File encryption storage method, storage medium and equipment
By slicing files and scattering them in multiple storage nodes, the security risks caused by plaintext file storage at the data storage level in the prior art are solved, and higher file storage and access confidentiality and security are achieved.
Patent Information
- Application Number
- CN202510480932.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-17
AI Technical Summary
The existing technology has clear file storage at the data storage level, which violates the principle of minimum permissions, resulting in the exposure of sensitive information to risks such as internal overprivileges, external malicious attacks, and supply chain penetration, hiding severe data leakage risks and compliance crises.
By slicing the file and storing it in different file paths in one or more storage nodes, the access control of files is strengthened to ensure that files can only be accessed through the system interface.
It improves the confidentiality of file storage and access, reduces the security risks of file storage, enhances the protection of sensitive information, and reduces the risks of data leakage and compliance.
Smart Images

Figure CN120012139A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of file storage, and in particular to a file encryption storage method, a storage medium and a device. Background Art
[0002] With the in-depth evolution of the digitalization process, data assets have become the key carrier of the core competitiveness of enterprises, and the security issues that come with it have also risen to the core issues of various industries. At present, although most companies implement transport layer encryption on the communication links between servers and clients and web pages through the HTTPS protocol, there is still a widespread phenomenon of directly retaining files in plain text at the data storage level. This type of storage mode not only violates the principle of least privilege, but also exposes sensitive information to multiple risks such as internal unauthorized access, external malicious attacks, and supply chain penetration, which hides serious data leakage risks and compliance crises. Summary of the invention
[0003] Based on this, the present invention provides a file encryption storage method, storage medium and device, which encrypts file slices and stores the encrypted slices in different file paths in one or more storage nodes, ensuring that resource files can only be accessed through a system interface, avoiding direct access to files, improving the confidentiality of file storage and access, and reducing security risks of file storage.
[0004] In a first aspect, the present invention provides a file encryption storage method, which is applied to a file storage system, wherein the file storage system includes a file storage server and a plurality of storage nodes, wherein the file storage server is in communication connection with each storage node, and the file encryption storage method is executed by the file storage server, and includes the following steps:
[0005] Step S101, obtaining a file to be encrypted and a preset file slice length;
[0006] Step S102, randomly generating a first random number, and obtaining an actual slice length according to the first random number and a preset file slice length;
[0007] Step S103: cutting the file to be encrypted in sequence from the cutting starting point according to the actual slice length to obtain a first file slice;
[0008] Step S104, randomly generating a second random number;
[0009] Step S105, converting the first random number into hexadecimal to obtain a slice header, and converting the second random number into hexadecimal to obtain a slice tail;
[0010] Step S106, sequentially concatenate the slice header, the first file slice, the second random number, and the slice tail to obtain a slice to be encrypted;
[0011] Step S107, encrypting the slice to be encrypted according to the MD5 value of the previous file slice to obtain a pre-encrypted slice;
[0012] Step S108, performing secondary encryption on the MD5 value of the previous file slice and the pre-encrypted slice to obtain the MD5 value of the first file slice;
[0013] Step S109, sequentially concatenating the MD5 value of the previous file slice, the pre-encrypted slice, and the MD5 value of the first file slice to obtain a slice encrypted file;
[0014] Step S110, taking the end position of the first file slice as the starting point for cutting the next file slice in the file to be encrypted, and repeating the above steps S102-S109 until all contents in the file to be encrypted are encrypted, thereby obtaining a plurality of slice encrypted files;
[0015] Step S111, using the first several bits of the MD5 value of each first file slice as the file storage path of the slice encrypted file, and storing the slice encrypted file to each storage node according to the file storage path;
[0016] Step S112, storing the file storage path of the slice encryption file, the MD5 value of the first file slice, the data relationship between the slice encryption file and the file to be encrypted, and the index number of the slice encryption file in a database.
[0017] Furthermore, the file encryption storage method also includes:
[0018] When the cutting starting point is the initial position of the file to be encrypted, the MD5 value of the previous file slice corresponding to the first file slice is 32 bits of 0.
[0019] Furthermore, the length of the slice header and the slice tail is 2 bytes.
[0020] Furthermore, the to-be-encrypted slice is encrypted according to the MD5 value of the previous file slice to obtain the pre-encrypted slice, specifically:
[0021] The last two characters of the MD5 value of the previous file slice are extracted, and the encryption algorithm is determined according to the modulus result of the last two characters, and the slice to be encrypted is encrypting according to the MD5 value of the previous file slice and the encryption algorithm to obtain a pre-encrypted slice.
