File Encryption Method, Device, Electronic Device, and Computer-Readable Medium
Through multi-layer encryption processing for audio and video, images and text files, combined with file history visits and user identity information, a file re-encryption key is generated, which solves the problem of privacy data leakage caused by a single encryption algorithm, and realizes file transfer security and resource conservation.
Patent Information
- Application Number
- CN202411965712.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2044-12-30
AI Technical Summary
In the prior art, when a file is encrypted through a single encryption algorithm, if the file key is transmitted and leaked, all files using the same encryption algorithm have problems of privacy data leakage, resulting in privacy data leakage of internal files of the enterprise and reducing the security of file transmission.
The audio and video chaotic mapping algorithm and audio and video encryption confrontation model are used to encrypt audio and video files, the image files are encrypted in a mess, the text documents are encrypted in privacy, and the file priority is determined based on the file historical visits, the department and user identity information, and the file re-encryption key is generated, the file is ring signature processing and re-encrypted, and finally compressed and sent to the target terminal for decryption.
It improves the security during file sending and transmission, reduces the waste of transmission resources, ensures the encryption effect and security of different types of files, and reduces the risk of privacy data leakage.
Smart Images

Figure CN119885231B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technology, and more particularly to file encryption methods, devices, electronic devices, and computer-readable media. Background Art
[0002] With the continuous development of mobile communication technology and the increasing business needs of enterprises, private files and internal files within enterprises need to be frequently transmitted. How to ensure the security of transmitted files and avoid data leakage of private data during the transmission process, as well as the search and matching of encryption keys during the file encryption process, have increasingly become issues of growing concern. For file encryption, the commonly used method is: using a single encryption algorithm to generate a file encryption key. Then, through the file encryption key, the file to be encrypted is encrypted for transmission and the storage of the file encryption key.
[0003] However, it has been found in practice that when encrypting files in the above manner, there is often the following technical problem 1: When encrypting a file using a single encryption algorithm, if the file key is leaked, all files encrypted using the same encryption algorithm have the problem of private data leakage, resulting in the leakage of private data of internal enterprise files and reducing the security of file transmission.
[0004] The above information disclosed in this background art section is only used to enhance the understanding of the background of the concept of the present disclosure. Therefore, it may include information that does not form the prior art known to ordinary technicians in this field in this country. Summary of the Invention
[0005] The content part of the present disclosure is used to briefly introduce concepts, which will be described in detail in the following detailed implementation part. The content part of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0006] Some embodiments of the present disclosure propose file encryption methods, devices, electronic devices, and computer-readable media to solve one or more of the technical problems mentioned in the above background art section.
[0007] In a first aspect, some embodiments of the present disclosure provide a file encryption method, including: obtaining information of a file to be encrypted, where the information of the file to be encrypted includes at least one of the following: the historical access volume of the file, the information of the department to which the file belongs, and the identity information of the user to which the file belongs; in response to determining that there is an audio-visual file in the file to be encrypted corresponding to the information of the file to be encrypted, extracting data from the audio-visual coding information corresponding to the audio-visual file to obtain audio-visual extraction information; inputting the audio-visual extraction information into an audio-visual encryption model to obtain an audio-visual encrypted file, where the audio-visual encryption model includes: an audio-visual chaotic mapping algorithm and an audio-visual encryption adversarial model; in response to determining that there is an image file in the file to be encrypted, performing scrambling and diffusion encryption processing on the image file to obtain an image encrypted file; in response to determining that there is a text document in the file to be encrypted, performing privacy encryption processing on the privacy data included in the text document to obtain a text encrypted file; determining the file priority of the file to be encrypted according to the historical access volume of the file, the identity information of the user to which the file belongs, and the information of the department to which the file belongs; determining the file re-encryption key of the file to be encrypted according to the historical access volume of the file, the file priority, and the encrypted file, and storing the file re-encryption key in a key storage server, where the encrypted file may be a file composed of the audio-visual encrypted file, the image encrypted file, and the text encrypted file; performing ring signature processing on the file to be encrypted to obtain file signature information; performing re-encryption processing on the file signature information and the encrypted file according to the file re-encryption key to obtain a re-encrypted file; compressing and sending the re-encrypted file to a target terminal for the target terminal to perform search matching based on user identity information in the key storage server to obtain a file matching key for decryption processing to obtain a decrypted file.
[0008] Second aspect, some embodiments of the present disclosure provide a file encryption device, including: an acquisition unit configured to acquire information of a file to be encrypted, where the information of the file to be encrypted includes at least one of the following: the historical access volume of the file, the information of the department to which the file belongs, and the identity information of the user to which the file belongs; a data extraction unit configured to, in response to determining that there is an audio-visual file in the file to be encrypted corresponding to the information of the file to be encrypted, perform data extraction on the audio-visual coding information corresponding to the audio-visual file to obtain audio-visual extraction information; an input unit configured to input the audio-visual extraction information into an audio-visual encryption model to obtain an audio-visual encrypted file, where the audio-visual encryption model includes: an audio-visual chaotic mapping algorithm and an audio-visual encryption adversarial model; a scrambling and diffusion encryption unit configured to, in response to determining that there is an image file in the file to be encrypted, perform scrambling and diffusion encryption processing on the image file to obtain an image encrypted file; a privacy encryption unit configured to, in response to determining that there is a text document in the file to be encrypted, perform privacy encryption processing on the privacy data included in the text document to obtain a text encrypted file; a first determination unit configured to determine the file priority of the file to be encrypted according to the historical access volume of the file, the identity information of the user to which the file belongs, and the information of the department to which the file belongs; a second determination unit configured to determine the file re-encryption key of the file to be encrypted according to the historical access volume of the file, the file priority, and the encrypted file, and store the file re-encryption key in a key storage server, where the encrypted file may be a file composed of the audio-visual encrypted file, the image encrypted file, and the text encrypted file; a ring signature unit configured to perform ring signature processing on the file to be encrypted to obtain file signature information; a re-encryption unit configured to perform re-encryption processing on the file signature information and the encrypted file according to the file re-encryption key to obtain a re-encrypted file; a sending unit configured to compress and send the re-encrypted file to a target terminal for the target terminal to perform search matching based on user identity information in the key storage server to obtain a file matching key for decryption processing to obtain a decrypted file.
[0009] Third aspect, some embodiments of the present disclosure provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method described in any implementation manner of the first aspect.
[0010] Fourth aspect, some embodiments of the present disclosure provide a computer-readable medium storing a computer program thereon, where when the computer program is executed by a processor, it implements the method described in any implementation manner of the first aspect.
