A mobile terminal-based file security access method
By using a proprietary file access application customized on mobile terminals and a dedicated network channel for operators, combined with the SM4 block cipher algorithm and a secure access platform, the vulnerability and leakage of secure file access on mobile devices are solved, enabling secure file transmission and access.
Patent Information
- Application Number
- CN202311690088.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-08
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-12-08
AI Technical Summary
Secure access to files on mobile devices faces vulnerabilities to attacks, file leaks, and loss, and existing technologies struggle to provide efficient and convenient protection measures.
By customizing a proprietary file access application built into the mobile terminal, utilizing the operator's dedicated network channel and the server's secure access platform and relay front-end service, the SM4 block cipher algorithm is used to encrypt and decrypt access requests and file data, and permissions are queried in the intranet, supporting secure file access.
It ensures confidentiality and integrity during file transfer, prevents unauthorized access and tampering, supports multiple operating systems, and has wide applicability.
Smart Images

Figure CN118094612B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a secure file access method based on a mobile terminal, belonging to the field of network security technology. Background Technology
[0002] With the widespread use of mobile devices and the increasing volume of data, file security on mobile devices is receiving growing attention. In daily life, people use mobile devices to store, process, and transfer various types of files. However, the portability and ease of use of mobile devices also make secure file access a challenge. Mobile devices are vulnerable to attacks that could steal or tamper with users' files. Furthermore, the loss or theft of mobile devices can lead to file leaks. Therefore, to protect user privacy and security, an efficient and convenient method for secure file access is needed.
[0003] This patent proposes a method for securely accessing files in an intranet environment via mobile devices, which can effectively solve the problem of important files not being able to be viewed at any time. Summary of the Invention
[0004] To address the problems existing in the prior art, this invention proposes a secure file access method based on mobile terminals.
[0005] The technical solution of the present invention is as follows:
[0006] On one hand, the present invention provides a method for secure file access based on a mobile terminal, comprising the following steps:
[0007] Log in to the proprietary file access application built into the customized mobile terminal. After logging in to the proprietary file access application, the customized mobile terminal initiates a file access request. The customized mobile terminal encrypts the access request and sends it to the server through the operator's dedicated network channel.
[0008] The server-side built-in secure access platform verifies the validity of the request according to the security policy. If the verification is successful, the access request is forwarded to the server-side built-in forwarding service. The forwarding service decrypts the access request and then forwards the decrypted access request to the server-side built-in intranet service.
[0009] The intranet service analyzes access permissions through the decrypted access request and queries the corresponding file data in the intranet. Then, it encrypts the file data and returns it to the forwarding service. The forwarding service encrypts the file data and returns it to the secure access platform. The secure access platform returns the data to the customized mobile terminal through the operator's dedicated network channel. Finally, the customized mobile terminal decrypts the file data and displays the file content.
[0010] In a preferred embodiment of the present invention, the access request and file data are both encrypted and decrypted using the SM4 block cipher algorithm.
[0011] In a preferred embodiment of the present invention, the secure access platform includes port mapping and protocol control functions. The secure access platform uses the above functions to shield internal service ports from the outside world, allowing only access requests for specific ports and corresponding protocols to enter the server's intranet.
[0012] In a preferred embodiment of the present invention, the relay front-end service includes configuration management, data encryption / decryption, and request forwarding functions;
[0013] The configuration management function binds customized mobile terminals to personal or departmental information. When a customized mobile terminal is lost, the configuration management function can remotely unbind the personal or departmental information bound to the customized mobile terminal and erase the data on the customized mobile terminal.
[0014] In a preferred embodiment of the present invention, the transit pre-service encrypts the file data, converts the file data into a streaming PDF format, and loads a digital signature watermark.
[0015] On the other hand, the present invention also provides a file security access system based on a mobile terminal, including a customized mobile terminal, a dedicated network channel for operators, and a server.
[0016] The customized mobile terminal is used to initiate file access requests through a built-in proprietary file access application, and after encrypting the access request, it is sent to the server through the operator's dedicated network channel. At the same time, the customized mobile terminal is also used to decrypt the file data returned by the server and display the file content.
[0017] The server-side built-in secure access platform verifies the validity of file requests initiated by the customized mobile terminal according to security policies. If the verification is successful, the access request is forwarded to the server-side built-in relay front-end service. The relay front-end service decrypts the access request and forwards it to the server-side built-in intranet service. The intranet service analyzes the access permissions through the decrypted access request and queries the corresponding file data in the intranet. Then, it encrypts the file data and returns it to the relay front-end service. The relay front-end service encrypts the file data and returns it to the secure access platform. The secure access platform returns the data to the customized mobile terminal through the operator's dedicated network channel.
