File access system, method, electronic device, storage medium, and program product

CN120723726BActive Publication Date: 2026-09-29LENS SYST INTEGRATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510710981.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2026-09-29
Estimated Expiration
2045-05-29

AI Technical Summary

Technical Problem

[0004]本发明实施例的目的是提供一种文件访问系统、一种文件访问方法、一种电子设备、一种机器可读存储介质和一种计算机程序产品,用以解决如何稳定、便捷地实现企业数据安全的加解密缓存的问题

Benefits of technology

[0078]系统兼容:此双缓存设计实现便捷,由系统管理缓存映射,无须修改文件系统(如NTFS、Ext4),天然适配多种存储架构。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120723726B_ABST
    Figure CN120723726B_ABST
Patent Text Reader

Abstract

The application provides a file access system, method, electronic equipment, storage medium and program product, and belongs to the technical field of computers, and the system comprises a sending module, a file filtering drive module and an encryption and decryption module; the sending module creates a file object corresponding to an access request based on an access request of an application program, and sends the file object to the file filtering drive module; the access request comprises the identification of a file to be accessed; the file filtering drive module determines a target cache area for the access request to access according to the permission type of the application program, the identification of the file to be accessed, and a first section object pointer and a second section object pointer associated with the file object in flow context information; and the encryption and decryption module determines an encryption and decryption strategy for the file to be accessed in the target cache area based on the permission type of the application program and the type of the access request. The application is used to solve the problem of how to stably and conveniently implement encryption and decryption caching of enterprise data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and more specifically to a file access system, a file access method, an electronic device, a machine-readable storage medium, and a computer program product. Background Technology

[0002] In the modern business environment, companies typically need to store large amounts of sensitive data, including customer information, financial data, and technical information. Protecting this data from unauthorized access is crucial to avoid data breaches and potential legal liabilities.

[0003] Traditional caching methods involve flushing and clearing the cache between authorized and unauthorized processes, ensuring that unauthorized processes cannot see plaintext in the cache. However, this leads to significant system instability. Layered file system drivers emerged, implementing dual caching by designing a separate layered file system and creating two file control blocks (FCBs). However, the amount of code required is almost identical to implementing a file system driver, and importantly, Windows file systems are not open-source and therefore not universally compatible. Therefore, how to stably and conveniently implement enterprise data security encryption / decryption caching has become a pressing technical problem. Summary of the Invention

[0004] The purpose of this invention is to provide a file access system, a file access method, an electronic device, a machine-readable storage medium, and a computer program product to solve the problem of how to stably and conveniently implement encryption and decryption caching for enterprise data security.

[0005] To achieve the above objectives, embodiments of the present invention provide a file access system, including:

[0006] The sending module creates a file object corresponding to the access request based on the application's access request, and sends the file object to the file filtering driver module. The access request includes the identifier of the file to be accessed.

[0007] The file filtering driver module determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information.

[0008] The encryption / decryption module determines the encryption / decryption strategy for the file to be accessed in the target cache based on the permission type of the application and the type of the access request.

[0009] The first object pointer points to the plaintext buffer, and the second object pointer points to the ciphertext buffer.

[0010] Optionally, determining the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information includes:

[0011] When the application's permission type is authorized process and the identifier of the file to be accessed indicates that plaintext data access is required, the file filtering driver module determines that the access request is to perform cached access to the plaintext cache area based on the object pointer in the first section.

[0012] Optionally, determining the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information includes:

[0013] When the application's permission type is unauthorized process and the identifier of the file to be accessed indicates that encrypted data needs to be accessed, the file filtering driver module determines that the access request is to perform cached access to the encrypted cache area based on the object pointer in the second section.

[0014] Optionally, the first section object pointer and the second section object pointer are created through the following steps:

[0015] When the file to be accessed is created, a ciphertext buffer is created on the file filtering driver module and the second section object pointer is stored in the stream context information;

[0016] When reading the file to be accessed, the cache manager module creates a plaintext cache and stores the pointer to the first section object in the stream context information.

[0017] Optionally, determining the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the type of the access request includes:

[0018] When the application's permission type is authorized process, the access request type is read request, and the target cache is plaintext cache, the encryption / decryption module decrypts the file to be accessed in the plaintext cache.

