High-performance large file fragment confusion and heterogeneous encryption method, device and equipment

By performing sharded obfuscation and heterogeneous encryption of large files, combining parallel processing and hardware acceleration, and dynamic management of keys, the performance bottlenecks and security risks of traditional encryption methods in large file processing are solved, and an efficient and secure encryption solution is achieved.

CN120223313APending Publication Date: 2025-06-27CHINA TELECOM SHANGHAI IDEAL INFORMATION IND GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510414823.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-27

Smart Images

  • Figure CN120223313A_ABST
    Figure CN120223313A_ABST
Patent Text Reader

Abstract

The invention relates to a high-performance large file fragment confusion and heterogeneous encryption method, device and equipment, and the method comprises the steps: carrying out the file confusion fragmentation of a large file according to a fragment size initial interval and a random number mechanism, and obtaining a plurality of file fragments with different sizes and the relative position information of each file fragment in the large file; determining the importance of each file fragment, and determining an encryption algorithm of each file fragment according to the importance to encrypt each file fragment to obtain a ciphertext of each file fragment; and dynamically generating a transmission key according to the file characteristics of the encrypted large file and the encryption time, wherein the transmission key is used for encrypting the encrypted large file when the encrypted large file is transmitted. According to the embodiment of the invention, the file type is analyzed to determine the fragmentation interval, and random fragmentation increases the cracking difficulty; selecting an encryption algorithm according to fragment importance; parallel processing and hardware acceleration are carried out to improve the performance; dynamic key management ensures security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and particularly to a high-performance large-file sharding obfuscation and heterogeneous encryption method, device and equipment. Background Art

[0002] In today's digital age, the secure storage and transmission of data are of vital importance. With the rapid development of information technology, the processing requirements for large files are increasing day by day, such as high-definition videos, large software installation packages, enterprise-level database backups, etc. However, traditional encryption methods often have performance bottlenecks and security risks when dealing with large files.

[0003] Existing file encryption technologies mainly include symmetric encryption and asymmetric encryption. Symmetric encryption algorithms are faster, but key management is more complex; asymmetric encryption algorithms are highly secure, but the encryption and decryption speeds are slower. In addition, for the encryption of large files, a single encryption method may not meet the requirements of security and performance.

[0004] The file sharding technology is a method of splitting a large file into multiple small segments for processing. This method can improve the file transmission speed and processing efficiency, but it also brings new security challenges. If the sharded file segments are illegally obtained, the entire file may be leaked. Summary of the Invention

[0005] To solve the problems existing in the prior art, embodiments of the present invention provide a high-performance large-file sharding obfuscation and heterogeneous encryption method, device and equipment, which analyze the file type to determine the sharding interval, randomly shard to increase the cracking difficulty; select the encryption algorithm according to the importance of the segments; perform parallel processing and hardware acceleration to improve performance; and ensure security through dynamic key management.

[0006] To solve any of the above technical problems, the specific technical solutions of the present invention are as follows:

[0007] Embodiments of the present invention provide a high-performance large-file sharding obfuscation and heterogeneous encryption method, including:

[0008] Performing file obfuscation sharding on a large file according to the sharding size initial interval and random number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file;

[0009] Determining the importance of each file shard, and encrypting each file shard according to the importance to determine the encryption algorithm of each file shard to obtain the ciphertext of each file shard;

[0010] Taking the ciphertext of each file shard and the encrypted relative position information of each file shard as the encrypted large file;

[0011] Dynamically generate a transmission key according to the file characteristics and encryption time of the encrypted large file, where the transmission key is used to encrypt the encrypted large file when transmitting the encrypted large file.

[0012] Further, file confusion sharding of the large file according to the initial interval of shard size and random number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file further includes:

[0013] After splitting out the previous file shard, record the relative position information of the previous file, and randomly select a value within the initial interval of the shard size as the size of the next file shard;

[0014] Read the file content of the size of the next file shard from the position corresponding to the end of the previous file shard in the large file to obtain the next file shard.

[0015] Further, if the large file is in video format, file confusion sharding of the large file according to the initial interval of shard size and random number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file further includes:

[0016] Determine the key frame positions of the large file within multiple consecutive initial intervals of the shard size according to the encoding standard and container format of the large file;

[0017] Split the large file according to the key frame positions to obtain multiple file shards, and record the relative position information of each file shard.