[0022] Furthermore, the encryption algorithm includes an AES-256 CBC encryption algorithm, an AES-256 CFB encryption algorithm and an AES-256 CTR encryption algorithm.
[0023] Furthermore, the file encryption storage method also includes:
[0024] If a file access request is received from a client, a verification instruction is sent to the client;
[0025] Verify whether the user terminal is a legitimate user and whether the user terminal has file access permissions based on the verification information fed back by the user terminal and the user information stored in the database;
[0026] If the user terminal is a legitimate user and has file access rights, the file path of all encrypted slices of the access file is obtained according to the file access request, and all encrypted slices are read according to the file path;
[0027] Decrypting the encrypted slices by using a plurality of decoders to obtain decrypted slices;
[0028] All decrypted slices are stitched together in order to obtain the restored file, and the restored file is pushed to the user end.
[0029] Decrypting the encrypted slices by a plurality of decoders to obtain decrypted slices, decrypting any encrypted slice comprises the following steps:
[0030] The first 32 characters of the encrypted slice are intercepted and recorded as the first segment, the first 33-64 characters of the encrypted slice are intercepted and recorded as the second segment, and the remaining characters are recorded as the third segment;
[0031] If the MD5 values of the first segment and the encrypted slice are consistent, determine the encryption method of the third segment according to the second segment, and decrypt the third segment in combination with the encryption method to obtain a decrypted segment;
[0032] Cutting a slice header and a slice tail of the decrypted segment according to a preset number of bytes to obtain an intermediate decrypted segment;
[0033] The second random number length is derived according to the tail of the slice, and the second random number is deleted from the tail of the middle decrypted segment according to the second random number length to obtain the decrypted slice.
[0034] Furthermore, the file encryption storage method also includes:
[0035] While pushing the restored file to the user, the temporary file corresponding to the restored file is destroyed.
[0036] In a second aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of any one of the file encryption storage methods in the first aspect.
[0037] In a third aspect, the present invention further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it executes any one of the file encryption storage methods in the first aspect.
[0038] The beneficial effects of adopting the above technical solution are as follows: this embodiment introduces random numbers to dynamically adjust the file slice size, and dynamically calculates the encryption rules based on the hash value of the previous slice, and then stores the encrypted file slices in multiple paths and multiple nodes, which increases the difficulty for illegal users to crack the encryption of resource files and ensures the security of files in the file storage server. Furthermore, this embodiment shortens the time it takes for the user to decrypt and read encrypted files through multi-threaded decryption and restoration, and is equipped with a push-and-burn method to reduce the risk of temporary file leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for describing the embodiments or the prior art are briefly introduced below.
[0040] Figure 1 This is a schematic diagram of a file encryption storage method in one embodiment of the present application;
[0041] Figure 2 This is a schematic diagram of the file slice encryption process in one embodiment of the present application;
[0042] Figure 3 This is a schematic diagram of the file slice decryption process in one embodiment of the present application. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. In order to explain the present invention in more detail, the file encryption storage method, storage medium and device provided by the present invention are specifically described below in combination with the drawings.
[0044] Unless otherwise defined, the technical terms or scientific terms used in the disclosure of this application should be understood by people with ordinary skills in the field to which the present invention belongs. The "first", "second" and similar words used in the present invention do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, similar words such as "one", "one" or "the" do not indicate quantity restrictions, but indicate that there is at least one. Similar words such as "include" or "include" mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Similar words such as "connect" or "connected" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship can also change accordingly.
[0045] The present invention provides a file encryption storage method, storage medium and device, which dynamically adjusts the file slice size in combination with random numbers, dynamically calculates encryption rules according to the hash value of the previous slice, and then performs multi-path and multi-node storage on the encrypted file slice, thereby increasing the difficulty for illegal users to crack the encryption of resource files and ensuring the security of files in the file storage server. This method is applied to a terminal device as an example for explanation, and combined with the attached Figure 1 The schematic diagram of the file encryption storage method shown in FIG. Figure 2 The file slicing encryption process diagram and attached Figure 3 A schematic diagram of the file slice decryption process is shown.
