File Encryption Storage Method, Storage Medium and Device

By slicing the files and storing them in different paths of multiple storage nodes, the security risks caused by plain-text file storage at the data storage level in the prior art are solved, and high confidentiality and security file storage and access are achieved.

CN120012139BActive Publication Date: 2025-06-24广州市迪士普音响科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510480932.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-06-24
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

The existing technology has clear-text file storage at the data storage level, which violates the principle of minimum permissions, resulting in sensitive information being exposed to multiple risks such as internal overprivileged access, external malicious attacks, and supply chain penetration, hiding severe data leakage risks and compliance crises.

Method used

By slicing files and storing encrypted slices in different file paths in one or more storage nodes, we ensure that resource files can only be accessed through the system interface, improving the confidentiality of file storage and access, and reducing the security risks of file storage.

Benefits of technology

It improves the confidentiality of file storage and access, reduces the difficulty of cracking and encrypting resource files by illegal users, ensures the security of files in the file storage server, shortens the decryption and reading time of encrypted files by the user side, and reduces the risk of temporary files being leaked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012139B_ABST
    Figure CN120012139B_ABST
Patent Text Reader

Abstract

The present invention provides a file encryption storage method, a storage medium and a device. The method introduces a random number to dynamically adjust the file slice size, and dynamically calculates the encryption rule according to the hash value of the previous slice. When storing the encrypted file in multiple paths and multiple nodes, it improves the difficulty of illegal users' encryption cracking of resource files and ensures the security of files in the file storage server. In addition, based on this file encryption storage method, a multi-threaded decryption and restoration method can be adopted to reduce the decryption and reading time of the encrypted file, and a push-and-burn method is set to reduce the risk of leakage of plaintext temporary files.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of file storage, and particularly to a file encryption storage method, a storage medium, and a device. Background Art

[0002] With the deep evolution of the digitalization process, data assets have become the key carriers of an enterprise's core competitiveness, and the accompanying security issues have also risen to the core issues of various industries. Currently, although most enterprises implement transport layer encryption for the communication links between servers and clients and Web pages through the Https protocol, at the data storage level, there is still a widespread phenomenon of directly retaining files in plain text. Such a storage mode not only violates the principle of least privilege but also exposes sensitive information to multiple risks such as internal unauthorized access, external malicious attacks, and supply chain penetration, hiding serious data leakage hazards and compliance crises. Summary of the Invention

[0003] Based on this, the present invention provides a file encryption storage method, a storage medium, and a device. By encrypting file slices and storing the encrypted slices in different file paths of one or more storage nodes, it is ensured that resource files can only be accessed through system interfaces, avoiding direct access to files, improving the confidentiality of file storage and access, and reducing the security hazards of file storage.

[0004] In a first aspect, the present invention provides a file encryption storage method. The file encryption storage method is applied to a file storage system. The file storage system includes a file storage server and several storage nodes. The file storage server is communicatively connected to each storage node. The file encryption storage method is executed by the file storage server and includes the following steps:

[0005] Step S101, obtain a file to be encrypted and a preset file slice length;

[0006] Step S102, randomly generate a first random number, and obtain an actual slice length according to the first random number and the preset file slice length;

[0007] Step S103, cut the file to be encrypted in order from the cutting starting point according to the actual slice length to obtain a first file slice;

[0008] Step S104, randomly generate a second random number;

[0009] Step S105, convert the first random number to hexadecimal to obtain a slice header, and convert the second random number to hexadecimal to obtain a slice tail;

[0010] Step S106: Concatenate the slice header, the first file slice, the second random number, and the slice tail in sequence to obtain the slice to be encrypted.

[0011] Step S107: Encrypt the slice to be encrypted according to the MD5 value of the previous file slice to obtain the pre-encrypted slice.

[0012] Step S108: Perform secondary encryption on the MD5 value of the previous file slice and the pre-encrypted slice to obtain the MD5 value of the first file slice.

