File access control method and system, encryption method and system, controller and storage medium

By obtaining the files and addresses to be decrypted on the user side, determining whether to decrypt and determining the user access range based on the address, the existing access control methods are solved and the complex problems of vulnerability to attacks and key management are achieved, and efficient and secure file access control is achieved.

CN119995956APending Publication Date: 2025-05-13JIANGSU TIANHE ENERGY STORAGE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510078517.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Existing access control methods are vulnerable to attacks, and complex key management increases maintenance costs, affecting fast and convenient access to data.

Method used

By obtaining the file and address to be decrypted on the user side, determine whether to decrypt it. If so, determine the user access range based on the address and decrypt the file; if so, destroy the file to be decrypted. This method uses preset whitelists and intranet segment scope to determine decryption permissions, reducing the management complexity of username and password.

Benefits of technology

It realizes identity identification based on user-side address, reduces the complexity of access control and management costs, improves the security of sensitive data, and destroys files to be decrypted if they are not approved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995956A_ABST
    Figure CN119995956A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of access control and file encryption, particularly provides a file access control method and system, an encryption method and system, a controller and a storage medium, and aims to solve the problem of how to improve the security of data access at low cost. In order to achieve the purpose, the method comprises the steps that a to-be-decrypted file determined by a user side and a user side address are obtained, and whether the to-be-decrypted file is decrypted or not is judged according to the user side address; if yes, determining a user access range of the to-be-decrypted file according to the user side address; decrypting the to-be-decrypted file according to the user access range; and if not, destroying the to-be-decrypted file at the user side. Thus, a large number of user names and passwords do not need to be managed or stored, the user access range can be directly determined according to the user side address, the access permission of the user side address to the sensitive data stored in the file is limited according to the user access range, the security degree of the sensitive data is improved, and the complexity and management cost of file access control are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of access control and file encryption, and in particular to a file access control method, encryption method, system, controller and storage medium. Background Art

[0002] In modern computer network environments, data security and confidentiality are becoming increasingly important. Especially in enterprise environments, where large amounts of sensitive information need to be stored and transmitted, effective data encryption and access control systems are needed to protect this information.

[0003] However, existing access control methods usually rely on user names and passwords for user authentication, but this access control method is vulnerable to attacks such as password guessing and dictionary attacks, which reduces data security. Moreover, this access control method is not conducive to internal personnel circulating or modifying data, because internal personnel can access all data with just a user name and password, which may lead to the leakage of sensitive information and abuse of data. Existing data encryption technology usually requires a complex key management distribution mechanism, which requires high maintenance and management costs, and increases the complexity of the data access system, which is not conducive to internal staff's quick and convenient access to data.

[0004] Accordingly, a new solution is needed in the art to solve the above problems. Summary of the invention

[0005] In order to overcome the above-mentioned defects, the present application is proposed to solve or at least partially solve the technical problem of how to improve the security of data access at a low cost.

[0006] In a first aspect, a file access control method is provided, the method comprising:

[0007] Obtain the file to be decrypted determined by the user end;

[0008] Determining whether to decrypt the file to be decrypted according to the user terminal address;

[0009] If yes, determining the user access scope of the file to be decrypted according to the client address;

[0010] Decrypting the file to be decrypted according to the user access scope;

[0011] If not, destroy the file to be decrypted on the user terminal.

[0012] In a technical solution of the above file access control method,

[0013] The client address includes the physical address and Internet Protocol address accessed by the user;

[0014] The step of determining whether to decrypt the file to be decrypted according to the client address includes:

[0015] Based on a preset whitelist, determining whether the physical address meets the preset decryption requirements;

[0016] If yes, decrypt the file to be decrypted;

[0017] If not, determine whether the Internet Protocol address belongs to the intranet based on the intranet segment range;

[0018] If yes, decrypt the file to be decrypted;

[0019] If not, the file to be decrypted is not decrypted.

[0020] In a technical solution of the above file access control method,

[0021] The step of determining the user access range of the file to be decrypted according to the user terminal address includes:

[0022] If the physical address is in the preset whitelist, determining that the user access range is the entire data range of the file to be decrypted;

[0023] If the physical address is not in the preset whitelist and the Internet Protocol address belongs to the intranet, determining the user access scope according to the user terminal access rights corresponding to the Internet Protocol address;

[0024] The user terminal access rights are data access rights pre-allocated to the user terminal whose Internet Protocol address belongs to the intranet.

