Document isolation method and terminal

By obtaining the hash value corresponding to the instance identification of the application software instance, determining the target authentication key and encrypting the document, the problem of inconsistent with the new document encryption key and the source document key is solved, and the security of data communication is improved.

CN120046187APending Publication Date: 2025-05-27NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510097088.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art cannot guarantee the consistency between the encryption key of the new document generated by saving and the encryption key of the source document, resulting in low security during data communication.

Method used

By obtaining the first hash value corresponding to the instance identification of the application software instance, the target authentication key is determined, the document is encrypted based on the target authentication key, and the relevant hash value is stored in the document.

Benefits of technology

It ensures the consistency between the encryption key of the new document generated by saving and the encryption key of the source document, and improves the security during data communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046187A_ABST
    Figure CN120046187A_ABST
Patent Text Reader

Abstract

The invention discloses a document isolation method and a terminal, and the method comprises the steps: obtaining a first hash value corresponding to an instance identifier of a current application software instance based on an identifier corresponding relation after determining that a document is an encrypted confidential document; determining a target authentication key based on the first hash value and the received authentication key set; generating a data key based on the target authentication key and a preset encryption algorithm; after the document is encrypted through the data key, the data key is encrypted based on the target authentication key, and the first hash value, the hash value of the data key and the hash value of the target authentication key are stored in the document. That is to say, the first hash value corresponding to the instance identifier is obtained through the ciphertext document, the target authentication key of the source document is determined, and the document is encrypted based on the target authentication key, so that the encryption key of the new document and the encryption key of the source document which are generated by other storage are ensured to be consistent. And the security in the data exchange process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of document security, and particularly to a document isolation method and a terminal. Background Art

[0002] Document isolation is an important means to ensure data security during data communication. Currently, document isolation mainly achieves content isolation of documents through key isolation, that is, different keys are sent to each terminal by the server, so that the terminal encrypts or decrypts the document according to the obtained key.

[0003] However, due to the principle of the hierarchical design of the operating system, the terminal cannot determine the key of the source document, and the default key of the terminal will be used to encrypt the document during the encryption process of the save-as operation, thus unable to ensure the consistency of the encryption key of the new document generated by the save-as and the encryption key of the source document, and further resulting in uncontrollable margins of document isolation and low security during data communication. Summary of the Invention

[0004] The present invention provides a document isolation method and a terminal to solve the problem in the prior art that the consistency of the encryption key of the new document generated by the save-as and the encryption key of the source document cannot be ensured, resulting in low security during data communication.

[0005] In a first aspect, an embodiment of the present application provides a document isolation method, which includes:

[0006] After determining that the document is an encrypted classified document, based on the identification correspondence, obtain the first hash value corresponding to the instance identification of the current application software instance;

[0007] Based on the first hash value and the received set of authentication keys, determine the target authentication key;

[0008] Based on the target authentication key and a preset encryption algorithm, generate a data key;

[0009] After encrypting the document with the data key, encrypt the data key with the target authentication key, and store the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document;

[0010] Wherein, the set of authentication keys is sent by the server to the terminal, and the set of authentication keys includes at least one authentication key.

[0011] In a possible implementation manner, the method further includes:

[0012] After determining that the document is an unencrypted classified document, determine the default key in the set of authentication keys;

[0013] Calculate the default hash value by performing calculations on the default secret key based on an irreversible algorithm;

[0014] Use the default hash value as the first hash value.

[0015] In a possible implementation, determining the target authentication key based on the first hash value and the received set of authentication keys includes:

[0016] Calculate the second hash value of each authentication key in the set of authentication keys based on an irreversible algorithm;

[0017] Compare the first hash value with each second hash value, and use the second hash value that is identical to the first hash value as the target second hash value;

[0018] Use the authentication key corresponding to the target second hash value as the target authentication key.

[0019] In a possible implementation, after storing the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document, it further includes:

[0020] Respond to a document opening operation triggered by the user;

[0021] Based on the identification correspondence, determine the third hash value corresponding to the instance identification of each started application software instance;

[0022] Compare each third hash value with the first hash value, and perform an operation on the document based on the comparison result.

[0023] In a possible implementation, comparing each third hash value with the first hash value and performing an open operation on the document based on the comparison result includes:

[0024] When the comparison result indicates that there is a third hash value identical to the first hash value, use the instance identification corresponding to the third hash value as the target instance identification, and perform an open operation on the document based on the application software instance corresponding to the target instance identification and the target authentication key;

[0025] When the comparison result indicates that there is no instance identification corresponding to the first hash value, prohibit performing an open operation on the document.

[0026] In a possible implementation, after storing the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document, it further includes:

[0027] Respond to the document copy operation triggered by the user;

[0028] Compare the instance identifier corresponding to the current document with the instance identifier corresponding to the target document, where the target document is the document for which the paste operation is performed;

[0029] If they are determined to be the same, perform a copy operation on the current document; if they are determined to be different, prohibit performing a copy operation on the current document.

