A file encryption method, device and equipment based on quantum encryption and medium

Through the collaborative work between the client and the electronic document security management platform and the quantum cryptography service platform, the quantum key filling medium and working key are used to solve the problem of multi-client file data transmission and decryption in the existing technology, and realize secure file transmission and convenient decryption between multiple users.

CN119293823BActive Publication Date: 2025-10-10中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411461966.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-18
Publication Date
2025-10-10
Estimated Expiration
2044-10-18

AI Technical Summary

Technical Problem

Existing file encryption methods based on quantum random numbers cannot achieve secure transmission of file data between multiple clients and file decryption after distribution.

Method used

Through the collaborative work between the client, the electronic document security management platform and the quantum cryptography service platform, the quantum key is used to fill the medium and the working key to realize file encryption and decryption operations, ensuring the secure file transmission and decryption between multiple users.

Benefits of technology

It realizes secure file transfer and convenient decryption operations between multiple users, improving the security of electronic files and the convenience of decryption after encrypted file transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119293823B_ABST
    Figure CN119293823B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a file encryption method, device and equipment based on quantum encryption and a medium, comprising: when detecting an encryption operation of a user on a first target file, obtaining a first working key and corresponding key information, and encrypting the file; sending the encrypted first target file, the key information and corresponding file information to an electronic file security management platform; when detecting a decryption operation of the user on a second target file, sending a file viewing request to the electronic file security management platform, including the file information corresponding to the file; receiving the key information corresponding to the second target file sent by the platform, further obtaining a second working key, and decrypting the second target file. The electronic file security management platform is used as an intermediary to distribute quantum keys and files, ensuring that multiple users can safely and reliably distribute shared quantum keys, and improving the security of electronic files and the convenience of decryption operation after encrypted file transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum encryption technology, and in particular to a file encryption method based on quantum encryption, a file encryption device based on quantum encryption, an electronic device and a corresponding computer-readable storage medium. Background Art

[0002] With the advent of the era of comprehensive enterprise informatization, businesses are increasingly leveraging advanced technologies like computers and the internet to bring their operations and management processes online. All business data is processed systematically to rapidly generate the business intelligence required by management. Consequently, electronic files have become the primary storage method for enterprise information and a crucial vehicle for information exchange within and across the enterprise. As a crucial aspect of information security, the secure transmission and storage of electronic files is receiving increasing attention.

[0003] The file encryption and decryption method based on quantum random numbers is to use a quantum random number generator to generate a random number of a specified length as a key, use the key to encrypt the file to be encrypted, and store the key locally. Then, according to the specific identifier of the encrypted file, the locally stored key is found to perform decryption operations, thereby achieving secure encryption and decryption operations during file data transmission. However, this file encryption and decryption method based on quantum random numbers focuses more on encryption and decryption operations on a single client, and cannot achieve secure transmission of file data between multiple clients and decryption of files after distribution. Summary of the Invention

[0004] In view of the above problems, embodiments of the present invention are proposed to provide a file encryption method based on quantum encryption, a file encryption device based on quantum encryption, an electronic device and a corresponding computer-readable storage medium that overcome the above problems or at least partially solve the above problems.

[0005] In a first aspect, an embodiment of the present invention discloses a file encryption method based on quantum encryption, which is applied to a client. The method includes:

[0006] When detecting an encryption operation of the user on the first target file, obtaining a first working key and corresponding key information;

[0007] Encrypting the first target file using the first working key;

[0008] Sending the encrypted first target file, the key information, and file information corresponding to the first target file to the electronic file security management platform;

[0009] When a decryption operation of the user on the second target file is detected, a file viewing request is sent to the electronic file security management platform; the file viewing request includes file information corresponding to the second target file;

[0010] Receiving key information corresponding to the second target file sent by the electronic file security management platform;

[0011] A second working key is obtained according to the key information corresponding to the second target file, and the second target file is decrypted according to the second working key.

[0012] Optionally, the client includes a quantum key injection medium;

[0013] The obtaining of the first working key and corresponding key information includes:

[0014] Send a request to the quantum cryptography service platform to obtain the working key;

[0015] Receiving a first working key ciphertext and corresponding key information sent by the quantum cryptography service platform;

[0016] The first working key ciphertext is decrypted using the injection key in the quantum key injection medium to obtain the first working key.

[0017] Optionally, before sending the file viewing request to the electronic file security management platform, the method further includes:

[0018] Determining whether the user has viewing permission for the second target file;

[0019] The sending of a file viewing request to the electronic file security management platform includes:

[0020] If the user has viewing authority for the second target file, a file viewing request is sent to the electronic file security management platform.

[0021] Optionally, the key information corresponding to the second target file is sent by the electronic file security management platform after determining that the user has viewing authority for the second target file.

[0022] In a second aspect, an embodiment of the present invention provides a file encryption method based on quantum encryption, which is applied to an electronic file security management platform. The method includes:

[0023] Receiving the encrypted first target file, key information, and file information corresponding to the first target file sent by the client;

[0024] Establishing an association relationship between file information corresponding to the first target file and key information;

[0025] receiving a file viewing request for a second target file sent by the client, wherein the file viewing request includes file information corresponding to the second target file;

[0026] searching for key information corresponding to the second target file according to the file information corresponding to the second target file;

[0027] The key information corresponding to the second target file is sent to the client, so that the client obtains a second working key according to the key information corresponding to the second target file and decrypts the second target file according to the second working key.

[0028] Optionally, the file viewing request includes user information and identification information of the quantum key injection medium of the client;

[0029] The method further comprises:

[0030] Obtaining pre-established identity association information, the identity association information including an association between user information and identification information of a quantum key-filled medium;

[0031] Determining whether the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information;

[0032] The searching for key information corresponding to the second target file according to the file information corresponding to the second target file includes:

[0033] If the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information, the key information corresponding to the second target file is searched according to the file information corresponding to the second target file.

[0034] Optionally, it also includes:

[0035] Determining whether the user has viewing permission for the second target file;

[0036] The searching for key information corresponding to the second target file according to the file information corresponding to the second target file includes:

[0037] If the user has the viewing authority for the second target file, the key information corresponding to the second target file is searched according to the file information corresponding to the second target file.

