Data identification method, device and storage medium

By using fingerprint information comparison and storage space of other terminals or servers in terminal security software, the target identification results of data to be identified are determined, which solves the problem of low terminal file identification efficiency and improves scanning speed and resource utilization.

CN115865355BActive Publication Date: 2025-08-08SANGFOR TECH INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111108374.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-22
Publication Date
2025-08-08
Estimated Expiration
2041-09-22

AI Technical Summary

Technical Problem

Existing terminal security software is less efficient when performing file authentication, the scanning process consumes resources and affects business operation, and the scanning speed is slow.

Method used

By determining that the fingerprint information of the data to be identified is compared with the scanned fingerprint information of the local preset storage space, if there is no result, the target identification result will be determined using the scanned fingerprint information and identification results in the storage space of other terminals or servers to reduce repeated scanning.

Benefits of technology

It improves the efficiency of terminal file identification, reduces scanning time, reduces resource consumption, and ensures normal operation of business.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865355B_ABST
    Figure CN115865355B_ABST
Patent Text Reader

Abstract

The present invention provides a data identification method, device and storage medium. By determining the fingerprint information of the data to be identified, the fingerprint information is compared with the scanned fingerprint information of the local corresponding preset storage space to obtain a comparison result; if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals, the target identification result of the data to be identified is determined. Since the local terminal can obtain the corresponding target identification result through the fingerprint information combined with the storage space corresponding to other terminals when there is no scanning, the time for scanning and identification is saved, thereby improving the identification efficiency of the data to be identified. In the case where the server is connected to multiple terminals, each terminal can obtain the corresponding identification result through the fingerprint information combined with the other terminals, thereby improving the identification efficiency of each terminal for files.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of terminal security technology, and in particular to a data authentication method, device, and storage medium. Background Art

[0002] All current endpoint security products, such as antivirus software, endpoint protection platforms (EPP), and endpoint detection and response (EDR), rely on scanning to identify all files on the endpoint to detect potential virus threats or suspicious files. This scanning process requires traversing, reading, and detecting all files, and with hundreds of thousands of files on the endpoint, scanning is very slow. The industry's typical approach to speeding up this process is to increase the speed of the file scanning engine.

[0003] In recent years, challenges such as attack and defense, ransomware attacks, and other threats have gradually led many enterprises to prioritize endpoint security. Deploying enterprise antivirus, EPP, and EDR endpoint security software has become the norm. Using these software to initiate threat scanning and identification, and regularly checking endpoints across the entire network, has become a commonplace operation and maintenance task for Internet Technology (IT). However, the scanning process of such software typically consumes considerable resources, potentially disrupting normal business operations. Slow scanning speeds increase identification time, impacting business operations. Therefore, the current low efficiency of file identification in endpoints is a pressing issue that needs to be addressed. Summary of the Invention

[0004] The embodiments of the present invention provide a data authentication method, device, and storage medium, which can effectively improve the efficiency of file authentication within a terminal.

[0005] The technical solution of the present invention is achieved as follows:

[0006] An embodiment of the present invention provides a data authentication method, comprising:

[0007] Determine the fingerprint information of the data to be authenticated, compare the fingerprint information with the scanned fingerprint information in the corresponding local preset storage space, and obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and the corresponding authentication result;

[0008] If the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then:

[0009] Based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal, a target identification result of the data to be identified is determined.

[0010] In the above solution, determining the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal includes:

[0011] Sending the fingerprint information of the data to be identified to the server side in a first query instruction;

[0012] Receive the target identification result corresponding to the fingerprint information fed back by the server in response to the first query instruction; the target identification result is obtained by querying the shared repository of the server; the shared repository stores the identification results of multiple data shared by various terminal sources.

[0013] In the above solution, determining the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal includes:

[0014] carrying the fingerprint information of the data to be authenticated in a second query instruction and sending it to the other terminals;

[0015] Receive the target identification result corresponding to the fingerprint information fed back by at least one other terminal in response to the second query instruction; the target identification result is obtained by querying the storage space corresponding to the at least one other terminal.

[0016] In the above solution, after the fingerprint information of the data to be identified is carried in the first query instruction and sent to the server, the method further includes:

[0017] receiving a not-found message fed back by the server in response to the first query instruction; the not-found message indicating that the server has not found the target identification result of the fingerprint information in the shared storage repository;

[0018] In response to the not-found message, performing an authentication scan on the data to be authenticated to determine a target authentication result of the data to be authenticated;

[0019] After establishing target mapping information between the target identification result and the fingerprint information, the target mapping information is stored in the preset storage space, and the target mapping information is sent to the server for the server to update the shared storage repository.

[0020] In the above solution, the method further includes:

[0021] Calculating the historical identification data to obtain historical fingerprint information of the historical identification data;

[0022] Scanning the historical identification data to determine a historical identification result of the historical identification data;

[0023] The historical mapping information between the historical identification result and the historical fingerprint information is stored in the preset storage space, and the historical mapping information is sent to the server for the server to update the shared storage repository.

[0024] In the above solution, after receiving the target identification result corresponding to the fingerprint information fed back by the server in response to the first query instruction, the method further includes:

[0025] The target identification result and the fingerprint information are combined to form target mapping information, and the target mapping information is updated in the preset storage space.

[0026] The embodiment of the present invention further provides a data authentication method, which is applied to a server and includes:

[0027] receiving a first query instruction sent by a local terminal, wherein the first query instruction carries fingerprint information of data to be authenticated;

[0028] Determining a query result corresponding to the fingerprint information in a shared repository; the shared repository stores authentication results of multiple data shared by other terminal sources;

[0029] If the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared storage repository, the target identification result is extracted from the shared storage repository and sent to the local terminal.

[0030] In the above solution, after determining the query result corresponding to the fingerprint information in the shared repository, the method further includes:

[0031] If the query result indicates that the target identification result of the fingerprint information is not found in the shared storage repository, sending a not found message to the local terminal; the not found message indicates that the target identification result of the fingerprint information is not found in the shared storage repository;

[0032] Receive target mapping information sent by the local terminal in response to the not found message, and update the target mapping information in the shared repository; the target mapping information is correspondence information between the target identification result of the data to be identified and the fingerprint information.

[0033] An embodiment of the present invention further provides a data authentication method, applied to at least one other terminal, comprising:

[0034] receiving a second query instruction sent by the local terminal, wherein the second query instruction carries fingerprint information of the data to be authenticated;

[0035] Determining the query result corresponding to the fingerprint information in the storage space; the storage space stores the scanned fingerprint information of the data and the corresponding identification result;

[0036] If the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space, the target identification result is extracted from the storage space and sent to the local terminal.

[0037] An embodiment of the present invention further provides a data identification device, applied to a local terminal, comprising:

[0038] a determination unit, configured to determine fingerprint information of the data to be authenticated, and compare the fingerprint information with scanned fingerprint information in a local preset storage space to obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding authentication result;

[0039] The determination unit is further configured to, if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, determine the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals.

[0040] The embodiment of the present invention further provides a data identification device, which is applied to a server and includes:

[0041] A first receiving unit is configured to receive a first query instruction sent by a local terminal, wherein the first query instruction carries fingerprint information of data to be authenticated;

[0042] A first query unit is configured to determine a query result corresponding to the fingerprint information in a shared repository; the shared repository stores authentication results of multiple data shared by other terminal sources;

[0043] The first sending unit is configured to extract the target identification result from the shared storage repository if the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared storage repository, and send the target identification result to the local terminal.

[0044] An embodiment of the present invention further provides a data authentication device, applied to at least one other terminal, comprising:

[0045] a second receiving unit, configured to receive a second query instruction sent by a local terminal, wherein the second query instruction carries fingerprint information of the data to be authenticated;

[0046] a second query unit, configured to determine a query result corresponding to the fingerprint information in a storage space; the storage space storing scanned fingerprint information and corresponding identification results;

[0047] The second sending unit is configured to extract the target identification result from the storage space and send the target identification result to the local terminal if the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space.

