Image file transmission method and image file transmission system

By adopting multiple check code mechanisms and encrypted data transmission protocols during the image file transmission process, the security risks in the image file transmission process are solved, and the safe, complete and accurate transmission of image files is achieved.

CN120602724APending Publication Date: 2025-09-05THE PEOPLES BANK OF CHINA NAT CLEARING CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510749116.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing image file transmission methods have security risks during the transmission process, and data encryption technology alone cannot guarantee the integrity, security and correctness of image files.

Method used

A multiple check code mechanism is adopted, including check code verification between the image initiating unit, storage unit and receiving unit, combined with encrypted data transmission protocol and digital signature certificate to ensure the security of image files during transmission.

Benefits of technology

Through multiple verification and encryption processes, the security of image files during transmission is ensured, the risk of image file leakage and tampering is avoided, and the security and accuracy of transmission are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602724A_ABST
    Figure CN120602724A_ABST
Patent Text Reader

Abstract

The invention discloses an image file transmission method and an image file transmission system, and relates to the field of data processing, and the method comprises the steps that an image initiating unit receives image file data uploaded by a user and a first check code generated by calculating the encoded image file data; the image initiating unit encodes the image file data, calculates to generate a second check code, verifies the first check code and the second check code, calculates the encoded image file data to generate a third check code if the verification is correct, and sends the encoded image file data and the third check code to the image storage unit; and the image storage unit calculates the encoded image file data to generate a fourth check code, verifies the fourth check code and the third check code, and stores the encoded image file data and sends a storage identifier ID of the encoded image file data to the image initiating unit if the verification is correct. According to the scheme provided by the invention, the transmission security of the image file is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to an image file transmission method and an image file transmission system. Background Art

[0002] In the financial field, image files generally contain sensitive information and have high security requirements. Therefore, how to ensure that image files are not tampered with during transmission is an important issue.

[0003] A common method for secure image file transmission is to use data encryption technology to improve security. In the actual image transmission process, from the initiator uploading the image file to the file being transferred to the target system, the transmission process goes through multiple links, each of which may have security risks. Furthermore, untrusted third parties often implement file storage and forwarding. Therefore, data encryption technology alone cannot guarantee the integrity, security, and correctness of image files. Summary of the Invention

[0004] The present invention provides an image file transmission method and an image file transmission system, which improve the security of image file transmission.

[0005] According to one aspect of the present invention, there is provided a method for transmitting an image file, comprising:

[0006] The image initiating unit receives the image file data uploaded by the user and a first check code calculated and generated based on the encoded image file data;

[0007] The image initiating unit encodes the image file data and calculates and generates a second check code, and verifies the first check code and the second check code. If the verification is correct, the image file data is calculated and generated into a third check code, and the encoded image file data and the third check code are sent to the image storage unit;

[0008] The image storage unit calculates the fourth check code for the encoded image file data and verifies the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage ID of the encoded image file data is sent to the image initiating unit.

[0009] In one embodiment, after the image storage unit calculates and generates a fourth check code for the encoded image file data, and verifies the fourth check code and the third check code, and if the verification is correct, stores the encoded image file data and sends the storage ID of the encoded image file data to the image initiating unit, the method further includes:

[0010] The image initiating unit sends an image file sending message to the image receiving unit according to the image file sending instruction sent by the user, wherein the image file sending message includes the storage ID of the encoded image file data and the third check code;

[0011] The image storage unit receives the storage ID of the encoded image file data sent by the image receiving unit and sends the corresponding encoded image file data and the fourth check code to the image receiving unit;

[0012] The image receiving unit determines whether the received third verification code and the fourth verification code are the same, and if they are the same, confirms that the image file is received successfully.

[0013] In one embodiment, the image initiating unit sends an image file sending message to the image receiving unit according to the image file sending instruction sent by the user, including:

[0014] The image initiating unit encrypts the storage ID and the third verification code of the encoded image file data using the private key of the digital signature certificate according to the image file sending instruction sent by the user, and then sends the encrypted data to the image receiving unit;

[0015] Before the image storage unit receives the storage ID of the encoded image file data sent by the image receiving unit, the method further includes:

[0016] The image receiving unit uses the public key of the digital signature certificate to verify whether the storage ID and the third check code of the encoded image file data have been tampered with.

[0017] In one embodiment, data is transmitted between the image receiving unit and the image storage unit using an encrypted data transmission protocol.

[0018] In one embodiment, after the image storage unit calculates and generates a fourth check code for the encoded image file data, and verifies the fourth check code and the third check code, and if the verification is correct, stores the encoded image file data and sends the storage ID of the encoded image file data to the image initiating unit, the method further includes:

[0019] The image initiating unit sets the data status of the image file corresponding to the storage ID to pending review and sends a review notification to the user;

[0020] After receiving the audit passed message sent by the user, the image initiating unit sets the status of the image file data corresponding to the storage ID to audit passed.

