Distributed data security protection method based on dynamic authority management
Through a distributed data security protection method based on dynamic rights management, the user access security problem is solved, user identity authentication and data security access are guaranteed, and the security of user data and download security are ensured.
Patent Information
- Application Number
- CN202510850669.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-19
AI Technical Summary
With the emergence of new distributed systems such as cloud computing and the Internet of Things, user access security issues are becoming increasingly serious, and existing technologies are difficult to effectively guarantee the security of user data and access security.
A distributed data security protection method based on dynamic permission management is adopted to ensure user identity authentication and data security through steps such as client identity authentication, account and password processing, and encrypted download of the file platform management system.
It achieves the security of user information and secure access to data, ensuring that users can securely enter the file platform management system with the correct account and password and download safely.
Smart Images

Figure CN120675775A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer security processing, and in particular to a distributed data security protection method based on dynamic authority management. Background Art
[0002] With the rapid development of information technology and the increasing use of internet technology in daily life and businesses, information security in network environments is receiving increasing attention. However, with the emergence of new distributed systems such as cloud computing and the Internet of Things, data is growing rapidly and the number of users is also increasing. This has led to an increasing demand for user access security in various systems, necessitating a system that can safeguard user security. Summary of the Invention
[0003] The present invention aims to at least solve the technical problems existing in the prior art, and in particular innovatively proposes a distributed data security protection method based on dynamic rights management.
[0004] In order to achieve the above-mentioned object of the present invention, the present invention provides a distributed data security protection method based on dynamic rights management, comprising the following steps:
[0005] S1, the client obtains identity information authentication, the identity information includes the client IP information and / or the client location information;
[0006] S2, obtain the correct account and password, process the correct account and password on the client, and then enter the file platform management system;
[0007] S3, obtaining the correct account number and password, processing the correct account number and password through the file platform management system, and then entering the file platform management system;
[0008] S4, securely download the file data.
[0009] In a preferred embodiment of the present invention, step S1 includes:
[0010] Determine the connection method:
[0011] If it is a WiFi connection, execute step S11;
[0012] If it is other connection, execute step S12;
[0013] S11: If the identity information obtained by the client is IP information, determine the relationship between the IP information and the IP information set:
[0014] If ip client ∈IPυ={IP1,IP2,IP3,…,IP υ}, ipclient is the IP information obtained by the client, IPυ is the IP information set that the client has successfully logged in v times; v is a positive integer greater than or equal to 3; IP1 is the first IP information in the IP information set IPυ, IP2 is the second IP information in the IP information set IPυ, IP3 is the third IP information in the IP information set IPυ, and IP υ is the υ-th IP information in the IP information set IPυ, υ is the number of IP information in the IP information set IPυ; then execute step S3;
[0015] like ip client is the IP information obtained by the client, IPυ is the IP information set that the client has successfully logged in v times; v is a positive integer greater than or equal to 3; IP1 is the first IP information in the IP information set IPυ, IP2 is the second IP information in the IP information set IPυ, IP3 is the third IP information in the IP information set IPυ, and IP υ is the υth IP information in the IP information set IPυ, υ is the number of IP information in the IP information set IPυ; then execute step S2;
[0016] S12: If the identity information obtained by the client is location information, determine the relationship between the location information and the location information set:
[0017] If GPS client ∈GPSμ={GPS1, GPS2, GPS3,…,GPS μ}, GPS client is the positioning information obtained by the client, GPSμ is the positioning information set that the client has successfully logged in l times; l is a positive integer greater than or equal to 5; GPS1 is the first GPS information in the positioning information set GPSμ, GPS2 is the second GPS information in the positioning information set GPSμ, GPS3 is the third GPS information in the positioning information set GPSμ, GPS μ is the μth GPS information in the positioning information set GPSμ, μ is the number of positioning information in the positioning information set GPSμ; then execute step S3;
[0018] like GPS client is the positioning information obtained by the client, GPSμ is the positioning information set that the client has successfully logged in l times; l is a positive integer greater than or equal to 5; GPS1 is the first GPS information in the positioning information set GPSμ, GPS2 is the second GPS information in the positioning information set GPSμ, GPS3 is the third GPS information in the positioning information set GPSμ, GPS μ is the μth GPS information in the positioning information set GPSμ, μ is the number of positioning information in the positioning information set GPSμ; then execute step S3.
[0019] In a preferred embodiment of the present invention, the method for entering the file platform management system after the correct account and password are input and processed by the platform in step S2 includes the following steps:
[0020] S21, obtaining the input account and password, and the client processes the obtained account and password to obtain a fourth binary account and password;
[0021] S22, sending the binary fourth account number and password to the file platform management system;
[0022] S23, determine whether the received binary fourth account number and password exist in the file platform management system:
[0023] If the received binary fourth account and password exist in the file platform management system, it means that the correct account and password have been entered to enter the file platform management system;
[0024] If the received binary fourth account number and password do not exist in the file platform management system, it means that the account number and password are entered incorrectly and the file platform management system cannot be entered.