[0025] In a technical solution of the above file access control method,

[0026] Decrypting the file to be decrypted according to the user access scope includes:

[0027] Obtain all encrypted data information within the user access range of the file to be decrypted;

[0028] Decrypting the encrypted data information based on the key corresponding to the file to be decrypted to obtain decrypted data information;

[0029] According to the correspondence between the encrypted data information and the decrypted data information, the decrypted data information is used to overwrite the encrypted data information to obtain a decrypted file.

[0030] In a second aspect, a file encryption method is provided, the method comprising:

[0031] Get the file to be encrypted uploaded by the user;

[0032] Determine at least one user access range in the file to be encrypted, wherein the user access range is an accessible data range set for different client addresses;

[0033] The file to be encrypted is encrypted based on the user access scope.

[0034] In a technical solution of the above file encryption method,

[0035] The client address includes a physical address and an Internet Protocol address;

[0036] Determining at least one user access range in the file to be encrypted includes:

[0037] Determining original data information and processed data information in the file to be encrypted;

[0038] Determine a first user access range according to the processed data information, where the first user access range is a data range accessible to a user terminal address whose physical address is not in a preset whitelist and whose Internet Protocol address belongs to an intranet;

[0039] A second user access range is determined according to the original data information and the processed data information, where the second user access range is a data range accessible to a user terminal address whose physical address is in a preset whitelist.

[0040] In a technical solution of the above file encryption method,

[0041] The step of encrypting the file to be encrypted comprises:

[0042] Using a symmetric encryption algorithm to generate a key for the file to be encrypted;

[0043] Based on the key, encrypt the data information to be encrypted in the file to be encrypted to obtain encrypted data information;

[0044] According to the correspondence between the encrypted data information and the data information to be encrypted, the encrypted data information is used to overwrite the data information to be encrypted in the file to be encrypted, so as to obtain an encrypted file.

[0045] In a third aspect, there is provided a file access control system, the file access control system comprising an encryption module and an access control module;

[0046] The encryption module is used to execute the file encryption method described in any one of the above file encryption methods;

[0047] The access control module is used to execute the file encryption method described in any one of the above file encryption methods.

[0048] In a fourth aspect, a controller is provided, comprising at least one processor; and a memory communicatively connected to the at least one processor; wherein a computer program is stored in the memory, and when the computer program is executed by the at least one processor, the method described in any one of the technical solutions of the above-mentioned file access control method or file encryption method is implemented.

[0049] In a fifth aspect, a computer-readable storage medium is provided, which stores a plurality of program codes, wherein the program codes are suitable for being loaded and run by a processor to execute the method described in any one of the technical solutions of the above-mentioned file access control method or file encryption method.

[0050] The above one or more technical solutions of the present application have at least one or more of the following beneficial effects:

[0051] In the technical solution of the file access control method provided by the present application, the present application can obtain the to-be-decrypted file and the user-side address determined by the user end, and determine whether to decrypt the to-be-decrypted file according to the user-side address; if so, determine the user access range of the to-be-decrypted file according to the user-side address; decrypt the to-be-decrypted file according to the user access range; if not, destroy the to-be-decrypted file on the user end. Through the above configuration method, the present application can directly identify the identity of the accessing user according to the user-side address, without the need to manage or save a large number of user names and passwords, thereby reducing the complexity and management cost of file access control. At the same time, according to the user access range corresponding to the user-side address, the user-side address is restricted from accessing the sensitive data stored in the file, and the operation of directly destroying the to-be-decrypted file can be performed when the user-side address is not approved, which greatly improves the security of sensitive data in the file. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The disclosure of the present application will become easier to understand with reference to the accompanying drawings. It is easy for those skilled in the art to understand that these drawings are only for illustrative purposes and are not intended to limit the scope of protection of the present application. Among them:

[0053] Figure 1 It is a flowchart of the main steps of a file access control method according to an embodiment of the present application;

[0054] Figure 2 This is a flowchart of the main steps of a file access control method in one implementation of an embodiment of the present application;

[0055] Figure 3This is a flowchart of the main steps of a file encryption method according to an embodiment of the present application;

[0056] Figure 4 This is a flowchart of the main steps of a file encryption method in one implementation of an embodiment of the present application;

[0057] Figure 5 is a schematic diagram of the structure of a file access system according to an embodiment of the present application;

[0058] Figure 6 It is a schematic diagram of the main structure of a controller according to an embodiment of the present application.

[0059] Reference numerals:

[0060] 100: file access control system; 101: encryption module; 102: access control module; 11: memory; 12: processor. DETAILED DESCRIPTION

[0061] Some embodiments of the present application are described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present application and are not intended to limit the protection scope of the present application.