[0013] Step S109: Concatenate the MD5 value of the previous file slice, the pre-encrypted slice, and the MD5 value of the first file slice in sequence to obtain the slice encrypted file.

[0014] Step S110: Use the end position of the first file slice as the cutting start point of the subsequent file slice in the file to be encrypted, and repeat the above steps S102 - S109 until all the content in the file to be encrypted is encrypted, obtaining a number of slice encrypted files.

[0015] Step S111: Use the first several bits of the MD5 value of each first file slice as the file storage path of the slice encrypted file, and store the slice encrypted file to each storage node according to the file storage path.

[0016] Step S112: Store the file storage path of the slice encrypted file, the MD5 value of the first file slice, the data relationship between the slice encrypted file and the file to be encrypted, and the index number of the slice encrypted file in the database for preservation.

[0017] Further, the file encryption and storage method further includes:

[0018] When the cutting start point is the initial position of the file to be encrypted, the MD5 value of the previous file slice corresponding to the first file slice is 32 bits of 0.

[0019] Further, the lengths of the slice header and the slice tail are 2 bytes.

[0020] Further, the encrypting the slice to be encrypted according to the MD5 value of the previous file slice to obtain the pre-encrypted slice specifically is:

[0021] Extract the last two characters of the MD5 value of the previous file slice, determine the encryption operation algorithm according to the modulo result of the last two characters, and encrypt the slice to be encrypted according to the MD5 value of the previous file slice and the encryption operation algorithm to obtain the pre-encrypted slice.

[0022] Further, the encryption operation algorithm includes the AES-256 CBC encryption operation algorithm, the AES-256 CFB encryption operation algorithm, and the AES-256 CTR encryption operation algorithm.

[0023] Further, the file encryption and storage method further includes:

[0024] If a file access request sent by the client is received, a verification instruction is sent to the client;

[0025] According to the verification information fed back by the client and the user information stored in the database, it is verified whether the client is a legitimate user and whether the client has file access rights;

[0026] If the client is a legitimate user and the client has file access rights, according to the file access request, the file paths of all encrypted slices of the accessed file are obtained, and all encrypted slices are read according to the file paths;

[0027] The encrypted slices are decrypted by a plurality of decoders to obtain decrypted slices;

[0028] All the decrypted slices are spliced in sequence to obtain a restored file, and the restored file is pushed to the client.

[0029] The step of decrypting the encrypted slices by a plurality of decoders to obtain decrypted slices, and decrypting any one encrypted slice includes the following steps:

[0030] The first 32 characters of the encrypted slice are intercepted and recorded as the first segment, the 33rd to 64th characters of the encrypted slice are intercepted and recorded as the second segment, and the remaining characters are recorded as the third segment;

[0031] If the first segment is consistent with the MD5 value of the encrypted slice, the encryption method of the third segment is determined according to the second segment, and the third segment is decrypted in combination with the encryption method to obtain a decrypted segment;

[0032] The slice header and the slice tail of the decrypted segment are intercepted according to a preset number of bytes to obtain an intermediate decrypted segment;

[0033] The length of the second random number is deduced according to the slice tail, and the second random number is deleted from the tail of the intermediate decrypted segment according to the length of the second random number to obtain a decrypted slice.

[0034] Further, the file encryption and storage method further includes:

[0035] While pushing the restored file to the user, the temporary file corresponding to the restored file is destroyed.

[0036] In a second aspect, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of any one of the file encryption storage methods in the first aspect are implemented.

[0037] In a third aspect, the present invention further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, it executes any one of the file encryption storage methods in the first aspect.

[0038] The beneficial effects of adopting the above technical solutions are as follows: In this embodiment, a random number is introduced to dynamically adjust the file slice size, and the encryption rule is dynamically calculated according to the hash value of the previous slice, and then the encrypted file slices are stored in multiple paths and multiple nodes, which increases the difficulty for illegal users to crack the encryption of the resource file and ensures the security of the files in the file storage server. Further, in this embodiment, the decryption and restoration in multiple threads are used to shorten the decryption and reading time of the encrypted file by the user side, and a push-and-self-destruct method is set to reduce the risk of leakage of temporary files. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art.