[0025] In a preferred embodiment of the present invention, the method of processing the acquired account number and password in step S21 to obtain the binary fourth account number and password is:
[0026] S211, after obtaining the input account and password, convert the account and password into a binary account and password; the binary account and password include a binary account and a binary password;
[0027] S212, after converting the account and password into a binary account and password, convert the binary account and password into a binary first account and password respectively; the binary first account and password include a binary first account and a binary first password;
[0028] S213, after converting the binary account and password into a first binary account and password respectively, converting the first binary account and password into a second account and password; the second account and password include a second account and a second password;
[0029] S214, after converting the binary first account and password into a second account and password, converting the second account and password into a binary third account and password; the binary third account and password includes a binary third account and a binary third password;
[0030] S215 , after converting the second account and password into a binary third account and password, convert the binary third account and password into a binary fourth account and password; the binary fourth account and password include a binary fourth account and a binary fourth password.
[0031] In a preferred embodiment of the present invention, the method for entering the file platform management system after the correct account and password are processed by the file platform management system in step S3 includes the following steps:
[0032] S31, obtaining the input account and password, and sending the obtained account and password to the file platform management system, which processes the received account and password to obtain a fourth binary account and password;
[0033] S32, determining whether the calculated binary fourth account number and password exist in the file platform management system:
[0034] If the calculated binary fourth account and password exist in the file platform management system, it means that the correct account and password are entered to enter the file platform management system;
[0035] If the calculated binary fourth account number and password do not exist in the file platform management system, it means that an incorrect account number and password are entered and the file platform management system cannot be entered.
[0036] In a preferred embodiment of the present invention, in step S4, the method for securely downloading file data comprises the following steps:
[0037] S41, the file platform management system encrypts the selected file using the key to obtain an encrypted file;
[0038] S42, sending the encrypted file to the client. After receiving the encrypted file, the client uses the same key as in step S41 to decrypt it to obtain a decrypted file.
[0039] In a preferred embodiment of the present invention, the key in step S41 is obtained in the same manner as in step S42 as in step S41:
[0040] S411: The client generates and stores a pair of public and private keys.
[0041] S412: Send the public key to the file platform management system. After sending the public key to the file platform management system, the client clears the public key stored on the client. After receiving the public key, the file platform management system generates a secret key and stores it. The secret key is encrypted using the public key to obtain a secure key.
[0042] S413: Send the security key to the client. After receiving the security key, the client uses the private key to decrypt the security key, obtains the decrypted key, and stores it.
[0043] In a preferred embodiment of the present invention, the key in step S41 is obtained in the same manner as in step S42 as in step S41:
[0044] S411, the file platform management system generates and stores a pair of public and private keys;
[0045] S412: The public key is sent to the client. After the public key is sent to the client, the file platform management system clears the public key stored on the client. After the client receives the public key, it generates and stores a secret key, and encrypts the secret key using the public key to obtain a secure key.
[0046] S413, sending the security key to the file platform management system. After receiving the security key, the file platform management system decrypts the security key using the private key, obtains the decryption key, and stores it.
[0047] The present invention also discloses a computer system, comprising:
[0048] processor;
[0049] a memory for storing processor-executable instructions;
[0050] Wherein, the processor is configured to implement the distributed data security protection method based on dynamic rights management when executing the executable instructions.
[0051] The present invention also discloses a computer-readable storage medium, comprising:
[0052] a memory having a computer program stored thereon;
[0053] A processor is used to execute the program in the memory to implement the distributed data security protection method based on dynamic rights management.
[0054] In summary, due to the adoption of the above technical solution, the present invention can securely enter the file platform management system through the correct account and password, ensure the data security of system user information, and can securely download the required file data, ensuring secure access to user data.
[0055] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments with reference to the accompanying drawings, in which:
[0057] Figure 1 It is a schematic block diagram of the process of the present invention. DETAILED DESCRIPTION
[0058] The following describes embodiments of the present invention in detail. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended only to explain the present invention and are not to be construed as limiting the present invention.
[0059] The present invention discloses a distributed data security protection method based on dynamic authority management, such as Figure 1 As shown, the following steps are included:
[0060] S1, the client obtains identity information authentication, the identity information includes the client IP information and / or the client location information;
[0061] S11: If the identity information obtained by the client is IP information (in this case, a WiFi connection), the relationship between the IP information and the IP information set is determined:
[0062] If ip client ∈IPυ={IP1,IP2,IP3,…,IP υ}, ip client is the IP information obtained by the client, IPυ is the IP information set that the client has successfully logged in v times; v is a positive integer greater than or equal to 3; IP1 is the first IP information in the IP information set IPυ, IP2 is the second IP information in the IP information set IPυ, IP3 is the third IP information in the IP information set IPυ, and IP υ is the υ-th IP information in the IP information set IPυ, υ is the number of IP information in the IP information set IPυ; then execute step S3;
[0063] like ip client is the IP information obtained by the client, IPυ is the IP information set that the client has successfully logged in v times; v is a positive integer greater than or equal to 3; IP1 is the first IP information in the IP information set IPυ, IP2 is the second IP information in the IP information set IPυ, IP3 is the third IP information in the IP information set IPυ, and IP υ is the υth IP information in the IP information set IPυ, υ is the number of IP information in the IP information set IPυ; then execute step S2;
[0064] S12: If the identity information obtained by the client is positioning information (in this case, it is a 2G / 3G / 4G / 5G connection, first determine whether it is a WiFi connection, then determine other connections), then determine the relationship between the positioning information and the positioning information set:
[0065] If GPS client ∈GPSμ={GPS1, GPS2, GPS3,…,GPS μ}, GPS client is the positioning information obtained by the client, GPSμ is the positioning information set that the client has successfully logged in l times; l is a positive integer greater than or equal to 5; GPS1 is the first GPS information in the positioning information set GPSμ, GPS2 is the second GPS information in the positioning information set GPSμ, GPS3 is the third GPS information in the positioning information set GPSμ, GPS μ is the μth GPS information in the positioning information set GPSμ, μ is the number of positioning information in the positioning information set GPSμ; then execute step S3;
[0066] like GPS client is the positioning information obtained by the client, GPSμ is the positioning information set that the client has successfully logged in l times; l is a positive integer greater than or equal to 5; GPS1 is the first GPS information in the positioning information set GPSμ, GPS2 is the second GPS information in the positioning information set GPSμ, GPS3 is the third GPS information in the positioning information set GPSμ, GPS μ is the μth GPS information in the positioning information set GPSμ, μ is the number of positioning information in the positioning information set GPSμ; then execute step S3;
[0067] S2, obtain the correct account and password, process the correct account and password on the client, and then enter the file platform management system;
[0068] S3, obtaining the correct account number and password, processing the correct account number and password through the file platform management system, and then entering the file platform management system;
[0069] S4, securely download the file data.
