Method, apparatus, device and medium for preventing forwarding of encrypted file

By marking and encrypting encrypted files, the system ensures that files are only distributed among specific users, thus solving the problem of arbitrary forwarding of encrypted files and improving the security and control of file transmission.

CN119561703BActive Publication Date: 2025-11-25CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311130119.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-04
Publication Date
2025-11-25
Estimated Expiration
2043-09-04

AI Technical Summary

Technical Problem

In existing technologies, encrypted files cannot be effectively prevented from being forwarded arbitrarily during transmission, which compromises security.

Method used

The file to be sent is marked with the tagging information, a new tagged file is generated, and it is encrypted with a key. The encrypted file and key are sent only to the tagged user, ensuring that the file is only distributed within a specific scope.

Benefits of technology

It enables targeted forwarding of encrypted files, preventing unauthorized users from receiving and decrypting them, thus improving the security and control of file transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561703B_ABST
    Figure CN119561703B_ABST
Patent Text Reader

Abstract

The application provides a method, device, equipment and medium for preventing encrypted file forwarding. The method comprises the following steps: confirming whether a file to be sent is marked by marking information, obtaining a new marked file, wherein the new marked file comprises the marking information; encrypting the new marked file by a key, and confirming whether a target user receiving the new marked file is a marked user indicated by the marking information, wherein the marked user is an object allowed to be forwarded; if the target user is the marked user, encrypting the key, and sending the encrypted new marked file and the encrypted key to the target user. The method can effectively prevent the file from being randomly forwarded, and improves the security of file transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of file transfer technology, and in particular to a method, apparatus, device, and medium for preventing the forwarding of encrypted files. Background Technology

[0002] With the rapid development of mobile devices and mobile office solutions, storing and forwarding daily work files on mobile devices has become commonplace. To ensure the security of file transmission, files are usually encrypted before transmission.

[0003] However, for certain special or important files, such as those known only to a limited group, while encryption can ensure the security of the file transfer process, it cannot guarantee that the file will not be forwarded and disseminated. For example, if A sends a file to B in encryption, B can also forward the encrypted file again, which poses a security risk for certain special files.

[0004] Therefore, there is an urgent need to propose a file transfer process with higher security performance. Summary of the Invention

[0005] This application provides a method, apparatus, device, and medium for preventing the forwarding of encrypted files, in order to solve the problem in the prior art that it is impossible to prevent special files from being forwarded at will, thus affecting security.

[0006] Firstly, this application provides methods for preventing the forwarding of encrypted files, including:

[0007] Confirm whether the file to be sent has been tagged with the tagging information to obtain a new tagged file, wherein the new tagged file includes the tagging information;

[0008] The new tag file is encrypted using a key, and it is confirmed whether the target user receiving the new tag file is the tag user indicated by the tag information, wherein the tag user is an object that is allowed to be forwarded;

[0009] If the target user is the marked user, then the key is confirmed to be encrypted, and the encrypted new marked file and the encrypted key are sent to the target user.

[0010] In one possible implementation, the confirmation of whether the file to be sent has been marked with the marking information to obtain a new marked file includes:

[0011] If the file to be sent is an untagged file, then it is confirmed that the file to be sent has been tagged using the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information;

[0012] If the file to be sent is a tagged file, then it is confirmed that the file to be sent will not be tagged again, wherein the tagged file is a file that has been tagged by the tagging information.

[0013] In one possible implementation, marking the file to be sent using the marking information includes:

[0014] User information of a portion of the target users is selected from among the multiple target users as tagging information, and the file to be sent is tagged using the tagging information, wherein the user information includes the public key of the target user's identity.

[0015] In one possible implementation, after confirming that the file to be sent has been marked using the marking information and obtaining the newly marked file, the method further includes:

[0016] The newly tagged file is stored in the database as a tagged file, awaiting the next transmission.

[0017] In one possible implementation, confirming whether the target user to receive the new tag file is the tag user indicated by the tag information includes:

[0018] If the user information of the target user is consistent with the tag information of the new tag file, then the target user to receive the new tag file is confirmed as the tag user of the tag information;

[0019] If the user information of the target user is inconsistent with the tag information of the new tag file, then it is confirmed that the target user who is to receive the new tag file is not the tag user of the tag information.

