A File Transfer Protection Method, System and Device Based on Multiple Encryption Algorithms

Through multiple encryption algorithms and steganography technology, file shards are hierarchically encrypted, combined with dynamic session keys and sensitivity analysis, the problem of insufficient file transmission security and efficiency in the existing technology is solved, and efficient and secure file transmission protection is achieved.

CN119675967BActive Publication Date: 2025-07-04SUZHOU OMEGA NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411877988.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-07-04
Estimated Expiration
2044-12-19

AI Technical Summary

Technical Problem

Existing file transfer technologies are difficult to effectively resist complex attacks when processing highly sensitive data, single encryption algorithms and steganography technologies are difficult to ensure security and efficiency, and lack multi-layer protection and dynamic key generation mechanisms.

Method used

Multiple encryption algorithms are used to encrypt file shards in layers, and steganography is used to embed the carrier file, and dynamic session keys are generated through obfuscated key pools. Combined with sensitivity analysis and integrity verification, we ensure the security and integrity of file transfer.

Benefits of technology

It realizes efficient concealment, adaptability and attack resistance during file transfer, ensures data security and integrity, and improves transmission efficiency and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675967B_ABST
    Figure CN119675967B_ABST
Patent Text Reader

Abstract

The present invention discloses a file transmission protection method, system and device based on multiple encryption algorithms, which relates to the field of information technology. It includes selecting a target file to be transmitted and performing preprocessing to generate file shards; analyzing the sensitivity of each file shard and performing hierarchical encryption processing to obtain a set of encrypted shards; selecting a steganographic carrier file, embedding the encrypted shards into the carrier file to generate a steganographic index table; generating a dynamic session key based on a confusion key pool, encrypting the steganographic file transmission layer and embedding dynamic key generation parameters; the receiving end generates a session key according to the transmission packet header, decrypts the transmission layer data to extract the steganographic file and decrypts it; and reorganizing the decrypted and restored shard data into a complete file according to the identifier order. The present invention realizes the efficient embedding of shard data and the generation of a steganographic index table by dynamically matching the steganographic carrier file, ensuring the concealment and adaptability during the transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and particularly to a file transfer protection method, system and device based on multiple encryption algorithms. Background Art

[0002] With the development of information technology, the transmission of digital files has become an important part of daily work and life. However, during the transmission process, files are extremely vulnerable to security threats such as data leakage, tampering, and unauthorized access. Currently, mainstream file transfer technologies mostly rely on a single encryption algorithm for protection. Although it ensures the security of data to a certain extent, it has deficiencies in dealing with highly sensitive data and is difficult to effectively resist complex attacks. In addition, existing technologies usually rely on the basic verification mechanism of the transport protocol layer for the integrity verification of file transfer, lacking pertinence and multi-layer protection. Especially in file fragmentation processing and encryption protection, dynamic encryption is often not combined with the sensitivity of the file content, and it is difficult to balance transmission efficiency and security.

[0003] Existing file steganography transmission technologies mainly rely on a single carrier for data embedding, but it is difficult to efficiently embed when the data volume is large or the steganography carrier does not match. At the same time, the dynamic key generation mechanism designed for the transmission of file steganography data is relatively single and is easily predicted or cracked, resulting in a decrease in the security of steganographic information. Therefore, how to combine multiple encryption algorithms, steganography technologies, dynamic key generation mechanisms, and integrity verification methods during the file transfer process to construct a secure, efficient, and flexible file transfer protection system has become an urgent problem to be solved. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a file transfer protection method based on multiple encryption algorithms to solve the problems of insufficient recognition of data sensitivity, inflexible encryption protection, and low steganography embedding efficiency during the file transfer process.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a file transfer protection method based on multiple encryption algorithms, which includes selecting a target file to be transferred and performing preprocessing to generate file fragments;

[0008] Analyzing the sensitivity of each file fragment and performing hierarchical encryption processing to obtain a set of encrypted fragments;

[0009] Selecting a steganography carrier file, embedding the encrypted fragments into the carrier file, and generating a steganography index table;

[0010] Generate a dynamic session key based on a confusion key pool, encrypt the steganographic file transport layer, and embed dynamic key generation parameters;

[0011] The receiving end generates a session key according to the transport packet header, decrypts the transport layer data to extract the steganographic file and decrypts it;

[0012] Recombine the decrypted and restored fragmented data into a complete file in the order of identifiers, and verify whether the file is damaged through integrity verification to obtain a verification result.

[0013] As a preferred solution of the file transmission protection method based on multiple encryption algorithms described in the present invention, wherein: select a target file to be transmitted and perform preprocessing, and the steps of generating file fragments include the following,

[0014] The user selects a target file to be transmitted, and performs format verification on the target file to determine whether it belongs to the set of supported file types;

[0015] Detect the size of the target file based on the format verification result;

[0016] For the detected oversized file, fragment it according to a fixed size to determine the total number of fragments required;

[0017] According to the determined total number of fragments, extract data segments from the file in sequence to generate a fragment set;

[0018] Assign a unique identifier to each fragment in the fragment set, and record the fragment order and size.

