Fragmented encryption method and device for realizing OFD document security access, equipment and medium

By splitting OFD documents into multiple fragments and generating independent session keys for each fragment for encryption, the shortcomings of traditional encryption methods in data security and permission control are solved, and an efficient and secure OFD document access experience is achieved.

CN119939623APending Publication Date: 2025-05-06山东浪潮智慧医疗科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411941387.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The traditional OFD document encryption method has problems with data security and privacy protection during storage and transmission, and it is difficult to achieve fine-grained permission control and efficient access experience.

Method used

The fragmented encryption method is used to divide the OFD document into multiple fragments, and an independent session key is generated for each fragment for encryption. The encrypted fragments and metadata are stored on different encrypted hard disks respectively. After the user authenticates the permission, the required metadata and session key are obtained and reintegrated into an OFD document.

Benefits of technology

It realizes fine-grained encryption and access rights management of OFD documents, improves the security and access efficiency of documents, ensures the usage needs of legitimate users, and provides greater flexibility and usability in user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939623A_ABST
    Figure CN119939623A_ABST
Patent Text Reader

Abstract

The invention provides a fragmentation encryption method, device and equipment for achieving OFD document safe access and a medium, and belongs to the technical field of electronic document processing. The method comprises the steps that an OFD document is obtained and divided into a plurality of document fragments according to a preset rule, and a unique identifier and metadata are set; generating a session key for each document fragment to encrypt each document fragment; storing the encrypted document fragments in a first encrypted hard disk, integrating metadata into a metadata file, and storing the metadata file and each session key in a second encrypted hard disk; in response to an OFD document reading request of the user, after the reading permission of the user is verified, a metadata file and a session key of the required OFD document are returned from the second encrypted hard disk; and searching the encrypted document fragments according to the metadata file, decrypting the encrypted document fragments by using the session key, integrating the encrypted document fragments into an OFD document, and returning the OFD document to a user. The OFD document is encrypted in a fragmented manner, the file encryption efficiency is improved, and the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of electronic document processing, and in particular relates to a fragmentation encryption method, device, equipment and medium for realizing secure access to OFD documents. Background Art

[0002] OFD is the abbreviation of Open Fixed Document, an open format document.

[0003] With the development of information technology, OFD documents, as an open, standardized fixed-layout document format, have been widely used in electronic publishing, archive management and other application scenarios due to their cross-platform compatibility and information expression capabilities. However, OFD documents face the problem of data security and privacy protection during storage and transmission. Traditional document encryption methods usually encrypt the entire document as a whole. Although it protects the confidentiality of the document to a certain extent, it has many inconveniences in document access, editing, and sharing.

[0004] On the one hand, OFD documents may contain a large amount of sensitive information. Once this information is leaked, it will cause serious losses to the relevant parties. Traditional document encryption methods often encrypt the entire document uniformly. Once the encryption key is cracked, the content of the entire document will be completely exposed, and the security risk is extremely high. On the other hand, with the increasingly complex network environment today, documents face security threats from many aspects, especially the permission management of internal personnel in the enterprise has also become an important challenge. For example, the access rights of personnel in different departments and positions to documents should be different, but traditional encryption methods are difficult to achieve fine-grained permission control.

[0005] In addition, with the popularization of cloud computing and big data technology, the storage and access environment of OFD documents has become more complex and diverse. How to improve document access efficiency and user experience while ensuring data security has become an urgent problem to be solved in the current OFD document encryption technology. Summary of the invention

[0006] In a first aspect, an embodiment of the present application provides a fragmented encryption method for implementing secure access to OFD documents, comprising the following steps: S1. Obtain the OFD document and split it into several document fragments according to the preset rules, and set a unique identifier and metadata for each document fragment; S2. Generate an independent session key for each document fragment through the key management module, and use the corresponding session key to encrypt each document fragment; S3. The encrypted document fragments are stored in the first encrypted hard disk, the metadata is integrated into a metadata file and stored with each session key in the second encrypted hard disk; S4 responds to the user's OFD document read request, verifies the user's read permission, and returns the metadata file and session key of the required OFD document from the second encrypted hard disk; S5. According to the metadata file, the corresponding encrypted document fragments are searched from the first encrypted hard disk, decrypted using the session key, and then reassembled into an OFD document according to the original structure and returned to the user.