[0062] See attached Figure 1 , Figure 1 FIG. 1 is a flowchart of the main steps of a file access control method according to an embodiment of the present application. Figure 1 As shown, the file access control method in the embodiment of the present application mainly includes the following steps S101 to S105.

[0063] Step S101: Obtain the file to be decrypted determined by the user end.

[0064] In this embodiment, the file to be decrypted can be a file selected by the user to be decrypted. The file to be decrypted can be in a table (excel) format, a text (text) format, or a comma separated values ​​(CSV) file format, which does not affect the normal implementation of the embodiment of the present application.

[0065] In this embodiment, the user terminal may be a user-friendly window, application program or web browsing interface that can interact with the user and provide services to the user.

[0066] In one implementation, the Tkinter library can be used to implement the pages and windows for the user to interact with the user and to obtain and open the file to be decrypted selected by the user. The Tkinter library is a standard graphical user interface (GUI) library of Python, which is used to create a graphical user interface.

[0067] As an example, the filedialog module of the Tkinter library provides a simple dialog interface for users to select files or directories. Then, the askopenfilename or askopenfilenames method of the filedialog module is used to open a file dialog box to select one or more files and return the file path in a string. As an example, assuming that the file path of the file to be decrypted is file, the following code can be used to obtain the file to be decrypted:

[0068] from tkinter import filedialog

[0069] file=filedialog.askopenfilename()

[0070] Step S102: Determine whether to decrypt the file to be decrypted based on the client address. If so, proceed to step S103; if not, proceed to step S105.

[0071] In this embodiment, the user-side address may include an Internet Protocol address and a Media Access Control address. Among them, the Internet Protocol Address (IP Address) is a network layer address, which is the address used by the client to access the server. The client address may include a protocol (such as http: / / or https: / / ), a domain name (or IP address), a port number, a web application name, and a specific resource path. The Media Access Control Address (MAC Address), also known as a LAN Address, an Ethernet Address, a Hardware Address, or a Physical Address, is an address of the data link layer and is used to uniquely identify a network card in the network.

[0072] In one embodiment, the client address includes a physical address and an Internet Protocol address used by the client to determine the file to be decrypted.

[0073] In this embodiment, step S102 may further include steps S1021 to S1024:

[0074] Step S1021: Based on the preset whitelist, determine whether the physical address meets the preset decryption requirements; if so, proceed to step S1023, if not, proceed to step S1022.

[0075] Step S1022: Based on the intranet segment range, determine whether the Internet Protocol address belongs to the intranet. If yes, proceed to step S1023; if not, proceed to step S1024.

[0076] Step S1023: Decrypt the file to be decrypted.

[0077] Step S1024: Do not decrypt the file to be decrypted.

[0078] In this implementation, since the MAC address consists of a 48-bit binary number, which is usually expressed as 12 hexadecimal numbers, two MAC addresses containing 6 groups of hexadecimal numbers can be used to set the value range of the physical address as the preset white list, and every two hexadecimal numbers are separated by ":". For example, the preset white list can be set to [00-16-1c-b3-00-1c-bf, 00-16-EA-AE-3C-40].

[0079] In one implementation, the command in the getmac library of Python can be used to obtain the physical address of the user terminal. As an example, assuming that the obtained physical address is mac_address, the following code can be used to obtain the physical address of the user terminal:

[0080] import getmac

[0081] mac_address=getmac.get_mac_address(interface_name)

[0082] In one implementation, step S1021 can determine whether the physical address meets the preset decryption requirements based on whether the MAC address is in the preset whitelist. If the MAC address is in the preset whitelist, the physical address is determined to meet the preset decryption requirements; if the MAC address is not in the preset whitelist, the physical address is determined to not meet the preset decryption requirements.

[0083] In one implementation, the socket library used for network communication in Python can be used to obtain the IP address of the current client. Specifically, the client can be controlled to use the gethostname() function in the socket library to obtain the name of the current client, and then the IP address of the client can be obtained by communicating with the client. As an example, assuming that the obtained IP address is ip, the following code can be used to obtain the IP address of the client:

[0084] ip=socket.gethostbyname(socket.gethostname())

[0085] The gethostbyname function can be used to return a hostent structure containing the IP address information of the client according to the domain name of the client passed in. gethostname() is used to obtain the domain name of the client.

[0086] In one implementation, step S1022 can determine whether the Internet Protocol address (i.e., IP address) of the user terminal belongs to the intranet by determining whether the Internet Protocol address is within the intranet segment range. If the IP address is within the intranet segment range, then it is determined that the user terminal IP address belongs to the intranet; if not, then it is determined that the user terminal IP address does not belong to the intranet.

