A method, device and medium for file encryption and decryption based on a cloud desktop

The cloud desktop files are encrypted through SM4 and SM2 encryption algorithms, and the SM2 private key of the physical machine is decrypted, which solves the confidentiality problem of copying files from the cloud desktop to the physical machine, and realizes the secure transmission of files.

CN118627095BActive Publication Date: 2025-07-22GUANGZHOU BAOLUN ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410834723.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-26
Publication Date
2025-07-22
Estimated Expiration
2044-06-26

AI Technical Summary

Technical Problem

When copying files from cloud desktop to physical machines, the prior art has the problem of poor file confidentiality.

Method used

The target file is encrypted using SM4 and SM2 encryption algorithms, and the SM4 symmetric key is generated and the SM2 public key is encrypted. The SM2 private key of the entity machine is decrypted. Combined with the openssl encryption method, the file encryption and decryption is realized.

Benefits of technology

Improve file confidentiality when copying files from cloud desktop to physical machines, ensuring the security of files during transfer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118627095B_ABST
    Figure CN118627095B_ABST
Patent Text Reader

Abstract

The present application discloses a method, device and medium for file encryption and decryption based on a cloud desktop, belonging to the field of file encryption and decryption. The file encryption method based on a cloud desktop is applied to a cloud desktop. The cloud desktop is communicatively connected to a physical machine, and a client is installed on the physical machine. The method includes: in response to an operation by a target user to copy a target file from the cloud desktop to the physical machine, obtaining the target file through a target coroutine, encrypting the target file to obtain an encrypted target file; sending the encrypted target file to the client so that the client performs decryption approval on the encrypted target file according to decryption application information. If the decryption approval of the encrypted target file passes, decrypting the encrypted target file to obtain the target file; the decryption application information is obtained according to a decryption request for the target file initiated by the target user on the client, so as to improve the file confidentiality when copying a file from the cloud desktop to the physical machine.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of file encryption and decryption, and particularly to a method, device, and medium for file encryption and decryption based on a cloud desktop. Background Art

[0002] Currently, most of our software development and work documents, such as confidential documents like requirements analysis research reports, industry analysis, software programs, and software source codes, are developed on cloud desktops. When it is necessary to copy files from the cloud desktop to a physical machine, if the files are not encrypted, it is possible to leak relevant confidential information, and the confidentiality of the files is relatively poor. Summary of the Invention

[0003] This application provides a method, device, and medium for file encryption and decryption based on a cloud desktop to improve the confidentiality of files when copying files from the cloud desktop to a physical machine.

[0004] This application provides a file encryption method based on a cloud desktop, which is applied to the cloud desktop. The cloud desktop is communicatively connected to a physical machine, and a client is installed on the physical machine. The method includes:

[0005] In response to an operation by a target user on the cloud desktop to copy a target file to the physical machine, obtain the target file through a target coroutine, encrypt the target file to obtain an encrypted target file;

[0006] Send the encrypted target file to the client so that the client decrypts and approves the encrypted target file according to decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file; the decryption application information is obtained according to a decryption request for the target file initiated by the target user on the client.

[0007] Further, before obtaining the target file, it further includes:

[0008] Detect, through a target coroutine, an operation by the target user on the cloud desktop to copy a target file to the physical machine, and determine whether the copy of the target file is successful;

[0009] If the copy of the target file fails, end the target coroutine.

[0010] Further, encrypting the target file to obtain an encrypted target file specifically includes:

[0011] Use the SM4 encryption algorithm to calculate the target file to generate an SM4 symmetric key; the SM4 symmetric key includes: an SM4 key and an initialization vector;

[0012] Encrypt the SM4 symmetric key using the SM2 encryption algorithm to generate the SM2 public key of the cloud desktop and the SM2 private key of the physical machine respectively, and obtain the encrypted SM4 symmetric key;

[0013] Load the target file into memory in the way of reading the file stream, and encrypt the target file according to the SM4 symmetric key and the encryption method of openssl to obtain the encrypted target file.

[0014] As a preferred solution, this application uses a domestic encryption algorithm to encrypt the file transmitted from the cloud desktop, improving the file confidentiality when copying files from the cloud desktop to the physical machine.