[0019] As a preferred solution of the file transmission protection method based on multiple encryption algorithms described in the present invention, wherein: analyze the sensitivity of each file fragment and perform hierarchical encryption processing to obtain an encrypted fragment set, including the following steps,

[0020] Load the sensitive keyword list and the sensitivity level threshold S configured by the user from the sensitivity rule database th ;

[0021] Perform keyword matching and context analysis on the content of each fragment in the fragment set, and calculate the sensitivity score of the fragment. The expression is:

[0022]

[0023] Where S[i] represents the sensitivity score of the i-th fragment, i represents the fragment index, j represents the sensitive keyword index, m represents the total number of sensitive keywords, w j represents the weight of the j-th sensitive keyword, A[i] represents the total number of bytes of the i-th fragment, O j(The number of occurrences of the j-th sensitive keyword in the i-th shard is represented by A[i];

[0024] Classify the shards according to the sensitivity score;

[0025] When S[i] ≥ S th mark the shard as a highly sensitive shard. When S[i] < S th mark the shard as a low-sensitivity shard;

[0026] For the shards marked as highly sensitive, perform double encryption using the elliptic curve encryption algorithm and the AES-256 symmetric encryption method;

[0027] For the shards marked as low-sensitivity, perform single-layer encryption using AES-128 symmetric encryption;

[0028] Pack the encrypted highly sensitive shards and low-sensitivity shards, add an encryption mark and shard metadata information to each encrypted shard to obtain an encrypted shard set.

[0029] As a preferred solution of the file transfer protection method based on multiple encryption algorithms described in the present invention, wherein: select a steganographic carrier file, embed the encrypted shards into the carrier file, and generate a steganographic index table, including the following steps,

[0030] Load the steganographic carrier file library, extract the metadata of each file in the carrier file library, and generate a carrier information table;

[0031] Extract the size of each encrypted shard from the encrypted shard set, and dynamically match the carrier file in the carrier information table for each encrypted shard according to the carrier allocation rule;

[0032] For each encrypted shard and its matched carrier file, use the steganographic algorithm to embed the encrypted shard into a specific position of the carrier file;

[0033] After steganography is completed, generate a steganographic index table for each embedded shard.

[0034] As a preferred solution of the file transfer protection method based on multiple encryption algorithms described in the present invention, wherein: generate a dynamic session key based on the obfuscation key pool, encrypt the steganographic file transfer layer and embed dynamic key generation parameters, including the following steps,

[0035] Obtain the current timestamp and the user's dynamic operation mode, and generate a unique device fingerprint identifier based on the hardware characteristics of the sending device;

[0036] The obtained current timestamp, the user's dynamic operation mode, and the generated unique device fingerprint identifier are obfuscated using a hash function and an encryption algorithm to generate a dynamic key seed, with the expression:

[0037] Seed key = HMAC-SHA256(T current ||F device ||B user ,K static );

[0038] Among them, Seed key represents the dynamic key seed, T current represents the current timestamp, B user represents the user's dynamic operation mode, F device represents the fingerprint identifier of the unique device, HMAC represents the hash-based message authentication code, SHA256 represents mapping input data of any length to a fixed-length 256-bit output value, and K static represents a secure static root key;

[0039] A pseudo-random key is extracted from the dynamic key seed using a key derivation function, with the expression:

[0040] PRK = HMAC-SHA256(Seed key ,K static );

[0041] Among them, PRK represents the pseudo-random key;

[0042] The pseudo-random key is converted into a dynamic session key of the required length, with the expression:

[0043] K session = HKDF-Expand(PRK,info,L);

[0044] Among them, K session represents the dynamic session key, HKDF-Expand represents generating a key of the required length from the pseudo-random key, info represents optional context information, and L represents the length of the required session key;

[0045] Start a transport layer encryption session, use the generated dynamic session key, and transmit and encrypt the steganographic files in the steganographic index table through the transport layer encryption channel;

[0046] During the transmission, embed the dynamic key seed in the dynamic key in each transport header.