[0011] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: The file encryption method of some embodiments of the present disclosure can encrypt each file with a unique key and compress and send it, which can improve the security during the file sending and transmission process while reducing the waste of transmission resources. Specifically, the leakage of private data of relevant enterprise internal files and the reduction of file transmission security are caused by: encrypting files through a single encryption algorithm. If the file key is leaked during transmission, all files encrypted with the same encryption algorithm have the problem of private data leakage, resulting in the leakage of private data of enterprise internal files and the reduction of file transmission security. Based on this, the file encryption method of some embodiments of the present disclosure can first, obtain the information of the file to be encrypted, where the above-mentioned information of the file to be encrypted includes at least one of the following: the historical access volume of the file, the information of the department to which the file belongs, and the identity information of the user to whom the file belongs. Here, the information of the file to be encrypted facilitates subsequent file encryption. Secondly, in response to determining that there is an audio-video file in the file to be encrypted corresponding to the above-mentioned information of the file to be encrypted, extract data from the audio-video coding information corresponding to the above-mentioned audio-video file to obtain audio-video extraction information. Here, important information in the audio-video can be extracted, which can reduce the amount of data to be encrypted. Thirdly, input the above-mentioned audio-video extraction information into the audio-video encryption model to obtain an audio-video encrypted file, where the above-mentioned audio-video encryption model includes: an audio-video chaotic mapping algorithm and an audio-video encryption adversarial model. Here, the audio-video encryption model can improve the randomness and irregularity of the generated encryption key through deep learning methods, and encrypting the audio-video extraction information with a smaller amount of data can improve the encryption efficiency, enhance the encryption effect, and reduce the encryption operation load of the system. Then, in response to determining that there is an image file in the above-mentioned file to be encrypted, perform scrambling and diffusion encryption processing on the above-mentioned image file to obtain an image encrypted file. Here, it can be more suitable for the encryption of image files, improve the encryption effect, and be more targeted. Subsequently, in response to determining that there is a text document in the above-mentioned file to be encrypted, perform privacy encryption processing on the private data included in the above-mentioned text document to obtain a text encrypted file. Here, it can be more suitable for the encryption of text documents, improve the encryption effect, be more targeted, and reduce the amount of encrypted data, thereby improving the encryption efficiency. Then, according to the above-mentioned historical access volume of the file, the identity information of the user to whom the file belongs, and the information of the department to which the file belongs, determine the file priority of the above-mentioned file to be encrypted. Here, it can better distinguish different files, so as to be more in line with encrypting each file with a unique key and improve the security of different files to be encrypted. After that, according to the above-mentioned historical access volume of the file, the above-mentioned file priority, and the encrypted file, determine the file re-encryption key of the above-mentioned file to be encrypted, and store the above-mentioned file re-encryption key in the key storage server, where the above-mentioned encrypted file can be a file composed of the above-mentioned audio-video encrypted file, the above-mentioned image encrypted file, and the above-mentioned text encrypted file.Here, the security of the file re-encryption key can be enhanced, and it is convenient for subsequent encryption processing. Then, ring signature processing is performed on the above-mentioned file to be encrypted to obtain file signature information. Here, the integrity of the file can be verified, further enhancing the security of the file and facilitating the monitoring of the file during the transmission process. Then, based on the above-mentioned file re-encryption key, re-encryption processing is performed on the above-mentioned file signature information and the above-mentioned encrypted file to obtain a re-encrypted file. Here, double encryption and targeted encryption for different types of files can further enhance the security of the file and the security of sending and transmission. Finally, the above-mentioned re-encrypted file is compressed and sent to the target terminal for the above-mentioned target terminal to perform a search and match based on the user identity information in the above-mentioned key storage server to obtain a file matching key for decryption processing to obtain the decrypted file. Here, compressed sending can reduce the amount of data sent, reduce the waste of transmission resources, and the search for access control based on the search and match of user identity information can enhance the security of the file re-encryption key. Thus, it can be seen that this file encryption method can perform one-time encryption and compressed sending for the file to be encrypted, enhancing the security during the file sending and transmission process while reducing the waste of transmission resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In conjunction with the accompanying drawings and referring to the following specific embodiments, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the elements and components are not necessarily drawn to scale.
[0013] Figure 1 is a flowchart of some embodiments of a file encryption method according to the present disclosure;
[0014] Figure 2 is a schematic structural diagram of some embodiments of a file encryption apparatus according to the present disclosure;
[0015] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not used to limit the protection scope of the present disclosure.
[0017] In addition, it should be noted that for ease of description, only parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.
[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions executed by these devices, modules or units or their interdependent relationships.
[0019] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0021] The present disclosure will be described in detail below with reference to the drawings and in combination with embodiments.
[0022] Figure 1 Flow 100 of some embodiments of a file encryption method according to the present disclosure is shown. The file encryption method includes the following steps:
[0023] Step 101, obtain information of the file to be encrypted.
[0024] In some embodiments, the execution subject (such as an electronic device) of the above file encryption method can obtain the information of the file to be encrypted through a wired connection method or a wireless connection method. Among them, the above information of the file to be encrypted includes at least one of the following: the historical access volume of the file, the information of the department to which the file belongs, and the identity information of the user to whom the file belongs. Among them, the above information of the file to be encrypted can be the information of the file waiting for encrypted transmission. The above historical access volume of the file can be the number of times the file to be encrypted is sent for access before the current time. The above information of the department to which the file belongs can be the information of the department of the enterprise to which the network address sending the file to be encrypted belongs. For example, the above information of the department to which the file belongs can be the development and testing department. The above identity information of the user to whom the file belongs can be the information representing the identity of the user sending the file to be encrypted. For example, the above identity information of the user to whom the file belongs can be the employee number or the employee title.
[0025] Step 102, in response to determining that there is an audio-visual file in the file to be encrypted corresponding to the information of the file to be encrypted, perform data extraction on the audio-visual coding information corresponding to the audio-visual file to obtain audio-visual extraction information.
[0026] In some embodiments, the above-mentioned execution entity may, in response to determining that there is an audio-visual file in the file to be encrypted corresponding to the above-mentioned file information to be encrypted, extract data from the audio-visual coding information corresponding to the above-mentioned audio-visual file to obtain audio-visual extraction information. Among them, the above-mentioned audio-visual coding information may be the information stored by audio-visual coding. For example, if the above-mentioned audio-visual file is an MP4 (Moving Picture Experts Group 4) file, the above-mentioned audio-visual coding information may be the information in the samples in the chunks stored in the Box of the MP4 storage format. The above-mentioned audio-visual extraction information may be the privacy information located in the above-mentioned audio-visual coding information and the information that needs to be encrypted.
[0027] In some optional implementation manners of some embodiments, the above-mentioned extraction of data from the audio-visual coding information corresponding to the above-mentioned audio-visual file to obtain audio-visual extraction information may include the following steps:
[0028] First step, determine the audio-visual coding header information of each audio-visual frame included in the above-mentioned audio-visual coding information to obtain an audio-visual coding header information set. Among them, the above-mentioned audio-visual coding header information may be the information used to judge the importance and type of the audio-visual frame. For example, the above-mentioned audio-visual coding header information may be the NALU Header.
[0029] Second step, perform a bitwise AND operation on each audio-visual coding header information in the above-mentioned audio-visual coding header information set and a preset coding value to obtain an audio-visual frame coding type set of each of the above-mentioned audio-visual frames. Among them, the audio-visual frame coding types in the above-mentioned audio-visual frame coding type set may represent the coding method of the audio-visual during the coding process in a binary manner. The above-mentioned coding method may include: an intra-coded frame based on intra-image coding, a forward prediction frame based on forward coding of an intra-coded frame, and a bidirectional interpolation frame based on coding before and after an intra-coded frame and a forward prediction coded frame. The above-mentioned preset coding value may be a preset hexadecimal value. For example, the above-mentioned preset coding value may be 0x1F. In practice, the above-mentioned execution entity may perform a bitwise AND operation on the 8-bit binary sequence included in each audio-visual coding header information in the above-mentioned audio-visual coding header information set and the preset coding value to generate information of the lower 5 bits of an 8-bit binary number as the audio-visual frame coding type to obtain the audio-visual frame coding type. Among them, the lower 5 bits of the above-mentioned 8-bit binary number may represent the coding method of the audio-visual frame and the type of the audio-visual frame.
[0030] Third step, screen out at least one audio-visual coding header information corresponding to the audio-visual frame coding type being a key frame from the above-mentioned audio-visual coding header information set. Among them, the above-mentioned key frame may be an intra-coded frame.
[0031] Fourth, determine the audio-visual payload information sets corresponding to the above-mentioned audio-visual frames. Among them, the audio-visual payload information in the above-mentioned audio-visual payload information sets can be information recording the actual data of the audio-visual frames and located after the above-mentioned audio-visual coding header information. For example, the above-mentioned audio-visual payload information can include, but is not limited to, at least one of the following: prediction residual, transform coefficient, and motion vector difference.
[0032] Fifth, extract coding information from each audio-visual payload information in the above-mentioned audio-visual payload information sets to obtain an audio-visual payload coding information set. Among them, the audio-visual payload coding information in the above-mentioned audio-visual payload coding information sets can be parameter information that is indispensable in the coding transmission of the audio-visual file and does not affect the transmission of the audio-visual file and is located in the audio-visual payload information. The above-mentioned audio-visual payload coding information set can include: motion vector difference, transform coefficient, and non-zero transform coefficient amplitude.
[0033] Sixth, determine the audio-visual extraction information by using the above-mentioned at least one audio-visual coding header information and the above-mentioned audio-visual payload coding information set.
[0034] Step 103, input the audio-visual extraction information into the audio-visual encryption model to obtain an audio-visual encrypted file.