[0030] In a second aspect, an embodiment of the present application provides a terminal, and the terminal includes:

[0031] An authentication key management module, configured to, after determining that the document is an encrypted classified document, obtain a first hash value corresponding to the instance identifier of the current application software instance based on the identifier correspondence relationship; determine a target authentication key based on the first hash value and the received set of authentication keys, where the set of authentication keys is sent by the server to the terminal, and the set of authentication keys includes at least one authentication key;

[0032] A data key management module, configured to generate a data key based on the target authentication key and a preset encryption algorithm;

[0033] A document encryption and decryption module, configured to encrypt the document with the data key, then encrypt the data key with the target authentication key, and store the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document.

[0034] In a possible implementation manner, the authentication key management module is further configured to:

[0035] After determining that the document is an unencrypted classified document, determine the default key in the set of authentication keys;

[0036] Calculate a default hash value based on a non-invertible algorithm for the default key;

[0037] Use the default hash value as the first hash value.

[0038] In a possible implementation manner, the authentication key management module is specifically configured to:

[0039] Calculate a second hash value for each authentication key in the set of authentication keys based on a non-invertible algorithm;

[0040] Compare the first hash value with each second hash value, and use the second hash value that is the same as the first hash value as the target second hash value;

[0041] Use the authentication key corresponding to the target second hash value as the target authentication key.

[0042] In a possible implementation, it further includes an isolation decision module:

[0043] The isolation decision module is used to respond to the document opening operation triggered by the user;

[0044] Based on the identification correspondence, determine the third hash value corresponding to the instance identification of each started application software instance;

[0045] Compare each third hash value with the first hash value, and perform an operation on the document based on the comparison result.

[0046] In a possible implementation, the isolation decision module is specifically used for:

[0047] When the comparison result is that there is a third hash value identical to the first hash value, use the instance identification corresponding to the third hash value as the target instance identification, and perform an open operation on the document based on the application software instance corresponding to the target instance identification and the target authentication key;

[0048] When the comparison result is that there is no instance identification corresponding to the first hash value, prohibit performing an open operation on the document.

[0049] In a possible implementation, the isolation decision module is specifically used for:

[0050] Respond to the document copy operation triggered by the user;

[0051] Compare the instance identification corresponding to the current document with the instance identification corresponding to the target document, where the target document is the document for which the paste operation is performed;

[0052] When it is determined to be consistent, perform a copy operation on the current document; when it is determined to be inconsistent, prohibit performing a copy operation on the current document.

[0053] In a third aspect, an embodiment of the present application provides a terminal, including a memory and a processor, where a computer program is stored on the memory and runs on the processor. When the computer program is executed by the processor, the method described in any item of the first aspect is implemented.

[0054] The beneficial effects of the present invention are as follows:

[0055] The embodiments of the present application provide a document isolation method and a terminal. After determining that a document is a classified and encrypted document, based on the identification correspondence relationship, a first hash value corresponding to the instance identifier of the current application software instance is obtained; based on the first hash value and the received set of authentication keys, a target authentication key is determined; based on the target authentication key and a preset encryption algorithm, a data key is generated; after encrypting the document with the data key, the data key is encrypted with the target authentication key, and the first hash value, the hash value of the data key, and the hash value of the target authentication key are stored in the document; wherein, the set of authentication keys is sent by the server to the terminal, and the set of authentication keys includes at least one authentication key. That is to say, the present application obtains the first hash value corresponding to the instance identifier through the ciphertext document, and then determines the target authentication key of the source document, and performs an encryption operation on the document based on the target authentication key, so as to ensure the consistency of the encryption keys of the new document generated by saving another copy and the encryption key of the source document, thereby improving the security during the data exchange process. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0057] Figure 1 A schematic diagram of an application scenario of a document isolation method provided by an embodiment of the present application;

[0058] Figure 2 A schematic flowchart of a document isolation method provided by an embodiment of the present application;

[0059] Figure 3 A schematic flowchart of another document isolation method provided by an embodiment of the present application;

[0060] Figure 4 A schematic flowchart of another document isolation method provided by an embodiment of the present application;

[0061] Figure 5 A schematic flowchart of another document isolation method provided by an embodiment of the present application;

[0062] Figure 6 A schematic flowchart of another document isolation method provided by an embodiment of the present application;

[0063] Figure 7 A schematic diagram of the structure of a terminal provided by an embodiment of the present application;

[0064] Figure 8Another structural schematic diagram of a terminal provided by an embodiment of this application. Detailed implementation manners

[0065] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0066] It should be noted that the terms "including" and "having" and their variants involved in the documents of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0067] In this application, "(English: of)", "corresponding (English: corresponding, relevant)", and "corresponding (English: corresponding)" can sometimes be used interchangeably. It should be noted that when their differences are not emphasized, the meanings they express are the same. In the embodiments of this application, communication and transmission can sometimes be used interchangeably. It should be noted that when their differences are not emphasized, the meanings they express are the same. For example, transmission can include sending and / or receiving, and can be a noun or a verb.

