program; performing signature verification on the summary information of files to be uploaded, and performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtaining multiple files to be uploaded in the list of files to be uploaded and performing signature verification on the multiple files to be uploaded, thereby being able to improve the file transmission efficiency while ensuring the security of file transmission. Description of the Drawings

[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to these drawings without creative efforts.

[0044] Figure 1 It is one of the flow diagrams of the file secure transmission method in the embodiments of the present application;

[0045] Figure 2 It is another flow diagram of the file secure transmission method in the embodiments of the present application;

[0046] Figure 3 It is yet another flow diagram of the file secure transmission method in the embodiments of the present application;

[0047] Figure 4 It is still another flow diagram of the file secure transmission method in the embodiments of the present application;

[0048] Figure 5 It is one of the structural diagrams of the file secure transmission apparatus in the embodiments of the present application;

[0049] Figure 6 It is another structural diagram of the file secure transmission apparatus in the embodiments of the present application;

[0050] Figure 7The third structural diagram of the file secure transmission device in the embodiments of the present application;

[0051] Figure 8 The fourth structural diagram of the file secure transmission device in the embodiments of the present application;

[0052] Figure 9 The schematic diagram of file secure transmission interaction in a specific embodiment of the present application;

[0053] Figure 10 The schematic diagram of multi - file signature in a specific embodiment of the present application;

[0054] Figure 11 The schematic diagram of multi - file signature verification in a specific embodiment of the present application;

[0055] Figure 12 The structural schematic diagram of the electronic device in the embodiments of the present application. Specific embodiments

[0056] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application.

[0057] In the technical solutions of the present application, the acquisition, storage, use, processing, etc. of data all comply with the relevant regulations of national laws and regulations.

[0058] Considering the problems existing in the prior art, the present application provides a file secure transmission method and device. By receiving the summary information of files to be uploaded sent by the user, wherein the summary information of files to be uploaded is digitally signed by a preset U - shield program; performing signature verification on the summary information of files to be uploaded, and performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtaining multiple files to be uploaded in the list of files to be uploaded and performing signature verification on the multiple files to be uploaded, thereby being able to improve the file transmission efficiency while ensuring the security of file transmission.

[0059] In order to improve the file transmission efficiency while ensuring the security of file transmission, an embodiment of a file secure transmission method is provided in the present application. Refer to Figure 1 , and the file secure transmission method specifically includes the following content:

[0060] Step S101: Receive the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program.

[0061] Optionally, in this application, when the user clicks upload on the page, the system first summarizes the number of files to obtain the current total number of files, the total file size, and the submitter information. The system triggers the API interface provided by the U shield driver program to sign the current summary information, and then sends it to the web application server and registers it for storage in the database server, and returns the result to the PC side.

[0062] Step S102: Perform signature verification on the summary information of files to be uploaded. After the signature verification passes, perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded.

[0063] Optionally, in this application, the file server receives the summary information uploaded by the user, calls the module of the file signature verification service to verify the signature of the summarized information, and returns the result to the PC side; after sending the summary information, start signing each of the multiple files one by one. Before signing, calculate the MD5 value of the file and compare it with the previous MD5 value. If they are inconsistent, report an error and terminate the signature. If they are consistent, perform the signature.

[0064] Step S103: If the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, where the multiple files to be uploaded are digitally signed one by one by a preset U shield program.

[0065] Optionally, in this application, the system triggers the file upload web client program to send the signature information of the U shield and the path information of multiple files selected by the customer to the web application server and registers it for storage in the database server, and returns the result to the PC side; the file server receives the files uploaded by the user, calls the module of the file signature verification service to verify the signature of the signed files, and returns the result to the PC side; the application server calls the API to obtain the files on the file server according to the information in the database by the asynchronous module.

[0066] As can be seen from the above description, the file secure transmission method provided by the embodiment of this application can receive the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program; perform signature verification on the summary information of files to be uploaded, and perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, thereby being able to improve the file transmission efficiency while ensuring the security of file transmission.

[0067] In an embodiment of the file secure transmission method of the present application, referring to Figure 2 , the following specific content may also be included:

[0068] Step S201: Calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded before the signature verification, where the multiple files to be uploaded are selected by the user.

[0069] Step S202: After the signature verification passes, calculate the MD5 values of the multiple files to be uploaded in the list of files to be uploaded again, and compare the MD5 values before and after numerically.