[0070] In a preferred embodiment of the present invention, the method for securely downloading file data in step S4 comprises the following steps:
[0071] S41, the file platform management system encrypts the selected file using the key to obtain an encrypted file;
[0072] S42, sending the encrypted file to the client. After receiving the encrypted file, the client uses the same key as in step S41 to decrypt it to obtain a decrypted file.
[0073] In a preferred embodiment of the present invention, the key in step S41 is obtained in the same manner as in step S42 as in step S41:
[0074] S411: The client generates and stores a pair of public and private keys.
[0075] S412: Send the public key to the file platform management system. After sending the public key to the file platform management system, the client clears the public key stored on the client. After receiving the public key, the file platform management system generates and stores a secret key. The stored secret key is the secret key in step S41. The secret key is encrypted using the public key to obtain a secure key.
[0076] S413: The security key is sent to the client. After receiving the security key, the client uses the private key to decrypt the security key to obtain and store the decryption key. The decryption key is the same as the key in step S41.
[0077] It can also be:
[0078] S411, the file platform management system generates and stores a pair of public and private keys;
[0079] S412, sending the public key to the client. After sending the public key to the client, the file platform management system clears the public key stored on the client. After receiving the public key, the client generates and stores a secret key. The stored secret key is the same as the secret key in step S41. The secret key is encrypted using the public key to obtain a secure key.
[0080] S413: Send the security key to the file platform management system. After receiving the security key, the file platform management system decrypts the security key using the private key to obtain a decryption key and stores it. The decryption key is the key in step S41.
[0081] In a preferred embodiment of the present invention, the method for entering the file platform management system after the correct account and password are input and processed by the platform in step S2 includes the following steps:
[0082] S21, obtaining the input account and password, and the client processes the obtained account and password to obtain a fourth binary account and password;
[0083] S22, sending the binary fourth account number and password to the file platform management system;
[0084] S23, determine whether the received binary fourth account number and password exist in the file platform management system:
[0085] If the received binary fourth account and password exist in the file platform management system, it means that the correct account and password have been entered to enter the file platform management system;
[0086] If the received binary fourth account number and password do not exist in the file platform management system, it means that the account number and password are entered incorrectly and the file platform management system cannot be entered.
[0087] In a preferred embodiment of the present invention, step S23 may also be: converting the received binary fourth account number and binary password into a hexadecimal fourth account number and a hexadecimal password;
[0088] Determine whether the fourth account number and password in hexadecimal format exist in the file platform management system:
[0089] If the fourth account number in hexadecimal format and the password in hexadecimal format exist in the file platform management system, it means that the correct account number and password have been entered to enter the file platform management system;
[0090] If the fourth hexadecimal account and password do not exist in the file platform management system, it means that the account and password are entered incorrectly and the file platform management system cannot be entered.
[0091] In a preferred embodiment of the present invention, the method of processing the acquired account number and password in step S21 to obtain the binary fourth account number and password is:
[0092] S211, after obtaining the input account and password, convert the account and password into a binary account and password; the binary account and password include a binary account and a binary password;
[0093] S212, after converting the account and password into a binary account and password, convert the binary account and password into a binary first account and password respectively; the binary first account and password include a binary first account and a binary first password;
[0094] S213, after converting the binary account and password into a first binary account and password respectively, converting the first binary account and password into a second account and password; the second account and password include a second account and a second password;
[0095] S214, after converting the binary first account and password into a second account and password, converting the second account and password into a binary third account and password; the binary third account and password includes a binary third account and a binary third password;
[0096] S215 , after converting the second account and password into a binary third account and password, convert the binary third account and password into a binary fourth account and password; the binary fourth account and password include a binary fourth account and a binary fourth password.
[0097] In a preferred embodiment of the present invention, the method for converting the account and password into a binary account and password in step S211 is:
[0098] Use Unicode to convert the account and password into a binary account and password; the number of digits of the binary account is 8A, where A is the number of digits of the account obtained in step S21; the number of digits of the binary password is 8B, where B is the number of digits of the password obtained in step S21.