[0048] An embodiment of the present invention further provides a data authentication device, comprising a first memory and a first processor, wherein the first memory stores a computer program that can be run on the first processor, and the first processor implements the above method when executing the program.

[0049] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, which implements the above method when executed by a first processor.

[0050] In an embodiment of the present invention, by determining the fingerprint information of the data to be identified, the fingerprint information is compared with the scanned fingerprint information in a local corresponding preset storage space (the preset storage space may be stored in the local terminal or may not be stored in the local terminal, and this application is not limited to this) (the specific "comparison operation" may be executed in the local terminal, or the local terminal may send a trigger information to other devices, and the other devices may execute the "comparison operation", and this application is not limited to this), to obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and the corresponding identification result; if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal (similarly, the storage space corresponding to the other terminal may be stored locally in the corresponding other terminal or may not be stored locally in the corresponding other terminal, for example, the storage space corresponding to the other terminal X may be stored locally in X or may not be stored locally in X, and this application is not limited to this), the target identification result of the data to be identified is determined. Since the local terminal first determines whether the data to be identified has been scanned locally through fingerprint information, the local terminal can obtain the corresponding target identification result through the fingerprint information combined with the corresponding storage space of other terminals if it has not been scanned, saving the time of scanning and identification, thereby improving the identification efficiency of the terminal for the data to be identified. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1An optional flow chart of a data identification method provided in an embodiment of the present invention;

[0052] Figure 2 An optional effect diagram of the data identification method provided by the embodiment disclosed in the present invention;

[0053] Figure 3 An optional effect diagram of the data identification method provided by the embodiment disclosed in the present invention;

[0054] Figure 4 An optional flow chart of a data identification method provided in an embodiment of the present invention;

[0055] Figure 5 An optional flow chart of a data identification method provided in an embodiment of the present invention;

[0056] Figure 6 An optional flow chart of a data identification method provided in an embodiment of the present invention;

[0057] Figure 7 An interactive diagram of a data identification method provided by an embodiment of the present invention;

[0058] Figure 8 Schematic diagram of the structure of the data identification device provided in the embodiment disclosed by the present invention Figure 1 ;

[0059] Figure 9 A hardware entity diagram of a data identification device provided by an embodiment of the present invention Figure 1 ;

[0060] Figure 10 Schematic diagram of the structure of the data identification device provided in the embodiment disclosed by the present invention Figure 2 ;

[0061] Figure 11 A hardware entity diagram of a data identification device provided by an embodiment of the present invention Figure 2 ;

[0062] Figure 12 Schematic diagram of the structure of the data identification device provided in the embodiment disclosed by the present invention Figure 3 ;

[0063] Figure 13 A hardware entity diagram of a data identification device provided by an embodiment of the present invention Figure 3 ; DETAILED DESCRIPTION

[0064] In order to make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions of the present invention are further elaborated in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limiting the present invention. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0065] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0066] If similar descriptions of "first / second" appear in the invention document, the following explanation is added. In the following description, the terms "first\second\third" involved are only used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that "first\second\third" can be interchanged with the specific order or sequence where permitted, so that the embodiments of the invention described herein can be implemented in an order other than that illustrated or described herein.

[0067] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present invention pertains. The terms used herein are for the purpose of describing embodiments of the present invention only and are not intended to limit the present invention.

[0068] Currently, all endpoint security products in the industry are typically installed on endpoints as software agents. Specifically developed software is installed on endpoints (such as personal computers (PCs) or server hosts) to authenticate files. Software agents include client software deployed on the endpoints and server software that centrally manages these software agents. Software agents are based on a client / server model. Existing antivirus software includes Endpoint Detection and Response (EDR) and Endpoint Protection Platforms (EPP). Endpoint security products such as EDR and EPP are typically deployed as software agents.

[0069] EDR is a popular endpoint security protection device. EDR deploys agent software on endpoint hosts to perform multiple security functions, including information collection, threat detection, threat prevention, and threat response. This protection device has a manager side, operating in a client / server format. The agent's collection and detection information is synchronized to the manager for presentation and comprehensive detection. The manager then transmits instructions to the agent through policy issuance. EPP is a solution deployed on endpoint devices to prevent file-based malware attacks, detect malicious activity, and provide the investigation and remediation capabilities required to respond to dynamic security events and alerts.

[0070] However, the EDR and EPP scanning processes typically consume significant resources, potentially impacting normal business operations. Slow scanning speeds increase identification time, potentially impacting business operations. Therefore, the current low efficiency of file identification in terminals is an urgent issue that needs to be addressed.

[0071] In order to solve the above technical problems, an embodiment of the present invention provides a data identification method. Figure 1 This is an optional flow chart of the data identification method provided by the embodiment of the present invention, which is applied to the terminal. Figure 1 The steps shown are explained.

[0072] S101. Determine fingerprint information of data to be authenticated, compare the fingerprint information with scanned fingerprint information in a local corresponding preset storage space, and obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding authentication result.

[0073] In an embodiment of the present invention, the local terminal determines the fingerprint information of the data to be authenticated, compares the fingerprint information with the scanned fingerprint information in the corresponding local preset storage space, and obtains a comparison result. The preset storage space stores the scanned fingerprint information of the data and the corresponding authentication result.

[0074] In an embodiment of the present invention, the local terminal may calculate all or part of the binary information of the data to be authenticated using a message digest algorithm (md5) to obtain fingerprint information of the data to be authenticated. In an embodiment of the present invention, the local terminal may also calculate the fingerprint information of the data to be authenticated using other cryptographic calculation methods, such as, for example, a hash algorithm. Specific methods for calculating fingerprint information are known in the art and are not limited in this application.

[0075] In an embodiment of the present invention, the data to be authenticated may include any one of files, folders, text data, video data, image data, and audio data in a directory on the local terminal. The local terminal may be any one of multiple terminals connected to the server.

[0076] In an embodiment of the present invention, the preset storage space includes the scanned fingerprint information of the scanned data of the local terminal and the corresponding identification results. The preset storage space may also include the scanned fingerprint information of the scanned data of other terminals and the corresponding identification results (for example, the fingerprint information and identification results synchronized to the local terminal by other terminals). The corresponding local preset storage space may be configured on the local terminal device or not. In addition, the specific comparison algorithm execution may be performed by the local terminal or not.

[0077] In this embodiment of the present invention, the comparison result indicates whether the data to be authenticated exists in the preset storage space. In this embodiment of the present invention, the data to be authenticated may also include multiple data items. The local terminal determines multiple fingerprint information items for the multiple data items, compares the multiple fingerprint information items with the scanned fingerprint information in the preset storage space, and determines multiple comparison results corresponding to the multiple fingerprint information items.

[0078] In the embodiment of the present invention, for all the files on the terminals / hosts of most enterprises, due to similar businesses (such as office PCs), the proportion of the same files on each terminal is relatively high (more than 50% or even more, such as system-related files, commonly used office software, office files passed between employees, etc.). The present invention will take advantage of this feature and combine it with the existing "local storage" of current key security software (that is, the "preset storage space" mentioned above can be stored in the local terminal, so that the local terminal can access it faster) to achieve the purpose. The "local storage" in the usual terminal security software is also called "scanning fingerprint", that is, the fingerprint information such as md5 + scanning results of the scanned files are locally stored and recorded, so that the next time a scan is performed, the scan can be skipped for the same file, thereby speeding up the scan.