[0087] In one implementation, since the intranet IP address is usually within the private IP address range, the intranet network segment range can be set to the private IP address range, for example, the intranet network segment range can be set to 10.0.0.0 / 8, 172.16.0.0 / 12 to 172.31.0.0 / 16 or 192.168.0.0 / 16.

[0088] In this implementation, the built-in function any() in Python can be used to check whether there is at least one element in the intranet segment range that is the user's IP address. If it exists, the any() function returns True; if it does not exist, it returns False. As an example, assuming that the user's IP address is ip, the following code can be used to determine whether the Internet Protocol address belongs to the intranet:

[0089] result=any(ipaddress.ip_address(ip)in network for network inprivate_networks)

[0090] Among them, result is a Boolean value, which is used to indicate whether the user's IP address belongs to the intranet. ipaddress.ip_address(ip) is used to convert the ip string into an IP address object, and private_networks is the intranet segment range.

[0091] Step S103: Determine the user access scope of the file to be decrypted according to the user terminal address.

[0092] In this embodiment, at least two user access ranges can be set in the file to be decrypted, so that different user end addresses can access different data contents in the file to be decrypted, so as to protect sensitive data in the file to be decrypted. For example, when the file to be decrypted is in a table (excel) format, including worksheet 1, worksheet 2 and worksheet 3, each worksheet can be used as a user access range; when the file to be decrypted is in a text (txt) format, it can be divided into two access ranges according to the text line.

[0093] In one implementation, step S103 may further include steps S1031 to S1032:

[0094] Step S1031: If the physical address is in the preset whitelist, determine that the user access range is the entire data range of the file to be decrypted.

[0095] Step S1032: If the physical address is not in the preset whitelist and the Internet Protocol address belongs to the intranet, determine the user access scope according to the client access rights corresponding to the Internet Protocol address.

[0096] In this embodiment, the physical address refers to the MAC address of the user end.

[0097] In this embodiment, the user terminal access rights are data access rights pre-assigned to the user terminal whose Internet Protocol address belongs to the intranet. Correspondingly, the user access range can be divided in the to-be-decrypted file for the user terminal whose Internet Protocol address belongs to the intranet according to the user terminal access rights, so that the intranet user terminal can access the data content in the user access range.

[0098] In one embodiment, access rights to the files to be decrypted can be set for each client according to the client address as the client access rights. For example, a client whose MAC address is in a preset whitelist can have client access rights to access all files to be decrypted, and a client whose IP address belongs to an intranet and whose MAC address is not in the preset whitelist can have client access rights to access data in a preset table or preset location of the files to be decrypted.

[0099] In one implementation, two user access ranges may be set in the file to be decrypted, the first user access range being used to store unprocessed source data, the second user access range being used to store processed data, the user access range of the user terminal whose MAC address is in a preset whitelist being determined as the first user access range and the second user access range; the user access range of the user terminal whose MAC address is not in the preset whitelist and whose Internet Protocol address belongs to an intranet being determined as the second user access range.

[0100] Step S104: Decrypt the file to be decrypted according to the user access scope.

[0101] In this embodiment, the file to be decrypted may be decrypted locally at the user end, so that the decrypted file to be decrypted only displays data content within the user's access range.

[0102] In one implementation, step S104 may further include steps S1041 to S1043:

[0103] Step S1041: Acquire all encrypted data information within the user access range in the file to be decrypted.

[0104] Step S1042: decrypt the encrypted data information based on the key corresponding to the file to be decrypted to obtain the decrypted data information.

[0105] Step S1043: Based on the correspondence between the encrypted data information and the decrypted data information, the decrypted data information is used to overwrite the encrypted data information to obtain a decrypted file.

[0106] In this embodiment, if the file to be decrypted is decrypted using a symmetric encryption algorithm, each file to be decrypted may correspond to a key, and each file to be decrypted uses the same key for encryption and decryption. The user end may obtain the key corresponding to the file to be decrypted while obtaining the file to be decrypted. If the file to be decrypted is encrypted using an asymmetric algorithm, each file to be decrypted may correspond to a private key, and each file to be decrypted uses a public key for encryption and a private key for decryption. The user end may pre-store the private keys of all files to be decrypted, and after determining the user access scope, use the private key to decrypt the corresponding file to be decrypted. In some other embodiments, the corresponding private key may also be obtained while obtaining the file to be decrypted, which does not affect the normal implementation of this embodiment.