[0020] In one possible implementation, if the target user is not the marked user, the method further includes:

[0021] Sending the encrypted new tag file and the encrypted key to the target user is prohibited.

[0022] Secondly, this application provides a device for preventing the forwarding of encrypted files, comprising:

[0023] The acquisition module is used to confirm whether the file to be sent has been marked with the marking information, and to obtain a new marked file, wherein the new marked file includes the marking information;

[0024] The processing module is used to encrypt the new tag file with a key and confirm whether the target user to receive the new tag file is the tag user indicated by the tag information, wherein the tag user is an object that is allowed to be forwarded;

[0025] The sending module is configured to, if the target user is the marked user, confirm that the key is encrypted, and send the encrypted new marked file and the encrypted key to the target user.

[0026] In one possible implementation, the acquisition module is specifically used for:

[0027] If the file to be sent is an untagged file, then it is confirmed that the file to be sent has been tagged using the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information;

[0028] If the file to be sent is a tagged file, then it is confirmed that the file to be sent will not be tagged again, wherein the tagged file is a file that has been tagged by the tagging information.

[0029] Thirdly, this application provides a device for preventing the forwarding of encrypted files, comprising: at least one processor and a memory;

[0030] The memory stores computer-executed instructions;

[0031] The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the method described above for preventing the forwarding of encrypted files.

[0032] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method for preventing the forwarding of encrypted files as described above.

[0033] This application provides a method, apparatus, device, and medium for preventing the forwarding of encrypted files. The method involves confirming whether a file to be sent has been marked with tagging information to obtain a new tagged file, wherein the new tagged file includes the tagging information; encrypting the new tagged file with a key; and confirming whether the target user receiving the new tagged file is the tagged user indicated by the tagging information, wherein the tagged user is an object permitted to be forwarded; if the target user is the tagged user, then confirming the encryption of the key, and sending the encrypted new tagged file and the encrypted key to the target user.

[0034] In the above method, before the file to be sent is encrypted and forwarded, the file to be sent is marked to obtain a new marked file. The new marked file is then encrypted. Before encrypting the key corresponding to the new marked file, it is necessary to use the marking information to check whether the target user matches the user marked by the marking information. If it is confirmed that the target user is marked, then the key encryption and forwarding and file forwarding are performed to ensure that the file can be forwarded to the specially selected target user. Correspondingly, the target user who is not selected cannot be forwarded, thus ensuring the specificity and security of the target direction of file forwarding. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 A schematic diagram illustrating a scenario for preventing the forwarding of encrypted files, provided as an embodiment of this application;

[0037] Figure 2 A flowchart illustrating a method for preventing the forwarding of encrypted files provided in this application embodiment. Figure 1 ;

[0038] Figure 3 A flowchart illustrating a method for preventing the forwarding of encrypted files provided in this application embodiment. Figure 2 ;

[0039] Figure 4 A flowchart illustrating a method for preventing the forwarding of encrypted files provided in this application embodiment. Figure 3 ;

[0040] Figure 5 A diagram of a device for preventing the forwarding of encrypted files provided in an embodiment of the present invention;

[0041] Figure 6 This is a hardware schematic diagram of a device for preventing the forwarding of encrypted files, provided in an embodiment of the present invention. Detailed Implementation

[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0043] To ensure that files are not arbitrarily damaged, altered, or leaked during file transfer, there are many technical methods to guarantee the security of file transfer, including encrypting files. However, encryption alone is not enough for some users with high security requirements, because for some special files, users want them to be forwarded and disseminated only within a certain scope.

[0044] For example, in a high-security organization, in order to ensure the secure transmission of information, all work documents are transmitted via secure IM (Instant Messaging) software. However, for some important documents (such as classified documents), if A sends a file to B in an encrypted manner, it is necessary to control the scope of the file's dissemination to prevent B from forwarding the file to other people who do not meet the conditions for receiving the file.

[0045] In other words, there is no corresponding way to handle situations where some users want their files to be prevented from being arbitrarily distributed and are only used within a specific scope.