[0047] As a preferred solution of the file transfer protection method based on multiple encryption algorithms according to the present invention, wherein: the receiving end generates a session key according to the transmission message header, and decrypting the transport layer data to extract the steganographic file and decrypt it includes the following steps,

[0048] After receiving the encrypted steganographic file, the receiving end parses the dynamic key seed in the transmission message header, and generates a dynamic session key through the same logic and key pool as the sending end;

[0049] Use the generated dynamic session key to decrypt the encrypted transport layer data and extract the steganographic file;

[0050] Extract the embedded steganographic index table from the decrypted steganographic file, and according to the steganographic index table, load the corresponding steganographic carrier file, and extract the metadata of the carrier file from the steganographic carrier file;

[0051] Use the least significant bit anti-embedding algorithm to extract the shard data from the pixel data;

[0052] Use the inverse discrete cosine transform algorithm to extract the shard data from the frequency domain coefficients;

[0053] Use the shard identifier to verify whether the extracted shard data is complete and correct;

[0054] According to the sensitivity mark of the shard, select the corresponding decryption algorithm and decrypt the shard data one by one;

[0055] Compare the decrypted shard data with the shard identifier to verify the integrity of the decrypted data.

[0056] As a preferred solution of the file transfer protection method based on multiple encryption algorithms according to the present invention, wherein: reorganize the decrypted and restored shard data into a complete file in the order of the identifiers, and verify whether the file is damaged through integrity verification, and the obtained verification result includes the following steps,

[0057] Extract all shard data from the decrypted shard data, and use the quicksort algorithm to sort it in ascending order;

[0058] Create a file buffer, and write the sorted shard data into the buffer in sequence to obtain the reorganized file;

[0059] Use the SHA-256 algorithm to calculate the hash of the buffer of the reorganized file to generate the verification value of the complete file;

[0060] Compare the generated verification value of the complete file with the original file verification value to obtain the verification result;

[0061] When the verification passes, write the buffer of the reorganized file to the disk to generate the final original file;

[0062] When the verification fails, an error message is returned and the user is prompted to re-transmit the relevant shards.

[0063] In a second aspect, the present invention provides a file transmission protection system based on multiple encryption algorithms, including

[0064] A file preprocessing module that selects a target file to be transmitted and performs preprocessing to generate file shards;

[0065] A shard encryption module that analyzes the sensitivity of each file shard and performs hierarchical encryption processing to obtain a set of encrypted shards;

[0066] A steganography embedding module that selects a steganography carrier file and embeds the encrypted shards into the carrier file to generate a steganography index table;

[0067] A key generation module that generates a dynamic session key based on a confusion key pool, encrypts the steganographic file transmission layer, and embeds dynamic key generation parameters;

[0068] A decryption and extraction module that, at the receiving end, generates a session key based on the transmission packet header, decrypts the transmission layer data to extract the steganographic file, and decrypts it;

[0069] A file recombination module that recombines the decrypted and restored shard data into a complete file in the order of identifiers, and verifies whether the file is damaged through integrity verification to obtain a verification result.

[0070] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the file transmission protection method based on multiple encryption algorithms as described in the first aspect of the present invention is implemented.

[0071] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the file transmission protection method based on multiple encryption algorithms as described in the first aspect of the present invention is implemented.

[0072] The beneficial effects of the present invention are as follows: By performing format verification and size detection, the standardization of the transmitted file is ensured, and large files are fragmented, enhancing the support ability for large-scale files; Using the sensitivity analysis mechanism, dynamic hierarchical encryption is performed on the fragmented content, optimizing the encryption efficiency while improving security; By dynamically matching steganographic carrier files, efficient embedding of fragmented data and generation of steganographic index tables are achieved, ensuring the concealment and adaptability during the transmission process; The confusion key pool is used to generate dynamic session keys, and the key generation parameters are dynamically embedded, enhancing the randomness and anti-attack ability of the session keys; The steganographic file is restored using the dynamic key and the fragmented data is extracted, and the corresponding decryption algorithm is selected through sensitivity marking, ensuring the efficiency and accuracy of data decryption; By quickly sorting and reorganizing the fragmented data, it is verified whether the file has been tampered with or lost, ensuring the integrity and reliability of the transmitted file. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0074] Figure 1 It is a flowchart of the file transmission protection method based on multiple encryption algorithms in Embodiment 1.

[0075] Figure 2 It is a schematic diagram of hierarchical encryption processing in Embodiment 1. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0076] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention with reference to the accompanying drawings of the specification.

[0077] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0078] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation of the present invention. The phrase "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments.

[0079] Embodiment 1, refer to Figure 1 and Figure 2, which is the first embodiment of the present invention. This embodiment provides a file transfer protection method based on multiple encryption algorithms, including the following steps:

[0080] S1. Select the target file to be transferred and perform preprocessing to generate file shards.

[0081] S1.1. The user selects the target file to be transferred and performs format verification on the target file to determine whether it belongs to the supported file type set.

[0082] Specifically, file format verification refers to detecting whether the file format is legal. Format verification is performed by reading the file header identifier. If the file format is not supported, an error message is returned and the operation is terminated; if the file format is legal, proceed to the next step of processing.

[0083] S1.2. Detect the size of the target file based on the format verification result.

