Network synchronization data protection method and device
By using a virtual file system to encrypt and decrypt the data in the network synchronous data transmission, the problems of complex user operations and server-side encryption security risks in the prior art are solved, and unsensed network synchronous data protection and secure transmission are realized.
Patent Information
- Application Number
- CN202411984535.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-02
AI Technical Summary
The prior art has shortcomings in realizing network synchronization data encryption without perception by users, which increases the user's operational burden, and server encryption has security risks, which cannot effectively solve the security problems of data during network transmission.
By establishing a mapping relationship between the virtual disk and the folder between the first terminal and the second terminal, the virtual file system is used to encrypt and decrypt the target file, and unsensed network synchronization data protection is achieved.
It realizes secure encryption and decryption of network synchronized data, reduces the complexity of user operations, ensures the security of data during transmission, and avoids the security risks of server encryption.
Smart Images

Figure CN119921990A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data security, and in particular to a method and device for protecting network synchronization data. Background Art
[0002] With the widespread application of network-based synchronized data, data security is particularly important.
[0003] In the prior art, using encryption and decryption technology to protect data is a common data protection method. Usually, users need to do it manually, which increases the complexity and inconvenience of use. The following is a description of some prior art:
[0004] 1.1 Manual encryption and decryption:
[0005] Users need to use special software to manually encrypt and decrypt files. Although this method can ensure data security, it increases the user's operational burden.
[0006] 1.2 Encryption function of cloud storage service:
[0007] Some cloud storage services provide data encryption functions, but they are usually server-side encryption. Users cannot control the encryption keys, which poses certain security risks.
[0008] For example, Dropbox and Google Drive provide data encryption features, but the encryption keys are managed by the service provider and users cannot fully control their data security.
[0009] 1.3 File system level encryption:
[0010] The file system-level encryption functions provided by the operating system, such as BitLocker in Windows and FileVault in macOS, can encrypt the entire disk, but cannot achieve imperceptible encryption of network synchronized data.
[0011] These encryption functions are mainly used to protect the data security of local storage devices and cannot solve the security issues of data during network transmission.
[0012] 1.4 Third-party encryption software:
[0013] Some third-party encryption software can achieve automatic encryption and decryption, but usually requires users to perform complex configurations and cannot be seamlessly integrated with cloud storage services.
[0014] In summary, the existing technology has many deficiencies in achieving user-unaware network synchronization data encryption. Summary of the invention
[0015] In view of the problems in the prior art, an embodiment of the present invention provides a network synchronization data protection method and device, which can at least partially solve the problems in the prior art.
[0016] In one aspect, the present invention provides a network synchronization data protection method, which is applied to a first terminal and a second terminal, and includes:
[0017] The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk;
[0018] The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0019] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0020] The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0021] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0022] The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0023] Wherein, establishing the first preset corresponding relationship includes:
[0024] The first preset corresponding relationship is established in response to a first configuration action of configuring the first virtual disk corresponding to the first virtual file system and a second configuration action of configuring the first folder executed at the first terminal.
[0025] Before the step of establishing the first preset corresponding relationship, the network synchronization data protection method further includes:
[0026] In response to a first user authentication operation performed at the first terminal, the first virtual file system is started.
[0027] The encrypting the target file by using the first virtual disk includes:
[0028] The target file is encrypted by using a preset algorithm and the first virtual disk.
[0029] Wherein, establishing the second preset corresponding relationship includes:
[0030] In response to a third configuration action of configuring the second virtual disk corresponding to the second virtual file system and a fourth configuration action of configuring the second folder executed at the second terminal, the second preset corresponding relationship is established.
[0031] Before the step of establishing the second preset corresponding relationship, the network synchronization data protection method further includes:
[0032] In response to a second user authentication operation performed at the second terminal, the second virtual file system is started.
[0033] The decrypting the encrypted target file by using the second virtual disk includes:
[0034] The same target preset algorithm as used for encryption is used, and the encrypted target file is decrypted through the second virtual disk.
[0035] In one aspect, the present invention provides a network synchronization data protection device, comprising:
[0036] An encryption unit, used for controlling the first terminal to respond to a write operation on a target file through the first virtual disk, and encrypting the target file through the first virtual disk;
[0037] A synchronization unit, configured to control the first terminal to determine a first folder corresponding to the first virtual disk according to a pre-established first preset correspondence, store the encrypted target file in the first folder, and synchronize the first folder to a network storage medium;
[0038] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0039] a determining unit, configured to control the second terminal to obtain the encrypted target file from the second folder, and determine a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0040] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0041] The decryption unit is used to control the second terminal to respond to the read operation of the target file through the second virtual disk, decrypt the encrypted target file through the second virtual disk, and read the decrypted target file.