[0107] In one implementation, if the file to be decrypted is in a table (Excel) format, the decrypt method of the Fernet class can be used to decrypt the encrypted data within the user's access range back to the original format and the to_excel() method of the pandas library can be used to overwrite the encrypted data within the user's access range. Fernet is a symmetric encryption algorithm that can be used to encrypt and decrypt data. The main function of the decrypt method is to convert the encrypted data into the original data. The to_excel() function can be used to write two-dimensional table data into an Excel file.

[0108] In an application scenario according to this embodiment, assuming that the file to be decrypted is an Excel file containing multiple worksheets, step S1042 may further include steps S10421 to S10422:

[0109] Step S10421: Obtain the worksheets in the user access range in the Excel file, and read the encrypted data content of each worksheet.

[0110] Step S10422: Decrypt the encrypted data content to obtain the decrypted data content.

[0111] As an example, step S10422 may use the following code to decrypt the encrypted data content:

[0112] def decrypt_data(data_df,cipher):

[0113] Returndata_df.applymap(lambdax:cipher.decrypt(x.encode()).decode())

[0114] decrypted_df=decrypt_data(data_df,cipher)

[0115] decrypted_sheets[sheet_name]=decrypted_df

[0116] Among them, data_df is used to represent the encrypted data content, cipher is used to represent the key corresponding to the file to be decrypted, decrypted_df is used to represent the decrypted data content, sheet_name is used to represent the name of the current worksheet within the user's access range, and decrypted_sheets is a dictionary that saves the key-value pairs of the encrypted data content in the worksheet and the decrypted data content of the worksheet.

[0117] In this embodiment, the encrypted data content can be overwritten with the decrypted data content according to the dictionary storing the encrypted data content in the worksheet and the key-value pairs of the decrypted data content in the worksheet, so as to obtain a decrypted file. As an example, the following code can be used to implement the overwriting of the encrypted data content:

[0118] With pd.ExcelWriter(file)as writer:

[0119] for sheet_name,decrypted_df in decrypted_sheets.items():

[0120] decrypted_df.to_excel(writer,sheet_name=sheet_name,index=False)

[0121] Among them, file is the file path of the file to be decrypted on the user side, decrypted_df is used to represent the decrypted data content, sheet_name is used to represent the name of the current worksheet within the user's access range, and decrypted_sheets is a dictionary that saves the key-value pairs of the encrypted data content in the worksheet and the decrypted data content of the worksheet.

[0122] Step S105: destroy the file to be decrypted on the user side.

[0123] In this embodiment, the file to be decrypted can be pre-downloaded on the user terminal, and in the process of opening the file to be decrypted, the file to be decrypted is decrypted according to the user access range. When destroying the file to be decrypted, the process of opening the file to be decrypted can be terminated first, and then the file to be decrypted can be deleted.

[0124] In one implementation, assuming that the file to be decrypted is file and the path of the file to be decrypted is path, the file to be decrypted can be destroyed according to the following code:

[0125] os.system('taskkill / f / im{}'.format(file))

[0126] os.remove("path")

[0127] In an application scenario according to this embodiment, when the file to be decrypted is an Excel file, please refer to the attached Figure 2 , attached Figure 2 1 is a flowchart of the main steps of a file access control method in one implementation of an embodiment of the present application. Figure 2As shown, this embodiment may specifically include steps S201 to S206:

[0128] Step S201: Obtain the Excel file that needs to be decrypted by the user.

[0129] Step S202: Determine whether the client MAC address is in the whitelist. If so, proceed to step S203; if not, proceed to step S204.

[0130] Step S203: decrypt the original data of all worksheets in the Excel file, and write the decrypted data into the Excel file to overwrite the corresponding original data in the Excel file.

[0131] Step S204: Determine whether the IP address of the client belongs to the intranet. If so, proceed to step S206; proceed to step S205.

[0132] Step S205: destroy the excel file.

[0133] Step S206: decrypt the original data in the worksheet viewable by the intranet user, and write the decrypted data into the Excel file to overwrite the corresponding original data in the Excel file.

[0134] In this embodiment, the worksheet viewable by the intranet user can be used to save data processed by other users, processing log data or other non-sensitive data.

[0135] See attached Figure 3 , Figure 3 FIG. 1 is a flowchart of the main steps of a file encryption method according to an embodiment of the present application. Figure 3 As shown, the file encryption method in the embodiment of the present application mainly includes the following steps S301 to S303.

[0136] Step S301: Obtain the file to be encrypted uploaded by the user.

[0137] In this embodiment, the file to be encrypted may be a file that needs to be encrypted for storing data. The file to be encrypted may be in a table (excel) format, a text (text) format, or a comma separated values ​​(CSV) file format, which does not affect the normal implementation of the embodiment of the present application.