[0021] In one embodiment, data transmission between the image initiating unit and the image storage unit is performed via an encrypted data transmission protocol.

[0022] In one embodiment, the image initiating unit receives the image file data uploaded by the user and calculates a first verification code generated by the encoded image file data, including:

[0023] The image initiating unit receives the image file data uploaded by the user, a first check code generated by encoding the image file data and a first timestamp of the uploaded image file data, and a first timestamp;

[0024] The image initiating unit encodes the image file data and calculates and generates a second check code, and verifies the first check code and the second check code, including:

[0025] The image initiating unit generates a second check code by encoding the image file data and the first timestamp, and determines whether the first check code and the second check code are the same.

[0026] In one embodiment, after the image initiating unit receives the image file data uploaded by the user, the first verification code generated by encoding the image file data and the first timestamp of the uploaded image file data, and the first timestamp, the image initiating unit further includes:

[0027] The image initiating unit determines whether the time difference between the second timestamp and the first timestamp of the image file data uploaded by the user exceeds a preset time threshold; if the time difference exceeds the preset time threshold, it is determined that the image file data has a tampering risk.

[0028] According to another aspect of the present invention, there is provided an image file transmission system, comprising:

[0029] The image initiating unit is configured to receive image file data uploaded by a user and a first check code generated by calculating the encoded image file data; encode the image file data and calculate a second check code, verify the first check code and the second check code, and if the verification is correct, calculate a third check code for the encoded image file data, and send the encoded image file data and the third check code to the image storage unit;

[0030] The image storage unit is used to calculate and generate a fourth check code for the encoded image file data, and verify the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage ID of the encoded image file data is sent to the image initiation unit.

[0031] In one embodiment, the image initiating unit is further configured to send an image file sending message to the image receiving unit according to the image file sending instruction sent by the user, wherein the image file sending message includes the storage ID of the encoded image file data and the third check code;

[0032] The image storage unit is further configured to receive the storage ID of the encoded image file data sent by the image receiving unit and send the corresponding encoded image file data and the fourth check code to the image receiving unit;

[0033] The image file transmission system also includes:

[0034] The image receiving unit is used to determine whether the received third verification code and the fourth verification code are the same, and if they are the same, confirm that the image file is received successfully.

[0035] In one embodiment, the image initiating unit is specifically configured to encrypt the storage ID and the third verification code of the encoded image file data using the private key of the digital signature certificate according to the image file sending instruction sent by the user, and then send the encrypted data to the image receiving unit;

[0036] The image receiving unit is specifically used to use the public key of the digital signature certificate to verify whether the storage ID and the third check code of the encoded image file data have been tampered with.

[0037] In one embodiment, data is transmitted between the image receiving unit and the image storage unit using an encrypted data transmission protocol.

[0038] In one embodiment, the image storage unit is specifically used to set the status of the image file data corresponding to the storage ID to pending review and send a review notification to the user; after receiving the review pass message sent by the user, the status of the image file data corresponding to the storage ID is set to review passed.

[0039] In one embodiment, data transmission between the image initiating unit and the image storage unit is performed via an encrypted data transmission protocol.

[0040] In one embodiment, the image initiation unit is specifically used to receive image file data uploaded by a user, encode the image file data and the first timestamp of the uploaded image file data to generate a first verification code, and a first timestamp; encode the image file data and the first timestamp to generate a second verification code, and determine whether the first verification code and the second verification code are the same.

[0041] In one embodiment, the image initiating unit is further used to determine whether the time difference between the second timestamp and the first timestamp of the image file data uploaded by the user exceeds a preset time threshold; if the time difference exceeds the preset time threshold, it is determined that the image file data is at risk of tampering.

[0042] According to the technical solution of the embodiment of the present invention, after the image initiating unit receives the image file data uploaded by the user and the first check code calculated for the encoded image file data, the image initiating unit encodes the image file data and calculates a second check code, and verifies the first check code and the second check code. If the verification is correct, a third check code is calculated for the encoded image file data, and the encoded image file data and the third check code are sent to the image storage unit. The image storage unit can calculate a fourth check code for the encoded image file data, and verify the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage ID of the encoded image file data is sent to the image initiating unit, thereby completing the secure uploading of the image file. The image file sending end can only send the storage ID corresponding to the image file to the receiving end, and the image file receiving end can obtain the corresponding image file from the image storage unit, thereby avoiding the risk of leakage during the image file sending process, and multiple verifications are performed during the process of uploading and storing the image file in the image storage unit, thereby ensuring the secure flow of the image file.

[0043] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0045] Figure 1 A schematic diagram of a flow chart of an image file transmission method provided by an embodiment of the present invention;

[0046] Figure 2 A schematic flow chart of another image file transmission method provided by an embodiment of the present invention;

[0047] Figure 3 A schematic diagram of a specific process of image file transmission according to the image file transmission method provided in an embodiment of the present invention;

[0048] Figure 4 A schematic structural diagram of an image file transmission system provided by an embodiment of the present invention;

[0049] Figure 5 A schematic structural diagram of another image file transmission system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0050] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of the present invention. The acquisition, storage, use, processing, etc. of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0051] Figure 1 A flowchart of an image file transmission method provided by an embodiment of the present invention is shown as follows: Figure 1 As shown, the image file transmission method provided in this embodiment includes:

[0052] Step S110: The image initiating unit receives the image file data uploaded by the user and a first verification code generated by calculating the encoded image file data.