[0035] In some embodiments, the above-mentioned execution subject can input the above-mentioned audio-visual extraction information into the audio-visual encryption model to obtain an audio-visual encrypted file. Among them, the above-mentioned audio-visual encryption model includes: an audio-visual chaotic mapping algorithm and an audio-visual encryption adversarial model. Among them, the above-mentioned audio-visual encrypted file can be a file obtained by encrypting the above-mentioned audio-visual extraction information. The above-mentioned audio-visual encryption model can be a model that encrypts the input audio-visual extraction information and outputs the encrypted audio-visual. The above-mentioned audio-visual chaotic mapping algorithm can be a two-dimensional mapping algorithm for generating an encryption key for the audio-visual extraction information. For example, the above-mentioned audio-visual chaotic mapping algorithm can be a two-dimensional Henon mapping algorithm. The above-mentioned audio-visual encryption adversarial model can be a generative adversarial network that removes the periodicity of the encryption key generated by the above-mentioned audio-visual chaotic mapping algorithm and improves the randomness of the key. The above-mentioned audio-visual encryption adversarial model can include: a chaotic sequence generator and a chaotic sequence discriminator. The above-mentioned chaotic sequence generator can be a deconvolution neural network or a transposed convolution neural network that extracts the feature information of the chaotic sequence output by the input audio-visual chaotic mapping algorithm and generates a similar numerical sequence through the input random noise. The above-mentioned chaotic sequence discriminator can be a convolutional neural network that judges the difference between the numerical sequence output by the chaotic sequence generator and the sequence generated by the audio-visual chaotic mapping algorithm.
[0036] In some optional implementation manners of some embodiments, the step of inputting the above audio - video extraction information into the audio - video encryption model to obtain the audio - video encrypted file may include the following steps:
[0037] In the first step, input the initial parameter value set into the above audio - video chaotic mapping algorithm to obtain an audio - video chaotic sequence. Among them, the initial parameter values in the above initial parameter value set are randomly determined values. Among them, the audio - video chaotic sequences in the above audio - video chaotic sequence set may be a sequence composed of multiple integer values that are periodic and randomly generated. For example, the above audio - video chaotic sequence set may be (x1, x2, y1, y2). The above initial parameter value set includes: a first initial parameter value and a second initial parameter value. The value range of the above first initial parameter value may be [-1.5, 1.5]. The value range of the above second initial parameter value may be [-0.4, 0.4]. The above audio - video chaotic mapping algorithm may be x n may represent the first initial parameter value. y n may represent the second initial parameter value. a may represent a value that controls the non - linear degree of the audio - video chaotic mapping algorithm, and its value range may be [2.17, 2.36] ∪ [2.38, 3.89] ∪ [3.91, 4.02] ∪ [4.41, ∞]. b may represent a value that controls the dynamic change degree of the audio - video chaotic mapping algorithm, and its value is 0.3.
[0038] In the second step, input the above audio - video chaotic sequence into the above audio - video encryption adversarial model to obtain an audio - video adversarial sequence set. Among them, the above audio - video encryption adversarial model may include: a generator and a discriminator. The above generator may be a convolutional neural network model that performs feature learning on the input audio - video chaotic sequence and removes the periodicity in the audio - video chaotic sequence. The above generator may include: a two - dimensional convolutional layer, a batch normalization layer, a residual network with a leaky rectified linear unit (LeakyReLU) activation function, and a convolutional layer with a hyperbolic tangent (Tanh) activation function. The above discriminator may be used to judge the error between the random sequence generated by the above generator and the random sequence generated by the above audio - video chaotic mapping algorithm, that is, whether it can't distinguish the sequence generated by the generator and the sequence generated by the audio - video chaotic mapping algorithm. The above discriminator may be an encoder composed of a variational auto - encoder and a maximum mean discrepancy function.
[0039] In the third step, perform a fusion process on the above audio - video adversarial sequence set to obtain a fused audio - video sequence. Among them, the above fused audio - video sequence may be a sequence obtained by performing a weighted sum process on the above audio - video adversarial sequence set.
[0040] Step 4: Based on the above-mentioned fused audio-video sequence, encrypt each audio-video coding header information in the above-mentioned at least one audio-video coding header information to generate key frame encrypted header information, and obtain a set of key frame encrypted header information. Among them, the key frame encrypted header information in the above-mentioned set of key frame encrypted header information can be information obtained by performing bit-level mask replacement on the header information of the audio-video frame that is an intra-coded frame.
[0041] As an example, the above-mentioned execution entity can perform bit-level mask replacement processing based on DNA (DeoxyriboNucleic Acid) coding on each audio-video coding header information in the above-mentioned at least one audio-video coding header information according to the above-mentioned fused audio-video sequence, to obtain a set of key frame encrypted header information.
[0042] Step 5: Encrypt the above-mentioned set of audio-video payload coding information to obtain a set of encrypted audio-video payload information. In practice, the above-mentioned execution entity can first perform binarization processing on each audio-video payload coding information in the above-mentioned set of audio-video payload coding information by using the K-order Columbus exponent and the TR code, to obtain a set of binarized audio-video payload coding information. Then, perform exclusive OR encryption processing on each audio-video payload binarized coding information in the above-mentioned set of audio-video adversarial sequences and the above-mentioned set of binarized audio-video payload coding information, to obtain a set of encrypted audio-video payload information.
[0043] Step 6: Replace the corresponding coding information in the above-mentioned audio-video coding information with the above-mentioned set of encrypted audio-video payload information and the above-mentioned set of key frame encrypted header information, to obtain the replaced audio-video coding information, which is used as the encrypted audio-video file.
[0044] In some optional implementation manners of some embodiments, the above-mentioned set of audio-video adversarial sequences includes: a first audio-video adversarial sequence, a second audio-video adversarial sequence, a third audio-video adversarial sequence, and a fourth audio-video adversarial sequence. Among them, the above-mentioned first audio-video adversarial sequence, second audio-video adversarial sequence, third audio-video adversarial sequence, and fourth audio-video adversarial sequence can be different sequences generated by the above-mentioned audio-video encryption model.
[0045] Optionally, the above-mentioned fusion processing of the above-mentioned set of audio-video adversarial sequences to obtain a fused audio-video sequence may include the following steps:
[0046] Step 1: For each first audio-video adversarial value in the above-mentioned first audio-video adversarial sequence, perform the following determination steps:
[0047] Sub-step 1: Determine the second audio-video confrontation value, the third audio-video confrontation value, and the fourth audio-video confrontation value corresponding to the first audio-video confrontation value in the above-mentioned second audio-video confrontation sequence, the above-mentioned third audio-video confrontation sequence, and the above-mentioned fourth audio-video confrontation sequence.
[0048] Sub-step 2: Determine the product of the above-mentioned first audio-video confrontation value, the above-mentioned second audio-video confrontation value, and the above-mentioned third audio-video confrontation value as the target audio-video confrontation value.
[0049] Sub-step 3: Determine the remainder obtained by dividing the difference between the above-mentioned target audio-video confrontation value and the above-mentioned fourth audio-video confrontation value by a preset value as the first audio-video confrontation remainder. Here, the above-mentioned preset value is a pre-set value. For example, the above-mentioned preset value can be 256.
[0050] Sub-step 4: Determine the remainder obtained by dividing the sum of the square of the above-mentioned first audio-video confrontation remainder and the above-mentioned first audio-video confrontation value by the above-mentioned preset value as the second audio-video confrontation remainder.
[0051] Sub-step 5: Determine the remainder obtained by dividing the sum of the square of the above-mentioned second audio-video confrontation remainder and the above-mentioned second audio-video confrontation value by the above-mentioned preset value as the third audio-video confrontation remainder.
[0052] Sub-step 6: Determine the remainder obtained by dividing the sum of the square of the above-mentioned third audio-video confrontation remainder and the above-mentioned third audio-video confrontation value by the above-mentioned preset value as the fourth audio-video confrontation remainder.
[0053] Sub-step 7: Determine the remainder obtained by dividing the difference between the product of the above-mentioned first audio-video confrontation remainder, the above-mentioned second audio-video confrontation remainder, and the above-mentioned third audio-video confrontation remainder and the target audio-video confrontation remainder by the above-mentioned preset value as the first audio-video confrontation intermediate value. Here, the above-mentioned target audio-video confrontation remainder can be a value whose order in the fourth audio-video confrontation remainder sequence corresponding to the above-mentioned fourth audio-video confrontation remainder is less than the order of the above-mentioned first audio-video confrontation value. When the first audio-video confrontation value is at the initial position in the above-mentioned first audio-video confrontation sequence, the above-mentioned target audio-video confrontation remainder can be the value at the initial position in the above-mentioned fourth audio-video remainder sequence.