[0046] Therefore, in order to meet users' higher personalized needs, to limit the spread of important files, and to further increase the security of file transmission, this application proposes a processing method to prevent the forwarding of encrypted files.

[0047] The implementation process of a method for preventing the forwarding of encrypted files proposed in this application is described below with reference to the accompanying drawings and specific embodiments.

[0048] Figure 1 This is a schematic diagram illustrating a scenario for preventing the forwarding of encrypted files, provided as an embodiment of this application. Figure 1 As shown, the system includes: a first terminal 101, a second terminal 102, and an encrypted file 103; wherein, the first terminal includes the file before encryption and can encrypt the file before encryption; the second terminal is used to receive the encrypted file and can also be used to decrypt the encrypted file to obtain the decrypted file; file transfer can occur between terminals or within a terminal.

[0049] Before being officially sent, the file is in a pending state, i.e., a file to be sent. A terminal typically contains many files, and the terminal can manage the forwarding of some or all files according to user needs. Files selected for management and forwarding can be marked; that is, files to be sent that need management can be marked using marking information, resulting in a newly marked file. The marking information can authenticate whether the target user is allowed to be forwarded. If so, the encrypted newly marked file and the key used to encrypt it can be forwarded to the target user (e.g., the user in the second terminal 102). Otherwise, forwarding is prohibited, thus preventing arbitrary file forwarding, meeting user needs, and ensuring file transmission security.

[0050] Figure 2 A flowchart illustrating a method for preventing the forwarding of encrypted files provided in this application embodiment. Figure 1 .like Figure 2 As shown, the method includes:

[0051] S201. Confirm whether the file to be sent is marked using the marking information, and obtain a new marked file, wherein the new marked file includes the marking information.

[0052] Depending on user needs, the file to be sent can be either a file that needs to be tagged or a file that does not need to be tagged. Users can select the files they want to be tagged before sending the file. The tagged file can be sent to a specific user. The tagged file is a new tagged file, and the new tagged file carries tagging information to facilitate subsequent authentication with the target user.

[0053] S202. Encrypt the new tag file using a key, and confirm whether the target user to receive the new tag file is the tag user indicated by the tag information, wherein the tag user is an object that is allowed to be forwarded.

[0054] The key used to encrypt the new tagged file can be selected based on the experience of the technicians or the resources of the terminal itself. For example, a symmetric key can be used to encrypt the new tagged file. In order to ensure file security, the new tagged file should be encrypted regardless of what kind of transmission it undergoes. After encryption, the tagging information is verified to confirm whether the tagging information in the new tagged file indicates that the target user is the tagged user. If so, the verification is successful and the next step can be carried out.

[0055] The marking method involves marking confirmed files to be sent with marking information. This marking information can be used for matching and authentication with target users. For example, the marking information records the target users who can be forwarded. The recorded target users are marked users, and the unrecorded target users are unmarked users.

[0056] S203. If the target user is the marked user, then confirm that the key is encrypted, and send the encrypted new marked file and the encrypted key to the target user.

[0057] When a file to be forwarded begins to be sent (during the sending process), if the target user is found to be under the record of the tagging information, then the target user is a tagged user, that is, the target user is confirmed to be a tagged user through the tagging information; conversely, if the target user is found to be not under the record of the tagging information, then the target user is a non-tagged user, that is, the target user is confirmed to be a non-tagged user through the tagging information.

[0058] If the target user is designated as the tagging user, then the key for encrypting the new tagging file can be encrypted using the target user's public key. After the encrypted new tagging file and the encrypted key are sent to the target user, the target user can also decrypt the encrypted key using their own public key to obtain the key to open the new tagging file.

[0059] If the target user is not the marked user, then it is confirmed that no further forwarding operation is needed. For example, if the target user is not the marked user, the method further includes:

[0060] Sending the encrypted new tag file and the encrypted key to the target user is prohibited.

[0061] If the target user is designated as an untagged user, then that target user is not allowed to forward the file, and the target user's public key cannot be used to encrypt the key. Sending the encrypted new tagged file to the target user is prohibited. Even if a mis-sent file is sent, the target user cannot decrypt it using their own public key, thus ensuring the security of file forwarding.