[0015] Correspondingly, this application also provides a file decryption method based on the cloud desktop, which is applied to the client. The client is installed on the physical machine, and the physical machine and the cloud desktop are communicatively connected. The method includes:

[0016] After the client receives the encrypted target file sent by the cloud desktop, the encrypted target file is obtained by the cloud desktop in response to the operation of the target user copying the target file to the physical machine on the cloud desktop, obtaining the target file through the target coroutine, and encrypting the target file.

[0017] In response to the decryption request of the target file initiated by the target user on the client, obtain the decryption application information according to the decryption request;

[0018] Perform decryption approval on the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file.

[0019] Further, the performing decryption approval on the encrypted target file specifically is:

[0020] Determine the approval personnel information corresponding to the target user according to the domain control account organizational structure information;

[0021] If there is no approval personnel in the approval personnel information, the decryption approval of the encrypted target file passes;

[0022] If there is one or more approval personnel in the approval personnel information, send the decryption application information to the terminals of each approval personnel for approval;

[0023] If all the approval personnel pass the approval of the decryption application information, the decryption approval of the encrypted target file passes.

[0024] Further, before decrypting the encrypted target file to obtain the target file, it further includes:

[0025] Connect to the public server of the cloud desktop to obtain the SM2 private key of the physical machine and the SM4 symmetric key; the SM4 symmetric key includes: the SM4 key and the initialization vector.

[0026] Further, decrypting the encrypted target file to obtain the target file specifically includes:

[0027] Decrypt the SM4 key and the initialization vector respectively according to the SM2 private key of the physical machine to obtain the SM4 symmetric key;

[0028] Use the SM4 symmetric key to decrypt the encrypted target file to obtain the target file.

[0029] As a preferred solution, the present application performs decryption approval on the file obtained from the cloud desktop, and performs corresponding decryption on the file after the decryption approval passes, improving the file confidentiality when obtaining the file copied from the cloud desktop.

[0030] Correspondingly, the present application further provides a file encryption device based on the cloud desktop, which is applied to the cloud desktop. The cloud desktop is communicatively connected to the physical machine, and a client is installed on the physical machine. The device includes: an encryption module and a sending module;

[0031] The encryption module is configured to, in response to an operation of a target user copying a target file from the cloud desktop to the physical machine, obtain the target file through a target coroutine, and encrypt the target file to obtain an encrypted target file;

[0032] The sending module is configured to send the encrypted target file to the client, so that the client performs decryption approval on the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file; the decryption application information is obtained according to a decryption request for the target file initiated by the target user on the client.

[0033] Correspondingly, the present application further provides a file decryption device based on the cloud desktop, which is applied to the client. The client is installed on the physical machine, and the physical machine is communicatively connected to the cloud desktop. The device includes: an approval module and a decryption module;

[0034] The approval module is configured to, after the client receives the encrypted target file sent by the cloud desktop, the encrypted target file is obtained by the cloud desktop in response to an operation of a target user copying a target file from the cloud desktop to the physical machine, obtaining the target file through a target coroutine, and encrypting the target file;

[0035] In response to a decryption request for the target file initiated by a target user on a client, obtain decryption application information according to the decryption request; perform decryption approval on the encrypted target file according to the decryption application information;

[0036] The decryption module is used to decrypt the encrypted target file to obtain the target file if the decryption approval of the encrypted target file passes.

[0037] Correspondingly, the present application also provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute a file encryption method based on a cloud desktop as described in the content of the present application, or a file decryption method based on a cloud desktop as described in the content of the present application. Description of the Drawings

[0038] Figure 1 It is a schematic flowchart of an embodiment of a file encryption method based on a cloud desktop provided by the present application;

[0039] Figure 2 It is a schematic flowchart of an embodiment of a file decryption method based on a cloud desktop provided by the present application;

[0040] Figure 3 It is a schematic structural diagram of an embodiment of a file encryption device based on a cloud desktop provided by the present application;

[0041] Figure 4 It is a schematic structural diagram of an embodiment of a file decryption device based on a cloud desktop provided by the present application. Detailed Embodiments

[0042] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0043] Guomi (SM, Chinese Cryptography) is a cryptographic algorithm standard issued by the China National Cryptography Administration to protect the country's information security. Among them, SM2 is an asymmetric encryption algorithm used for key negotiation, digital signature, and data encryption. SM2 uses Elliptic Curve Cryptography (ECC) as its underlying mathematical principle. Its public key cryptosystem is based on the intractability of the Elliptic Curve Discrete Logarithm Problem (ECDLP).

