File transmission method, device, equipment, medium and product

By matching the security verification tool client with the user server, calling the file selection interface and performing signature processing, the file transfer problem under multiple browsers and operating systems is solved, and the security and compatibility are improved.

CN116055212BActive Publication Date: 2025-11-07INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310118323.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-02
Publication Date
2025-11-07
Estimated Expiration
2043-02-02

AI Technical Summary

Technical Problem

Existing technologies cannot support multiple modern browsers and operating systems, resulting in limitations in file transfer methods between external clients and the intranet.

Method used

By matching the security verification tool client with the user server, the target file is selected by calling the file selection interface, and a signature file is generated through signature processing and transmitted to the intranet application server for verification, which is compatible with multiple operating systems and shields browser differences.

Benefits of technology

It enables secure file transfer across multiple modern browsers and operating systems, improving the security and compatibility of file transfer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116055212B_ABST
    Figure CN116055212B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of information security, and specifically provides a file transmission method, device, equipment, medium and product. The method comprises the following steps: in response to a file selection operation of a user on a webpage application page, calling a file selection interface of a security verification tool client, and selecting a target file to be transmitted; receiving a security verification tool password input by the user, and sending the security verification tool password to an intranet application server, so that the intranet application server detects the security verification tool password; after receiving detection success information sent by the intranet application server, performing signature processing on the target file to generate a target signature file; and transmitting the target signature file to the intranet application server, so that the intranet application server verifies the target signature file. The method of the application can meet the support for multiple operating systems and multiple modern browsers through an adaptive security verification tool client.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and in particular to a file transmission method, device, equipment, medium and product. BACKGROUND

[0002] File exchange between applications in a financial system intranet and external file exchange for customers belong to two completely different systems, the former runs in a relatively safe internal network, and the focus is to guarantee the efficiency and timeliness of large-scale file transmission, and the latter runs on the Internet, the transmission scale is small, and the focus is to guarantee the safety of the transmitted files. External customers generally provide file upload and download functions based on the front end of internal applications, and realize file exchange with the intranet through the Internet.

[0003] Currently, file exchange between external customers and the intranet is mainly based on the IE (English full name: Internet Explorer) browser and the windows operating system, which cannot meet the support for multiple modern browsers and multiple operating systems.

[0004] Therefore, there is a lack of a file transmission method for external customers and the intranet that can meet the support for multiple modern browsers and multiple operating systems. SUMMARY

[0005] The present application provides a file transmission method, device, equipment, medium and product to solve the problem that there is currently a lack of a file transmission method for external customers and the intranet that can meet the support for multiple modern browsers and multiple operating systems.

[0006] The first aspect of the present application provides a file transmission method, a user server is connected with a security verification tool, and the method comprises:

[0007] In response to a file selection operation of a user on a web application page, a file selection interface of a security verification tool client is called, and a target file to be transmitted is selected; the security verification tool client is matched with the operating system of the user server;

[0008] Receiving a security verification tool password input by the user, and sending the security verification tool password to an intranet application server, so that the intranet application server detects the security verification tool password;

[0009] After receiving the detection success information sent by the intranet application server, the target file is signed to generate a target signature file;

[0010] Transmitting the target signature file to the intranet application server, so that the intranet application server verifies the target signature file.

[0011] Further, the method as described above, the calling the file selection interface of the security verification tool client in response to the file selection operation of the user on the web application page, and selecting the target file to be transmitted, comprises:

[0012] The file selection interface of the security verification tool client is called by using the native messaging in response to the file selection operation of the user on the web application page, and the target file to be transmitted is selected.

[0013] Further, the method as described above, the receiving the security verification tool password input by the user, comprises:

[0014] The security verification tool password input box is displayed in the web application page in response to the click operation of the user on the upload component;

[0015] The security verification tool password input by the user in the security verification tool password input box is received.

[0016] Further, the method as described above, the signing the target file to generate the target signature file, comprises:

[0017] The target file is signed by the security verification tool client to generate the target signature file.

[0018] Further, the method as described above, before the calling the security verification tool client to sign the target file to generate the target signature file, further comprises:

[0019] The storage path of the target file and the data of the target file are obtained;

[0020] The first detection token is generated by hash calculation according to the storage path, the data of the target file and the preset random number;

[0021] After the calling the security verification tool client to sign the target file to generate the target signature file, further comprises:

[0022] The storage path of the target signature file and the data of the target signature file are obtained;

[0023] The second detection token is generated by hash calculation according to the storage path of the target signature file, the data of the target signature file and the preset random number;

[0024] If the first detection token and the second detection token are the same, the step of transmitting the target signature file to the intranet application server is executed.

[0025] Further, the method as described above, the transmitting the target signature file to the intranet application server to enable the intranet application server to verify the target signature file comprises:

[0026] If it is determined that the data size of the target signature file is greater than the preset threshold, the target signature file is divided into a preset number of sub-signature files;

[0027] Transmit all the sub-signature files to the intranet application server to enable the intranet application server to verify all the sub-signature files.