[0054] Sub-step 8: Determine the remainder obtained by dividing the sum of the square of the above-mentioned first audio-video confrontation intermediate value and the above-mentioned first audio-video confrontation remainder by the above-mentioned preset value as the second audio-video confrontation intermediate value.
[0055] Sub-step 9: Determine the remainder obtained by dividing the sum of the square of the above-mentioned second audio-video confrontation intermediate value and the above-mentioned second audio-video confrontation remainder by the above-mentioned preset value as the third audio-video confrontation intermediate value.
[0056] Sub-step 10, determine the remainder of the sum of the above-mentioned third audio-video confrontation intermediate value and the sum of the squares of the above-mentioned third audio-video confrontation remainder divided by the above-mentioned preset value as the fourth audio-video confrontation intermediate value.
[0057] Sub-step 11, determine the remainder of the sum of the above-mentioned second audio-video confrontation intermediate value, the above-mentioned third audio-video confrontation intermediate value, and the above-mentioned fourth audio-video confrontation intermediate value divided by the above-mentioned preset value as the fused audio-video value.
[0058] Second step, determine each of the obtained fused audio-video values as a fused audio-video sequence.
[0059] Step 104, in response to determining that there is an image file in the file to be encrypted, perform scrambling and diffusion encryption processing on the image file to obtain an encrypted image file.
[0060] In some embodiments, the above-mentioned execution entity may, in response to determining that there is an image file in the above-mentioned file to be encrypted, perform scrambling and diffusion encryption processing on the above-mentioned image file to obtain an encrypted image file. Among them, the above-mentioned encrypted image file may be a file obtained by performing permutation processing on the pixels in the above-mentioned image file.
[0061] In some optional implementation manners of some embodiments, the above-mentioned performing scrambling and diffusion encryption processing on the above-mentioned image file to obtain an encrypted image file may include the following steps:
[0062] First step, perform privacy image recognition on each image included in the above-mentioned image file to obtain a privacy image set. Among them, the privacy images in the above-mentioned privacy image set may be images in which the information included is privacy information. The above-mentioned privacy information may include, but is not limited to, at least one of the following: user identity information, user account information.
[0063] Second step, for each privacy image in the above-mentioned privacy image set, perform the following image hiding steps:
[0064] Sub-step 1, perform grayscale processing on the above-mentioned privacy image to obtain a grayscale privacy image. Among them, the above-mentioned grayscale privacy image may be an image representing the privacy image with 0 or 255.
[0065] Sub-step 2, perform numerical transformation on the row values and column values of the image two-dimensional matrix corresponding to the above-mentioned grayscale privacy image respectively to obtain transformed row values and transformed column values as the first chaotic initial value and the second chaotic initial value.
[0066] As an example, the above-mentioned execution entity may first convert the above row numerical value into a binary number sequence to obtain a row binary sequence. Secondly, convert the above row binary number into a Gray code to obtain a row Gray code. Thirdly, convert the above row Gray code into a decimal number to obtain a transformed row numerical value as the first chaotic initial value. Then, convert the column numerical value into a binary sequence to obtain a column binary sequence. Subsequently, insert 1 between the third and fourth digits from the end in the above column binary sequence to obtain an inserted binary sequence. Then, perform a cyclic right shift operation on the above inserted binary sequence to obtain a right-shifted binary sequence. Finally, convert the above cyclically right-shifted binary sequence into a decimal number to obtain a transformed column numerical value.
[0067] Sub-step 3: Input the above first chaotic initial value and the above second chaotic initial value into a one-dimensional image chaotic mapping algorithm to obtain an image chaotic mapping array. Among them, the number of values included in the above image chaotic mapping array is the same as the number of values included in the above image two-dimensional matrix. Among them, the above image chaotic mapping array may be the value obtained by running the above one-dimensional image chaotic mapping algorithm for the product of the length and width corresponding to the above privacy image. The above one-dimensional image chaotic mapping algorithm may be an algorithm for generating a one-dimensional random sequence. The above one-dimensional image chaotic mapping algorithm may be p n+1 = α(μ(1 - 2p n 2 ) + p n-1 - [μ(1 - 2p n 2 ) + p n-1 ). p n+1 may represent the image chaotic mapping array. α may represent the value range controlling the one-dimensional image chaotic mapping algorithm, and the value range may be any non-zero real number. μ may represent a control parameter, and the value range may be any real number. p n may represent the first chaotic initial value. p n-1 may represent the second chaotic initial value. [] may represent the floor operation.
[0068] Sub-step 4: Perform a rounding format conversion process on the above image chaotic mapping array to obtain a converted image chaotic two-dimensional matrix. Among them, the above rounding format conversion process may be first, convert the above image chaotic mapping values into a two-dimensional matrix according to the length and width of the above privacy image to obtain a chaotic image two-dimensional matrix, and then, take the remainder of the product of each value in the above chaotic image two-dimensional matrix and 10 to the 8th power divided by 256 to obtain the conversion process of the converted image chaotic two-dimensional matrix.
[0069] Sub-step 5: Perform an exclusive OR operation on the above converted image chaotic two-dimensional matrix and the above image two-dimensional matrix to obtain an image exclusive OR two-dimensional matrix.
[0070] Sub-step 6: Perform diffusion processing on the above XOR two-dimensional matrix of the image to obtain a two-dimensional matrix of the diffused image. Among them, the above two-dimensional matrix of the diffused image can be a two-dimensional matrix obtained by sequentially permuting the above XOR two-dimensional matrix of the image after diffusion.
[0071] As an example, the above execution entity can first perform the above-mentioned first chaotic initial value iterations on the above one-dimensional image chaotic mapping algorithm at intervals where the first chaotic initial value first appears in the image chaotic mapping array to obtain an iterated array. Secondly, multiply each iterated value in the above iterated array by 100 and round down to obtain a rounded array, and use the values in the rounded array as the interval for selecting scrambling positions. Subsequently, convert the above XOR two-dimensional matrix of the image into a one-dimensional array as the XOR array of the image, and starting from the first value in the rounded array, select the values in the above XOR array of the image at intervals of each value in the above rounded array. Before selection, it is necessary to first determine whether the currently selected value in the above XOR array of the image has been selected. If it has been selected, jump to the next value for continuous selection, and so on in a loop. At the same time, determine whether the number of unselected values in the above XOR array of the image is less than the preset selection threshold. If it is less than the above preset selection threshold, directly place the unselected values in the above XOR array of the image in order after the selected values as the selected value array. Then, determine the positions of each value in the above selected value array in the above XOR array of the image as the position value array, and take the remainder of each value in the above position value array divided by 256 to obtain the remainder value array. Finally, perform two-dimensional matrix conversion and XOR processing on the above selected value array and the above remainder value array to obtain a two-dimensional matrix of the diffused image.
[0072] Sub-step 7: Hide the above two-dimensional matrix of the diffused image into the carrier image to obtain an image encryption file. Among them, the above carrier image is an image with a size greater than or equal to twice the size of the private image and without private information.
[0073] Step 105: In response to determining that there is a text document in the file to be encrypted, perform privacy encryption processing on the private data included in the text document to obtain a text encryption file.
[0074] In some embodiments, the above execution entity can, in response to determining that there is a text document in the above file to be encrypted, perform privacy encryption processing on the private data included in the above text document to obtain a text encryption file. Among them, the above text encryption file can be a file obtained by encrypting the private data in the above text document.
[0075] In some optional implementation manners of some embodiments, the above-mentioned performing privacy encryption processing on the private data included in the above text document to obtain a text encryption file may include the following steps:
[0076] In the first step, identify sensitive data in the above text document to obtain a text sensitive data set. Among them, the above text sensitive data set can be data that will cause harm to an enterprise after data leakage.
[0077] As an example, the above execution subject can input the above text document into a sensitive data recognition model to obtain a text sensitive data set. Among them, the above sensitive data recognition model can include: an unsupervised bidirectional language model based on deep learning, a fully connected layer, and a CRF (Conditional Random Field) layer. The above bidirectional language model can be BERT (Bidirectional Encoder Representation from Transformers), ELMo (Embedding from Language Model), GPT (Generative Pre-training Transformer).
[0078] In the second step, determine the byte set of the above text sensitive data set to obtain a text sensitive byte set. Among them, the above text sensitive byte set can be the total byte set corresponding to each type of data in the above text sensitive data set.