[0038] In a third aspect, an embodiment of the present invention provides a file encryption system based on quantum encryption, including a client and an electronic file security management platform;

[0039] The client is configured to, when detecting a user's encryption operation on a first target file, obtain a first working key and corresponding key information; encrypt the first target file using the first working key; send the encrypted first target file, the key information, and file information corresponding to the first target file to an electronic file security management platform; when detecting a user's decryption operation on a second target file, send a file viewing request to the electronic file security management platform; the file viewing request includes file information corresponding to the second target file; receive key information corresponding to the second target file sent by the electronic file security management platform; obtain a second working key based on the key information corresponding to the second target file, and decrypt the second target file based on the second working key;

[0040] The electronic document security management platform is used to receive the encrypted first target file, key information and file information corresponding to the first target file sent by the client; establish an association relationship between the file information corresponding to the first target file and the key information; receive a file viewing request for a second target file sent by the client, the file viewing request including the file information corresponding to the second target file; search for the key information corresponding to the second target file based on the file information corresponding to the second target file; send the key information corresponding to the second target file to the client, so that the client obtains a second working key based on the key information corresponding to the second target file, and decrypts the second target file based on the second working key.

[0041] Optionally, it is characterized by further comprising: a quantum cryptography service platform; the client comprises a quantum key filling medium;

[0042] The client is configured to send a working key acquisition request to the quantum cryptography service platform; receive a first working key ciphertext and corresponding key information sent by the quantum cryptography service platform; and decrypt the first working key ciphertext using the injection key in the quantum key injection medium to obtain a first working key.

[0043] Optionally, the client is used to determine whether the user has viewing permission for the second target file before sending a file viewing request to the electronic file security management platform; if the user has viewing permission for the second target file, sending a file viewing request to the electronic file security management platform.

[0044] Optionally, the file viewing request includes user information and identification information of the quantum key injection medium of the client;

[0045] The electronic file security management platform is configured to obtain pre-established identity association information, the identity association information including an association between user information and identification information of a quantum key-filled medium; determine whether the user information in the file viewing request and the identification information of the quantum key-filled medium of the client match the identity association information; and if the user information in the file viewing request and the identification information of the quantum key-filled medium of the client match the identity association information, search for key information corresponding to the second target file based on file information corresponding to the second target file.

[0046] Optionally, the electronic document security management platform is used to determine whether the user has viewing permission for the second target file; if the user has viewing permission for the second target file, the key information corresponding to the second target file is searched based on the file information corresponding to the second target file.

[0047] In a fourth aspect, an embodiment of the present invention discloses a file encryption device based on quantum encryption, which is applied to a client and includes:

[0048] An acquisition module, configured to acquire a first working key and corresponding key information when an encryption operation of a user on a first target file is detected;

[0049] an encryption module, configured to encrypt the first target file using the first working key;

[0050] A first sending module, configured to send the encrypted first target file, the key information, and file information corresponding to the first target file to an electronic file security management platform;

[0051] A second sending module is configured to send a file viewing request to the electronic file security management platform when a decryption operation of a user on a second target file is detected; the file viewing request includes file information corresponding to the second target file;

[0052] A first receiving module, configured to receive key information corresponding to the second target file sent by the electronic file security management platform;

[0053] The decryption module is configured to obtain a second working key according to the key information corresponding to the second target file, and decrypt the second target file according to the second working key.

[0054] Optionally, the client includes a quantum key injection medium, and the acquisition module includes:

[0055] The first sending submodule is used to send a working key acquisition request to the quantum cryptography service platform;

[0056] A first receiving submodule is configured to receive a first working key ciphertext and corresponding key information sent by the quantum cryptography service platform;

[0057] The first decryption submodule is configured to decrypt the first working key ciphertext using the injection key in the quantum key injection medium to obtain a first working key.

[0058] Optionally, it also includes:

[0059] A first determining module, configured to determine whether the user has viewing authority for the second target file;

[0060] The second sending module includes:

[0061] The second sending submodule is configured to send a file viewing request to the electronic file security management platform if the user has viewing authority for the second target file.

[0062] Optionally, the key information corresponding to the second target file is sent by the electronic file security management platform after determining that the user has viewing authority for the second target file.

[0063] In a fifth aspect, an embodiment of the present invention discloses a file encryption device based on quantum encryption, which is applied to an electronic file security management platform, and includes:

[0064] A second receiving module is configured to receive the encrypted first target file, key information, and file information corresponding to the first target file sent by the client;

[0065] a relationship establishing module, configured to establish an association relationship between the file information corresponding to the first target file and the key information;

[0066] a third receiving module, configured to receive a file viewing request for a second target file sent by the client, wherein the file viewing request includes file information corresponding to the second target file;

[0067] A search module, configured to search for key information corresponding to the second target file based on file information corresponding to the second target file;

[0068] The third sending module is used to send key information corresponding to the second target file to the client, so that the client obtains a second working key according to the key information corresponding to the second target file and decrypts the second target file according to the second working key.

[0069] Optionally, the file viewing request includes user information and identification information of the quantum key injection medium of the client;

[0070] The third receiving module comprises:

[0071] The first obtaining sub-module is configured to obtain pre-established identity association information, wherein the identity association information comprises an association relationship between user information and identification information of a quantum key top-up medium.

[0072] The second determining sub-module is configured to determine whether the user information in the file viewing request and the identification information of the quantum key top-up medium of the client match the identity association information.

[0073] The searching module comprises:

[0074] The searching sub-module is configured to search for key information corresponding to the second target file according to file information corresponding to the second target file if the user information in the file viewing request and the identification information of the quantum key top-up medium of the client match the identity association information.

[0075] Optionally, the method further comprises:

[0076] The third determining sub-module is configured to determine whether the user has viewing permission for the second target file.

[0077] The searching sub-module comprises:

[0078] The searching unit is configured to search for key information corresponding to the second target file according to file information corresponding to the second target file if the user has viewing permission for the second target file.

[0079] In a sixth aspect, an embodiment of the present application discloses an electronic device, comprising a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of the file encryption method based on quantum encryption as described above.

[0080] In a seventh aspect, an embodiment of the present application discloses a computer readable storage medium, wherein a computer program is stored in the computer readable storage medium, and the computer program, when executed by a processor, implements the steps of the file encryption method based on quantum encryption as described above.