[0062] In this embodiment, it is confirmed whether the file to be sent is marked with the marking information to obtain a new marked file, wherein the new marked file includes the marking information; the new marked file is encrypted with a key, and it is confirmed whether the target user receiving the new marked file is the marked user indicated by the marking information, wherein the marked user is an object that is allowed to be forwarded; if the target user is the marked user, it is confirmed that the key is encrypted, and the encrypted new marked file and the encrypted key are sent to the target user;

[0063] Before encrypting and forwarding the file to be sent, the file is marked to obtain a new marked file. The new marked file is then encrypted. Before encrypting the key corresponding to the new marked file, the target user needs to be checked against the marked information to see if they match the marked user. If they are confirmed to be the marked user, the key encryption and forwarding and file forwarding are then performed to ensure that the file can be forwarded to the specially selected target user. Correspondingly, the file cannot be forwarded to the target user who is not selected, thus ensuring the specificity and security of the target direction of file forwarding.

[0064] Figure 3 A flowchart illustrating a method for preventing the forwarding of encrypted files provided in this application embodiment. Figure 2 .like Figure 3 As shown, the method includes:

[0065] S301. If the file to be sent is an untagged file, then confirm that the file to be sent is tagged using the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information.

[0066] If the file to be sent is selected by the user and needs to be marked, before marking, in order to avoid duplicate marking, it is also necessary to confirm whether the file to be sent is an unmarked file. If it is an unmarked file, the file to be sent can be marked using the marking information to obtain a new marked file containing the marking information.

[0067] To authenticate a target user using tagging information, the tagging information can be the target user's user information:

[0068] For example, user information of a portion of the target users is selected as tagging information from among the multiple target users, and the file to be sent is tagged using the tagging information, wherein the user information includes the public key of the target user's identity.

[0069] When a file transfer occurs with a terminal that sends a file, there may be multiple target users receiving the file. The terminal that sends the file can select which target user can receive the file as needed. The selected target user can provide content for marking the file to be sent; for example, user information can be used as marking information and carried by the file to be sent.

[0070] If user information is selected as tagging information, for example, if the target user's public key is selected as tagging information, then the new tagging file includes the target user's public key. When it is confirmed that the new tagging file matches the public key of a target user, it can be confirmed that the target user is a tagged user and is an object that is allowed to be forwarded.

[0071] The identity public key can also be used to encrypt the key; after confirming that the key is encrypted, the new tag file is encrypted using the symmetric key. If the target user wants to be able to decrypt the encrypted new tag file after obtaining it, they need to obtain the key.

[0072] If the target user is the tag user, then the target user's own identity public key can decode the encrypted key to obtain the decrypted key, and the decrypted key can be used to open the encrypted new tag file;

[0073] If the target user is an unmarked user, then the target user's own identity public key cannot decode the encrypted key. In this case, the unmarked user will be restricted from receiving the decrypted new mark file. Alternatively, even if the unmarked user receives the encrypted new mark file, at the beginning of the reception process, the identity public key needs to be verified to check whether the identity public key can open the encrypted key. If it cannot, the unmarked user will stop sending the encrypted new mark file and return a file sending failure feedback to the sender.

[0074] For files that have just been marked, the file and its marking information can be stored together in the database:

[0075] After confirming that the file to be sent has been marked using the marked information and obtaining the new marked file:

[0076] For example, the new tagged file is stored in the database as a tagged file, waiting for the next transmission.

[0077] If a file is to be sent again, it will be selected from the database. Since the file has already been tagged, it does not need to be tagged again and can be directly authenticated with the target user. The tagged files stored in the database can have their tagging information deleted according to user needs, or the user can select the tagged file.

[0078] S302. If the file to be sent is a tagged file, then confirm that the file to be sent will not be tagged again, wherein the tagged file is a file that has been tagged by the tagging information.

[0079] If the file to be sent is a file that has already been tagged (tagged file), then there is no need to tag it again. In other words, the file to be sent has already been tagged before this sending is prepared, and the authentication between the file and the target user can start directly.

[0080] In this embodiment of the application, if the file to be sent is an untagged file, it is confirmed that the file to be sent is tagged using the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information; if the file to be sent is a tagged file, it is confirmed that the file to be sent will not be tagged again.