[0007] Furthermore, the specific steps of step S1 are as follows: S11. Obtain the OFD document and identify the document size; When the document size is greater than or equal to the first threshold, proceed to step S12; When the document size is less than the first threshold, proceed to step S13; S12. Divide the OFD document into document fragments according to page type, and proceed to step S14; S13. Segment the OFD document into document fragments according to paragraph type; S14. Set a unique identifier for each document fragment; S15. Create a metadata record for each fragment, recording the type, sequence number and location of the fragment in the OFD document.

[0008] Furthermore, the specific steps of step S2 are as follows: S21. The key management module randomly generates a master key, generates a session key equal to the document fragment using a key derivation function based on the master key, and assigns a session key to each document fragment; S22. Use the session key to encrypt the corresponding document fragment to obtain the encrypted document fragment.

[0009] Furthermore, the specific steps of step S3 are as follows: S31. storing each encrypted document fragment in a first encrypted hard disk, and recording the first storage location in the corresponding metadata; S32. The session key is stored in a second encrypted hard disk, and the second storage location is recorded in the corresponding metadata; S33. Integrate each metadata into a metadata file, encrypt it using the AES-256 encryption algorithm to obtain the metadata file ciphertext, and name the metadata file ciphertext using the association identifier of the original OFD document; S34. Save the metadata file ciphertext and its key to the second encrypted hard disk.

[0010] Furthermore, the specific steps of step S4 are as follows: S41. After receiving the user's OFD document read request, verify the user's authority; If the authority verification is passed, proceed to step S43; If the authority verification fails, proceed to step S42; S42 returns to the user that he has no right to view the OFD document, and ends; S43. Find the corresponding metadata file ciphertext and its key from the second encrypted hard disk according to the association identifier of the OFD document, decrypt the metadata file ciphertext using the AES-256 encryption algorithm, and obtain the metadata file; S44. Obtain metadata of each document fragment from the metadata file, and search for the session key of each document fragment from the second encrypted hard disk according to the second storage location in the metadata.

[0011] Furthermore, the specific steps of step S5 are as follows: S51. Searching for each encrypted document fragment from the first encrypted hard disk according to the first storage location in each metadata; S52. Decrypt the encrypted document fragments using the session key to obtain the original document fragments; S53. The document fragments are spliced ​​according to the sequence number recorded in the metadata and the position in the OFD document to obtain a reorganized OFD and return it to the user.

[0012] Furthermore, the specific steps of step S53 are as follows: S531. Sort the document fragments according to the sequence number recorded in the metadata; S532. Create an empty OFD document structure; S533. Traverse the sorted document fragments and insert them into the corresponding positions of the created OFD document structure according to the storage locations in the metadata; If the fragment is inserted successfully, go to step S537; If there is any fragment missing, go to step S534; S534. Determine whether the number of lost fragments exceeds a threshold or is at the beginning or end of a document; If yes, go to step S535; If not, proceed to step S536; S535. Continue to insert the remaining document fragments, and mark the missing parts in the reorganized OFD document, and proceed to step S537; S536. Continue to insert the remaining document fragments, and mark the missing parts in the reorganized OFD document, and generate a warning message added to the OFD document, indicating that the reorganized document may be incomplete or contain errors; S537. After format adjustment and verification of the reorganized OFD document, it is returned to the user.

[0013] In a second aspect, the embodiment of the present application further provides a fragmented encryption system for implementing secure access to OFD documents, including: The document fragmentation unit is used to obtain the OFD document and divide it into several document fragments according to preset rules, and set a unique identifier and metadata for each document fragment; A fragment independent encryption unit, used to generate an independent session key for each document fragment through a key management module, and encrypt each document fragment using the corresponding session key; A fragment storage unit, used for storing the encrypted document fragments in the first encrypted hard disk, integrating the metadata into a metadata file and storing the metadata with each session key in the second encrypted hard disk; A read permission verification unit, used to respond to a user's OFD document read request, verify the user's read permission and return the metadata file and session key of the required OFD document from the second encrypted hard disk; A fragment reassembly unit is used to search for corresponding encrypted document fragments from the first encrypted hard disk according to the metadata file, decrypt them using the session key, and then reintegrate them into an OFD document according to the original structure and return them to the user. In a third aspect, an embodiment of the present application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the fragmented encryption method for secure access to OFD documents as described in the first aspect are implemented.

