File encryption transmission device
Through the automated preprocessing, algorithm selection and key management of the file encryption transmission device, the problems of improper key management and unstable data transmission in the existing technology are solved, an efficient and secure file transmission process is achieved, and data integrity and security are ensured.
Patent Information
- Application Number
- CN202510984002.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-09-12
AI Technical Summary
Existing encrypted file transfer devices lack an automated management mechanism for key management, which makes it difficult to distribute, store, and update keys efficiently and securely. Errors and data loss that may occur during file transfer are not fully addressed, and existing monitoring and recovery mechanisms cannot guarantee successful data transmission in complex network environments.
A file encryption transmission device is designed, which includes a file preprocessing module, an algorithm selection module, a key management module, a transmission module, a decryption module and a verification module. Through automated file preprocessing, algorithm selection and key management, combined with security protocols and multiple verification mechanisms, the security and integrity of data during transmission are ensured.
It significantly improves the system's automation, security, and efficiency, and can flexibly adjust encryption and decryption operations according to different file types and encryption requirements, reducing manual intervention, ensuring the security and integrity of data transmission, providing real-time operation feedback, and enhancing the system's operability and transparency.
Smart Images

Figure CN120639458A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of file encryption, and in particular to a file encryption transmission device. Background Art
[0002] With the rapid development of information technology, data security and privacy protection have become significant global concerns. Protecting data confidentiality and integrity is crucial during information transmission, especially on the internet and enterprise networks. Within this broad area, encryption technology is widely used for data protection and security, including encrypted file transfer and encrypted communications. The core purpose of encryption technology is to prevent unauthorized access, tampering, or leakage of data during transmission. Specifically, in the field of encrypted file transfer, the primary focus is on achieving secure file transmission while ensuring data integrity and confidentiality. Consequently, various encrypted transmission devices have emerged, becoming key technologies for safeguarding the security, integrity, and reliability of file transmission.
[0003] While existing encrypted file transfer devices have made some progress in ensuring data security, significant shortcomings and challenges remain. For example, existing devices often have limitations in encryption algorithm selection, key management, and monitoring and error handling during transmission, making file security vulnerable during transmission. Regarding key management, many systems lack automated mechanisms, making it difficult to distribute, store, and update keys efficiently and securely. Furthermore, potential errors and data loss during file transfers have not been fully addressed, and existing monitoring and recovery mechanisms cannot guarantee successful data transmission in complex network environments.
[0004] Therefore, we propose a file encryption transmission device to solve the above-mentioned problems. Summary of the Invention
[0005] The present invention aims to provide a file encryption transmission device to address the aforementioned background art issues: many systems lack automated management mechanisms for key management, making it difficult to efficiently and securely distribute, store, and update keys. Furthermore, errors and data loss that may occur during file transfers have not been adequately addressed, and existing monitoring and recovery mechanisms cannot guarantee successful data transmission in complex network environments.
[0006] To achieve the above-mentioned object, the present invention provides the following technical solutions: a file encryption transmission device, comprising a file preprocessing module, an algorithm selection module, a key management module, a transmission module, a decryption module, a verification module, and a feedback module;
[0007] The file pre-processing module is used to automatically classify and pre-process files according to file type and size to facilitate subsequent encryption processing;
[0008] The algorithm selection module automatically selects a suitable encryption algorithm based on the file type, performance requirements, and security needs;
[0009] The key management module manages the keys used for encryption and decryption operations, including the generation, distribution, storage and update of keys;
[0010] The transmission module is used to transmit the encrypted files and file blocks through a security protocol;
[0011] The decryption module is used to crack the received encrypted file and automatically select the appropriate decryption algorithm according to the file type and encryption method;
[0012] The verification module is used to ensure that the encrypted file has not been tampered with or lost during transmission;
[0013] The feedback module is used to feed back the results of each stage to the visualization terminal.
[0014] Preferably, the file pre-processing module includes a file classification and type identification unit, a file splitting and block processing unit, and a streaming processing and buffering unit;
[0015] The file classification and type identification unit is responsible for identifying and classifying the file type selected by the user, and determining whether it is a small file, a large file, or a streaming media file based on the file's size, format, and purpose;
[0016] The file splitting and block processing unit is used to split a large file into multiple blocks according to a set size and add a mark to each block;
[0017] The streaming processing and buffering unit is used to continuously read and encrypt streaming media data, and to perform buffering and queue management on the encrypted streaming media.
[0018] Preferably, the algorithm selection module includes an encryption algorithm selection unit, a key management and generation unit, and an algorithm and performance evaluation unit;
[0019] The encryption algorithm selection unit is responsible for automatically selecting a suitable encryption algorithm based on the file type, size and other attributes;
[0020] The key management and generation unit is used to generate or manage the key required for encryption using the selected encryption algorithm;
[0021] The encryption algorithm selection unit is used to evaluate the performance of different algorithms in an actual environment based on the resources and encryption requirements of the current system.
[0022] Preferably, the key management module includes a key generation and initialization unit, a key distribution and transmission unit, and a key storage and update unit;
[0023] The key generation and initialization unit is used to generate the required key according to the requirements of the encryption algorithm;
[0024] The key distribution and transmission unit is used to ensure the security of the key during transmission and prevent the key from being leaked or tampered;
[0025] The key storage and update unit is responsible for securely storing keys and managing the life cycle of keys.