[0099] In a preferred embodiment of the present invention, the method of converting the binary account and password into a binary first account and password respectively in step S212 is:
[0100] The binary account and password are converted into a binary first account and password respectively using the MD5 algorithm, where the number of bits of the binary first account and the binary first password are 128 bits respectively.
[0101] In a preferred embodiment of the present invention, the method for converting the binary first account and password into the second account and password in step S213 is:
[0102] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account and password; the second account and the second password are 22 digits each. The specific method of using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account is as follows:
[0103] S2131, determine the number of digits of the first binary account number:
[0104] If the number of digits in the first binary account number is equal to dC, proceed to the next step;
[0105] If the number of digits in the first binary account number is less than dC, add 0 after the first binary account number so that the number of digits in the first binary account number after adding 0 equals dC; then proceed to the next step;
[0106] S2132, divide the binary first account into groups of d, from left to right, into C groups in total;
[0107] S2133, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up Table 1.
[0108] Table 1 Numeric-character query table
[0109] Numerical character Numerical character Numerical character Numerical character Numerical character 0 A 13 N 26 a 39 n 52 0 1 B 14 O 27 b 40 o 53 1 2 C 15 P 28 c 41 p 54 2 3 D 16 Q 29 d 42 q 55 3 4 E 17 R 30 e 43 r 56 4 5 F 18 S 31 f 44 s 57 5 6 G 19 T 32 g 45 t 58 6 7 H 20 U 33 h 46 u 59 7 8 I 21 V 34 i 47 v 60 8 9 J 22 W 35 j 48 w 61 9 10 K 23 X 36 k 49 x 62 + 11 L 24 Y 37 l 50 y 63 / 12 M 25 Z 38 m 51 z
[0110] The method for converting a binary first password into a second password using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / is the same as the method for converting a binary first account into a second account using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / . Specifically:
[0111] S213-1, determine the number of bits of the first binary code:
[0112] If the number of bits of the first binary password is equal to d′C′, proceed to the next step;
[0113] If the number of digits of the first binary password is less than d′C′, add 0 after the first binary password so that the number of digits of the first binary password after adding 0 is equal to d′C′; then proceed to the next step;
[0114] S213-2, divide the binary first codes into groups of d′ from left to right, for a total of C′ groups;
[0115] S213-3, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up Table 1.
[0116] In a preferred embodiment of the present invention, the calculation method of C in step S2131 is:
[0117]
[0118] Where C is the number of groups;
[0119] D0 is the number of digits of the first binary account number; here it is 128;
[0120] d is the number of bits per character group; here it is 6;
[0121] is a ceiling function; for example
[0122] is the floor function; for example
[0123] In a preferred embodiment of the present invention, the calculation method of C′ in step S213-1 is:
[0124]
[0125] Where C′ is the number of cipher groups;
[0126] D0′ is the number of bits of the first binary code; here it is 128;
[0127] d′ is the number of bits per character group; here it is 6.
[0128] In a preferred embodiment of the present invention, the method for converting the second account and password into a binary third account and password in step S214 is:
[0129] Unicode is used to convert the second account and password into a binary third account and password. The number of bits of the binary third account and the binary third password are 176 bits respectively.
[0130] In a preferred embodiment of the present invention, the method for converting the binary third account and password into the binary fourth account and password in step S215 is:
[0131] The binary third account number and password are converted into a binary fourth account number and password using the MD5 algorithm; the number of bits of the binary fourth account number and the binary fourth password are 128 bits respectively.
[0132] For example, the account number and password entered are Beite520 and woaiBT1314 respectively; the account number and password stored in the file platform management system are 10111100001001111001010000011110010101010110111100100110011011010111011110010000110111101010000010000111101010001101010010101010101010101010101010101010101010100000100001111010001101010101010101010101010 100 and 111011101101010110100011100000101001110101010110111111111010000101111100010011101101111001101010100111011010111000110000011100101.
[0133] The first step is to obtain the input account number Beite520 and password woaiBT1314, and then use Unicode to convert the account number Beite520 into a binary account number 01000010011001010101101001010111010001100101001101010011001000110000;
[0134] Convert the password woaiBT1314 using Unicode to the binary password 01110111011011110110000101101001010000100101010000110001001100110011000100110100.
[0135] The second step is to use the MD5 algorithm to convert the binary account 01000010011001010101010010111010001100101001010011001000110000 to the binary first account 10010101010100001000010100 0011110100000010111110100011001000010100000001110011101000101010101010101110111110100000101111010001;
[0136] Use the MD5 algorithm to convert the binary password 0111011101101111011000010110101001010000100101010000110001001100110011000100110100 to the binary first password 11101111111110011 110010011101110101000111000111010010001101001000010111110101001100001000101100101111.
[0137] The third step is to use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account number 100101010101000010000101000011110100000010111110100011001000010100000001110011101000101010111010101010111011111011111000000101111010001 to the second account number lUIUPQL6MhQHOiuq3vwL0Q; specifically:
[0138] 1) Since the number of digits of the first binary account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101111011111000000101111010001 is 128 Therefore, the number of digits in the binary first account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101101111011111000000101111010001 is less than 132. , so add 0 after the first binary account 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101111011111000000101111010001, and we get The first account number equal to 132 bits of binary is 10010101010000100001010000111101000000101111101000110010000101000000011100111010001010111010101011011110111110000001011110100010000.