[0081] Embodiments of the present application have the following advantages:

[0082] The application introduces a quantum encryption file encryption method, device, equipment and medium, comprising: when detecting the encryption operation of a user on a first target file, obtaining a first working key and corresponding key information, and encrypting the first target file; sending the encrypted first target file, key information and corresponding file information to an electronic file security management platform; when detecting the decryption operation of a user on a second target file, sending a file viewing request to the electronic file security management platform, including the file information corresponding to the file; receiving the key information corresponding to the second target file sent by the platform, further obtaining a second working key, and decrypting the second target file. The method effectively distributes quantum keys, uses the electronic file security management platform as an intermediary to distribute quantum keys and files, is no longer limited to one-to-one file transmission between users, ensures that multiple users can safely and reliably distribute shared quantum keys, improves the security of electronic files, and improves the convenience of decryption operation after encrypted file transmission. BRIEF DESCRIPTION OF DRAWINGS

[0083] Figure 1 is a step flowchart of a quantum encryption-based file encryption method provided by an embodiment of the application;

[0084] Figure 2 is a step flowchart of another quantum encryption-based file encryption method provided by an embodiment of the application;

[0085] Figure 3 is a system schematic diagram of a quantum encryption-based file encryption method provided by an embodiment of the application;

[0086] Figure 4 is a quantum key charging flowchart of a quantum encryption-based file encryption method provided by an embodiment of the application;

[0087] Figure 5 is a working key application flowchart of a quantum encryption-based file encryption method provided by an embodiment of the application;

[0088] Figure 6 is a structure block diagram of a quantum encryption-based file encryption device provided by an embodiment of the application;

[0089] Figure 7 is a structure block diagram of another quantum encryption-based file encryption device provided by an embodiment of the application. DETAILED DESCRIPTION

[0090] In order to make the above-mentioned purposes, features and advantages of the application more obvious and easy to understand, the application will be further described in detail below with reference to the drawings and specific embodiments.

[0091] Quantum encryption technology refers to the use of quantum principles to perform a series of encryption technologies for file data transmission, including key generation, plaintext obfuscation encryption, and anti-eavesdropping.

[0092] One of the core concepts of the embodiments of the present invention is a file encryption system based on quantum cryptography, comprising an electronic file security management platform, a quantum cryptography service platform, a client, and a quantum key charging medium. A user logs in to the client, which then binds its identity to the quantum key charging medium. The quantum key charging medium then obtains a charging key and a working key from the quantum cryptography service platform. The working key is then encrypted and protected using the charging key. The file is then encrypted on the client, implementing the file encryption operation. When another user submits a file viewing request, the electronic file security management platform's permission policy module checks the user's decryption permissions and obtains the file's corresponding working key information. The user's corresponding quantum key charging medium then retrieves the corresponding working key from the quantum cryptography service platform based on the working key information, implementing the file decryption operation. This facilitates file transfer and distribution between multiple users.

[0093] Reference Figure 1 , shows a flowchart of a file encryption method based on quantum encryption provided by an embodiment of the present invention. The method may specifically include the following steps:

[0094] Step 101: When a user's encryption operation on a first target file is detected, a first working key and corresponding key information are obtained;

[0095] In this embodiment, the working key is a pair of symmetric keys provided by the quantum cryptography service platform and used to encrypt files and protect the confidentiality and integrity of file data. The first working key here refers to the working key used by the sender of the file to encrypt the target file through the encryption and decryption client, and the key information refers to the filling key and other related information required to decrypt the working key. In one embodiment, the working key can be generated by a quantum random number generator (QRNG), a device that uses the principles of quantum mechanics to generate truly random numbers. Unlike traditional pseudo-random number generators (PRNGs), the random numbers generated by QRNGs are based on physical processes and are therefore more unpredictable and secure.

[0096] The client includes a quantum key charging medium; the quantum key charging medium refers to a secure medium with a built-in secure zone storage area, and the area can only be read and written normally after the identity authentication of the password is passed. By utilizing the characteristics of the secure storage area, management operations such as charging, encryption, writing, and reading of quantum keys are realized. Charging key: a symmetric key provided by the quantum cryptography service platform and written into the key space of the secure medium (key charging). The charging key serves as the terminal master key and is used for terminal identity authentication between the secure medium and the quantum cryptography service platform, encrypted distribution of the working key, and encryption protection of the working key. In this embodiment, the quantum key charging medium can be a quantum security Ukey, which can be inserted into a PC (personal computer) to read the charging key therein.

[0097] In one embodiment, step 101 may include the following sub-steps:

[0098] Sub-step S11, sending a working key acquisition request to the quantum cryptography service platform;

[0099] The quantum cryptography service platform provides full lifecycle management of quantum keys, including key generation, key storage, key injection, key usage, and key destruction. Clients who want to encrypt or decrypt files must first apply for a key through the quantum cryptography service platform.

[0100] Sub-step S12, receiving the first working key ciphertext and corresponding key information sent by the quantum cryptography service platform;

[0101] After the client sends a key request to the quantum cryptography service platform, the quantum cryptography service platform responds to the request. The client receives the working key for encrypting the target file from the quantum cryptography service platform, as well as the charging key and key identity information corresponding to the decryption of the working key ciphertext, in order to decrypt the corresponding working key.

[0102] Sub-step S13: decrypting the first working key ciphertext using the injection key in the quantum key injection medium to obtain the first working key.

[0103] Before obtaining a working key to encrypt and decrypt the target file, a key charging system is required to protect the working key required for subsequent encryption and decryption, ensuring secure file transmission and authenticating the identities of both parties against man-in-the-middle attacks. The charging key is encapsulated in a digital envelope when issued, ensuring secure transmission and storage of the charging key. Before file transmission, the charging key can be obtained through a quantum key charging medium to protect the working key. After the user confirms their identity using the charging key and their identity information, the first working key ciphertext is decrypted to obtain the working key plaintext, thereby improving the overall security of the system.

[0104] Step 102: Encrypt the first target file using the first working key;

[0105] The target file to be transmitted is encrypted using the first working key obtained from the quantum cryptography service platform. The subsequent recipient decrypts the target file using the second working key that is symmetric to the first working key, thereby achieving secure transmission of the target file.