[0026] Preferably, the transmission module includes a data encryption and packaging unit, a secure transmission channel management unit, and a transmission monitoring and retry unit;
[0027] The data encryption and packaging unit is used to package the encrypted files;
[0028] The secure transmission channel management unit is used to establish a secure communication channel between the sending end and the receiving end to ensure that data is not intercepted, tampered with or stolen during transmission;
[0029] The transmission monitoring and retry unit is used to monitor the status of data during the transmission process to ensure that the data is successfully transmitted. If a transmission failure or data loss occurs, it can automatically retry or resend.
[0030] Preferably, the decryption module includes a decryption algorithm selection and application unit, a key verification and recovery unit, and an integrity check and repair unit;
[0031] The decryption algorithm selection and application unit is used to select a suitable decryption algorithm for decryption according to the encryption method of the file and the algorithm used during the transmission process;
[0032] The key verification and recovery unit is used to verify the correctness of the received decryption key and ensure that the key used is consistent with the sending end;
[0033] The integrity check and repair unit is used to perform integrity check on the decrypted file to ensure that the file has not been tampered with or damaged during transmission.
[0034] Preferably, the verification module includes an integrity check unit, a digital signature verification unit, and an error detection and recovery unit;
[0035] The integrity checking unit is used to perform integrity checking on the received file;
[0036] The digital signature verification unit is used to verify the digital signature of the file;
[0037] The error detection and recovery unit is used to detect errors that may occur during the transmission process.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] 1. Compared with traditional encryption transmission solutions, this file encryption transmission device significantly improves the system's automation, security and efficiency. Through automated file preprocessing, algorithm selection and key management, the system can flexibly adjust encryption and decryption operations according to different file types and encryption requirements, reducing the complexity of manual intervention while improving encryption and decryption efficiency. The transmission module ensures the security and efficiency of data during transmission through security protocols and block transmission methods. The verification module ensures the integrity of files during transmission through multiple verification mechanisms and error repair functions, avoiding data loss or tampering. The feedback module provides users with real-time operation feedback, enhancing the system's operability and transparency. Compared with existing technologies, this device not only achieves significant improvements in data security, file transmission efficiency and system intelligence, but also better meets the multiple demands for efficiency, security and reliability in the current information transmission process.
[0040] 2. The algorithm selection module significantly improves the intelligence and efficiency of the encrypted transmission system through automated encryption algorithm selection, key management and generation, and algorithm and performance evaluation. Compared to traditional manual settings and static selection methods, the system can automatically adjust encryption policies based on different file types and system resources, ensuring efficient execution of the encryption process and improving its security and reliability. Automatic key generation and management avoids the potential risks caused by improper key management in traditional encryption systems, while algorithm performance evaluation ensures that the system can execute the optimal encryption algorithm even under resource constraints. Through these innovations, the system has achieved significant improvements in encryption efficiency, security, and resource utilization, and can meet the increasingly complex data transmission security needs. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a schematic diagram of the overall three-dimensional structure of the present invention.
[0042] In the figure: 1. File preprocessing module; 11. File classification and type identification unit; 12. File splitting and block processing unit; 13. Streaming and buffering unit; 2. Algorithm selection module; 21. Encryption algorithm selection unit; 22. Key management and generation unit; 23. Algorithm and performance evaluation unit; 3. Key management module; 31. Key generation and initialization unit; 32. Key distribution and transmission unit; 33. Key storage and update unit; 4. Transmission module; 41. Data encryption and packaging unit; 42. Secure transmission channel management unit; 43. Transmission monitoring and retry unit; 5. Decryption module; 51. Decryption algorithm selection and application unit; 52. Key verification and recovery unit; 53. Integrity check and repair unit; 6. Verification module; 61. Integrity check unit; 62. Digital signature verification unit; 63. Error detection and recovery unit; 7. Feedback module. DETAILED DESCRIPTION
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0044] Example 1: Please refer to Figure 1 , a file encryption transmission device, comprising a file preprocessing module 1, an algorithm selection module 2, a key management module 3, a transmission module 4, a decryption module 5, a verification module 6 and a feedback module 7;
[0045] The file pre-processing module 1 is used to automatically classify and pre-process files according to their type and size to facilitate subsequent encryption processing;
[0046] Algorithm selection module 2 automatically selects the appropriate encryption algorithm based on file type, performance requirements and security needs;
[0047] The key management module 3 manages the keys used for encryption and decryption operations, including key generation, distribution, storage and update;
[0048] The transmission module 4 is used to transmit the encrypted files and file blocks through a security protocol;
[0049] The decryption module 5 is used to crack the received encrypted file and automatically select the appropriate decryption algorithm according to the file type and encryption method;
[0050] Verification module 6 is used to ensure that the encrypted file has not been tampered with or lost during transmission;
[0051] The feedback module 7 is used to feed back the results of each stage to the visualization terminal.