[0028] Further, the method as described above, the transmitting all the sub-signature files to the intranet application server to enable the intranet application server to verify all the sub-signature files comprises:

[0029] Transmit all the sub-signature files to the intranet application server to enable the intranet application server to verify all the sub-signature files.

[0030] Further, the method as described above, after the transmitting the target signature file to the intranet application server, further comprises:

[0031] Receiving the file transmission success information fed back by the intranet application server.

[0032] The second aspect of the present application provides a file transmission device, a user server is connected with a security verification tool, the device comprises:

[0033] The selection module is configured to respond to a file selection operation of a user on a web application page, call a file selection interface of a security verification tool client, and select a target file to be transmitted; the security verification tool client is matched with an operating system of the user server;

[0034] The sending module is configured to receive a security verification tool password input by a user, and send the security verification tool password to an intranet application server to enable the intranet application server to detect the security verification tool password;

[0035] The signature module is configured to, after receiving detection success information sent by the intranet application server, perform signature processing on the target file to generate a target signature file;

[0036] The transmission module is configured to transmit the target signature file to the intranet application server to enable the intranet application server to verify the target signature file.

[0037] Further, the device as described above, the selection module is specifically configured to:

[0038] In response to a file selection operation of a user on the webpage application page, a native messaging is used to call a file selection interface of the security verification tool client, and a target file to be transmitted is selected.

[0039] Further, the sending module is specifically configured to, when receiving a security verification tool password input by a user:

[0040] In response to a click operation of a user on the upload component, a security verification tool password input box is displayed in the webpage application page; and a security verification tool password input by a user in the security verification tool password input box is received.

[0041] Further, the signing module is specifically configured to, when performing signature processing on the target file to generate a target signature file, include:

[0042] The security verification tool client is called to perform signature processing on the target file to generate a target signature file.

[0043] Further, the signing module is further configured to:

[0044] The storage path of the target file and the data of the target file are obtained; and a first detection token is generated by performing hash calculation on the storage path, the data of the target file, and a preset random number;

[0045] The signing module is further configured to:

[0046] The storage path of the target signature file and the data of the target signature file are obtained; a second detection token is generated by performing hash calculation on the storage path of the target signature file, the data of the target signature file, and the preset random number; and if the first detection token and the second detection token are the same, the step of transmitting the target signature file to the intranet application server is performed.

[0047] Further, the transmitting module is specifically configured to:

[0048] If it is determined that the data size of the target signature file is greater than a preset threshold, the target signature file is divided into a preset number of sub-signature files; and all the sub-signature files are transmitted to the intranet application server, so that the intranet application server verifies all the sub-signature files.

[0049] Further, the transmitting module is specifically configured to, when transmitting all the sub-signature files to the intranet application server so that the intranet application server verifies all the sub-signature files:

[0050] transmit all the sub-signed files to the intranet application server, so that the intranet application server splices all the sub-signed files to generate a spliced signed file, and checks the spliced signed file.

[0051] Further, the apparatus as described above, the apparatus further comprises:

[0052] The receiving module is configured to receive file transmission success information fed back by the intranet application server.

[0053] The third aspect of the present application provides an electronic device, comprising a memory and a processor;

[0054] The memory stores computer execution instructions;

[0055] The processor executes the computer execution instructions stored in the memory to implement the file transmission method according to any one of the first aspect.

[0056] The fourth aspect of the present application provides a computer readable storage medium, the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the file transmission method according to any one of the first aspect.

[0057] The fifth aspect of the present application provides a computer program product, comprising a computer program, and the computer program is executed by the processor to implement the file transmission method according to any one of the first aspect.

[0058] This application provides a file transfer method, apparatus, device, medium, and product. The method includes: responding to a user's file selection operation on a web application page, calling the file selection interface of a security verification tool client and selecting a target file to be transferred; the security verification tool client is compatible with the operating system of the user server; receiving a security verification tool password input by the user and sending the security verification tool password to an intranet application server so that the intranet application server can detect the security verification tool password; after receiving a successful detection message from the intranet application server, performing signature processing on the target file to generate a target signature file; and transmitting the target signature file to the intranet application server so that the intranet application server can verify the target signature file. In this file transfer method, the security verification tool client is compatible with the operating system of the user server, and the user server is connected to the security verification tool. When a user transfers a file, responding to the user's file selection operation on a web application page, the security verification tool client's file selection interface is called, and a target file to be transferred is selected. Then, the security of file transfer is improved by detecting the user's input security verification tool password. Simultaneously, the security of file transfer is further improved by performing signature processing on the target file to be transferred. Furthermore, the file transfer method of this application can support multiple operating systems through an adapted security verification tool client, and at the same time, it can shield the differences between various modern browsers, thereby supporting multiple modern browsers. Attached Figure Description

[0059] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0060] Figure 1 This is a scenario diagram illustrating how the file transfer method described in the embodiments of this application can be implemented;

[0061] Figure 2 Flowchart of the file transfer method provided in this application Figure 1 ;

[0062] Figure 3 Flowchart of the file transfer method provided in this application Figure 2 ;

[0063] Figure 4 A schematic diagram of the overall process of the file transfer method provided in this application. Figure 1 ;

[0064] Figure 2 A schematic diagram of the overall process of the file transfer method provided in this application. Figure 6 ;

[0065] Figure 7A browser architecture diagram of a file transmission method provided in the present application is shown in the following figure;

[0066] Figure 8 A structure diagram of a file transmission device provided in the present application is shown in the following figure;

[0067] Figure 1 A structure diagram of an electronic device provided in the present application is shown in the following figure.

