File encryption method and device, equipment and medium
In the file encryption method, the key is randomly generated based on the text content of the file and encrypted with dynamic offsets, the security problem of key fixation in the prior art is solved, and higher file encryption security and reliability are achieved.
Patent Information
- Application Number
- CN202411823819.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, file encryption methods are easily cracked due to the problem of key fixation, resulting in file leakage.
By completing the verification process based on the user's identity information, the pending file uploaded by the user is obtained, and the file key is randomly generated based on the text content of the file, and the file is encrypted in combination with the preset dynamic offset.
By building file unique keys and dynamic offsets, file leakage caused by key theft is avoided, and the security and reliability of file encryption are improved.
Smart Images

Figure CN119989374A_ABST
Abstract
Description
Background Art
[0002] With the rapid development of information technology and the advancement of office digitization, many files with a high level of confidentiality will also be transmitted through the Internet and stored on the server side. This makes data security issues increasingly prominent, because in actual applications, there may be problems of hackers invading and stealing confidential files, thereby causing commercial losses to the corresponding users.
[0003] Therefore, it is necessary to encrypt various data and files of the enterprise to provide a certain security guarantee for the enterprise information. The commonly used file encryption method is: pre-build an encryption key, after obtaining the file, encrypt the file by asymmetric or symmetric encryption according to the pre-set encryption key, and then upload and store it for user access.
[0004] However, the commonly used methods currently have the following technical problems: since the secret key is fixed and the storage location of the secret key is calculated using a static fixed formula, once the secret key is leaked, the static key can be cracked by brute force, resulting in file leakage. Summary of the invention
[0005] The present invention provides a file encryption method, device, equipment and medium, which can solve the technical problems of low encryption security and easy cracking in the prior art.
[0006] A first aspect of an embodiment of the present invention provides a file encryption method, the method comprising: After completing the verification process according to the user's identity information, obtain the files to be processed uploaded by the user; Randomly generate a corresponding file key based on the text content of the file to be processed; The file to be processed is encrypted using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attribute of the file to be processed.
[0007] In combination with the first aspect, in one implementation, the randomly generating a corresponding file key based on the text content of the file to be processed includes: After reading the text content of the file summary of the file to be processed, a hash value of the text is obtained according to the text content; Generate a random string based on the hash value, and concatenate the random string, a preset obfuscation value, and a preset public key to obtain a file key; The preset obfuscation value is a value generated according to a user token, and the preset public key is a key pre-built by the user.
[0008] In combination with the first aspect, in one implementation, the using the file key and the preset dynamic offset to encrypt the to-be-processed file to obtain the encrypted file includes: Read the file to be processed through the AES encryption stream to obtain the data position of the file to be processed; The file key and the preset dynamic offset are operated with the data corresponding to the data position to obtain an encrypted file.
[0009] In conjunction with the first aspect, in one implementation, the operation of the calculation includes: Acquire data features of each row of data according to the data position, the data features including: data type, data priority, and data viewing permission value; The corresponding operation formula is searched according to the data feature, and the operation formula is used to operate the file key and the preset dynamic offset to obtain the encrypted file.
[0010] In conjunction with the first aspect, in one implementation, completing the verification process according to the user's identity information includes: When the user logs in, obtain the logo token extracted from the user's identity information; Determine whether the logo token is the same as a preset token, wherein the preset token is user information generated by the server and stored in the cache when the user logs in to the server for the first time; If they are the same, the verification process is completed; If they are not the same, the verification process is not completed.
[0011] In combination with the first aspect, in one implementation, after the step of obtaining the encrypted file, the method further includes: Obtaining an encrypted position of the encrypted file, where the encrypted position is a file position where the file key and a preset dynamic offset are encrypted and calculated and stored; The encrypted location is stored in a database, and a corresponding location ID is generated. The location ID is bound to the encrypted file for user access.
[0012] In combination with the first aspect, in one implementation, after the step of obtaining the encrypted file, the method further includes: After receiving and parsing the user's access request and completing the user's identity authentication, obtain the file name of the file accessed by the user; After determining the file ID corresponding to the file name, extracting the encrypted file from the database according to the location information corresponding to the file ID; After obtaining the preset decryption offset, the encrypted file is decrypted using the preset decryption offset to obtain a decrypted file.