[0052] In this embodiment: The file preprocessing module 1 provides the necessary preparations for subsequent encryption operations by automatically identifying and classifying file types and sizes. The module first divides files into different categories such as small files, large files, and streaming media files based on characteristics such as file format, purpose, and size. For large files, the system will split them into predetermined block sizes and assign an independent identifier to each file block for subsequent encryption and transmission. For streaming media files, the module adopts a streaming processing method to ensure that no delays or freezes occur during the encryption process. In addition, the preprocessing module also performs appropriate caching and queue management on the file content to ensure efficient file processing. This processing process makes the encryption operation more efficient and flexible, and can adapt to the encryption requirements of different types of files.
[0053] Algorithm Selection Module 2 automatically selects the most appropriate encryption algorithm based on file type, size, performance requirements, and security needs. This module comprehensively considers file characteristics, transmission performance, and encryption strength, intelligently selecting the appropriate encryption algorithm based on predefined rules to achieve the optimal balance between encryption effectiveness and system performance. Automated algorithm selection eliminates manual intervention and the complexity of selection, improves system flexibility, and ensures that the encryption process meets security requirements while being completed efficiently. This module's design ensures that different file types can be fully protected without sacrificing performance, enhancing the adaptability of the entire encryption system.
[0054] The Key Management Module 3 is responsible for the generation, distribution, storage, and updating of the keys required for encryption and decryption. This module ensures key security, automatically generating keys according to the requirements of the encryption algorithm and transmitting them to the recipient using a secure distribution mechanism to prevent theft or tampering during transmission. Furthermore, the module provides key storage and update functions, effectively managing keys and regularly updating expired keys to prevent security risks caused by key leaks. The Key Management Module provides strong support for the encryption process, ensuring the high security of keys during encryption and decryption operations, thereby improving the overall security of the system.
[0055] The transmission module 4 transmits the encrypted file or file blocks to the recipient through a security protocol, ensuring the confidentiality and integrity of the data during transmission. This module uses security protocols such as SSL / TLS to prevent data from being intercepted, tampered with, or leaked during transmission. During the file transfer process, the module divides the file into small blocks and transmits them block by block, reducing the network burden caused by excessively large files and improving the efficiency and fault tolerance of file transfer. For possible interruptions during network transmission, the transmission module provides an automatic retry mechanism to ensure that the data can be successfully transmitted to the recipient. The design of the transmission module makes the entire transmission process both efficient and secure, effectively avoiding the risk of data loss and tampering.
[0056] The decryption module 5 decrypts encrypted files at the receiving end, automatically selecting the most appropriate decryption method based on the file type and encryption algorithm. This module ensures that encrypted files can be successfully restored to their original form and automatically adapts to changes in encryption methods. By verifying the correctness of the key, the decryption module ensures key consistency during the decryption process, preventing file decryption failures due to key errors. Furthermore, the decryption module verifies the file's integrity to ensure it has not been tampered with or damaged during transmission. This module enables the recipient to accurately restore the file's contents while ensuring the security and integrity of the file during the decryption process.
[0057] Verification module 6 ensures that encrypted files have not been tampered with or lost during transmission, guaranteeing their integrity and authenticity. This module performs data verification through multiple mechanisms, including integrity checking, digital signature verification, and error detection. First, the module calculates and verifies the file's hash value to ensure that the file has not been altered during transmission. Second, digital signature verification ensures the legitimacy of the file's source. If data is lost or corrupted during transmission, the module uses error detection and recovery mechanisms to perform real-time repairs, safeguarding the integrity of the file at the receiving end. The design of the verification module effectively prevents file tampering and transmission errors, enhancing system reliability and security.
[0058] Feedback Module 7 is responsible for real-time monitoring and providing feedback on the execution status of each stage, visually presenting the results of the file encryption and transmission process to the user. This module uses a graphical interface to display the status and progress of each processing step, allowing users to intuitively understand the file processing status and transmission process. Through the feedback module, users can immediately identify and resolve potential system issues, optimize the file processing process, and improve operational convenience and system transparency. Furthermore, the feedback module provides real-time alarms, notifying users in the event of transmission errors or encryption failures to take necessary corrective measures.
[0059] Compared with traditional encryption transmission solutions, this file encryption transmission device significantly improves the system's automation, security, and efficiency. Through automated file preprocessing, algorithm selection, and key management, the system can flexibly adjust encryption and decryption operations according to different file types and encryption requirements, reducing the complexity of manual intervention while improving encryption and decryption efficiency. The transmission module ensures the security and efficiency of data during transmission through security protocols and block transmission methods. The verification module ensures the integrity of files during transmission through multiple verification mechanisms and error repair functions, avoiding the problem of data loss or tampering. The feedback module provides users with real-time operational feedback, enhancing the operability and transparency of the system. Compared with existing technologies, this device has not only achieved significant improvements in data security, file transmission efficiency, and system intelligence, but also better meets the multiple demands for efficiency, security, and reliability in the current information transmission process.
[0060] Example 2: Please refer to Figure 1 , the file pre-processing module 1 includes a file classification and type identification unit 11, a file splitting and block processing unit 12 and a streaming processing and buffering unit 13;
[0061] The file classification and type identification unit 11 is responsible for identifying and classifying the file type selected by the user, and determining whether it is a small file, a large file, or a streaming media file based on the file size, format, and purpose;
[0062] The file splitting and block processing unit 12 is used to split a large file into multiple blocks according to a set size and add a mark to each block;
[0063] The streaming processing and buffering unit 13 is used to continuously read the streaming media data and perform encryption, and perform buffering and queue management on the encrypted streaming media.