[0019] When the application's permission type is authorized process, the access request type is write request, and the target cache is plaintext cache, the encryption / decryption module decrypts the file to be accessed in the plaintext cache and encrypts the data stream after the data is written to the file to be accessed in the plaintext cache.

[0020] Optionally, determining the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the type of the access request includes:

[0021] When the application's permission type is unauthorized process, the access request type is read request or write request, and the target cache is ciphertext cache, the encryption / decryption module does not process the file to be accessed.

[0022] On the other hand, embodiments of the present invention also provide a file access method, including:

[0023] Based on the application's access request, a file object corresponding to the access request is created, and the file object is sent to the file filtering driver module. The access request includes the identifier of the file to be accessed.

[0024] The file filtering driver module determines the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information.

[0025] The encryption / decryption module determines the encryption / decryption strategy for the file to be accessed in the target cache based on the permission type of the application and the type of the access request;

[0026] The first object pointer points to the plaintext buffer, and the second object pointer points to the ciphertext buffer.

[0027] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the above-described file access method.

[0028] On the other hand, the present invention also provides a machine-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described file access method.

[0029] On the other hand, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described file access method.

[0030] Through the above technical solution, this embodiment of the invention uses a file filtering driver module to determine the target cache area for access by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second object pointers associated with the file object in the stream context information; and an encryption / decryption module determines the encryption / decryption strategy for the file to be accessed in the target cache area based on the application's permission type and the type of the access request. Thus, this invention achieves transparent encryption / decryption with dual caching through the first and second object pointers. Compared to traditional methods that refresh and clear the cache between authorized and unauthorized processes, and create two file buffers (FCBs) to achieve dual caching, the file access system provided by this embodiment of the invention can stably and conveniently implement encryption / decryption caching for enterprise data security.

[0031] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0032] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0033] Figure 1 This is a schematic diagram of the file access system provided by the present invention;

[0034] Figure 2 This is a flowchart illustrating the process of an application initiating a cache read operation, as provided by the present invention.

[0035] Figure 3 This is one of the schematic diagrams comparing the technical concepts of the present invention and traditional methods;

[0036] Figure 4 This is a schematic diagram of the file object pointing process provided by the present invention;

[0037] Figure 5 This is the second schematic diagram comparing the technical concepts of the present invention and traditional methods;

[0038] Figure 6 This is a schematic diagram of the dual-cache creation process provided by the present invention;

[0039] Figure 7 This is a schematic diagram illustrating the data asynchrony between the plaintext cache and the ciphertext cache provided by the present invention;

[0040] Figure 8 This is one of the flowcharts illustrating the file access method provided by the present invention;

[0041] Figure 9This is the second flowchart illustrating the file access method provided by the present invention;

[0042] Figure 10 This is the third flowchart illustrating the file access method provided by the present invention;

[0043] Figure 11 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0044] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.

[0045] The cache is a memory area jointly maintained by the cache manager and the memory manager. After an authorized process performs a cache read operation, the cache contains the plaintext. If an unauthorized process then attempts to read the cache, it will also read the plaintext, which is obviously incorrect. One approach is to refresh and clear the cache between the two processes, but such frequent cache operations often lead to system instability. Another approach is to maintain two sets of caches using two file control blocks (FCBs), but this method is too cumbersome.

[0046] In view of this, embodiments of the present invention provide a file access system, a file access method, an electronic device, a machine-readable storage medium, and a computer program product to solve the problem of how to stably and conveniently implement encryption and decryption caching for enterprise data security.

[0047] System Implementation Examples

[0048] Please refer to Figure 1 This invention provides a file access system, which includes a sending module 10, a file filtering driver module 20, and an encryption / decryption module 30.

[0049] The sending module 10 creates a file object corresponding to the access request based on the application's access request, and sends the file object to the file filtering driver module 20. The access request includes the identifier of the file to be accessed.

[0050] When a user creates an access request for a file in an application (such as a text editor), the sending module 10 interacts with the file through a file object provided by the operating system (such as Windows) (e.g., the object returned by the open() function in Python), and sends the file object to the file filtering driver module 20. The file object encapsulates parameters such as the file path and read / write permissions of the file to be accessed, and provides specific operations such as the read() and write() functions. The identifier of the file to be accessed can be either the file ID or the file path of the file to be accessed.