[0079] To further explain the embodiments of the present invention, Figure 2 For illustration, assuming that the above “preset storage space” stores the identification results of the files scanned by the local terminal, all local files of the local terminal can be divided into the following categories: Figure 2The following types of files are shown: files that have been scanned locally (recorded in the preset storage space) and files that have not been scanned locally (not recorded in the preset storage space). Among them, files that have not been scanned locally may correspond to files that have been scanned by other terminals or files that have not been scanned by other terminals. In the present invention, a shared database can be established in advance on the server side. The terminal can first obtain the scan results of files that have been scanned by other terminals and have not been scanned locally from the shared storage library on the server side. In this way, the terminal does not need to perform a full scan again, but only needs to scan the files that have been scanned by other terminals and have not been scanned locally. Figure 2 Scan the "files that have not been scanned by other terminals" in the local terminal, thereby improving the scanning efficiency of all local files on the local terminal.

[0080] S102. If the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then: based on the scanned fingerprint information and corresponding identification results stored in the storage space corresponding to the other terminal, determine the target identification result of the data to be identified.

[0081] In an embodiment of the present invention, if the comparison result obtained by the local terminal indicates that there is no identification result of the data to be identified in the preset storage space, then: based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals, the target identification result of the data to be identified is determined.

[0082] The storage space corresponding to other terminals may be configured on the corresponding terminals or not. The source of the scanned data stored in the storage space may include the identification results of the terminal corresponding to the storage space scanning the local data, and may also include the identification results of other terminals.

[0083] In an embodiment of the present invention, if the comparison result obtained by the local terminal indicates that the data to be authenticated does not exist in the preset storage space, the local terminal sends the fingerprint information of the data to be authenticated to the server in a first query instruction. The local terminal receives the server's response to the first query instruction, extracts the target authentication result from the shared storage, and returns it.

[0084] In an embodiment of the present invention, if the comparison result obtained by the local terminal indicates that the predetermined storage space does not contain the identification data, the local terminal transmits the fingerprint information of the identification data to the plurality of other terminals along with the second query instruction. The local terminal receives a response to the second query instruction from at least one of the other terminals, extracts the target identification result from the corresponding storage space, and feeds back the response.

[0085] In an embodiment of the present invention, by determining the fingerprint information of the data to be identified, the fingerprint information is compared with the scanned fingerprint information of the local corresponding preset storage space to obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding identification result; if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals, the target identification result of the data to be identified is determined. Since the local terminal first determines whether the local data to be identified has been scanned by the fingerprint information, if it has not been scanned, the local terminal can obtain the corresponding target identification result through the fingerprint information combined with the storage space corresponding to other terminals, thereby saving the time of scanning and identification, thereby improving the identification efficiency of the terminal for the data to be identified. In the case of multiple terminals connected to the server, each terminal can obtain the corresponding identification result through the fingerprint information combined with the storage space corresponding to other terminals, thereby improving the identification efficiency of each terminal for the file.

[0086] In some embodiments, Figure 1 The illustrated S102 can also be implemented through S103 to S104 , which will be described in conjunction with each step.

[0087] S103: If the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then: fingerprint information of the data to be identified is carried in a first query instruction and sent to the server.

[0088] In the embodiment of the present invention, if the local terminal detects that the comparison result indicates that there is no data to be authenticated in the preset storage space, the fingerprint information of the authentication data is carried in the first query instruction and sent to the server.

[0089] In the embodiment of the present invention, the local terminal may establish a communication connection with the server in advance. The local terminal may send the fingerprint information of the data to be identified to the server in the first query instruction through the communication connection established in advance with the server.

[0090] The application scenarios of the embodiments of the present invention can be scenario 1 where an enterprise internal server is connected to multiple terminals, or scenario 2 where a cloud in a certain region is connected to multiple terminals. The server in scenario 1 is a server, and the server in scenario 2 is a cloud server.

[0091] In the embodiment of the present invention, combined with Figure 3, the server 100 can connect to n terminals at the same time. That is, the n terminals include: terminal 1, terminal 2 to terminal n. Among them, each terminal corresponds to a preset storage space. Each preset storage space stores the scanned fingerprint information of the scanned data of the corresponding terminal and the corresponding identification results (that is: the preset storage space of terminal 1 stores the fingerprint information and identification results of the data scanned locally by terminal 1, the preset storage space of terminal 2 stores the fingerprint information and identification results of the data scanned locally by terminal 2... the preset storage space of terminal n stores the fingerprint information and identification results of the data scanned locally by terminal n). The server 100 establishes a shared repository. The shared repository stores the fingerprint information of the scanned data shared by each terminal and its corresponding identification results. When terminal 1 has new data, terminal 1 scans the new data and obtains the identification results. Terminal 1 reports the fingerprint information of the new data and the corresponding identification results to update the storage, that is, reports the fingerprint information of the new data and the corresponding identification results to the server, so that the server can update the shared repository. When other terminals have new data, they report the fingerprint information of the new data and the corresponding identification results to the server for the server to update the shared storage library. At the same time, the server sends the fingerprint information of the new data of other terminals and the corresponding identification results to terminal 1 for terminal 1 to update the corresponding preset storage space.

[0092] S104: Receive the target identification result corresponding to the fingerprint information fed back by the server in response to the first query instruction.

[0093] In this embodiment of the present invention, a local terminal receives a target identification result corresponding to fingerprint information from a server in response to a first query instruction. The target identification result is obtained by querying a shared repository on the server. The shared repository stores identification results of multiple data sources shared by various terminals.

[0094] In this embodiment of the present invention, a shared repository stores multiple authentication results for multiple data sources shared by various terminals. Each of these authentication results has its own corresponding fingerprint information. The server matches the fingerprint information of the data to be authenticated with the multiple fingerprint information corresponding to the multiple authentication results, determining the target fingerprint information corresponding to the fingerprint information of the data to be authenticated. The server then extracts the target authentication result corresponding to the target fingerprint information from the shared repository. The server transmits this target authentication result to the local terminal via a pre-established communication link with the local terminal.

[0095] In an embodiment of the present invention, the server can also simultaneously receive first query instructions sent by multiple local terminals. The server queries the shared repository for the fingerprint information in the first query instructions of each local terminal, and determines the target identification result corresponding to each local terminal. The server then sends the target identification result of each local terminal to the corresponding local terminal.

[0096] In the embodiment of the present invention, the shared storage repository may be a storage area in a server, or a cloud storage area in a cloud.

[0097] In the embodiment of the present invention, establishing a shared storage repository on the server requires the following two properties:

[0098] 1. Each storage information in the shared repository should be unique.

[0099] Each stored information is generally unique based on information such as file md5. In addition, the preset storage space of the local terminal is also unique to avoid conversion during the query / synchronization process.

[0100] 2. The server should provide query and update interfaces, which are used to connect and update with the local terminal.

[0101] in:

[0102] Query interface: used to query whether the file has been detected and scanned by other local terminals and obtain the identification results;

[0103] The update interface is used to synchronize the fingerprint information and identification results of files that have been scanned by the local terminal but are not available in the shared repository on the server, so as to update the shared repository.

[0104] There are many files on the server network. The construction of a shared repository needs to consider the storage space and query speed of a large amount of data. It is recommended to use a mainstream database and combine it with big data retrieval technology to achieve it.

[0105] In an embodiment of the present invention, by determining the fingerprint information of the data to be identified, the fingerprint information is compared with the scanned fingerprint information in the preset storage space to obtain a comparison result; if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, the fingerprint information of the data to be identified is carried in a first query instruction and sent to the server; the server responds to the first query instruction and feedbacks the target identification result corresponding to the fingerprint information. Since the local terminal first determines whether it has scanned the data to be identified through the fingerprint information, the local terminal can obtain the corresponding target identification result in the shared storage library through the fingerprint information if no scanning has been done, thus saving the time for scanning and identification, thereby improving the identification efficiency of the local terminal for the data to be identified. In the case of multiple local terminals connected to the server, each local terminal can obtain the corresponding identification result in the shared storage library through the fingerprint information, thereby improving the identification efficiency of the files by each local terminal connected to the server.

[0106] Furthermore, in the embodiments of the present application, there can be multiple shared storage libraries, which facilitates the formation of multiple different trust groups. For example, if terminals 1, 2, and 3 can access each other's preset storage spaces, and terminals 4 and 5 can access each other's preset storage spaces, then two shared databases can be established: one for terminals 1, 2, and 3, and the other for terminals 4 and 5; thus, two trust groups can be established.