[0046] The present application embodiment provides an application scenario of the file encryption storage method, which includes the terminal device provided in the embodiment, and the terminal device includes but is not limited to a smart phone and a computer device, wherein the computer device can be at least one of a desktop computer, a portable computer, a laptop computer, a mainframe computer, a tablet computer, etc. The terminal device receives the file to be encrypted and obtains a sliced encrypted file. For the specific process, please refer to the embodiment of the file encryption storage method.
[0047] It should be noted that the file encryption storage method of this embodiment is applied to a file storage system, and the file storage system includes a file storage server and several storage nodes. The file storage server is in communication with each storage node, and the file encryption storage method is executed by the file storage server. Among them, the file storage server includes a storage module and a processor module. The storage module has a built-in database, a file storage path for storing sliced encrypted files, an MD5 value of the first file slice, a data relationship between the slice encrypted file and the file to be encrypted, an index number of the slice encrypted file, etc.; the processor module is used to execute the file encryption storage method on the file to be encrypted. Based on this, the file encryption storage method is described below:
[0048] Step S101, obtaining a file to be encrypted and a preset file slice length.
[0049] Specifically, a user uploads a file that needs to be encrypted and stored through a standard interface, and the preset file slice length is the file slice length expected by the user, not the actual file slice length.
[0050] Step S102: randomly generate a first random number, and obtain an actual slice length according to the first random number and a preset file slice length.
[0051] Step S103, cutting the file to be encrypted in sequence from a cutting starting point according to an actual slice length to obtain a first file slice.
[0052] Specifically, the first random number is Figure 2 Random Number , the random number The value range is 0-65535. Use the preset file slice length Subtract the first random number Get the actual slice length , and then according to the actual slice length The encrypted file is cut in order from the cutting starting point to obtain the first file slice, thereby obtaining the first random number. The actual slice length is dynamically adjusted to obtain first file slices of different lengths, thereby improving the unpredictability of the slice file content of the slice encrypted file.
[0053] Step S104: randomly generate a second random number.
[0054] Specifically, the second random number is recorded as Figure 2 Random Number , the random number The value range is 0-65535. Random number Used to extend the length of the first file slice and convert the random number It should be noted that, in this embodiment, the length of the segment after the random number B and the first file slice are spliced is not fixed, and the length of the segment after splicing is not equal to the preset file slice length. For example, the preset file slice length is 1000, and the first file slice length is 1000. The first random number in the slice , the second random number , then the length of the spliced fragment is 1000-5+20=1015; The first random number in the slice , the second random number , then the splicing length is 1000-8+22=1014.
[0055] Step S105: convert the first random number into hexadecimal to obtain a slice header, and convert the second random number into hexadecimal to obtain a slice tail.
[0056] Specifically, the first random number After the hexadecimal conversion, a slice header with a length of 2 characters is formed, which is recorded as ; The second random number After the hexadecimal conversion, a slice tail of 2 characters in length is formed, recorded as .
[0057] Step S106, sequentially concatenate the slice header, the first file slice, the second random number and the slice tail to obtain the slice to be encrypted.
[0058] Specifically, as attached Figure 2 As shown, slice the header , first file slice , the second random number and the end of the slice Sequentially splice to get the slice to be encrypted, denoted as , the content of the slice to be encrypted can be expressed as .
[0059] Step S107, encrypt the slice to be encrypted according to the MD5 value of the previous file slice to obtain a pre-encrypted slice.
[0060] Specifically, considering the sequential nature of slices, the MD5 value of the previous file slice can be introduced during the slice encryption process (see Appendix Figure 2 In Chinese ) for the slice to be encrypted Pre-encryption is performed. Slice the MD5 value according to the previous file Use AES-256 algorithm as iv value to get pre-encrypted slice .
[0061] It should be noted that, considering that the first slice to be encrypted does not have a previous file slice, when the above-mentioned cutting starting point is the initial position of the file to be encrypted, the MD5 value of the previous file slice corresponding to the first file slice or the slice to be encrypted is set to 32 bits of 0.
[0062] Furthermore, considering that there are multiple AES-256 algorithms, the encrypted slice can select a specific encryption algorithm according to the following method:
[0063] Extract the last two characters of the MD5 value of the previous file slice, determine the encryption algorithm based on the modulo result of the last two characters, and encrypt the to-be-encrypted slice based on the MD5 value of the previous file slice and the encryption algorithm to obtain a pre-encrypted slice. The encryption algorithm includes the AES-256 CBC encryption algorithm, the AES-256 CFB encryption algorithm, and the AES-256 CTR encryption algorithm. If the modulo result is 0, select the AES-256 CBC encryption algorithm; if the modulo result is 1, select the AES-256 CFB encryption algorithm; if the modulo result is 2, select the AES-256 CTR encryption algorithm.