[0040] Figure 1 It is a schematic diagram of a file encryption storage method in an embodiment of the present application;

[0041] Figure 2 It is a schematic diagram of the file slice encryption process in an embodiment of the present application;

[0042] Figure 3 It is a schematic diagram of the file slice decryption process in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. In order to describe the present invention in more detail, the file encryption storage method, storage medium and device provided by the present invention will be specifically described below with reference to the drawings.

[0044] Unless otherwise defined, the technical terms or scientific terms used in this application disclosure shall have the ordinary meanings as understood by those of ordinary skill in the art to which this invention pertains. The terms "first", "second" and similar words used in this invention do not denote any order, quantity or importance, but are only used to distinguish different components. Similarly, words such as "a", "an" or "the" do not denote a quantity limitation, but mean that there is at least one. Words such as "comprising" or "including" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. Words such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Upper", "lower", "left", "right", etc. are only used to indicate relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0045] The present invention provides a file encryption storage method, a storage medium and a device, which dynamically adjust the file slice size in combination with a random number, dynamically calculate an encryption rule according to the hash value of the previous slice, and then perform multi-path multi-node storage on the encrypted file slices, thereby increasing the difficulty for illegal users to crack the encryption of the resource file and ensuring the security of the files in the file storage server. Taking the application of this method to a terminal device as an example for illustration, in combination with the Figure 1 schematic diagram of the file encryption storage method shown in the attached Figure 2 schematic diagram of the file slice encryption process shown in the attached Figure 3 schematic diagram of the file slice decryption process shown in the attached.

[0046] The embodiments of the present application provide an application scenario of the file encryption storage method. This application scenario includes the terminal device provided by the embodiment. The terminal device includes, but is not limited to, smart phones and computer devices, where the computer device can be at least one of devices such as desktop computers, portable computers, laptop computers, mainframe computers, and tablet computers. The terminal device receives the file to be encrypted to obtain a sliced encrypted file. For the specific process, please refer to the embodiments of the file encryption storage method.

[0047] It should be noted that the file encryption storage method in this embodiment is applied to a file storage system, which includes a file storage server and several storage nodes. The file storage server is communicatively connected to each storage node, and the file encryption storage method is executed by the file storage server. Among them, the file storage server includes a storage module and a processor module. The storage module has a built-in database, a file storage path for storing sliced encrypted files, the MD5 value of the first file slice, the data relationship between the sliced encrypted file and the file to be encrypted, the index number of the sliced encrypted file, etc.; the processor module is used to execute the file encryption storage method for the file to be encrypted. Based on this, the file encryption storage method is described as follows:

[0048] Step S101: Obtain the file to be encrypted and a preset file slice length.

[0049] Specifically, the user uploads the file to be encrypted and stored through a standard interface. The preset file slice length is the file slice length expected by the user, rather than the actual file slice length.

[0050] Step S102: Randomly generate a first random number, and obtain the actual slice length according to the first random number and the preset file slice length.

[0051] Step S103: Cut the file to be encrypted in sequence from the cutting starting point according to the actual slice length to obtain the first file slice.

[0052] Specifically, the first random number is an additional Figure 2 random number , and the random number ranges from 0 to 65535. Using the preset file slice length subtract the first random number to obtain the actual slice length , and then cut the file to be encrypted in sequence from the cutting starting point according to the actual slice length to obtain the first file slice. Thus, the actual slice length is dynamically adjusted through the first random number to obtain first file slices of different lengths, improving the unpredictability of the sliced file content of the sliced encrypted file. Dynamic adjustment of the actual slice length is performed to obtain first file slices of different lengths, thereby improving the unpredictability of the sliced file content of the sliced encrypted file.

[0053] Step S104: Randomly generate a second random number.