[0107] In some embodiments, Figure 1 The illustrated S102 can also be implemented through S105 to S106 , which will be described in conjunction with each step.

[0108] S105: If the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then: the fingerprint information of the data to be identified is carried in a second query instruction and sent to several other terminals.

[0109] In an embodiment of the present invention, if the local terminal detects that the comparison result indicates that there is no data to be authenticated in the preset storage space, then: fingerprint information of the data to be authenticated is carried in a second query instruction and sent to several other terminals.

[0110] In an embodiment of the present invention, the local terminal may carry the fingerprint information in the second query instruction and send the query instructions to several other terminals respectively. The several other terminals may be one other terminal or multiple other terminals.

[0111] The other terminals may be terminals other than the local terminal. Several other terminals may be connected to the same server together with the local terminal. Several other terminals may also be connected to different servers together with the local terminal.

[0112] In an embodiment of the present invention, the local terminal can send the second query instruction to all other terminals that are communicatively connected to the local terminal, or can send the second query instruction to some other terminals that are communicatively connected to the local terminal, or can only send the second query instruction to one other terminal. This is not limited in the embodiment of the present invention.

[0113] Compared to S103-S104, this solution bypasses the server, allowing multiple terminals to communicate directly with each other. This can reduce the computing burden on the server. Typically, the server bears a large amount of computing work. Therefore, to reduce the burden on the server, the solution of S105-S106 can be adopted to allow direct communication between terminals. Of course, those skilled in the art will readily understand that in order to ensure security or to form different trust groups, authentication operations must be performed before terminals can access each other.

[0114] However, direct communication between multiple terminals can lead to a high volume of network traffic at any given moment, such as when terminal 1 simultaneously sends broadcast messages to other terminals. Therefore, establishing a "shared database" on the server side, centralizing processing by the server, can prevent network congestion caused by excessive messages at any given moment. Furthermore, establishing multiple "shared databases" on the server side is much simpler when building multiple trust groups. However, direct communication between terminals requires configuring authentication-related information into each terminal device, which can be complex and difficult to implement, making it more difficult to establish different trust groups.

[0115] S106: Receive a target identification result corresponding to the fingerprint information fed back by at least one of the other terminals in response to the second query instruction.

[0116] In the embodiment of the present invention, the local terminal receives a target identification result corresponding to the fingerprint information fed back by at least one of the other terminals in response to the second query instruction.

[0117] In the embodiment of the present invention, when the at least one other terminal is one other terminal, the one other terminal searches the corresponding storage space for a target identification result corresponding to the fingerprint information, and the one other terminal sends the target identification result to the local terminal.

[0118] In an embodiment of the present invention, when the at least one other terminal is two other terminals, the two other terminals may include: terminal A and terminal B. Terminal A and terminal B query the target identification result corresponding to the fingerprint information in their respective corresponding storage spaces, and terminal A and terminal B respectively send the target identification results they have queried to the local terminal.

[0119] In an embodiment of the present invention, when the target identification result fed back by at least one other terminal includes multiple target identification results, the local terminal will detect the multiple target identification results. If the detection results of the multiple target identification results are exactly the same, the local terminal determines that any one of the multiple target identification results is the final target identification result. If the detection results of the multiple target identification results indicate that at least two target identification results are different, the local terminal will again send a second query instruction to several other terminals (for example, if it was terminal A and terminal B last time, then inquire again to several terminals other than terminal A and B (for example, terminal C, or terminal C and D), thereby determining the identification result in a minority-majority manner) to query the accurate target identification result, or the local terminal directly scans the data to be identified, etc.

[0120] In some embodiments, S103 also includes S107 to S109, which will be described in conjunction with each step.

[0121] S107: Receive a not found message fed back by the server in response to the first query instruction, where the not found message indicates that the server has not found a target identification result of the fingerprint information in the shared storage repository.

[0122] In the embodiment of the present invention, the local terminal receives a "not found" message fed back by the server in response to the first query instruction, wherein the "not found" message indicates that the server has not found the target identification result of the fingerprint information in the shared storage library.

[0123] S108 : In response to a message that no data is found, an authentication scan is performed on the data to be authenticated to determine a target authentication result of the data to be authenticated.

[0124] In the embodiment of the present invention, in response to the message not being found, the local terminal scans and authenticates the data to be authenticated, and determines a target authentication result of the data to be authenticated.

[0125] In an embodiment of the present invention, after receiving a first query instruction, the server determines a query result based on the fingerprint information carried in the first query instruction. If the query result indicates that the server has not found a target identification result for the fingerprint information in the shared repository, the server sends a "not found" message to the local terminal via a pre-established communication line with the local terminal. Upon receiving the "not found" message, the local terminal executes scanning software using a pre-set program to scan the data to be identified and determines a target identification result for the data to be identified.

[0126] In the embodiment of the present invention, the local terminal may scan and authenticate the data to be authenticated through EDR or EPP, and further determine a target authentication result of the data to be authenticated.

[0127] S109: After establishing target mapping information between the target identification result and the fingerprint information, the target mapping information is stored in a preset storage space, and the target mapping information is sent to the server for the server to update the shared storage library.

[0128] In this embodiment of the present invention, after the local terminal establishes target mapping information between the target identification result and the fingerprint information, the local terminal stores the target mapping information in a preset storage space. This creates a new storage in the preset storage space. Simultaneously, the local terminal sends the target mapping information to the server for the server to update the shared storage repository.

[0129] In an embodiment of the present invention, when the local terminal detects that a data in the local terminal has changed, such as an update, the local terminal determines that the updated data is the data to be identified. After the data is updated, the fingerprint information of the data has also changed. The local terminal carries the new fingerprint information of the data in the first query instruction and sends it to the server, and receives a not found message fed back by the server in response to the first query instruction. Therefore, the local terminal obtains a target identification result after scanning and identifying the updated data in response to the not found message. The local terminal needs to establish target mapping information between the new fingerprint information of the updated data and the target identification result. The local terminal stores the target mapping information in a preset storage space and sends it to the server at the same time for the server to update the shared storage library.

[0130] In an embodiment of the present invention, when the local terminal finds that the data to be identified has no corresponding target identification result in the preset storage space and the shared storage library, the local terminal starts a scanning and identification process, determines the target identification result of the data to be identified to update the preset storage space and the shared storage library. When the next data to be identified by the local terminal is the same as the data to be identified, the local terminal can directly extract the target identification result from the preset storage space or the shared storage library, thereby improving the identification efficiency.

[0131] In some embodiments, the embodiment of the present invention further includes S110 to S112, which will be described in conjunction with each step.

[0132] S110: Calculate the historical identification data to obtain historical fingerprint information of the historical identification data.

[0133] In the embodiment of the present invention, the local terminal may calculate the binary information of the historical identification data to obtain the historical fingerprint information of the historical identification data.

[0134] In an embodiment of the present invention, a local terminal can calculate the binary information of historical authentication data using the MD5 algorithm to obtain historical fingerprint information of the historical authentication data. The MD5 algorithm can be used as an electronic signature method. Using the MD5 algorithm, a unique "fingerprint information" can be generated for any file (regardless of its size, format, or number). Using this "fingerprint information," the local terminal can determine whether the source file has been modified by checking whether the MD5 values before and after the file have changed.

[0135] The historical identification data may be data requiring identification and scanning before the current moment of the local terminal.

[0136] S111. Perform an authentication scan on the historical authentication data to determine a historical authentication result of the historical authentication data.

[0137] In the embodiment of the present invention, the local terminal performs an authentication scan on the historical authentication data to determine a historical authentication result of the historical authentication data.

[0138] In the embodiment of the present invention, the local terminal performs an authentication scan on the historical authentication data through EPP or EDR to determine a historical authentication result of the historical authentication data.