[0081] By confirming whether the file to be sent has been marked, confirming whether the file to be sent should be marked, marking the unmarked file to be sent, and not marking the already marked file to be sent again, the system can reasonably distinguish the files that the user selects to be marked and managed.

[0082] Figure 4 A flowchart illustrating a method for preventing the forwarding of encrypted files provided in this application embodiment. Figure 3 .like Figure 4 As shown, the method includes:

[0083] S401. If the user information of the target user is consistent with the tag information of the new tag file, then the target user to receive the new tag file is confirmed as the tag user of the tag information.

[0084] User information includes the target user's identity public key. When the new tag file selects the target user's user information as the tag information, the tag information is consistent with the user information. That is, the identity public key recorded in the new tag file is consistent with the target user's identity public key. Therefore, it can be confirmed that the target user of the new tag file is the selected tag user who is allowed to forward the message.

[0085] S402. If the user information of the target user is inconsistent with the tag information of the new tag file, then it is confirmed that the target user who is to receive the new tag file is not the tag user of the tag information.

[0086] Conversely, if the tagging information is inconsistent with the user information, that is, if the public key of the identity recorded in the new tagging file is inconsistent with the public key of the target user, then it can be confirmed that the target user of the new tagging file is a selected tagging user who is not allowed to forward the tag.

[0087] In this embodiment of the application, if the user information of the target user is consistent with the tagging information of the new tagging file, then the target user to receive the new tagging file is confirmed to be the tagging user of the tagging information; if the user information of the target user is inconsistent with the tagging information of the new tagging file, then the target user to receive the new tagging file is confirmed to be the tagging user of the tagging information.

[0088] By authenticating the new tagged file and the target user, it is confirmed whether the user information is consistent with the tag information, whether the target user is a tagged user who is allowed to forward the new tagged file, and the forwarding target is clearly defined. This ensures that the new tagged file is forwarded accurately and prevents it from being forwarded to the wrong location.

[0089] Figure 5 A diagram of a device for preventing the forwarding of encrypted files is provided in an embodiment of the present invention, as shown below. Figure 5 As shown, the device includes: an acquisition module 501, a processing module 502, and a transmission module 503;

[0090] The acquisition module 501 is used to confirm whether the file to be sent has been marked with the marking information and to obtain a new marked file, wherein the new marked file includes the marking information.

[0091] The acquisition module 501 is further configured to, if the file to be sent is an untagged file, confirm that the file to be sent has been tagged by the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information;

[0092] If the file to be sent is a tagged file, then it is confirmed that the file to be sent will not be tagged again, wherein the tagged file is a file that has been tagged by the tagging information.

[0093] The acquisition module 501 is further configured to select a portion of the user information of the target users from among the multiple target users as tagging information, and to tag the file to be sent using the tagging information, wherein the user information includes the public key of the target user's identity.

[0094] The acquisition module 501 is further configured to confirm that the file to be sent has been marked by the marking information. After obtaining the newly marked file, the method further includes:

[0095] The newly tagged file is stored in the database as a tagged file, awaiting the next transmission.

[0096] The processing module 502 is used to encrypt the new tag file with a key and confirm whether the target user to receive the new tag file is the tag user indicated by the tag information, wherein the tag user is an object that is allowed to be forwarded.

[0097] The processing module 502 is further configured to confirm that the target user of the new tag file to be received is the tag user of the tag information if the user information of the target user is consistent with the tag information of the new tag file;

[0098] If the user information of the target user is inconsistent with the tag information of the new tag file, then it is confirmed that the target user who is to receive the new tag file is not the tag user of the tag information.

[0099] The sending module 503 is configured to, if the target user is the marked user, confirm that the key is encrypted, and send the encrypted new marked file and the encrypted key to the target user.

[0100] The sending module 503 is further configured to, if the target user is not the marked user, then the method further includes:

[0101] Sending the encrypted new tag file and the encrypted key to the target user is prohibited.

[0102] This application also provides a device for preventing the forwarding of encrypted files, comprising: at least one processor and a memory;

[0103] The memory stores computer-executed instructions;

[0104] The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform a method for preventing the forwarding of encrypted files.