[0084] Specifically, file size detection refers to reading the size of the file, setting a size threshold, and determining whether the file size is greater than the threshold. If the file size is less than or equal to the size threshold, no sharding is required and directly enter the encryption process of the next step; if the file size is greater than the size threshold, enter the sharding process.

[0085] S1.3. For the detected oversized file, shard it according to a fixed size to determine the total number of shards required.

[0086] Specifically, the total number of shards is based on the ratio of the total number of bytes of the file to a single shard, and the ceiling operation is performed on the size of the ratio.

[0087] S1.4. According to the determined total number of shards, extract data segments from the file in sequence to generate a shard set; assign a unique identifier to each shard in the shard set, and record the shard order and size.

[0088] Specifically, the identifier is generated by calculating the hash value of the shard content to generate a unique identifier. The SHA-256 algorithm is used to calculate the hash value of each shard. The output of the SHA-256 algorithm is a fixed 256-bit (32-byte) string. Since the content of each shard is different, its hash value is unique.

[0089] S2. Analyze the sensitivity of each file shard and perform hierarchical encryption processing to obtain an encrypted shard set.

[0090] Load the sensitive keyword list and the sensitivity level threshold S configured by the user from the sensitivity rule database th ; perform keyword matching and context analysis on the content of each shard in the shard set, and calculate the sensitivity score of the shard. The expression is:

[0091]

[0092] Among them, S[i] represents the sensitivity score of the i-th shard. The higher the score, the more sensitive the shard is and the more strictly it is encrypted. i represents the shard index, j represents the sensitive keyword index, m represents the total number of sensitive keywords, and w j represents the weight of the j-th sensitive keyword, and A[i] represents the total number of bytes of the i-th shard, O j (A[i] represents the number of times the j-th sensitive keyword appears in the i-th shard, which is used to count the actual occurrence frequency of each keyword in the shard. The more times it appears, the higher the contribution of this keyword to the shard sensitivity score;

[0093] Classify the shards according to the sensitivity score; when S[i]≥S th , mark the shard as a high-sensitivity shard, and when S[i]<S th , mark the shard as a low-sensitivity shard; for the shards marked as high-sensitivity, use the elliptic curve encryption algorithm and the AES-256 symmetric encryption method for double encryption; for the shards marked as low-sensitivity, use AES-128 symmetric encryption for single encryption; pack the encrypted high-sensitivity shards and low-sensitivity shards, add an encryption mark and shard metadata information to each encrypted shard, and obtain the encrypted shard set.

[0094] S3. Select a steganographic carrier file, embed the encrypted shards into the carrier file, and generate a steganographic index table.

[0095] S3.1. Load the steganographic carrier file library, extract the metadata of each file in the carrier file library, and generate a carrier information table.

[0096] Specifically, the steganographic carrier file library includes picture files, audio files, and video files.

[0097] Picture files (such as JPEG, PNG): Suitable for pixel-level embedding and support the LSB steganography algorithm.

[0098] Audio files (such as MP3, WAV): Suitable for frequency-domain embedding, such as modifying low-frequency coefficients.

[0099] Video files (such as MP4, AVI): Suitable for intra-frame embedding and support DCT or motion vector modification.

[0100] The metadata includes the file name, file type, and embeddable capacity.

[0101] S3.2. Extract the size of each encrypted shard from the encrypted shard set, and dynamically match the carrier file in the carrier information table for each encrypted shard according to the carrier allocation rule.

[0102] Specifically, the operation of dynamically matching the carrier file in the carrier information table for each encrypted shard according to the carrier allocation rule is as follows:

[0103] When the size of the encrypted shard is less than or equal to the embeddable capacity in the carrier file, the carrier is directly allocated; when the size of the encrypted shard is greater than the embeddable capacity in the carrier file, the encrypted shard is split into multiple sub-shards, and the size of each sub-shard does not exceed the capacity of a single carrier.

[0104] S3.3. For each encrypted shard and its allocated carrier file, use the steganography algorithm to embed the encrypted shard into a specific position in the carrier file; after steganography is completed, generate a steganography index table for each shard after embedding.

[0105] Specifically, the steganography algorithms include the LSB (Least Significant Bit) steganography algorithm applicable to picture carriers and the DCT (Discrete Cosine Transform) steganography algorithm applicable to audio / video carriers.

[0106] The LSB (Least Significant Bit) steganography algorithm realizes data embedding by modifying the least significant bit of the picture pixels. The change amplitude is small and cannot be detected by the naked eye. The specific embedding steps are as follows:

[0107] Read the shard data and convert it into a bit stream; read the allocated picture carrier, extract its pixel data, and sequentially embed the bit stream into the least significant bit of the pixels. For the k-th pixel, the embedded pixel value is obtained, and the expression is:

[0108] P k =(P k &254)|b;

[0109] where, P' k represents the k-th pixel value after embedding, P k represents the k-th pixel value before embedding, b represents a bit in the bit stream to be embedded, k represents the index number of the pixel, and & represents a bitwise operation.