[0054] Specifically, denote the second random number as an additional Figure 2 random number , and the random number ranges from 0 to 65535. The random number is used to expand the length of the first file slice. The random number Append to the end of the first file slice. It should be noted that in this embodiment, the length of the segment after splicing the random number B and the first file slice is uncertain, and the length of the spliced segment is not equal to the preset file slice length. For example, the preset file slice length is 1000, and the first random number in the th slice, and the second random number , then the length of this spliced segment is 1000 - 5 + 20 = 1015; the first random number in the th slice, and the second random number , then the spliced length is 1000 - 8 + 22 = 1014.

[0055] Step S105: Convert the first random number to hexadecimal to obtain the slice header, and convert the second random number to hexadecimal to obtain the slice tail.

[0056] Specifically, after the first random number is converted to hexadecimal, it forms a slice header with a length of 2 characters, denoted as ; after the second random number is converted to hexadecimal, it forms a slice tail with a length of 2 characters, denoted as .

[0057] Step S106: Splice the slice header, the first file slice, the second random number, and the slice tail in sequence to obtain the slice to be encrypted.

[0058] Specifically, as shown in the appendix Figure 2 , splice the slice header , the first file slice , the second random number , and the slice tail in sequence to obtain the slice to be encrypted, denoted as , and the content of this slice to be encrypted can be expressed as .

[0059] Step S107: Encrypt the slice to be encrypted according to the MD5 value of the previous file slice to obtain the pre-encrypted slice.

[0060] Specifically, considering the sequentiality of the slices, the MD5 value of the previous file slice (denoted as Figure 2 in the appendix ) can be introduced to pre-encrypt the slice to be encrypted . Among them, the slice to be encrypted uses the MD5 value of the previous file slice as the iv value and uses the AES-256 algorithm to obtain the pre-encrypted slice .

[0061] It should be noted that considering that there is no previous file slice for the first slice to be encrypted, when the above cutting starting point is the initial position of the file to be encrypted, the MD5 value of the previous file slice corresponding to the first file slice or the slice to be encrypted is set to 32 zeros.

[0062] Furthermore, considering that there are multiple AES-256 algorithms, the slice to be encrypted can select a specific encryption algorithm according to the following method:

[0063] Extract the last two characters of the MD5 value of the previous file slice, determine the encryption operation algorithm according to the modulo result of the last two characters, and encrypt the slice to be encrypted according to the MD5 value of the previous file slice and the encryption operation algorithm to obtain a pre-encrypted slice. Among them, the encryption operation algorithms include AES-256 CBC encryption operation algorithm, AES-256 CFB encryption operation algorithm, and AES-256 CTR encryption operation algorithm. If the modulo result is 0, select the AES-256 CBC encryption operation algorithm; if the modulo result is 1, select the AES-256 CFB encryption operation algorithm; if the modulo result is 2, select the AES-256 CTR encryption operation algorithm.

[0064] For example, the MD5 value of the previous file slice is used as the iv value, and this iv value is "c4ca4238a0b923820dcc509a6f75849b". The last two characters of this iv are "9b". Convert "9b" to decimal to get "155", and then take the modulo of 155 to get 155%3 = 2; if the modulo result is 0, the CBC encryption operation algorithm is used; if the modulo result is 1, the CFB encryption operation algorithm is used; if the modulo result is 2, the CTR encryption operation algorithm is used. Thus, the modulo result of this example uses the CTR encryption operation algorithm and uses this iv value for encryption operation to obtain a pre-encrypted slice.

[0065] Step S108, perform secondary encryption on the MD5 value of the previous file slice and the pre-encrypted slice to obtain the MD5 value of the first file slice.

[0066] Furthermore, the MD5 value of the previous file slice and the pre-encrypted slice are concatenated and then subjected to secondary encryption to obtain the MD5 value of the first file slice, denoted as .

[0067] Step S109, concatenate the MD5 value of the previous file slice, the pre-encrypted slice, and the MD5 value of the first file slice in sequence to obtain a sliced encrypted file.

[0068] Specifically, the content of the sliced encrypted file can be expressed as , and at this time, the encryption step of the to-be-encrypted slice is completed, and the sliced encrypted file can be denoted as .