[0068] The terms "first" and "second" in the text are only used for descriptive purposes and cannot be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of this application, unless otherwise specified, the meaning of "a plurality" is two or more.

[0069] The term "exemplary" used hereinafter means "serving as an example, embodiment, or illustration". Any embodiment described as "exemplary" does not have to be construed as superior to or better than other embodiments.

[0070] Some technical terms involved in this application will be explained first below.

[0071] 1) Hash value: Also known as a hash code, it is the output value of a fixed length obtained by converting input data (such as text, files, etc.) through a hash function. This output value is usually represented in hexadecimal. Hash values are unique. Even if the input data changes slightly, the generated hash value will change significantly. They are commonly used for data integrity verification, quick lookups, and encryption.

[0072] 2) Application software instance: In a computer system, a running copy or execution process of a specific application is an application software instance. When an application is launched, the operating system creates an instance that contains the resources and status information required by the application and starts executing the logic in the program. Each application software instance is usually isolated and independent when running in memory. Even if multiple instances run the same program, their internal data and status do not interfere with each other. For example, opening multiple browser windows or running multiple document editor windows. Although they are the same application, each window or process is a separate instance.

[0073] 3) Instance identifier: It refers to the identifier used to uniquely identify a running instance of an application or service. In computer science, instance identifiers are crucial for differentiating and managing multiple running instances, ensuring that different instances do not interfere with each other and can be managed and operated independently.

[0074] Document isolation is an important means to ensure data security during the data exchange process. In the related technology, the permission isolation method issues permissions from the server to the terminal. When the terminal receives a permission document, it opens the document based on the obtained permissions. However, each document requires the user to perform an authorization operation, resulting in low efficiency during a large amount of data exchange. In addition, since the permission information needs to be synchronized on the server, the security during the data exchange process is reduced.

[0075] In the key isolation method in the related technology, the server issues different keys to each terminal. Thus, when the terminal performs the operation of opening a document, it decrypts the document based on the obtained key, or when the document performs the operation of encrypting a document, it encrypts the document based on the obtained key. Without holding the key for the encrypted document, the document cannot be opened.

[0076] However, due to the principle of the hierarchical design of the operating system, the terminal cannot determine the key of the source document. During the encryption process of the save-as operation, the terminal's default key is used to encrypt the document, thus unable to ensure the consistency of the encryption key of the new document generated by the save-as and the encryption key of the source document. Furthermore, it causes the marginal uncontrollability of document isolation, resulting in a lower security problem during the data exchange process.

[0077] For example, the server sends the key A to terminal 1, the key B to terminal 2, and the key C to terminal 3. If terminal 2 wants to open the document A1 encrypted by terminal 1, it needs to send a request to the server. After terminal 2 receives the key A sent by the server, it can open the document A1 encrypted by terminal 1. However, due to the principle of the hierarchical design of the operating system, the operating system kernel layer of terminal 2 cannot determine the key of the source document, that is, terminal 2 cannot determine the key of document A1. When terminal 2 encrypts document A1, it will use the default key B of terminal 2 to encrypt document A1 to generate document B1, resulting in inconsistent encryption keys between the newly generated document B1 after saving as a copy and the encryption key of the source document A1. If there is a terminal 4 that holds the key B, then this terminal 4 can also open the newly generated document B1 after saving as a copy, further causing the marginal uncontrollability of document isolation and resulting in low security during the data exchange process.

[0078] To solve this problem, the embodiments of the present application provide a document isolation method and a terminal. By obtaining the first hash value corresponding to the instance identifier, the target authentication key of the source document is further determined, and the document is encrypted based on the target authentication key, so as to ensure the consistency of the encryption keys of the newly generated document after saving as a copy and the encryption key of the source document, and further improve the security during the data exchange process.

[0079] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments.

[0080] Figure 1 An exemplary application scenario of a possible document isolation method provided by the embodiments of the present application is shown as Figure 1 As shown, the server 100 is communicatively connected to the terminal device 102 through the network 101. Among them, the network 101 can be, but is not limited to, a local area network, a metropolitan area network, a wide area network, etc. The number of terminal devices connected to the server 100 can be multiple. Among them, the terminal device 102 can be a portable device (such as: mobile phone, tablet computer, smart watch, etc.), or a computer, a smart screen or a personal computer (PC, Personal Computer), etc.

[0081] The server 100 can be an application-level server that stores multiple applications. The server 100 can be any device with networking capabilities and capable of providing data processing capabilities. Exemplarily, the server 100 can be a cloud server, or a server set composed of one or more servers.

[0082] Figure 1 The application scenario shown is only an example of an application scenario for implementing the embodiments of the present application, and the embodiments of the present application are not limited to the above Figure 1The application scenarios described above.