[0070] Optionally, in the present application, when the file server receives the summary information uploaded by the user, it calls the module of the file signature verification service to verify the signature of the summarized information and returns the result to the PC side; after sending the summary information, it starts to sign each of the multiple files one by one. Before signing, calculate the MD5 value of the file and compare it with the previous MD5 value. If they are inconsistent, an error is reported and the signature is terminated. If they are consistent, the signature is performed.

[0071] In an embodiment of the file secure transmission method of the present application, referring to Figure 3 , the following specific content may also be included:

[0072] Step S301: Check the information consistency between the summary information of the files to be uploaded and the linked list of signatures to be verified.

[0073] Step S302: If the information consistency check passes, perform signature verification on the summary information of the files to be uploaded according to a preset key.

[0074] Optionally, the file server program of the present application checks the total number and / or total size of the files in the summary information against the files in the linked list of signatures to be verified.

[0075] In an embodiment of the file secure transmission method of the present application, referring to Figure 4 , the following specific content may also be included:

[0076] Step S401: Call the server component of the third-party financial certification center to perform signature verification on each of the multiple files to be uploaded one by one.

[0077] Step S402: After the signature verification passes, store the corresponding uploaded file in a specified directory.

[0078] Optionally, in the present application, the file server program calls the server component provided by CFCA for each file in the linked list of signatures to be verified to verify the signature of the current signed file.

[0079] In order to improve the file transfer efficiency while ensuring the security of file transfer, an embodiment of a file security transfer device for implementing all or part of the content of the file security transfer method is provided in this application. Refer to Figure 5 The file security transfer device specifically includes the following content:

[0080] A summary information receiving module 10, configured to receive the summary information of the files to be uploaded sent by the user, where the summary information of the files to be uploaded is digitally signed by a preset U shield program.

[0081] A summary information verification module 20, configured to perform signature verification on the summary information of the files to be uploaded, and perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes.

[0082] A multi-file verification module 30, configured to, if the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, where the multiple files to be uploaded are digitally signed one by one by a preset U shield program.

[0083] As can be seen from the above description, the file security transfer device provided in the embodiment of this application can receive the summary information of the files to be uploaded sent by the user, where the summary information of the files to be uploaded is digitally signed by a preset U shield program; perform signature verification on the summary information of the files to be uploaded, and perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, thereby being able to improve the file transfer efficiency while ensuring the security of file transfer.

[0084] In an embodiment of the file security transfer device of this application, refer to Figure 6 The summary information verification module 10 includes:

[0085] An MD5 calculation unit 11, configured to calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded before the signature verification, where the multiple files to be uploaded are selected by the user.

[0086] An MD5 comparison unit 12, configured to calculate the MD5 values of multiple files to be uploaded in the list of files to be uploaded again after the signature verification passes, and compare the MD5 values before and after numerically.

[0087] In an embodiment of the file security transfer device of this application, refer to Figure 7 The summary information verification module 10 includes:

[0088] The information consistency verification unit 13 is used to verify the information consistency between the summary information of the file to be uploaded and the list of signatures to be verified.

[0089] The signature verification unit 14 is used to, if the information consistency verification passes, verify the signature of the summary information of the file to be uploaded according to a preset key.

[0090] In an embodiment of the file secure transmission device of the present application, refer to Figure 8 , the multi-file verification module 30 includes:

[0091] The third-party verification unit 31 is used to call the server component of the third-party financial certification center to verify the signatures of the multiple files to be uploaded one by one.

[0092] The file storage unit 32 is used to store the corresponding uploaded file in a specified directory after the signature verification passes.

[0093] To further illustrate the present solution, the present application also provides a specific application example of a system for implementing a file secure transmission method using the above file secure transmission device, specifically including the following content:

[0094] Refer to Figure 9 , the system includes a USB key 100, a PC computer 200, a web application server 300, a database server 400, a file upload server 500, a file signature verification server 600, and an application server 700. The user uses the USB key 100 to log in to the online bank on the PC computer 200, uses the online bank file upload function, selects the file to be uploaded from the local disk. The online bank file upload function page supports the user to select multiple files. After the selection is completed, the system calculates the MD5 value of each file for backup.