[0139] 2) Arrange the binary first account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101011011110111110000001011110100010000 in groups of 6 from left to right, and divide it into 22 groups in total, as shown in the first column of Table 2.
[0140] Table 2 Binary-decimal-character correspondence table
[0141]
[0142]
[0143] 3) Convert the binary characters in each group to decimal, as shown in the second column of Table 2; obtain the corresponding characters of each group by looking up Table 1, as shown in the third column of Table 2.
[0144] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first password 1110111111111100111100100111011101010001110001110100100011010010000101111111010100110000111111011010100001000101100101111 to the second password 7 / nk7qOOkaQv6nMP3tCLLw. Specifically:
[0145] 1) Since the number of bits of the first binary code 111011111111100111100100111011101010001110001110100100011010010000101111111010100111001100001111101111010100001000101100101111 is 128 Therefore, the number of bits of the binary first password 11101111111110011110010011101110101000111000111010010001101001000010111111101010011100110000111111011010100001000101100101111 has less than 132 bits. , so add 0 after the first binary password 1110111111111001111001001110111010100011100011101001000110100100001011111110101001110000111110111010100001000101100101111, and we get The first binary password equal to 132 bits is 111011111111100111100100111011101010001110001110100100011010010000101111111010100111001100001111110110101000010001011001011110000101100101111000010110010111100001011001011110000.
[0146] 2) Arrange the binary first password 1110111111111100111100100111011101010001110001110100100011010010000101111111010101001110011000011111011110110100001000101100101111 in groups of 6 from left to right, and divide it into 22 groups in total, as shown in the first column of Table 3.
[0147] Table 3 Binary-decimal-character correspondence table
[0148] Binary Decimal character 111011 59 7 111111 63 / 100111 39 n 100100 36 k 111011 59 7 101010 42 q 001110 14 O 001110 14 O 100100 36 k 011010 26 a 010000 16 Q 101111 47 v 111010 58 6 100111 39 n 001100 12 M 001111 15 P 110111 55 3 101101 45 t 000010 2 C 001011 11 L 001011 11 L 110000 48 w
[0149] 3) Convert the binary characters in each group to decimal, as shown in the second column of Table 3; obtain the corresponding characters of each group by looking up Table 1, as shown in the third column of Table 3.
[0150] The fourth step is to use Unicode to convert the second account number lUIUPQL6MhQHOiuq3vwL0Q into the binary third account number 0110110001010101010010010101010101010000010100010100110000110110010011010101000010100100001001001000010011110110101010101010100010010000100100100100001001111011010101010110001001100110110100110000101000010100001;
[0151] The second password 7 / nk7qOOkaQv6nMP3tCLLw is converted into a binary third password using Unicode: 0011011100101111011011001101011001101110111000101001111010011101010110100001010100010111011000110110011010101010011010100000011001101101010100100110101000000110011011010001001101101000100000110011011010001000110110111.
[0152] The fifth step is to use the MD5 algorithm to convert the binary third account 01101100010101010101001001010101010101000001010001010011000011011001001101010000101001000010010010011101101010101011100010011001101100111 0111010011000011000001010001 converted to binary fourth account number 10111100001001111001010100000111100101010101101111001001100110101011101111001000011011110101010000100001111010101000010000111101000110100101010101010100;
[0153] Use MD5 algorithm to convert the binary third password 001101110010111101101101100110101100110111011100010100111101001110110101100001010100010111011000110110110010101010011010100000011001101101010100010000 11010011000100110001110111 converted to binary the fourth code is 11101110110101010110001110000010100111010101011111111101000010111110001001110110111100110101010011101101010111000110000011100101.
[0154] Since the fourth binary account number is 10111100001001111001010000011110010101010101101111001001100110101011101111001000011011110101010000100001111010001101001010101010100 and the fourth binary password is 111011101 101011010110001110000010100111010101011010111111111010000101111000100111011011110011010100111011010111000110000011100101 is consistent with the account and password stored in the file platform management system, so the user can enter the file platform management system.
[0155] In a preferred embodiment of the present invention, the method for entering the file platform management system after the correct account and password are processed by the file platform management system in step S3 includes the following steps:
[0156] S31, obtaining the input account and password, and sending the obtained account and password to the file platform management system, which processes the received account and password to obtain a fourth binary account and password;
[0157] S32, determining whether the calculated binary fourth account number and password exist in the file platform management system:
[0158] If the calculated binary fourth account and password exist in the file platform management system, it means that the correct account and password are entered to enter the file platform management system;
[0159] If the calculated binary fourth account number and password do not exist in the file platform management system, it means that an incorrect account number and password are entered and the file platform management system cannot be entered.
[0160] In a preferred embodiment of the present invention, step S32 may also be: converting the binary fourth account number and the binary password into a hexadecimal fourth account number and a hexadecimal password;
[0161] Determine whether the fourth account number and password in hexadecimal format exist in the file platform management system:
[0162] If the fourth account number in hexadecimal format and the password in hexadecimal format exist in the file platform management system, it means that the correct account number and password have been entered to enter the file platform management system;
[0163] If the fourth hexadecimal account and password do not exist in the file platform management system, it means that the account and password are entered incorrectly and the file platform management system cannot be entered.