[0014] In a fourth aspect, an embodiment of the present application further provides a storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the steps of the fragmented encryption method for secure access to OFD documents as described in the first aspect are implemented.

[0015] It can be seen from the above technical solutions that the present invention has the following advantages: The fragmented encryption method, device, equipment and medium for realizing secure access to OFD documents provided by the present application adopt a fragmented encryption method to perform fine-grained encryption and access permission management on OFD documents, thereby improving the security of the documents; by dividing the documents into fragments and encrypting them independently, even if some fragments are cracked, the entire document will not be leaked; at the same time, the encrypted fragments and metadata are stored in different encrypted hard disks respectively, further enhancing the security of the data; different segmentation strategies are adopted according to the size of the document, thereby improving the rationality and efficiency of the segmentation; in terms of document access, editing and sharing, users can partially access or modify the document content as needed without encrypting and decrypting the entire document, thereby improving the flexibility of use; a unique identifier and metadata are set for each document fragment, recording the type, serial number and the fragment in OFD The location of the document ensures that the original structure and format of the document can be accurately restored during reorganization; and when fragments are lost, different processing can be performed according to the situation, marking the missing part or generating an alarm message, which improves the user's awareness of the integrity of the reorganized document; when the user reads the document, the user's authority is verified first to ensure that only legitimate users can obtain the document, and the reorganized document is returned to the user after format adjustment and verification, which ensures the quality and availability of the document and improves the user experience. The present invention can improve the access efficiency and user experience of documents while ensuring data security, and adapts to the current complex storage and access environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solution of the present invention, the accompanying drawings required for use in the description will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0017] Figure 1 The figure is a flow chart of the fragmented encryption method for implementing secure access to OFD documents according to the present invention.

[0018] Figure 2 It is a schematic diagram of a fragmented encryption system for implementing secure access to OFD documents according to the present invention. DETAILED DESCRIPTION

[0019] In the specific steps of the fragmentation encryption method for implementing secure access to OFD documents, which will be described in detail below, various embodiments of the present disclosure will be described more comprehensively. The present disclosure may have various embodiments, and adjustments and changes may be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but the present disclosure should be understood to cover all adjustments, equivalents and / or alternatives that fall within the spirit and scope of the various embodiments of the present disclosure.

[0020] For example, OFD (Open Fixed Document), as a product of the advancement of information technology, has shown great application potential in many fields such as electronic publishing and archive management due to its openness and standardization. This document format is not only cross-platform compatible, but also can efficiently express complex information. However, with the widespread application of OFD documents, the issues of data security and privacy protection during their storage and transmission have become increasingly prominent. Traditional document encryption methods usually adopt an overall encryption strategy. Although it ensures the confidentiality of the document to a certain extent, it brings many inconveniences in practical applications. Especially when it is necessary to partially access or modify the content of the document, the overall encryption method requires the entire document to be decrypted and re-encrypted, which undoubtedly increases the computing cost and also increases the risk of the document content being stolen by unauthorized users during the decryption process.

[0021] In order to overcome the limitations of traditional encryption methods, fragmented encryption methods have emerged. This method divides OFD documents into multiple smaller fragments and encrypts each fragment independently, thus achieving fine-grained control of document content and flexible management of access rights. However, although the fragmented encryption method has improved the security of documents to a certain extent, there are still some problems that need to be solved when processing OFD documents.

[0022] On the one hand, some existing fragmentation encryption methods lack segmentation strategies tailored to the characteristics of OFD documents. Since OFD documents usually contain complex layouts and rich information elements, simple segmentation methods often fail to maintain the original structure and format of the document, resulting in a significant reduction in the quality of the reorganized document. On the other hand, some fragmentation encryption methods fail to fully consider the integrity and availability of document fragments during the encryption and storage process. Once some fragments are lost or damaged during storage or transmission, the entire document may be unrecoverable or only partially recoverable, causing serious losses to users.

[0023] In addition, with the rapid development of cloud computing and big data technology, the storage and access environment of OFD documents has become more complex and diverse. How to improve document access efficiency and user experience while ensuring data security has become an important challenge facing the current OFD document encryption technology.

[0024] In view of the above problems, this embodiment provides a fragmented encryption method for implementing secure access to OFD documents, which can improve document access efficiency and user experience while ensuring data security, and adapt to the current complex storage and access environment.