[0013] A second aspect of an embodiment of the present invention provides a file encryption device, the device comprising: The file acquisition module is used to obtain the files to be processed uploaded by the user after completing the verification process according to the user's identity information; A key generation module, used for randomly generating a corresponding file key based on the text content of the file to be processed; The encryption module is used to encrypt the to-be-processed file using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attribute of the to-be-processed file.
[0014] In conjunction with the second aspect, in one implementation, the randomly generating a corresponding file key based on the text content of the file to be processed includes: After reading the text content of the file summary of the file to be processed, a hash value of the text is obtained according to the text content; Generate a random string based on the hash value, and concatenate the random string, a preset obfuscation value, and a preset public key to obtain a file key; The preset obfuscation value is a value generated according to a user token, and the preset public key is a key pre-built by the user.
[0015] In combination with the second aspect, in one implementation, the using the file key and the preset dynamic offset to encrypt the to-be-processed file to obtain the encrypted file includes: Read the file to be processed through the AES encryption stream to obtain the data position of the file to be processed; The file key and the preset dynamic offset are operated with the data corresponding to the data position to obtain an encrypted file.
[0016] In conjunction with the second aspect, in one implementation, the operation of the calculation includes: Acquire data features of each row of data according to the data position, the data features including: data type, data priority, and data viewing permission value; The corresponding operation formula is searched according to the data feature, and the operation formula is used to operate the file key and the preset dynamic offset to obtain the encrypted file.
[0017] In conjunction with the second aspect, in one implementation, completing the verification process according to the user's identity information includes: When the user logs in, obtain the logo token extracted from the user's identity information; Determine whether the logo token is the same as a preset token, wherein the preset token is user information generated by the server and stored in the cache when the user logs in to the server for the first time; If they are the same, the verification process is completed; If they are not the same, the verification process is not completed.
[0018] In conjunction with the second aspect, in one implementation, the device further includes: An acquisition position module, used for acquiring the encryption position of the encrypted file after the step of obtaining the encrypted file, wherein the encryption position is the file position stored after the file key and the preset dynamic offset are encrypted and calculated; The binding module is used to store the encrypted location in a database, generate a corresponding location ID, and bind the location ID to the encrypted file for user call.
[0019] In conjunction with the second aspect, in one implementation, the device includes: The module for obtaining the file name is used to obtain the file name of the file accessed by the user after receiving and parsing the user's access request and completing the user's identity authentication; A file extraction module, used to extract the encrypted file from the database according to the location information corresponding to the file ID after determining the file ID corresponding to the file name; The decryption module is used to decrypt the encrypted file using the preset decryption offset after obtaining the preset decryption offset to obtain a decrypted file.
[0020] Compared with the prior art, the file encryption method, device, equipment and medium provided by the embodiment of the present invention have the following beneficial effects: the present invention can obtain the to-be-processed file uploaded by the user after completing the verification process according to the user's identity information; randomly generate the corresponding file key based on the text content of the to-be-processed file; encrypt the to-be-processed file using the file key and a preset dynamic offset to obtain an encrypted file. The present invention constructs a unique and corresponding file key for the file through the text content of the file text, and uses the unique key for encryption to avoid file leakage due to key theft, so as to improve the security and reliability of file encryption. At the same time, the file key of each file is calculated based on the content of the file itself, and each file key is different, which can reduce the risk of the key being cracked, and further improve the security of the encrypted file. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 The following is a flowchart of a file encryption method provided by an embodiment of the present invention. Figure 1 ; Figure 2 The following is a flowchart of a file encryption method provided by an embodiment of the present invention. Figure 2 ; Figure 3 It is a structural schematic diagram of a file encryption device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0022] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0023] With the rapid development of information technology and the advancement of office digitization, many files with a high level of confidentiality will also be transmitted through the Internet and stored on the server side. This makes data security issues increasingly prominent, because in actual applications, there may be problems of hackers invading and stealing confidential files, thereby causing commercial losses to the corresponding users.