[0068] The specific embodiments of the present application have been shown in the above figures, and will be described in more detail hereinafter. These figures and the written description are not intended to limit the scope of the present application concept in any way, but to illustrate the present application concept to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0069] The exemplary embodiments will be described in detail herein with reference to the attached drawings. When the description below refers to the drawings, the same numbers in different drawings refer to the same or similar elements unless otherwise described. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with some aspects of the present application as detailed in the appended claims.

[0070] In the technical solutions of the embodiments of the present application, the collection, storage, use, processing, transmission, provision and disclosure of user personal information comply with relevant laws and regulations and do not violate public order and good customs.

[0071] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the relevant data need to comply with relevant laws and regulations and standards of relevant countries and regions, and provide corresponding operation portal for the user to choose authorization or refusal.

[0072] It should be noted that the file transmission method, device, equipment, medium and product of the present application can be used in the field of information security or other related fields. It can also be used in any field other than the field of information security or other related fields. The application field of the file transmission method, device, equipment, medium and product of the present application is not limited.

[0073] The technical solutions of the present application will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present application will be described below with reference to the drawings.

[0074] In order to clearly understand the technical solutions of the present application, the prior art solutions are first introduced in detail. Currently, the external client and the financial system internal network application file exchange runs on the Internet, the transmission scale is small, and the safety of the transmitted files is focused on. Its capacity demand: the external client generally provides file upload and download functions based on the internal application front end, and realizes file exchange with the internal network through the Internet.

[0075] Internet access features of external clients:

[0076] First, the identity of the service handling client is difficult to identify. Network frauds are endless, and it is difficult to accurately locate and identify the real identity of the exchange file client.

[0077] Second, the authenticity of the service handling is difficult to determine. Due to the complexity of the Internet environment and business processing, operation, and fraud risks, it is difficult to confirm the authenticity of the business processing in a timely manner.

[0078] Third, the sensitivity of the exchanged data is protected. The exchange of data files between the client and the financial system often involves important or sensitive information, and there is a risk of information leakage during Internet transmission.

[0079] Fourth, the continuity risk of the service handling. Due to the limitations or instability of the client's network resources, there is a risk of interruption of the business processing when the client exchanges files through the Internet, especially the repeated uploading of large files affecting the client experience.

[0080] In view of the Internet access features of external clients, the traditional large file safe transmission capacity is generally based on the C / S (English full name: Client-Server, Chinese: Server-Client) architecture product, the front-end client is generally an ActiveX control based on IE plug-in technology, embedded in the business application front page, and cooperates with the C / C++ (a computer programming language) dynamic library deployed on the Windows system to work, supporting the client to upload or download data files through the front page. The server background adopts cluster deployment, and after uniformly receiving the files, it realizes file transfer with the internal business application background through the file transmission tool.

[0081] Since the file exchange between the external client and the internal network is mainly based on the IE (English full name: Internet Explorer) browser and the windows operating system, it cannot meet the support for multiple modern browsers and multiple operating systems.

[0082] Therefore, at present, there is a lack of a file transmission method between the external client and the internal network that can meet the support for multiple modern browsers and multiple operating systems.

[0083] Therefore, in order to solve the problem that there is no external client and internal network file transmission method which can meet the support of multiple modern browsers and multiple operating systems in the prior art, the inventors have found, in the research, that in order to solve the problem, due to the security requirements of modern browsers, the actual file on the client cannot be obtained according to the file path (it must be manually dragged or uploaded to the browser), and the file path returned is also a virtual path and cannot obtain the real path of the file. This is different from the IE browser, which can directly obtain the local file path and the actual file content through the ActiveX control, so under the modern browser, the actual path of the file can be obtained by selecting the file through the security verification tool client. At the same time, the security of file transmission can be improved through security verification tools such as U disk, mobile digital certificate, etc.

[0084] Specifically, in response to a file selection operation of a user on a web application page, a file selection interface of a security verification tool client is called, and a target file to be transmitted is selected. The security verification tool client is matched with the operating system of the user server. The security verification tool password input by the user is received, and the security verification tool password is sent to the internal network application server, so that the internal network application server detects the security verification tool password. After receiving the detection success information sent by the internal network application server, the target file is signed to generate a target signed file. The target signed file is transmitted to the internal network application server, so that the internal network application server verifies the target signed file.