[0018] Further, if the large file is a database file, file confusion sharding of the large file according to the initial interval of shard size and random number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file further includes:

[0019] Shard the large file according to the database table structure and the initial interval of the shard size to obtain multiple file shards, and record the relative position information of each file shard.

[0020] Further, determining the importance of each file shard further includes:

[0021] Extract the key information in each file shard respectively;

[0022] Match the key information with a predetermined key information library. If the match is successful, the file shard corresponding to the key information is an important file shard. If the match is not successful, the file shard corresponding to the key information is a non-important file shard.

[0023] Further, encrypting each file fragment according to the encryption algorithm determined for each file fragment according to the importance further includes:

[0024] If the file fragment is an important file fragment, select an encryption algorithm from a first predetermined set of encryption algorithms to encrypt the file fragment;

[0025] If the file fragment is a non-important file fragment, select an encryption algorithm from a second predetermined set of encryption algorithms to encrypt the file fragment.

[0026] Further, before performing file obfuscation fragmentation on the large file according to the initial interval of the fragmentation size and the random number mechanism, the method further includes:

[0027] Divide the large file into several consecutive parts, so as to allocate each part to its corresponding processing unit to perform file obfuscation fragmentation and encryption of the file fragments in parallel.

[0028] Further, dynamically generating a transmission key according to the file characteristics and encryption time of the encrypted large file further includes:

[0029] Use the file characteristics and encryption time of the encrypted large file as dynamic key generation parameters, where the file characteristics include file size, file name, and / or file type;

[0030] Generate the transmission key according to the dynamic key generation parameters through a predetermined algorithm.

[0031] On the other hand, an embodiment of the present invention further provides a high-performance large file fragmentation obfuscation and heterogeneous encryption device, including:

[0032] A file obfuscation fragmentation unit, configured to perform file obfuscation fragmentation on a large file according to the initial interval of the fragmentation size and the random number mechanism, to obtain a plurality of file fragments with different sizes and the relative position information of each file fragment in the large file;

[0033] A file fragment encryption unit, configured to determine the importance of each file fragment, and encrypt each file fragment according to the encryption algorithm determined for each file fragment according to the importance, to obtain ciphertexts of each file fragment;

[0034] An encrypted large file composition unit, configured to use the ciphertexts of each file fragment and the encrypted relative position information of each file fragment as the encrypted large file;

[0035] A dynamic key transmission unit, configured to dynamically generate a transmission key according to the file characteristics and encryption time of the encrypted large file, where the transmission key is used to encrypt the encrypted large file when transmitting the encrypted large file.

[0036] On the other hand, an embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored on the memory. When the processor executes the computer program, the above method is implemented.

[0037] The beneficial effects of the embodiments of the present invention are as follows:

[0038] 1. Unique sharding and obfuscation mechanism

[0039] The embodiments of the present invention adopt a brand-new file sharding and obfuscation technology. When sharding large files, not only are the files divided according to a fixed size, but also a randomization factor is introduced, making the size and position of each file fragment uncertain. This obfuscation mechanism greatly increases the difficulty for attackers to crack the files. Even if an attacker obtains some file fragments, it is difficult to determine their positions and orders in the original file.

[0040] 2. Heterogeneous encryption strategy

[0041] Different from the traditional single encryption method, the embodiments of the present invention adopt a heterogeneous encryption strategy. Combining multiple different types of encryption algorithms, different file fragments are encrypted. For example, for important file shards, a high-strength asymmetric encryption algorithm is used, while for general file fragments, a relatively fast symmetric encryption algorithm can be used. This heterogeneous encryption method not only ensures the security of the files but also improves the efficiency of encryption and decryption.

[0042] 3. High-performance implementation

[0043] Aiming at the performance problem of large file processing, the embodiments of the present invention have carried out an optimized design. Through technologies such as parallel processing and hardware acceleration, the speed of file sharding, encryption, and decryption has been greatly improved. Compared with the prior art, the encryption and decryption operations of large files can be completed in a shorter time, meeting the requirements for high performance in practical applications.