[0024] Therefore, it is necessary to encrypt various data and files of the enterprise to provide a certain security guarantee for the enterprise information. The commonly used file encryption method is: pre-build an encryption key, after obtaining the file, encrypt the file by asymmetric or symmetric encryption according to the pre-set encryption key, and then upload and store it for user access.
[0025] However, the commonly used methods currently have the following technical problems: since the secret key is fixed and the storage location of the secret key is calculated using a static fixed formula, once the secret key is leaked, the static key can be cracked by brute force, resulting in file leakage.
[0026] In order to solve the above problems, a file encryption method, device, equipment and medium provided in the embodiments of the present application will be introduced and explained in detail through the following specific embodiments.
[0027] Reference Figure 1 , which shows a schematic diagram of a process of a file encryption method provided by an embodiment of the present invention Figure 1 .
[0028] In one embodiment, the method is applicable to a file management server. The server may be a computer or a management system, and the server may be provided with a database, which may be used to store and manage various encrypted files. In order to facilitate different users to perform file encryption processing, the server may be connected to multiple smart terminals, and each smart terminal may be a user's mobile terminal, such as a mobile phone or a tablet computer.
[0029] As an example, the file encryption method may include: S11. After completing the verification process according to the user's identity information, obtain the to-be-processed file uploaded by the user.
[0030] In one embodiment, before a user needs to encrypt a file, he or she may upload identity information, including an account number, a password, and a verification code, through his or her smart terminal. The server may perform verification processing based on the user's identity information. After completing the verification processing based on the user's identity information, the file to be processed uploaded by the user through his or her smart terminal may be obtained. The file to be processed may be a file that the user needs to encrypt.
[0031] For example, if the user is an administrative staff of xx enterprise, the file to be processed may be the contract information of each employee of xx enterprise, which needs to be encrypted and kept.
[0032] For another example, if the user is a financial staff member of xx enterprise, the file to be processed may be the salary income of each employee of xx enterprise in March and the financial income of the enterprise in March, which needs to be encrypted and kept.
[0033] In specific operations, each file to be processed can be adjusted according to actual needs.
[0034] In one embodiment, if the user is required to upload identity information such as account, password and verification code for verification processing every time, the server processing takes a long time and is inefficient, which reduces the efficiency of the entire encryption processing. In order to improve the processing efficiency and simplify the verification processing process, as an example, the verification processing according to the user's identity information can include the following sub-steps: S111. When a user logs in, a logo token is extracted from the user identity information.
[0035] S112. Determine whether the logo token is the same as a preset token, wherein the preset token is user information generated by the server and stored in the cache when the user logs in to the server for the first time.
[0036] S113: If they are the same, the verification process is completed.
[0037] S114: If they are not the same, the verification process is not completed.
[0038] Specifically, when a user logs in to the server through his smart terminal, the user can directly upload his logo token. The logo token can be a token. The specific verification method can be to verify whether the user's token is valid through the server. If the verification is invalid, it will prompt to log in again. If it is valid, the verification process is completed.
[0039] The definition of the logo token Token can be a string of characters generated by the server, which is used as a token for the user's smart terminal to request. After the first login, the server generates two tokens, one is the logo token Token, and the other is the token corresponding to the logo token Token, which is the preset token. The logo token Token is sent to the user, and the other token is stored in the Redis cache to record user information, etc.
[0040] In the subsequent login process, when the user logs in to the server through his smart terminal, he only needs to bring this token to request data, without having to bring the username and password again. This can greatly simplify the entire verification process.
[0041] S12: Randomly generate a corresponding file key based on the text content of the file to be processed.
[0042] After obtaining the files to be processed, since the text content of each file to be processed may be the same or different, and the traditional encryption method is to encrypt with a fixed encryption key, the encryption key of each file is the same. Once the encryption key is cracked, all encrypted files can be decrypted, which will lead to file leakage and increase security risks.