[0164] In a preferred embodiment of the present invention, in step S31, the file platform management system processes the received account and password to obtain the fourth binary account and password in the following manner:
[0165] S311, after receiving the input account and password, the file platform management system converts the account and password into a binary account and password; the binary account and password include a binary account and a binary password;
[0166] S312, after converting the account and password into a binary account and password, convert the binary account and password into a binary first account and password respectively; the binary first account and password include a binary first account and a binary first password;
[0167] S313, after converting the binary account and password into a first binary account and password respectively, converting the first binary account and password into a second account and password; the second account and password include a second account and a second password;
[0168] S314, after converting the binary first account and password into a second account and password, converting the second account and password into a binary third account and password; the binary third account and password includes a binary third account and a binary third password;
[0169] S315 , after converting the second account and password into a binary third account and password, convert the binary third account and password into a binary fourth account and password; the binary fourth account and password include a binary fourth account and a binary fourth password.
[0170] In a preferred embodiment of the present invention, the method for converting the account and password into a binary account and password in step S311 is:
[0171] Use Unicode to convert the account and password into a binary account and password; the number of digits of the binary account is 8A, where A is the number of digits of the account obtained in step S31; the number of digits of the binary password is 8B, where B is the number of digits of the password obtained in step S31.
[0172] In a preferred embodiment of the present invention, the method for converting the binary account and password into a binary first account and password respectively in step S312 is:
[0173] The binary account and password are converted into a binary first account and password respectively using the MD5 algorithm, where the number of bits of the binary first account and the binary first password are 128 bits respectively.
[0174] In a preferred embodiment of the present invention, the method for converting the binary first account and password into the second account and password in step S313 is:
[0175] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account and password; the second account and the second password are 22 digits each. The specific method of using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account is as follows:
[0176] S3131, determine the number of digits of the first binary account number:
[0177] If the number of digits in the first binary account number is equal to dC, proceed to the next step;
[0178] If the number of digits in the first binary account number is less than dC, add 0 after the first binary account number so that the number of digits in the first binary account number after adding 0 equals dC; then proceed to the next step;
[0179] S3132, divide the binary first account into groups of d, from left to right, into C groups in total;
[0180] S3133, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up Table 1.
[0181] The method for converting a binary first password into a second password using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / is the same as the method for converting a binary first account into a second account using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / . Specifically:
[0182] S313-1, determine the number of bits of the first binary code:
[0183] If the number of bits of the first binary password is equal to d′C′, proceed to the next step;
[0184] If the number of digits of the first binary password is less than d′C′, add 0 after the first binary password so that the number of digits of the first binary password after adding 0 is equal to d′C′; then proceed to the next step;
[0185] S313-2, divide the binary first ciphers into groups of d′ from left to right, into C′ groups in total;
[0186] S313-3, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up Table 1.
[0187] In a preferred embodiment of the present invention, the calculation method of C in step S3131 is:
[0188]
[0189] Where C is the number of groups;
[0190] D0 is the number of digits of the first binary account number; here it is 128;
[0191] d is the number of bits per character group; here it is 6;
[0192] is a ceiling function; for example
[0193] is the floor function; for example
[0194] In a preferred embodiment of the present invention, the calculation method of C′ in step S313-1 is:
[0195]
[0196] Where C′ is the number of cipher groups;
[0197] D0′ is the number of bits of the first binary code; here it is 128;
[0198] d′ is the number of bits per character group; here it is 6.
[0199] In a preferred embodiment of the present invention, the method for converting the second account and password into a binary third account and password in step S314 is:
[0200] Unicode is used to convert the second account and password into a binary third account and password. The number of bits of the binary third account and the binary third password are 176 bits respectively.
[0201] In a preferred embodiment of the present invention, the method for converting the binary third account and password into the binary fourth account and password in step S315 is:
[0202] The binary third account number and password are converted into a binary fourth account number and password using the MD5 algorithm; the number of bits of the binary fourth account number and the binary fourth password are 128 bits respectively.
[0203] For example, the account number and password entered are Beite520 and woaiBT1314 respectively; the account number and password stored in the file platform management system are BC27941E556F266D7790DEA087A34AD4 and EED6B1C14EAD7FD0BE276F353B5C60E5 respectively.
[0204] The first step is to obtain the input account number Beite520 and password woaiBT1314, and then send them to the file platform management system. After receiving the input account number Beite520 and password woaiBT1314, the file platform management system converts the account number Beite520 into a binary account number 0100001001100101011010010101110100011001010011010100110010001100000;
[0205] Convert the password woaiBT1314 using Unicode to the binary password 01110111011011110110000101101001010000100101010000110001001100110011000100110100.
[0206] The second step is to use the MD5 algorithm to convert the binary account 01000010011001010101010010111010001100101001010011001000110000 to the binary first account 10010101010100001000010100 0011110100000010111110100011001000010100000001110011101000101010101010101110111110100000101111010001;
[0207] Use the MD5 algorithm to convert the binary password 0111011101101111011000010110101001010000100101010000110001001100110011000100110100 to the binary first password 11101111111110011 110010011101110101000111000111010010001101001000010111110101001100001000101100101111.