[0083] Based on the above Figure 1 application scenarios shown above and the content of the above related technology introduction, an embodiment of the present application provides a document isolation method. Figure 2 Exemplarily shows a possible flowchart of a document isolation method provided by an embodiment of the present application. As Figure 2 shown, the method includes:

[0084] S201. After determining that the document is an encrypted confidential document, based on the identification correspondence, obtain the first hash value corresponding to the instance identifier of the current application software instance;

[0085] In a possible implementation manner, the identification correspondence stores the correspondence between the instance identifier and the hash value. Among them, each instance identifier has a corresponding hash value, and each instance identifier has a corresponding application software instance.

[0086] Further, in an embodiment of the present application, before operating on the document, it is necessary to determine whether the document is a confidential document based on the confidential document identifier saved in the file header or file tail of the document. In the case of the existence of the confidential document identifier, it is determined that the document is a confidential document. In the case of the non-existence of the confidential document, it is determined that the document is a non-confidential document. Among them, after determining that the document is a non-confidential document, there is no need to perform encryption or decryption operations on the document.

[0087] In addition, if after determining that the document is a confidential document, it is determined that the document is in plain text, that is, it is determined that the document is an unencrypted confidential document. If an encryption operation is performed on the document, the default key of the terminal is used to encrypt the document.

[0088] Specifically, as Figure 3 shown, it is a flowchart of another document isolation method provided by an embodiment of the present application. After determining that the document is an unencrypted confidential document, the following steps are further included:

[0089] S301. Determine the default key in the authentication key set;

[0090] S302. Calculate the default key based on a non-invertible algorithm to obtain a default hash value;

[0091] S303. Use the default hash value as the first hash value.

[0092] Exemplarily, the correspondence between the instance identifier and the hash value in the identification correspondence is pre-stored. If it is determined that the document is an encrypted confidential document and the instance identifier of the document is not found in the identification correspondence, the decryption operation on the document is prohibited.

[0093] Exemplarily, if it is determined that the document is an unencrypted classified document, an encryption operation or a decryption operation is performed on the document based on the default key of the terminal. Therefore, it is necessary to obtain the default hash value of the default key through an irreversible algorithm, and use the default key hash value as the first hash value. It should be noted that the default hash value and the default instance identifier are pre-stored in the identifier correspondence relationship.

[0094] Specifically, the irreversible algorithm in the embodiments of the present application may be an irreversible hash function, including: MD5 (Message Digest Algorithm 5), SHA-1 (Secure Hash Algorithm 1), SHA-256 (Secure Hash Algorithm 256).

[0095] Among them, the authentication key set is sent by the server to the terminal, and the authentication key set includes at least one authentication key. As an example, the server sends different key sets to each terminal, and each key set includes a pre-set default key.

[0096] For example, the server sends an authentication key set including authentication key A, authentication key B, and authentication key D to terminal 1, and uses authentication key A as the default key of terminal 1. The server sends an authentication key set including authentication key C and authentication key D to terminal 2, and uses authentication key C as the default key of terminal 2. The server sends an authentication key set including authentication key A, authentication key B, and authentication key C to terminal 3, and uses authentication key C as the default key of terminal 3. The server sends an authentication key set including authentication key D to terminal 4, and uses authentication key D as the default key of terminal 4.

[0097] For example, after terminal 1 determines that the document is an unencrypted classified document, it determines the pre-set default key A based on authentication key A, authentication key B, and authentication key D in the obtained authentication key set. Then, it calculates the default key A based on the irreversible algorithm to obtain the default hash value A* of the default key A, and uses the default hash value A* as the first hash value.

[0098] For example, after terminal 2 determines that the document is an encrypted classified document and cannot find the instance identifier in the identifier correspondence relationship, it prohibits the execution of the decryption operation on the document.

[0099] For example, after terminal 4 determines that the document is an unencrypted classified document, it determines the pre-set default key D based on authentication key D in the obtained authentication key set. Then, it calculates the default key D based on the irreversible algorithm to obtain the default hash value D* of the default key D, and uses the default hash value D* as the first hash value.

[0100] S202. Determine a target authentication key based on the first hash value and the received set of authentication keys.

[0101] Exemplarily, after determining the first hash value based on the identifier correspondence relationship, the present application determines the target authentication key by comparing the first hash value with the second hash value of each authentication key in the set of authentication keys, thereby ensuring the consistency of the encryption key of the newly generated document saved separately and the encryption key of the source document, and improving the security during the data exchange process.

[0102] In a possible implementation manner, as Figure 4 shown, it is a schematic flowchart of another document isolation method provided by an embodiment of the present application. The target authentication key is determined through the following manner, including the following steps:

[0103] S401. Calculate the second hash value of each authentication key in the set of authentication keys based on a non-reversible algorithm.