[0053] The image file transmission method provided in the embodiment of the present application is used to realize the secure transmission of image files, including the secure transmission of image files from the initiating end to the storage end, and the secure transmission from the storage end to the receiving end. The image file transmission method provided in the embodiment of the present application is applied to an image file transmission system. The image file transmission system is arranged on a server or service node that provides an image file transmission function. The server can be centrally or dispersedly deployed at a service provider that provides image file transmission services, or it can be deployed in the cloud. The image file transmission method provided in the embodiment of the present application can be executed by a dedicated image file transmission system, or it can be executed by a hardware module or software module deployed on a server or service node. Preferably, the image file transmission method can be executed by a software module deployed in a server or service node.

[0054] To achieve secure transmission of image files, traditional data transmission methods use various file encryption algorithms to encrypt the image files being transmitted, and digital signature technology and other methods can be used to improve the transmission security of image files. However, the transmission process of image files may pass through multiple environments, each of which may have security risks, including untrusted nodes. Encrypting files using only conventional file encryption methods still cannot guarantee the security of image files during transmission. Therefore, embodiments of the present application provide a method for encrypting image files during image file transmission to improve the security of image file transmission.

[0055] First, the image initiation unit receives the image file data uploaded by the user and a first verification code generated by calculating the encoded image file data. The image initiation unit is a hardware or software unit located at the image file sending end. Users can upload the image file to be transmitted to the image initiation unit, which processes it before sending it to the image storage unit for storage. Security verification is performed during the image file upload process to the image initiation unit and the image file transmission process from the image initiation unit to the image storage unit. Users submit image files through the image file upload portal. Image files are graphical representations of files. After being uploaded, the image files are first converted into digital image file data. To store and transmit the file data, the image file data must be encoded to obtain the encoded image file data. The image file data can be encoded using any data encoding method that is convenient for file transmission and storage. The image initiation unit receives the encoded image file data uploaded by the user. In addition, to ensure that the image file data received by the image initiation unit has not been tampered with, the user can also perform encryption calculations on the encoded image file data to generate a first verification code before uploading the image file and transmitting it to the image initiation unit. The first verification code is a string of numbers or letters of a fixed length. The first verification code is obtained by processing the encoded image file data according to a certain encryption encoding method. Different first verification codes will be obtained when processing different encoded image file data. The image initiating unit will receive the image file data uploaded by the user and the first verification code calculated based on the encoded image file data.

[0056] The user uploads the image file data through, for example, a web page or a dedicated file upload port. This file upload portal may also be referred to as an image file upload front end, and the image initiation unit serves as an image file upload back end. When the user uploads the image file data through the image file data upload portal, the image file data upload portal may encode and encrypt the image file data to obtain the encoded image file data and generate a first verification code, and then send the first verification code and the image file data together to the image initiation unit.

[0057] In step S120, the image initiation unit encodes the image file data and calculates and generates a second check code, and verifies the first check code and the second check code. If the verification is correct, the third check code is calculated and generated for the encoded image file data, and the encoded image file data and the third check code are sent to the image storage unit.

[0058] After the image initiation unit receives the uploaded image file data, it encodes the image file data and encrypts it to generate a second check code. The encoding algorithm and encryption algorithm used by the image initiation unit to encode and encrypt the image file data are the same as the encoding algorithm and encryption algorithm used by the image file data upload entry to encode and encrypt the image file data. If the image file data received by the image initiation unit is exactly the same as the image file data uploaded by the user, the first check code and the second check code are the same. Therefore, after the image initiation unit generates the second check code, the first check code and the second check code are verified and compared. If the two are the same, it means that the verification is correct. At this time, the encoded image file data is encrypted again to generate a third check code, and the encoded image file data and the third check code are sent to the image storage unit. The encoding algorithm used by the image initiation unit to encode the image file and the encoding algorithm used by the file data upload entry to encode the image file data can be the same or different.

[0059] In step S130, the image storage unit calculates and generates a fourth check code for the encoded image file data, and verifies the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage ID of the encoded image file data is sent to the image initiating unit.

[0060] The image storage unit is a dedicated storage unit for user-uploaded image file data. It is located on a dedicated storage server or in the cloud to meet the image file data reception needs of different users. By setting up the image storage unit, users can avoid sending image file data directly to the receiving end. Instead, multiple file encryption and verification mechanisms can be set up between the image file data sender and the image storage unit, and between the image storage unit and the image file data receiver, thereby improving the transmission security of image files.