[0110] The DCT (Discrete Cosine Transform) steganography algorithm realizes data embedding by modifying the frequency domain coefficients of the carrier. Usually, transform operations are performed on audio or video frames. The embedding steps are as follows.

[0111] For the encrypted shard, convert it into a bit stream. For the audio / video carrier of the shard, extract its frame data and perform a discrete cosine transform. The expression is:

[0112]

[0113] Among them, F(u, v) represents the coefficient at a specific position (u, v) in the frequency domain. The frequency domain coefficient is used to represent the component intensity of the original data at different frequencies. Steganography is achieved by modifying the low-frequency coefficients (usually the part with the largest energy), which can not only maintain data integrity but also reduce the detectability of embedding. u represents the frequency component in the horizontal frequency direction, v represents the component in the vertical frequency direction, N represents the total number of pixels in the horizontal direction, M represents the total number of pixels in the vertical direction, x represents the pixel index in the horizontal direction, y represents the pixel index in the vertical direction, and f(x, y) represents the original value of the pixel (x, y) in the time domain.

[0114] S4. Generate a dynamic session key based on the confusion key pool, encrypt the steganography file transport layer, and embed the dynamic key generation parameters.

[0115] Obtain the current timestamp and the user's dynamic operation mode, and generate a unique device fingerprint identifier based on the hardware characteristics of the sender device; use a hash function and an encryption algorithm to confuse the obtained current timestamp, the user's dynamic operation mode, and the generated unique device fingerprint identifier to generate a dynamic key seed, and the expression is:

[0116] Seed key =HMAC-SHA256(T current ||F device ||B user ,K static );

[0117] Among them, Seed key represents the dynamic key seed, T current represents the current timestamp, B user represents the user's dynamic operation mode, F device represents the fingerprint identifier of the unique device, HMAC represents the hash-based message authentication code, SHA256 represents mapping input data of any length to a fixed-length 256-bit output value, and K static represents a secure static root key, stored at the sender and receiver, and used as the key for HMAC;

[0118] Use a key derivation function to extract a pseudo-random key from the dynamic key seed, and the expression is:

[0119] PRK=HMAC-SHA256(Seed key ,K static );

[0120] Among them, PRK represents the pseudo-random key;

[0121] Convert the pseudo-random key into a dynamic session key of the required length, and the expression is:

[0122] K session = HKDF-Expand(PRK, info, L);

[0123] Where K session represents the dynamic session key, HKDF-Expand represents generating a key of the required length from a pseudorandom key, info represents optional context information used to label the purpose of the session key, and L represents the length of the required session key;

[0124] Initiate a transport layer encryption session, use the generated dynamic session key to transmit and encrypt the steganographic files in the steganographic index table through the transport layer encryption channel; during the transmission process, embed the dynamic key seed in the dynamic key in each transport header.

[0125] S5. The receiving end generates a session key based on the transport packet header, decrypts the transport layer data to extract the steganographic file and decrypts it.

[0126] After receiving the encrypted steganographic file, the receiving end parses the dynamic key seed in the transport packet header and generates a dynamic session key through the same logic and key pool as the sending end; uses the generated dynamic session key to decrypt the encrypted transport layer data, extracts the steganographic file; extracts the embedded steganographic index table from the decrypted steganographic file, and based on the steganographic index table, loads the corresponding steganographic carrier file, and extracts the metadata of the carrier file from the steganographic carrier file; uses the least significant bit de-embedding algorithm to extract the shard data from the pixel data; uses the inverse discrete cosine transform algorithm to extract the shard data from the frequency domain coefficients; uses the shard identifier to verify whether the extracted shard data is complete and correct; according to the sensitivity label of the shard, selects the corresponding decryption algorithm to decrypt the shard data one by one; compares the decrypted shard data with the shard identifier to verify the integrity of the decrypted data.

[0127] S6. Recombine the decrypted and restored shard data into a complete file in the order of the identifiers, and verify whether the file is damaged through integrity verification to obtain the verification result.

[0128] Extract all the shard data from the decrypted shard data and perform ascending sorting using the quicksort algorithm; create a file buffer, write the sorted shard data into the buffer in sequence to obtain the recombined file; use the SHA-256 algorithm to calculate the hash value of the buffer of the recombined file to generate the verification value of the complete file; compare the generated verification value of the complete file with the original file verification value to obtain the verification result; when the verification passes, write the buffer of the recombined file to the disk to generate the final original file; when the verification fails, return an error message and prompt the user to re-transmit the relevant shards.