[0051] The file filtering driver module 20 determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information.

[0052] This invention uses a file filtering driver module 20 as a discriminator to determine the target cache area for access requests. The application's permission types include authorized processes and unauthorized processes. In one embodiment, a ciphertext cache area can be established on the file micro-filtering driver module of the file filtering driver module 20, and a plaintext cache area can be established on the original file system driver's cache manager module. The ciphertext cache area corresponds to a second object pointer, and the plaintext cache area corresponds to a first object pointer. The first object pointer points to the plaintext cache area, and the second object pointer points to the ciphertext cache area. The first and second object pointers are stored in the stream context information of the file filtering driver module 20. The stream context information stores the first and second object pointers corresponding to the identifier of the file to be accessed. In this invention, authorized processes use the plaintext cache area, and unauthorized processes use the ciphertext cache area. That is, authorized processes access the plaintext cache area using the first object pointer, and unauthorized processes access the plaintext cache area using the second object pointer. Essentially, this elevates the traditional fcb approach to a higher level by using two FileObjects. The amount of code is very small, and the functionality is exactly the same.

[0053] The encryption / decryption module 30 determines the encryption / decryption strategy for the file to be accessed in the target cache based on the permission type of the application and the type of the access request.

[0054] The types of access requests include read requests, write requests, and creation requests. Read requests may include file information query requests. In this embodiment of the invention, the encryption / decryption module 30 can determine the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the type of the access request.

[0055] In one embodiment, determining the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the type of the access request includes:

[0056] When the application's permission type is an authorized process, the access request type is a read request, and the target cache is a plaintext cache, the encryption / decryption module 30 decrypts the file to be accessed in the plaintext cache.

[0057] When the application's permission type is an authorized process, the access request type is a write request, and the target cache is a plaintext cache, the encryption / decryption module 30 decrypts the file to be accessed in the plaintext cache and encrypts the data stream after the data is written to the file to be accessed in the plaintext cache.

[0058] The data in the file to be accessed, whether in the plaintext buffer or the ciphertext buffer, is ciphertext data. When the application's permission type is authorized, the access request type is read or write, and the target buffer is a plaintext buffer, the encryption / decryption module 30 first decrypts the file to be accessed in the plaintext buffer. If the access request type is read, the decrypted file is read directly; if the access request type is write, the encryption / decryption module 30 encrypts the data stream after the data is written to the file in the plaintext buffer.

[0059] In another embodiment, the encryption / decryption strategy for the file to be accessed in the target cache is determined based on the permission type of the application and the type of the access request, including: when the permission type of the application is an unauthorized process, the type of the access request is a read request or a write request, and the target cache is a ciphertext cache, the encryption / decryption module 30 does not process the file to be accessed.

[0060] In this embodiment of the invention, the unauthorized process accesses the file using a ciphertext buffer. Regardless of whether the access request is a read or write request, the encryption / decryption module 30 does not process the file to be accessed in the ciphertext buffer, thereby preventing the unauthorized process from reading or modifying the file.

[0061] This invention, through a file filtering driver module 20, determines the target cache area for access requests based on the application's permission type, the identifier of the file to be accessed, and the first and second object pointers associated with the file object in the stream context information. Furthermore, an encryption / decryption module 30 determines the encryption / decryption strategy for the file to be accessed in the target cache area based on the application's permission type and the type of the access request. Thus, this invention achieves transparent encryption / decryption with dual caching using the first and second object pointers. Compared to traditional methods that refresh and clear the cache between authorized and unauthorized processes and create two FCBs (file control blocks) to achieve dual caching, this invention provides a stable and convenient way to implement encryption / decryption caching for enterprise data security.