[0042] In another aspect, an embodiment of the present invention provides an electronic device, including: a processor, a memory, and a bus, wherein:
[0043] The processor and the memory communicate with each other via the bus;
[0044] The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the following method:
[0045] The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk;
[0046] The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0047] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0048] The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0049] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0050] The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0051] An embodiment of the present invention provides a non-transitory computer-readable storage medium, including:
[0052] The non-transitory computer-readable storage medium stores computer instructions, which cause the computer to execute the following method:
[0053] The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk;
[0054] The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0055] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0056] The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0057] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0058] The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0059] The network synchronization data protection method and device provided by the embodiment of the present invention are as follows: the first terminal responds to the write operation of the target file through the first virtual disk, and encrypts the target file through the first virtual disk; the first terminal determines the first folder corresponding to the first virtual disk according to the pre-established first preset correspondence relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to the network storage medium; wherein the first preset correspondence relationship includes the mapping relationship between the first folder and the first virtual disk; the network storage medium also synchronizes a second folder corresponding to the second terminal; the second terminal obtains the encrypted target file from the second folder, and determines the second virtual disk corresponding to the second folder according to the pre-established second preset correspondence relationship; wherein the second preset correspondence relationship includes the mapping relationship between the second folder and the second virtual disk; the second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file, so that the network synchronization data can be protected safely and conveniently. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0061] Figure 1 It is a flowchart of a network synchronization data protection method provided by an embodiment of the present invention.
[0062] Figure 2It is a flow chart of a network synchronization data protection method provided by another embodiment of the present invention.
[0063] Figure 3 It is a structural diagram of a network synchronization data protection device provided by an embodiment of the present invention.
[0064] Figure 4 A schematic diagram of the physical structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0065] In order to make the purpose, technical scheme and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention. It should be noted that, in the absence of conflict, the embodiments in this application and the features in the embodiments can be combined with each other arbitrarily.
[0066] Figure 1 FIG. 1 is a flow chart of a network synchronization data protection method provided by an embodiment of the present invention. Figure 1 As shown, the network synchronization data protection method provided by the embodiment of the present invention includes:
[0067] Step S1: The first terminal responds to a write operation on a target file through a first virtual disk and encrypts the target file through the first virtual disk.
[0068] Step S2: the first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0069] The first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; and a second folder corresponding to a second terminal is also synchronized in the network storage medium.
[0070] Step S3: the second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0071] The second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk.
[0072] Step S4: the second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0073] In the above step S1, the first terminal of the device responds to the write operation of the target file through the first virtual disk, and encrypts the target file through the first virtual disk. The device can be a computer device that executes the method, specifically a first terminal for writing files and a second terminal for reading files. It should be noted that the acquisition and analysis of data involved in the embodiments of the present invention are authorized by the user.
[0074] In the above step S2, the first terminal of the device determines a first folder corresponding to the first virtual disk according to a pre-established first preset correspondence, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0075] The first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; and a second folder corresponding to a second terminal is also synchronized in the network storage medium.
[0076] In the above step S3, the second terminal of the device obtains the encrypted target file from the second folder, and determines the second virtual disk corresponding to the second folder according to the pre-established second preset corresponding relationship;
[0077] The second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk.
[0078] In the above step S4, the second terminal of the device responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0079] Establishing the first preset corresponding relationship includes:
[0080] The first preset corresponding relationship is established in response to a first configuration action of configuring the first virtual disk corresponding to the first virtual file system and a second configuration action of configuring the first folder executed at the first terminal.
[0081] Before the step of establishing the first preset corresponding relationship, the network synchronization data protection method further includes:
[0082] In response to a first user authentication operation performed at the first terminal, the first virtual file system is started.
[0083] The encrypting the target file by using the first virtual disk includes:
[0084] The target file is encrypted by using a preset algorithm and the first virtual disk.
[0085] Establishing the second preset corresponding relationship includes:
[0086] In response to a third configuration action of configuring the second virtual disk corresponding to the second virtual file system and a fourth configuration action of configuring the second folder executed at the second terminal, the second preset corresponding relationship is established.
[0087] Before the step of establishing the second preset corresponding relationship, the network synchronization data protection method further includes:
[0088] In response to a second user authentication operation performed at the second terminal, the second virtual file system is started.