[0044] Example 1

[0045] Please refer to Figure 1 , a file encryption method based on a cloud desktop provided by an embodiment of this application, which is applied to a cloud desktop. The cloud desktop is communicatively connected to a physical machine, and a client is installed on the physical machine. The method includes steps S101 - S102:

[0046] Step S101: In response to the operation of the target user copying the target file from the cloud desktop to the physical machine, obtain the target file through the target coroutine, encrypt the target file to obtain an encrypted target file;

[0047] Step S102: Send the encrypted target file to the client so that the client decrypts and approves the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file; the decryption application information is obtained according to the decryption request of the target user initiated on the client.

[0048] Further, before obtaining the target file, it further includes:

[0049] Detect the operation of the target user copying the target file from the cloud desktop to the physical machine through the target coroutine, and determine whether the copying of the target file is successful;

[0050] If the copying of the target file fails, end the target coroutine.

[0051] In this embodiment, after the target user copies the target file from the cloud desktop to the physical machine, a go coroutine is opened to detect whether the copying of the target file is successful. If the copying of the target file is successful, obtain the target file, encrypt the target file to obtain an encrypted target file;

[0052] If it is detected that the copying of the target file fails, end the go coroutine, and no target file acquisition and encryption operations will be performed;

[0053] If the acquisition of the target file fails, the go routine will end, and the encryption operation of the target file will not be performed.

[0054] Further, the encryption of the target file to obtain the encrypted target file is specifically as follows:

[0055] Use the SM4 encryption algorithm to calculate the target file to generate an SM4 symmetric key; the SM4 symmetric key includes: an SM4 key and an initialization vector;

[0056] Use the SM2 encryption algorithm to encrypt the SM4 symmetric key to generate the SM2 public key of the cloud desktop and the SM2 private key of the physical machine respectively, and obtain the encrypted SM4 symmetric key;

[0057] Load the target file into the memory in the way of reading the file stream, and encrypt the target file according to the SM4 symmetric key and the encryption method of openssl to obtain the encrypted target file.

[0058] In this embodiment, when using the SM4 encryption algorithm, an SM4 key (Key) and an initialization vector (IV) are required to perform encryption and decryption operations.

[0059] The initialization vector (IV) is a fixed-length random value, which is used together with the key in the encryption and decryption processes to enhance the security of the password. The length of the initialization vector (IV) is usually the same as the cipher block size. For the SM4 algorithm, the length of the IV is 128 bits (16 bytes). Before encrypting each new data block, the initialization vector is mixed with the previous ciphertext block to increase the complexity and security of the password.

[0060] When using the SM4 encryption algorithm, the key (Key) and the initialization vector (IV) are necessary parameters, and the specific operation mode will determine whether the initialization vector needs to be used. For example, in the CBC mode, the key and the initialization vector need to be provided, while in the ECB (Electronic Codebook) mode, only the key needs to be provided.

[0061] In this embodiment, the SM2 algorithm is required to encrypt the SM4 key (Key) and the initialization vector (IV). In the SM2 algorithm, the communication parties generate public key and private key pairs respectively. The public key is used for encryption and signature verification, and the private key is used for decryption and signature. When encrypting, the public key of the other party is used for encryption. When decrypting, the private key of one's own is used for decryption. When signing, the private key of one's own is used for signing. When verifying the signature, the public key of the other party is used for signature verification.

[0062] When encrypting the SM4 key using the SM2 algorithm, a pair of SM2 public key and SM2 private key is generated. Usually, a point on the elliptic curve is used as the public key, and the private key is a random number. Among them, the process of generating a pair of public key and private key can be implemented using a cryptographic library, such as OpenSSL, Bouncy Castle, or the crypto library in Go language.

[0063] Use the SM2 public key to encrypt the SM4 key (Key) and the initialization vector (IV), encrypt the plaintext into ciphertext using the SM2 encryption algorithm, and the encryption process involves operations on points on the elliptic curve.

[0064] Implementing the embodiments of this application has the following effects:

[0065] This application uses a domestic encryption algorithm to encrypt the files transmitted from the cloud desktop, improving the file confidentiality when copying files from the cloud desktop to the physical machine.