[0085] The file transmission method of the present application, the security verification tool client is matched with the operating system of the user server, and the user server is connected with the security verification tool. When the user transmits the file, in response to the file selection operation of the user on the web application page, the file selection interface of the security verification tool client is called, and the target file to be transmitted is selected. Then, the security of file transmission is improved by detecting the security verification tool password input by the user, and at the same time, the security of file transmission is further improved by signing the target file to be transmitted. In addition, the file transmission method of the present application can meet the support of multiple operating systems through the adapted security verification tool client, and can shield the differences of various modern browsers, thereby supporting multiple modern browsers.

[0086] Based on the above creative findings, the inventors propose the technical solution of the present application.

[0087] The application scenario of the file transmission method provided by the embodiment of the present application is introduced as follows. Figure 2As shown, 10 is the user server, 20 is the user, and 30 is the intranet application server. The network architecture of the application scenario corresponding to the file transfer method provided in this embodiment includes: user server 10 and intranet application server 30. User 20 can be an external customer of the financial system. A corresponding security verification tool client is pre-configured in user server 10. This security verification tool client is compatible with the operating system of user server 10, which can be Windows / OS or other operating systems. Simultaneously, the security verification tool client supports modern browsers, such as Chrome.

[0088] For example, when user 20 prepares to upload a file, they insert a security verification tool into user server 10, establishing a connection between the tool and server 10. This security verification tool can be a USB key, mobile digital certificate, etc. Simultaneously, user 20 completes login verification on the business application's website page and selects a file on the web application page. In response to the user's file selection on the web application page, user server 10 calls the file selection interface of the security verification tool client and selects the target file to be transferred. Then, user 20 enters the security verification tool password, which user server 10 sends to the intranet application server 30 for verification. If user server 10 receives a successful verification message from the intranet application server, it signs the target file, generates a target signature file, and transmits it to the intranet application server 30 for verification. After verifying the target signature file, the intranet application server 30 can send a message of successful file transfer to the user server 10 so that the user 20 is aware of the file transfer result.

[0089] The embodiments of this application are described below with reference to the accompanying drawings.

[0090] Figure 1 Flowchart of the file transfer method provided in this application Figure 2 ,like Figure 3 As shown, in this embodiment, the execution subject of this application embodiment is a file transfer device, which can be integrated into an electronic device, and the electronic device can be a user server. Therefore, the file transfer method provided in this embodiment includes the following steps:

[0091] Step S101: In response to the user's file selection operation on the web application page, the file selection interface of the security verification tool client is invoked, and the target file to be transferred is selected. The security verification tool client is compatible with the operating system of the user server.

[0092] In this embodiment, when preparing to upload a file, the user inserts a security verification tool into the user server, so that the security verification tool is connected with the user server. The security verification tool can adopt different security verification tools according to different application scenarios, such as a U disk, a mobile digital certificate, and the like. The U disk is used more in the bank system. Meanwhile, the user completes the login verification of the business website itself on the website page of the business application, and performs a file selection operation on the webpage application page.

[0093] At this time, the user server, in response to the file selection operation of the user on the webpage application page, calls a file selection interface of the security verification tool client, and selects a target file to be transmitted. The target file is a local file to be transmitted.

[0094] The security verification tool function provider pre-compiles a driver client of a windows / uos operating system, which is used for reading a security verification tool peripheral, and different operating systems provide client drivers compiled based on different architectures. When the security verification tool client provides an interface, only a JS (English full name: JavaScript) file that shields the differences of operating systems and browsers is provided. The webpage browser can call the interface of the security verification tool by referring to the JS file of the security verification tool, so as to realize the file selection, file signature, file acquisition and the like of the security verification tool. The file transmission component only needs to judge different browsers and operating systems according to a User-Agent field in a file request header, so as to call the actual security verification tool service through the JS interface, and the file is provided by the security verification tool synchronously.

[0095] In step S102, the security verification tool password input by the user is received, and the security verification tool password is sent to the intranet application server, so that the intranet application server detects the security verification tool password.

[0096] In this embodiment, after the target file to be transmitted is determined, the user can be prompted to input the security verification tool password, and the certificate of the security verification tool can be verified, and the security verification tool password is sent to the intranet application server for identity verification by the intranet application server.

[0097] For example, when the U disk is adopted, the user can be prompted to input the security verification tool password, and the U disk certificate can be verified.

[0098] In step S103, after receiving the detection success information sent by the intranet application server, the target file is signed to generate a target signature file.

[0099] After the identity verification is completed, the target file can be signed to generate a target signature file, so as to further improve the security of file transmission.

[0100] Due to modern browser security requirements, it is not allowed to obtain the actual file on the client according to the file path, and the file path returned is also a virtual path that cannot obtain the real path of the file. Therefore, under the modern browser, the help of a security verification tool client is needed to select and obtain the actual path of the file.

[0101] The security verification tool, such as a U disk, can provide the following interface:

[0102] File selection interface: prompt the client to select a file, and after the client completes the selection of the file to be signed, internally calculate the first detection token token = HASH (Chinese for Hash) value (file full path + file content + random number), realize the mapping relationship of token and random number, file path, and save it at the same time, and return the result.