[0025] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0026] See also Figure 1 The flowchart of a fragmented encryption method for implementing secure access to OFD documents in a specific embodiment is shown, and the method includes the following steps: S1. Obtain the OFD document and split it into several document fragments according to the preset rules, and set a unique identifier and metadata for each document fragment; S2. Generate an independent session key for each document fragment through the key management module, and use the corresponding session key to encrypt each document fragment; S3. The encrypted document fragments are stored in the first encrypted hard disk, the metadata is integrated into a metadata file and stored with each session key in the second encrypted hard disk; S4 responds to the user's OFD document read request, verifies the user's read permission, and returns the metadata file and session key of the required OFD document from the second encrypted hard disk; S5. According to the metadata file, the corresponding encrypted document fragments are searched from the first encrypted hard disk, decrypted using the session key, and then reassembled into an OFD document according to the original structure and returned to the user.

[0027] This embodiment achieves fine-grained access permission management and improves document security by dividing the OFD document into fragments and encrypting them independently. At the same time, the encrypted fragments and metadata are stored in different encrypted hard disks, further enhancing data security. When a user reads a document, the required document can be accurately returned based on the permission verification result, ensuring the usage needs of legitimate users.

[0028] Further, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process in this embodiment, another fragmented encryption method for implementing secure access to OFD documents is provided, and the method includes the following steps: S1. Obtain an OFD document and divide it into several document fragments according to preset rules, and set a unique identifier and metadata for each document fragment; the specific steps of step S1 are as follows: S11. Obtain the OFD document and identify the document size; When the document size is greater than or equal to the first threshold, proceed to step S12; When the document size is less than the first threshold, proceed to step S13; S12. Divide the OFD document into document fragments according to page type, and proceed to step S14; S13. Segment the OFD document into document fragments according to paragraph type; S14. Set a unique identifier for each document fragment; S15. Create a metadata record for each fragment, recording the type, serial number and location of the fragment in the OFD document; It should be noted that different segmentation methods are used according to the size of the document to ensure that the fragments after segmentation can better maintain the original structure and format of the document when reorganized; for larger documents, segmentation is performed by page type, and for smaller documents, segmentation is performed by paragraph type, which improves the rationality and efficiency of segmentation; S2. Generate an independent session key for each document fragment through the key management module, and use the corresponding session key to encrypt each document fragment; the specific steps of step S2 are as follows: S21. The key management module randomly generates a master key, generates a session key equal to the document fragment using a key derivation function based on the master key, and assigns a session key to each document fragment; S22. Encrypt the corresponding document fragments using the session key to obtain encrypted document fragments; It should be noted that the key management module randomly generates a master key and derives a session key, assigning an independent session key to each document fragment for encryption, which enhances the security of encryption and prevents a single key from being cracked, leading to the leakage of the entire document; S3. The encrypted document fragments are stored in the first encrypted hard disk, and the metadata is integrated into a metadata file and stored with each session key in the second encrypted hard disk; the specific steps of step S3 are as follows: S31. storing each encrypted document fragment in a first encrypted hard disk, and recording the first storage location in the corresponding metadata; S32. The session key is stored in a second encrypted hard disk, and the second storage location is recorded in the corresponding metadata; S33. Integrate each metadata into a metadata file, encrypt it using the AES-256 encryption algorithm to obtain the metadata file ciphertext, and name the metadata file ciphertext using the association identifier of the original OFD document; S34. Save the metadata file ciphertext and its key to the second encrypted hard disk; It should be noted that the encrypted document fragments are stored in the first encrypted hard disk, and the storage location is recorded in the metadata to facilitate subsequent search and reorganization; the metadata file is encrypted and named using the associated identifier of the original OFD document, which improves the security and identifiability of the metadata; S4. Respond to the user's OFD document read request, verify the user's read permission and return the metadata file and session key of the required OFD document from the second encrypted hard disk; the specific steps of step S4 are as follows: S41. After receiving the user's OFD document read request, verify the user's authority; If the authority verification is passed, proceed to step S43; If the authority verification fails, proceed to step S42; S42 returns to the user that he has no right to view the OFD document, and ends; S43. Find the corresponding metadata file ciphertext and its key from the second encrypted hard disk according to the association identifier of the OFD document, decrypt the metadata file ciphertext using the AES-256 encryption algorithm, and obtain the metadata file; S44. Obtaining metadata of each document fragment from the metadata file, and searching the session key of each document fragment from the second encrypted hard disk according to the second storage location in the metadata; It should be noted that when a user makes a read request, the user's permissions are verified first to ensure that only legitimate users can access the document; the metadata file ciphertext is found and decrypted through the associated identifier, and then the session key is obtained, ensuring the security and accuracy of document access; S5. According to the metadata file, the corresponding encrypted document fragments are searched from the first encrypted hard disk and decrypted using the session key, and then reintegrated into an OFD document according to the original structure and returned to the user; the specific steps of step S5 are as follows: S51. Searching for each encrypted document fragment from the first encrypted hard disk according to the first storage location in each metadata; S52. Decrypt the encrypted document fragments using the session key to obtain the original document fragments; S53. According to the sequence number recorded in the metadata and the position of the OFD document, the document fragments are spliced ​​to obtain the reorganized OFD and returned to the user; It should be noted that the encrypted document fragments are searched and decrypted according to the storage location in the metadata, thereby achieving accurate restoration of the document fragments; the document fragments are spliced ​​according to the sequence number and position, ensuring that the reorganized document is consistent with the original document structure.