[0044] 4. Dynamic key management

[0045] The embodiments of the present invention adopt a dynamic key management mechanism, which is different from the static key management method in the prior art. In the encryption process of the embodiments of the present invention, dynamic keys are generated according to factors such as the characteristics of the files and the encryption time, making the encryption key of each file unique. At the same time, through a secure key storage and transmission method, the security of the keys is ensured. Description of the Drawings

[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0047] Figure 1 The following is a schematic flowchart of a high-performance large file sharding obfuscation and heterogeneous encryption method in an embodiment of the present invention;

[0048] Figure 2 The following is a schematic flowchart of file obfuscation sharding of a large file according to the initial interval of shard size and the random number mechanism in an embodiment of the present invention, obtaining multiple file shards of different sizes and the relative position information of each file shard in the large file;

[0049] Figure 3 The following is a schematic flowchart of determining the importance of each file shard in an embodiment of the present invention;

[0050] Figure 4 The following is a schematic flowchart of dynamically generating a transmission key according to the file characteristics and encryption time of the encrypted large file in an embodiment of the present invention;

[0051] Figure 5 The following is a schematic structural diagram of a high-performance large file sharding obfuscation and heterogeneous encryption device in an embodiment of the present invention;

[0052] Figure 6 The following is a schematic structural diagram of a computer device in an embodiment of the present invention.

[0053]

Explanation of attached drawing reference numerals

[0054] 501, file obfuscation sharding unit;

[0055] 502, file shard encryption unit;

[0056] 503, encrypted large file composition unit;

[0057] 504, dynamic key transmission unit;

[0058] 602, computer device;

[0059] 604, processing device;

[0060] 606, storage resource;

[0061] 608, driving mechanism;

[0062] 610, input / output module;

[0063] 612. Input device;

[0064] 614. Output device;

[0065] 616. Presentation device;

[0066] 618. Graphical user interface;

[0067] 620. Network interface;

[0068] 622. Communication link;

[0069] 624. Communication bus. Detailed implementation manner

[0070] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0071] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.

[0072] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0073] In order to solve the problems existing in the prior art, the embodiments of the present invention provide a high-performance large-file sharding obfuscation and heterogeneous encryption method, which analyzes the file type to determine the sharding interval, randomly shards to increase the cracking difficulty; selects an encryption algorithm according to the fragment importance; uses parallel processing and hardware acceleration to improve performance; and dynamically manages keys to ensure security. Figure 1The following is a schematic flowchart of a high-performance large-file sharding obfuscation and heterogeneous encryption method according to an embodiment of the present invention. The process of sharding and encrypting a large file is described in this figure, but it may include more or fewer operation steps based on routine or non-creative labor. The order of steps listed in the embodiment is only one of the execution orders of numerous steps and does not represent the only execution order. When the actual system or device product executes, it can be executed in the order of the method shown in the embodiment or the accompanying drawings or executed in parallel. Specifically, as Figure 1 shown, the method may include:

[0074] Step 101: Perform file obfuscation sharding on the large file according to the initial interval of shard size and the random number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file;

[0075] Specifically, as Figure 2 shown, performing file obfuscation sharding on the large file according to the initial interval of shard size and the random number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file further includes:

[0076] Step 201: After splitting out the previous file shard, record the relative position information of the previous file, and randomly select a value within the initial interval of shard size as the size of the next file shard;

[0077] Step 202: Read the file content of the size of the next file shard from the position corresponding to the end of the previous file shard in the large file to obtain the next file shard.

[0078] In the embodiment of this specification, first, it is necessary for the staff to conduct a comprehensive analysis of the file types, considering the characteristics and common size distributions of different types of files. For example, for image files, text files, video files, etc., their general size ranges are respectively counted. According to these analysis results, a relatively reasonable initial interval of shard size is determined, such as [1MB, 2MB]. The selection of this interval should not only consider the convenience of management after file splitting but also avoid excessive management overhead caused by too small shards or affecting the flexibility of encryption due to too large shards.

[0079] Then a high-quality random number generator is introduced to ensure that the generated random numbers have sufficient randomness and unpredictability. When fragmenting a large file, each time the size of the next fragment needs to be determined, the random number generator randomly selects a value within the set fragment size range. For example, if the current file size is 100MB and a part has been segmented, leaving 50MB to be segmented. At this time, the random number generator randomly generates a value within the range of [1MB, 2MB], assuming it is 1.5MB, then the next file fragment will be segmented with a size of 1.5MB.

[0080] During the segmentation process, an efficient file reading and segmentation algorithm is used to ensure that the file content is not damaged during segmentation. According to the randomly determined fragment size, the file is read and segmented paragraph by paragraph from the beginning of the file. For example, if the current fragment size is 1.5MB, 1.5MB of file content is read as a file fragment. During the segmentation process, the integrity of each file fragment must be ensured to avoid data loss or damage.