[0106] Step 103: Send the encrypted first target file, the key information, and file information corresponding to the first target file to the electronic file security management platform;

[0107] In addition to sending the target file to be transferred to the electronic document security management platform, the client also sends the key information and file information required to decrypt the target file. This ensures that the recipient can accurately locate the desired file and the corresponding decryption key. The key information refers to the working key ID (usually a unique identifier on the network, such as an ID card, username, or account number) and the corresponding charging key ID. The file information corresponding to the first target file refers to the file ID of the encrypted target file.

[0108] Step 104: When a decryption operation of the user on the second target file is detected, a file viewing request is sent to the electronic file security management platform; the file viewing request includes file information corresponding to the second target file;

[0109] Once the target file, related file information, and key information are sent to the file security management platform, anyone who meets the required permissions and passes verification can apply to the platform to view and receive the file. This file access refers not only to the target file itself, but also to its corresponding file ID. The file security management platform can manage multiple files, and using file IDs can accurately locate the target file, improving the efficiency and accuracy of file transfers between multiple users.

[0110] Before sending the file viewing request to the electronic file security management platform, the method further includes:

[0111] In one embodiment, step 104 may include the following sub-steps:

[0112] Sub-step S21, determining whether the user has viewing authority for the second target file;

[0113] To improve file transfer security and prevent file leaks caused by someone accidentally picking up a Quantum Security UKey and accessing the key, the electronic file security management platform also verifies the user's identity to determine whether they have permission to view the target file. The electronic file security management platform's permission policy management module verifies the user's document decryption permissions. Only after successful verification can the user continue to receive the working key and view the file.

[0114] Sub-step S22: If the user has viewing authority for the second target file, a file viewing request is sent to the electronic file security management platform.

[0115] The electronic document management platform establishes user groups. Users in the same user group have the same permissions. For example, user A and user B are in the same group, and user A and B can view each other's files. Users who are not in the same group need to manually assign permissions. For example, user C and user A are not in the same group. User C needs to view A's encrypted files, and the electronic document management platform needs to manually assign permissions. After the assignment, user C is assigned the permission to view the encrypted documents generated by user A. User C has the permission to view the encrypted documents generated by user A. The permission policy can be stored on the platform server or distributed to each encryption and decryption client.

[0116] After the user passes the verification of the electronic file security management platform and is confirmed to have viewing authority, he / she sends a file viewing request to the electronic file security management platform, requesting to view the target file, as well as the corresponding file ID and key information, so as to subsequently decrypt the target file and receive it.

[0117] Step 105: receiving key information corresponding to the second target file sent by the electronic file security management platform;

[0118] Receive and send a request to view the file to the electronic document security management system (if the permission policy is on the client at this time, there is no need to check the permission on the server, and the permission can be viewed on the recipient's client); the electronic document security management system needs to detect whether the recipient has the decryption permission to the file (if the permission policy is on the client, the client can also check it by itself); if the recipient has the decryption permission to the file, the electronic document management platform will send the work key ID corresponding to the file to the recipient.

[0119] In one embodiment, the key information corresponding to the second target file is sent by the electronic file security management platform after determining that the user has viewing authority for the second target file.

[0120] Step 106: Obtain a second working key according to the key information corresponding to the second target file, and decrypt the second target file according to the second working key.

[0121] After the receiving user obtains the file ciphertext, he logs in to the encryption and decryption client with his user ID and inserts the quantum security Ukey bound to the user on the PC. The quantum security Ukey uses the charging key to decrypt the working key ciphertext corresponding to the working key ID received from the quantum cryptography service platform and obtain the working key plaintext. The client uses the working key plaintext of the quantum security Ukey to complete the file decryption operation.

[0122] The embodiment of the present invention is applied to the client. When a user's encryption operation for a first target file is detected, the first working key and corresponding key information are obtained to encrypt the first target file; the encrypted first target file, key information and corresponding file information are sent to the electronic file security management platform; when a user's decryption operation for a second target file is detected, a file viewing request is sent to the electronic file security management platform, including the file information corresponding to the file; the key information corresponding to the second target file sent by the receiving platform is further obtained, and the second working key is decrypted. The method effectively distributes quantum keys and uses the electronic file security management platform as an intermediary to distribute quantum keys and files. It is no longer limited to file transfers between one-to-one users, ensuring that multiple users can safely and reliably distribute to shared quantum keys, thereby improving the security of electronic files and the convenience of decryption operations after encrypted file transfers.

[0123] Reference Figure 2 , shows a flowchart of another file encryption method based on quantum encryption provided by an embodiment of the present invention, the method may specifically include the following steps:

[0124] Step 201: receiving an encrypted first target file, key information, and file information corresponding to the first target file from a client;

[0125] Generally, the key for encrypting and decrypting files based on quantum keys is stored locally, and then the locally stored key is found according to the specific identifier of the encrypted file for decryption operation, so as to realize secure encryption and decryption operations during file data transmission. However, this file encryption and decryption method based on quantum random numbers focuses more on the encryption and decryption operations of a single client, and cannot realize the secure transmission of file data between multiple clients and the decryption of files after distribution.

[0126] The embodiment of the present invention sends the key information, target file and file information to the electronic file security management platform for processing. In this way, as long as the corresponding working key can be applied for through identity authentication, the file can be applied for on the file management platform first, and the file can be transferred conveniently and securely between multiple users.

[0127] Step 202: establishing an association relationship between the file information corresponding to the first target file and the key information;

[0128] The file information corresponding to the first target file is the file ID of the file, and the key information is the key ID corresponding to the working key. The sender's quantum security Ukey uses the built-in charging key to apply for a working key from the quantum cryptography service platform. The quantum cryptography service platform returns the key ID and working key ciphertext. The sender's encryption client sends the encrypted document ID and the corresponding working key ID to the electronic document security management platform. The electronic document security management platform establishes an association between the target file ID and the working key ID and maintains a data table of the association. This facilitates the electronic document security management platform's authorization verification of the receiving user and enables the recipient to accurately locate the target file, improving the security and convenience of file transfers.