[0079] As an example, the above execution subject can first perform clustering processing on the above text sensitive data set to obtain text sensitive data sets of each data type. Then, use a one-way function to determine the byte subsets corresponding to the text sensitive data sets of each data type. Finally, splice the obtained multiple byte subsets to obtain a sensitive byte set.
[0080] In the third step, generate a key vector matrix for the above text sensitive byte set through a preset key generation function. Among them, the above preset key generation function can be the Weierstrass equation. The above key vector matrix can be a parameter matrix for converting text sensitive data into ciphertext.
[0081] In the fourth step, encrypt the above key vector matrix to obtain a communication data key for the text sensitive byte set. Among them, the above communication data key can be a disordered check code used to ensure that text sensitive data is not stolen during transmission.
[0082] As an example, the above execution subject can use the encryption algorithm of an elliptic curve to encrypt the above key vector matrix to obtain a communication data key for the text sensitive byte set.
[0083] Step 5: Perform hash value mapping on the above communication data key to obtain a text encoding hash value for the text-sensitive data set. Among them, the above text encoding hash value can represent the hash value of the encoded position information of the encrypted text-sensitive data during transmission. The above execution entity can use the logistic map to perform hash value mapping on the above communication data key to obtain a text encoding hash value for the text-sensitive data set.
[0084] Step 6: Generate a text transmission key arrangement diagram for the text-sensitive byte set through the above text encoding hash value. Among them, the above text transmission key arrangement diagram can be a two-dimensional arrangement diagram used to represent the transmission order of the text-sensitive data set.
[0085] As an example, the above execution entity can determine the text encoding position corresponding to each text-sensitive data after encoding through the text encoding hash value to obtain a text encoding position set. Then, a text transmission key arrangement diagram for the text-sensitive byte set is generated through the above text encoding position set.
[0086] Step 7: Reorder the above text-sensitive data set and the remaining text data set through the above text transmission key arrangement diagram to obtain a reordered file as the text encryption file, where the above remaining text data set is the data set obtained by removing the above text-sensitive data set from the above text document.
[0087] In the process of adopting the technical solution to solve the above technical problem 1, there is often accompanied by the following technical problem 2: How to accurately identify the privacy data in the text document to improve the security of the privacy data and reduce the encrypted data volume, thereby reducing the waste of transmission resources. For the above technical problem 2, the conventional solution is generally: Identify the privacy data in the above text document through the privacy data identification rules stipulated by expert experience. However, the above conventional solution still has the following technical problems: Since the privacy field names determined by expert experience have limitations, the coverage is not comprehensive enough, and expert experience has certain subjectivity, it is easy to have situations of missed identification and misidentification, resulting in low accuracy of privacy data identification, reducing the security of privacy data, increasing the risk of privacy data leakage, increasing the waste of transmission resources and the operation load of decryption by the target terminal. Considering the disadvantages of the conventional solution, and combining the advantages / technical status of the inventor's privacy data identification, the inventor can decide to adopt the following solution:
[0088] In some optional implementation manners of some embodiments, the above identification of sensitive data in the above text document to obtain a text-sensitive data set may further include the following steps:
[0089] First step, screen out at least one text data with a structured type from the above text document to obtain a structured text data set.
[0090] Second step, determine the business information entropy of each structured text data in the above structured text data set to obtain a business information entropy set. Among them, the above business information entropy can be the source entropy of the structured text data.
[0091] Third step, determine the maximum discrete entropy of each structured text data in the above structured text data set to obtain a maximum discrete entropy set. Among them, the above maximum discrete entropy can be the discrete entropy determined by the maximum discrete entropy theorem.
[0092] Fourth step, generate the data sensitivity value of each structured text data in the above structured text data set according to the above business information entropy set and the above maximum discrete entropy set to obtain a data sensitivity value set. Among them, the above data sensitivity value can represent the probability value of the structured text data being private data. The above data sensitivity value can be an index for measuring the degree of disorder of the structured text data in the structured text data set. The smaller the above data sensitivity value, the greater the probability that the structured text data is private data.
[0093] As an example, the above execution subject can perform the following determination steps for each structured text data in the above structured text data set: First, determine the difference between the maximum discrete entropy and the business information entropy of the structured text data to obtain difference data. Then, determine the ratio of the difference data to the maximum discrete entropy as the data sensitivity value.
[0094] Fifth step, determine the number of business clusters of the above structured text data set. Among them, the above number of business clusters can be the number of clusters for clustering the determined structured text data set. In practice, the above execution subject can use the elbow method to determine the number of business clusters of the above structured text data set.
[0095] Sixth step, perform clustering processing on the above structured text data set according to the above number of business clusters and the above data sensitivity value set to obtain an initial sensitive text data cluster and an initial non-sensitive text data cluster. Among them, the above clustering processing can be clustering using the k-means clustering algorithm.
[0096] Step 7: Determine the set of data association relationship information between the above-mentioned initial sensitive text data clusters and the above-mentioned initial non-sensitive text data clusters. Among them, the data association relationship information in the above-mentioned set of data association relationship information can be the association relationship information for inferring private data through non-private data. In practice, the above-mentioned execution entity can use the Apriori algorithm to determine the set of data association relationship information between the above-mentioned initial sensitive text data clusters and the above-mentioned initial non-sensitive text data clusters.
[0097] Step 8: Perform screening processing on the above-mentioned set of data association relationship information to obtain a screened set of data association relationship information. Among them, the above-mentioned screening processing can be to screen out the data association information set in the set of data association relationship information whose association confidence is greater than or equal to 0.7.
[0098] Step 9: In response to determining that the ratio of the screened quantity to the associated quantity is greater than or equal to a preset ratio threshold, update the above-mentioned initial sensitive text data clusters and initial non-sensitive text data clusters according to the above-mentioned set of data association relationship information to obtain updated sensitive text data clusters and updated non-sensitive text data clusters. Among them, the above-mentioned screened quantity can be the number of screened data association relationship information included in the above-mentioned screened set of data association relationship information. The above-mentioned associated quantity can be the number of data association relationship information included in the above-mentioned set of data association relationship information. The above-mentioned preset ratio threshold can be a preset value. For example, the above-mentioned preset ratio threshold can be one-third.
[0099] As an example, the above-mentioned execution entity can perform the following average value determination steps for each structured text data in the above-mentioned structured text data set: First, determine the structured text data that has data association information with the above-mentioned structured text data as associated structured text data to obtain an associated structured text data set. Second, determine the business conditional entropy of the above-mentioned structured text data under the association conditions of each associated structured data in the above-mentioned associated structured text data set to obtain a set of business conditional entropy. Then, determine the ratio of the difference between the maximum discrete entropy of the structured text data and each business conditional entropy in the above-mentioned set of business conditional entropy to the maximum discrete entropy as the updated data sensitivity value to obtain a set of updated data sensitivity values. Finally, determine the average value of the above-mentioned set of updated data sensitivity values to obtain the updated data sensitivity value of the above-mentioned structured text data. Second, perform clustering processing on the obtained set of updated data sensitivity values to obtain updated sensitive text data clusters and updated non-sensitive text data clusters.
[0100] Step 10: Determine the above-mentioned updated sensitive text data clusters and the above-mentioned unstructured private data set as the business private data set.
[0101] The above technical solution and its related content, combined with step "step 110", as an inventive point of an embodiment of the present disclosure, solve technical problem two mentioned in the background art, "Since the privacy field names determined by expert experience have limitations, the coverage is not comprehensive enough, and expert experience has certain subjectivity, it is easy to have missed identification and misidentification situations, resulting in low accuracy of privacy data identification, reducing the security of privacy data, increasing the risk of privacy data leakage, increasing the waste of transmission resources, and increasing the encryption and decryption operation loads of the target terminal and the file sending end". The factors that lead to low accuracy of privacy data identification, reduce the security of privacy data, increase the risk of privacy data leakage, increase the waste of transmission resources, and increase the encryption and decryption operation loads of the target terminal and the file sending end are usually as follows: Since the privacy field names determined by expert experience have limitations, the coverage is not comprehensive enough, and expert experience has certain subjectivity, it is easy to have missed identification and misidentification situations. If the above factors are solved, the effect of improving the accuracy of privacy data identification and the security of privacy data, reducing the risk of privacy data leakage, reducing the waste of transmission resources, and reducing the encryption and decryption operation loads of the target terminal and the file sending end can be achieved. To achieve this effect, the present disclosure first quantifies the sensitivity of structured text data by generating a data sensitivity value by determining the business information entropy and the maximum discrete entropy of each structured text data. Secondly, through the data sensitivity value, the structured text data set is clustered to obtain an initial privacy text data cluster and an initial non-privacy text data cluster. The automated initial division through the data sensitivity value set can avoid the identification of human experience to a certain extent and increase the objectivity of privacy data identification. Then, determine the data association relationship information of the initial privacy text data cluster and the initial non-privacy text data cluster, and update the initial privacy text data cluster and the initial non-privacy text data cluster through the data association relationship information to obtain a business privacy data set. By adding the relevance between data based on the data set distance metric for privacy data identification, privacy data can be determined through multi-dimensional analysis, further improving the accuracy of privacy data identification, reducing the situations of misidentification and missed identification, thereby improving the security of the text document, reducing the amount of data transmitted to the target terminal, reducing the waste of transmission resources, and the encryption and decryption loads of the file sending end and the target terminal for the encrypted text document.