[0064] For example, the MD5 value of the previous file slice is used as the iv value, and the iv value is "c4ca4238a0b923820dcc509a6f75849b". The last two characters of the iv are "9b". Convert "9b" to decimal to get "155", and then take the modulus of 155 to get 155%3=2. If the result after the modulus is 0, the CBC encryption algorithm is used, the result after the modulus is 1, the CFB encryption algorithm is used, and the result after the modulus is 2, the CTR encryption algorithm is used. Therefore, the modulus result of this example uses the CTR encryption algorithm, and uses the iv value for encryption to obtain a pre-encrypted slice.
[0065] Step S108, performing secondary encryption on the MD5 value of the previous file slice and the pre-encrypted slice to obtain the MD5 value of the first file slice.
[0066] Further, the MD5 value of the previous file slice is With pre-encrypted slices After concatenation, the second encryption is performed to obtain the MD5 value of the first file slice, which is recorded as .
[0067] Step S109, sequentially concatenate the MD5 value of the previous file slice, the pre-encrypted slice, and the MD5 value of the first file slice to obtain a slice encrypted file.
[0068] Specifically, the content of the slice encryption file can be expressed as At this point, the encryption step of the slice to be encrypted is completed, and the slice encryption file can be recorded as .
[0069] Step S110, taking the end position of the first file slice as the cutting starting point of the next file slice in the file to be encrypted, and repeating the above steps S102-S109 until all contents in the file to be encrypted are encrypted, and obtaining a plurality of slice encrypted files.
[0070] Specifically, the above steps S102-S109 are repeated to slice and encrypt the file to be encrypted in sequence until all the contents in the file to be encrypted are encrypted, and a number of sliced encrypted files are obtained, which can be recorded as , … And because the random number A that determines the length of each slice file is different, the content length of each slice file is different, but the length of the encrypted slice encrypted file is the same, thereby improving the security of the slice encrypted file.
[0071] Step S111, using the first several bits of the MD5 value of each first file slice as the file storage path of the slice encrypted file, and storing the slice encrypted file to each storage node according to the file storage path.
[0072] Specifically, the MD5 value of each slice ( , … ) is used as the file storage path of the slice encryption file, for example The value of is e807f1fcf82d132f9bb018ca6738a19f, and the first 4 digits are taken as the file storage path. Then the corresponding slice encrypted file is stored in the e8 / 07 directory. Similarly, other slice encrypted files are stored in the same way. Furthermore, the length of the file storage path can be expanded, such as taking the first 6 digits of the MD5 value of each slice as the file storage path, so that it can point to different storage servers to achieve distributed data storage.
[0073] Step S112, storing the file storage path of the slice encryption file, the MD5 value of the first file slice, the data relationship between the slice encryption file and the file to be encrypted, and the index number of the slice encryption file in a database.
[0074] Furthermore, based on the above-mentioned file encryption storage method, the file to be encrypted uploaded by the user is sliced and encrypted and then stored in each storage node. When the user needs to access the resource file, the file storage server executes the following method steps:
[0075] Step S201: If a file access request sent by a client is received, a verification instruction is sent to the client.
[0076] Step S202: Verify whether the user terminal is a legitimate user and whether the user terminal has file access permissions based on the verification information fed back by the user terminal and the user information stored in the database.
[0077] Step S203: If the user terminal is a legitimate user and has file access rights, the file path of all encrypted slices of the access file is obtained according to the file access request, and all encrypted slices are read according to the file path.
[0078] Step S204, decrypting the encrypted slices through a plurality of decoders to obtain decrypted slices.
[0079] Step S205: All decrypted slices are spliced in order to obtain a restored file, and the restored file is pushed to the user end.
[0080] Among them, combined with Figure 3 The schematic diagram of the encrypted file decryption process shown in the figure, in the above step S203, the encrypted slices are decrypted by several decoders to obtain decrypted slices, and decrypting any encrypted slice includes the following steps:
[0081] Step S301, intercepting the first 32 characters of the encrypted slice and recording them as the first fragment, intercepting the first 33-64 characters of the encrypted slice and recording them as the second fragment, and the remaining characters are recorded as the third fragment.