[0061] After receiving the encoded image file data and the third check code sent by the image initiating unit, the image storage unit encrypts the encoded image file data and generates a fourth check code. The encryption algorithm used by the image storage unit to encrypt the encoded image file data is the same as the encryption algorithm used by the image initiating unit to encrypt the encoded image file data. Therefore, if the encoded image file data received by the image storage unit and the encoded image file data sent by the image initiating unit are exactly the same, then the third check code and the fourth check code are the same. Therefore, after the image storage unit generates the fourth check code, it verifies and compares the third check code and the fourth check code. If the two are the same, it means that the verification is correct, which means that the encoded image file data sent by the image initiating unit has not been tampered with, and the encoded image file data can be stored. The image storage unit then assigns a storage identification (ID) to the stored encoded image file and sends the storage ID to the image initiating unit, so that the image initiating unit knows that the image file has been successfully stored. When sending the image file to the image file receiving end, it can only send the storage ID corresponding to the image file uploaded to the image storage unit, thereby avoiding the risk of image file leakage during transmission. In the image storage unit, one storage ID uniquely corresponds to one encoded image file data.

[0062] The image file transmission method provided by this embodiment is as follows: when the image initiating unit receives the image file data uploaded by the user and the first check code calculated for the encoded image file data, the image initiating unit encodes the image file data and calculates a second check code, and verifies the first check code and the second check code. If the verification is correct, a third check code is calculated for the encoded image file data, and the encoded image file data and the third check code are sent to the image storage unit. The image storage unit can then calculate a fourth check code for the encoded image file data, and verify the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage ID of the encoded image file data is sent to the image initiating unit, thereby completing the secure uploading of the image file. The image file sending end can only send the storage ID corresponding to the image file to the receiving end, and the image file receiving end can obtain the corresponding image file from the image storage unit, thereby avoiding the risk of leakage during the image file sending process, and multiple verifications are performed during the process of uploading and storing the image file in the image storage unit, thereby ensuring the security of the image file.

[0063] In one embodiment, data is transmitted between the image initiating unit and the image storage unit via an encrypted data transmission protocol. The encrypted data transmission protocol is a data transmission protocol that includes a security verification protocol. By transmitting data between the image initiating unit and the image storage unit via the encrypted data transmission protocol, the security of the data transmission can be further improved. The encrypted data transmission protocol in the embodiment of the present application can be, for example, Hypertext Transfer Protocol Secure (HTTPS). Of course, the encrypted data transmission protocol can also be any other encrypted data transmission protocol.

[0064] Figure 2 A flow chart of another image file transmission method provided by an embodiment of the present invention is shown as follows: Figure 2 As shown, the image file transmission method provided in this embodiment includes:

[0065] Step S210: The image initiating unit sends an image file sending message to the image receiving unit according to the image file sending instruction sent by the user. The image file sending message includes the storage ID of the encoded image file data and a third check code.

[0066] The image file transmission method provided in this embodiment is used for Figure 1 The image file transmission method shown in the figure includes a process in which, after uploading an image file to an image storage unit, the image file sending end sends the image file data to the image file receiving end. When the image storage unit stores image file data uploaded by a user through an image initiating unit, the user can send an image file sending instruction through the image initiating unit. This image file sending instruction instructs the image initiating unit to send an image file sending message to the image receiving unit. The image receiving unit is the image receiving unit at the image file receiving end that needs to receive the image file. The image file sending message includes the storage ID of the encoded image file data and a third verification code corresponding to the image file data. The storage ID of the image file data is sent by the image storage unit to the image initiating unit after the image initiating unit successfully uploads the image file data to the image storage unit. The third verification code is calculated and generated by the image initiating unit during the image file uploading process. The storage ID sent by the image initiating unit to the image receiving unit is used by the image receiving unit to determine the image file data to be sent, and the third verification code is used by the image receiving unit to verify the received image file data.

[0067] In step S220 , the image storage unit receives the storage ID of the encoded image file data sent by the image receiving unit and sends the corresponding encoded image file data and the fourth verification code to the image receiving unit.

[0068] After receiving the storage ID of the encoded image file data and the third verification code, the image receiving unit sends the storage ID of the encoded image file data to the image storage unit. That is, based on the storage ID, the image storage unit searches for and requests downloading of the corresponding image file data. After receiving the storage ID sent by the image receiving unit, the image storage unit searches for the encoded image file data and the corresponding fourth verification code corresponding to the storage ID, and then sends the encoded image file data and the fourth verification code to the image receiving unit.

[0069] In step S230 , the image receiving unit determines whether the received third verification code and the received fourth verification code are the same. If they are the same, it is confirmed that the image file is received successfully.

[0070] After the image receiving unit receives the fourth verification code sent by the image storage unit, it verifies whether the third verification code received from the image initiating unit is the same as the above-mentioned fourth verification code. If they are the same, it is determined that the image file is received successfully, that is, it is confirmed that the encoded image file data sent by the image storage unit is the data corresponding to the image file to be sent by the user. The image receiving unit only needs to decode the encoded image file data to realize the transmission of the image file from the image file sending end to the image file receiving end.