[0102] Step 106, determine the file priority of the file to be encrypted according to the file historical access volume, the file owner's identity information, and the file owner's department information.
[0103] In some embodiments, the above-mentioned execution entity may determine the file priority of the above-mentioned file to be encrypted according to the above-mentioned file historical access volume, the identity information of the user to whom the file belongs, and the department information to which the file belongs. Among them, the above-mentioned file priority may represent the importance of the file to be encrypted.
[0104] As an example, the above-mentioned execution entity may first determine the user identity priority and department priority of the above-mentioned identity information of the user to whom the file belongs and the department information to which the file belongs. Then, perform a weighted summation process on the above-mentioned file historical access volume, the above-mentioned user identity priority, and the above-mentioned department priority to obtain the file priority of the above-mentioned file to be encrypted.
[0105] Step 107: Determine the file re-encryption key of the file to be encrypted according to the file historical access volume, file priority, and encrypted file, and store the file re-encryption key in the key storage server.
[0106] In some embodiments, the above-mentioned execution entity may determine the file re-encryption key of the above-mentioned file to be encrypted according to the above-mentioned file historical access volume, the above-mentioned file priority, and the encrypted file, and store the above-mentioned file re-encryption key in the key storage server. Among them, the above-mentioned encrypted file may be a file composed of the above-mentioned audio-video encrypted file, the above-mentioned image encrypted file, and the above-mentioned text encrypted file. Among them, the above-mentioned file re-encryption key may be a numerical sequence for encryption. The above-mentioned key storage server may be a server for storing keys. The above-mentioned encrypted file may be a file composed of one or more of the above-mentioned audio-video encrypted file, the above-mentioned image encrypted file, and the above-mentioned text encrypted file.
[0107] As an example, the above-mentioned execution entity may first perform numerical coding processing on the above-mentioned file historical access volume and the above-mentioned file priority to obtain a coded feature vector. Then, input the above-mentioned coded feature vector into the above-mentioned audio-video encryption model to obtain a file chaotic sequence. Among them, the number of numerical values included in the above-mentioned file chaotic sequence and the numerical sequence corresponding to the above-mentioned encrypted file is the same. Finally, determine the difference between the above-mentioned encrypted file and the above-mentioned file chaotic sequence as the file re-encryption key.
[0108] Step 108: Perform ring signature processing on the file to be encrypted to obtain file signature information.
[0109] In some embodiments, the above-mentioned execution entity may perform ring signature processing on the above-mentioned file to be encrypted to obtain file signature information. Among them, the above-mentioned file signature information may be information used to verify whether the file after being sent is the same as the file before being sent.
[0110] As an example, the above-mentioned execution entity may use the ring signature algorithm to perform ring signature processing on the above-mentioned file to be encrypted to obtain file signature information.
[0111] Step 109: Re-encrypt the file signature information and the encrypted file according to the file re-encryption key to obtain a re-encrypted file.
[0112] In some embodiments, the above-mentioned execution entity may re-encrypt the above-mentioned file signature information and the above-mentioned encrypted file according to the above-mentioned file re-encryption key to obtain a re-encrypted file.
[0113] As an example, the above-mentioned execution entity may use a symmetric encryption algorithm to re-encrypt the above-mentioned file signature information and the above-mentioned encrypted file according to the above-mentioned file re-encryption key to obtain a re-encrypted file.
[0114] Step 110: Compress and send the re-encrypted file to the target terminal for the target terminal to perform a search and match based on the user identity information in the above-mentioned key storage server to obtain a file matching key for decryption processing to obtain a decrypted file.
[0115] In some embodiments, the above-mentioned execution entity may compress and send the above-mentioned re-encrypted file to the target terminal for the above-mentioned target terminal to perform a search and match based on the user identity information in the above-mentioned key storage server to obtain a file matching key for decryption processing to obtain a decrypted file. Among them, the above-mentioned target terminal may be a user terminal or a server for receiving the re-encrypted file. The above-mentioned file matching key may be a key corresponding to the above-mentioned re-encrypted file and used for decrypting the above-mentioned re-encrypted file. The above-mentioned compressed sending may be compression of the above-mentioned re-encrypted file using a compression algorithm. In practice, the above-mentioned file matching key may be a search access algorithm based on user identity information to access and match the key set included in the above-mentioned key storage server to obtain a key corresponding to the above-mentioned re-encrypted file.
[0116] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: The file encryption method of some embodiments of the present disclosure can perform one-time encryption and compression transmission for the file to be encrypted, improving the security during the file sending and transmission process while reducing the waste of transmission resources. Specifically, the leakage of privacy data of relevant enterprise internal files and the reduction of file transmission security are due to: encrypting the file through a single encryption algorithm. If the file key is leaked during transmission, all files encrypted with the same encryption algorithm have privacy data leakage problems, resulting in the leakage of privacy data of enterprise internal files and the reduction of file transmission security. Based on this, the file encryption method of some embodiments of the present disclosure can first, obtain the information of the file to be encrypted, where the above-mentioned information of the file to be encrypted includes at least one of the following: file historical access volume, file department information, and file user identity information. Here, the information of the file to be encrypted facilitates subsequent file encryption. Secondly, in response to determining that there is an audio-video file in the file to be encrypted corresponding to the above-mentioned information of the file to be encrypted, extract data from the audio-video coding information corresponding to the above-mentioned audio-video file to obtain audio-video extraction information. Here, important information in the audio-video can be extracted, reducing the amount of data to be encrypted. Thirdly, input the above-mentioned audio-video extraction information into the audio-video encryption model to obtain an audio-video encrypted file, where the above-mentioned audio-video encryption model includes: an audio-video chaotic mapping algorithm and an audio-video encryption adversarial model. Here, the audio-video encryption model can improve the randomness and irregularity of the generated encryption key through deep learning methods, and encrypting the audio-video extraction information with a smaller amount of data can improve the encryption efficiency, enhance the encryption effect, and reduce the system encryption operation load. Then, in response to determining that there is an image file in the above-mentioned file to be encrypted, perform scrambling and diffusion encryption processing on the above-mentioned image file to obtain an image encrypted file. Here, it can better conform to the encryption of image files, improve the encryption effect, and be more targeted. Subsequently, in response to determining that there is a text document in the above-mentioned file to be encrypted, perform privacy encryption processing on the privacy data included in the above-mentioned text document to obtain a text encrypted file. Here, it can better conform to the encryption of text documents, improve the encryption effect, be more targeted, and reduce the amount of encrypted data, improving the encryption efficiency. Then, according to the above-mentioned file historical access volume, the above-mentioned file user identity information, and the above-mentioned file department information, determine the file priority of the above-mentioned file to be encrypted. Here, it can better distinguish different files, so as to better conform to one-time encryption for each file and improve the security of different files to be encrypted. After that, according to the above-mentioned file historical access volume, the above-mentioned file priority, and the encrypted file, determine the file re-encryption key of the above-mentioned file to be encrypted, and store the above-mentioned file re-encryption key in the key storage server, where the above-mentioned encrypted file can be a file composed of the above-mentioned audio-video encrypted file, the above-mentioned image encrypted file, and the above-mentioned text encrypted file.Here, the security of the file re-encryption key can be enhanced, and it is also convenient for subsequent encryption processing. Then, ring signature processing is performed on the above-mentioned file to be encrypted to obtain file signature information. Here, the integrity of the file can be verified, further enhancing the security of the file and facilitating the monitoring of the file during the transmission process. Subsequently, based on the above-mentioned file re-encryption key, re-encryption processing is performed on the above-mentioned file signature information and the above-mentioned encrypted file to obtain a re-encrypted file. Here, double encryption and targeted encryption of different types of files can further enhance the security of the file and the security of sending and transmission. Finally, the above-mentioned re-encrypted file is compressed and sent to the target terminal for the target terminal to perform a search and match based on the user identity information in the above-mentioned key storage server to obtain a file matching key for decryption processing to obtain the decrypted file. Here, compressed sending can reduce the amount of data sent, reduce the waste of transmission resources, and the search for access control based on the search and match of user identity information can enhance the security of the file re-encryption key. Thus, it can be seen that this file encryption method can perform one-time encryption and compressed sending of the file to be encrypted, enhancing the security during the file sending and transmission process while reducing the waste of transmission resources.