[0043] To this end, the text content of the file to be processed can be obtained, and then the file key corresponding to the file to be processed can be randomly generated based on the text content of the file to be processed. Since the key of each file is generated according to its content, the key is not uniform, and the key is matched with the content of the file, so the two are related, associated and bound, and are specific. Subsequent encryption with its specific key can reduce the risk of cracking, improve the security of information, and ensure the security of information and files.
[0044] Since the text content of the file to be processed is various, including title, abstract, body and ending. If it is a table, it also contains various numerical values, images and graphics. In an optional embodiment, if the text content is directly read to construct the file key, when the text content of the file to be processed is relatively simple, there is still a risk of being cracked. In order to further improve the security of the file key and reduce the risk of being cracked, as an example, the corresponding file key is randomly generated based on the text content of the file to be processed, which can include the following sub-steps: S121. After reading the text content of the file summary of the file to be processed, a hash value of the text is obtained according to the text content.
[0045] S122. Generate a random string based on the hash value, and concatenate the random string, a preset obfuscation value, and a preset public key to obtain a file key.
[0046] The preset obfuscation value is a value generated according to a user token, and the preset public key is a key pre-built by the user.
[0047] Specifically, the text content of the file summary of the file to be processed can be read, and then the hash value of the text can be found according to the text content of the file summary, for example, a number A can be obtained. Then, the number A is modulo to obtain a number B less than 10, and then a random string of length B is generated.
[0048] Specifically, the text content of the file summary can be read, and the text content of the file summary can be input into a preset hash function (such as the common MD5, SHA-1, SHA-256 hash functions), and the hash value of the text can be calculated.
[0049] Optionally, a random character string may be arbitrarily generated according to the text content of the file summary, or a character string of a preset length may be arbitrarily extracted from the text content of the file summary to obtain a character string.
[0050] After obtaining the random string, the file key can be obtained by concatenating the random string, the preset obfuscation value and the preset public key. The obfuscation value can be a fixed value written in the code, or a value generated based on the user's token and a preset formula. The public key is a key obtained by conventional technical means and will not be described in detail here.
[0051] In one implementation, the concatenated file key may be as follows: File key = random string + obfuscation value + public key; File key: wxfads+525WTO+sdad8545.
[0052] The generated file key can then be written into the user's pending file to form the final file that needs to be encrypted.
[0053] Optionally, the number of characters in the random string, the obfuscated value, and the public key may be counted. If the number of characters is different, the characters are padded, and 0 characters may be padded to make the number of characters of the three the same.
[0054] When the random string, obfuscation value, and public key have the same number of characters, you can extract a character from the beginning of the random string, obfuscation value, and public key in order, and then concatenate the three characters into a combined character, and so on, until all characters are concatenated, you can get multiple combined characters. Finally, concatenate multiple combined characters to get the file key.
[0055] Referring to the above example, the random string is wxfads, the obfuscation value is 525WTO, and the public key is sdad8545. The number of characters in the three is different, the number of characters in the random string is 6, the number of characters in the obfuscation value is 6, and the number of characters in the public key is 8. The random string and the obfuscation value can be padded, the padded random string is wxfads00, and the obfuscation value is 525WTO00.
[0056] Next, we can extract a character from the beginning of the random string, the obfuscated value, and the public key, which are w, 5, and s, respectively, and combine them to get w5s, which is the first combined character. Then we extract the second character, which are x, 2, and d, respectively, and combine them to get x2d. And so on, we can get the last combined character 005.
[0057] Finally, multiple combination characters can be combined to obtain the file key.
[0058] In an optional embodiment, there may be multiple files that need to be encrypted, and the multiple files to be encrypted may record the same or similar text content. For example, it is necessary to encrypt multiple trading contracts of colleagues, and the summaries of the multiple trading contracts are similar. The file keys generated subsequently may be the same, and then the same file key is used for encryption. At this time, once any file key is stolen, multiple encrypted files may be cracked.
[0059] In order to avoid the above situation, as an example, after the step of concatenating the random string, the preset obfuscation value and the preset public key to obtain the file key, the method may further include: S123: Determine whether the file key is the same as multiple historical keys.
[0060] S124: If the file key is the same as any historical key, modify the random character string corresponding to the file key to obtain a modified character string.