[0081] Special situations that may damage integrity and handling methods:

[0082] Hardware failure:

[0083] Situation: If there are bad sectors in the storage device (such as a hard disk) during the file reading process, it may cause some data to be unable to be read normally. Even if segmented by 1.5MB, the data within a certain fragment may be incomplete. For example, a certain sector of the hard disk is damaged, and this sector happens to be within the reading range of a 1.5MB fragment.

[0084] Handling: Data recovery techniques can be adopted, such as using the bad sector repair function built into the storage device (some hard disks have this function) to try to recover the data; or obtaining the complete file from the backup storage medium (if there is a file backup) and re-segmenting it. At the same time, during daily use, the storage device should be regularly detected and maintained to detect and handle possible hardware problems in advance.

[0085] Software error or exception:

[0086] Situation: If there are vulnerabilities in the program that implements the reading and segmentation algorithm, such as pointer out-of-bounds, poor memory management, etc., it may lead to inaccurate data reading, thereby damaging the integrity of the fragments. For example, an error occurs when the program allocates memory to store a 1.5MB fragment, resulting in the actual amount of stored data being insufficient or exceeding, making the fragment data incomplete or contaminated.

[0087] Processing: Conduct strict debugging and testing on the program, and use various testing tools (such as unit testing, integration testing, etc.) to find and fix possible software errors. During the program running process, set up a perfect error handling mechanism. When an abnormal situation (such as memory allocation failure, etc.) occurs, it can prompt the user in time and take reasonable remedial measures, such as re - attempting to read the shard or terminating the operation and prompting the user to check the program environment, etc.

[0088] In some other embodiments of this specification, for some files with complex formats, such as video files (which may contain multiple audio - video streams, index information, etc.) or database files (with specific table structures, indexes, etc.), simply sharding by 1.5MB may happen to cut at the key structural information, resulting in a shard that cannot be fully understood on its own. Although the data may be read completely, its integrity is affected at the application level. For example, the index information of a video file is divided into two different shards, and abnormal playback may occur when playing a single shard.

[0089] In response to this, according to an embodiment of this specification, if the large file is in video format, further including performing file - scrambling sharding on the large file according to the initial shard - size range and random - number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file:

[0090] Determine the key - frame positions of the large file within multiple consecutive initial shard - size ranges according to the encoding standard and container format of the large file;

[0091] Specifically, the tool for extracting key frames can be determined according to the encoding standard and container format, and use this tool (such as ffprobe of FFmpeg) to extract the byte offsets of all key frames. Then, according to the initial shard - size range, divide the large file into consecutive fixed - size ranges. Finally, map the offsets of the key frames to the corresponding shard ranges and record the relative positions to obtain the key - frame positions.

[0092] Split the large file according to the key - frame positions to obtain multiple file shards, and record the relative position information of each file shard. To ensure that each file shard has relatively complete operability in application scenarios such as playback.

[0093] If the large file is a database file, further including performing file - scrambling sharding on the large file according to the initial shard - size range and random - number mechanism to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file:

[0094] Slice the large file according to the database table structure and the initial range of the slice size to obtain multiple file slices, and record the relative position information of each file slice.

[0095] Specifically, first scan the large file, extract the values of the slice keys and analyze their distributions. For example, the slice keys can be user IDs, timestamps, etc., and the distributions of the slice keys can be the minimum value, the maximum value, the frequency, etc. Slice according to a certain field such as the user ID or date. Then, according to the limit of the initial range of the slice size, dynamically divide the range according to the sorted values of the slice keys. Optionally, first determine the range of the slice keys, such as the time range or the numerical range, and then calculate the boundaries of each slice to ensure that the size of each slice does not exceed the initial range of the slice size. For example, if slicing by time, each slice covers a fixed time period (such as 1 day), and if the data exceeds the limit, it is split into smaller granularities (such as 6 hours); if slicing by numerical range, dynamically adjust the end point of the range by calculating the cumulative data volume to ensure that a single slice does not exceed the threshold. Then slice according to the divided ranges.

[0096] And after processing special format files such as video formats or databases, preferably perform functional tests (such as playback tests, database query tests, etc.) to verify whether the file slices after slicing can be used normally.