[0062] In other aspects of the embodiments of the present invention, the technical approach of implementing dual-caching functionality based on the first and second object pointers is as follows: Please refer to... Figure 2 The file micro-filter driver module, or Minifilter, is a component within the Windows operating system's file system, managed by the Filter Manager (file filter driver module 20). By registering events to be listened to in the file micro-filter driver module, it can filter IRP requests sent from the IO Manager to the file system driver, including Create, Read, and Write operations. In this case, the operation is a cached read operation initiated by the application. Since the cache has not yet been established, the IRP is created by the IO Manager, sent to the file system driver (hereinafter referred to as the file system driver) via the file micro-filter driver module, and then the file system driver establishes a cache. The cache manager module and the memory manager module then jointly initiate a non-cached paging read operation (arrow 6). This request is encapsulated into an IRP by the IO Manager, sent again to the file system driver via the file micro-filter driver module, and the file system driver reads the file from the disk (arrows 7, 8, 9) and then returns step by step. It can be seen that each time an IRP is sent from the IO Manager to the file system driver, it enters the file micro-filter driver module once; the return from the file system driver to the IO Manager also enters the file micro-filter driver module. In read operations, the former is called PreRead, and the latter is called PostRead.

[0063] Please refer to Figure 3Based on the characteristic that IRP requests repeatedly enter the file micro-filtering driver module, this embodiment of the invention adopts another method. It allocates a separate memory block for the cache-related structures within the FileObject, creating a encrypted cache area on this private cache structure memory of the file micro-filtering driver module, and a plaintext cache area on the original file system driver's cache manager module. Authorized processes use the plaintext cache area, and unauthorized processes use the encrypted cache area. Essentially, it elevates the original FCB approach to a higher level, using two file objects (plaintext and encrypted). This results in a very small amount of code while achieving the same functionality.

[0064] The FileObject structure has two key fields: FsContext and SectionObjectPointer (a pointer to a section object). FsContext1 points to the file control block (fcb), and SectionObjectPointer points to the file mapping in the cache manager module. Furthermore, fcb (FsContext2) also points to SectionObjectPointer. Therefore, the flowchart is as follows: Figure 4As shown. `FileObject->PrivateCacheMap` and `FileObject->SectionObjectPointer` are the cache-related parts of `FileObject`. `SectionObjectPointer` is a pointer to a `NonPagedPool` allocated by the lookahead list in `fcb`. This memory is shared by all `FileObject`s of a file, meaning all `FileObject`s of the same file use the same cache. `SectionObject`'s `DataSectionObject` and `SharedCacheMap` are two pointers used by the file cache. `DataSectionObject`, or `ControlArea`, is the part of the memory manager module that manages the cache, while `SharedCacheMap` is the part of the cache manager module that manages the cache. `PrivateCacheMap` is private to each file object and stores the history of read operations for that file object, providing the read-ahead algorithm with the read position and read length. It does not store the actual cache. This embodiment of the invention does not need to consider PrivateCacheMap, because the memory it points to is either a pre-prepared block of memory within FileObject->SectionObjectPointer->SharedCacheMap, or newly allocated memory by the cache manager module, and then inserted into the PrivateList linked list of the corresponding SharedCacheMap. That is, PrivateCacheMap and SharedCacheMap have a many-to-one correspondence. Because this embodiment of the invention starts processing file objects in PostCreate, PrivateCacheMap is not yet established at this time. As long as this embodiment of the invention replaces SectionObjectPointer (the pointer to the section object) before the cache is built, then PrivateCacheMap corresponds to the Shadow SectionObjectPointer (the pointer to the encrypted cache area) established later in this embodiment of the invention.

[0065] To optimize performance, the file system driver doesn't create a file cache during creation; instead, it's created during read / write operations. This is determined by checking if the `SectionObjectPointer` of the `FileObject` and `PrivateCacheMap` are null. In one embodiment, the first section object pointer (plaintext section object pointer) and the second section object pointer (ciphertext section object pointer) are created through the following steps: When creating a file to be accessed, a ciphertext cache is created on the file filtering driver module 20 (e.g., a file micro-filtering driver module), and the second section object pointer is stored in the stream context information; when reading a file to be accessed, the cache manager module creates a plaintext cache and stores the first section object pointer in the stream context information. Please refer to... Figure 5 In this embodiment of the invention, a double buffering function is implemented by using a first object pointer (plaintext object pointer) and a second object pointer (ciphertext object pointer).