[0061] S125. Concatenate the modification string, the preset obfuscation value and the preset public key to obtain a modification key.
[0062] In specific operations, if file keys are generated at the same time, after the file keys are generated, it can be determined whether multiple file keys are the same as each other, and whether the file key just generated is the same as several previous historical keys, where the historical key can be the file key generated first.
[0063] If the file key is the same as any historical key, the random string corresponding to the file key can be modified to obtain a modified string. Then the modified string, the preset obfuscation value and the preset public key are concatenated to obtain the modified key. The modified key can be used for subsequent encryption processing.
[0064] The modification method can be as follows: The first step is to obtain key features of the file key, wherein the key features include: a time node for generating the file key, an account authority value of a user corresponding to the file key, and an account type of the user corresponding to the file key; The second step is to extract a value from the key feature at random to obtain a feature value, and add characters corresponding to the feature value to a random character string to obtain a modified character string.
[0065] The random string may be modified to obtain a modified string by extracting the value of the key feature and adding characters corresponding to the value of the key feature to the random string.
[0066] Optionally, the characters corresponding to the characteristic value may be concatenated with the random character string to obtain a modified character string.
[0067] In another optional embodiment, the key comparison needs to be saved at the same time. Once the server is hacked, there is still a risk of the key being stolen. Therefore, when the key comparison is needed, several threads can be created according to the preset number, and then each thread reads an encrypted file that has been encrypted and saved, and extracts the encryption key corresponding to the file from an encrypted file, so as to obtain the historical key, and then compare the newly generated encryption key with the historical key. If there is no difference, several threads can be created according to the preset number, and then the comparison is performed, and so on.
[0068] In order to reduce the number of comparisons, the encryption key of the encrypted file here may be compared, and the previous encryption key of the deleted encrypted file may not be compared.
[0069] S13. Encrypt the file to be processed by using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attribute of the file to be processed.
[0070] After obtaining the encryption key, the file to be processed may be encrypted using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attributes of the file to be processed.
[0071] Specifically, the preset dynamic offset may be an offset obtained by calculation. The dynamic offset refers to a dynamic quantity a calculated based on a specific attribute of the file to be processed (such as a file hash value, or other file attribute values), and a modulus operation is performed on the dynamic quantity a to obtain a final dynamic offset A. Then, the file key and the preset dynamic offset may be used for encryption to obtain an encrypted file.
[0072] In one embodiment, if conventional encryption is performed using a file key and a preset dynamic offset, there is still a risk of being cracked. In order to further improve the encryption capability and prevent the encrypted file from being cracked to ensure the security of user information, as an example, the method of encrypting the file to be processed using the file key and the preset dynamic offset to obtain the encrypted file may include the following sub-steps: S131. Read the file to be processed through an AES encryption stream to obtain a data position of the file to be processed.
[0073] S132: Calculate the file key, the preset dynamic offset, and the data corresponding to the data position to obtain an encrypted file.
[0074] In the process of encrypting a file, key initialization and AES configuration are first performed. Specifically, the encryptor or decryptor is initialized using the AES algorithm based on the complete file key Key.
[0075] After the file key is initialized and AES is configured, in order to encrypt the content of the file to be processed, the preset dynamic offset is obtained, and the encryptor initialized with the AES algorithm is used to encrypt the content of the file to be processed according to the file key and the preset dynamic offset, thereby obtaining the encrypted file.
[0076] Specifically, the data of the file to be processed can be read by using the encryptor stream initialized with the AES algorithm to obtain the position of each line of data in the file to be processed, and the data position can be obtained. According to the data position, each line of data is subjected to an XOR operation or other conversion operation using the file key and a preset dynamic offset multiplied by a constant, and then written into the target file. Since the text content and each line of data may involve different types, for example, line a data is text characters, line b data is numbers, in order to target data of different types, different contents and different users, in one operation mode, the operation of performing calculations may include the following steps: S1321. Acquire data features of each row of data according to the data position, wherein the data features include: data type, data priority, and data viewing permission value.