[0139] S112: storing historical mapping information between historical identification results and historical fingerprint information in a preset storage space, and sending the historical mapping information to the server for the server to update the shared storage repository.

[0140] In an embodiment of the present invention, the local terminal creates historical mapping information from historical identification results and historical fingerprint information. The local terminal stores the historical mapping information in a preset storage space. At the same time, the local terminal sends the historical mapping information to the server for the server to update the shared storage repository.

[0141] In an embodiment of the present invention, the local terminal scans and authenticates the historical authentication data to obtain the historical authentication results, and updates the historical authentication results in the preset storage space and the shared storage library. When the next data to be authenticated is the same as the historical authentication data, the local terminal can extract the target authentication results from the preset storage space or the shared storage library, thereby improving the authentication efficiency.

[0142] In some embodiments, Figure 1 S101 shown in FIG. 1 also includes S113 , which will be described in conjunction with each step.

[0143] S113: If the comparison result represents the identification result of the data to be identified in the preset storage space, extract the target identification result corresponding to the fingerprint information from the preset storage space.

[0144] In the embodiment of the present invention, if the local terminal obtains a comparison result representing an identification result of the data to be identified in the preset storage space, the local terminal extracts a target identification result corresponding to the fingerprint information in the preset storage space.

[0145] In an embodiment of the present invention, a local terminal performs a one-to-one match between the fingerprint information of the data to be authenticated and multiple scanned fingerprint information in a preset storage space. If target fingerprint information matches the fingerprint information of the data to be authenticated, the local terminal obtains a comparison result indicating the authentication result of the data to be authenticated in the preset storage space. The local terminal extracts the target authentication result corresponding to the target fingerprint information from the preset storage space. If target fingerprint information does not match the fingerprint information of the data to be authenticated, the local terminal obtains a comparison result indicating that no authentication result of the data to be authenticated exists in the preset storage space.

[0146] In the embodiment of the present invention, after the local terminal extracts the target identification result, the local terminal can also create target mapping information between the target identification result and the fingerprint information, and send the target mapping information to the server to update the shared storage library.

[0147] In the embodiment of the present invention, if the target identification result exists in the preset storage space, the local terminal can directly extract the target identification result from the shared storage library, thereby saving scanning identification time and improving identification efficiency.

[0148] In some embodiments, S102 also includes S114, which will be explained in conjunction with each step.

[0149] S114. If the target identification result does not match the preset identification result, an alarm is issued for the data to be identified.

[0150] In the embodiment of the present invention, if the target identification result detected by the local terminal does not match the preset identification result, an alarm is issued for the data to be identified.

[0151] The target identification result may be a target identification result obtained by the local terminal in a preset storage space. The target identification result may also be a target identification result sent by the server to the local terminal. The target identification result may also be a target identification result sent by at least one other terminal to the local terminal. The target identification result may also be a target identification result obtained by the local terminal after scanning the data to be identified.

[0152] In an embodiment of the present invention, if the target identification result detected by the local terminal does not match the preset identification result, that is, the local terminal detects that the target identification result is threatening, the local terminal may display a prompt message on the current page indicating that the data to be identified is threatening, allowing the user of the local terminal to process the data to be identified. Processing includes deleting the data to be identified or rescanning and identifying the data to be identified.

[0153] In the embodiment of the present invention, when the target identification result is a threat, an alarm is issued for the data to be identified, thereby protecting the local terminal from the threat.

[0154] In some embodiments, S104 also includes S115, which will be explained in conjunction with each step.

[0155] S115: The target identification result and the fingerprint information are combined to form target mapping information, and the target mapping information is updated in a preset storage space.

[0156] In the embodiment of the present invention, the local terminal forms target mapping information with the target identification result and the fingerprint information, and stores the target mapping information in a preset storage space.

[0157] In some embodiments, see Figure 4 , Figure 4 An optional flow chart of a data identification method provided in an embodiment of the present invention will be described in conjunction with each step.

[0158] S301, traverse each file.

[0159] In the embodiment of the present invention, the local terminal traverses each file in a directory and determines a file to be authenticated in the directory.

[0160] S302: Extract fingerprint information and compare it with the preset storage space.

[0161] In an embodiment of the present invention, a local terminal extracts fingerprint information of a file to be authenticated, compares the fingerprint information with multiple fingerprint information in a preset storage space, and obtains a comparison result.

[0162] S303: Has the local scan been performed?

[0163] In the embodiment of the present invention, the local terminal determines whether the file to be identified has been scanned.

[0164] S304: Is it a known threat?

[0165] In this embodiment of the present invention, if the file to be identified has already been scanned, the local terminal retrieves the target identification result from a preset storage space. If the target identification result is a known threat, S306 is executed, and an alarm is issued, indicating that a threat has been found. If the target identification result is not a known threat, S307 is executed, indicating that no threat has been found, and the process is skipped.

[0166] S305: Query the server for the entire network repository.

[0167] In the embodiment of the present invention, if the file to be authenticated has not been scanned, the local terminal queries the network-wide storage repository of the server.

[0168] S308: Check whether the file has been scanned.

[0169] In the embodiment of the present invention, if the server queries whether the file to be identified is a file that has been scanned.

[0170] S309: Is it a known threat?

[0171] In this embodiment of the present invention, if the file to be identified has already been scanned, the server extracts the target identification result from the network-wide repository and sends it to the local terminal. If the target identification result is a known threat, the local terminal executes S311 and issues an alert, indicating that a threat has been found. If the target identification result is not a known threat, the local terminal executes S312, indicating that no threat has been found, and the process is skipped.

[0172] S309: Update the preset storage space.

[0173] In the embodiment of the present invention, the local terminal updates the target identification result sent by the server in a preset storage space.

[0174] S310: Enter the local threat engine scanning process.

[0175] In an embodiment of the present invention, if the server queries that the file to be identified is not a file that has been scanned, the local terminal enters the local threat engine scanning process to scan and identify the file to be identified, and obtains the target identification result.

[0176] S313: Is it a new threat?

[0177] In the embodiment of the present invention, if the target identification result is a new threat, the local terminal executes S314, issues an alarm, and finds a threat. If the target identification result is not a new threat, the local terminal executes S315, does not find a threat, and skips.

[0178] S317. Synchronize the results to the network-wide shared repository.

[0179] S316: Update the preset storage space.

[0180] S318. Complete the scanning and identification of a file.

[0181] In the embodiment of the present invention, after the local terminal completes the scanning and identification of the file to be identified, the local terminal continues to scan the next file, and the above process is performed in this way.

[0182] In some embodiments, see Figure 5 , Figure 5 An optional flow chart of a data authentication method provided in an embodiment of the present invention is applied to a server and will be described in conjunction with each step.

[0183] S201: Receive a first query instruction sent by a local terminal, where the first query instruction carries fingerprint information of data to be authenticated.

[0184] In the embodiment of the present invention, the server receives a first query instruction sent by the local terminal, where the first query instruction carries fingerprint information of data to be authenticated.

[0185] In the embodiment of the present invention, the local terminal may establish a communication connection with the server in advance. The server may receive the first query instruction sent by the local terminal through the communication connection established in advance with the local terminal.

[0186] In the embodiment of the present invention, the first query instruction may be a character string.

[0187] S202: Determine the query result corresponding to the fingerprint information in the shared storage repository; the shared storage repository stores the identification results of multiple data shared by other terminal sources.

[0188] In an embodiment of the present invention, the server terminal determines the query result of the fingerprint information in the shared storage library, wherein the shared storage library stores the authentication results of multiple data shared by other terminal sources.

[0189] In an embodiment of the present invention, in response to a first query instruction, the server compares the fingerprint information of the data to be authenticated with multiple scanned fingerprint information of multiple data in a shared repository. If target fingerprint information matches the fingerprint information, the server determines a query result indicating that the target authentication result for the data to be authenticated exists in the shared repository. The server then extracts the target authentication result corresponding to the target fingerprint information from the shared repository and sends it to the local terminal. If the target fingerprint information does not match the fingerprint information, the server determines a query result indicating that the target authentication result for the data to be authenticated does not exist in the shared repository.