[0029] In an embodiment of the present invention, based on step S53, a possible embodiment is given below to illustrate its specific implementation scheme in a non-limiting manner.

[0030] The specific steps of step S53 are as follows: S531. Sort the document fragments according to the sequence number recorded in the metadata; S532. Create an empty OFD document structure; S533. Traverse the sorted document fragments and insert them into the corresponding positions of the created OFD document structure according to the storage locations in the metadata; If the fragment is inserted successfully, go to step S537; If there is any fragment missing, go to step S534; S534. Determine whether the number of lost fragments exceeds a threshold or is at the beginning or end of a document; If yes, go to step S535; If not, proceed to step S536; S535. Continue to insert the remaining document fragments, and mark the missing parts in the reorganized OFD document, and proceed to step S537; S536. Continue to insert the remaining document fragments, and mark the missing parts in the reorganized OFD document, and generate a warning message added to the OFD document, indicating that the reorganized document may be incomplete or contain errors; S537. After the reorganized OFD document is formatted and verified, it is returned to the user; It should be noted that the document fragments are sorted and inserted to ensure the orderliness of the reorganization process; when fragments are lost, different processing is performed according to the situation, marking the missing parts or generating alarm information to remind users to identify the integrity of the document after reorganization, while trying to ensure that users can obtain some available content.

[0031] It should be understood that the order of execution of the steps in the above embodiment does not necessarily mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present invention.

[0032] like Figure 2 As shown, the following is an embodiment of a fragmented encryption system for implementing secure access to OFD documents provided by an embodiment of the present disclosure. The system and the fragmented encryption methods for implementing secure access to OFD documents in the above-mentioned embodiments belong to the same inventive concept. For details not fully described in the embodiment of the fragmented encryption system for implementing secure access to OFD documents, reference can be made to the above-mentioned embodiments of the fragmented encryption methods for implementing secure access to OFD documents.

[0033] The system includes: The document fragmentation unit is used to obtain the OFD document and divide it into several document fragments according to preset rules, and set a unique identifier and metadata for each document fragment; A fragment independent encryption unit, used to generate an independent session key for each document fragment through a key management module, and encrypt each document fragment using the corresponding session key; A fragment storage unit, used for storing the encrypted document fragments in the first encrypted hard disk, integrating the metadata into a metadata file and storing the metadata with each session key in the second encrypted hard disk; A read permission verification unit, used to respond to a user's OFD document read request, verify the user's read permission and return the metadata file and session key of the required OFD document from the second encrypted hard disk; The fragment reassembly unit is used to search the corresponding encrypted document fragments from the first encrypted hard disk according to the metadata file, decrypt them using the session key, and then reassemble them into an OFD document according to the original structure and return them to the user.

[0034] The document fragmentation unit of this embodiment ensures that the document segmentation is reasonable, the fragment independent encryption unit improves the encryption security, the fragment storage unit ensures the data storage security, the read permission verification unit guarantees the access of legitimate users, and the fragment reorganization unit realizes the accurate reorganization of the document. Finally, through the collaborative work of various units, the fragmented encryption, storage and secure reading of OFD documents are realized.