[0077] S1322. Search for a corresponding calculation formula according to the data feature, and use the calculation formula to calculate the file key and a preset dynamic offset to obtain an encrypted file.
[0078] Users can pre-set a formula for different data features. For example, there are 10 data types, each of which corresponds to a calculation formula. For example, there are 5 data priorities, each of which corresponds to a calculation formula. There are 3 data viewing permissions, each of which corresponds to a calculation formula.
[0079] For example, the data type is a, the data priority is 2, and the data viewing permission is 3. Then, three calculation formulas are obtained based on the three data features. Then, the data to be calculated (file key and preset dynamic offset) is input into the calculation formula corresponding to the data type for calculation, the output result is input into the calculation formula corresponding to the data priority for calculation, and finally, the output result is input into the calculation formula corresponding to the data viewing permission for calculation to obtain the calculation result.
[0080] Through the above method, the difficulty of calculation can be increased, thereby improving the accuracy of encryption and reducing the risk of file cracking.
[0081] In an optional embodiment, the encrypted file needs to be stored in a database to ensure the security of the file. In order to record the location where the file is stored, it is convenient for the user to call the file when needed later. As an example, after the step of obtaining the encrypted file, the method further includes: S14. Obtain an encrypted position of the encrypted file, where the encrypted position is a file position stored after the file key and a preset dynamic offset are encrypted and calculated.
[0082] S15. Store the encrypted location in a database, generate a corresponding location ID, and bind the location ID to the encrypted file for user access.
[0083] After obtaining the encrypted file, the encrypted position of the encrypted file can be obtained, and the encrypted position is the location information of the file position stored after the file key and the preset dynamic offset are encrypted and calculated. Specifically, the file key and the preset dynamic offset can be recorded in the header of the encrypted stream file or other locations, and the location information of the stored file key and the preset dynamic offset can be obtained. Then, the location information of the file key and the preset dynamic offset can be stored in a database or other locations, and the ID corresponding to the storage location can be generated through file ID scheduling to obtain the location ID. The server can return the associated record of the location ID and the corresponding file to the user's smart terminal for subsequent calls by the user.
[0084] In this embodiment, the embodiment of the present invention provides a file encryption method, and its beneficial effects are: the present invention can obtain the to-be-processed file uploaded by the user after completing the verification process according to the user's identity information; randomly generate the corresponding file key based on the text content of the to-be-processed file; use the file key and the preset dynamic offset to encrypt the to-be-processed file to obtain an encrypted file. The present invention constructs a unique and corresponding file key of the file through the text content of the file text, and uses the unique key for encryption to avoid the situation where the file is leaked due to the key being stolen, so as to improve the security and reliability of file encryption. At the same time, the file key of each file is calculated according to the content of the file itself, and each file key is different, which can reduce the risk of the key being cracked, and further improve the security of the encrypted file.
[0085] Reference Figure 2 , which shows a schematic diagram of a process of a file encryption method provided by an embodiment of the present invention Figure 2 .
[0086] In one embodiment, the method is also applicable to a file management server. The server may be a computer or a management system, and the server may be provided with a database, which may be used to decrypt and manage various encrypted files. After the server encrypts the file, it stores the encrypted file in the database, and subsequent users may need to call the encrypted file. In order to allow users to quickly find the required encrypted file from the database and extract the original data content from it, as an example, after the step of obtaining the encrypted file, the method may also include: S21. After receiving and parsing the user's access request and completing identity authentication for the user, obtain the file name of the file accessed by the user.
[0087] S22. After determining the file ID corresponding to the file name, extract the encrypted file from the database according to the location information corresponding to the file ID.
[0088] S23. After obtaining a preset decryption offset, decrypt the encrypted file using the preset decryption offset to obtain a decrypted file.
[0089] Specifically, the user can access various encrypted files and other files stored on the server through his smart terminal. The server can receive and parse the access request sent by the user's smart terminal, verify the user's identity with a token, and determine the file name that the user expects to access through the token to obtain the file name.