[0089] Decrypting the encrypted target file by using the second virtual disk includes:
[0090] The same target preset algorithm as used for encryption is used, and the encrypted target file is decrypted through the second virtual disk.
[0091] The network storage medium may specifically include a cloud or distributed file system or blockchain. The use of a distributed file system can provide higher scalability and data redundancy. The use of a blockchain can provide data immutability and transparency.
[0092] The user authentication operation may include entering a user name and password, or may include using multi-factor authentication instead of a single user name and password authentication to improve system security and prevent unauthorized access.
[0093] The preset algorithms can include asymmetric encryption algorithms and symmetric encryption algorithms. The public key is used to encrypt data and the private key is used to decrypt data, further improving data security. It can also include end-to-end encryption to ensure that data remains encrypted during transmission.
[0094] You can also use hardware security modules to store encryption keys, providing greater security to prevent the keys from being compromised.
[0095] The implementation method of the present invention is described as follows:
[0096] The virtual file system is responsible for mapping a specific local physical folder to a virtual disk, intercepting file operation requests, and encrypting write operations and decrypting read operations on the virtual disk. At the same time, the data stored in a specific local physical folder is actually encrypted. When a specific local physical folder is mapped to the network cloud storage, the data will be automatically encrypted. The data synchronized back to the local machine will be automatically decrypted when accessed through the virtual disk.
[0097] The encryption technology of the present invention is described as follows:
[0098] The data is encrypted and decrypted using a symmetric encryption algorithm (such as AES). The encryption key is stored on the client side to ensure the security of the data during transmission and storage.
[0099] The file operation process of the present invention is described as follows:
[0100] File reading: When a user reads a file, the virtual file system obtains the encrypted data from the local folder and decrypts it on the client side through the virtual disk and exposes it to the user.
[0101] File writing: When a user writes a file, the virtual file system encrypts the data through the virtual disk and stores it synchronously in the local folder.
[0102] The technical principle of the present invention is described as follows:
[0103] Virtual file system creation: The client software creates a virtual file system, and users perform file operations through the virtual disk created by the virtual file system. When creating a virtual disk, users need to enter the correct user name and password to decrypt and encrypt data.
[0104] Local folder mapping: The virtual disk will be mapped to a local folder (such as C:\VisualDisk on computer A), and the files in this folder are encrypted.
[0105] Encryption and decryption process: During the file reading and writing process, the virtual disk will automatically encrypt and decrypt the data. Specifically, when the user reads a file, the virtual file system will obtain the encrypted data from the local folder and automatically decrypt it when the user reads it; when the user writes a file, the virtual file system will write the encrypted data to the virtual disk and store the data in the local folder.
[0106] Data synchronization security: Since the data in the local folder is encrypted, when the folder is synchronized to the cloud, the data is still encrypted and cannot be read normally. The data in the virtual disk can only be read normally when the client is installed and mapped to the virtual disk.
[0107] Password protection: The virtual file system requires the user to enter the correct username and password when starting up in order to decrypt and encrypt data, further improving data security. The username is visible and has a unique identifier.
[0108] like Figure 2 As shown, the method of the present invention is described as follows in combination with the usage scenario:
[0109] Computer A: A virtual file system software is installed on Computer A. The user needs to enter the correct user name and password when starting the virtual file system. The virtual file system of Computer A is mapped to the P:\ drive, and the local folder (such as C:\VisualDisk) is mapped to the P:\ drive. When the user operates files through the P:\ drive, the files are automatically encrypted and stored in the C:\VisualDisk folder. The files synchronized from the C:\VisualDisk folder to the cloud are also encrypted.
[0110] Computer B: Computer B synchronizes files from the network cloud of computer A's C:\VisualDisk folder to (such as computer B's C:\AsyncDisk). It must install the virtual file system software and enter the same user name and password as computer A to map the cloud-synchronized folder (such as computer B's C:\AsyncDisk) to the virtual file system (such as computer B's V:\disk). When users operate files through computer B's V:\disk, the virtual file system will automatically decrypt the files and users can read the files normally.
[0111] The network synchronization data protection method provided by the embodiment of the present invention realizes a non-perceptual network synchronization data protection method based on virtual file system read-write separation by combining virtual file system and encryption technology. Users do not need to manually encrypt and decrypt data during use, which greatly improves data security and convenience of use.