[0103] File signature interface: complete the signature function of the selected target file, the interface prompts the client to input the security verification tool password and select the security verification tool certificate, and complete the signature of the selected target file in the form of large file signature, and write the signature result to the local file. Through the encryption algorithm, calculate the second detection token token = HASH value (file full path + file content + random number) of the target signature file, realize the relationship mapping and saving of token and random number, file path.

[0104] File acquisition interface: compare the first detection token token with the second detection token token, if they are the same, the interface authorizes the caller to read the corresponding file content.

[0105] Step S104, transmit the target signature file to the intranet application server, so that the intranet application server verifies the target signature file.

[0106] After the target signature file is transmitted to the intranet application server, the intranet application server can verify the signature through the verification tool. If the data size of the target signature file is too large, the target signature file can also be divided into multiple sub-signature files, and the sub-signature files are transmitted to the intranet application server. The intranet application server can splice the sub-signature files after receiving all the sub-signature files to form a complete target signature file and perform verification.

[0107] The file transmission method, device, equipment, medium and product provided by the embodiment of the application, the method comprises the following steps.

[0108] The file transmission method of the application is matched with the operating system of the user server and the security verification tool client, and the user server is connected with the security verification tool. When the user transmits the file, the file selection interface of the security verification tool client is called in response to the file selection operation of the user on the webpage application page, and the target file to be transmitted is selected. Then, the security of the file transmission is improved by detecting the security verification tool password input by the user, and the security of the file transmission is further improved by signing the target file to be transmitted. In addition, the file transmission method of the application can support multiple operating systems through the adaptive security verification tool client, and can shield the differences between various modern browsers, thereby supporting multiple modern browsers.

[0109] Figure 2 The flowchart of the file transmission method provided by the application Figure 3 As shown in Figure 4-6 The file transmission method provided by the embodiment is further refined on the basis of the file transmission method provided by the previous embodiment of the application. The file transmission method provided by the embodiment comprises the following steps.

[0110] Step S201, in response to the file selection operation of the user on the webpage application page, the file selection interface of the security verification tool client is called by using the local information tool Native messaging, and the target file to be transmitted is selected.

[0111] In the embodiment, the modern browser used can be a chrome browser. Cross-process local information transmission is performed by using the local information tool Native messaging, so as to call the file selection interface of the security verification tool client. The information transmission efficiency is improved, so as to improve the efficiency of selecting the target file to be transmitted.

[0112] Meanwhile, the chrome browser can also call the function of the security verification tool client through the JS file of the security verification tool, and the related function of the security verification tool client is called through the local information tool Native messaging during the cross-process local information transmission.

[0113] In step S202, in response to the click operation of the user on the upload component, a security verification tool password input box is displayed in the web application page.

[0114] In this embodiment, after the user selects the file to be transmitted, the user can click the upload component. At this time, in response to the click operation of the user, a security verification tool password input box is displayed in the web application page, so that the user can input the security verification tool password.

[0115] In step S203, the security verification tool password input by the user in the security verification tool password input box is received.

[0116] In this embodiment, after the user views the security verification tool password in the security verification tool, the user can input the security verification tool password in the security verification tool password input box.

[0117] In step S204, the security verification tool password is sent to the intranet application server, so that the intranet application server detects the security verification tool password.

[0118] In this embodiment, the intranet application server is provided with an identity recognition tool for detecting the security verification tool password, and the security verification tool password can be detected.

[0119] The detection result has two aspects. One is that the detection is successful, and the intranet application server sends the detection success information to the user server. The other is that the detection fails, and the intranet application server sends the detection failure information or the identity authentication failure information to the user server, prompting the re-detection process.

[0120] In step S205, after receiving the detection success information sent by the intranet application server, the security verification tool client is called to perform signature processing on the target file, and a target signature file is generated.

[0121] In this embodiment, the signature processing on the target file by calling the security verification tool client can be signature processing in a signature mode for large files. The large file can be a file with a data size greater than a preset threshold. The signature processing can adopt a common digital signature mode.

[0122] Optionally, before step S205, the embodiment further includes:

[0123] The storage path of the target file and the data of the target file are obtained.

[0124] According to the storage path, the data of the target signature file and the preset random number, a first detection token is generated by hash calculation.

[0125] After step S205, the method further comprises:

[0126] The storage path of the target signature file and the data of the target signature file are obtained.

[0127] According to the storage path of the target signature file, the data of the target signature file and the preset random number, a second detection token is generated by hash calculation.

[0128] If the first detection token and the second detection token are the same, step S206 is executed.

[0129] If the first detection token and the second detection token are not the same, error information is displayed to prompt the user.

[0130] In order to prevent malicious callers from reading other files of the client locally through the interface of the security verification tool client, causing the client information to be leaked, the interface of the security verification tool needs to increase the verification and security protection on the overall content and format of the file to be read, and the above-mentioned verification and security protection can be performed by comparing the first detection token and the second detection token. Meanwhile, the file format of the target signature file needs to meet the relevant file signature result specification requirements.

[0131] In step S206, if it is determined that the data size of the target signature file is greater than a preset threshold, the target signature file is divided into a preset number of sub-signature files.