[0190] S203: If the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared storage repository, the target identification result is extracted from the shared storage repository and sent to the local terminal.

[0191] In the embodiment of the present invention, if the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared storage repository, the server extracts the target identification result from the shared storage repository and sends the target identification result to the local terminal.

[0192] In an embodiment of the present invention, a server receives a first query instruction sent by a local terminal, the first query instruction carries fingerprint information of data to be identified; the server determines a query result corresponding to the fingerprint information in a shared repository; the shared repository stores identification results of multiple data shared by other terminal sources; if the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared repository, the target identification result is extracted from the shared repository and the target identification result is sent to the local terminal. Since the local terminal detects that there is no target identification result in the preset storage space, the server can find the target identification result through the fingerprint information, and then send the target identification result to the local terminal, which saves the time of the local terminal scanning for identification, thereby improving the identification efficiency of the local terminal for the identification data. In the case of multiple local terminals connected to the server, each local terminal can obtain the corresponding identification result in the shared repository through the fingerprint information, thereby improving the identification efficiency of each local terminal connected to the server for the file.

[0193] In some embodiments, Figure 5 S202 shown in FIG. 2 also includes S204 to S205 , which will be described in conjunction with each step.

[0194] S204: If the query result indicates that the target identification result of the fingerprint information is not found in the shared storage repository, a message indicating that the result was not found is sent to the local terminal.

[0195] In an embodiment of the present invention, if the query result obtained by the server indicates that the target identification result of the fingerprint information is not found in the shared storage repository, the server sends a "not found" message to the local terminal. The "not found" message indicates that the target identification result of the fingerprint information is not found in the shared storage repository.

[0196] S205: Receive the target mapping information sent by the local terminal in response to the message that the local terminal has not found the target, and update the target mapping information in the shared storage library.

[0197] In the embodiment of the present invention, the server receives the target mapping information sent by the local terminal in response to the message that the target is not found, and updates the target mapping information in the storage repository.

[0198] The target mapping information is the correspondence information between the target identification result of the data to be identified and the fingerprint information.

[0199] In some embodiments, the embodiment of the present invention further includes S206, which will be described in conjunction with each step.

[0200] S206: Receive historical mapping information sent by the local terminal, and update the historical mapping information in the shared storage repository.

[0201] In the embodiment of the present invention, the server receives the historical mapping information sent by the local terminal, and updates the historical mapping information in the shared storage repository.

[0202] The historical mapping information is the correspondence information between the historical identification results of the historical identification data and the historical fingerprint information of the historical identification data. The server may be a server or a cloud connected to multiple local terminals.

[0203] In this embodiment of the present invention, a server receives target mapping information and historical mapping information sent by a local terminal and updates the target mapping information and historical mapping information in a shared repository. When the local terminal's next data to be authenticated matches the target authentication result or the historical authentication result in the target mapping information and historical mapping information, the server can use the fingerprint information of the next data to be authenticated to find the next target authentication result in the shared repository and send it to the local terminal. This improves the authentication efficiency of the local terminal pair.

[0204] In some embodiments, see Figure 6 , Figure 6 An optional flow chart of a data authentication method provided in an embodiment of the present invention is applied to at least one other terminal and will be described in conjunction with each step.

[0205] S301: Receive a second query instruction sent by a local terminal, where the second query instruction carries fingerprint information of data to be authenticated.

[0206] In the embodiment of the present invention, at least one other terminal receives a second query instruction sent by the local terminal, where the second query instruction carries fingerprint information of the data to be authenticated.

[0207] The at least one other terminal may be one terminal or multiple terminals among several other terminals connected to the local terminal.

[0208] S302: Determine the query result corresponding to the fingerprint information in the storage space; the storage space stores the scanned fingerprint information of the data and the corresponding identification result.

[0209] In an embodiment of the present invention, at least one other terminal determines a query result corresponding to the fingerprint information in a storage space, wherein the storage space stores the scanned fingerprint information of the corresponding terminal data and the corresponding identification result.

[0210] S303: If the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space, the target identification result is extracted from the storage space and sent to the local terminal.

[0211] In the embodiment of the present invention, if the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space, at least one other terminal extracts the target identification result from the storage space and sends the target identification result to the local terminal.

[0212] See also Figure 7 , Figure 7 The interactive schematic diagram of the data identification method provided by the embodiment of the present invention will be described in conjunction with each step.

[0213] S401. The local terminal determines the fingerprint information of the data to be authenticated, compares the fingerprint information with the scanned fingerprint information in the local corresponding preset storage space, and obtains a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding authentication result.

[0214] The detailed implementation of step S401 is consistent with that of step S101 and will not be repeated here.

[0215] S402: If the local terminal obtains an identification result indicating that the preset storage space does not contain the data to be identified as a result of the comparison, then: fingerprint information of the data to be identified is carried in a first query instruction and sent to the server.

[0216] The detailed implementation of step S402 is consistent with that of step S103 and will not be repeated here.

[0217] S403: The local terminal receives the target identification result corresponding to the fingerprint information, which is fed back by the server in response to the first query instruction.

[0218] The detailed implementation of step S403 is consistent with that of step S104 and will not be repeated here.

[0219] S404: If the local terminal obtains an identification result indicating that the preset storage space does not contain the data to be identified as a result of the comparison, then: fingerprint information of the data to be identified is carried in a second query instruction and sent to several other terminals.

[0220] The detailed implementation of step S404 is consistent with that of step S105 and will not be repeated here.

[0221] In the embodiment of the present invention, step S402 may also be performed simultaneously with step S404, that is, the local terminal sends the first query instruction to the server while also sending the second query instruction to several other terminals.

[0222] S405: The local terminal receives a target identification result corresponding to the fingerprint information fed back by at least one of the other terminals in response to the second query instruction.

[0223] The detailed implementation of step S405 is consistent with that of step S106 and will not be repeated here.

[0224] See also Figure 8 , Figure 8 Schematic diagram of the structure of the data identification device provided by the embodiment of the present invention Figure 1 .

[0225] The embodiment of the present invention further provides a data identification device 700 , which is applied to a local terminal and includes: a determination unit 703 .

[0226] The determination unit 703 is configured to determine the fingerprint information of the data to be authenticated, and compare the fingerprint information with the scanned fingerprint information in a corresponding local preset storage space to obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding authentication result;

[0227] The determination unit 703 is also used to determine the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space.

[0228] In an embodiment of the present invention, the determination unit 703 in the data identification device 700 is also used to carry the fingerprint information of the data to be identified in a first query instruction and send it to the server; receive the target identification result corresponding to the fingerprint information fed back by the server in response to the first query instruction; the target identification result is obtained by querying in the shared repository of the server; the shared repository stores the identification results of multiple data shared by various terminal sources.

[0229] In an embodiment of the present invention, the determination unit 703 in the data identification device 700 is also used to carry the fingerprint information of the data to be identified in a second query instruction and send it to several other terminals; receive the target identification result corresponding to the fingerprint information fed back by at least one other terminal among the other terminals in response to the second query instruction; the target identification result is obtained by querying the storage space corresponding to the at least one other terminal.

[0230] In an embodiment of the present invention, the determination unit 703 in the data identification device 700 is also used to receive a not found message fed back by the server in response to the first query instruction; the not found message indicates that the server has not found the target identification result of the fingerprint information in the shared repository; in response to the not found message, the data to be identified is scanned for identification to determine the target identification result of the data to be identified; after establishing target mapping information between the target identification result and the fingerprint information, the target mapping information is stored in the preset storage space, and the target mapping information is sent to the server for the server to update the shared repository.