[0035] The fragmentation encryption method for realizing safe access of OFD documents provided in the embodiment of the present application can be applied to electronic devices. It will be appreciated by those skilled in the art that the electronic device structure involved in the embodiment of the present invention does not constitute a limitation on the electronic device, and the electronic device may include more or less components than shown in the figure, or combine certain components, or arrange different components. In the embodiment of the present invention, the electronic device includes but is not limited to a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the embodiments of the present application described herein and / or required.

[0036] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, buttons, a camera, a display, and a SIM card interface, etc.

[0037] It is to be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device. In other embodiments of the present application, the electronic device may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0038] The processor may include one or more processing units, for example, the processor may include a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated into one or more processors.

[0039] The processor can be the nerve center and command center of the electronic device. The controller can generate an operation control signal according to the instruction operation code and timing signal to complete the control of fetching and executing instructions.

[0040] A memory may also be provided in the processor for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. The memory may store instructions or data that the processor has just used or is cyclically used. If the processor needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor, and thus improves system efficiency.

[0041] The above-mentioned electronic device implements the fragmented encryption method of the present application for realizing secure access to OFD documents, which includes obtaining an OFD document and dividing it into several document fragments according to preset rules and setting a unique identifier and metadata; generating a session key for each document fragment to encrypt each document fragment; storing the encrypted document fragments on a first encrypted hard disk, integrating the metadata into a metadata file and storing it with each session key on a second encrypted hard disk; responding to a user's OFD document read request, verifying the user's read permission and returning the metadata file and session key of the required OFD document from the second encrypted hard disk; searching for the encrypted document fragments according to the metadata file and decrypting them with the session key, and then integrating them into an OFD document and returning them to the user. The technical solution can achieve the beneficial effect of improving document access efficiency and user experience while ensuring data security.

[0042] The storage medium provided in the present application stores a program product capable of implementing the fragmented encryption method for secure access to OFD documents of the present application.

[0043] The fragmented encryption method for achieving secure access to OFD documents includes: obtaining an OFD document and dividing it into several document fragments according to preset rules, setting a unique identifier and metadata for each document fragment; generating an independent session key for each document fragment through a key management module, and using the corresponding session key to encrypt each document fragment; storing the encrypted document fragments on a first encrypted hard disk, integrating the metadata into a metadata file and storing it with each session key on a second encrypted hard disk; responding to a user's OFD document read request, verifying that the user's read authority is passed, and returning the metadata file and session key of the required OFD document from the second encrypted hard disk; searching for the corresponding encrypted document fragment from the first encrypted hard disk according to the metadata file, decrypting it using the session key, and then reintegrating it into an OFD document according to the original structure and returning it to the user.

[0044] In some possible implementations, the fragmented encryption method for implementing secure access to OFD documents disclosed herein can be implemented in the form of a program product, which includes a program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps described in the above "Exemplary Method" section of this specification according to various exemplary implementations of the present disclosure.

[0045] The storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0046] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A fragmentation encryption method for achieving secure access to OFD documents, characterized in that: The steps include: S1. Obtain the OFD document and split it into several document fragments according to the preset rules, and set a unique identifier and metadata for each document fragment; S2. Generate an independent session key for each document fragment through the key management module, and use the corresponding session key to encrypt each document fragment; S3. The encrypted document fragments are stored in the first encrypted hard disk, the metadata is integrated into a metadata file and stored with each session key in the second encrypted hard disk; S4 responds to the user's OFD document read request, verifies the user's read permission, and returns the metadata file and session key of the required OFD document from the second encrypted hard disk; S5. According to the metadata file, the corresponding encrypted document fragments are searched from the first encrypted hard disk, decrypted using the session key, and then reassembled into an OFD document according to the original structure and returned to the user.

2. The fragmentation encryption method for implementing secure access to OFD documents according to claim 1, characterized in that: The specific steps of step S1 are as follows: S11. Obtain the OFD document and identify the document size; When the document size is greater than or equal to the first threshold, proceed to step S12; When the document size is less than the first threshold, proceed to step S13; S12. Divide the OFD document into document fragments according to page type, and proceed to step S14; S13. Segment the OFD document into document fragments according to paragraph type; S14. Set a unique identifier for each document fragment; S15. Create a metadata record for each fragment, recording the type, sequence number and location of the fragment in the OFD document.