[0129] Step 203: receiving a file viewing request for a second target file sent by the client, wherein the file viewing request includes file information corresponding to the second target file;

[0130] In one embodiment, the file viewing request includes user information and identification information of the quantum key injection medium of the client;

[0131] The electronic document security management platform is responsible for managing multiple groups of files. If the recipient wants to receive the target file, he or she needs to obtain the file information of the target file, namely the file ID, and also needs to obtain the working key for decrypting the file. The working key is protected by the injection key for transmission. Therefore, the recipient also needs to apply to view the injection key carried by the quantum key injection medium, namely the quantum security Ukey, and verify the identity of the client's quantum security Ukey for security reasons.

[0132] The step 203 may include the following sub-steps:

[0133] Sub-step S31, obtaining pre-established identity association information, wherein the identity association information includes an association relationship between user information and identification information of a quantum key-filled medium;

[0134] During the file encryption process, the electronic file security management platform establishes an association between user information and the identification information of the quantum key charging medium, that is, the identity association information between the encrypted client user ID and the quantum security Ukey.

[0135] Sub-step S32, determining whether the user information in the file viewing request and the identification information of the quantum key charging medium of the client match the identity association information;

[0136] The recipient logs in to the encryption client with the user ID and inserts the quantum security Ukey on the PC. Only when the recipient's user ID and the inserted quantum security Ukey are bound, the identification information of the client's quantum key filling medium matches the identity association information and passes the verification; otherwise, it does not match and the viewing request cannot be passed.

[0137] Step 204: searching for key information corresponding to the second target file based on the file information corresponding to the second target file;

[0138] Since the file ID and key ID have been linked in the electronic file security management platform, the user obtains the working key ID corresponding to the target file based on the received target file ID, and decrypts the working key ciphertext using the injection key in the quantum security Uke to obtain the working key ciphertext that can decrypt the target file.

[0139] In one embodiment, step 204 may include the following sub-steps:

[0140] If the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information, the key information corresponding to the second target file is searched according to the file information corresponding to the second target file.

[0141] If the user's client ID and Quantum Security Ukey are bound and associated with the identity, then if the information matches, the corresponding key ID and working key ciphertext can be found based on the second target file information that needs to be received.

[0142] In another embodiment, step 204 may further include the following sub-steps:

[0143] Sub-step S41, determining whether the user has viewing authority for the second target file;

[0144] If the receiving user and the sending user are in the same group and have the same permissions, the receiving user in the same group can directly submit a file viewing request, receive the target file, and decrypt it without going through permission verification on the electronic document security management platform. Alternatively, if users are not in the same group, permissions can be manually assigned. For example, if user C and user A are not in the same group and user C needs to view A's encrypted file, the electronic document management platform will manually assign permissions. After the assignment, user C will be assigned permission to view the encrypted document generated by user A. User C will then have permission to view the encrypted document generated by user A.

[0145] Sub-step S42: if the user has the viewing authority for the second target file, searching for key information corresponding to the second target file according to the file information corresponding to the second target file.

[0146] Receive and send a request to view the file to the electronic document security management system (if the permission policy is on the client at this time, there is no need to check the permission on the server, and the permission can be viewed on the recipient's client); the electronic document security management system needs to detect whether the recipient has the decryption permission to the file (if the permission policy is on the client, the client can also check it by itself); if the recipient has the decryption permission to the file, the electronic document management platform will send the work key ID corresponding to the file to the recipient.

[0147] Step 205: Send key information corresponding to the second target file to the client, so that the client obtains a second working key according to the key information corresponding to the second target file and decrypts the second target file according to the second working key.

[0148] The quantum cryptography service platform returns the working key ID corresponding to the working key ciphertext. The quantum security Ukey uses the charging key to decrypt it and obtain the working key plaintext; the decryption client uses the quantum security Ukey working key to complete the file decryption operation.

[0149] The embodiment of the present invention is applied to an electronic file security management platform, which receives an encrypted first target file, key information, and file information corresponding to the first target file sent by a client; establishes an association between the file information corresponding to the first target file and the key information; receives a file viewing request for a second target file sent by a client, including the file information corresponding to the second target file; searches for the key information corresponding to the second target file based on the file information corresponding to the second target file; sends the key information corresponding to the second target file to the client, so that the client obtains a second working key based on the key information corresponding to the second target file, and decrypts the second target file based on the second working key. This method effectively distributes quantum keys, uses the electronic file security management platform as an intermediary to distribute quantum keys and files, is no longer limited to one-to-one file transfers between users, ensures that multiple users can safely and reliably distribute to shared quantum keys, improves the security of electronic files, and improves the convenience of decryption operations after encrypted file transfers.

[0150] The embodiment of the present invention also discloses a file encryption system based on quantum encryption, which is characterized by comprising a client and an electronic file security management platform;

[0151] The client is configured to, when detecting a user's encryption operation on a first target file, obtain a first working key and corresponding key information; encrypt the first target file using the first working key; send the encrypted first target file, the key information, and file information corresponding to the first target file to an electronic file security management platform; when detecting a user's decryption operation on a second target file, send a file viewing request to the electronic file security management platform; the file viewing request includes file information corresponding to the second target file; receive key information corresponding to the second target file sent by the electronic file security management platform; obtain a second working key based on the key information corresponding to the second target file, and decrypt the second target file based on the second working key;

[0152] The electronic document security management platform is used to receive the encrypted first target file, key information and file information corresponding to the first target file sent by the client; establish an association relationship between the file information corresponding to the first target file and the key information; receive a file viewing request for a second target file sent by the client, the file viewing request including the file information corresponding to the second target file; search for the key information corresponding to the second target file based on the file information corresponding to the second target file; send the key information corresponding to the second target file to the client, so that the client obtains a second working key based on the key information corresponding to the second target file, and decrypts the second target file based on the second working key.

[0153] Furthermore, the client is used to determine whether the user has viewing permission for the second target file before sending a file viewing request to the electronic file security management platform; if the user has viewing permission for the second target file, then send a file viewing request to the electronic file security management platform.

[0154] In one embodiment of the present invention, the file viewing request includes user information and identification information of the quantum key injection medium of the client;

[0155] The electronic file security management platform is configured to obtain pre-established identity association information, the identity association information including an association relationship between user information and identification information of a quantum key-filled medium; determine whether the user information in the file viewing request and the identification information of the quantum key-filled medium of the client match the identity association information; and if the user information in the file viewing request and the identification information of the quantum key-filled medium of the client match the identity association information, search for key information corresponding to the second target file based on file information corresponding to the second target file.