[0129] This embodiment also provides a file transfer protection system based on a multiple encryption algorithm, including:

[0130] A file preprocessing module that selects target files to be transferred and performs preprocessing to generate file shards; a shard encryption module that analyzes the sensitivity of each file shard and performs hierarchical encryption processing to obtain a set of encrypted shards; a steganography embedding module that selects a steganography carrier file and embeds the encrypted shards into the carrier file to generate a steganography index table; a key generation module that generates a dynamic session key based on a confusion key pool, encrypts the steganographic file transfer layer, and embeds dynamic key generation parameters; a decryption and extraction module that the receiving end generates a session key according to the transmission packet header, decrypts the transmission layer data to extract the steganographic file and decrypts it; a file recombination module that recombines the decrypted and restored shard data into a complete file in the order of identifiers, and verifies whether the file is damaged through integrity verification to obtain a verification result.

[0131] This embodiment also provides a computer device applicable to the case of a file transfer protection method based on a multiple encryption algorithm, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the file transfer protection method based on a multiple encryption algorithm proposed in the above embodiment.

[0132] This computer device may be a terminal, and this computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of this computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of this computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of this computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0133] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the file transfer protection method based on multiple encryption algorithms proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0134] In summary, the present invention ensures the standardization of the transmitted file through format verification and size detection, and performs fragmentation processing on large files, enhancing the support ability for large-scale files; uses a sensitivity analysis mechanism to perform dynamic hierarchical encryption on the fragmented content, optimizing the encryption efficiency while improving security; realizes the efficient embedding of fragmented data and the generation of a steganographic index table by dynamically matching steganographic carrier files, ensuring the concealment and adaptability during the transmission process; generates a dynamic session key using a confusion key pool and dynamically embeds key generation parameters, enhancing the randomness and anti-attack ability of the session key; uses a dynamic key to restore the steganographic file and extract fragmented data, and selects the corresponding decryption algorithm through sensitivity marking, ensuring the efficiency and accuracy of data decryption; reorganizes the fragmented data through quick sorting to verify whether the file has been tampered with or lost, ensuring the integrity and reliability of the transmitted file.

[0135] Embodiment 2, referring to Table 1, is the second embodiment of the present invention. To further verify the technical solution of the present invention, experimental simulation data of the file transfer protection method based on multiple encryption algorithms are given.

[0136] To verify the effectiveness of the file transfer protection method of the present invention, a target test file (with a size of 45MB, a format of PDF, named test_file.pdf) is selected as the test object to conduct a simulation experiment of the file transfer process. The experiment is carried out in six steps: file preprocessing, fragmentation, encryption, steganography, transmission, and data recovery and integrity verification.

[0137] First, the test performed a format check on the file. The file header information was recognized as PDF format, which conforms to the supported file type set, and entered the file size detection phase. According to the set sharding threshold (10MB), the file size exceeded the threshold, so sharding processing was required. Through calculation, test_file.pdf was divided into 5 shards (each shard is 10MB, and the size of the last shard is 5MB). Subsequently, the SHA-256 algorithm was used to calculate a unique identifier for each shard, and the shard order and size information were recorded to generate a shard set, as shown in Table 1 below:

[0138] Table 1 Shard Set Data Table

[0139]

[0140] Then, a sensitivity analysis was performed on each shard in the shard set. According to the sensitive keyword list (such as "confidential", "secret", etc.) and the sensitivity level threshold (S th ) configured by the user, a sensitivity score was calculated for each shard. In the experiment, the shard sensitivity score range was 0.2 - 0.8, among which 3 shards with a score greater than 0.6 were marked as highly sensitive shards and were encrypted using the elliptic curve encryption algorithm and AES-256 double encryption; the remaining 2 low-sensitivity shards were encrypted using AES-128 single encryption, as shown in Table 2 below:

[0141] Table 2 Sensitivity Results Table

[0142]

[0143]

[0144] The expression for the sensitivity score is:

[0145]

[0146] The experimental data is set as follows,

[0147] Shard information:

[0148] Shard size: The size of each shard is 10MB (the last shard is 5MB).

[0149] Converted to bytes:

[0150] Each 10MB shard: 10 × 1024 × 1024 = 10,485,760 bytes

[0151] The 5th shard: 5 × 1024 × 1024 = 5,242,880 bytes

[0152] Sensitive keyword list:

[0153] Keywords: ["confidential", "secret", "classified", "private"]

[0154] Weight (w): [0.4, 0.3, 0.2, 0.1] (set according to keyword sensitivity)

[0155] Number of occurrences of keywords in sharded content (O j ):

[0156] Suppose the number of occurrences of sensitive keywords in each sharded content is as follows:

[0157] Segment number confidential secret classified private 1 12 8 5 3 2 5 4 8 1 3 15 12 8 6 4 10 8 6 4 5 3 2 1 1

[0158] Taking shard 1 as an example, the calculation process is as follows:

[0159]

[0160] The others are calculated in the same way as shard 1 to obtain the final result.