3. The fragmentation encryption method for implementing secure access to OFD documents according to claim 2, characterized in that: The specific steps of step S2 are as follows: S21. The key management module randomly generates a master key, generates a session key equal to the document fragment using a key derivation function based on the master key, and assigns a session key to each document fragment; S22. Use the session key to encrypt the corresponding document fragment to obtain the encrypted document fragment.

4. The fragmentation encryption method for implementing secure access to OFD documents according to claim 3, characterized in that: The specific steps of step S3 are as follows: S31. storing each encrypted document fragment in a first encrypted hard disk, and recording the first storage location in the corresponding metadata; S32. The session key is stored in a second encrypted hard disk, and the second storage location is recorded in the corresponding metadata; S33. Integrate each metadata into a metadata file, encrypt it using the AES-256 encryption algorithm to obtain the metadata file ciphertext, and name the metadata file ciphertext using the association identifier of the original OFD document; S34. Save the metadata file ciphertext and its key to the second encrypted hard disk.

5. The fragmentation encryption method for implementing secure access to OFD documents according to claim 4, characterized in that: The specific steps of step S4 are as follows: S41. After receiving the user's OFD document read request, verify the user's authority; If the authority verification is passed, proceed to step S43; If the authority verification fails, proceed to step S42; S42 returns to the user that he has no right to view the OFD document, and ends; S43. Find the corresponding metadata file ciphertext and its key from the second encrypted hard disk according to the association identifier of the OFD document, decrypt the metadata file ciphertext using the AES-256 encryption algorithm, and obtain the metadata file; S44. Obtain metadata of each document fragment from the metadata file, and search for the session key of each document fragment from the second encrypted hard disk according to the second storage location in the metadata.

6. The fragmentation encryption method for implementing secure access to OFD documents according to claim 5, characterized in that: The specific steps of step S5 are as follows: S51. Searching for each encrypted document fragment from the first encrypted hard disk according to the first storage location in each metadata; S52. Decrypt the encrypted document fragments using the session key to obtain the original document fragments; S53. The document fragments are spliced ​​according to the sequence number recorded in the metadata and the position in the OFD document to obtain a reorganized OFD and return it to the user.

7. The fragmentation encryption method for implementing secure access to OFD documents according to claim 6, characterized in that: The specific steps of step S53 are as follows: S531. Sort the document fragments according to the sequence number recorded in the metadata; S532. Create an empty OFD document structure; S533. Traverse the sorted document fragments and insert them into the corresponding positions of the created OFD document structure according to the storage locations in the metadata; If the fragment is inserted successfully, go to step S537; If there is any fragment missing, go to step S534; S534. Determine whether the number of lost fragments exceeds a threshold or is at the beginning or end of a document; If yes, go to step S535; If not, proceed to step S536; S535. Continue to insert the remaining document fragments, and mark the missing parts in the reorganized OFD document, and proceed to step S537; S536. Continue to insert the remaining document fragments, and mark the missing parts in the reorganized OFD document, and generate a warning message added to the OFD document, indicating that the reorganized document may be incomplete or contain errors; S537. After format adjustment and verification of the reorganized OFD document, it is returned to the user.

8. A fragmented encryption system for implementing secure access to OFD documents, characterized in that: include: The document fragmentation unit is used to obtain the OFD document and divide it into several document fragments according to preset rules, and set a unique identifier and metadata for each document fragment; A fragment independent encryption unit, used to generate an independent session key for each document fragment through a key management module, and encrypt each document fragment using the corresponding session key; A fragment storage unit, used for storing the encrypted document fragments in the first encrypted hard disk, integrating the metadata into a metadata file and storing the metadata with each session key in the second encrypted hard disk; A read permission verification unit, used to respond to a user's OFD document read request, verify the user's read permission and return the metadata file and session key of the required OFD document from the second encrypted hard disk; The fragment reassembly unit is used to search the corresponding encrypted document fragments from the first encrypted hard disk according to the metadata file, decrypt them using the session key, and then reassemble them into an OFD document according to the original structure and return them to the user.

9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the fragmented encryption method for realizing secure access to OFD documents as claimed in any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the fragmented encryption method for implementing secure access to OFD documents as claimed in any one of claims 1 to 7 are implemented.