[0082] Among them, combined with the above encryption process, it can be seen that the first fragment is , the second fragment is , the third fragment is .
[0083] Step S302: If the MD5 value of the first fragment is consistent with that of the encrypted slice, determine the encryption method of the third fragment according to the second fragment, and decrypt the third fragment in combination with the encryption method to obtain a decrypted fragment.
[0084] Specifically, the first segment If the encrypted slice file is consistent with the MD5 value of the encrypted slice file, it indicates that the encrypted slice file has not been tampered with and the data is credible. In addition, the order of the encrypted slice file can be checked based on the first fragment to see if it is consistent with the data storage order recorded in the database.
[0085] The second segment The last two characters can determine the encryption method of the third fragment. If the modulo result of the last two characters is 0, the encryption method of the third fragment is the AES-256 CBC encryption algorithm; if the modulo result of the last two characters is 1, the encryption method of the third fragment is the AES-256 CFB encryption algorithm; if the modulo result of the last two characters is 2, the encryption method of the third fragment is the AES-256 CTR encryption algorithm. After determining the encryption method of the third fragment, the third fragment is decrypted according to the encryption method to obtain the decrypted fragment. However, the decrypted fragment also contains a random number , Slice Head and the end of the slice .
[0086] Step S303, the slice header and the slice tail are cut from the decrypted segment according to a preset number of bytes to obtain an intermediate decrypted segment. According to the above encryption process, the slice header and the slice tail are both 2 characters long.
[0087] Step S304: according to the tail of the slice The second random number length is derived, and the second random number is deleted from the end of the middle decrypted segment according to the second random number length to obtain the decrypted slice.
[0088] It should be noted that since multiple encrypted slices in this embodiment belong to independent decryption tasks and are allowed to be performed simultaneously, the above-mentioned encrypted slice file decryption process can adopt multi-threaded decryption, which does not require decryption of each file one by one, greatly shortening the file decryption time. Users do not need to increase waiting time costs by decrypting the encrypted files one by one after downloading.
[0089] Considering that a temporary file corresponding to the restored file will be formed after the encrypted slice file is decrypted on the file storage server, in order to prevent the leakage of plaintext data, the file encryption storage method also includes:
[0090] While pushing the restored file to the user, the temporary file corresponding to the restored file is destroyed.
[0091] It should be understood that although the Figure 1 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Figure 1At least part of the steps may include multiple sub-steps or sub-stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0092] In one embodiment, the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of the above-mentioned file-based encryption storage method when executed by a processor.
[0093] The computer-readable storage medium may be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM (erasable programmable read-only memory), a hard disk or a ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium has a storage space for program codes for executing any method step of the above method. These program codes may be read from or written into one or more computer program products, and the program codes may be compressed in an appropriate form.
[0094] In one embodiment, the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the above-mentioned file encryption storage method when executing the computer program.
[0095] The computer device includes a memory, a processor, and one or more computer programs, wherein the one or more computer programs can be stored in the memory and configured to be executed by one or more processors, and the one or more application programs are configured to execute the above-mentioned file encryption storage method.
[0096] The processor may include one or more processing cores. The processor uses various interfaces and lines to connect the various parts of the entire computer device, and executes various functions of the computer device and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory, and calling data stored in the memory. Optionally, the processor can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor can integrate one or more combinations of a central processing unit (Central Processing Unit, CPU), a reporting verifier (Graphics Processing Unit, GPU) for buried data, and a modem. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor, but may be implemented separately through a communication chip.
[0097] The memory may include a random access memory (RAM) or a read-only memory (ROM). The memory may be used to store instructions, programs, codes, code sets or instruction sets. The memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc. The data storage area may also store data created by the terminal device during use, etc.