[0138] In this embodiment, the user can select the file path of the file to be encrypted through the user-friendly window, and then upload the file to be encrypted on the user end.

[0139] In one implementation, a user-friendly window can be created through a third library such as the tkinter library to obtain the file to be encrypted. As an example, the following code can be used to implement a user-friendly window and obtain the file selected by the user:

[0140] from tkinter import filedialog

[0141] file=filedialog.askopenfilename()

[0142] Among them, file is used to indicate the file to be encrypted.

[0143] Step S302: Determine at least one user access range in the file to be encrypted.

[0144] In this embodiment, the user access range is an accessible data range set for different user-side addresses.

[0145] In some other implementations, the user-side address may also include other types of addresses such as a DNS address, a public network address, a private address, a host number, a wireless network identifier, or a network port, all of which can be used to set the user access range in the file to be encrypted to allocate user access rights to user terminals with different addresses.

[0146] In one implementation, the user terminal address may include a physical address and an Internet Protocol address, and step S302 may further include steps S3021 to S3023:

[0147] Step S3021: Determine the original data information and processed data information in the file to be encrypted.

[0148] Step S3022: Determine the access scope of the first user according to the processed data information.

[0149] Step S3023: Determine the access scope of the second user according to the original data information and the processed data information.

[0150] In this embodiment, the first user access range is the data range accessible to the user-end address whose physical address is not in the preset whitelist and whose Internet Protocol address belongs to the intranet, and the second user access range is the data range accessible to the user-end address whose physical address is in the preset whitelist.

[0151] As an example, when the user address includes a MAC address and an IP address, two user access ranges can be set in the file to be encrypted, so that the user whose MAC address is in the whitelist can access both user access ranges at the same time, and the user whose MAC address is not in the whitelist and whose IP address belongs to the intranet can only access one of the user access ranges.

[0152] In one implementation, the file to be encrypted may be an Excel file, which includes multiple worksheets. For example, it may include worksheet 1, worksheet 2, and worksheet 3, wherein worksheet 1 is used to store original data information, and worksheet 2 and worksheet 3 are used to store data information after processing the original data information. Then worksheet 1 may be used as the first user access range, and worksheet 2 and worksheet 3 may be used as the second user access range.

[0153] Step S303: Encrypt the file to be encrypted based on the user access scope.

[0154] In this embodiment, different encryption methods or keys may be used to encrypt different user access ranges, so as to implement access permission configuration of different user access ranges in the file to be encrypted on the user end.

[0155] In one implementation, the file to be encrypted may be encrypted as a whole, and when the encrypted file to be encrypted is subsequently decrypted, the data information in the user access range is decrypted according to the user access range corresponding to the user terminal address of the user terminal.

[0156] In this embodiment, the encrypted file can be encrypted using a symmetric algorithm or an asymmetric algorithm, neither of which affects the normal implementation of the embodiment of the present application.

[0157] In one implementation, step S303 may further include steps S3031 to S3033:

[0158] Step S3031: Use a symmetric encryption algorithm to generate a key for the file to be encrypted.

[0159] In this embodiment, the encryption method using the symmetric encryption algorithm uses the same key when encrypting and decrypting files, so a key needs to be generated before performing the encryption operation.

[0160] Step S3032: Encrypt the data information to be encrypted in the file to be encrypted based on the key to obtain the encrypted data information.

[0161] Step S3033: Based on the correspondence between the encrypted data information and the data information to be encrypted, the encrypted data information is used to overwrite the data information to be encrypted in the file to be encrypted, so as to obtain an encrypted file.

[0162] In one implementation, step S303 may implement symmetric encryption of the file to be encrypted based on the Fernet class in the cryptography library, wherein the cryptography library is a powerful Python encryption library that provides high-level and low-level access methods to encryption algorithms and protocols, and may be used to implement functions such as data encryption, signature, and key management.

[0163] In this embodiment, a fixed-length byte string can be generated by a hash function. Since the key required for the Fernet class to implement symmetric encryption needs to be in a URL-safe format, the string generated by the hash function can be Base64-encoded, and the encoding result is processed by the Fernet class to obtain a key in a URL-safe format. The URL-safe format refers to a format that ensures that the URL is not tampered with or damaged during transmission.

[0164] As an example, step S3031 may use the following code to generate a key:

[0165] from cryptography.fernet import Fernet

[0166] import hashlib

[0167] import base64

[0168] def generate_key(password:str):

[0169] key=hashlib.sha256(password.encode()).digest()

[0170] return base64.urlsafe_b64encode(key)

[0171] cipher=Fernet(key)

[0172] Among them, key is used to represent the string generated by the hash function, and cipher is used to represent the generated key.