[0161] Load the steganographic carrier file library, dynamically match the appropriate carrier file according to the size of each shard. In the experiment, 2 shards are embedded in JPEG picture carriers, 3 shards are embedded in MP3 audio carriers. The LSB steganographic algorithm is used to embed in the picture carrier, and the DCT steganographic algorithm is used to embed in the audio carrier. Finally, a steganographic index table is generated to record the embedding information. In the transmission stage, a dynamic session key is generated based on the confusion key pool, and the HMAC-SHA256 algorithm is used to generate a dynamic key seed, which is further derived into a dynamic session key. The steganographic file and the steganographic index table are transmitted to the receiving end through the TLS encryption layer, and the dynamic key generation parameters are embedded in the message header. The receiving end parses the dynamic key seed in the transmission message header to generate a dynamic session key, decrypts the data in the transport layer to extract the steganographic file and the steganographic index table. Through the LSB and DCT reverse embedding algorithms, the encrypted shards are extracted from the carrier file and decrypted according to the shard metadata information. Finally, the quicksort algorithm is used to reorganize into a complete file in the order of shard identifiers, and the SHA-256 hash value is used to verify the integrity and verify the consistency between the reorganized file and the original file. The experimental results show that the file is successfully restored and the data is complete, as shown in Table 3 below:

[0162] Table 1 Record Table of Steganographic Embedding and Transmission Process

[0163]

[0164]

[0165] From the above table, it can be seen that the steganographic embedding success rate is 100% (all shards are successfully embedded in the carrier); the extraction success rate is 80% (4 out of 5 shards are successfully extracted, and 1 is partially successful); the integrity verification pass rate is 60% (the recombined data of 3 shards is consistent with the original data).

[0166] Failed to extract shard 2:

[0167] You can try to re-transmit this shard or recover the lost data through redundant coding.

[0168] Partially successful extraction of shard 3:

[0169] You can try to repair the partially lost steganographic data by combining the shard metadata information and the error recovery algorithm.

[0170] Overall file recovery:

[0171] Since the data of some shards is incomplete, the final file may require manual intervention or re-transmission of some data to complete the recovery.

[0172] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A file transfer protection method based on multiple encryption algorithms, characterized in that: including, select the target file to be transmitted and perform preprocessing to generate file shards; analyze the sensitivity of each file shard and perform hierarchical encryption processing to obtain a set of encrypted shards; select a steganographic carrier file, embed the encrypted shards into the carrier file, and generate a steganographic index table; generate a dynamic session key based on the obfuscated key pool, encrypt the steganographic file transport layer, and embed the dynamic key generation parameters; the receiving end generates a session key according to the transport message header, decrypts the transport layer data to extract the steganographic file, and extracts and decrypts the shards according to the steganographic index table; reassemble the decrypted and restored shard data into a complete file in the order of the identifiers, and verify whether the file is damaged through integrity verification to obtain the verification result.

2. The file transfer protection method based on multiple encryption algorithms according to claim 1, characterized in that: Select the target file to be transmitted and perform preprocessing to generate file shards, including the following steps, The user selects the target file to be transmitted, and performs format verification on the target file to determine whether it belongs to the supported file type set; Detect the size of the target file based on the format verification result; For the detected oversized file, slice it according to a fixed size to determine the total number of slices required; According to the determined total number of slices, extract data segments from the file in sequence to generate a set of slices; Assign a unique identifier to each slice in the slice set, and record the slice order and size.

3. The file transfer protection method based on multiple encryption algorithms according to claim 2, characterized in that: Analyze the sensitivity of each file shard and perform hierarchical encryption processing to obtain a set of encrypted shards, including the following steps, Load the sensitive keyword list and the sensitivity level threshold configured by the user from the sensitivity rule database ; Perform keyword matching and context analysis on the content of each slice in the slice set, calculate the sensitivity score of the slice, and the expression is: ; Among them, represents the sensitivity score of the th shard, represents the shard index, represents the sensitive keyword index, represents the total number of sensitive keywords, represents the weight of the th sensitive keyword, represents the total number of bytes of the th shard, ) represents the number of times the th sensitive keyword appears in the th shard; Classify the slices according to the sensitivity score; When , mark the shard as a highly sensitive shard. When , mark the shard as a low-sensitivity shard; For the slices marked as highly sensitive, perform double encryption using the elliptic curve encryption algorithm and the AES-256 symmetric encryption method; For the slices marked as low sensitive, perform single-layer encryption using AES-128 symmetric encryption; Pack the encrypted highly sensitive slices and low sensitive slices, add encryption tags and slice metadata information to each encrypted slice to obtain a set of encrypted slices.