[0104] S402. Compare the first hash value with each second hash value, and use the second hash value that is consistent with the first hash value as the target second hash value.

[0105] S403. Use the authentication key corresponding to the target second hash value as the target authentication key.

[0106] For example, terminal 1 searches based on the identifier correspondence relationship and obtains the first hash value A* corresponding to instance identifier 101. If the set of authentication keys of terminal 1 includes authentication key A, authentication key B, authentication key C, and authentication key D, calculate the second hash value of each authentication key in the set of authentication keys, and the obtained second hashes are A*, B*, C*, and D* respectively. Compare the first hash value A* with the second hash values A*, B*, C*, and D*, determine the second hash value A* that is consistent with the first hash value A*, use the second hash value A* as the target second hash value, and use the authentication key A corresponding to the target second hash value A* as the target authentication key.

[0107] For example, terminal 4 searches based on the identifier correspondence relationship and obtains the first hash value D* corresponding to instance identifier 401. If the set of authentication keys of terminal 4 includes authentication key A, authentication key B, and authentication key C, calculate the second hash value of each authentication key in the set of authentication keys, and the obtained second hash values are A*, B*, and C* respectively. Compare the first hash value D* with the second hash values A*, B*, and C*, determine that there is no second hash value that is consistent with the first hash value D*, that is, the target authentication key cannot be determined, and terminal 4 does not have the permission to open the document.

[0108] S203. Generate a data key based on the target authentication key and a preset encryption algorithm.

[0109] In a specific embodiment, after obtaining the target authentication key, a data key is generated based on a preset encryption algorithm, the target authentication key, and the document information. The preset encryption algorithm can be a symmetric encryption algorithm, such as AES (Advanced Encryption Standard) and DES (Data Encryption Standard), or an asymmetric encryption algorithm, such as ECC (Elliptic Curve Cryptography) and DSA (Digital Signature Algorithm).

[0110] S204. After encrypting the document with the data key, encrypt the data key based on the target authentication key, and store the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document.

[0111] In a specific embodiment, the data key is used to encrypt or decrypt the document. After the document content is encrypted with the data key, the security during the data communication process is improved. The target authentication key is used to encrypt the data key, and the target authentication key is used to improve the security of the data key and prevent the data key from being illegally accessed.

[0112] The embodiment of the present application provides a document isolation method. After determining that the document is an encrypted confidential document, based on the identification correspondence relationship, obtain the first hash value corresponding to the instance identifier of the current application software instance; determine the target authentication key based on the first hash value and the received set of authentication keys; generate a data key based on the target authentication key and a preset encryption algorithm; after encrypting the document with the data key, encrypt the data key based on the target authentication key, and store the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document; where the set of authentication keys is sent by the server to the terminal, and the set of authentication keys includes at least one authentication key. That is to say, the present application obtains the first hash value corresponding to the instance identifier through the ciphertext document, and then determines the target authentication key of the source document, and encrypts the document based on the target authentication key, so as to ensure the consistency of the encryption key of the newly generated document saved separately and the encryption key of the source document, and further improve the security during the data communication process.

[0113] In a possible implementation manner, as Figure 5 shown, it is a schematic flowchart of another document isolation method provided by the embodiment of the present application. After storing the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document, the following steps are further included:

[0114] S501. Respond to the document opening operation triggered by the user;

[0115] S502. Based on the identification correspondence, determine the third hash value corresponding to the instance identification of each started application software instance;

[0116] S503. Compare each third hash value with the first hash value, and perform an operation on the document based on the comparison result.

[0117] In a specific embodiment, after responding to the document opening operation triggered by the user, based on the identification correspondence, compare the first hash value of the document with the third hash value corresponding to each started application software instance, and determine to perform an opening operation on the document based on the started application software instance or start a new application software instance to perform an opening operation on the document based on the comparison result.

[0118] Exemplarily, when the comparison result is that there is a third hash value identical to the first hash value, use the instance identification corresponding to the third hash value as the target instance identification, and perform an opening operation on the document based on the application software instance corresponding to the target instance identification and the target authentication key; when the comparison result is that there is no instance identification corresponding to the first hash value, prohibit performing an opening operation on the document.

[0119] For example, the third hash values corresponding to the instance identifications of each started application software instance include A*, B*, C*, and D*. If the first hash value is A*, use the instance identification corresponding to the hash value with the third hash value of A* as the target instance identification, and open the document based on the application software instance corresponding to the target instance identification and the target authentication key.

[0120] For example, the third hash values corresponding to the instance identifications of each started application software instance include A*, B*, C*, and D*. If the first hash value is E*, the comparison result is that there is no instance identification corresponding to the first hash value, and the document opening is prohibited.