[0064] In this embodiment, the file classification and type identification unit 11 first analyzes the file selected by the user and automatically identifies the file's size, format, and purpose. Based on this information, the system determines whether the file is a small file, a large file, or a streaming media file, and assigns different processing flows to each file. For example, if a file is identified as a large file, the system will split it into multiple smaller blocks for encryption and transmission to avoid performance bottlenecks caused by large files during the encryption process. If the file is a streaming media file, the system will adopt a streaming processing method to ensure that the data can be transmitted continuously and in real time during the encryption process. Through this automatic classification and identification, the system not only improves the efficiency of the encryption process, but also avoids the tedious process of manual setup, significantly simplifying user operations.
[0065] The file splitting and chunking unit 12 is responsible for dividing large files into multiple chunks of predetermined size and assigning unique identifiers to each chunk. This process crucially breaks down complex, large files into smaller, independently encrypted and transmitted parts, avoiding computational bottlenecks that can arise with traditional encryption methods when dealing with large files. For example, with traditional methods, encryption of large files often slows due to the sheer volume of data or consumes excessive memory and computing resources. Chunking, however, accelerates the entire encryption process by parallelizing operations.
[0066] During the file segmentation process, each block is assigned a unique identifier, allowing these blocks to be accurately restored in sequence during decryption, ensuring that the decrypted file is completely consistent with the original. Segmentation also allows for effective load balancing of large files during transmission. Even if network bandwidth is limited, file blocks can be transferred incrementally, avoiding stalls or interruptions associated with the transfer of a single large file. Furthermore, because files are segmented, each block can undergo separate error detection and retries, significantly improving the stability and fault tolerance of data transmission.
[0067] The streaming processing and buffering unit 13 is optimized for the special needs of streaming media files. It can encrypt the file data in real time during transmission and ensure the smooth transmission of the encrypted data. Unlike ordinary static files, streaming media files must ensure real-time and continuous data transmission. Any delays or pauses during transmission will affect the user's viewing experience. Therefore, encryption operations must not affect the transmission efficiency of streaming media.
[0068] Streaming media is encrypted using a streaming approach, meaning encryption occurs as data is transmitted, rather than all at once as with traditional files. Buffering and queue management mechanisms within the encryption process ensure real-time encryption, preventing playback or transmission bottlenecks. Once encrypted, streaming media data is immediately sent to the receiving end for decryption, eliminating any potential delays during the encryption process that could impact streaming playback. This real-time encryption ensures data security without compromising performance, maintaining smooth encrypted transmission even in unstable network environments.
[0069] The automated classification, block processing, and streaming media encryption technologies employed by File Preprocessing Module 1 significantly enhance the flexibility, efficiency, and reliability of encrypted file transmission. Traditional encrypted transmission processes often encounter issues such as slow encryption, transmission lag, and difficulty recovering large or streaming media files. This module's automated classification and file splitting technology allows the system to select the most appropriate processing method for each file type, making file encryption and transmission more efficient. Furthermore, the real-time encryption of streaming media files avoids the inability of traditional encryption methods to meet real-time requirements.
[0070] Example 3: Please refer to Figure 1 , the algorithm selection module 2 includes an encryption algorithm selection unit 21, a key management and generation unit 22, and an algorithm and performance evaluation unit 23;
[0071] The encryption algorithm selection unit 21 is used to automatically select the appropriate encryption algorithm based on the file type, size and other attributes;
[0072] The key management and generation unit 22 is used to generate or manage the keys required for encryption using the selected encryption algorithm;
[0073] The encryption algorithm selection unit 21 is used to evaluate the performance of different algorithms in an actual environment based on the resources and encryption requirements of the current system.
[0074] In this embodiment, the encryption algorithm selection unit 21 automatically selects an appropriate encryption algorithm based on file type, size, and other attributes, thereby solving the problem of inflexible algorithm selection in traditional encryption systems. In traditional encryption systems, users typically need to manually select an encryption algorithm, a cumbersome process that may not select the optimal algorithm due to the characteristics of different file types, resulting in low efficiency or insufficient security. The module's automated encryption algorithm selection function intelligently determines the appropriate encryption algorithm based on the characteristics of the file to achieve the most efficient encryption effect and system performance. Automated encryption algorithm selection reduces human intervention, simplifies the operational process, and ensures that the system can achieve optimal encryption processing when processing different types of files. The system can dynamically adjust encryption strategies based on specific file characteristics, thereby improving encryption efficiency and ensuring data security. This intelligent, automated encryption algorithm selection method not only improves the flexibility of the encryption process, but also makes it more efficient and adaptable, avoiding performance bottlenecks caused by inappropriate encryption algorithms.
[0075] The key management and generation unit 22 is responsible for generating and managing the keys required for encryption based on the selected encryption algorithm. The key is a crucial part of the encryption process. Key management in traditional encryption systems often has some security risks. For example, the generation, storage and transmission of the key may not be secure enough and may be vulnerable to attacks. This module automatically generates keys that match the encryption algorithm through close cooperation with the encryption algorithm and provides a secure management mechanism for encryption keys. The generation, storage and update of keys can all be completed within the system, avoiding security vulnerabilities that may be caused by manual configuration. This improvement greatly improves the security and convenience of key management, and avoids data leakage and tampering problems that may be caused by improper key management in traditional systems. By automatically generating and managing keys, the system can ensure the continued security of the encryption process, avoid encryption failures caused by key leakage or expiration, and make key management more efficient and secure.