[0095] When the user clicks the upload button on the page, the system first aggregates the number of files to obtain the current total number of files, the total file size, and the submitter information. The system triggers the API interface provided by the U shield 100 driver to sign the current aggregated information, and then sends it to the web application server 300 and registers and stores it in the database server 400, and returns the result to the PC client 200; The file server 500 receives the aggregated information uploaded by the user, calls the module of the file signature verification service 600 to verify the signature of the signed aggregated information, and returns the result to the PC client 200; After sending the aggregated information, start signing each file one by one. Before signing, calculate the MD5 value of the file and compare it with the previous MD5 value. If they are inconsistent, report an error and terminate the signing. If they are consistent, perform the signing. The system triggers the file upload web client program to upload the signed information of the user's selection through the U shield 100 and the path information of multiple files to the web application server 3 hundred and register and store it in the database server 400, and return the result to the PC client 200; The file server 500 receives the files uploaded by the user, calls the module of the file signature verification service 600 to verify the signature of the signed files, and returns the result to the PC client 200; The application server 700 calls the API to obtain the files on the file server according to the information in the database 400 according to the asynchronous module. [[ID=—2]]

[0096] In a specific embodiment, the present application provides a multi-file signature process, see Figure 10 :

[0097] Step A1, the user selects the files to be uploaded on the online banking page, and the system calculates the MD5 value of the selected files.

[0098] Step A2, after selecting a file, the system prompts the user whether all the files to be uploaded have been selected. If not, continue to select. If selected, the upload button is displayed.

[0099] Step A3, after the user clicks the upload button.

[0100] Step A4, the system generates a summary information (the current total number of files, the total file size, and the submitter information).

[0101] Step A5, the upload client is called, and at the same time, the API in the U shield is called to pop up a human-machine interaction interface for password input to sign the summary information, and then upload it to the file server after signing.

[0102] Step A6, traverse the list of files to be uploaded, recalculate the MD5 value of each file, and compare it with the MD5 value calculated when selecting the files before.

[0103] Step A7, the system checks whether the recalculated MD5 is consistent with the MD5 when the file was selected. If they are consistent, proceed to Step A9; if not, execute Step A8 to terminate the upload.

[0104] Step A8, the system reports an error and terminates the file upload.

[0105] Step A9, the system signature module reads each file on the disk for digital signature according to the previously obtained certificate and private key.

[0106] Step A10, after all file signatures are completed, call the upload module. The file upload module pops up a window to display the upload progress and uploads the signed files to the file server one by one.

[0107] In a specific embodiment, the present application provides a multi-file verification and signature process. See Figure 11 :

[0108] Step B1, the file server receives the signed files uploaded by the file upload client.

[0109] Step B2, determine whether it is summary information. If it is summary information, execute B4; if not, execute B3.

[0110] Step B3, the file server program registers the current file name to be verified and the server-side path in the linked list of files to be verified. After registration, return to Step B1.

[0111] Step B4, the file server program verifies the summary information.

[0112] Step B5, judge the verification result. If the verification fails, directly return to the client; if the verification is successful, continue to Step B6.

[0113] Step B6, the file server program extracts the total number, total size, and submitter information from the summary information.

[0114] Step B7, the file server program continues to judge whether all files have been received. If not, continue to wait; if all files have been received, execute Step B8.

[0115] Step B8, the file server program checks the total number and total size with the files in the linked list of files to be verified according to the summary information.

[0116] Step B9, judge the result of the summary information check. If it fails, return the verification failure to the client; if it is successful, execute Step B10.

[0117] Step B10, the file server program calls the server-side components provided by CFCA for each file in the linked list of files to be verified to verify the current signed file.

[0118] Step B11, the file server - side program returns the signature verification result to the client.

[0119] From the hardware level, in order to ensure the security of file transmission while improving the file transmission efficiency, this application provides an embodiment of an electronic device for implementing all or part of the content in the file security transmission method. The electronic device specifically includes the following:

[0120] A processor, a memory, a communications interface, and a bus; wherein, the processor, the memory, and the communications interface complete communication with each other through the bus; the communications interface is used to implement information transmission between the file security transmission device and related devices such as the core business system, the user terminal, and the relevant database, etc. The logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., and this embodiment is not limited thereto. In this embodiment, the logic controller can be implemented with reference to the embodiments of the file security transmission method and the embodiments of the file security transmission device, and its content is incorporated herein, and the repeated parts will not be elaborated.

[0121] It can be understood that the user terminal may include a smart phone, a tablet electronic device, a network set - top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle - mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, smart watches, smart bracelets, etc.

[0122] In practical applications, part of the file security transmission method can be executed on the electronic device side as described above, or all operations can be completed in the client device. Specifically, it can be selected according to the processing capacity of the client device and the limitations of the user usage scenario, etc. This application does not make a limitation in this regard. If all operations are completed in the client device, the client device may further include a processor.