[0066] Specifically, in this embodiment of the invention, a file cache is first created during the `create` process. This is essentially creating a second section object pointer (a pointer to the section object, storing its memory address). This cache can be used as plaintext or ciphertext, depending on the requirements. For example, in this embodiment, it is used as a ciphertext cache. Then, this embodiment saves the second section object pointer of this cache to the context of the file filtering driver module 20. After creating this cache, this embodiment continues to deceive the file system driver into believing that no cache has been created yet. Therefore, the file system driver will create another cache and a corresponding first section object pointer during read and write operations. This process of creating a new cache is transparent to the file system; the dual-cache creation is as follows... Figure 6 As shown below.

[0067] After establishing dual caching, one issue is distinguishing between the authorized process and the allocated cache area. In this embodiment of the invention, a new cache is created during the `create` phase. Therefore, the authorized process is also determined during `create`, and the cache within the file object is replaced. The technical solution of this application is that the authorized process uses a plaintext cache area, while the non-authorized process uses a ciphertext cache area.

[0068] Specifically, the file filtering driver module 20 determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second object pointers associated with the file object in the stream context information. This includes: when the permission type of the application is an authorized process and the identifier of the file to be accessed indicates that plaintext data is to be accessed, the file filtering driver module 20 determines that the access request will perform cache access to the plaintext cache area based on the first object pointer.

[0069] If the identifier of the file to be accessed includes a confidential tag in the file attributes, it indicates that encrypted data is to be accessed; otherwise, if the identifier of the file to be accessed does not include a confidential tag in the file attributes, it indicates that plaintext data is to be accessed. When the application's permission type is authorized process, and the identifier of the file to be accessed indicates that plaintext data is to be accessed, based on the technical approach of using a plaintext cache for authorized processes, the file filtering driver module 20 determines that the access request is to cache the plaintext cache based on the object pointer in the first section. Subsequently, when the application's permission type is authorized process, the access request type is a read request or a write request, and the target cache is a plaintext cache, the encryption / decryption module 30 will decrypt the file to be accessed in the plaintext cache. If the access request type is a read request, the decrypted file to be accessed is read directly; if the access request type is a write request, the encryption / decryption module 30 will encrypt the data stream after the data is written to the file to be accessed in the plaintext cache.

[0070] In other aspects of the embodiments of the present invention, the file filtering driver determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information. This includes: when the permission type of the application is an unauthorized process and the identifier of the file to be accessed indicates that encrypted data needs to be accessed, the file filtering driver module 20 determines that the access request performs cache access to the encrypted cache area based on the second section object pointer.

[0071] When the application's permission type is unauthorized process, and the identifier of the file to be accessed indicates that encrypted data access is required, the unauthorized process uses the encrypted buffer technology. The file filtering driver module 20 determines that the access request is cached based on the object pointer in the second section. Subsequently, when the application's permission type is unauthorized process and the access request type is a read request or a write request, since the unauthorized process uses the encrypted buffer in this embodiment, the encryption / decryption module 30 does not process the file to be accessed regardless of whether the access request is a read request or a write request. This prevents the unauthorized process from reading or modifying the file to be accessed.

[0072] Please refer to Figure 7 It should be noted that in this embodiment of the invention, the plaintext cache and the ciphertext cache will not be synchronized.

[0073] Therefore, this embodiment of the invention implements dual caching based on the first and second object pointers. Authorized processes and unauthorized processes use plaintext and ciphertext caches respectively. Authorized processes are allowed to modify the plaintext cache, while unauthorized processes are not allowed to modify the ciphertext cache. By providing a plaintext cache for authorized processes and a ciphertext cache for unauthorized processes, transparent management of data state is achieved. Users and applications do not need to know whether a file is encrypted or decrypted, thus achieving automatic management of data state. This embodiment of the invention implements automatic encryption and decryption of files. This means that users and applications do not need to manually intervene in the encryption and decryption process and can use files as usual.

[0074] In other aspects of this invention, the embodiments use StreamContext to store encryption information and file header identifiers during file runtime, storing the decryption information required by the file in the 4KB header. The encryption / decryption module 30 of this invention uses the AES-128ECB encryption algorithm and employs ciphertext stealing to handle the padding issue caused by misaligned plaintext blocks. By using the AES-128ECB block cipher algorithm and introducing ciphertext stealing padding, the confidentiality and integrity of the data are ensured. This invention protects data from unauthorized access and tampering.