[0076] The algorithm and performance evaluation unit 23 evaluates the performance of different encryption algorithms in real-world environments based on the current system's resources and encryption requirements. This design addresses the mismatch between algorithm performance and resource consumption in traditional encryption systems. In some cases, even if an encryption algorithm offers high security, using it in scenarios with limited resources or high performance requirements can lead to inefficient encryption processes and even affect the normal operation of the system. Through the algorithm and performance evaluation unit, the system can dynamically evaluate the performance of different algorithms in the current hardware environment and select the optimal algorithm based on system resources, file size, and encryption requirements. The introduction of this evaluation mechanism ensures that the encryption algorithm selection not only considers security but is also optimized based on the actual system environment, maximizing encryption processing efficiency while ensuring security. The system can automatically determine the most suitable encryption algorithm, avoiding performance bottlenecks caused by algorithm mismatch in traditional systems, improving the efficiency of the encryption process and the utilization of system resources.
[0077] Algorithm Selection Module 2 significantly enhances the intelligence and efficiency of the encrypted transmission system through automated encryption algorithm selection, key management and generation, and algorithm and performance evaluation. Compared to traditional manual settings and static selection methods, the system can automatically adjust encryption strategies based on different file types and system resources, ensuring efficient execution of the encryption process and improving its security and reliability. Automatic key generation and management avoids the potential risks caused by improper key management in traditional encryption systems, while algorithm performance evaluation ensures that the system can execute the optimal encryption algorithm even under resource constraints. Through these innovations, the system has achieved significant improvements in encryption efficiency, security, and resource utilization, meeting the increasingly complex data transmission security needs.
[0078] Example 4: Please refer to Figure 1 , the key management module 3 includes a key generation and initialization unit 31, a key distribution and transmission unit 32 and a key storage and update unit 33;
[0079] The key generation and initialization unit 31 is used to generate the required key according to the requirements of the encryption algorithm;
[0080] The key distribution and transmission unit 32 is used to ensure the security of the key during transmission and prevent the key from being leaked or tampered;
[0081] The key storage and update unit 33 is responsible for securely storing keys and managing the life cycle of the keys.
[0082] In this embodiment: the key generation and initialization unit 31 is responsible for generating the required keys according to the requirements of the selected encryption algorithm. In traditional encryption systems, key generation is usually a separate and complex process, which requires manual configuration or the generation of keys through external tools. This not only increases the complexity of operation, but may also cause key security issues due to human errors. Through the automated key generation and initialization process, the unit ensures that the generation of keys meets the specific requirements of the current encryption algorithm and can efficiently provide the system with the required encryption keys. The application of the generated keys in the entire encryption process will be more accurate and secure, avoiding the problem of generating mismatched or unsafe keys in traditional methods. Automated key generation and initialization can greatly simplify the operating process and improve the security and accuracy of the system. Ensuring a high degree of match between the key and the encryption algorithm avoids security vulnerabilities caused by manual generation or configuration errors, and ensures the security of the entire encryption system from the source.
[0083] The key distribution and transmission unit 32 is responsible for ensuring the security of keys during transmission and preventing them from being leaked or tampered with. In traditional encryption systems, key transmission is often carried out through insecure channels, which are vulnerable to hacker attacks and man-in-the-middle attacks, resulting in key leakage and thus undermining the security of the entire encryption transmission process. This unit uses an encrypted transmission protocol to ensure the security of keys during network transmission, ensuring the integrity and confidentiality of the keys and avoiding the risk of theft or tampering during transmission. The secure key distribution and transmission mechanism greatly improves the confidentiality of the keys and avoids the risk of keys being intercepted or tampered with during transmission. By transmitting keys through strongly encrypted communication channels, the system ensures data security and encryption effectiveness, further enhancing the system's resistance to external attacks.
[0084] The key storage and update unit 33 is responsible for securely storing encryption keys and managing the key lifecycle. In traditional key management systems, key storage often lacks adequate protection measures and may be illegally accessed or leaked due to improper storage. In addition, as the key is used for a longer period of time, its security may gradually decrease, causing the encryption system to face potential risks. This unit uses high-security storage technology to encrypt and store keys, and can regularly update and replace keys to ensure that the key lifecycle management meets the highest security standards. The secure storage and dynamic update mechanism effectively protects the keys from the threat of leakage and tampering. Regular key updates can ensure the encryption security of the system, not only reducing the risk of key leakage, but also preventing security risks after the key expires. Through comprehensive lifecycle management, the system can more effectively maintain the integrity and security of the key, thereby ensuring the continued security of the encryption process.
[0085] Key Management Module 3 provides full lifecycle protection for encryption keys by managing the entire process of key generation, distribution, storage, and updates. Compared to traditional systems, the design of this module significantly improves key security and management efficiency. During key generation, an automated process aligns with the requirements of the encryption algorithm, ensuring key security and accuracy. During key transmission, an encryption protocol is employed to protect key transmission and avoid security vulnerabilities in intermediate links. Furthermore, secure storage and regular key updates further enhance the system's resilience to attacks, preventing security issues caused by key leakage or expiration.