4. The file transfer protection method based on multiple encryption algorithms according to claim 3, characterized in that: Select a steganographic carrier file, embed the encrypted shards into the carrier file, and generate a steganographic index table including the following steps, Load the steganographic carrier file library, extract the metadata of each file in the carrier file library, and generate a carrier information table; Extract the size of each encrypted slice from the set of encrypted slices, and dynamically match the carrier file in the carrier information table for each encrypted slice according to the carrier allocation rule; For each encrypted slice and its matched carrier file, use the steganographic algorithm to embed the encrypted slice into a specific position of the carrier file; After steganography is completed, generate a steganographic index table for each embedded slice.

5. The file transfer protection method based on multiple encryption algorithms according to claim 4, characterized in that: Generate a dynamic session key based on the obfuscated key pool, encrypt the steganographic file transport layer, and embed the dynamic key generation parameters, including the following steps, Obtain the current timestamp and the user's dynamic operation mode, and generate a unique device fingerprint identifier based on the hardware characteristics of the sending device; Use a hash function and an encryption algorithm to obfuscate the obtained current timestamp, the user's dynamic operation mode, and the generated unique device fingerprint identifier to generate a dynamic key seed, and the expression is: ; Among them, represents the dynamic key seed, represents the current timestamp, represents the user's dynamic operation mode, represents the fingerprint identifier of the unique device, represents the hash-based message authentication code, represents mapping input data of any length to a fixed-length 256-bit output value, represents the secure static root key; Extract a pseudo-random key from the dynamic key seed using a key derivation function, with the expression: ; Among them, represents a pseudo-random key; Convert the pseudo-random key into a dynamic session key of the required length, with the expression: ; Among them, represents the dynamic session key, represents generating a key of the required length from the pseudo-random key, represents optional context information, represents the length of the required session key; Initiate a transport layer encryption session, use the generated dynamic session key, and transmit and encrypt the steganographic files in the steganographic index table through the transport layer encryption channel; During the transmission process, embed the dynamic key seed in the dynamic key in each transport header.

6. The file transfer protection method based on multiple encryption algorithms according to claim 5, characterized in that: The receiving end generates a session key based on the transport packet header, decrypts the transport layer data to extract the steganographic file and decrypts it, including the following steps, After receiving the encrypted steganographic file, the receiving end parses the dynamic key seed in the transport packet header and generates a dynamic session key through the same logic and key pool as the sending end; Use the generated dynamic session key to decrypt the encrypted transport layer data and extract the steganographic file; Extract the embedded steganographic index table from the decrypted steganographic file, and based on the steganographic index table, load the corresponding steganographic carrier file and extract the metadata of the carrier file from the steganographic carrier file; Use the least significant bit inverse embedding algorithm to extract the shard data from the pixel data; Extract the shard data from the frequency domain coefficients through the inverse discrete cosine transform algorithm; According to the sensitivity markings of the shards, select the corresponding decryption algorithm and decrypt the shard data one by one; Compare the decrypted shard data with the shard identifier to verify the integrity of the decrypted data.

7. The file transfer protection method based on multiple encryption algorithms according to claim 6, characterized in that: Recombine the decrypted and restored shard data into a complete file in the order of the identifiers, and verify whether the file is damaged through integrity verification, and obtain the verification result, including the following steps, Extract all the shard data from the decrypted shard data and perform ascending sorting using the quicksort algorithm; Create a file buffer, write the sorted shard data into the buffer in sequence to obtain the recombined file; Use the SHA-256 algorithm to calculate the hash of the buffer of the recombined file to generate the check value of the complete file; Compare the generated check value of the complete file with the original file check value to obtain the verification result; When the verification passes, write the buffer of the recombined file to the disk to generate the final original file; When the verification fails, return an error message and prompt the user to re-transmit the relevant shards.

8. A file transfer protection system based on multiple encryption algorithms, based on the file transfer protection method based on multiple encryption algorithms according to any one of claims 1 to 7, characterized in that: Including, A file preprocessing module that selects the target file to be transmitted and performs preprocessing to generate file shards; A shard encryption module that analyzes the sensitivity of each file shard and performs hierarchical encryption processing to obtain a set of encrypted shards; A steganographic embedding module that selects a steganographic carrier file, embeds the encrypted shards into the carrier file, and generates a steganographic index table; A key generation module that generates a dynamic session key based on a confusion key pool, encrypts the steganographic file transport layer, and embeds dynamic key generation parameters; A decryption and extraction module that the receiving end generates a session key based on the transport packet header, decrypts the transport layer data to extract the steganographic file, and extracts and decrypts the shards according to the steganographic index table; A file recombination module that recombines the decrypted and restored shard data into a complete file in the order of the identifiers, and verifies whether the file is damaged through integrity verification to obtain the verification result.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, the steps of the file transfer protection method based on multiple encryption algorithms according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the file transfer protection method based on multiple encryption algorithms according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Data sharing method and device, computer equipment, chip and readable storage medium

    CN117725619A

  • Encryption method and related equipment

    CN119129003A