[0075] In other aspects of this invention, the Write and Read operations use SwapBuffers for transparent encryption and decryption. This invention employs reentry for privileged encryption and decryption of files, allowing the file micro-filter driver module to re-enter its encryption or decryption code, enabling the driver to encrypt and decrypt files. Furthermore, to adapt to composite files such as Office files, special handling is applied during FileRenameInformation, thus automatically encrypting and decrypting docx, doc, pptx, ppt, xlsx, xls, and other files read and written using the tmp file renaming method. Regarding process control and protection, a doubly linked list is used to store process strategies, and relevant process callback functions are registered. Simultaneously, the integrity of the authorized process code segment (.text segment) is periodically scanned to achieve process control and protection. Special handling is applied to Office files to adapt to common office document formats. User-defined special file handling is also supported. The system also registers process callbacks to verify the integrity of process code segments, providing additional control and protection for processes.

[0076] In other aspects of this invention, authorized processes copy files normally, and unauthorized processes copy files normally as well. If an encrypted file is opened by an authorized process, other processes are not allowed to overwrite (drag and drop) it; this is also a Windows operating system mechanism. If no authorized process opens the file, then overwriting (drag and drop) is allowed. Because each software implements its own file operations, such as whether to synchronize when the same file is opened and edited by different software simultaneously, software requiring special attention needs to be adapted separately. The clipboard is implemented at the user layer, and the recommended Windows system monitoring API or process injection can be selected.

[0077] The file access system of this invention has the following advantages:

[0078] System compatibility: This dual-caching design is easy to implement, with cache mapping managed by the system. It does not require modification of the file system (such as NTFS, Ext4) and is naturally compatible with various storage architectures.

[0079] Read / write performance: Relying on the operating system's preset cache scheduling algorithm (such as LRU, Least Recently Used), the overhead of switching between kernel mode and user mode is reduced, and the measured IO throughput is improved by 15% to 20%.

[0080] Security isolation: Dynamically switch DataSectionObject mapping through process-level permission verification (MD5 / HASH), unauthorized processes can only access the encrypted cache, avoiding memory dump attacks.

[0081] Data synchronization: Utilize the operating system's native cache refresh mechanism (such as Flush Buffer) to ensure that encrypted data written to disk is synchronized with plaintext data in memory in real time, avoiding the risk of leakage of temporary Office files.

[0082] Convenience and Automation: Enterprises can easily deploy this system. Administrators can configure different basic policies, encryption / decryption policies, control policies, and scheduled tasks based on computing groups or authenticated users. This enables customized and precise enterprise management. Once a file is modified, the system will automatically perform encryption operations to protect data security without requiring additional user intervention.

[0083] Method Implementation Examples

[0084] Please refer to Figure 8 This invention also provides a file access method, including:

[0085] Step 100: Create a file object corresponding to the access request based on the application's access request, and send the file object to the file filtering driver module 20. The access request includes the identifier of the file to be accessed.

[0086] When a user creates an access request for a file in an application (such as a text editor), the sending module 10 interacts with the file through a file object provided by the operating system (such as the object returned by the open() function in Python) and sends the file object to the file filtering driver module 20. The file object encapsulates parameters such as the file path and read / write permissions of the file to be accessed, and provides specific operations such as the read() and write() functions. The identifier of the file to be accessed can be either the file ID or the file path of the file to be accessed.

[0087] Step 200: The file filtering driver module 20 determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information.

[0088] In one embodiment, a ciphertext cache can be established on the file micro-filtering driver module of the file filtering driver module 20, and a plaintext cache can be established on the original file system driver's cache manager module. The ciphertext cache corresponds to a second object pointer, and the plaintext cache corresponds to a first object pointer. The first object pointer points to the plaintext cache, and the second object pointer points to the ciphertext cache. The first and second object pointers are stored in the stream context information of the file filtering driver module 20. The stream context information stores the first and second object pointers corresponding to the identifier of the file to be accessed. In this embodiment, authorized processes use the plaintext cache, and unauthorized processes use the ciphertext cache. That is, authorized processes access the plaintext cache using the first object pointer, and unauthorized processes access the plaintext cache using the second object pointer. Essentially, it elevates the traditional fcb approach to a higher level by using two FileObjects. This results in a very small amount of code and achieves the same functionality.