[0086] Example 5: Please refer to Figure 1 , the transmission module 4 includes a data encryption and packaging unit 41, a secure transmission channel management unit 42 and a transmission monitoring and retry unit 43;
[0087] The data encryption and packaging unit 41 is used to package the encrypted files;
[0088] The secure transmission channel management unit 42 is used to establish a secure communication channel between the sending end and the receiving end to ensure that the data is not intercepted, tampered with or stolen during the transmission process;
[0089] The transmission monitoring and retry unit 43 is used to monitor the status of data during the transmission process to ensure that the data is successfully transmitted. If a transmission failure or data loss occurs, it can automatically retry or resend.
[0090] In this embodiment: the data encryption and packaging unit 41 is responsible for packaging the encrypted files to ensure that the files are fully protected during the transmission process. Traditional file transmission systems often do not have special encryption packaging processing, which may cause the encrypted data to be destroyed or leaked during the transmission process. Through the encryption and packaging function, the system can package the encrypted files and transmit them in a standardized format to ensure that the file content maintains integrity during the transmission process and avoid unauthorized access. The packaging of each encrypted file block can also include necessary metadata to ensure that the file can be unpacked and decrypted in the correct order at the receiving end. Through encryption and packaging processing, the system can ensure that the encrypted files are not tampered with or lost during the transmission process, and can effectively manage the order and structure of the files to ensure that the receiving end can correctly decrypt and restore the files. In addition, this design enhances the transmission flexibility of the system, enabling it to better adapt to various network environments and transmission requirements.
[0091] The secure transmission channel management unit 42 ensures the security of data during transmission by establishing a secure communication channel to prevent data from being intercepted, tampered with or stolen. This unit usually uses strong encryption protocols such as SSL / TLS to encrypt the communication channel, and provides identity authentication and data integrity verification to ensure that the identities of both parties to the transmission are legal and that the transmitted content has not been tampered with. Unlike traditional transmission protocols, this module can dynamically establish a dedicated secure channel for each file transfer, avoiding security risks such as man-in-the-middle attacks and replay attacks that may be encountered in public network environments. This function greatly improves the confidentiality and integrity of data during network transmission. Through a secure communication channel, the system can effectively prevent data from being subjected to network attacks and unauthorized access during transmission, ensuring that encrypted files can only be read and decrypted by legitimate recipients, thereby enhancing security during data transmission.
[0092] The transmission monitoring and retry unit 43 is responsible for monitoring the status of the file in real time during the data transmission process, and automatically retrying or resending the data in the event of transmission failure or data loss. Traditional file transfer systems may cause file transmission to be interrupted or lost due to network fluctuations or other unforeseen factors. In this case, the user often needs to intervene manually to resend the file. Through the transmission monitoring and retry mechanism, the system can automatically detect transmission failures and start the retry program to ensure that the file can be transmitted to the receiving end completely and reliably. The automatic retry mechanism improves the fault tolerance of the system and reduces the need for manual intervention after file transmission failures. Even in complex network environments, the system can ensure the successful transmission of data through real-time monitoring and intelligent retry, thereby improving the reliability and stability of file transmission.
[0093] Transmission Module 4 significantly improves the security, reliability, and efficiency of encrypted file transfers through data encryption and packaging, secure transmission channel management, and a transmission monitoring and retry mechanism. Compared to traditional file transfer systems, this module provides stronger security. By encrypting and packaging files, establishing a dedicated secure communication channel, and implementing an automatic reset mechanism, it effectively prevents security risks and transmission failures that may occur during file transfer. Encryption and packaging ensure the integrity and order of file content, secure transmission channel management strengthens data confidentiality during transmission, and transmission monitoring and retry mechanisms improve the system's fault tolerance and stability.
[0094] Example 6: Please refer to Figure 1 , the decryption module 5 includes a decryption algorithm selection and application unit 51, a key verification and recovery unit 52, and an integrity check and repair unit 53;
[0095] The decryption algorithm selection and application unit 51 is used to select a suitable decryption algorithm for decryption according to the encryption method of the file and the algorithm used during the transmission process;
[0096] The key verification and recovery unit 52 is used to verify the correctness of the received decryption key and ensure that the key used is consistent with the sending end;
[0097] The integrity check and repair unit 53 is used to perform integrity check on the decrypted file to ensure that the file has not been tampered with or damaged during transmission.
[0098] In this embodiment: the decryption algorithm selection and application unit 51 automatically selects a suitable decryption algorithm for decryption based on the encryption method of the file and the encryption algorithm used during the transmission process. This design solves the problem of lack of flexibility in traditional decryption methods. In traditional systems, decryption operations usually rely on fixed algorithms, which requires manual adjustment of the decryption strategy when facing files with different encryption methods, increasing complexity and the possibility of errors. By automatically selecting a suitable decryption algorithm, the unit can intelligently select a decryption algorithm based on the encryption method of the file to ensure that the decryption process is efficient and accurate. In this way, the decryption operation process is greatly simplified, the need for manual intervention is avoided, and the system can process files with different encryption algorithms. Automatic selection of decryption algorithms not only improves decryption efficiency, but also ensures that files with different encryption methods can be correctly restored, reduces the risk of decryption failure due to improper algorithm selection, and thus improves the flexibility and adaptability of the system.