[0069] Step S110: Use the end position of the first file slice as the cutting starting point of the subsequent file slice in the to-be-encrypted file, and repeatedly execute the above steps S102 - S109 until all the content in the to-be-encrypted file is encrypted, obtaining several sliced encrypted files.

[0070] Specifically, repeatedly execute the above steps S102 - S109 to slice and encrypt the to-be-encrypted file in sequence until all the content in the to-be-encrypted file is encrypted, obtaining several sliced encrypted files, which can be denoted as , …… , and since the random number A determining the length of each slice file is different, the lengths of the contents of each slice file are different, but the lengths of the encrypted sliced encrypted files are the same, thereby improving the security of the sliced encrypted files.

[0071] Step S111: Use the first several bits of the MD5 value of each first file slice as the file storage path of the sliced encrypted file, and store the sliced encrypted file to each storage node according to the file storage path.

[0072] Specifically, use the first 4 bits of each slice MD5 value ( , …… ) as the file storage path of the sliced encrypted file. For example, if the value of is e807f1fcf82d132f9bb018ca6738a19f, take the first 4 bits as the file storage path, then store the corresponding sliced encrypted file in the e8 / 07 directory, and so on. Other sliced encrypted files are stored in the same way. Further, the length of the file storage path can be extended, such as taking the first 6 bits of each slice MD5 value as the file storage path, thereby pointing to different storage servers to achieve distributed data storage.

[0073] Step S112: Store the file storage path of the sliced encrypted file, the MD5 value of the first file slice, the data relationship between the sliced encrypted file and the to-be-encrypted file, and the index number of the sliced encrypted file in the database for preservation.

[0074] Furthermore, based on the above file encryption and storage method, after slicing and encrypting the to-be-encrypted file uploaded by the user and storing it to each storage node, when the user needs to access the resource file, the file storage server executes the following method steps:

[0075] In step S201, if a file access request sent by the client is received, a verification instruction is sent to the client.

[0076] In step S202, according to the verification information feedback by the client and the user information stored in the database, it is verified whether the client is a legitimate user and whether the client has file access permission.

[0077] In step S203, if the client is a legitimate user and the client has file access permission, according to the file access request, the file paths of all encrypted slices of the accessed file are obtained, and all encrypted slices are read according to the file paths.

[0078] In step S204, the encrypted slices are decrypted by a plurality of decoders to obtain decrypted slices.

[0079] In step S205, all decrypted slices are spliced in sequence to obtain a restored file, and the restored file is pushed to the client.

[0080] Among them, combined with the schematic diagram of the encrypted file decryption process shown in the appendix Figure 3 In step S203 above, the encrypted slices are decrypted by a plurality of decoders to obtain decrypted slices. Decrypting any one of the encrypted slices includes the following steps:

[0081] In step S301, the first 32 characters of the encrypted slice are intercepted and recorded as the first segment, the 33 - 64th characters of the encrypted slice are intercepted and recorded as the second segment, and the remaining characters are recorded as the third segment.

[0082] Among them, combined with the above encryption process, it can be known that the first segment is , and the second segment is , and the third segment is .

[0083] In step S302, if the first segment is consistent with the MD5 value of the encrypted slice, the encryption method of the third segment is determined according to the second segment, and the third segment is decrypted in combination with the encryption method to obtain a decrypted segment.

[0084] Specifically, if the first segment is consistent with the MD5 value of the encrypted slice, it indicates that the encrypted slice file has not been tampered with and the data is credible. Moreover, the order of the encrypted slice file can be checked according to the first segment to see if it is consistent with the data storage order recorded in the database.

[0085] The second segment The last two characters can determine the encryption method of the third segment. If the modulo result of the last two characters is 0, the encryption method of the third segment is the AES-256 CBC encryption algorithm; if the modulo result of the last two characters is 1, the encryption method of the third segment is the AES-256 CFB encryption algorithm; if the modulo result of the last two characters is 2, the encryption method of the third segment is the AES-256 CTR encryption algorithm. After determining the encryption method of the third segment, decrypt the third segment according to this encryption method to obtain the decrypted segment. However, the decrypted segment also contains a random number , the slice header and the slice tail .