[0089] Specifically, the first section object pointer and the second section object pointer are created through the following steps:

[0090] When the file to be accessed is created, a ciphertext buffer is created on the file filtering driver module 20 and the second section object pointer is stored in the stream context information;

[0091] When reading the file to be accessed, the cache manager module creates a plaintext cache and stores the pointer to the first section object in the stream context information.

[0092] In this embodiment of the invention, a file cache is first created during the `create` process. This is essentially creating a second section object pointer (a pointer to the section object, storing its memory address). This cache can be used as plaintext or ciphertext, depending on the requirements. For example, in this embodiment, it is used as a ciphertext cache. Then, this embodiment saves the second section object pointer of this cache to the context of the file filtering driver module 20. After creating this cache, this embodiment continues to deceive the file system driver into believing that no cache has yet been created. Therefore, the file system driver will create another cache and a corresponding first section object pointer during read and write operations. This process of creating a new cache is essentially transparent to the file system.

[0093] In another embodiment, the file filtering driver module 20 determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information. This includes: when the permission type of the application is an authorized process and the identifier of the file to be accessed indicates that plaintext data is to be accessed, the file filtering driver module 20 determines that the access request performs cache access to the plaintext cache area based on the first section object pointer.

[0094] Wherein, if the identifier of the file to be accessed includes a confidential tag in the file attributes, it indicates that encrypted data is to be accessed; otherwise, if the identifier of the file to be accessed does not include a confidential tag in the file attributes, it indicates that plaintext data is to be accessed. When the application's permission type is authorized process, and the identifier of the file to be accessed indicates that plaintext data is to be accessed, based on the technical approach of using a plaintext cache for authorized processes, the file filtering driver module 20 determines that the access request performs cached access to the plaintext cache based on the object pointer in the first section.

[0095] In other aspects of the embodiments of the present invention, the file filtering driver determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information. This includes: when the permission type of the application is an unauthorized process and the identifier of the file to be accessed indicates that encrypted data needs to be accessed, the file filtering driver module 20 determines that the access request performs cache access to the encrypted cache area based on the second section object pointer.

[0096] When the application's permission type is unauthorized process, and the identifier of the file to be accessed indicates that encrypted data needs to be accessed, the unauthorized process uses the technical approach of the encrypted cache area. The file filtering driver module 20 determines that the access request is to perform cached access to the encrypted cache area based on the object pointer in the second section.

[0097] Step 300: The encryption / decryption module 30 determines the encryption / decryption strategy for the file to be accessed in the target cache based on the permission type of the application and the type of the access request;

[0098] In one embodiment, the encryption / decryption module 30 determines the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the type of the access request, including:

[0099] When the application's permission type is an authorized process, the access request type is a read request, and the target cache is a plaintext cache, the encryption / decryption module 30 decrypts the file to be accessed in the plaintext cache.

[0100] When the application's permission type is an authorized process, the access request type is a write request, and the target cache is a plaintext cache, the encryption / decryption module 30 decrypts the file to be accessed in the plaintext cache and encrypts the data stream after the data is written to the file to be accessed in the plaintext cache.

[0101] The data in the file to be accessed, whether in the plaintext buffer or the ciphertext buffer, is ciphertext data. When the application's permission type is authorized, the access request type is read or write, and the target buffer is a plaintext buffer, the encryption / decryption module 30 first decrypts the file to be accessed in the plaintext buffer. If the access request type is read, the decrypted file is read directly; if the access request type is write, the encryption / decryption module 30 encrypts the data stream after the data is written to the file in the plaintext buffer.

[0102] In another embodiment, determining the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the type of the access request includes:

[0103] When the application's permission type is unauthorized process, the access request type is read request or write request, and the target cache is ciphertext cache, the encryption / decryption module 30 does not process the file to be accessed.