[0071] Since the information sent by the image initiating unit to the image receiving unit does not directly include the image file data, but only sends the storage ID and the third verification code corresponding to the image file data, there is no risk of image file data being leaked during this process. In the process of data interaction between the image receiving unit and the image storage unit, the image receiving unit verifies the third verification code received from the image initiating unit and the fourth verification code received from the image storage unit, thereby also preventing the image file data from being tampered with. Therefore, the image file transmission method provided by this embodiment is Figure 1 On the basis of the embodiment shown, the transmission security of the image file is further improved.

[0072] In one embodiment, data is transmitted between the image receiving unit and the image storage unit via an encrypted data transmission protocol. The encrypted data transmission protocol is a data transmission protocol that includes a security verification protocol. By transmitting data between the image receiving unit and the image storage unit via the encrypted data transmission protocol, the security of the data transmission can be further improved. The encrypted data transmission protocol in the embodiment of the present application can be, for example, Hypertext Transfer Protocol Secure (HTTPS). Of course, the encrypted data transmission protocol can also be any other encrypted data transmission protocol.

[0073] In one embodiment, in order to further improve the security of image file transmission, the image file transmission method provided in the embodiment of the present application can also use a digital signature certificate verification method to verify the image file data transmission process. Specifically, the image initiating unit can encrypt the storage ID and the third check code of the encoded image file data using the digital signature certificate private key according to the image file sending instruction sent by the user, and then send it to the image receiving unit. After the image receiving unit receives the encrypted storage ID and the third check code of the encoded image file data sent by the image initiating unit, it uses the digital signature certificate public key to verify whether the encoded image file data and the third check code have been tampered with. If not, the image receiving unit confirms that the received information is correct, and then obtains the image file data from the image storage unit. The method of verifying data using a digital signature can adopt any digital signature verification method based on asymmetric keys in the prior art.

[0074] In one embodiment, after the image storage unit sends the storage ID of the encoded image file data to the image initiation unit, the image initiation unit may set the status of the image file data corresponding to the storage ID to pending review and send a review notification to the user. After the image initiation unit stores the image file data in the image storage unit, the image file data uploaded to the image storage unit may be reviewed and confirmed by relevant staff to further ensure the accuracy of the image file data. After the image initiation unit receives the storage ID sent by the image storage unit, it means that the image storage unit has completed the storage of the image file. At this time, the image initiation unit sets the status of the image file data corresponding to the storage ID to pending review. After receiving the review notification, the user responsible for reviewing the image file data reviews and confirms the image file with a status of pending review, that is, determines whether the image file data uploaded to the image storage unit is accurate. If it is accurate, the image initiation unit will receive a review approval message sent by the user. At this time, the image initiation unit will set the status of the image file data corresponding to the storage ID to approved. If the user fails to pass the review of the image file data, the image initiation unit will set the image file data status corresponding to the storage ID to failed review, and further trigger the image storage unit to delete the encoded image file data corresponding to the storage ID, and notify the user to re-upload the image file data.

[0075] In one embodiment, an image initiation unit receives image file data uploaded by a user and calculates a first verification code generated by encoding the encoded image file data, including: the image initiation unit receives the image file data uploaded by the user, encodes the image file data and a first timestamp of the uploaded image file data to generate the first verification code, and the first timestamp. To further improve the transmission security of the image file data, when the user uploads the image file data through an image file data upload portal, the first timestamp of the uploaded image file data is simultaneously recorded. The image file data upload portal can then encode and encrypt the image file data and the first timestamp to generate a first verification code, and then transmit the image file data, the first verification code generated by encoding the image file data and the first timestamp of the uploaded image file data, and the first timestamp to the image initiation unit. After the image initiation unit receives the image file data, the first verification code generated by encoding the image file data and the first timestamp of the uploaded image file data, and the first timestamp, the image initiation unit encodes the image file data and the first timestamp to generate a second verification code, and then determines whether the first verification code and the second verification code are the same. Since the generated first check code and the second check code are based on the image file data and the first timestamp, they simultaneously reflect the characteristics of the image file data and the first timestamp. Since the timestamp information is added, the security of the image file transmission is further improved.

[0076] In one embodiment, when using timestamps to assist in the encryption of image file data, upon receiving information such as the image file data uploaded by the user, the image initiating unit also records a second timestamp of the time the image initiating unit receives the information and calculates the time difference between the first timestamp and the second timestamp. The image initiating unit then determines whether the calculated time difference exceeds a preset time threshold. If the calculated time difference does not exceed the preset time threshold, the data transmission is normal. If the calculated time difference exceeds the preset time threshold, it means that the data transmission delay exceeds the normal data transmission delay, thus determining that the image file data is at risk of tampering. For example, if the normal average delay from the user uploading the image file data to the image file data reaching the image initiating unit is 10ms due to factors such as system response and data transmission path, the preset time threshold can be set to 20ms. If the difference between the calculated first timestamp and the second timestamp exceeds 20ms, the image file data may have been tampered with during transmission, and a warning message can be issued to the user indicating the risk of image file data tampering.