[0173] In one implementation, when the file to be encrypted is an Excel file, the contents of all worksheets in the Excel file are traversed, and each worksheet therein is encrypted to ensure that the data information in the file to be encrypted is encrypted.

[0174] As an example, you can use the method in the pandas library to read the contents of an Excel file. Use the following code to read the contents of each worksheet in the Excel file:

[0175] import pandas as pd

[0176] df = pd.ExcelFile(file)

[0177] for sheet_name in df.sheet_names:

[0178] data_df=df.parse(sheet_name)

[0179] Among them, flie is used to represent the file to be encrypted, sheet_names is used to represent all worksheets in the file to be encrypted, sheet_name is used to represent the current worksheet in the Excel file, and data_df is used to represent the contents of all worksheets.

[0180] In one implementation, the encrypt method of the Fernet class may be used in step S3032 to encrypt the data information of all worksheets in the file to be encrypted. For example, the following code may be used to encrypt the file to be encrypted:

[0181] def encrypt_data(data_df,cipher):

[0182] return data_df.applymap(lambdax:cipher.encrypt(x.encode()).decode())

[0183] encrypted_df=encrypt_data(data_df,cipher)

[0184] encrypted_sheets[sheet_name]=encrypted_df

[0185] Among them, data_df is used to represent the data information of all worksheets in the file to be encrypted, sheet_name is used to represent the current worksheet to be encrypted, encrypted_df is used to represent the encrypted data information, encrypted_sheets is used to represent the dictionary that stores the corresponding key-value pairs of the data information in the worksheet and the encrypted data information of the worksheet, and cipher is used to represent the key used for encryption.

[0186] In one implementation, in step S3033, the to_excel() method of the pandas library is used to overwrite the encrypted data information in the file to be encrypted with the encrypted data information. As an example, the following code can be used to overwrite the original data information of the file to be encrypted:

[0187] with pd.ExcelWriter(file)as writer:

[0188] for sheet_name,encrypted_df in encrypted_sheets.items():

[0189] encrypted_df.to_excel(writer,sheet_name=sheet_name,index=Fal se)

[0190] Among them, file is used to represent the file path of the file to be encrypted, encrypted_sheets is used to represent the dictionary that stores the corresponding key-value pairs of data information in the worksheet and the encrypted data information of the worksheet, sheet_name is used to represent the worksheet name in the file to be encrypted, and encrypted_df is used to represent the encrypted data information.

[0191] In an application scenario according to this embodiment, when the file to be encrypted is an Excel file, please refer to the attached Figure 4 , Figure 4 1 is a flowchart of the main steps of a file encryption method in one implementation of an embodiment of the present application. Figure 4 As shown, it may specifically include steps S401 to S404:

[0192] Step S401: Obtain the original Excel file to be encrypted.

[0193] Step S402: Generate a key.

[0194] Step S403: Read all worksheets in the original Excel, traverse all worksheets, and encrypt each element in the worksheet.

[0195] Step S404: Write the encrypted data into the Excel file to overwrite the original Excel file.

[0196] In other implementations, the data information of each user's access range may be obtained first, and the data information of each user's access range may be encrypted using the encryption method in the above implementation.

[0197] Based on the file access control method described in steps S101 to S105 above, the present application can directly identify the identity of the accessing user based on the user-side address, without the need to manage or save a large number of user names and passwords, thereby reducing the complexity and management cost of file access control. At the same time, based on the user access range corresponding to the user-side address, the access rights of the user-side address to sensitive data stored in the file are limited, and the operation of directly destroying the file to be decrypted can be performed when the user-side address is not approved, thereby greatly improving the security of sensitive data in the file.

[0198] Another aspect of the present application also provides a file access control system.

[0199] In an embodiment of a file access control system according to the present application, please refer to the attached Figure 5 , attached Figure 5 FIG. 1 is a schematic diagram of the structure of a file access system according to an embodiment of the present application. Figure 5 As shown, the file access control system 100 includes an encryption module 101 and an access control module 102 .

[0200] The encryption module 101 is used to execute the file encryption method described in the above embodiment;

[0201] The access control module 102 is used to execute the file access control method described in the above embodiment.

[0202] Another aspect of the present application also provides a computer-readable storage medium.

[0203] In an embodiment of a computer-readable storage medium according to the present application, the computer-readable storage medium may be configured to store a program for executing the file access control method or file encryption method of the above method embodiment, and the program may be loaded and run by a processor to implement the above file access control method or file encryption method. For ease of explanation, only the parts related to the embodiment of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiment of the present application. The computer-readable storage medium may be a storage device formed by various electronic devices. Optionally, the computer-readable storage medium in the embodiment of the present application is a non-temporary computer-readable storage medium.