[0156] Further, the electronic file security management platform is configured to determine whether the user has the viewing permission for the second target file, and if the user has the viewing permission for the second target file, search for the key information corresponding to the second target file according to the file information corresponding to the second target file.

[0157] In an embodiment of the present application, the client further comprises a quantum key charging medium, and the quantum key service platform further comprises a quantum key charging medium.

[0158] The client is configured to send a working key acquisition request to the quantum key service platform, receive the first working key ciphertext and the corresponding key information sent by the quantum key service platform, and decrypt the first working key ciphertext by using the charging key in the quantum key charging medium to obtain the first working key.

[0159] The present application discloses a quantum encryption file encryption system, which comprises a client and an electronic file security management platform. When detecting an encryption operation of a user on a first target file, a first working key and corresponding key information are acquired, and the first target file is encrypted. The encrypted first target file, the key information and corresponding file information are sent to the electronic file security management platform. When detecting a decryption operation of a user on a second target file, a file viewing request is sent to the electronic file security management platform, including the file information corresponding to the file. The key information corresponding to the second target file sent by the platform is received, and a second working key is further acquired to decrypt the second target file. The method can effectively allocate quantum keys, ensure that multiple users can safely and reliably distribute shared quantum keys, and use the quantum keys allocated by the method to encrypt and decrypt files, which not only effectively improves the security of electronic files, but also significantly improves the convenience of decryption operation after encrypted file transmission, thereby bringing great security and operation efficiency advantages to the field of electronic file management.

[0160] Referring to Figure 3 , a system architecture diagram of a quantum encryption file encryption method provided by an embodiment of the present application is shown, and the method can specifically include the following steps:

[0161] The quantum security Ukey applies for a charging key from the quantum cryptography service platform. When the charging key is issued, it is encapsulated in a digital envelope to protect the transmission and storage security of the charging key; the electronic document security management platform establishes identity association information between the client user ID and the quantum security Ukey; the sender logs in to the encryption client through the user ID, inserts the quantum security Ukey bound to the user on the PC, and selects a file to be encrypted; the sender's quantum security Ukey applies for a working key from the quantum cryptography service platform through the built-in charging key. The quantum cryptography service platform returns the key ID and working key ciphertext. The quantum security Ukey uses the charging key to decrypt and obtain the working key plaintext. The encryption client uses the quantum security Ukey's working key to complete the file encryption operation; the client sends the encrypted document ID and the corresponding key ID to the electronic document security management platform, and the electronic document security management platform establishes an association between the document ID and the working key.

[0162] After the receiving user obtains the file ciphertext, he logs in to the encryption client with his user ID, inserts the quantum security Ukey bound to the user on the PC, and sends a file viewing request to the electronic document security management platform; the permission policy management module of the electronic document security management platform verifies the user's document viewing permission. If the verification is successful, the recipient obtains the working key ID corresponding to the document; the recipient's quantum security Ukey applies for the working key from the quantum cryptography service platform through the built-in charging key and working key ID. The quantum cryptography service platform returns the working key ciphertext corresponding to the working key ID. The quantum security Ukey uses the charging key to decrypt and obtain the working key plaintext. The encryption client uses the working key of the quantum security Ukey to complete the file decryption operation.

[0163] Reference Figure 4 , shows a quantum key injection flow chart of a file encryption method based on quantum encryption provided by an embodiment of the present invention, which is specifically described as follows:

[0164] The Quantum Security Ukey is inserted into the charging terminal. The Quantum Cryptography Service Platform checks the charging terminal's registration information to prevent unauthorized use. After identity authentication, the charging terminal initiates a charging key request. The charging key is encapsulated in a digital envelope when it is issued, protecting its transmission and storage security. The charging key is then written to the Quantum Security Ukey's secure storage area.

[0165] Reference Figure 5 , shows a working key application flow chart of a file encryption method based on quantum encryption provided by an embodiment of the present invention, which is specifically described as follows:

[0166] The electronic document security management platform establishes identity association information between the encryption client user ID and the quantum security Ukey; the sender logs in to the encryption client using the user ID, inserts the quantum security Ukey bound to the user on the PC, and selects a file to encrypt; the sender's quantum security Ukey applies for a working key from the quantum cryptography service platform using the built-in charging key. The quantum cryptography service platform returns the key ID and working key ciphertext, which the quantum security Ukey decrypts using the charging key to obtain the working key plaintext; the encryption client uses the quantum security Ukey's working key to complete the file encryption operation.

[0167] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0168] Reference Figure 6 , shows a structural block diagram of a file encryption device based on quantum encryption provided by an embodiment of the present invention, which may specifically include the following modules:

[0169] An acquisition module 601 is configured to acquire a first working key and corresponding key information when an encryption operation of a user on a first target file is detected;

[0170] An encryption module 602 is configured to encrypt the first target file using the first working key;

[0171] A first sending module 603 is configured to send the encrypted first target file, the key information, and file information corresponding to the first target file to the electronic file security management platform;

[0172] The second sending module 604 is configured to send a file viewing request to the electronic file security management platform when a decryption operation of the user on the second target file is detected; the file viewing request includes file information corresponding to the second target file;

[0173] A first receiving module 605 is configured to receive key information corresponding to the second target file sent by the electronic file security management platform;

[0174] The decryption module 606 is configured to obtain a second working key according to the key information corresponding to the second target file, and decrypt the second target file according to the second working key.

[0175] In the embodiment of the present application, the client comprises a quantum key charging medium, and the acquisition module comprises:

[0176] The first sending sub-module is configured to send a working key acquisition request to the quantum cryptography service platform.

[0177] The first receiving sub-module is configured to receive the first working key ciphertext and the corresponding key information sent by the quantum cryptography service platform.

[0178] The first decryption sub-module is configured to decrypt the first working key ciphertext by using the charging key in the quantum key charging medium to obtain the first working key.

[0179] In the embodiment of the present application, the method further comprises:

[0180] The first determining module is configured to determine whether the user has the viewing permission for the second target file.