[0066] Embodiment Two

[0067] Please refer to Figure 2 , a file decryption method based on the cloud desktop provided by the embodiments of this application, which is applied to the client. The client is installed on the physical machine, and the physical machine is communicatively connected to the cloud desktop. The method includes steps S201 - S202:

[0068] Step S201: After the client receives the encrypted target file sent by the cloud desktop, the encrypted target file is obtained by the cloud desktop in response to the operation of the target user copying the target file from the cloud desktop to the physical machine, and obtaining the target file and encrypting it;

[0069] In response to the decryption request of the target user initiated on the client, obtain the decryption application information according to the decryption request;

[0070] Step S202: Perform decryption approval on the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file.

[0071] Further, the performing decryption approval on the encrypted target file is specifically:

[0072] Determine the approval personnel information corresponding to the target user according to the domain control account organizational structure information;

[0073] If there is no approval personnel in the approval personnel information, the decryption approval of the encrypted target file passes;

[0074] If there is one or more approvers in the approver information, the decryption application information will be sent to the terminals of each approver for approval;

[0075] If all the approvers approve the decryption application information, the decryption approval of the encrypted target file is passed.

[0076] In this embodiment, the domain control account organization structure of the company is read to determine the approver information corresponding to the target user. Exemplarily, the domain control account organization structure of the company from top to bottom is: R & D director, development supervisor, and ordinary employee. That is, the superior of an ordinary employee is the development supervisor, and the superior of the development supervisor is the R & D director.

[0077] If the target user is an ordinary employee, the approver information corresponding to the target user is the R & D director and the development supervisor; it is required that both the R & D director and the development supervisor agree to the decryption application information of the target user, and the decryption approval of the encrypted target file is passed.

[0078] According to the convention, when there is more than one approver in the approver information, the approval is initiated in the order from bottom to top of the domain control account organization structure. When any one of the approvers does not agree to the application, there is no need for the superior approver to approve, and the approval process is terminated, directly determining that the decryption approval of the encrypted target file is not passed.

[0079] If the target user is a development supervisor, the approver information corresponding to the target user is the R & D director; it is required that the R & D director agrees to the decryption application information of the target user, and the decryption approval of the encrypted target file is passed.

[0080] If the target user is the R & D director, there is no approver in the approver information corresponding to the target user, and the decryption approval of the encrypted target file is directly passed.

[0081] Further, before decrypting the encrypted target file to obtain the target file, it further includes:

[0082] Link to the public server of the cloud desktop to obtain the SM2 private key of the physical machine and the SM4 symmetric key; the SM4 symmetric key includes: the SM4 key and the initialization vector.

[0083] Further, the decrypting the encrypted target file to obtain the target file is specifically:

[0084] According to the SM2 private key of the physical machine, decrypt the SM4 key and the initialization vector respectively to obtain the SM4 symmetric key;

[0085] Use the SM4 symmetric key to decrypt the encrypted target file to obtain the target file.

[0086] In this embodiment, the client decrypts the received encrypted SM4 key using its SM2 private key, thereby restoring the original SM4 symmetric key. The restored SM4 symmetric key is used to decrypt the file content, thereby restoring the original file data, and the decrypted content is saved to the local disk of the client.

[0087] In this embodiment, after obtaining the original target file, if the target user wants to send the target file externally, an approval for the external sending application needs to be initiated, and according to the domain control account organizational structure information, the approval personnel information corresponding to the target user is determined;

[0088] If there is no approval personnel in the approval personnel information, the external sending approval of the target file passes;

[0089] If there is one or more approval personnel in the approval personnel information, the external sending application information is sent to the terminals of each of the approval personnel for approval;

[0090] If all the approval personnel approve the decryption application information, the external sending approval of the target file passes.

[0091] Implementing the embodiments of the present application has the following effects:

[0092] The present application decrypts and approves the files obtained from the cloud desktop, and decrypts the files correspondingly after the decryption approval passes, improving the file confidentiality when obtaining the files copied from the cloud desktop.