[0117] Further referring to Figure 2 , as an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a file encryption device. These device embodiments correspond to Figure 1 the method embodiments shown, and this file encryption device can be specifically applied to various electronic devices.
[0118] As Figure 2As shown in the figure, a file encryption device 200 includes: an acquisition unit 201, a data extraction unit 202, an input unit 203, a scrambling and diffusion encryption unit 204, a privacy encryption unit 205, a first determination unit 206, a second determination unit 207, a ring signature unit 208, a re-encryption unit 209, and a sending unit 210. Among them, the acquisition unit 201 is configured to: acquire information of a file to be encrypted, where the information of the file to be encrypted includes at least one of the following: file historical access volume, file department information, and file owner identity information. The data extraction unit 202 is configured to: in response to determining that there is an audio-video file in the file to be encrypted corresponding to the information of the file to be encrypted, extract data from the audio-video coding information corresponding to the audio-video file to obtain audio-video extraction information. The input unit 203 is configured to: input the audio-video extraction information into an audio-video encryption model to obtain an audio-video encrypted file, where the audio-video encryption model includes: an audio-video chaotic mapping algorithm and an audio-video encryption adversarial model. The scrambling and diffusion encryption unit 204 is configured to: in response to determining that there is an image file in the file to be encrypted, perform scrambling and diffusion encryption processing on the image file to obtain an image encrypted file. The privacy encryption unit 205 is configured to: in response to determining that there is a text document in the file to be encrypted, perform privacy encryption processing on the privacy data included in the text document to obtain a text encrypted file. The first determination unit 206 is configured to: determine the file priority of the file to be encrypted according to the file historical access volume, the file owner identity information, and the file department information. The second determination unit 207 is configured to: determine the file re-encryption key of the file to be encrypted according to the file historical access volume, the file priority, and the encrypted file, and store the file re-encryption key in a key storage server, where the encrypted file may be a file composed of the audio-video encrypted file, the image encrypted file, and the text encrypted file. The ring signature unit 208 is configured to: perform ring signature processing on the file to be encrypted to obtain file signature information. The re-encryption unit 209 is configured to: perform re-encryption processing on the file signature information and the encrypted file according to the file re-encryption key to obtain a re-encrypted file. The sending unit 210 is configured to: compress and send the re-encrypted file to a target terminal, so that the target terminal performs search and matching based on user identity information in the key storage server to obtain a file matching key for decryption processing to obtain a decrypted file. [[ID=|1]] [[ID=|2]]
[0119] [[ID=|3]]It can be understood that the units described in the file encryption device 200 correspond to the respective steps in the method described in the reference [[ID=|4]] Figure 1 [[ID=|5]]description. Therefore, the operations, features, and beneficial effects described above for the method also apply to the file encryption device 200 and the units included therein, and will not be elaborated here. [[ID=|6]]
[0120] Reference will now be made to Figure 3 , which shows a schematic structural diagram of an electronic device (e.g., an electronic device) 300 suitable for use in implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0121] As Figure 3 shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0122] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 the electronic device 300 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be alternatively implemented or had. Figure 3 Each block shown in
[0123] may represent a device or, as needed, multiple devices.
[0124] It should be noted that in some embodiments of the present disclosure, the above-mentioned computer-readable medium can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above. [[ID=~1]] [[ID=~2]]
[0125] [[ID=~3]]In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (Hyper Text Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks. [[ID=~4]] [[ID=~5]]
[0126] The above computer-readable medium may be included in the above electronic device; or it may exist separately and not be assembled into the electronic device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to: obtain information of a file to be encrypted, where the information of the file to be encrypted includes at least one of the following: the historical access volume of the file, the information of the department to which the file belongs, and the identity information of the user to which the file belongs; in response to determining that there is an audio-video file in the file to be encrypted corresponding to the above information of the file to be encrypted, perform data extraction on the audio-video coding information corresponding to the audio-video file to obtain audio-video extraction information; input the above audio-video extraction information into an audio-video encryption model to obtain an audio-video encrypted file, where the above audio-video encryption model includes: an audio-video chaotic mapping algorithm and an audio-video encryption adversarial model; in response to determining that there is an image file in the file to be encrypted, perform scrambling and diffusion encryption processing on the image file to obtain an image encrypted file; in response to determining that there is a text document in the file to be encrypted, perform privacy encryption processing on the privacy data included in the text document to obtain a text encrypted file; determine the file priority of the file to be encrypted according to the above historical access volume of the file, the identity information of the user to which the file belongs, and the information of the department to which the file belongs; determine the file re-encryption key of the file to be encrypted according to the above historical access volume of the file, the above file priority, and the encrypted file, and store the above file re-encryption key in a key storage server, where the above encrypted file may be a file composed of the above audio-video encrypted file, the above image encrypted file, and the above text encrypted file; perform ring signature processing on the above file to be encrypted to obtain file signature information; perform re-encryption processing on the above file signature information and the above encrypted file according to the above file re-encryption key to obtain a re-encrypted file; compress and send the above re-encrypted file to a target terminal for the above target terminal to perform search and matching based on user identity information in the above key storage server to obtain a file matching key for decryption processing to obtain a decrypted file.
[0127] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0128] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0129] The units described in some embodiments of the present disclosure may be implemented in software or in hardware. The described units may also be provided in a processor. For example, it may be described as: a processor includes an acquisition unit, a data extraction unit, an input unit, a scrambling and diffusion encryption unit, a privacy encryption unit, a first determination unit, a second determination unit, a ring signature unit, a re-encryption unit, and a sending unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the acquisition unit may also be described as "the unit for acquiring information of the file to be encrypted".
[0130] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0131] The above description is only some preferred embodiments of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A file encryption method, comprising: Acquire information about a file to be encrypted, wherein the information about the file to be encrypted includes at least one of the following: a history of file accesses, information about the department to which the file belongs, and identity information of the user to whom the file belongs; In response to determining that an audio or video file exists in the file to be encrypted corresponding to the file information to be encrypted, extracting data from the audio and video encoding information corresponding to the audio or video file to obtain audio or video extraction information; Inputting the audio and video extraction information into an audio and video encryption model to obtain an audio and video encrypted file, wherein the audio and video encryption model includes: an audio and video chaotic mapping algorithm and an audio and video encryption adversarial model; In response to determining that an image file exists in the file to be encrypted, performing scrambling diffusion encryption processing on the image file to obtain an encrypted image file; In response to determining that a text document exists in the file to be encrypted, performing privacy encryption processing on the private data included in the text document to obtain a text encrypted file; Determining the file priority of the file to be encrypted based on the number of historical file accesses, the identity information of the user to whom the file belongs, and the information of the department to which the file belongs; Determining a file re-encryption key for the file to be encrypted based on the number of historical file accesses, the file priority, and the encrypted file, and storing the file re-encryption key in a key storage service client, wherein the encrypted file is a file consisting of the audio and video encrypted file, the image encrypted file, and the text encrypted file; Performing ring signature processing on the file to be encrypted to obtain file signature information; Re-encrypting the file signature information and the encrypted file according to the file re-encryption key to obtain a re-encrypted file; The re-encrypted file is compressed and sent to the target terminal, so that the target terminal can search and match based on the user identity information on the key storage service terminal, obtain the file matching key for decryption processing, and obtain the decrypted file.