[0181] The second sending module comprises:

[0182] The second sending sub-module is configured to send a file viewing request to the electronic file security management platform if the user has the viewing permission for the second target file.

[0183] In the embodiment of the present application, the key information corresponding to the second target file is sent by the electronic file security management platform after determining that the user has the viewing permission for the second target file.

[0184] The present application discloses a quantum encryption file encryption device, which acquires a first working key and corresponding key information when detecting an encryption operation of a user on a first target file, encrypts the first target file, sends the encrypted first target file, the key information and corresponding file information to an electronic file security management platform, sends a file viewing request to the electronic file security management platform when detecting a decryption operation of the user on a second target file, receives the key information corresponding to the second target file sent by the platform, further acquires a second working key and decrypts the second target file. The method can effectively allocate quantum keys, ensure that multiple users can safely and reliably distribute shared quantum keys, and use the method to encrypt and decrypt files by using the quantum keys allocated by the electronic file security management platform, thereby effectively improving the security of electronic files and significantly improving the convenience of decryption operation after encrypted file transmission, thereby bringing great security and operation efficiency advantages to the field of electronic file management.

[0185] Reference Figure 7, shows a structural block diagram of another file encryption device based on quantum encryption provided by an embodiment of the present invention, which may specifically include the following modules:

[0186] The second receiving module 701 is configured to receive the encrypted first target file, key information, and file information corresponding to the first target file sent by the client;

[0187] A relationship establishing module 702 is configured to establish an association relationship between the file information corresponding to the first target file and the key information;

[0188] A third receiving module 703 is configured to receive a file viewing request for a second target file sent by the client, wherein the file viewing request includes file information corresponding to the second target file;

[0189] A search module 704 is configured to search for key information corresponding to the second target file based on the file information corresponding to the second target file;

[0190] The third sending module 705 is configured to send key information corresponding to the second target file to the client, so that the client obtains a second working key according to the key information corresponding to the second target file and decrypts the second target file according to the second working key.

[0191] In an embodiment of the present invention, the file viewing request includes user information and identification information of the quantum key injection medium of the client; the third receiving module includes:

[0192] A first acquisition submodule is configured to acquire pre-established identity association information, wherein the identity association information includes an association relationship between user information and identification information of a quantum key-filled medium;

[0193] a second determining submodule, configured to determine whether the user information in the file viewing request and the identification information of the quantum key charging medium of the client match the identity association information;

[0194] In an embodiment of the present invention, the search module includes:

[0195] a search submodule, configured to search for key information corresponding to the second target file based on file information corresponding to the second target file if the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information.

[0196] In the embodiment of the present invention, it also includes:

[0197] A third determining submodule, configured to determine whether the user has viewing authority for the second target file;

[0198] The search submodules include:

[0199] A searching unit is configured to search for key information corresponding to the second target file based on file information corresponding to the second target file if the user has viewing authority for the second target file.

[0200] The present invention discloses a file encryption device using quantum encryption, which receives an encrypted first target file, key information, and file information corresponding to the first target file sent by a client; establishes an association between the file information corresponding to the first target file and the key information; receives a file viewing request for a second target file sent by a client, including the file information corresponding to the second target file; searches for the key information corresponding to the second target file based on the file information corresponding to the second target file; sends the key information corresponding to the second target file to the client, so that the client obtains a second working key based on the key information corresponding to the second target file, and decrypts the second target file based on the second working key. This method can effectively distribute quantum keys, ensuring that multiple users can safely and reliably distribute to shared quantum keys. Using this method to encrypt and decrypt files using quantum keys distributed through an electronic file security management platform not only effectively improves the security of electronic files, but also significantly improves the convenience of decryption operations after encrypted file transmission, thereby bringing significant security and operational efficiency advantages to the field of electronic file management.

[0201] As for the system and device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0202] An embodiment of the present invention also provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned quantum encryption-based file encryption method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0203] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned file encryption method embodiment based on quantum encryption are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0204] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0205] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, apparatus, or computer program product. Accordingly, embodiments of the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer program instructions.

[0206] Embodiments of the present application are described herein with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing terminal apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0207] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing terminal apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0208] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal apparatus to cause a series of operational steps to be performed on the computer or other programmable terminal apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable terminal apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0209] While preferred embodiments of the present application have been described, additional variations and modifications can be made to these embodiments by those skilled in the art once they learn of the basic inventive concepts. Therefore, the appended claims are intended to cover all such modifications and variations as fall within the scope of the present application.

[0210] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0211] The above is a detailed introduction to a file encryption method based on quantum encryption, a file encryption device, system, equipment and medium based on quantum encryption provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A file encryption method based on quantum encryption, characterized in that: Applied to a client, the method includes: When detecting an encryption operation of the user on the first target file, obtaining a first working key and corresponding key information; Encrypting the first target file using the first working key; Sending the encrypted first target file, the key information, and file information corresponding to the first target file to the electronic file security management platform; When a decryption operation of the user on the second target file is detected, a file viewing request is sent to the electronic file security management platform; the file viewing request includes file information corresponding to the second target file; Receiving key information corresponding to the second target file sent by the electronic file security management platform; Obtaining a second working key according to the key information corresponding to the second target file, and decrypting the second target file according to the second working key; Wherein, the client includes a quantum key injection medium; The obtaining of the first working key and corresponding key information includes: Send a request to the quantum cryptography service platform to obtain the working key; Receiving a first working key ciphertext and corresponding key information sent by the quantum cryptography service platform; The first working key ciphertext is decrypted using the injection key in the quantum key injection medium to obtain the first working key.

2. The method according to claim 1, characterized in that Before sending the file viewing request to the electronic file security management platform, the method further includes: Determining whether the user has viewing permission for the second target file; The sending of a file viewing request to the electronic file security management platform includes: If the user has viewing authority for the second target file, a file viewing request is sent to the electronic file security management platform.

3. The method according to claim 1, characterized in that The key information corresponding to the second target file is sent by the electronic file security management platform after determining that the user has the viewing authority for the second target file.