[0132] In the embodiment, the preset threshold can be set to 70 megabytes. When the size of the uploaded file exceeds 70 megabytes, the browser may not be able to carry it at one time, causing the browser to crash, so that the target signature file needs to be segmented and read for uploading. The preset threshold can also be set according to the actual application situation, and the embodiment does not limit this.

[0133] In step S207, all the sub-signature files are transmitted to the intranet application server, so that the intranet application server verifies all the sub-signature files.

[0134] In the embodiment, all the sub-signature files are transmitted to the intranet application server, and the intranet application server can verify all the sub-signature files by using a preset signature verification tool.

[0135] Optionally, after step S207, the method further comprises:

[0136] The file transmission success information fed back by the intranet application server is received.

[0137] In this embodiment, after checking all the sub-signature files and the checking is successful, the file transmission is completed, at this time, the intranet application server can feed back the file transmission success information to the user server, so as to prompt the user the file transmission result.

[0138] When the checking fails, the file transmission failure information can also be fed back to the user server.

[0139] In order to further illustrate the file transmission method of the present application, the following will be described in detail in combination with the drawings. As shown in the drawings, the present embodiment is described for both financial application and general application. Figure 4 Figure 4 The flow sequence 1 to 7 is used to describe the flow sequence, which is the sequence of 1, 2, 3 to 7. The user server and the intranet application server are connected, the file transmission combination component in the financial application front page and the file transmission combination component in the financial application server cluster all include the exchange assembly function, the file transmission function and the security verification function.

[0140] In this embodiment, the new standardized client and server public components are directly selected or flexibly packaged by the business application as needed, the new client public component (file transmission combination component) is deployed in the business application front interface, and the new server public component (file transmission combination component) is directly deployed in the application background server, so as to realize the direct and efficient exchange of business application front and background files, and align with the industry exchange design mode.

[0141] The whole flow interaction between the user server and the intranet application server is shown in the drawings: Figure 5 As shown in the drawings: the client submits the file in the financial application front page of the user server, the user server initiates the connection to the intranet application server, and the intranet application server sends the identity authentication instruction to the user server. At this time, the user server prompts the user to input the user password of the U disk or the U disk certificate, the user server sends the user password of the U disk or the U disk certificate to the intranet application server, and the intranet application server feeds back the identity verification result after checking. If the identity verification result is passed, the user server encrypts and signs the file selected by the client to be submitted to generate a target signature file, and at the same time, transmits the encrypted target signature file to the intranet application server. The intranet application server performs file checking processing, which specifically includes file signature verification and decryption.

[0142] If it is a general file processed on the general application front page, after the client submits the file on the general application front page, the user server directly initiates the connection to the intranet application server and transmits the file, without the need of identity authentication and file encryption and decryption processing flow.

[0143] The whole flow of file transmission is shown in the drawings, and specifically as follows: Figure 6 The whole flow of file transmission is shown in the drawings, and specifically as follows:

[0144] (11) The customer has completed the login verification of the business website itself on the website page of the financial service application, comes to the relevant business page, and involves the uploading of an attached file.

[0145] (12) The customer inserts the U disk hardware applied for by the user server, and the customer clicks the browse button. The page initiates the security control, selects the local file through the file selection box provided by the U disk manufacturer, and performs the local file selection.

[0146] (13) The customer clicks the upload button on the page, and a U disk password input dialog box is popped up. The customer inputs the U disk password. If the password is incorrect, the customer is prompted to continue inputting the password. If the password is correct, the password input dialog box is closed.

[0147] (14) The page security control performs signature and other operations on the local business data file selected by the customer, to generate a new signature data file.

[0148] (15) The page uploads the signature data file to the background. This stage is a cyclic acquisition. For example, a 100M (megabyte) file is divided into 5 pieces, each piece is 20M, and the file is divided into pieces and transmitted to the back end. The back end performs file splicing.

[0149] (16) After the signature data file reaches the background, the back end checks whether the file pieces have all arrived. If all have arrived, the file is spliced into a complete signature file. Then, the encryption machine is called to perform file verification. After the verification is successful, it is indicated that the customer has completed the business operation. After the file is spliced and verified, the finally generated file is placed in the specified mounting directory, so as to facilitate different servers to share the same file path for file sharing.

[0150] The transmission capacity of the large file is mainly composed of the ability of piece division and sequential transmission. The file security ability is mainly completed by the JS interface ability of the U disk client provided by the U disk manufacturer. To realize the large file security transmission ability of cross-platform and multiple browsers, the cross-platform and browser support ability of the U disk is relied on to some extent.

[0151] In the embodiment, by adopting the technical architecture mode of the JS interface of the U disk client + nativeMessage communication technology + local program, the modern browser can call the local program of the user server through the nativeMessage communication mode, to complete the ability of local file signature.