[0204] Another aspect of the present application also provides a controller.

[0205] In an embodiment of a controller according to the present application, the controller may include at least one processor; and a memory connected to the at least one processor; wherein a computer program is stored in the memory, and when the computer program is executed by at least one processor, the file access control method or the file encryption method described in any of the above embodiments is implemented. The controller described in the present application may include but is not limited to mobile phones, tablet computers, desktop computers, laptops, handheld computers, notebook computers, vehicle-mounted devices, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), augmented reality (AR) and virtual reality (VR) devices, etc., and the embodiments of the present application are not limited to this. Please refer to the attached Figure 6 , Figure 6 FIG. 4 exemplarily shows that the memory 11 and the processor 12 are communicatively connected via a bus.

[0206] So far, the technical solution of the present application has been described in conjunction with an embodiment shown in the accompanying drawings, but it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments. Without departing from the principles of the present application, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present application.

Claims

1. A file access control method, characterized in that: include: Obtain the file to be decrypted determined by the user end; Determining whether to decrypt the file to be decrypted according to the user terminal address; If yes, determining the user access scope of the file to be decrypted according to the client address; Decrypting the file to be decrypted according to the user access scope; If not, destroy the file to be decrypted on the user terminal.

2. The file access control method according to claim 1, characterized in that: The client address includes the physical address and Internet Protocol address accessed by the user; The step of determining whether to decrypt the file to be decrypted according to the client address includes: Based on a preset whitelist, determining whether the physical address meets the preset decryption requirements; If yes, decrypt the file to be decrypted; If not, determine whether the Internet Protocol address belongs to the intranet based on the intranet segment range; If yes, decrypt the file to be decrypted; If not, the file to be decrypted is not decrypted.

3. The file access control method according to claim 2, characterized in that: The step of determining the user access range of the file to be decrypted according to the user terminal address includes: If the physical address is in the preset whitelist, determining that the user access range is the entire data range of the file to be decrypted; If the physical address is not in the preset whitelist and the Internet Protocol address belongs to the intranet, determining the user access scope according to the user terminal access rights corresponding to the Internet Protocol address; The user terminal access rights are data access rights pre-allocated to the user terminal whose Internet Protocol address belongs to the intranet.

4. The file access control method according to claim 1, characterized in that: Decrypting the file to be decrypted according to the user access scope includes: Obtain all encrypted data information within the user access range of the file to be decrypted; Decrypting the encrypted data information based on the key corresponding to the file to be decrypted to obtain decrypted data information; According to the correspondence between the encrypted data information and the decrypted data information, the decrypted data information is used to overwrite the encrypted data information to obtain a decrypted file.

5. A file encryption method, characterized in that: include: Get the file to be encrypted uploaded by the user; Determine at least one user access range in the file to be encrypted, wherein the user access range is an accessible data range set for different client addresses; The file to be encrypted is encrypted based on the user access scope.

6. The file encryption method according to claim 5, characterized in that: The client address includes a physical address and an Internet Protocol address; Determining at least one user access range in the file to be encrypted includes: Determining original data information and processed data information in the file to be encrypted; Determine a first user access range according to the processed data information, where the first user access range is a data range accessible to a user terminal address whose physical address is not in a preset whitelist and whose Internet Protocol address belongs to an intranet; A second user access range is determined according to the original data information and the processed data information, where the second user access range is a data range accessible to a user terminal address whose physical address is in a preset whitelist.

7. The file encryption method according to claim 5, characterized in that: The step of encrypting the file to be encrypted comprises: Using a symmetric encryption algorithm to generate a key for the file to be encrypted; Based on the key, encrypt the data information to be encrypted in the file to be encrypted to obtain encrypted data information; According to the correspondence between the encrypted data information and the data information to be encrypted, the encrypted data information is used to overwrite the data information to be encrypted in the file to be encrypted, so as to obtain an encrypted file.

8. A file access control system, characterized in that: The file access control system includes an encryption module and an access control module; The encryption module is used to execute the file encryption method described in any one of claims 5 to 7 above; The access control module is used to execute the file access control method described in any one of claims 1 to 4 above.

9. An electronic device, comprising a memory and a processor, characterized in that: The memory stores a computer program, and when the processor runs the program, the file access control method according to any one of claims 1 to 4 or the file encryption method according to any one of claims 5 to 7 is executed.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program, when running, executes the file access control method described in any one of claims 1 to 4 or the file encryption method described in any one of claims 5 to 7.