[0099] The key verification and recovery unit 52 is responsible for verifying the correctness of the received decryption key, ensuring that the key used is consistent with the sending end. This unit verifies the key at the receiving end, preventing decryption failures due to key errors or tampering. In traditional encrypted transmission systems, key verification is typically performed during the system's initial configuration phase. If problems arise during the subsequent key transmission process, the decryption process is prone to security vulnerabilities. However, this module uses a key verification mechanism to ensure that only valid and correct keys are used for decryption operations, effectively preventing the risks associated with incorrect key transmission or tampering. The key verification and recovery mechanism significantly improves system security, ensuring that decryption operations are always performed based on the correct key. This mechanism prevents hackers from obtaining or tampering with keys through methods such as man-in-the-middle attacks, ensuring the reliability and consistency of the data decryption process. Through this module, the system can verify the legitimacy of the key, effectively avoiding decryption errors caused by inconsistent keys, and enhancing the security of data transmission.
[0100] The integrity check and repair unit 53 is responsible for performing an integrity check on the file after decryption to ensure that the file has not been tampered with or damaged during transmission. Traditional file transfer systems typically focus only on file encryption and decryption, ignoring the potential data loss or corruption that may occur during transmission. Through integrity checking, the system can verify whether the file has been tampered with. If the file content is inconsistent with the original file, the unit can also perform repair processing to ensure that the file content obtained by the receiving end is exactly the same as the sending end. The integrity check and repair mechanism enhances the system's anti-tampering capabilities during transmission. By verifying the file's hash value or other integrity identifier, the system can ensure that the received file has not been tampered with or damaged. Even if a file encounters a problem during transmission, this mechanism can promptly detect and repair it, ensuring that the final transmitted file is complete and correct. This not only improves the reliability of file transmission, but also greatly enhances data security.
[0101] The design of Decryption Module 5 significantly enhances the intelligence and security of the file decryption process through automated decryption algorithm selection, key verification and recovery, and integrity checking and repair. Compared to traditional decryption systems, this module's automated decryption algorithm selection mechanism ensures the system intelligently selects a decryption strategy based on the actual encrypted file, avoiding human error or inappropriate algorithm selection. The key verification and recovery mechanism ensures the correctness and consistency of the key during the decryption process, mitigating potential risks in key transmission and ensuring the security of the decryption operation. The integrity checking and repair function further ensures the integrity of the transmitted file, preventing tampering or loss during transmission.
[0102] Example 6: Please refer to Figure 1 , the verification module 6 includes an integrity check unit 61, a digital signature verification unit 62 and an error detection and recovery unit 63;
[0103] The integrity check unit 61 is used to perform integrity check on the received file;
[0104] The digital signature verification unit 62 is used to verify the digital signature of the document;
[0105] The error detection and recovery unit 63 is used to detect errors that may occur during the transmission process.
[0106] In this embodiment: the integrity check unit 61 is responsible for performing integrity checks on the received files to ensure that the files have not been tampered with or damaged during the transmission process. During the encrypted transmission process, traditional file transmission systems may not be able to effectively detect file damage or tampering during transmission, which may cause the data received by the receiving end to be inconsistent with the original data on the sending end, thereby affecting the security and validity of the data. Through integrity verification, the system can verify the hash value of the file to ensure the consistency and integrity of the file during the transmission process. The integrity verification mechanism ensures that the received file has not been tampered with or damaged. If any changes occur to the file during the transmission process, the system can identify and reject the file before decryption, thereby avoiding potential risks in the transmission. This improvement greatly enhances the reliability of the file transmission process and the security of the data, ensuring the accuracy of the file throughout the transmission process.
[0107] The digital signature verification unit 62 is responsible for verifying the digital signature of a file, ensuring the legitimacy of the file's source and that the file has not been tampered with. A digital signature is an identifier generated after encrypting the file's contents. The receiving end can verify the signature to confirm whether the file was sent by the legitimate sender and whether the file's contents were protected during transmission. Traditional systems may rely solely on encryption and ignore the verification of the file's identity. Digital signature verification provides an additional security measure to prevent malicious tampering and forgery. Through digital signature verification, the system can ensure the authenticity of the file and the credibility of its source. Even if the file is transmitted through encryption, the recipient can confirm that the file has not been tampered with or forged by verifying the digital signature, which increases the security of the file transmission process. Especially when processing sensitive information, digital signature verification can effectively prevent unauthorized modification or forgery, providing a reliable identity authentication mechanism and improving the system's anti-counterfeiting capabilities.
[0108] The error detection and recovery unit 63 is used to detect errors that may occur during the transmission process and provide the necessary repair mechanisms. During the file transmission process, files may be damaged due to network instability, data loss, or other problems. In traditional systems, manual intervention may be required to resend files or handle errors. Through the error detection and recovery mechanism, the system can automatically identify errors that occur during transmission and take measures to recover data, avoiding file damage or loss due to network interruptions or other problems. The error detection and recovery function improves the system's fault tolerance. Even if errors or file loss occur during transmission, the system can automatically detect and initiate a recovery program without manual intervention, greatly improving the reliability of file transmission. Through this mechanism, the system can ensure the integrity of files during transmission and can handle common network transmission problems, improving the stability of data transmission and user experience.