[0152] As Figure 7As shown, the browser used in this embodiment is the Chrome browser, and the U disk supplier needs to provide a driver installation package, a browser extension package and a page auxiliary JS file that can be installed on various systems. The driver installation package integrates a driver library, a local Native Host program and a json (English full name: JavaScript Object Notation, Chinese JS object notation) configuration file of a NativeMessaging program. The browser extension package integrates a manifest.json display file, a content.js content file and a background.js background file, and the above three files are related files of the Chrome plug-in. The page auxiliary JS file provides related function interfaces such as U disk calling, which are used for transmission component page to call and use, and the JS file internally implements functions such as extension message transmission and interface result feedback.

[0153] The Web (English full name: World Wide Web, Chinese: global wide area network) application page references the U disk manufacturer JS file, calls the related function interfaces in the JS file, the function in the JS file encapsulates the corresponding U disk interface function, and is responsible for data and instruction transmission with the Chromium kernel browser extension, and the client processing result return. The Chrome browser can call the corresponding function of the U disk client through the JS file.

[0154] Figure 7 The structure diagram of the file transmission device provided in the present application is shown in Figure 2 As shown, in this embodiment, the file transmission device 300 can be arranged in a user server, the user server is connected with a security verification tool, and the file transmission device 300 comprises:

[0155] A selection module 301 is configured to, in response to a file selection operation of a user on a web application page, call a file selection interface of a security verification tool client, and select a target file to be transmitted. The security verification tool client is matched with the operating system of the user server.

[0156] A sending module 302 is configured to receive a security verification tool password input by a user, and send the security verification tool password to an intranet application server, so that the intranet application server detects the security verification tool password.

[0157] A signature module 303 is configured to, after receiving detection success information sent by the intranet application server, perform signature processing on the target file to generate a target signature file.

[0158] A transmission module 304 is configured to transmit the target signature file to the intranet application server, so that the intranet application server checks the target signature file.

[0159] The file transmission device provided by the embodiment can perform Figure 2 The technical solutions of the method embodiments, the implementation principles and the technical effects are similar to those of the file transmission device embodiments, which will not be repeated here. Figure 5 The method embodiments are similar to the file transmission device embodiments, which will not be repeated here.

[0160] Figure 2 The structure of the file transmission device provided by the embodiment is shown in the figure Figure 2-6 The file transmission device provided by the embodiment is further refined on the basis of the file transmission device provided in the previous embodiment, and the file transmission device 300 comprises:

[0161] Optionally, in the embodiment, the selection module 301 is specifically configured to:

[0162] In response to the file selection operation of the user on the web application page, the file selection interface of the security verification tool client is called by using the native messaging, and the target file to be transmitted is selected.

[0163] Optionally, in the embodiment, when the security verification tool password input by the user is received, the sending module 302 is specifically configured to:

[0164] In response to the click operation of the user on the upload component, a security verification tool password input box is displayed in the web application page. The security verification tool password input by the user in the security verification tool password input box is received.

[0165] Optionally, in the embodiment, when the target file is signed to generate the target signature file, the signature module 303 comprises:

[0166] The target file is signed by calling the security verification tool client to generate the target signature file.

[0167] Optionally, in the embodiment, the signature module 303 is further configured to:

[0168] The storage path of the target file and the data of the target file are obtained. The first detection token is generated by performing hash calculation on the storage path, the data of the target file and the preset random number.

[0169] The signature module 303 is further configured to:

[0170] The storage path of the target signature file and the data of the target signature file are obtained. The second detection token is generated by performing hash calculation on the storage path of the target signature file, the data of the target signature file and the preset random number. If the first detection token and the second detection token are the same, the step of transmitting the target signature file to the intranet application server is performed.

[0171] Optionally, in the embodiment, the transmission module 304 is specifically configured to:

[0172] If the target signature file's data size exceeds a preset threshold, the target signature file is divided into a preset number of sub-signature files. All sub-signature files are then transmitted to the intranet application server for verification.

[0173] Optionally, in this embodiment, when the transmission module 304 transmits all sub-signature files to the intranet application server so that the intranet application server can verify all sub-signature files, it is specifically used for:

[0174] All sub-signature files are transmitted to the intranet application server, so that the intranet application server can concatenate all the sub-signature files to generate a concatenated signature file and verify the concatenated signature file.

[0175] Optionally, in this embodiment, the file transfer device 300 further includes:

[0176] The receiving module is used to receive file transfer success information from the intranet application server.

[0177] The file transfer device provided in this embodiment can perform... Figure 2-6 The technical solution of the method embodiment shown has the same implementation principle and technical effect as... Figure 8 The methods and embodiments shown are similar and will not be described in detail here.

[0178] According to embodiments of this application, this application also provides an electronic device, a computer-readable storage medium, and a computer program product.

[0179] like Figure 8 As shown, Figure 8 This is a schematic diagram of the electronic device provided in this application. The electronic device is intended for various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, blade servers, mainframe computers, and other suitable computers. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present application described and / or claimed herein.

[0180] like Figure 7 As shown, the electronic device includes a processor 401 and a memory 402. The various components are interconnected via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processor can process instructions executed within the electronic device.

[0181] The memory 402 is a non-transitory computer readable storage medium provided by the present application. The memory stores instructions executable by the at least one processor, so that the at least one processor executes the file transmission method provided by the present application. The non-transitory computer readable storage medium of the present application stores computer instructions for causing a computer to execute the file transmission method provided by the present application.