[0121] In a possible implementation manner, as Figure 6 shown, it is a schematic flowchart of another document isolation method provided by an embodiment of the present application. After storing the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document, the following steps are further included:

[0122] S601. Respond to the document copy operation triggered by the user;

[0123] S602. Compare the instance identification corresponding to the current document with the instance identification corresponding to the target document, where the target document is the document for which a paste operation is performed;

[0124] S603. When it is determined that they are consistent, perform a copy operation on the current document; when it is determined that they are inconsistent, prohibit performing a copy operation on the current document.

[0125] In a specific embodiment, after responding to a document copy operation triggered by a user, determine whether the application software instance of the current document and the application software instance of the target document are consistent based on the instance identifier. When the instance identifier corresponding to the current document and the instance identifier corresponding to the target document are consistent, perform a copy operation on the current document; when the instance identifier corresponding to the current document and the instance identifier corresponding to the target document are inconsistent, prohibit performing a copy operation on the current document, thereby improving the security during the data exchange process.

[0126] Furthermore, to better introduce the embodiments of the present application, a document isolation scenario is selected for illustration. It should be noted that the following examples in the embodiments of the present application are only for illustration and do not constitute a limitation to the embodiments of the present application:

[0127] Exemplarily, assume that the embodiments of the present application include at least two types of devices in this document isolation scenario, namely a server and a terminal. Among them, the above-mentioned device or software for executing the document isolation method of the present application can be deployed in the terminal. The following is an introduction based on different devices respectively:

[0128] The server in the document isolation scenario:

[0129] In this scenario, the server in the embodiments of the present application is used to generate an authentication key, construct an authentication key set based on the generated authentication key, and send the authentication key set to the terminal(s) based on a preset permission relationship, where the terminal(s) can be one or more.

[0130] As an example, the server includes an authentication key distribution subsystem. If the server has established a permission relationship with three terminals, after generating an authentication key, the server is used to construct an authentication key set based on the generated authentication key and set a default key in the authentication key set; based on the preset permission relationship and the authentication key distribution subsystem, send the authentication key sets to Terminal 1, Terminal 2, and Terminal 3 respectively, where each authentication key set includes a default key and non-default keys.

[0131] The terminal in the document isolation system:

[0132] As an example, each terminal includes an operation behavior monitoring subsystem, an authentication key parsing subsystem, an isolation decision subsystem, and an authentication key management subsystem.

[0133] Exemplarily, the operation behavior monitoring subsystem is used to respond to document operations triggered by a user, including save-as operations, open operations, copy operations, etc.

[0134] The authentication key parsing subsystem is used to obtain the first hash value corresponding to the instance identifier of the current application software instance based on the identity correspondence relationship. By comparing the first hash value with the second hash values of each authentication key in the authentication key set, the target authentication key is determined. If the target authentication key is not determined in the authentication key set, there is no permission to open the document. And it is used to generate a data key based on the target authentication key and a preset encryption algorithm, encrypt the document with the data key, encrypt the data key with the target authentication key, and store the data key and the hash value of the target authentication key in the document.

[0135] The isolation decision subsystem is used to compare the first hash value of the document with the third hash values corresponding to each started application software instance based on the identity correspondence relationship, and determine to perform an open operation on the document based on the comparison result for the started application software instance. And it is used to determine whether the application software instance of the current document is the same as that of the target document based on the instance identifier. When the instance identifier corresponding to the current document is the same as that corresponding to the target document, a copy operation is performed on the current document; when the instance identifier corresponding to the current document is different from that corresponding to the target document, the copy operation on the current document is prohibited, thereby improving the security in the data exchange process.

[0136] That is to say, the embodiment of the present application provides a document isolation method and a terminal. By obtaining the first hash value corresponding to the instance identifier from the ciphertext document, the target authentication key of the source document is further determined, and the document is encrypted based on the target authentication key, so as to ensure the consistency of the encryption keys of the newly generated document saved separately and the source document, and further improve the security in the data exchange process.

[0137] Based on the same inventive concept, the embodiment of the present application also provides a terminal. The principle of this terminal is similar to the above-mentioned document isolation method, and the repeated parts will not be described again.

[0138] As Figure 7 shown, it is a schematic structural diagram of a terminal provided by the embodiment of the present application. The terminal includes:

[0139] The authentication key management module 701 is used to obtain the first hash value corresponding to the instance identifier of the current application software instance based on the identity correspondence relationship after determining that the document is an encrypted classified document; determine the target authentication key based on the first hash value and the received authentication key set; wherein, the authentication key set is sent by the server to the terminal, and the authentication key set includes at least one authentication key;

[0140] The data key management module 702 is used to generate a data key based on the target authentication key and a preset encryption algorithm;

[0141] A document encryption and decryption module 703, which is used to encrypt the document with the data key, then encrypt the data key based on the target authentication key, and store the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document.