[0097] Then assign a unique identifier to each file slice. A unique string can be generated as the identifier by using a hash algorithm combined with information such as timestamps. At the same time, record the relative position information of each file slice in the original file. Record the correspondence between the unique identifier and the position information. To increase security, encrypt the position information. A symmetric encryption algorithm or an asymmetric encryption algorithm can be used to encrypt the position information to ensure that the accurate position order can be obtained only after correct decryption. The encrypted position information can be stored in a separate database or stored together with the file fragments, but in an encrypted form.

[0098] Step 102: Determine the importance of each file slice, and determine the encryption algorithm for each file slice according to the importance to encrypt each file slice to obtain the ciphertext of each file slice;

[0099] In the embodiments of this specification, as Figure 3 shown, determining the importance of each file slice further includes:

[0100] Step 301: Extract the key information in each file slice respectively;

[0101] Step 302: Match the key information with a predetermined key information library. If the match is successful, the file slice corresponding to the key information is an important file slice. If the match is not successful, the file slice corresponding to the key information is a non-important file slice.

[0102] In the embodiments of this specification, for each file fragment, it can be analyzed from multiple aspects to determine its degree of importance. For example, if a file fragment contains specific keywords, sensitive data types (such as ID numbers, bank account numbers, etc.), or comes from a specific area of the file (such as the configuration information section at the beginning of the file), then this file fragment can be considered relatively important. Natural language processing techniques can be used to extract keywords from text-based file fragments. If keywords such as "confidential" or "contract" are included in the file fragment, then this file fragment is considered relatively important. For image files, analyze their metadata. If it contains specific markers or comes from a specific project folder, it is considered important. For video files, check their title and description information. If it involves important projects or customer information, it is determined to be important. Through these analyses, it is determined whether each file fragment is an important file fragment.

[0103] Determining the encryption algorithm for each file fragment according to the importance and encrypting each file fragment further includes:

[0104] If the file fragment is an important file fragment, select an encryption algorithm from the first predetermined encryption algorithm set to encrypt this file fragment;

[0105] If the file fragment is a non-important file fragment, select an encryption algorithm from the second predetermined encryption algorithm set to encrypt this file fragment.

[0106] Exemplarily, for important file fragments, the RSA asymmetric encryption algorithm is adopted. For non-important file fragments, the AES symmetric encryption algorithm is used.

[0107] For file fragments encrypted with the symmetric encryption algorithm, generate a random key and store the key in a secure encrypted storage device. Use this key to encrypt the file fragment. For file fragments encrypted with the asymmetric encryption algorithm, use the public key for encryption, and the private key is kept by authorized management personnel for decrypting the file fragment. During the encryption process, strictly check the execution of the encryption algorithm to ensure that there are no encryption errors or vulnerabilities.

[0108] Step 103: Use the ciphertexts of each file fragment and the encrypted relative position information of each file fragment as the encrypted large file;

[0109] Step 104: Dynamically generate a transmission key according to the file characteristics and encryption time of the encrypted large file, and the transmission key is used to encrypt the encrypted large file when transmitting the encrypted large file.

[0110] In the embodiments of this specification, as Figure 4As shown, dynamically generating a transmission key based on the file characteristics and encryption time of the encrypted large file further includes:

[0111] Step 401: Use the file characteristics and encryption time of the encrypted large file as dynamic key generation parameters, where the file characteristics include file size, file name, and / or file type;

[0112] Step 402: Generate the transmission key according to the dynamic key generation parameters through a predetermined algorithm.

[0113] Specifically, determine the key generation parameters according to factors such as the characteristics of the file and the encryption time. For example, for a file with a size of 100MB, a file type of document, and an encryption time of 15:30 on November 7, 2024, use this information as the key generation parameters.

[0114] Then use a specific algorithm to generate a dynamic key in combination with the above parameters. For example, through hash operations and encryption operations, process parameters such as file size, file name, file type, and encryption time to generate a unique dynamic key. Ensure that the encryption key for each file is unique to increase security.

[0115] Then store the dynamic key in an encrypted database. The database adopts a multi-layer encryption and access control mechanism, and only authorized users can access the key. At the same time, back up the key regularly to prevent data loss.

[0116] When the transmission key is needed, use a secure encryption channel for transmission. For example, use the SSL / TLS protocol to establish a secure connection, encrypt the key, and transmit it to the authorized recipient. The recipient uses the corresponding decryption algorithm and key to decrypt it to ensure the security of the key during transmission.