[0090] Next, the file ID of the encrypted file to be retrieved can be obtained through the file name, and then the location information of the dynamic offset of the corresponding file can be obtained according to the file ID, so as to obtain the dynamic offset; the value of the dynamic offset is read out in the decryption stream according to the location information and converted into a number. If the conversion is successful, the verification is successful, otherwise it fails and the original file is returned. The encrypted file read can be the encrypted file constructed in the above embodiment.
[0091] After the dynamic offset is correctly read, the dynamic offset is used and multiplied by a constant to perform XOR decryption or other conversion operations on the read decryption stream data block, and the original data is restored through the AES decryption stream according to the complete key.
[0092] In this embodiment, the embodiment of the present invention provides a method for decrypting an encrypted file, and its beneficial effect is that: the present invention can obtain the file name of the file accessed by the user after receiving and parsing the user's access request and completing the identity authentication of the user; after determining the file ID corresponding to the file name, extract the encrypted file from the database according to the location information corresponding to the file ID; after obtaining the preset decryption offset, use the preset decryption offset to decrypt the encrypted file to obtain the decrypted file. Through the above operation, the required encrypted file can be quickly extracted and decrypted, which can improve the processing efficiency and facilitate the user to extract files.
[0093] The present invention also provides a file encryption device. Figure 3 , showing a schematic structural diagram of a file encryption device provided by an embodiment of the present invention.
[0094] Wherein, as an example, the file encryption device may include: The file acquisition module 310 is used to acquire the to-be-processed file uploaded by the user after completing the verification process according to the user's identity information; A key generation module 320, configured to randomly generate a corresponding file key based on the text content of the file to be processed; The encryption module 330 is used to encrypt the to-be-processed file using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attribute of the to-be-processed file.
[0095] Optionally, the randomly generating a corresponding file key based on the text content of the file to be processed includes: After reading the text content of the file summary of the file to be processed, a hash value of the text is obtained according to the text content; Generate a random string based on the hash value, and concatenate the random string, a preset obfuscation value, and a preset public key to obtain a file key; The preset obfuscation value is a value generated according to a user token, and the preset public key is a key pre-built by the user.
[0096] Optionally, the using the file key and a preset dynamic offset to encrypt the to-be-processed file to obtain an encrypted file includes: Read the file to be processed through the AES encryption stream to obtain the data position of the file to be processed; The file key and the preset dynamic offset are operated with the data corresponding to the data position to obtain an encrypted file.
[0097] Optionally, the operation of the calculation includes: Acquire data features of each row of data according to the data position, the data features including: data type, data priority, and data viewing permission value; The corresponding calculation formula is searched according to the data feature, and the calculation formula is used to calculate the file key and the preset dynamic offset to obtain the encrypted file Optionally, completing the verification process according to the user's identity information includes: When the user logs in, obtain the logo token extracted from the user's identity information; Determine whether the logo token is the same as a preset token, wherein the preset token is user information generated by the server and stored in the cache when the user logs in to the server for the first time; If they are the same, the verification process is completed; If they are not the same, the verification process is not completed.
[0098] Optionally, the device further comprises: An acquisition position module, used for acquiring the encryption position of the encrypted file after the step of obtaining the encrypted file, wherein the encryption position is the file position stored after the file key and the preset dynamic offset are encrypted and calculated; The binding module is used to store the encrypted location in a database, generate a corresponding location ID, and bind the location ID to the encrypted file for user call.
[0099] Optionally, the device may further include: The module for obtaining the file name is used to obtain the file name of the file accessed by the user after receiving and parsing the user's access request and completing the user's identity authentication; A file extraction module, used to extract the encrypted file from the database according to the location information corresponding to the file ID after determining the file ID corresponding to the file name; The decryption module is used to decrypt the encrypted file using the preset decryption offset after obtaining the preset decryption offset to obtain a decrypted file.
[0100] Those skilled in the art can clearly understand that, for the sake of convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0101] Furthermore, an embodiment of the present application also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the file encryption method as described in the above embodiment is implemented.
[0102] Furthermore, an embodiment of the present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer-executable program, and the computer-executable program is used to enable a computer to execute the file encryption method described in the above embodiment.