[0077] The following is a detailed description of the image file transmission method provided by the embodiment of the present application using a specific embodiment:

[0078] 1. Worker A at the image file sending end uploads the image file through the front end of the image initiating unit (image file data upload entrance). Specifically:

[0079] The front end of the image initiation unit converts the image file uploaded by the user into binary data, denoted as a0; then the binary format of the image file is converted into a Base64-encoded text format (any other encoding method for data transmission can also be used), denoted as a1, a1=base64_encode(a0); then the SM3 digest (first verification code) of the encoded image file data and the first timestamp (t0) is calculated, denoted as a2, a2=sm3(a1+t0), where SM3 is a cryptographic hash algorithm; then the front end of the image initiation unit sends the image file data (a0), SM3 digest (a2) and the first timestamp (t0) to the back end of the image initiation unit (image initiation unit).

[0080] 2. After receiving the image file data (a0), SM summary (a2) and first timestamp (t0), the image initiation unit backend performs the following processing:

[0081] The image initiation unit backend calculates the time difference between the current second timestamp (t1) and the first timestamp (t0) of the image initiation unit server, denoted as △t, △t = t1-t0, sets the interface response time threshold (preset time threshold), denoted as T, verifies that △t is smaller than the set threshold T, ensures the timeliness of image file upload, and prevents replay attacks. The image file data is encoded and denoted as b1, b1 = base64_encode(a0). The image initiation unit backend calculates the SM3 digest of the received image file data and the first timestamp, denoted as b2, b2 = sm3(b1+t0). The image initiation unit backend verifies and checks the SM3 digest b2 with the SM3 digest a2 uploaded by the image initiation frontend: compares whether b2 is equal to a2 to ensure that the image file has not been tampered with. The image initiation unit backend calculates the SM3 digest of the received image file data, denoted as b3, b3 = sm3(b1). The image initiation unit backend saves the image data file b1 and the corresponding SM3 digest b3 to the local database.

[0082] 3. Staff A at the sending end of the image file submits the image file at the front end of the image initiation unit. The image initiation unit uses the HTTPS transmission protocol to transmit the image file b1 and the image file SM3 summary b3 to the image storage unit.

[0083] 4. The image storage unit receives the image file data b1 and the image file SM3 summary b3. The image storage unit calculates the SM3 summary of the image file based on b1, denoted as c3, c3 = sm3(b1), and then compares whether c3 is equal to b3 to ensure that the image file has not been tampered with. The image storage unit generates an image storage ID, denoted as imgsid, saves the image file data b1, the image file SM3 summary c3 and the storage ID locally, and transmits imgsid to the image initiation unit via the HTTPS transmission protocol. The image initiation unit receives the image file storage ID and stores it in the local database.

[0084] 5. Staff member B at the image file sending end reviews the image information in the image initiating unit and reviews the image file on the client side to ensure the correctness of the image file through manual review.

[0085] 6. Worker B at the image file sending end adds a digital signature to the file storage ID and file SM3 summary b3 using the certificate private key in the image initiating unit and sends it to the image receiving unit

[0086] The image initiating unit transmits the image file storage ID and image file SM3 digest b3 to the image receiving unit in the form of a message. During the transmission process, the image storage ID, file SM3 digest b3, and other data are digitally signed using the initiating organization's digital certificate and then sent to the message transmission platform in the form of a message. The digital signature ensures the authenticity and credibility of the data. The message transmission platform performs SM4 encryption on the message before transmitting it to the image receiving unit. The encryption process during transmission ensures the confidentiality of the message.

[0087] 7. The image receiving unit receives and processes the image information

[0088] The message is digitally signed and verified based on the certificate public key to ensure that the message content has not been tampered with. The image file storage ID and the image file SM3 summary b3 are then saved to the image receiving unit. An image file download request is initiated to the image storage unit through the HTTPS transmission protocol based on the image storage ID.

[0089] 8. The image storage unit receives the image file download request and processes it

[0090] The image file b1 and the image file SM3 summary c3 are obtained according to the image storage ID, and the image storage unit sends the image file b1 and the image file SM3 summary c3 to the image receiving unit via the HTTPS transmission protocol.

[0091] 9. The image receiving unit receives the image file and processes it

[0092] The image receiving unit receives the image file b1 and the image file SM3 digest c3 from the image storage unit. Based on the image file b1, the SM3 digest is calculated, denoted as d3, where d3 = sm3(b1). The consistency of d3 and c3 is verified to ensure that the file transmitted from the image storage unit to the image receiving unit has not been tampered with. The consistency of the SM3 digest c3 in the image storage unit and the SM3 digest b3 of the file stored in the image receiving unit is checked to ensure that the image file has not been tampered with, thereby ensuring the security and correctness of the file transmission.