4. A file encryption method based on quantum encryption, characterized in that: Applied to an electronic document security management platform, the method includes: Receiving the encrypted first target file, key information, and file information corresponding to the first target file sent by the client; Establishing an association relationship between file information corresponding to the first target file and key information; receiving a file viewing request for a second target file sent by the client, wherein the file viewing request includes file information corresponding to the second target file; searching for key information corresponding to the second target file according to the file information corresponding to the second target file; Sending key information corresponding to the second target file to the client, so that the client obtains a second working key according to the key information corresponding to the second target file and decrypts the second target file according to the second working key; The file viewing request includes user information and identification information of the quantum key injection medium of the client; The method further comprises: Obtaining pre-established identity association information, the identity association information including an association between user information and identification information of a quantum key-filled medium; Determining whether the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information; The searching for key information corresponding to the second target file according to the file information corresponding to the second target file includes: If the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information, the key information corresponding to the second target file is searched according to the file information corresponding to the second target file.

5. The method according to claim 4, characterized in that Also includes: Determining whether the user has viewing permission for the second target file; The searching for key information corresponding to the second target file according to the file information corresponding to the second target file includes: If the user has the viewing authority for the second target file, the key information corresponding to the second target file is searched according to the file information corresponding to the second target file.

6. A file encryption system based on quantum encryption, characterized in that: It includes a client, an electronic document security management platform and a quantum cryptography service platform; the client includes a quantum key filling medium; The client is configured to obtain a first working key and corresponding key information when detecting an encryption operation of a user on a first target file; and encrypt the first target file using the first working key; sending the encrypted first target file, the key information, and the file information corresponding to the first target file to an electronic file security management platform; when detecting a user's decryption operation on a second target file, sending a file viewing request to the electronic file security management platform; the file viewing request includes the file information corresponding to the second target file; receiving the key information corresponding to the second target file sent by the electronic file security management platform; obtaining a second working key based on the key information corresponding to the second target file, and decrypting the second target file based on the second working key; The electronic file security management platform is configured to receive the encrypted first target file, key information, and file information corresponding to the first target file sent by the client; and establish an association between the file information corresponding to the first target file and the key information; receiving a file viewing request for a second target file sent by the client, the file viewing request including user information, identification information of a quantum key-charged medium of the client, and file information corresponding to the second target file; searching for key information corresponding to the second target file based on the file information corresponding to the second target file; and sending the key information corresponding to the second target file to the client, so that the client obtains a second working key based on the key information corresponding to the second target file, and decrypts the second target file based on the second working key; The client is used to send a working key acquisition request to the quantum cryptography service platform; receiving a first working key ciphertext and corresponding key information sent by the quantum cryptography service platform; decrypting the first working key ciphertext using the injection key in the quantum key injection medium to obtain a first working key; The electronic file security management platform is configured to obtain pre-established identity association information, the identity association information including an association between user information and identification information of a quantum key-filled medium; determine whether the user information in the file viewing request and the identification information of the quantum key-filled medium of the client match the identity association information; and if the user information in the file viewing request and the identification information of the quantum key-filled medium of the client match the identity association information, search for key information corresponding to the second target file based on file information corresponding to the second target file.

7. The system according to claim 6, characterized in that The client is used to determine whether the user has viewing permission for the second target file before sending a file viewing request to the electronic file security management platform; if the user has viewing permission for the second target file, then send a file viewing request to the electronic file security management platform.

8. The system according to claim 6, wherein: The electronic document security management platform is used to determine whether the user has viewing authority for the second target file; if the user has viewing authority for the second target file, the key information corresponding to the second target file is searched based on the file information corresponding to the second target file.

9. A file encryption device based on quantum encryption, characterized in that: The device is applied to a client, and includes: An acquisition module, configured to acquire a first working key and corresponding key information when an encryption operation of a user on a first target file is detected; an encryption module, configured to encrypt the first target file using the first working key; A first sending module, configured to send the encrypted first target file, the key information, and file information corresponding to the first target file to an electronic file security management platform; A second sending module is configured to send a file viewing request to the electronic file security management platform when a decryption operation of the user on the second target file is detected; the file viewing request includes file information corresponding to the second target file; A first receiving module, configured to receive key information corresponding to the second target file sent by the electronic file security management platform; a decryption module, configured to obtain a second working key according to the key information corresponding to the second target file, and decrypt the second target file according to the second working key; The client includes a quantum key injection medium, and the acquisition module includes: The first sending submodule is used to send a working key acquisition request to the quantum cryptography service platform; A first receiving submodule is configured to receive a first working key ciphertext and corresponding key information sent by the quantum cryptography service platform; The first decryption submodule is configured to decrypt the first working key ciphertext using the injection key in the quantum key injection medium to obtain a first working key.

10. A file encryption device based on quantum encryption, characterized in that: The device is applied to an electronic document security management platform, and comprises: A second receiving module is configured to receive the encrypted first target file, key information, and file information corresponding to the first target file sent by the client; a relationship establishing module, configured to establish an association relationship between the file information corresponding to the first target file and the key information; a third receiving module, configured to receive a file viewing request for a second target file sent by the client, wherein the file viewing request includes file information corresponding to the second target file; A search module, configured to search for key information corresponding to the second target file based on file information corresponding to the second target file; a third sending module, configured to send key information corresponding to the second target file to the client, so that the client obtains a second working key according to the key information corresponding to the second target file, and decrypts the second target file according to the second working key; The file viewing request includes user information and identification information of the quantum key injection medium of the client; The device further comprises: A first acquisition submodule is configured to acquire pre-established identity association information, wherein the identity association information includes an association between user information and identification information of a quantum key-filled medium; a second determining submodule, configured to determine whether the user information in the file viewing request and the identification information of the quantum key charging medium of the client match the identity association information; The search module includes: a search submodule, configured to search for key information corresponding to the second target file based on file information corresponding to the second target file if the user information in the file viewing request and the identification information of the quantum key injection medium of the client match the identity association information.

11. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of the file encryption method based on quantum encryption as described in any one of claims 1-2 or 3-4 are implemented.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the file encryption method based on quantum encryption according to any one of claims 1 to 2 or 3 to 4.

Citation Information

Patent Citations

  • Encrypted file retrieval method and system, terminal equipment and storage medium

    CN108038128A

  • Data processing method and device based on SIM card, electronic equipment and storage medium

    CN118748796A