[0117] According to an embodiment of the present specification, in order to improve the processing efficiency of large files, before performing file obfuscation and fragmentation on the large file according to the initial interval of the fragmentation size and the random number mechanism, the method further includes:

[0118] Divide the large file into several consecutive parts to facilitate assigning each part to its corresponding processing unit to perform file obfuscation and fragmentation and encryption of the file fragments in parallel.

[0119] In the embodiments of this specification, the file sharding and encryption processes are divided into multiple subtasks. For example, for the sharding task of a large file, the file can be divided into several parts and assigned to different cores of a multi-core processor for simultaneous processing. For the encryption task, different file segments can also be assigned to different processing units for parallel encryption. The task scheduler is used to dynamically allocate according to the load conditions of the processing units and the priorities of the tasks, ensuring that each processing unit can work efficiently in cooperation.

[0120] Furthermore, hardware acceleration can also be utilized. Specifically, the embodiments of the present invention check the enterprise's hardware devices and find that some servers are equipped with GPUs with encryption functions. For large-scale encryption tasks, these GPUs are used for acceleration. Specialized driver programs and interfaces are written to enable the encryption software to communicate and interact with the GPUs. Tasks suitable for hardware acceleration, such as large-scale symmetric encryption operations, are assigned to the GPUs for execution, greatly improving the speed of encryption and decryption.

[0121] Based on the same inventive concept, the embodiments of the present invention also provide a high-performance large file sharding obfuscation and heterogeneous encryption device, as Figure 5 shown, including:

[0122] A file obfuscation sharding unit 501, configured to perform file obfuscation sharding on a large file according to the initial interval of the sharding size and the random number mechanism, to obtain multiple file shards of different sizes and the relative position information of each file shard in the large file;

[0123] A file shard encryption unit 502, configured to determine the importance of each file shard, and encrypt each file shard according to the encryption algorithm determined according to the importance, to obtain the ciphertext of each file shard;

[0124] An encrypted large file composition unit 503, configured to use the ciphertext of each file shard and the encrypted relative position information of each file shard as the encrypted large file;

[0125] A dynamic key transmission unit 504, configured to dynamically generate a transmission key according to the file characteristics and encryption time of the encrypted large file, where the transmission key is used to encrypt the encrypted large file when transmitting the encrypted large file.

[0126] The beneficial effects obtained by the above device are the same as those obtained by the above method, and the embodiments of the present invention will not elaborate.

[0127] As Figure 6The following is a schematic structural diagram of a computer device according to an embodiment of the present invention. The device in the present invention may be the computer device in this embodiment, which executes the method of the present invention described above. The computer device 602 may include one or more processing devices 604, such as one or more central processing units (CPUs), and each processing unit may implement one or more hardware threads. The computer device 602 may also include any storage resource 606, which is used to store any type of information such as code, settings, data, etc. Non-limiting examples include any type of RAM, any type of ROM, flash memory devices, hard disks, optical discs, etc. More generally, any storage resource may use any technology to store information. Further, any storage resource may provide volatile or non-volatile retention of information. Further, any storage resource may represent a fixed or removable component of the computer device 602. In one case, when the processing device 604 executes the associated instructions stored in any storage resource or combination of storage resources, the computer device 602 may perform any operation of the associated instructions. The computer device 602 also includes one or more drive mechanisms 608 for interacting with any storage resource, such as a hard disk drive mechanism, an optical disc drive mechanism, etc.

[0128] The computer device 602 may also include an input / output module 610 (I / O), which is used to receive various inputs (via the input device 612) and to provide various outputs (via the output device 614). A specific output mechanism may include a presentation device 616 and an associated graphical user interface (GUI) 618. In other embodiments, the input / output module 610 (I / O), the input device 612, and the output device 614 may not be included, and it may only be a computer device in a network. The computer device 602 may also include one or more network interfaces 620, which are used to exchange data with other devices via one or more communication links 622. One or more communication buses 624 couple the components described above together.

[0129] The communication link 622 may be implemented in any manner, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 622 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.

[0130] The embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0131] An embodiment of the present invention also provides a computer-readable instruction. When a processor executes the instruction, the program therein causes the processor to execute the above method.

[0132] It should be understood that in various embodiments of the present invention, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0133] It should also be understood that in the embodiments of the present invention, the term "and / or" is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present invention generally represents an "or" relationship between the front and rear associated objects.

[0134] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present invention can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0135] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.

[0136] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection to each other can be an indirect coupling or communication connection through some interfaces, devices, or units, or can also be a connection in electrical, mechanical, or other forms.