[0093] Figure 3 FIG. 1 is a schematic diagram of a specific process of image file transmission according to an embodiment of the present invention. Figure 3 As shown, the image file transmission method is executed by an image file transmission system, which includes an image initiating unit, an image storage unit and an image receiving unit. The image file sending end at the image initiating unit and the image file receiving end at the image receiving unit are connected by Figure 3 The interactive process shown is used to transmit image files.

[0094] Figure 4 A schematic diagram of the structure of an image file transmission system provided by an embodiment of the present invention is shown in FIG. Figure 4 As shown, the image file transmission system provided in this embodiment includes:

[0095] The image initiation unit 41 is used to receive the image file data uploaded by the user and the first check code calculated for the encoded image file data; encode the image file data and calculate the second check code, and verify the first check code and the second check code. If the verification is correct, the third check code is calculated for the encoded image file data, and the encoded image file data and the third check code are sent to the image storage unit 42; the image storage unit 42 is used to calculate the fourth check code for the encoded image file data, and verify the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage ID of the encoded image file data is sent to the image initiation unit 41.

[0096] The impact file transmission system provided in this embodiment is used to implement Figure 1 The implementation principle and technical effects of the impact file transmission method in the illustrated embodiment are similar and will not be described in detail here.

[0097] Figure 5 A structural diagram of another image file transmission system provided by an embodiment of the present invention is shown as follows: Figure 5 As shown, the image file transmission system provided by this embodiment is Figure 4 On the basis of, it also includes an image receiving unit 43.

[0098] The image initiating unit 41 is also used to send an image file sending message to the image receiving unit 43 according to the image file sending instruction sent by the user, and the image file sending message includes the storage ID and the third verification code of the encoded image file data; the image storage unit 42 is also used to receive the storage ID of the encoded image file data sent by the image receiving unit 43 and send the corresponding encoded image file data and the fourth verification code to the image receiving unit 43; the image receiving unit 43 is used to determine whether the received third verification code and the fourth verification code are the same, and if they are the same, confirm that the image file is received successfully.

[0099] The impact file transmission system provided in this embodiment is used to implement Figure 2 The implementation principle and technical effects of the impact file transmission method in the illustrated embodiment are similar and will not be described in detail here.

[0100] In one embodiment, the image initiating unit 41 is specifically used to encrypt the storage ID and the third verification code of the encoded image file data using the private key of the digital signature certificate according to the image file sending instruction sent by the user, and then send it to the image receiving unit 43; the image receiving unit 43 is specifically used to use the public key of the digital signature certificate to verify whether the storage ID and the third verification code of the encoded image file data have been tampered with.

[0101] In one embodiment, the image receiving unit 43 and the image storage unit 42 perform data transmission via an encrypted data transmission protocol.

[0102] In one embodiment, the image storage unit 42 is specifically used to set the status of the image file data corresponding to the storage ID to pending review and send a review notification to the user; after receiving the review pass message sent by the user, the status of the image file data corresponding to the storage ID is set to review passed.

[0103] In one embodiment, the image initiating unit 41 and the image storage unit 42 perform data transmission via an encrypted data transmission protocol.

[0104] In one embodiment, the image initiation unit 41 is specifically used to receive image file data uploaded by a user, a first verification code and a first timestamp generated by encoding the image file data and the first timestamp of the uploaded image file data; generate a second verification code by encoding the image file data and the first timestamp, and determine whether the first verification code and the second verification code are the same.

[0105] In one embodiment, the image initiation unit 41 is also used to determine whether the time difference between the second timestamp and the first timestamp of the image file data uploaded by the user exceeds a preset time threshold; if the time difference exceeds the preset time threshold, it is determined that the image file data is at risk of tampering.

[0106] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0107] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for transmitting an image file, characterized in that: include: The image initiating unit receives the image file data uploaded by the user and a first check code calculated and generated based on the encoded image file data; The image initiating unit encodes the image file data and calculates and generates a second check code, verifies the first check code and the second check code, and if the verification is correct, calculates and generates a third check code for the encoded image file data, and sends the encoded image file data and the third check code to the image storage unit; The image storage unit calculates and generates a fourth check code for the encoded image file data, and verifies the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage identification ID of the encoded image file data is sent to the image initiation unit.

2. The method according to claim 1, characterized in that The image storage unit calculates and generates a fourth check code for the encoded image file data, verifies the fourth check code and the third check code, and if the verification is correct, stores the encoded image file data and sends the storage ID of the encoded image file data to the image initiating unit, further comprising: The image initiating unit sends an image file sending message to the image receiving unit according to the image file sending instruction sent by the user, wherein the image file sending message includes the storage ID of the encoded image file data and the third check code; The image storage unit receives the storage ID of the encoded image file data sent by the image receiving unit and sends the corresponding encoded image file data and the fourth check code to the image receiving unit; The image receiving unit determines whether the received third verification code and the fourth verification code are the same, and if they are the same, confirms that the image file is received successfully.