[0093] Embodiment Three

[0094] Please refer to Figure 3 , a file encryption device based on a cloud desktop provided by an embodiment of the present application, which is applied to a cloud desktop. The cloud desktop is communicatively connected to a physical machine, and a client is installed on the physical machine. The device includes: an encryption module 301 and a sending module 302;

[0095] The encryption module is used to respond to the operation of the target user copying the target file from the cloud desktop to the physical machine, obtain the target file through the target coroutine, and encrypt the target file to obtain an encrypted target file;

[0096] The sending module is used to send the encrypted target file to the client, so that the client decrypts and approves the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, the encrypted target file is decrypted to obtain the target file; the decryption application information is obtained according to the decryption request of the target file initiated by the target user on the client.

[0097] The above-mentioned file encryption device based on a cloud desktop can implement the file encryption method based on a cloud desktop in the above method embodiment. The optional items in the above method embodiment are also applicable to this embodiment and will not be elaborated here. The remaining content of the embodiment of the present application can refer to the content of the above method embodiment and will not be repeated in this embodiment.

[0098] Embodiment 4

[0099] Please refer to Figure 4 , a file decryption device based on a cloud desktop provided by an embodiment of the present application, which is applied to a client. The client is installed on a physical machine, and the physical machine is communicatively connected to the cloud desktop. The device includes: an approval module 401 and a decryption module 402;

[0100] The approval module is configured to, after the client receives an encrypted target file sent by the cloud desktop, the encrypted target file is obtained by the cloud desktop in response to an operation of a target user copying a target file to the physical machine on the cloud desktop, and encrypting the target file;

[0101] In response to a decryption request for the target file initiated by the target user on the client, obtaining decryption application information according to the decryption request; performing decryption approval on the encrypted target file according to the decryption application information;

[0102] The decryption module is configured to, if the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file.

[0103] The above-mentioned file decryption device based on a cloud desktop can implement the file decryption method based on a cloud desktop in the second method embodiment. The optional items in the above method embodiment are also applicable to this embodiment and will not be elaborated here. The remaining content of the embodiment of the present application can refer to the content of the above method embodiment and will not be repeated in this embodiment.

[0104] Embodiment 5

[0105] Correspondingly, the present application further provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute a file encryption method based on a cloud desktop or a file decryption method based on a cloud desktop described in any one of the above embodiments.

[0106] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present application. The one or more modules / units may be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the terminal device.

[0107] The terminal device may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.

[0108] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device, and connects various parts of the entire terminal device through various interfaces and circuits.

[0109] The memory may be used to store the computer program and / or modules. The processor realizes various functions of the terminal device by running or executing the computer program and / or modules stored in the memory, and by calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the use of the mobile terminal, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0110] Among them, if the modules / units integrated in the terminal device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of this application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0111] The specific embodiments described above further elaborate on the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only the specific embodiments of this application and is not used to limit the protection scope of this application. In particular, it is pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application should be included in the protection scope of this application.

Claims

1. A file encryption method based on a cloud desktop, characterized in that, Applied to a cloud desktop, the cloud desktop is communicatively connected to a physical machine, and a client is installed on the physical machine. The method includes: In response to an operation by a target user to copy a target file from the cloud desktop to the physical machine, obtain the target file through a target coroutine, and encrypt the target file to obtain an encrypted target file; The encrypting the target file to obtain an encrypted target file specifically includes: calculating the target file using the SM4 encryption algorithm to generate an SM4 symmetric key; the SM4 symmetric key includes: an SM4 key and an initialization vector; encrypting the SM4 symmetric key using the SM2 encryption algorithm to respectively generate an SM2 public key of the cloud desktop and an SM2 private key of the physical machine to obtain an encrypted SM4 symmetric key; loading the target file into the memory in a file stream reading manner, and encrypting the target file according to the SM4 symmetric key and the encryption method of openssl to obtain an encrypted target file; Send the encrypted target file to the client so that the client decrypts and approves the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file; the decryption application information is obtained according to a decryption request for the target file initiated by the target user on the client; Before obtaining the target file, it further includes: detecting, through a target coroutine, an operation by the target user to copy the target file from the cloud desktop to the physical machine, and determining whether the copy of the target file is successful; if the copy of the target file fails, end the target coroutine; The detecting, by the target coroutine, an operation by the target user to copy the target file from the cloud desktop to the physical machine and determining whether the copy of the target file is successful includes: After the target user operates to copy the target file from the cloud desktop to the physical machine, start a go coroutine to detect whether the copy of the target file is successful. If the copy of the target file is successful, obtain the target file and encrypt the target file to obtain an encrypted target file; Before decrypting the encrypted target file to obtain the target file, it further includes: connecting to a public server of the cloud desktop to obtain the SM2 private key of the physical machine and the SM4 symmetric key; the SM4 symmetric key includes: an SM4 key and an initialization vector; The decrypting and approving the encrypted target file specifically includes: Determine the approval personnel information corresponding to the target user according to the domain control account organizational structure information; If there is no approval personnel in the approval personnel information, the decryption approval of the encrypted target file passes; If there is one or more approval personnel in the approval personnel information, send the decryption application information to the terminals of each of the approval personnel for approval; If all the approval personnel pass the approval of the decryption application information, the decryption approval of the encrypted target file passes.