[0182] The memory 402 is a non-transitory computer readable storage medium, which can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules (for example, the selection module 301, the sending module 302, the signature module 303 and the transmission module 304 corresponding to the file transmission method in the embodiments of the present application) of the file transmission method in the embodiments of the present application. ​ The processor 401 executes various function applications and data processing of the electronic device by running the non-transitory software programs, instructions and modules stored in the memory 402, that is, implements the file transmission method in the above method embodiments.

[0183] Meanwhile, the present embodiment also provides a computer product. When the instructions in the computer product are executed by the processor of the electronic device, the electronic device can execute the file transmission method of the above embodiments.

[0184] Other embodiments of the present application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The present application is intended to cover any variations, uses or adaptive changes of the present application falling within the general scope of the application. The present application includes common knowledge or conventional technical means in the art which are not disclosed in the present application, which follow the general principles of the present application.

[0185] It should be understood that the present application is not limited to the precise construction that has been described above and shown in the accompanying drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the present application. The scope of the present application is only limited by the appended claims.

Claims

1. A file transfer method characterized by, The user server is connected with a security verification tool, and the method comprises: In response to a file selection operation of a user on a webpage application page, a file selection interface of a security verification tool client is called through Native messaging by referencing a JS file of the security verification tool, and a file selection box provided by the security verification tool client is used to select a target file to be transmitted; the security verification tool client is matched with an operating system of the user server; A security verification tool password input by a user is received, and the security verification tool password is sent to an intranet application server to enable the intranet application server to detect the security verification tool password; After receiving detection success information sent by the intranet application server, the target file is subjected to signature processing to generate a target signature file; Before the security verification tool client is called to process the target file to generate the target signature file, the method further comprises: A storage path of the target file and data of the target file are obtained; A first detection token is generated through hash calculation based on the storage path of the target file, the data of the target file and a preset random number; After the security verification tool client is called to process the target file to generate the target signature file, the method further comprises: A storage path of the target signature file and data of the target signature file are obtained; A second detection token is generated through hash calculation based on the storage path of the target signature file, the data of the target signature file and the preset random number; If the first detection token and the second detection token are the same, the target signature file is transmitted to the intranet application server to enable the intranet application server to verify the target signature file.

2. The method of claim 1, wherein, The security verification tool password input by the user is received, comprising: In response to a click operation of a user on an upload component, a security verification tool password input box is displayed on the webpage application page; The security verification tool password input by the user in the security verification tool password input box is received.

3. The method of claim 2, wherein, The target file is subjected to signature processing to generate a target signature file, comprising: The security verification tool client is called to process the target file to generate the target signature file.

4. The method according to any one of claims 1 to 3, characterized in that, The target signature file is transmitted to the intranet application server to enable the intranet application server to verify the target signature file, comprising: If it is determined that the data size of the target signature file is greater than a preset threshold, the target signature file is divided into a preset number of sub-signature files; All the sub-signature files are transmitted to the intranet application server to enable the intranet application server to verify all the sub-signature files.

5. The method of claim 4, wherein, The all sub-signature files are transmitted to the intranet application server to enable the intranet application server to verify all the sub-signature files, comprising: All the sub-signature files are transmitted to the intranet application server to enable the intranet application server to splice the sub-signature files to generate a spliced signature file, and the spliced signature file is verified.

6. The method of claim 4, wherein, After the target signature file is transmitted to the intranet application server, the method further comprises: Receive the file transmission success information fed back by the intranet application server.

7. A file transfer apparatus characterized by comprising: The user server is connected with a security verification tool, and the device comprises: A selection module is configured to, in response to a file selection operation of a user on a webpage application page, call a file selection interface of the security verification tool client by referencing a JS file of the security verification tool through Native messaging, and select a target file to be transmitted in a file selection box provided by the security verification tool client; the security verification tool client is matched with an operating system of the user server; A sending module is configured to receive a security verification tool password input by the user, and send the security verification tool password to the intranet application server, so that the intranet application server detects the security verification tool password; A signature module is configured to, after receiving detection success information sent by the intranet application server, perform signature processing on the target file to generate a target signature file; Obtain the storage path of the target file and the data of the target file; Generate a first detection token through hash calculation according to the storage path of the target file, the data of the target file, and a preset random number; Obtain the storage path of the target signature file and the data of the target signature file; Generate a second detection token through hash calculation according to the storage path of the target signature file, the data of the target signature file, and the preset random number; If the first detection token and the second detection token are the same, perform the step of transmitting the target signature file to the intranet application server; A transmission module is configured to transmit the target signature file to the intranet application server, so that the intranet application server verifies the target signature file.

8. An electronic device, comprising: Comprise: A memory and a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to realize the file transmission method of any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the file transmission method of any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to realize the file transmission method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data processing method, device and system

    CN105553976A

  • Internal / external network access authenticating system using USB KEY (universal serial bus key) as certificate medium

    CN201976122U