[0018] In a preferred embodiment of the present invention, the customized mobile terminal prohibits internet connection, disables WIFI transmission and USB transmission, establishes communication with the server through the operator's dedicated network channel based on a dedicated SIM card, and has a built-in secure TF card for secure data storage.
[0019] The customized mobile terminal has a built-in proprietary file access application that provides functions to prevent screenshots and copying. When the proprietary file access application is used to view file content, the file content is loaded into the application's memory, and watermark information is also loaded into the file content. Violations are also reported to the server for early warning.
[0020] In a preferred embodiment of the present invention, the access request and file data are both encrypted and decrypted using the SM4 block cipher algorithm.
[0021] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method as described in any embodiment of the present invention.
[0022] In another aspect, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in any embodiment of the present invention.
[0023] The present invention has the following beneficial effects:
[0024] 1. This invention establishes security measures at every stage, from the mobile terminal and network channel to file browsing, ensuring the confidentiality and integrity of files during transmission. Simultaneously, by encrypting files using encryption algorithms and implementing non-local file browsing, it effectively prevents unauthorized users from obtaining and tampering with files. Furthermore, the mobile terminal of this invention supports multiple operating systems and platforms, exhibiting broad applicability. Attached Figure Description
[0025] Figure 1 This is a data transmission flowchart of the present invention. Detailed Implementation
[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0027] It should be understood that the step numbers used in the text are for ease of description only and are not intended to limit the order in which the steps are performed.
[0028] It should be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0029] The terms “comprising” and “including” indicate the presence of the described feature, whole, step, operation, element and / or component, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.
[0030] The term “and / or” refers to any combination of one or more of the associated listed items, as well as all possible combinations, and includes these combinations.
[0031] Example 1:
[0032] See Figure 1 A method for secure file access based on a mobile terminal includes the following steps:
[0033] Log in to the proprietary file access application built into the customized mobile terminal. After logging in to the proprietary file access application, the customized mobile terminal initiates a file access request. The customized mobile terminal encrypts the access request and sends it to the server through the operator's dedicated network channel.
[0034] The server-side built-in secure access platform verifies the validity of the request according to the security policy. If the verification is successful, the access request is forwarded to the server-side built-in forwarding service. The forwarding service decrypts the access request and then forwards the decrypted access request to the server-side built-in intranet service.
[0035] The intranet service analyzes access permissions through the decrypted access request and queries the corresponding file data in the intranet. Then, it encrypts the file data and returns it to the forwarding service. The forwarding service encrypts the file data and returns it to the secure access platform. The secure access platform returns the data to the customized mobile terminal through the operator's dedicated network channel. Finally, the customized mobile terminal decrypts the file data and displays the file content.
[0036] In a preferred embodiment of this invention, the access request and file data are both encrypted and decrypted using the SM4 block cipher algorithm.
[0037] In a preferred embodiment of this invention, the secure access platform includes port mapping and protocol control functions. The secure access platform uses these functions to shield internal service ports from the outside world, allowing only access requests for specific ports and corresponding protocols to enter the server's intranet.
[0038] As a preferred embodiment of this example, the relay front-end service includes configuration management, data encryption / decryption, and request forwarding functions;
[0039] The configuration management function binds customized mobile terminals to personal or departmental information to prevent misuse. When a customized mobile terminal is lost, the configuration management function can remotely cancel the personal or departmental information bound to the customized mobile terminal and erase the data on the customized mobile terminal.
[0040] In a preferred embodiment of this example, the transit pre-service encrypts the file data, converts the file data into a streaming PDF format, and loads a digital signature watermark.
[0041] Example 2:
[0042] A file security access system based on a mobile terminal includes a customized mobile terminal, a dedicated network channel for mobile operators, and a server.
[0043] The customized mobile terminal is used to initiate file access requests through a built-in proprietary file access application, and after encrypting the access request, it is sent to the server through the operator's dedicated network channel. At the same time, the customized mobile terminal is also used to decrypt the file data returned by the server and display the file content.
[0044] The server-side built-in secure access platform verifies the validity of file requests initiated by the customized mobile terminal according to security policies. If the verification is successful, the access request is forwarded to the server-side built-in relay front-end service. The relay front-end service decrypts the access request and forwards it to the server-side built-in intranet service. The intranet service analyzes the access permissions through the decrypted access request and queries the corresponding file data in the intranet. Then, it encrypts the file data and returns it to the relay front-end service. The relay front-end service encrypts the file data and returns it to the secure access platform. The secure access platform returns the data to the customized mobile terminal through the operator's dedicated network channel.
[0045] In a preferred embodiment of this invention, the customized mobile terminal prohibits internet connection, disables WIFI transmission and USB transmission, establishes communication with the server through a dedicated network channel of the operator based on a dedicated SIM card, and has a built-in secure TF card for secure data storage.