[0098] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A file encryption storage method, the file encryption storage method is applied to a file storage system, the file storage system includes a file storage server and a plurality of storage nodes, the file storage server is in communication connection with each storage node, characterized in that: The file encryption storage method is executed by a file storage server and includes the following steps: Step S101, obtaining a file to be encrypted and a preset file slice length; Step S102, randomly generating a first random number, and obtaining an actual slice length according to the first random number and a preset file slice length; Step S103, cutting the file to be encrypted from the cutting starting point in sequence according to the actual slice length to obtain a first file slice; Step S104, randomly generating a second random number; Step S105, converting the first random number into hexadecimal to obtain a slice header, and converting the second random number into hexadecimal to obtain a slice tail; Step S106, sequentially concatenate the slice header, the first file slice, the second random number, and the slice tail to obtain a slice to be encrypted; Step S107, encrypting the slice to be encrypted according to the MD5 value of the previous file slice to obtain a pre-encrypted slice; Step S108, concatenating the MD5 value of the previous file slice with the pre-encrypted slice and performing secondary encryption to obtain the MD5 value of the first file slice; Step S109, sequentially concatenating the MD5 value of the previous file slice, the pre-encrypted slice, and the MD5 value of the first file slice to obtain a slice encrypted file; Step S110, taking the end position of the first file slice as the starting point for cutting the next file slice in the file to be encrypted, and repeating the above steps S102-S109 until all contents in the file to be encrypted are encrypted, thereby obtaining a plurality of slice encrypted files; Step S111, using the first several bits of the MD5 value of each first file slice as the file storage path of the slice encrypted file, and storing the slice encrypted file to each storage node according to the file storage path; Step S112, storing the file storage path of the slice encryption file, the MD5 value of the first file slice, the data relationship between the slice encryption file and the file to be encrypted, and the index number of the slice encryption file in a database.
2. The file encryption storage method according to claim 1, characterized in that: Also includes: When the cutting starting point is the initial position of the file to be encrypted, the MD5 value of the previous file slice corresponding to the first file slice is 32 bits of 0.
3. The file encryption storage method according to claim 2, characterized in that: The length of the slice header and the slice tail is 2 bytes.
4. The file encryption storage method according to claim 3, characterized in that: The method of encrypting the slice to be encrypted according to the MD5 value of the previous file slice to obtain the pre-encrypted slice is specifically as follows: The last two characters of the MD5 value of the previous file slice are extracted, and the encryption algorithm is determined according to the modulus result of the last two characters, and the to-be-encrypted slice is encrypting according to the MD5 value of the previous file slice and the encryption algorithm to obtain a pre-encrypted slice.
5. The file encryption storage method according to claim 4, characterized in that: The encryption algorithm includes an AES-256 CBC encryption algorithm, an AES-256 CFB encryption algorithm and an AES-256 CTR encryption algorithm.
6. The file encryption storage method according to any one of claims 1 to 5, characterized in that: Also includes: If a file access request is received from a client, a verification instruction is sent to the client; Verify whether the user terminal is a legitimate user and whether the user terminal has file access permissions based on the verification information fed back by the user terminal and the user information stored in the database; If the user terminal is a legitimate user and has file access rights, the file path of all encrypted slices of the access file is obtained according to the file access request, and all encrypted slices are read according to the file path; Decrypting the encrypted slices by using a plurality of decoders to obtain decrypted slices; All decrypted slices are stitched together in order to obtain the restored file, and the restored file is pushed to the user end.
7. The file encryption storage method according to claim 6, characterized in that: Decrypting the encrypted slices by a plurality of decoders to obtain decrypted slices, decrypting any encrypted slice comprises the following steps: The first 32 characters of the encrypted slice are intercepted and recorded as the first segment, the first 33-64 characters of the encrypted slice are intercepted and recorded as the second segment, and the remaining characters are recorded as the third segment; If the MD5 values of the first segment and the encrypted slice are consistent, determine the encryption method of the third segment according to the second segment, and decrypt the third segment in combination with the encryption method to obtain a decrypted segment; Cutting a slice header and a slice tail of the decrypted segment according to a preset number of bytes to obtain an intermediate decrypted segment; The second random number length is derived according to the tail of the slice, and the second random number is deleted from the tail of the middle decrypted segment according to the second random number length to obtain the decrypted slice.
8. The file encryption storage method according to claim 7, characterized in that: Also includes: While pushing the restored file to the user, the temporary file corresponding to the restored file is destroyed.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the file encryption storage method according to any one of claims 1 to 8 are implemented.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it performs the file encryption storage method described in any one of claims 1-8.
Citation Information
Patent Citations
Safe computer storage system
CN112149076A
Resource encryption and display method and system
CN112416450A
Method for enhancing data migration security in cloud storage
CN112764677A
Devise of business model through internet and invention of method for strengthening security
JP2023004495A