[0112] The network synchronization data protection method provided by the embodiment of the present invention comprises the following steps: a first terminal responds to a write operation on a target file through a first virtual disk, and encrypts the target file through the first virtual disk; the first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset correspondence relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium; wherein the first preset correspondence relationship includes a mapping relationship between the first folder and the first virtual disk; a second folder corresponding to the second terminal is also synchronized in the network storage medium; the second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset correspondence relationship; wherein the second preset correspondence relationship includes a mapping relationship between the second folder and the second virtual disk; the second terminal responds to a read operation on the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file, thereby being able to safely and conveniently protect network synchronization data.
[0113] Further, establishing the first preset corresponding relationship includes:
[0114] In response to the first configuration action of configuring the first virtual disk corresponding to the first virtual file system and the second configuration action of configuring the first folder executed at the first terminal, the first preset corresponding relationship is established.
[0115] Furthermore, before the step of establishing the first preset corresponding relationship, the network synchronization data protection method further includes:
[0116] In response to the first user authentication operation performed on the first terminal, the first virtual file system is started. The above-mentioned embodiments can be referred to for explanation and will not be described in detail.
[0117] Further, encrypting the target file by using the first virtual disk includes:
[0118] The target file is encrypted by using a preset algorithm and the first virtual disk. Please refer to the above embodiment for description, which will not be repeated here.
[0119] Further, establishing the second preset corresponding relationship includes:
[0120] In response to the third configuration action of configuring the second virtual disk corresponding to the second virtual file system and the fourth configuration action of configuring the second folder executed at the second terminal, the second preset corresponding relationship is established.
[0121] Furthermore, before the step of establishing the second preset corresponding relationship, the network synchronization data protection method further includes:
[0122] In response to the second user authentication operation performed on the second terminal, the second virtual file system is started. The above description may be referred to in the above embodiment and will not be repeated here.
[0123] Further, decrypting the encrypted target file by using the second virtual disk includes:
[0124] The same target preset algorithm as that used for encryption is used to decrypt the encrypted target file through the second virtual disk. The above description can be referred to and will not be repeated here.
[0125] Figure 3 is a schematic diagram of the structure of a network synchronization data protection device provided by an embodiment of the present invention. Figure 3 As shown, the network synchronization data protection device provided by the embodiment of the present invention includes an encryption unit 301, a synchronization unit 302, a determination unit 303 and a decryption unit 304, wherein:
[0126] The encryption unit 301 is used to control the first terminal to respond to the write operation of the target file through the first virtual disk, and encrypt the target file through the first virtual disk; the synchronization unit 302 is used to control the first terminal to determine the first folder corresponding to the first virtual disk according to a pre-established first preset correspondence relationship, store the encrypted target file in the first folder, and synchronize the first folder to the network storage medium; wherein the first preset correspondence relationship includes a mapping relationship between the first folder and the first virtual disk; the network storage medium also synchronizes a second folder corresponding to the second terminal; the determination unit 303 is used to control the second terminal to obtain the encrypted target file from the second folder, and determine the second virtual disk corresponding to the second folder according to a pre-established second preset correspondence relationship; wherein the second preset correspondence relationship includes a mapping relationship between the second folder and the second virtual disk; the decryption unit 304 is used to control the second terminal to respond to the read operation of the target file through the second virtual disk, decrypt the encrypted target file through the second virtual disk, and read the decrypted target file.
[0127] Specifically, the encryption unit 301 in the device is used to control the first terminal to respond to the write operation of the target file through the first virtual disk, and encrypt the target file through the first virtual disk; the synchronization unit 302 is used to control the first terminal to determine the first folder corresponding to the first virtual disk according to a pre-established first preset correspondence relationship, store the encrypted target file in the first folder, and synchronize the first folder to the network storage medium; wherein the first preset correspondence relationship includes a mapping relationship between the first folder and the first virtual disk; the network storage medium also synchronizes a second folder corresponding to the second terminal; the determination unit 303 is used to control the second terminal to obtain the encrypted target file from the second folder, and determine the second virtual disk corresponding to the second folder according to a pre-established second preset correspondence relationship; wherein the second preset correspondence relationship includes a mapping relationship between the second folder and the second virtual disk; the decryption unit 304 is used to control the second terminal to respond to the read operation of the target file through the second virtual disk, decrypt the encrypted target file through the second virtual disk, and read the decrypted target file.
[0128] The network synchronization data protection device provided by the embodiment of the present invention comprises: a first terminal responds to a write operation on a target file through a first virtual disk, and encrypts the target file through the first virtual disk; the first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset correspondence relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium; wherein the first preset correspondence relationship includes a mapping relationship between the first folder and the first virtual disk; a second folder corresponding to the second terminal is also synchronized in the network storage medium; the second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset correspondence relationship; wherein the second preset correspondence relationship includes a mapping relationship between the second folder and the second virtual disk; the second terminal responds to a read operation on the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file, thereby being able to safely and conveniently protect network synchronization data.