[0046] The customized mobile terminal has a built-in proprietary file access application that provides functions to prevent screenshots and copying. When the proprietary file access application is used to view file content, the file content is loaded into the application's memory, and watermark information is also loaded into the file content. Violations are also reported to the server for early warning.
[0047] In a preferred embodiment of this invention, the access request and file data are both encrypted and decrypted using the SM4 block cipher algorithm.
[0048] Example 3:
[0049] This embodiment proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the method described in any embodiment of the present invention.
[0050] Example 4:
[0051] This embodiment proposes a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the method described in any embodiment of the present invention.
[0052] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent the existence of A alone, A and B simultaneously, or B alone. A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of singular or plural items. For example, at least one of a, b, and c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0053] Those skilled in the art will recognize that the units and algorithm steps described in the embodiments disclosed herein can be implemented using electronic hardware, computer software, or a combination of electronic hardware and software. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0054] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0055] In the several embodiments provided in this application, any function, if implemented as a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0056] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for secure file access based on a mobile terminal, characterized in that, Includes the following steps: Log in to the proprietary file access application built into the customized mobile terminal. After logging in to the proprietary file access application, the customized mobile terminal initiates a file access request. The customized mobile terminal encrypts the access request and sends it to the server through the operator's dedicated network channel. The server-side built-in secure access platform verifies the validity of the request according to the security policy. If the verification is successful, the access request is forwarded to the server-side built-in forwarding service. The forwarding service decrypts the access request and then forwards the decrypted access request to the server-side built-in intranet service. The intranet service analyzes access permissions through the decrypted access request and queries the corresponding file data in the intranet. Then, it encrypts the file data and returns it to the forwarding service. The forwarding service encrypts the file data and returns it to the secure access platform. The secure access platform returns the data to the customized mobile terminal through the operator's dedicated network channel. Finally, the customized mobile terminal decrypts the file data and displays the file content.
2. The method for secure file access based on a mobile terminal according to claim 1, characterized in that, The access requests and file data are encrypted and decrypted using the SM4 block cipher algorithm.
3. The method for secure file access based on a mobile terminal according to claim 1, characterized in that, The secure access platform includes port mapping and protocol control functions. Through these functions, the secure access platform blocks internal service ports from the outside, allowing only access requests for specific ports and corresponding protocols to enter the server's internal network.
4. The method for secure file access based on a mobile terminal according to claim 1, characterized in that, The relay front-end service includes configuration management, data encryption / decryption, and request forwarding functions; The configuration management function binds customized mobile terminals to personal or departmental information. When a customized mobile terminal is lost, the configuration management function can remotely unbind the personal or departmental information bound to the customized mobile terminal and erase the data on the customized mobile terminal.
5. A method for secure file access based on a mobile terminal according to claim 4, characterized in that, The relay pre-service encrypts the file data, converts it into a streaming PDF format, and loads a digital signature watermark.
6. A file security access system based on a mobile terminal, characterized in that, This includes customized mobile terminals, dedicated network channels for operators, and server-side components; The customized mobile terminal is used to initiate file access requests through a built-in proprietary file access application, and after encrypting the access request, it is sent to the server through the operator's dedicated network channel. At the same time, the customized mobile terminal is also used to decrypt the file data returned by the server and display the file content. The server-side built-in secure access platform verifies the validity of file requests initiated by the customized mobile terminal according to security policies. If the verification is successful, the access request is forwarded to the server-side built-in relay front-end service. The relay front-end service decrypts the access request and forwards it to the server-side built-in intranet service. The intranet service analyzes the access permissions through the decrypted access request and queries the corresponding file data in the intranet. Then, it encrypts the file data and returns it to the relay front-end service. The relay front-end service encrypts the file data and returns it to the secure access platform. The secure access platform returns the data to the customized mobile terminal through the operator's dedicated network channel.
7. A file security access system based on a mobile terminal according to claim 6, characterized in that, The customized mobile terminal prohibits internet connection, disables WIFI transmission and USB transmission, establishes communication with the server through the operator's dedicated network channel based on a dedicated SIM card, and has a built-in secure TF card for secure data storage. The customized mobile terminal has a built-in proprietary file access application that provides functions to prevent screenshots and copying. When the proprietary file access application is used to view file content, the file content is loaded into the application's memory, and watermark information is also loaded into the file content. Violations are also reported to the server for early warning.
8. A file security access system based on a mobile terminal according to claim 6, characterized in that, The access requests and file data are encrypted and decrypted using the SM4 block cipher algorithm.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 5.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Mobile working method, server, client and system
CN107368747A
Data access method, data encryption method and data encryption and access system
CN111193755A