2. The method according to claim 1, wherein The step of extracting data from the audio and video encoding information corresponding to the audio and video file to obtain audio and video extraction information includes: Determining audio and video coding header information of each audio and video frame included in the audio and video coding information to obtain an audio and video coding header information set; Performing bitwise AND processing on each audio and video coding header information and a preset coding value in the audio and video coding header information set to obtain an audio and video frame coding type set for each audio and video frame; Filtering out at least one audio and video coding header information corresponding to an audio and video frame coding type of a key frame from the audio and video coding header information set; Determining an audio and video load information set corresponding to each audio and video frame; Extracting encoding information from each piece of audio and video load information in the audio and video load information set to obtain an audio and video load encoding information set; The at least one audio and video coding header information and the audio and video payload coding information set are determined as audio and video extraction information.
3. The method according to claim 2, wherein: The step of inputting the audio and video extraction information into an audio and video encryption model to obtain an audio and video encryption file includes: Inputting an initial parameter value set into the audio and video chaotic mapping algorithm to obtain an audio and video chaotic sequence, wherein the initial parameter values in the initial parameter value set are randomly determined values; Inputting the audio and video chaotic sequence into the audio and video encryption adversarial model to obtain an audio and video adversarial sequence set; Performing a fusion process on the audio and video adversarial sequence set to obtain a fused audio and video sequence; According to the fused audio and video sequence, encrypt each audio and video coding header information in the at least one audio and video coding header information to generate key frame encrypted header information, thereby obtaining a key frame encrypted header information set; Encrypting the audio and video payload encoding information set to obtain an audio and video encrypted payload information set; The audio and video encryption payload information set and the key frame encryption header information set replace the corresponding encoding information in the audio and video encoding information to obtain the replaced audio and video encoding information as the audio and video encryption file.
4. The method according to claim 3, wherein: The audio and video confrontation sequence set includes: a first audio and video confrontation sequence, a second audio and video confrontation sequence, a third audio and video confrontation sequence, and a fourth audio and video confrontation sequence; and The fusing the audio and video adversarial sequence set to obtain a fused audio and video sequence includes: For each first audio and video confrontation value in the first audio and video confrontation sequence, the following determination steps are performed: Determining a second audio and video confrontation value, a third audio and video confrontation value, and a fourth audio and video confrontation value corresponding to the first audio and video confrontation value in the second audio and video confrontation sequence, the third audio and video confrontation sequence, and the fourth audio and video confrontation sequence; Determine a product of the first audio and video confrontation value, the second audio and video confrontation value, and the third audio and video confrontation value as a target audio and video confrontation value; Determine a remainder of a difference between the target audio and video confrontation value and the fourth audio and video confrontation value divided by a preset value as a first audio and video confrontation remainder; Determine a remainder obtained by dividing the sum of the square of the first audio and video confrontation remainder and the first audio and video confrontation value by the preset value as a second audio and video confrontation remainder; Determine a remainder obtained by dividing the sum of the square of the second audio and video confrontation remainder and the second audio and video confrontation value by the preset value as a third audio and video confrontation remainder; Determine a remainder obtained by dividing the sum of the square of the third audio and video confrontation remainder and the third audio and video confrontation value by the preset value as a fourth audio and video confrontation remainder; Determine the remainder of the product of the first audio and video confrontation remainder, the difference between the product and the target audio and video confrontation remainder, and the remainder divided by the preset value as the first audio and video confrontation intermediate value, wherein the target audio and video confrontation remainder is a value whose order in the fourth audio and video confrontation remainder sequence corresponding to the fourth audio and video confrontation remainder is smaller than that of the first audio and video confrontation value; Determine a remainder of the sum of the square of the first audio and video confrontation intermediate value and the first audio and video confrontation remainder divided by the preset value as the second audio and video confrontation intermediate value; Determine a remainder of the sum of the square of the second audio and video confrontation intermediate value and the second audio and video confrontation remainder divided by the preset value as a third audio and video confrontation intermediate value; Determine a remainder of the sum of the sum of the square of the third audio and video confrontation intermediate value and the third audio and video confrontation remainder divided by the preset value as a fourth audio and video confrontation intermediate value; Determine a remainder of the sum of the second audio and video confrontation intermediate value, the third audio and video confrontation intermediate value, and the fourth audio and video confrontation intermediate value divided by the preset value as the fused audio and video value; The obtained fused audio and video values are determined as a fused audio and video sequence.
5. The method according to claim 1, wherein The performing scrambling diffusion encryption processing on the image file to obtain an encrypted image file includes: performing privacy image recognition on each image included in the image file to obtain a privacy image set; For each private image in the private image set, perform the following image hiding steps: grayscale the private image to obtain a grayscale private image; Performing numerical transformation on the row values and column values of the two-dimensional image matrix corresponding to the grayscale privacy image, respectively, to obtain transformed row values and transformed column values as the first chaotic initial value and the second chaotic initial value; Inputting the first chaotic initial value and the second chaotic initial value into a one-dimensional image chaotic mapping algorithm to obtain an image chaotic mapping array, wherein the number of values included in the image chaotic mapping array is the same as the number of values included in the image two-dimensional matrix; Performing integer format conversion processing on the image chaotic map array to obtain a converted image chaotic two-dimensional matrix; Performing an XOR process on the converted image chaotic two-dimensional matrix and the image two-dimensional matrix to obtain an image XOR two-dimensional matrix; Performing diffusion processing on the image XOR two-dimensional matrix to obtain a diffused image two-dimensional matrix; The diffused image two-dimensional matrix is hidden in a carrier image to obtain an image encryption file, wherein the carrier image is an image with a size greater than or equal to twice that of the private image and does not contain private information.
6. The method according to claim 1, wherein The step of performing privacy encryption processing on the private data included in the text document to obtain a text encrypted file includes: Performing sensitive data identification on the text document to obtain a text sensitive data set; Determine a byte set of the text-sensitive data set to obtain a text-sensitive byte set; Generate a key vector matrix for the text sensitive byte set by using a preset key generation function; Performing encryption processing on the key vector matrix to obtain a communication data key for a text sensitive byte set; Performing hash value mapping processing on the communication data key to obtain a text-encoded hash value for the text-sensitive data set; Generate a text transmission key arrangement diagram for a text sensitive byte set through the text encoding hash value; The text-sensitive data set and the remaining text data set are reordered through the text transmission key arrangement diagram to obtain a reordered file as a text encryption file, wherein the remaining text data set is a data set obtained by removing the text-sensitive data set from the text document.
7. A file encryption device comprising: An acquisition unit is configured to acquire information of a file to be encrypted, wherein the information of the file to be encrypted includes at least one of the following: a history of file accesses, information of the department to which the file belongs, and identity information of the user to whom the file belongs; A data extraction unit is configured to, in response to determining that an audio or video file exists in the file to be encrypted corresponding to the file information to be encrypted, extract data from the audio and video encoding information corresponding to the audio or video file to obtain audio and video extraction information; An input unit is configured to input the audio and video extraction information into an audio and video encryption model to obtain an audio and video encryption file, wherein the audio and video encryption model includes: an audio and video chaotic mapping algorithm and an audio and video encryption adversarial model; a scrambling diffusion encryption unit configured to, in response to determining that an image file exists in the file to be encrypted, perform scrambling diffusion encryption on the image file to obtain an encrypted image file; a privacy encryption unit configured to, in response to determining that a text document exists in the file to be encrypted, perform privacy encryption processing on the privacy data included in the text document to obtain a text encrypted file; a first determining unit configured to determine the file priority of the to-be-encrypted file according to the number of historical file accesses, the identity information of the user to whom the file belongs, and the information of the department to which the file belongs; a second determining unit configured to determine a file re-encryption key of the file to be encrypted based on the number of historical file accesses, the file priority, and the encrypted file, and to store the file re-encryption key in a key storage service client, wherein the encrypted file is a file consisting of the audio and video encrypted file, the image encrypted file, and the text encrypted file; a ring signature unit, configured to perform ring signature processing on the file to be encrypted to obtain file signature information; a re-encryption unit configured to re-encrypt the file signature information and the encrypted file according to the file re-encryption key to obtain a re-encrypted file; The sending unit is configured to compress and send the re-encrypted file to the target terminal, so that the target terminal can search and match the file based on the user identity information on the key storage service terminal, obtain the file matching key for decryption processing, and obtain the decrypted file.
8. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 6.
9. A computer-readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Data processing method and device, storage medium and electronic equipment
CN113329239A
File encryption method and system
CN115758422A