[0231] In an embodiment of the present invention, the determination unit in the data identification device 700 is also used to calculate the historical identification data to obtain historical fingerprint information of the historical identification data; scan the historical identification data to determine the historical identification result of the historical identification data; store the historical mapping information of the historical identification result and the historical fingerprint information in the preset storage space, and send the historical mapping information to the server for the server to update the shared storage repository.

[0232] In the embodiment of the present invention, the determination unit 703 in the data identification device 700 is further configured to form target mapping information using the target identification result and the fingerprint information, and update the target mapping information in the preset storage space.

[0233] In an embodiment of the present invention, the fingerprint information of the data to be identified is determined by the determination unit 703, and the fingerprint information is compared with the scanned fingerprint information of the preset storage space corresponding to the local area to obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding identification result; if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals, the target identification result of the data to be identified is determined. Since the terminal first determines whether the data to be identified has been scanned locally through the fingerprint information, if it has not been scanned, the terminal can obtain the corresponding target identification result through the fingerprint information combined with the storage space corresponding to other terminals, thereby saving the time of scanning and identification, thereby improving the identification efficiency of the terminal for the data to be identified. In the case of multiple terminals connected to the server, each terminal can obtain the corresponding identification result through the fingerprint information combined with the storage space corresponding to other terminals, thereby improving the identification efficiency of each terminal connected to the server for the file.

[0234] Correspondingly, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the method on the answering station side when the computer program is executed by the first processor.

[0235] Correspondingly, an embodiment of the present invention provides a data authentication device, including a first memory 702 and a first processor 701, wherein the first memory 702 stores a computer program that can be run on the first processor 701, and the first processor 701 implements the method on the response site side when executing the program.

[0236] It should be noted that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium and device embodiments of the present invention, please refer to the description of the method embodiments of the present invention for understanding.

[0237] It should be noted that Figure 9 A hardware entity diagram of a data identification device provided by an embodiment of the present invention Figure 1 , in addition, the Figure 9 It can also be the structure of a virtual machine, such as Figure 9 As shown, the hardware entity of the data identification device 700 includes: a first processor 701 and a first memory 702, wherein;

[0238] The first processor 701 generally controls the overall operation of the data authentication device 700 .

[0239] The first memory 702 is configured to store instructions and applications executable by the first processor 701, and can also store data to be processed or processed by the first processor 701 and the various modules in the data identification device 700 (for example, image data, audio data, voice communication data and video communication data), which can be implemented through flash memory (FLASH) or random access memory (Random Access Memory, RAM).

[0240] See also Figure 10 , Figure 10 Schematic diagram of the structure of the data identification device provided in the embodiment disclosed by the present invention Figure 2 .

[0241] An embodiment of the present invention provides a data identification device 800 , which is applied to a server and includes: a first receiving unit 803 , a first querying unit 804 and a first sending unit 805 .

[0242] The first receiving unit 803 is configured to receive a first query instruction sent by a local terminal, wherein the first query instruction carries fingerprint information of data to be authenticated;

[0243] The first query unit 804 is configured to determine a query result corresponding to the fingerprint information in a shared repository; the shared repository stores authentication results of multiple data shared by various terminal sources;

[0244] The first sending unit 805 is configured to extract the target identification result from the shared repository and send the target identification result to the local terminal if the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared repository.

[0245] In an embodiment of the present invention, the first sending unit 805 in the data identification device 800 is used to send a not found message to the local terminal if the query result indicates that the target identification result of the fingerprint information is not found in the shared repository; the not found message indicates that the target identification result of the fingerprint information is not found in the shared repository; the first receiving unit 803 is used to receive the target mapping information sent by the local terminal in response to the not found message, and update the target mapping information in the shared repository; the target mapping information is the corresponding information between the target identification result of the data to be identified and the fingerprint information.

[0246] In an embodiment of the present invention, the server receives a first query instruction sent by a local terminal through a first receiving unit 803, wherein the first query instruction carries fingerprint information of data to be identified; the server determines a query result corresponding to the fingerprint information in a shared repository through a first query unit 804; the shared repository stores identification results of multiple data shared by other terminal sources; if the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared repository through a first sending unit 805, the target identification result is extracted from the shared repository and sent to the local terminal. Since the local terminal detects that there is no target identification result in the preset storage space, the server can find the target identification result through the fingerprint information and then send the target identification result to the local terminal, which saves the time of the local terminal scanning for identification, thereby improving the identification efficiency of the local terminal for the identification data. In the case of multiple terminals connected to the server, each terminal can obtain the corresponding identification result in the shared repository through the fingerprint information, thereby improving the identification efficiency of each terminal connected to the server for the file.

[0247] Correspondingly, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the method on the server side when the computer program is executed by a processor.

[0248] Correspondingly, an embodiment of the present invention provides a data identification device 800, including a second memory 802 and a second processor 801, the second memory 802 stores a computer program that can be run on the second processor 801, and the second processor 801 implements the method on the server side when executing the program.

[0249] It should be noted that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium and device embodiments of the present invention, please refer to the description of the method embodiments of the present invention for understanding.

[0250] It should be noted that Figure 11 A hardware entity diagram of a data identification device provided in an embodiment of the present invention Figure 2 ,Should Figure 11 The structure shown can be a virtual machine structure, such as Figure 11 As shown, the hardware entity of the data identification device 800 includes: a second processor 801 and a second memory 802, wherein;

[0251] The second processor 801 generally controls the overall operation of the data authentication device 800 .

[0252] The second memory 802 is configured to store instructions and applications executable by the second processor 801, and can also store data to be processed or processed by the second processor 801 and each module in the data identification device 800 (for example, image data, audio data, voice communication data and video communication data), which can be implemented through flash memory (FLASH) or random access memory (Random Access Memory, RAM).

[0253] See also Figure 12 , Figure 12 Schematic diagram of the structure of the data identification device provided in the embodiment disclosed by the present invention Figure 3 .

[0254] An embodiment of the present invention provides a data authentication device 900 , which is applied to at least one other terminal and includes: a second receiving unit 903 , a second query unit 904 and a second sending unit 905 .

[0255] The second receiving unit 903 is configured to receive a second query instruction sent by the local terminal, wherein the second query instruction carries fingerprint information of the data to be authenticated;

[0256] The second query unit 904 is used to determine the query result corresponding to the fingerprint information in the storage space; the storage space stores the scanned fingerprint information and the corresponding identification result;

[0257] The second sending unit 905 is configured to extract the target identification result from the storage space and send the target identification result to the local terminal if the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space.

[0258] In an embodiment of the present invention, the server receives a second query instruction sent by a local terminal through a second receiving unit 903, wherein the second query instruction carries fingerprint information of the data to be identified; the query result corresponding to the fingerprint information is determined in the storage space through a second query unit 904; the storage space stores scanned fingerprint information and the corresponding identification result; if the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space, the target identification result is extracted from the storage space through a second sending unit 905, and the target identification result is sent to the local terminal. Since when the local terminal detects that there is no target identification result in the preset storage space, at least one other terminal can find the target identification result through the fingerprint information, and then send the target identification result to the local terminal, which saves the time of the local terminal scanning for identification, thereby improving the identification efficiency of the local terminal for the identification data.

[0259] Correspondingly, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the method on the server side when the computer program is executed by a processor.

[0260] Correspondingly, an embodiment of the present invention provides a data identification device 900, including a third memory 902 and a third processor 901, the third memory 902 stores a computer program that can be run on the third processor 901, and the third processor 901 implements the method on the server side when executing the program.

[0261] It should be noted that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium and device embodiments of the present invention, please refer to the description of the method embodiments of the present invention for understanding.

[0262] It should be noted that Figure 13 A hardware entity diagram of a data identification device provided in an embodiment of the present invention Figure 3 ,Should Figure 13 The structure shown can be a virtual machine structure. Figure 13 As shown, the hardware entity of the data identification device 900 includes: a third processor 901 and a third memory 902, wherein;

[0263] The third processor 901 generally controls the overall operation of the data authentication device 900.