[0086] Step S303, intercept the slice header and the slice tail from the decrypted segment according to a preset number of bytes to obtain an intermediate decrypted segment. Among them, according to the above encryption process, both the slice header and the slice tail are 2 characters in length.

[0087] Step S304, deduce the length of the second random number according to the slice tail and delete the second random number from the tail of the intermediate decrypted segment according to the length of the second random number to obtain a decrypted slice.

[0088] It should be noted that since multiple encrypted slices in this embodiment belong to independent decryption tasks and allow simultaneous execution, the above encrypted slice file decryption process can use multi-threaded decryption and does not require decrypting each file one by one, which greatly shortens the file decryption time, and users do not need to increase the waiting time cost by decrypting each encrypted file after downloading.

[0089] Considering that a temporary file corresponding to the restored file will be formed after decrypting the sliced encrypted file on the file storage server, to prevent the leakage of plaintext data, the file encryption and storage method further includes:

[0090] When pushing the restored file to the user, destroy the temporary file corresponding to the restored file.

[0091] It should be understood that although each step in the attached Figure 1 flowchart is shown in sequence according to the arrow indication, these steps are not necessarily executed in the order indicated by the arrow. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. And the attached Figure 1At least some of the steps may include multiple sub-steps or sub-phases, which do not necessarily need to be executed and completed at the same moment, but can be executed at different moments. The execution order of these sub-steps or sub-phases does not necessarily need to be sequential, but can be executed alternately or in rotation with at least some of the sub-steps or sub-phases of other steps or other steps.

[0092] In one embodiment, the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned file encryption storage method are implemented.

[0093] The computer-readable storage medium may be an electronic memory such as a flash memory, EEPROM (electrically erasable programmable read-only memory), EPROM (erasable programmable read-only memory), hard disk, or ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium has a storage space for program codes for executing any of the method steps in the above-mentioned method. These program codes can be read out from or written into one or more computer program products, and the program codes can be compressed in a suitable form.

[0094] In one embodiment, the present invention provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above-mentioned file encryption storage method is executed.

[0095] The computer device includes a memory, a processor, and one or more computer programs, where one or more computer programs can be stored in the memory and configured to be executed by one or more processors, and one or more application programs are configured to execute the above-mentioned file encryption storage method.

[0096] The processor may include one or more processing cores. The processor utilizes various interfaces and circuits to connect various parts within the entire computer device. By running or executing instructions, programs, code sets, or instruction sets stored in the memory, and by invoking data stored in the memory, it performs various functions of the computer device and processes data. Optionally, the processor may be implemented in at least one of the hardware forms of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor may integrate one or a combination of several of a central processing unit (CPU), a reporting validator for buried point data (Graphics Processing Unit, GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the displayed content; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor and can be implemented separately through a communication chip.

[0097] The memory may include random access memory (RAM) and may also include read-only memory. The memory can be used to store instructions, programs, code, code sets, or instruction sets. The memory may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for implementing at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc. The data storage area may also store data created during the use of the terminal device.