[0142] The embodiment of the present application provides a document isolation method and a terminal. After determining that the document is an encrypted classified document, based on the identification correspondence relationship, obtain the first hash value corresponding to the instance identifier of the current application software instance; based on the first hash value and the received set of authentication keys, determine the target authentication key; based on the target authentication key and a preset encryption algorithm, generate a data key; after encrypting the document with the data key, encrypt the data key based on the target authentication key, and store the first hash value, the data key, and the hash value of the target authentication key in the document; wherein, the set of authentication keys is sent by the server to the terminal, and the set of authentication keys includes at least one authentication key. That is to say, the present application obtains the first hash value corresponding to the instance identifier through the ciphertext document, and then determines the target authentication key of the source document, and encrypts the document based on the target authentication key, so as to ensure the consistency of the encryption key of the newly generated document saved separately and the encryption key of the source document, thereby improving the security in the data exchange process.

[0143] In a possible implementation manner, the authentication key management module 701 is further used for:

[0144] After determining that the document is an unencrypted classified document, determine the default key in the set of authentication keys;

[0145] Calculate the default hash value based on a non-invertible algorithm for the default key;

[0146] Use the default hash value as the first hash value.

[0147] In a possible implementation manner, the authentication key management module 701 is specifically used for:

[0148] Calculate the second hash value of each authentication key in the set of authentication keys based on a non-invertible algorithm;

[0149] Compare the first hash value with each second hash value, and use the second hash value that is the same as the first hash value as the target second hash value;

[0150] Use the authentication key corresponding to the target second hash value as the target authentication key.

[0151] In a possible implementation manner, it further includes an isolation decision module 704:

[0152] The isolation decision module is used to respond to the document opening operation triggered by the user;

[0153] Based on the identity correspondence, determine the third hash value corresponding to the instance identifier of each started application software instance;

[0154] Compare each third hash value with the first hash value, and perform an operation on the document based on the comparison result.

[0155] In a possible implementation manner, the isolation decision module 704 is specifically configured to:

[0156] When the comparison result is that there is a third hash value identical to the first hash value, use the instance identifier corresponding to the third hash value as the target instance identifier, and perform an open operation on the document based on the application software instance corresponding to the target instance identifier and the target authentication key;

[0157] When the comparison result is that there is no instance identifier corresponding to the first hash value, prohibit performing an open operation on the document.

[0158] In a possible implementation manner, the isolation decision module 704 is specifically configured to:

[0159] Respond to the document copy operation triggered by the user;

[0160] Compare the instance identifier corresponding to the current document with the instance identifier corresponding to the target document, where the target document is the document for performing a paste operation;

[0161] When it is determined to be consistent, perform a copy operation on the current document; when it is determined to be inconsistent, prohibit performing a copy operation on the current document.

[0162] Based on the same inventive concept, an embodiment of the present application further provides a terminal. The principle of this terminal is similar to that of the above document isolation method, and the repeated parts will not be elaborated. As Figure 8 shown, it includes a memory 801 and a processor 802. A computer program is stored on the memory 801 and runs on the processor 802. When the computer program is executed by the processor 802, the method described in any one of the document isolation methods is implemented.

[0163] The embodiments of the present application provide a document isolation method and a terminal. After determining that a document is a classified document that has been encrypted, based on the identification correspondence, a first hash value corresponding to the instance identifier of the current application software instance is obtained; based on the first hash value and the received set of authentication keys, a target authentication key is determined; based on the target authentication key and a preset encryption algorithm, a data key is generated; after encrypting the document with the data key, the data key is encrypted with the target authentication key, and the first hash value, the hash value of the data key, and the hash value of the target authentication key are stored in the document; wherein, the set of authentication keys is sent by the server to the terminal, and the set of authentication keys includes at least one authentication key. That is to say, the present application obtains the first hash value corresponding to the instance identifier through the ciphertext document, and then determines the target authentication key of the source document, and encrypts the document based on the target authentication key, so as to ensure the consistency of the encryption keys of the new document generated by saving and the encryption key of the source document, thereby improving the security during the data exchange process.

[0164] The present application is described above with reference to the block diagrams and / or flowcharts showing methods, apparatuses (systems) and / or computer program products according to embodiments of the present application. It should be understood that one block of the block diagrams and / or flowcharts and combinations of blocks in the block diagrams and / or flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, and / or other programmable data processing devices to produce a machine, so that the instructions executed by the computer processor and / or other programmable data processing devices create a method for implementing the functions / actions specified in the block diagrams and / or flowchart blocks.

[0165] Correspondingly, the present application can also be implemented by hardware and / or software (including firmware, resident software, microcode, etc.). Further, the present application can take the form of a computer program product on a computer-usable or computer-readable storage medium, which has computer-usable or computer-readable program code implemented in the medium for use by or in connection with an instruction execution system. In the context of the present application, a computer-usable or computer-readable medium can be any medium that can contain, store, communicate, transmit, or convey a program for use by or in connection with an instruction execution system, apparatus, or device.