[0264] The third memory 902 is configured to store instructions and applications executable by the third processor 901, and can also store data to be processed or processed by the third processor 901 and each module in the data identification device 900 (for example, image data, audio data, voice communication data and video communication data), which can be implemented through flash memory (FLASH) or random access memory (Random Access Memory, RAM).

[0265] The above description is merely an embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A data identification method, characterized in that: Applied to local terminals, including: Determine fingerprint information of the data to be authenticated, compare the fingerprint information with scanned fingerprint information in a corresponding local preset storage space, and obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding authentication result, as well as the scanned fingerprint information of data scanned by other terminals and its corresponding authentication result; the local terminal is any one of multiple terminals connected to the server; If the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, then: Based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal, a target identification result of the data to be identified is determined.

2. The data identification method according to claim 1, characterized in that: The determining of the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal includes: Sending the fingerprint information of the data to be identified to the server side in a first query instruction; Receive the target identification result corresponding to the fingerprint information fed back by the server in response to the first query instruction; the target identification result is obtained by querying the shared repository of the server; the shared repository stores the identification results of multiple data shared by various terminal sources.

3. The data identification method according to claim 1, wherein: The determining of the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to the other terminal includes: carrying the fingerprint information of the data to be authenticated in a second query instruction and sending it to the other terminals; Receive the target identification result corresponding to the fingerprint information fed back by at least one other terminal in response to the second query instruction; the target identification result is obtained by querying the storage space corresponding to the at least one other terminal.

4. The data identification method according to claim 2, characterized in that: After the fingerprint information of the data to be identified is carried in the first query instruction and sent to the server, the method further includes: receiving a not-found message fed back by the server in response to the first query instruction; the not-found message indicating that the server has not found the target identification result of the fingerprint information in the shared storage repository; In response to the not-found message, performing an authentication scan on the data to be authenticated to determine a target authentication result of the data to be authenticated; After establishing target mapping information between the target identification result and the fingerprint information, the target mapping information is stored in the preset storage space, and the target mapping information is sent to the server for the server to update the shared storage repository.

5. The data identification method according to claim 1, characterized in that: The method further comprises: Calculating the historical identification data to obtain historical fingerprint information of the historical identification data; Scanning the historical identification data to determine a historical identification result of the historical identification data; The historical mapping information between the historical identification result and the historical fingerprint information is stored in the preset storage space, and the historical mapping information is sent to the server for the server to update the shared storage repository.

6. The data identification method according to claim 2, characterized in that: After receiving the target identification result corresponding to the fingerprint information fed back by the server in response to the first query instruction, the method further includes: The target identification result and the fingerprint information are combined to form target mapping information, and the target mapping information is updated in the preset storage space.

7. A data identification method, characterized in that: Applied to the server, including: receiving a first query instruction sent by a local terminal, the first query instruction carrying fingerprint information of data to be identified; the first query instruction is sent after the local terminal determines the fingerprint information of the data to be identified, compares the fingerprint information with scanned fingerprint information in a corresponding local preset storage space, and obtains a comparison result indicating that the preset storage space does not contain an identification result of the data to be identified; the preset storage space stores the scanned fingerprint information of the data and its corresponding identification result, as well as the scanned fingerprint information of data scanned by other terminals and its corresponding identification result; the local terminal is any one of multiple terminals connected to the server; Determining a query result corresponding to the fingerprint information in a shared repository; the shared repository stores authentication results of multiple data shared by other terminal sources; If the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared storage repository, the target identification result is extracted from the shared storage repository and sent to the local terminal.

8. The data identification method according to claim 7, characterized in that: After determining the query result corresponding to the fingerprint information in the shared repository, the method further includes: If the query result indicates that the target identification result of the fingerprint information is not found in the shared storage repository, sending a not found message to the local terminal; the not found message indicates that the target identification result of the fingerprint information is not found in the shared storage repository; Receive target mapping information sent by the local terminal in response to the not found message, and update the target mapping information in the shared repository; the target mapping information is correspondence information between the target identification result of the data to be identified and the fingerprint information.

9. A data identification method, characterized in that: Applicable to at least one other terminal, including: receiving a second query instruction sent by a local terminal, the second query instruction carrying fingerprint information of the data to be identified; the second query instruction is sent after the local terminal determines the fingerprint information of the data to be identified, compares the fingerprint information with scanned fingerprint information in a corresponding local preset storage space, and obtains a comparison result indicating that the preset storage space does not contain an identification result of the data to be identified; the preset storage space stores the scanned fingerprint information of the data and its corresponding identification result, as well as the scanned fingerprint information of data scanned by other terminals and its corresponding identification result; the local terminal is any one of multiple terminals connected to the server; Determining the query result corresponding to the fingerprint information in the storage space; the storage space stores the scanned fingerprint information of the data and the corresponding identification result; If the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space, the target identification result is extracted from the storage space and sent to the local terminal.

10. A data identification device, characterized in that: Applied to local terminals, including: a determination unit, configured to determine fingerprint information of the data to be authenticated, compare the fingerprint information with scanned fingerprint information in a local preset storage space, and obtain a comparison result; the preset storage space stores the scanned fingerprint information of the data and its corresponding authentication result, as well as stores the scanned fingerprint information of data scanned by other terminals and its corresponding authentication result; the local terminal is any one of a plurality of terminals connected to the server; The determination unit is further configured to, if the comparison result indicates that there is no identification result of the data to be identified in the preset storage space, determine the target identification result of the data to be identified based on the scanned fingerprint information and the corresponding identification result stored in the storage space corresponding to other terminals.

11. A data identification device, characterized in that: Applied to the server, including: a first receiving unit, configured to receive a first query instruction sent by a local terminal, the first query instruction carrying fingerprint information of data to be identified; the first query instruction is sent after the local terminal determines the fingerprint information of the data to be identified, compares the fingerprint information with scanned fingerprint information in a corresponding local preset storage space, and obtains a comparison result indicating that the preset storage space does not contain an identification result of the data to be identified; the preset storage space stores the scanned fingerprint information of the data and its corresponding identification result, as well as the scanned fingerprint information of data scanned by other terminals and its corresponding identification result; the local terminal is any one of multiple terminals connected to the server; A first query unit is configured to determine a query result corresponding to the fingerprint information in a shared repository; the shared repository stores authentication results of multiple data shared by other terminal sources; The first sending unit is configured to extract the target identification result from the shared storage repository if the query result indicates that there is a target identification result corresponding to the fingerprint information in the shared storage repository, and send the target identification result to the local terminal.

12. A data identification device, characterized in that: Applicable to at least one other terminal, including: a second receiving unit, configured to receive a second query instruction sent by a local terminal, the second query instruction carrying fingerprint information of the data to be identified; the second query instruction is sent after the local terminal determines the fingerprint information of the data to be identified, compares the fingerprint information with scanned fingerprint information in a corresponding local preset storage space, and obtains a comparison result indicating that the preset storage space does not contain an identification result of the data to be identified; the preset storage space stores the scanned fingerprint information of the data and its corresponding identification result, as well as the scanned fingerprint information of data scanned by other terminals and its corresponding identification result; the local terminal is any one of a plurality of terminals connected to the server; a second query unit, configured to determine a query result corresponding to the fingerprint information in a storage space; the storage space storing scanned fingerprint information and corresponding identification results; The second sending unit is configured to extract the target identification result from the storage space and send the target identification result to the local terminal if the query result indicates that there is a target identification result corresponding to the fingerprint information in the storage space.

13. A data identification device, characterized in that: The method comprises a first memory and a first processor, wherein the first memory stores a computer program that can be run on the first processor, and when the first processor executes the program, the method according to any one of claims 1 to 9 is implemented.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the first processor, the method according to any one of claims 1 to 9 is implemented.

Citation Information

Patent Citations

  • File management method, device, equipment, system and readable storage medium

    CN108363799A