[0123] The above - mentioned client device may have a communication module (i.e., a communication unit), which can communicate with a remote server to realize data transmission with the server. The server may include a server on the task scheduling center side, and in other implementation scenarios, it may also include a server of an intermediate platform, such as a server of a third - party server platform having a communication link with the task scheduling center server. The server may include a single computer device, or a server cluster composed of multiple servers, or a server structure of a distributed device.

[0124] Figure 12Schematic block diagram of the system configuration of the electronic device 9600 according to an embodiment of the present application. As Figure 12 shown, the electronic device 9600 may include a central processing unit 9100 and a memory 9140; the memory 9140 is coupled to the central processing unit 9100. It should be noted that this Figure 12 is exemplary; other types of structures may also be used to supplement or replace this structure to achieve telecommunication functions or other functions.

[0125] In one embodiment, the function of the file secure transmission method may be integrated into the central processing unit 9100. Among them, the central processing unit 9100 may be configured to perform the following controls:

[0126] Step S101: Receive the summary information of the files to be uploaded sent by the user, where the summary information of the files to be uploaded is digitally signed by a preset U shield program.

[0127] Step S102: Perform signature verification on the summary information of the files to be uploaded. After the signature verification passes, perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded.

[0128] Step S103: If the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, where the multiple files to be uploaded are digitally signed one by one by a preset U shield program.

[0129] As can be seen from the above description, the electronic device provided by the embodiment of the present application, by receiving the summary information of the files to be uploaded sent by the user, where the summary information of the files to be uploaded is digitally signed by a preset U shield program; performing signature verification on the summary information of the files to be uploaded, and performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, thereby being able to improve the file transmission efficiency while ensuring the security of file transmission.

[0130] In another embodiment, the file secure transmission device may be separately configured from the central processing unit 9100. For example, the file secure transmission device may be configured as a chip connected to the central processing unit 9100, and the function of the file secure transmission method is implemented through the control of the central processing unit.

[0131] As Figure 12 shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include Figure 12All components shown in [description]; in addition, the electronic device 9600 may further include Figure 12 components not shown in [description], and reference may be made to the prior art.

[0132] As Figure 12 shown, the central processing unit 9100, sometimes also referred to as a controller or operation control, may include a microprocessor or other processor device and / or logic device. The central processing unit 9100 receives inputs and controls the operation of the various components of the electronic device 9600.

[0133] Among them, the memory 9140 may be, for example, one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. It can store the above information related to failures, and can also store programs for executing relevant information. And the central processing unit 9100 can execute the programs stored in the memory 9140 to implement information storage or processing, etc.

[0134] The input unit 9120 provides inputs to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.

[0135] The memory 9140 may be a solid-state memory, for example, a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be such a memory that stores information even when powered off, can be selectively erased and has more data. Examples of such a memory are sometimes referred to as EPROMs, etc. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142, which is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.

[0136] The memory 9140 may also include a data storage unit 9143, which is used to store data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers of the electronic device for communication functions and / or for performing other functions of the electronic device (such as a messaging application, an address book application, etc.).

[0137] The communication module 9110 is a transmitter / receiver 9110 that transmits and receives signals via the antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processor 9100 to provide input signals and receive output signals, which can be the same as in the case of a conventional mobile communication terminal.

[0138] Based on different communication technologies, multiple communication modules 9110 can be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) 9110 is also coupled to the speaker 9131 and the microphone 9132 via the audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby implementing the usual telecommunication functions. The audio processor 9130 can include any suitable buffers, decoders, amplifiers, etc. Additionally, the audio processor 9130 is also coupled to the central processor 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.

[0139] Embodiments of the present application also provide a computer-readable storage medium capable of implementing all steps in the file secure transmission method where the execution subject in the above embodiments is a server or a client. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, all steps in the file secure transmission method where the execution subject in the above embodiments is a server or a client are implemented. For example, when the processor executes the computer program, the following steps are implemented:

[0140] Step S101: Receive the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program.

[0141] Step S102: Perform signature verification on the summary information of files to be uploaded, and perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes.

[0142] Step S103: If the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, where the multiple files to be uploaded are digitally signed one by one by a preset U shield program.

[0143] As can be seen from the above description, the computer-readable storage medium provided by the embodiments of the present application receives the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program; performs signature verification on the summary information of files to be uploaded, and performs MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtains multiple files to be uploaded in the list of files to be uploaded and performs signature verification on the multiple files to be uploaded, thereby being able to improve the file transmission efficiency while ensuring the security of file transmission.