[0103] It should be noted that the orientation or positional relationship indicated by the terms "upper", "lower", etc. is based on the orientation or positional relationship shown in the accompanying drawings, which is only for the convenience of describing the embodiments of the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. When an element such as a layer, region or substrate is referred to as being "on" or "above" another element, it can be directly on the other element, or there can also be an intermediate element. On the contrary, when an element is referred to as "directly on" or "above" another element, there is no intermediate element. It should also be understood that when an element is referred to as being "under" or "below" another element, it can be directly under or below the other element, or there can also be an intermediate element. On the contrary, when an element is referred to as being "directly under" or "below" another element, there is no intermediate element. Unless otherwise clearly specified and limited, the terms "installed", "connected" and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0104] Those skilled in the art will appreciate that the embodiments of the present application may also provide computer program products. Therefore, the present application may adopt the form of complete hardware embodiments, complete software embodiments, or embodiments in combination with software and hardware. Moreover, the present application may adopt the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program codes.
[0105] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), apparatuses, and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0106] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0107] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0108] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A file encryption method, characterized in that: The method comprises: After completing the verification process according to the user's identity information, obtain the files to be processed uploaded by the user; Randomly generate a corresponding file key based on the text content of the file to be processed; The file to be processed is encrypted using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attribute of the file to be processed.
2. The file encryption method according to claim 1, characterized in that: The randomly generating a corresponding file key based on the text content of the file to be processed includes: After reading the text content of the file summary of the file to be processed, a hash value of the text is obtained according to the text content; Generate a random string based on the hash value, and concatenate the random string, a preset obfuscation value, and a preset public key to obtain a file key; The preset obfuscation value is a value generated according to a user token, and the preset public key is a key pre-built by the user.
3. The file encryption method according to claim 1, characterized in that: The step of encrypting the to-be-processed file by using the file key and the preset dynamic offset to obtain an encrypted file includes: Read the file to be processed through the AES encryption stream to obtain the data position of the file to be processed; The file key and the preset dynamic offset are operated with the data corresponding to the data position to obtain an encrypted file.
4. The file encryption method according to claim 3, characterized in that: The operations of the calculation include: Acquire data features of each row of data according to the data position, the data features including: data type, data priority, and data viewing permission value; The corresponding operation formula is searched according to the data feature, and the operation formula is used to operate the file key and the preset dynamic offset to obtain the encrypted file.
5. The file encryption method according to claim 1, characterized in that: The verification process is completed according to the user's identity information, including: When the user logs in, obtain the logo token extracted from the user's identity information; Determine whether the logo token is the same as a preset token, wherein the preset token is user information generated by the server and stored in the cache when the user logs in to the server for the first time; If they are the same, the verification process is completed; If they are not the same, the verification process is not completed.
6. The file encryption method according to any one of claims 1 to 5, characterized in that: After the step of obtaining the encrypted file, the method further comprises: Obtaining an encrypted position of the encrypted file, where the encrypted position is a file position where the file key and a preset dynamic offset are encrypted and calculated and stored; The encrypted location is stored in a database, and a corresponding location ID is generated. The location ID is bound to the encrypted file for user access.
7. The file encryption method according to any one of claims 1 to 5, characterized in that: After the step of obtaining the encrypted file, the method further comprises: After receiving and parsing the user's access request and completing the user's identity authentication, obtain the file name of the file accessed by the user; After determining the file ID corresponding to the file name, extracting the encrypted file from the database according to the location information corresponding to the file ID; After obtaining the preset decryption offset, the encrypted file is decrypted using the preset decryption offset to obtain a decrypted file.
8. A file encryption device, characterized in that: The device comprises: The file acquisition module is used to obtain the files to be processed uploaded by the user after completing the verification process according to the user's identity information; A key generation module, used for randomly generating a corresponding file key based on the text content of the file to be processed; The encryption module is used to encrypt the to-be-processed file using the file key and a preset dynamic offset to obtain an encrypted file, wherein the preset dynamic offset is a dynamic amount calculated according to the attribute of the to-be-processed file.
9. An electronic device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the file encryption method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer-executable program, and the computer-executable program is used to enable a computer to execute the file encryption method according to any one of claims 1 to 7.