[0137] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.

[0138] In addition, each functional unit in various embodiments of the present invention may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0139] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0140] Specific embodiments of the present invention are used to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of the present invention should not be construed as a limitation to the present invention.

Claims

1. A high-performance large file fragmentation obfuscation and heterogeneous encryption method, characterized in that: The method comprises: Perform file obfuscation fragmentation on a large file according to the initial fragment size interval and the random number mechanism to obtain multiple file fragments of different sizes and relative position information of each file fragment in the large file; Determine the importance of each file segment, and determine the encryption algorithm of each file segment according to the importance to encrypt each file segment to obtain the ciphertext of each file segment; The ciphertext of each file segment and the encrypted relative position information of each file segment are used as the encrypted large file; A transmission key is dynamically generated according to the file characteristics of the encrypted large file and the encryption time, and the transmission key is used to encrypt the encrypted large file when the encrypted large file is transmitted.

2. The method according to claim 1, characterized in that The large file is fragmented by file confusion according to the fragment size initial interval and the random number mechanism to obtain multiple file fragments of different sizes and the relative position information of each file fragment in the large file further includes: After the previous file segment is split, the relative position information of the previous file is recorded, and a value is randomly selected within the initial segment size interval as the size of the next file segment; The file content of the size of the next file fragment is read from the position in the large file corresponding to the end of the previous file fragment to obtain the next file fragment.

3. The method according to claim 1, characterized in that If the large file is in video format, the large file is fragmented by file confusion according to the initial interval of the fragment size and the random number mechanism to obtain multiple file fragments of different sizes and the relative position information of each file fragment in the large file further includes: Determining key frame positions of the large file within a plurality of consecutive initial intervals of the fragment size according to a coding standard and a container format of the large file; The large file is divided according to the key frame positions to obtain a plurality of the file segments, and the relative position information of each file segment is recorded.

4. The method according to claim 1, characterized in that: If the large file is a database file, the large file is fragmented by file confusion according to the initial interval of the fragment size and the random number mechanism to obtain a plurality of file fragments of different sizes and the relative position information of each file fragment in the large file further includes: The large file is fragmented according to the database table structure and the initial interval of the fragment size to obtain a plurality of the file fragments, and the relative position information of each file fragment is recorded.

5. The method according to claim 1, characterized in that Determining the importance of each file segment further includes: Extract key information from each file shard separately; The key information is matched with a predetermined key information database. If the match is successful, the file segment corresponding to the key information is an important file segment. If the match is not successful, the file segment corresponding to the key information is a non-important file segment.

6. The method according to claim 5, characterized in that Determining the encryption algorithm of each file segment according to the importance to encrypt each file segment further includes: If the file segment is an important file segment, selecting an encryption algorithm from a first predetermined encryption algorithm set to encrypt the file segment; If the file segment is a non-important file segment, an encryption algorithm is selected from a second predetermined encryption algorithm set to encrypt the file segment.

7. The method according to claim 1, characterized in that Before performing file obfuscation segmentation on a large file according to the segment size initial interval and the random number mechanism, the method further includes: The large file is divided into a plurality of continuous parts, so that each part is allocated to a corresponding processing unit to perform file obfuscation slicing and file slicing encryption in parallel.

8. The method according to claim 1, characterized in that Dynamically generating a transmission key based on the file characteristics of the encrypted large file and the encryption time further includes: Using the file characteristics of the encrypted large file and the encryption time as dynamic key generation parameters, the file characteristics including file size, file name and / or file type; The transmission key is generated by a predetermined algorithm according to the dynamic key generation parameters.

9. A high-performance large file fragment obfuscation and heterogeneous encryption device, characterized in that: include: A file obfuscation slicing unit, used to perform file obfuscation slicing on a large file according to an initial interval of slicing size and a random number mechanism, to obtain a plurality of file slicings of different sizes and relative position information of each file slicing in the large file; A file segment encryption unit, used to determine the importance of each file segment, and determine the encryption algorithm of each file segment according to the importance to encrypt each file segment to obtain a ciphertext of each file segment; The encrypted large file composition unit is used to use the ciphertext of each file segment and the encrypted relative position information of each file segment as the encrypted large file; A dynamic key transmission unit is used to dynamically generate a transmission key according to the file characteristics of the encrypted large file and the encryption time, and the transmission key is used to encrypt the encrypted large file when transmitting the encrypted large file.

10. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.