3. The method according to claim 2, characterized in that The image initiating unit sends an image file sending message to the image receiving unit according to the image file sending instruction sent by the user, including: The image initiating unit encrypts the storage ID of the encoded image file data and the third verification code using the private key of the digital signature certificate according to the image file sending instruction sent by the user, and then sends the encrypted data to the image receiving unit; Before the image storage unit receives the storage ID of the encoded image file data sent by the image receiving unit, the method further includes: The image receiving unit uses the digital signature certificate public key to verify whether the storage ID of the encoded image file data and the third verification code have been tampered with.

4. The method according to claim 2, characterized in that The image receiving unit and the image storage unit perform data transmission via an encrypted data transmission protocol.

5. The method according to any one of claims 1 to 4, characterized in that The image storage unit calculates and generates a fourth check code for the encoded image file data, verifies the fourth check code and the third check code, and if the verification is correct, stores the encoded image file data and sends the storage ID of the encoded image file data to the image initiating unit, further comprising: The image initiating unit sets the image file data status corresponding to the storage ID to be reviewed and sends a review notification to the user; After receiving the audit passed message sent by the user, the image initiating unit sets the status of the image file data corresponding to the storage ID to audit passed.

6. The method according to claim 5, characterized in that The image initiating unit and the image storage unit perform data transmission via an encrypted data transmission protocol.

7. The method according to any one of claims 1 to 4, characterized in that The image initiating unit receives the image file data uploaded by the user and calculates a first verification code generated by the encoded image file data, including: The image initiating unit receives image file data uploaded by a user, a first verification code generated by encoding the image file data and a first timestamp of uploading the image file data, and the first timestamp; The image initiating unit encodes the image file data and calculates and generates a second verification code, and verifies the first verification code and the second verification code, including: The image initiating unit generates a second check code based on the image file data and the first timestamp code, and determines whether the first check code is the same as the second check code.

8. The method according to claim 7, characterized in that After the image initiating unit receives the image file data uploaded by the user, a first verification code generated by encoding the image file data and a first timestamp of uploading the image file data, and the first timestamp, the method further includes: The image initiating unit determines whether the time difference between the second timestamp of the image file data uploaded by the user and the first timestamp exceeds a preset time threshold; if the time difference exceeds the preset time threshold, it determines that the image file data has a tampering risk.

9. An image file transmission system, characterized in that: include: An image initiating unit, configured to receive image file data uploaded by a user and calculate a first verification code generated by the encoded image file data; Encoding the image file data and calculating and generating a second check code, verifying the first check code and the second check code, and if the verification is correct, calculating and generating a third check code for the encoded image file data, and sending the encoded image file data and the third check code to the image storage unit; The image storage unit is used to calculate and generate a fourth check code for the encoded image file data, and verify the fourth check code and the third check code. If the verification is correct, the encoded image file data is stored and the storage identification ID of the encoded image file data is sent to the image initiation unit.

10. The system according to claim 9, characterized in that The image initiating unit is further configured to send an image file sending message to the image receiving unit according to the image file sending instruction sent by the user, wherein the image file sending message includes the storage ID of the encoded image file data and the third check code; The image storage unit is further configured to receive the storage ID of the encoded image file data sent by the image receiving unit and send the corresponding encoded image file data and the fourth check code to the image receiving unit; The image file transmission system also includes: The image receiving unit is used to determine whether the received third verification code and the fourth verification code are the same, and if they are the same, confirm that the image file is received successfully.

11. The system according to claim 10, wherein: The image initiating unit is specifically configured to encrypt the storage ID of the encoded image file data and the third verification code using the private key of the digital signature certificate according to the image file sending instruction sent by the user, and then send the encrypted data to the image receiving unit; The image receiving unit is specifically configured to use the public key of the digital signature certificate to verify whether the storage ID of the encoded image file data and the third verification code have been tampered with.

12. The system according to claim 10, wherein: The image receiving unit and the image storage unit perform data transmission via an encrypted data transmission protocol.

13. The system according to any one of claims 9 to 12, characterized in that: The image storage unit is specifically used to set the status of the image file data corresponding to the storage ID to pending review and send a review notification to the user; after receiving the review pass message sent by the user, the status of the image file data corresponding to the storage ID is set to review pass.

14. The system according to claim 13, wherein: The image initiating unit and the image storage unit perform data transmission via an encrypted data transmission protocol.

15. The system according to any one of claims 9 to 12, characterized in that: The image initiating unit is specifically configured to receive image file data uploaded by a user, a first verification code generated by encoding the image file data and a first timestamp of uploading the image file data, and the first timestamp; A second check code is generated for the image file data and the first timestamp code, and it is determined whether the first check code and the second check code are the same.

16. The system according to claim 15, wherein: The image initiating unit is further used to determine whether the time difference between the second timestamp of the image file data uploaded by the user and the first timestamp exceeds a preset time threshold; if the time difference exceeds the preset time threshold, it is determined that the image file data is at risk of tampering.