2. A file decryption method based on a cloud desktop, characterized in that, Applied to a client, the client is installed on a physical machine, and the physical machine is communicatively connected to a cloud desktop. The method includes: After the client receives the encrypted target file sent by the cloud desktop, the encrypted target file is obtained by the cloud desktop in response to the operation of the target user copying the target file to the physical machine on the cloud desktop, obtaining the target file through the target coroutine, and encrypting the target file; In response to the decryption request of the target file initiated by the target user on the client, obtain the decryption application information according to the decryption request; Perform decryption approval on the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file Before decrypting the encrypted target file to obtain the target file, it further includes: connecting to the public server of the cloud desktop, obtaining the SM2 private key of the physical machine, and the SM4 symmetric key; the SM4 symmetric key includes: the SM4 key and the initialization vector; Decrypting the encrypted target file to obtain the target file specifically includes: decrypting the SM4 key and the initialization vector respectively according to the SM2 private key of the physical machine to obtain the SM4 symmetric key; using the SM4 symmetric key to decrypt the encrypted target file to obtain the target file; Before obtaining the target file, it further includes: detecting the operation of the target user copying the target file to the physical machine on the cloud desktop through the target coroutine, and determining whether the copying of the target file is successful; if the copying of the target file fails, end the target coroutine; The target coroutine detects the operation of the target user copying the target file to the physical machine on the cloud desktop, and determines whether the copying of the target file is successful, including: After the target user copies the target file to the physical machine on the cloud desktop, start a go coroutine to detect whether the copying of the target file is successful. If the copying of the target file is successful, obtain the target file and encrypt the target file to obtain the encrypted target file.

3. A file encryption device based on a cloud desktop, characterized in that, Applied to the cloud desktop, used to execute a file encryption method based on the cloud desktop as described in claim 1. The cloud desktop is communicatively connected to the physical machine, and a client is installed on the physical machine. The device includes: an encryption module and a sending module; The encryption module is used to obtain the target file through the target coroutine in response to the operation of the target user copying the target file to the physical machine on the cloud desktop, and encrypt the target file to obtain the encrypted target file; The sending module is used to send the encrypted target file to the client, so that the client performs decryption approval on the encrypted target file according to the decryption application information. If the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file; the decryption application information is obtained according to the decryption request of the target file initiated by the target user on the client.

4. A file decryption device based on a cloud desktop, characterized in that, Applied to the client, used to execute a file decryption method based on the cloud desktop as described in claim 2. The client is installed on the physical machine, and the physical machine is communicatively connected to the cloud desktop. The device includes: an approval module and a decryption module; The approval module is used to, after the client receives the encrypted target file sent by the cloud desktop, where the encrypted target file is obtained by the cloud desktop in response to the operation of the target user copying the target file to the physical machine on the cloud desktop, and obtaining the target file through the target coroutine and encrypting the target file; In response to the decryption request of the target file initiated by the target user on the client, obtaining decryption application information according to the decryption request; performing decryption approval on the encrypted target file according to the decryption application information; The decryption module is used to, if the decryption approval of the encrypted target file passes, decrypt the encrypted target file to obtain the target file.

5. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program; wherein, the computer program controls the device where the computer-readable storage medium is located to execute a file encryption method based on a cloud desktop as described in claim 1, or a file decryption method based on a cloud desktop as described in claim 2 when running.

Citation Information

Patent Citations

  • File transmission method, system and device, storage medium and electronic equipment

    CN116208428A

  • Firmware detection method and device, electronic equipment, storage medium and program product

    CN116501573A