[0166] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A document isolation method, characterized in that: Applied to a terminal, the method comprises: After determining that the document is an encrypted confidential document, obtaining a first hash value corresponding to the instance identifier of the current application software instance based on the identifier correspondence relationship; Determining a target authentication key based on the first hash value and the received authentication key set; Generate a data key based on the target authentication key and a preset encryption algorithm; After encrypting the document by the data key, encrypting the data key based on the target authentication key, and storing the first hash value, the hash value of the data key and the hash value of the target authentication key in the document; The authentication key set is sent by the server to the terminal, and the authentication key set includes at least one authentication key.

2. The method according to claim 1, characterized in that The method further comprises: After determining that the document is an unencrypted confidential document, determining a default key in the authentication key set; Calculating the default key based on a non-reversible algorithm to obtain a default hash value; The default hash value is used as the first hash value.

3. The method according to claim 1, characterized in that The determining a target authentication key based on the first hash value and the received authentication key set includes: Calculating a second hash value of each authentication key in the authentication key set based on a non-reversible algorithm; Compare the first hash value with each second hash value, and use the second hash value consistent with the first hash value as the target second hash value; The authentication key corresponding to the target second hash value is used as the target authentication key.

4. The method according to any one of claims 1 to 3, characterized in that: After the first hash value, the hash value of the data key, and the hash value of the target authentication key are stored in the document, the method further includes: Respond to user-triggered document opening operations; Based on the identifier correspondence, determine a third hash value corresponding to the instance identifier of each started application software instance; Each third hash value is compared with the first hash value, and an operation is performed on the document based on the comparison result.

5. The method according to claim 4, characterized in that The comparing each third hash value with the first hash value and performing an operation on the document based on the comparison result includes: When the comparison result is that there is a third hash value that is the same as the first hash value, using the instance identifier corresponding to the third hash value as the target instance identifier, and performing an open operation on the document based on the application software instance corresponding to the target instance identifier and the target authentication key; When the comparison result is that there is no instance identifier corresponding to the first hash value, the opening operation on the document is prohibited.

6. The method according to any one of claims 1 to 3, characterized in that: After storing the first hash value, the hash value of the data key, and the hash value of the target authentication key in the document, the method further includes: Respond to user-triggered document copy operations; Comparing the instance identifier corresponding to the current document with the instance identifier corresponding to the target document, wherein the target document is the document on which the paste operation is performed; If the two documents are consistent, a copy operation is performed on the current document; if the two documents are inconsistent, the copy operation is prohibited on the current document.

7. A terminal, characterized in that: The terminal comprises: An authentication key management module is used to obtain a first hash value corresponding to the instance identifier of the current application software instance based on the identifier correspondence after determining that the document is an encrypted confidential document; determine a target authentication key based on the first hash value and the received authentication key set; wherein the authentication key set is sent by the server to the terminal, and the authentication key set includes at least one authentication key; A data key management module, used to generate a data key based on the target authentication key and a preset encryption algorithm; A document encryption and decryption module is used to encrypt the document with the data key, encrypt the data key based on the target authentication key, and store the first hash value, the hash value of the data key and the hash value of the target authentication key in the document.

8. The terminal according to claim 7, characterized in that The authentication key management module is also used for: After determining that the document is an unencrypted confidential document, determining a default key in the authentication key set; Calculating the default key based on a non-reversible algorithm to obtain a default hash value; The default hash value is used as the first hash value.

9. The terminal according to claim 7, characterized in that: The authentication key management module is specifically used for: Calculating a second hash value of each authentication key in the authentication key set based on a non-reversible algorithm; Compare the first hash value with each second hash value, and use the second hash value consistent with the first hash value as the target second hash value; The authentication key corresponding to the target second hash value is used as the target authentication key.

10. The terminal according to any one of claims 7 to 9, characterized in that: Also includes the isolation decision module: The isolation decision module is used to respond to the document opening operation triggered by the user; Based on the identifier correspondence, determine a third hash value corresponding to the instance identifier of each started application software instance; Each third hash value is compared with the first hash value, and an operation is performed on the document based on the comparison result.

11. The terminal according to claim 10, characterized in that The isolation decision module is specifically used for: When the comparison result is that there is a third hash value that is the same as the first hash value, using the instance identifier corresponding to the third hash value as the target instance identifier, and performing an open operation on the document based on the application software instance corresponding to the target instance identifier and the target authentication key; When the comparison result is that there is no instance identifier corresponding to the first hash value, the opening operation on the document is prohibited.

12. The terminal according to any one of claims 7 to 9, characterized in that: The isolation decision module is specifically used for: Respond to user-triggered document copy operations; Comparing the instance identifier corresponding to the current document with the instance identifier corresponding to the target document, wherein the target document is the document on which the paste operation is performed; If the two documents are consistent, a copy operation is performed on the current document; if the two documents are inconsistent, the copy operation is prohibited on the current document.

13. A terminal, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program to be run on the processor, and when the computer program is executed by the processor, the method according to any one of claims 1 to 6 is implemented.