[0098] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A file encryption storage method, the file encryption storage method is applied to a file storage system, the file storage system includes a file storage server and a plurality of storage nodes, the file storage server is in communication connection with each storage node, characterized in that: The file encryption storage method is executed by a file storage server and includes the following steps: Step S101, obtaining a file to be encrypted and a preset file slice length; Step S102, randomly generating a first random number, and obtaining an actual slice length according to the first random number and a preset file slice length; Step S103, cutting the file to be encrypted from the cutting starting point in sequence according to the actual slice length to obtain a first file slice; Step S104, randomly generating a second random number; Step S105, converting the first random number into hexadecimal to obtain a slice header, and converting the second random number into hexadecimal to obtain a slice tail; Step S106, sequentially concatenate the slice header, the first file slice, the second random number, and the slice tail to obtain a slice to be encrypted; Step S107, encrypting the slice to be encrypted according to the MD5 value of the previous file slice to obtain a pre-encrypted slice; Step S108, concatenating the MD5 value of the previous file slice with the pre-encrypted slice and performing secondary encryption to obtain the MD5 value of the first file slice; Step S109, sequentially concatenating the MD5 value of the previous file slice, the pre-encrypted slice, and the MD5 value of the first file slice to obtain a slice encrypted file; Step S110, taking the end position of the first file slice as the starting point for cutting the next file slice in the file to be encrypted, and repeating the above steps S102-S109 until all contents in the file to be encrypted are encrypted, thereby obtaining a plurality of slice encrypted files; Step S111, using the first several bits of the MD5 value of each first file slice as the file storage path of the slice encrypted file, and storing the slice encrypted file to each storage node according to the file storage path; Step S112, storing the file storage path of the slice encryption file, the MD5 value of the first file slice, the data relationship between the slice encryption file and the file to be encrypted, and the index number of the slice encryption file in a database.

2. The file encryption storage method according to claim 1, characterized in that: Also includes: When the cutting starting point is the initial position of the file to be encrypted, the MD5 value of the previous file slice corresponding to the first file slice is 32 bits of 0.

3. The file encryption storage method according to claim 2, characterized in that: The length of the slice header and the slice tail is 2 bytes.

4. The file encryption storage method according to claim 3, characterized in that: The method of encrypting the slice to be encrypted according to the MD5 value of the previous file slice to obtain the pre-encrypted slice is specifically as follows: The last two characters of the MD5 value of the previous file slice are extracted, and the encryption algorithm is determined according to the modulus result of the last two characters, and the to-be-encrypted slice is encrypting according to the MD5 value of the previous file slice and the encryption algorithm to obtain a pre-encrypted slice.

5. The file encryption storage method according to claim 4, characterized in that: The encryption algorithm includes an AES-256 CBC encryption algorithm, an AES-256 CFB encryption algorithm and an AES-256 CTR encryption algorithm.

6. The file encryption storage method according to any one of claims 1 to 5, characterized in that: Also includes: If a file access request is received from a client, a verification instruction is sent to the client; Verify whether the user terminal is a legitimate user and whether the user terminal has file access permissions based on the verification information fed back by the user terminal and the user information stored in the database; If the user terminal is a legitimate user and has file access rights, the file path of all encrypted slices of the access file is obtained according to the file access request, and all encrypted slices are read according to the file path; Decrypting the encrypted slices by using a plurality of decoders to obtain decrypted slices; All decrypted slices are stitched together in order to obtain the restored file, and the restored file is pushed to the user end.

7. The file encryption storage method according to claim 6, characterized in that: Decrypting the encrypted slices by a plurality of decoders to obtain decrypted slices, decrypting any encrypted slice comprises the following steps: The first 32 characters of the encrypted slice are intercepted and recorded as the first segment, the first 33-64 characters of the encrypted slice are intercepted and recorded as the second segment, and the remaining characters are recorded as the third segment; If the MD5 values ​​of the first segment and the encrypted slice are consistent, determine the encryption method of the third segment according to the second segment, and decrypt the third segment in combination with the encryption method to obtain a decrypted segment; Cutting a slice header and a slice tail of the decrypted segment according to a preset number of bytes to obtain an intermediate decrypted segment; The second random number length is derived according to the tail of the slice, and the second random number is deleted from the tail of the middle decrypted segment according to the second random number length to obtain the decrypted slice.

8. The file encryption storage method according to claim 7, characterized in that: Also includes: While pushing the restored file to the user, the temporary file corresponding to the restored file is destroyed.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the file encryption storage method according to any one of claims 1 to 8 are implemented.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it performs the file encryption storage method described in any one of claims 1-8.

Citation Information

Patent Citations

  • Safe computer storage system

    CN112149076A

  • Resource encryption and display method and system

    CN112416450A