[0208] The third step is to use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account number 100101010101000010000101000011110100000010111110100011001000010100000001110011101000101010111010101010111011111011111000000101111010001 to the second account number lUIUPQL6MhQHOiuq3vwL0Q; specifically:
[0209] 1) Since the number of digits of the first binary account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101111011111000000101111010001 is 128 Therefore, the number of digits in the binary first account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101101111011111000000101111010001 is less than 132. , so add 0 after the first binary account 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101111011111000000101111010001, and we get The first account number equal to 132 bits of binary is 10010101010000100001010000111101000000101111101000110010000101000000011100111010001010111010101011011110111110000001011110100010000.
[0210] 2) Arrange the binary first account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101011011110111110000001011110100010000 in groups of 6 from left to right, and divide it into 22 groups in total, as shown in the first column of Table 2.
[0211] 3) Convert the binary characters in each group to decimal, as shown in the second column of Table 2; obtain the corresponding characters of each group by looking up Table 1, as shown in the third column of Table 2.
[0212] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first password 1110111111111100111100100111011101010001110001110100100011010010000101111111010100110000111111011010100001000101100101111 to the second password 7 / nk7qOOkaQv6nMP3tCLLw. Specifically:
[0213] 1) Since the number of bits of the first binary code 111011111111100111100100111011101010001110001110100100011010010000101111111010100111001100001111101111010100001000101100101111 is 128 Therefore, the number of bits of the binary first password 11101111111110011110010011101110101000111000111010010001101001000010111111101010011100110000111111011010100001000101100101111 has less than 132 bits. , so add 0 after the first binary password 1110111111111001111001001110111010100011100011101001000110100100001011111110101001110000111110111010100001000101100101111, and we get The first binary password equal to 132 bits is 111011111111100111100100111011101010001110001110100100011010010000101111111010100111001100001111110110101000010001011001011110000101100101111000010110010111100001011001011110000.
[0214] 2) Arrange the binary first password 1110111111111100111100100111011101010001110001110100100011010010000101111111010101001110011000011111011110110100001000101100101111 in groups of 6 from left to right, and divide it into 22 groups in total, as shown in the first column of Table 3.
[0215] 3) Convert the binary characters in each group to decimal, as shown in the second column of Table 3; obtain the corresponding characters of each group by looking up Table 1, as shown in the third column of Table 3.
[0216] The fourth step is to use Unicode to convert the second account number lUIUPQL6MhQHOiuq3vwL0Q into the binary third account number 0110110001010101010010010101010101010000010100010100110000110110010011010101000010100100001001001000010011110110101010101010100010010000100100100100001001111011010101010110001001100110110100110000101000010100001;
[0217] The second password 7 / nk7qOOkaQv6nMP3tCLLw is converted into a binary third password using Unicode: 0011011100101111011011001101011001101110111000101001111010011110110101011011 000010101000101110110001101100110101010100000011001101101010100110011011010001000001100110110100010011000110111.
[0218] The fifth step is to use the MD5 algorithm to convert the binary third account 01101100010101010100100101010101010100000101000101001100001101100100110101000010100010100100001001111 01101001011101010111000100110011011011001110111010011000011000001010001 converted to binary the fourth account number is 1011110000100111100101010101010110111100100110011011010111011110010000110111101010100001000011110101000110111010001101110100001101111010100011011101000110110100101010101010100;
[0219] Use MD5 algorithm to convert the binary third password 001101110010111101101101100110101100110111011100010100111101001110110101100001010100010111011000110110110010101010011010100000011001101101010100010000 11010011000100110001110111 converted to binary the fourth code is 11101110110101010110001110000010100111010101011111111101000010111110001001110110111100110101010011101101010111000110000011100101.
[0220] Since the fourth binary account number is 10111100001001111001010000011110010101010101101111001001100110101011101111001000011011110101010000100001111010001101001010101010100 and the fourth binary password is 11101110110101010101100011100000101 The number of characters is too long. Converting them into hexadecimal, they are BC27941E556F266D7790DEA087A34AD4 and EED6B1C14EAD7FD0BE276F353B5C60E5 respectively.
[0221] Since the fourth account number BC27941E556F266D7790DEA087A34AD4 in hexadecimal format and the fourth password EED6B1C14EAD7FD0BE276F353B5C60E5 in hexadecimal format are consistent with the account number and password stored in the file platform management system, the user can log in to the file platform management system.
[0222] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.
Claims
1. A distributed data security protection method based on dynamic rights management, characterized in that: The following steps are involved: S1, the client obtains identity information authentication, the identity information includes the client IP information and / or the client location information; S2, obtain the correct account and password, process the correct account and password on the client, and then enter the file platform management system; S3, obtaining the correct account number and password, processing the correct account number and password through the file platform management system, and then entering the file platform management system; S4, securely download the file data.
2. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: Step S1 includes: Determine the connection method: If it is a WiFi connection, execute step S11; If it is other connection, execute step S12; S11: If the identity information obtained by the client is IP information, determine the relationship between the IP information and the IP information set: If ip client ∈IPυ={IP1,IP2,IP3,…,IP υ }, ip client is the IP information obtained by the client, IPυ is the IP information set that the client has successfully logged in v times; v is a positive integer greater than or equal to 3; IP1 is the first IP information in the IP information set IPυ, IP2 is the second IP information in the IP information set IPυ, IP3 is the third IP information in the IP information set IPυ, and IP υ is the υ-th IP information in the IP information set IPυ, υ is the number of IP information in the IP information set IPυ; then execute step S3; like ip client is the IP information obtained by the client, IPυ is the IP information set that the client has successfully logged in v times; v is a positive integer greater than or equal to 3; IP1 is the first IP information in the IP information set IPυ, IP2 is the second IP information in the IP information set IPυ, IP3 is the third IP information in the IP information set IPυ, and IP υ is the υth IP information in the IP information set IPυ, υ is the number of IP information in the IP information set IPυ; then execute step S2; S12: If the identity information obtained by the client is location information, determine the relationship between the location information and the location information set: If GPS client ∈GPSμ={GPS1, GPS2, GPS3,…,GPS μ }, GPS client is the positioning information obtained by the client, GPSμ is the positioning information set that the client has successfully logged in l times; l is a positive integer greater than or equal to 5; GPS1 is the first GPS information in the positioning information set GPSμ, GPS2 is the second GPS information in the positioning information set GPSμ, GPS3 is the third GPS information in the positioning information set GPSμ, GPS μ is the μth GPS information in the positioning information set GPSμ, μ is the number of positioning information in the positioning information set GPSμ; then execute step S3; like GPS client is the positioning information obtained by the client, GPSμ is the positioning information set that the client has successfully logged in l times; l is a positive integer greater than or equal to 5; GPS1 is the first GPS information in the positioning information set GPSμ, GPS2 is the second GPS information in the positioning information set GPSμ, GPS3 is the third GPS information in the positioning information set GPSμ, GPS μ is the μth GPS information in the positioning information set GPSμ, μ is the number of positioning information in the positioning information set GPSμ; then execute step S3.
3. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: The method for entering the file platform management system after the correct account and password are input and processed by the platform in step S2 includes the following steps: S21, obtaining the input account and password, and the client processes the obtained account and password to obtain a fourth binary account and password; S22, sending the binary fourth account number and password to the file platform management system; S23, determine whether the received binary fourth account number and password exist in the file platform management system: If the received binary fourth account and password exist in the file platform management system, it means that the correct account and password have been entered to enter the file platform management system; If the received binary fourth account number and password do not exist in the file platform management system, it means that the account number and password are entered incorrectly and the file platform management system cannot be entered.
4. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: The method of processing the acquired account number and password in step S21 to obtain the binary fourth account number and password is: S211, after obtaining the input account and password, convert the account and password into binary account and password; Binary account and password include binary account and binary password; S212, after converting the account and password into a binary account and password, convert the binary account and password into a binary first account and password respectively; the binary first account and password include a binary first account and a binary first password; S213, after converting the binary account and password into a first binary account and password respectively, converting the first binary account and password into a second account and password; The second account and password include the second account and the second password; S214, after converting the binary first account and password into a second account and password, convert the second account and password into a binary third account and password; The binary third account and password include a binary third account and a binary third password; S215, after converting the second account number and password into a binary third account number and password, converting the binary third account number and password into a binary fourth account number and password; The binary fourth account and password include a binary fourth account and a binary fourth password.
5. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: The method for entering the file platform management system after the correct account and password are processed by the file platform management system in step S3 includes the following steps: S31, obtaining the input account and password, and sending the obtained account and password to the file platform management system, which processes the received account and password to obtain a fourth binary account and password; S32, determining whether the calculated binary fourth account number and password exist in the file platform management system: If the calculated binary fourth account and password exist in the file platform management system, it means that the correct account and password are entered to enter the file platform management system; If the calculated binary fourth account number and password do not exist in the file platform management system, it means that an incorrect account number and password are entered and the file platform management system cannot be entered.
6. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: The method for securely downloading file data in step S4 includes the following steps: S41, the file platform management system encrypts the selected file using the key to obtain an encrypted file; S42, sending the encrypted file to the client. After receiving the encrypted file, the client uses the same key as in step S41 to decrypt it to obtain a decrypted file.
7. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: The key in step S41 is obtained in the same manner as in step S42 as in step S41: S411: The client generates and stores a pair of public and private keys. S412, sending the public key to the file platform management system. After sending the public key to the file platform management system, the client clears the public key stored on the client; After receiving the public key, the file platform management system generates a secret key and stores it, and encrypts the secret key using the public key to obtain a secure key. S413: Send the security key to the client. After receiving the security key, the client uses the private key to decrypt the security key, obtains the decrypted key, and stores it.
8. The distributed data security protection method based on dynamic rights management according to claim 1 is characterized in that: The key in step S41 is obtained in the same manner as in step S42 as in step S41: S411, the file platform management system generates and stores a pair of public and private keys; S412, sending the public key to the client. After sending the public key to the client, the file platform management system clears the public key stored on the client; After the client receives the public key, it generates and stores a secret key, and encrypts the secret key using the public key to obtain a secure key; S413, sending the security key to the file platform management system. After receiving the security key, the file platform management system decrypts the security key using the private key, obtains the decryption key, and stores it.
9. A computer system, characterized in that: include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the distributed data security protection method based on dynamic rights management as described in any one of claims 1 to 8 when executing the executable instructions.
10. A computer-readable storage medium, characterized in that include: a memory having a computer program stored thereon; A processor is used to execute the program in the memory to implement the distributed data security protection method based on dynamic rights management as described in any one of claims 1 to 8.