[0129] The embodiments of the present invention provide an embodiment of a network synchronization data protection device which can be specifically used to execute the processing flow of the above-mentioned method embodiments. Its functions are not described in detail here, and reference can be made to the detailed description of the above-mentioned method embodiments.
[0130] Figure 4 A schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as Figure 4 As shown, the electronic device includes: a processor (processor) 401, a memory (memory) 402 and a bus 403;
[0131] The processor 401 and the memory 402 communicate with each other via a bus 403;
[0132] The processor 401 is used to call the program instructions in the memory 402 to execute the methods provided by the above method embodiments, for example, including:
[0133] The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk;
[0134] The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0135] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0136] The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0137] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0138] The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0139] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can perform the methods provided by the above method embodiments, for example, including:
[0140] The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk;
[0141] The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0142] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0143] The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0144] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0145] The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0146] This embodiment provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program enables the computer to execute the methods provided by the above method embodiments, for example, including:
[0147] The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk;
[0148] The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium;
[0149] Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium;
[0150] The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship;
[0151] Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk;
[0152] The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
[0153] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0154] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0155] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0156] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0157] In the description of this specification, the description with reference to the terms "one embodiment", "a specific embodiment", "some embodiments", "for example", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0158] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A network synchronization data protection method, characterized in that: The network synchronization data protection method is applied to a first terminal and a second terminal, and includes: The first terminal responds to the write operation of the target file through the first virtual disk and encrypts the target file through the first virtual disk; The first terminal determines a first folder corresponding to the first virtual disk according to a pre-established first preset corresponding relationship, stores the encrypted target file in the first folder, and synchronizes the first folder to a network storage medium; Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium; The second terminal obtains the encrypted target file from the second folder, and determines a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship; Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk; The second terminal responds to the read operation of the target file through the second virtual disk, decrypts the encrypted target file through the second virtual disk, and reads the decrypted target file.
2. The network synchronization data protection method according to claim 1, characterized in that: Establishing the first preset corresponding relationship includes: In response to a first configuration action of configuring the first virtual disk corresponding to the first virtual file system and a second configuration action of configuring the first folder executed at the first terminal, the first preset corresponding relationship is established.
3. The network synchronization data protection method according to claim 2, characterized in that: Before the step of establishing the first preset corresponding relationship, the network synchronization data protection method further includes: In response to a first user authentication operation performed at the first terminal, the first virtual file system is started.
4. The network synchronization data protection method according to claim 1, characterized in that: The encrypting the target file by using the first virtual disk includes: The target file is encrypted by using a preset algorithm and the first virtual disk.
5. The network synchronization data protection method according to any one of claims 1 to 4, characterized in that: Establishing the second preset corresponding relationship includes: In response to a third configuration action of configuring the second virtual disk corresponding to the second virtual file system and a fourth configuration action of configuring the second folder executed at the second terminal, the second preset corresponding relationship is established.
6. The network synchronization data protection method according to claim 5, characterized in that: Before the step of establishing the second preset corresponding relationship, the network synchronization data protection method further includes: In response to a second user authentication operation performed at the second terminal, the second virtual file system is started.
7. The network synchronization data protection method according to claim 6, characterized in that: Decrypting the encrypted target file by using the second virtual disk includes: The same target preset algorithm as used for encryption is used, and the encrypted target file is decrypted through the second virtual disk.
8. A network synchronization data protection device, characterized in that: include: An encryption unit, used for controlling the first terminal to respond to a write operation on a target file through the first virtual disk, and encrypting the target file through the first virtual disk; A synchronization unit, configured to control the first terminal to determine a first folder corresponding to the first virtual disk according to a pre-established first preset correspondence, store the encrypted target file in the first folder, and synchronize the first folder to a network storage medium; Wherein, the first preset corresponding relationship includes a mapping relationship between a first folder and a first virtual disk; a second folder corresponding to a second terminal is also synchronized in the network storage medium; a determining unit, configured to control the second terminal to obtain the encrypted target file from the second folder, and determine a second virtual disk corresponding to the second folder according to a pre-established second preset corresponding relationship; Wherein, the second preset corresponding relationship includes a mapping relationship between a second folder and a second virtual disk; The decryption unit is used to control the second terminal to respond to the read operation of the target file through the second virtual disk, decrypt the encrypted target file through the second virtual disk, and read the decrypted target file.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.