[0144] An embodiment of the present application also provides a computer program product that can implement all steps in the file security transmission method with the execution subject being a server or a client in the above embodiments. When the computer program / instructions are executed by a processor, the steps of the file security transmission method are implemented. For example, the computer program / instructions implement the following steps:

[0145] Step S101: Receive the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program.

[0146] Step S102: Perform signature verification on the summary information of files to be uploaded, and perform MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes.

[0147] Step S103: If the MD5 verification passes, obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded, where the multiple files to be uploaded are digitally signed one by one by a preset U shield program.

[0148] As can be seen from the above description, the computer program product provided by the embodiments of the present application receives the summary information of files to be uploaded sent by the user, where the summary information of files to be uploaded is digitally signed by a preset U shield program; performs signature verification on the summary information of files to be uploaded, and performs MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes; if the MD5 verification passes, obtains multiple files to be uploaded in the list of files to be uploaded and performs signature verification on the multiple files to be uploaded, thereby being able to improve the file transmission efficiency while ensuring the security of file transmission.

[0149] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0150] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatuses), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one or more of the processes Figure 1 or a plurality of processes and / or blocks

[0151] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one or more of the processes Figure 1 or a plurality of processes and / or blocks

[0152] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in Figure 1 one or more of the processes Figure 1 or a plurality of processes and / or blocks

[0153] Specific embodiments are applied in the present invention to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A method for secure file transmission, characterized in that: Applied to a file server, the method includes: Receiving summary information of files to be uploaded sent by a user, where the summary information of files to be uploaded is digitally signed by a preset U shield program of the client; Performing signature verification on the summary information of files to be uploaded. After the signature verification passes, the client performs MD5 verification on multiple files to be uploaded in the list of files to be uploaded; If the MD5 verification passes and multiple files to be uploaded in the list of files to be uploaded are digitally signed one by one by the preset U shield program of the client, then obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded.

2. The method for secure file transmission according to claim 1, wherein: The performing MD5 verification on multiple files to be uploaded in the list of files to be uploaded after the signature verification passes includes: Calculating the MD5 values of multiple files to be uploaded in the list of files to be uploaded before the signature verification, where the multiple files to be uploaded are selected by the user; Calculating the MD5 values of multiple files to be uploaded in the list of files to be uploaded again after the signature verification passes, and comparing the MD5 values before and after numerically.

3. The file security transmission method according to claim 1, wherein The performing signature verification on the summary information of files to be uploaded includes: Performing information consistency check on the summary information of files to be uploaded and the signature verification list; If the information consistency check passes, then perform signature verification on the summary information of files to be uploaded according to a preset key.

4. The file secure transmission method according to claim 1, characterized in that The performing signature verification on the multiple files to be uploaded includes: Invoking the server component of a third-party financial certification center to perform signature verification on the multiple files to be uploaded one by one; After the signature verification passes, storing the corresponding file to be uploaded in a specified directory.

5. The method for secure file transmission according to claim 2, wherein: After the numerical comparison of the MD5 values before and after, it includes: Judging whether the MD5 values before and after are numerically the same; If so, determining that the MD5 verification passes, otherwise reporting an error and terminating the signature.

6. The file secure transmission method according to claim 3, wherein The performing information consistency check on the summary information of files to be uploaded and the signature verification list includes: Performing an operation of checking the consistency of the total number and / or total size of the files in the summary information of files to be uploaded and the signature verification list.

7. A file secure transmission device, characterized in that, Configured in a file server, it includes: A summary information receiving module, used to receive summary information of files to be uploaded sent by a user, where the summary information of files to be uploaded is digitally signed by a preset U shield program of the client; A summary information verification module, used to perform signature verification on the summary information of files to be uploaded. After the signature verification passes, the client performs MD5 verification on multiple files to be uploaded in the list of files to be uploaded; A multi-file verification module, used to, if the MD5 verification passes and multiple files to be uploaded in the list of files to be uploaded are digitally signed one by one by the preset U shield program of the client, then obtain multiple files to be uploaded in the list of files to be uploaded and perform signature verification on the multiple files to be uploaded.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, it implements the steps of the file secure transmission method described in any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the file secure transmission method described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by a processor, the steps of the file secure transmission method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Cleartext-document public network safety transmission system based on USBKEY

    CN104917741A

  • Cross-section file transmission method and system

    CN106936898A