[0109] Verification Module 6 significantly enhances the security, reliability, and integrity of file transfers through integrity checking, digital signature verification, and error detection and recovery mechanisms. Compared to traditional transmission systems, this module provides multiple layers of security, ensuring that received files have not been tampered with and confirming the legitimacy and authenticity of the source. Integrity checking and digital signature verification ensure the consistency and reliability of file content during transmission, while error detection and recovery mechanisms enhance the system's fault tolerance in the event of network instability or file transfer interruptions, automatically correcting transmission errors.
[0110] The contents not described in detail in this specification belong to the prior art known to those skilled in the art.
[0111] Although the present invention has been described in detail with reference to the aforementioned embodiments, it is still possible for those skilled in the art to modify the technical solutions described in the aforementioned embodiments, or to make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A file encryption transmission device, characterized by: It includes a file pre-processing module (1), an algorithm selection module (2), a key management module (3), a transmission module (4), a decryption module (5), a verification module (6) and a feedback module (7); The file pre-processing module (1) is used to automatically classify and pre-process files according to file type and size to facilitate subsequent encryption processing; The algorithm selection module (2) automatically selects a suitable encryption algorithm based on the file type, performance requirements and security requirements; The key management module (3) manages the keys used for encryption and decryption operations, including the generation, distribution, storage and update of the keys; The transmission module (4) is used to transmit the encrypted files and file blocks through a security protocol; The decryption module (5) is used to decrypt the received encrypted file and automatically select a suitable decryption algorithm according to the file type and encryption method; The verification module (6) is used to ensure that the encrypted file has not been tampered with or lost during transmission; The feedback module (7) is used to feed back the results of each stage to the visualization terminal.
2. The file encryption transmission device according to claim 1, characterized in that: The file pre-processing module (1) includes a file classification and type identification unit (11), a file splitting and block processing unit (12), and a stream processing and buffering unit (13); The file classification and type identification unit (11) is responsible for identifying and classifying the file type selected by the user, and judging whether it is a small file, a large file, or a streaming media file based on the size, format, and purpose of the file; The file splitting and block processing unit (12) is used to split a large file into multiple blocks according to a set size and add a mark to each block; The streaming processing and buffering unit (13) is used for continuously reading streaming media data and encrypting it, and performing buffering and queue management on the encrypted streaming media.
3. The file encryption transmission device according to claim 2, characterized in that: The algorithm selection module (2) includes an encryption algorithm selection unit (21), a key management and generation unit (22), and an algorithm and performance evaluation unit (23); The encryption algorithm selection unit (21) is responsible for automatically selecting a suitable encryption algorithm based on the file type, size and other attributes; The key management and generation unit (22) is used to generate or manage the key required for encryption using the selected encryption algorithm; The encryption algorithm selection unit (21) is used to evaluate the performance of different algorithms in an actual environment according to the resources and encryption requirements of the current system.
4. The file encryption transmission device according to claim 3, characterized in that: The key management module (3) includes a key generation and initialization unit (31), a key distribution and transmission unit (32), and a key storage and update unit (33); The key generation and initialization unit (31) is used to generate the required key according to the requirements of the encryption algorithm; The key distribution and transmission unit (32) is used to ensure the security of the key during transmission and prevent the key from being leaked or tampered with; The key storage and update unit (33) is responsible for securely storing keys and managing the life cycle of keys.
5. The file encryption transmission device according to claim 4, characterized in that: The transmission module (4) includes a data encryption and packaging unit (41), a secure transmission channel management unit (42), and a transmission monitoring and retry unit (43); The data encryption and packaging unit (41) is used to package the encrypted files; The secure transmission channel management unit (42) is used to establish a secure communication channel between the sending end and the receiving end to ensure that data is not intercepted, tampered with or stolen during the transmission process; The transmission monitoring and retry unit (43) is used to monitor the status of data during the transmission process to ensure successful data transmission. If transmission failure or data loss occurs, it can automatically retry or resend.
6. The file encryption transmission device according to claim 5, characterized in that: The decryption module (5) includes a decryption algorithm selection and application unit (51), a key verification and recovery unit (52), and an integrity check and repair unit (53); The decryption algorithm selection and application unit (51) is used to select a suitable decryption algorithm for decryption according to the encryption method of the file and the algorithm used during the transmission process; The key verification and recovery unit (52) is used to verify the correctness of the received decryption key and ensure that the key used is consistent with the sending end; The integrity check and repair unit (53) is used to perform integrity check on the decrypted file to ensure that the file has not been tampered with or damaged during transmission.
7. The file encryption transmission device according to claim 6, characterized in that: The verification module (6) includes an integrity check unit (61), a digital signature verification unit (62), and an error detection and recovery unit (63); The integrity check unit (61) is used to perform integrity check on the received file; The digital signature verification unit (62) is used to verify the digital signature of the file; The error detection and recovery unit (63) is used to detect errors that may occur during the transmission process.
Citation Information
Patent Citations
Communication content security encryption method
CN119071074A
Encryption method and system compatible with multiple encryption algorithms
CN119109682A
Cloud storage encryption integrated management system and encryption and decryption method thereof
CN119227155A
Data security management system and method in smart power grid
CN119598484A
Distributed data security protection system based on Internet of Things nodes
CN119766556A