[0105] Figure 6 This is a hardware schematic diagram of a device for preventing the forwarding of encrypted files provided in an embodiment of the present invention. Figure 6 As shown, the device 60 for preventing the forwarding of encrypted files provided in this embodiment includes at least one processor 601 and a memory 602. The device 60 also includes a communication component 603. The processor 601, memory 602, and communication component 603 are connected via a bus 604.

[0106] In a specific implementation, at least one processor 601 executes computer execution instructions stored in the memory 602, causing at least one processor 601 to perform the above-described method for preventing the forwarding of encrypted files.

[0107] The specific implementation process of processor 601 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0108] In the above Figure 6In the illustrated embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0109] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0110] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0111] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method for preventing the forwarding of encrypted files as described above.

[0112] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0113] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0114] The division of units described herein is merely a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0115] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0116] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0117] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0118] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0119] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A method for preventing the forwarding of encrypted files, characterized in that, include: Confirm whether the file to be sent has been tagged with the tagging information to obtain a new tagged file, wherein the new tagged file includes the tagging information; The new tag file is encrypted using a key, and it is confirmed whether the target user receiving the new tag file is the tag user indicated by the tag information, wherein the tag user is an object that is allowed to be forwarded; If the target user is the marked user, then the key is confirmed to be encrypted, and the encrypted new marked file and the encrypted key are sent to the target user.

2. The method according to claim 1, characterized in that, The confirmation of whether to mark the file to be sent using the marking information and obtain a new marked file includes: If the file to be sent is an untagged file, then it is confirmed that the file to be sent has been tagged using the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information; If the file to be sent is a tagged file, then it is confirmed that the file to be sent will not be tagged again, wherein the tagged file is a file that has been tagged by the tagging information.

3. The method according to claim 2, characterized in that, The step of marking the file to be sent using the marking information includes: User information of a subset of the target users is selected as tagging information, and the file to be sent is tagged using the tagging information. The user information includes the public key of the target user's identity.

4. The method according to claim 2, characterized in that, After confirming that the file to be sent has been marked using the marking information and obtaining the newly marked file, the method further includes: The newly tagged file is stored in the database as a tagged file, awaiting the next transmission.

5. The method according to claim 3, characterized in that, The step of confirming whether the target user to receive the new tagged file is the tagged user indicated by the tagged information includes: If the user information of the target user is consistent with the tag information of the new tag file, then the target user to receive the new tag file is confirmed as the tag user of the tag information; If the user information of the target user is inconsistent with the tagging information of the new tagging file, then it is confirmed that the target user who is to receive the new tagging file is not the tagging user of the tagging information.

6. The method according to claim 1, characterized in that, If the target user is not the marked user, the method further includes: Sending the encrypted new tag file and the encrypted key to the target user is prohibited.

7. A device for preventing the forwarding of encrypted files, characterized in that, include: The acquisition module is used to confirm whether the file to be sent has been marked with the marking information, and to obtain a new marked file, wherein the new marked file includes the marking information; The processing module is used to encrypt the new tag file with a key and confirm whether the target user to receive the new tag file is the tag user indicated by the tag information, wherein the tag user is an object that is allowed to be forwarded; The sending module is configured to, if the target user is the marked user, confirm that the key is encrypted, and send the encrypted new marked file and the encrypted key to the target user.

8. The apparatus according to claim 7, characterized in that, The acquisition module is specifically used for: If the file to be sent is an untagged file, then it is confirmed that the file to be sent has been tagged using the tagging information to obtain the new tagged file, wherein the untagged file is a file that has not been tagged by the tagging information; If the file to be sent is a tagged file, then it is confirmed that the file to be sent will not be tagged again, wherein the tagged file is a file that has been tagged by the tagging information.

9. A device for preventing the forwarding of encrypted files, characterized in that, include: At least one processor and memory; The memory stores computer-executed instructions; The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the method for preventing the forwarding of encrypted files as described in any one of claims 1-6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method for preventing the forwarding of encrypted files as described in any one of claims 1-6.

Citation Information

Patent Citations

  • File transmission method and device and computer readable storage medium

    CN115065478A

  • Method and system for running encrypted files

    US20140195825A1