[0104] In this embodiment of the invention, the unauthorized process accesses the file using a ciphertext buffer. Therefore, regardless of whether the access request is a read or write request, the encryption / decryption module 30 does not process the file to be accessed. This prevents the unauthorized process from reading or modifying the file.

[0105] This invention achieves transparent encryption and decryption with dual buffering through a first-section object pointer and a second-section object pointer. Compared to traditional methods that involve refreshing and clearing the cache between authorized and unauthorized processes, and creating two file control blocks (FCBs) to implement dual buffering, this invention provides a stable and convenient way to implement encryption and decryption caching for enterprise data security.

[0106] For other aspects of the embodiments of the present invention, please refer to Figure 9The authorized process I / O file reading logic is implemented through the following steps:

[0107] Step 1: When the authorized process calls the Win32 API application programming interface to read a file, the Win32 API sends a read request to the file filtering driver module 20. The read request carries the identifier of the file to be read. The identifier of the file to be read can be a file ID or a file path. Of course, those skilled in the art will understand that the identifier is not limited to these.

[0108] Step 2: The file filtering driver module 20 decrypts and reads plaintext data from the plaintext buffer based on the current authorized process, the identifier of the file to be read, and the first and second object pointers associated with the file object in the stream context information.

[0109] Step 3: The cache manager module retrieves the corresponding file content data from the memory-mapped list.

[0110] Step 4: If the file is not mapped, IO management generates a page fault and sends an unbuffered paging IO operation.

[0111] Step 5: Open the encrypted file and read the encrypted data using the cached read request.

[0112] Step 6: The system file system decrypts and reads the ciphertext data from the ciphertext cache.

[0113] Step 7: Cache management retrieves the corresponding file content data from the memory-mapped list.

[0114] Step 8: If the file is not mapped, IO management generates a page fault.

[0115] Step 9: Non-cached read requests are sent directly to the original file system.

[0116] Step 10: Uncached read requests read disk file data.

[0117] Step 11: Return disk file data.

[0118] Step 12: Return the encrypted data.

[0119] Step 13: Return the memory-mapped ciphertext data.

[0120] Step 14: Return the ciphertext data to the ciphertext buffer.

[0121] Step 15: The system file system receives the encrypted data.

[0122] Step 16: Return the encrypted data read from the cache to the file filtering driver module 20.

[0123] Step 17: The decrypted plaintext data is written into the mapped memory.

[0124] Step 18: Return the memory read request for the plaintext buffer.

[0125] Step 19: Complete the read request for the plaintext buffer.

[0126] Step 20: Return plaintext data to the application.

[0127] For other aspects of the embodiments of the present invention, please refer to Figure 10 The authorized process I / O file writing logic is implemented through the following steps:

[0128] Step 1: When the authorized process calls the Win32 API application programming interface to write a file, the Win32 API sends a write request to the file filtering driver module 20. The write request carries the identifier of the file to be written. The identifier of the file to be written can be a file ID or a file path, and the identifier is not limited to these.

[0129] Step 2: The file filtering driver decrypts and writes plaintext data into the plaintext buffer based on the current authorized process, the identifier of the file to be written, and the first and second object pointers associated with the file object in the stream context information.

[0130] Step 3: Cache management searches for the corresponding file content mapping in the memory mapping list.

[0131] Step 4: If the file is not mapped, IO management generates a page fault and sends an unbuffered paging IO operation.

[0132] Step 5: Cache write requests to open encrypted files.

[0133] Step 6: The system file system reads the ciphertext data from the ciphertext cache.

[0134] Step 7: Cache management retrieves the corresponding file content data from the memory-mapped list.

[0135] Step 8: If the file is not mapped, IO management generates a page fault.

[0136] Step 9: Non-cached write requests are sent directly to the original file system.

[0137] Step 10: Uncached write requests read disk file data.

[0138] Step 11: Return disk file data.

[0139] Step 12: Return the encrypted data read from the disk.

[0140] Step 13: The encrypted data is returned to the NTFS (New Technology File System) cache.

[0141] Step 14: Return the ciphertext data to the ciphertext buffer.

[0142] Step 15: The system file system receives the encrypted data.

[0143] Step 16: Return the encrypted data read from the NTFS cache to the file filtering driver module 20.

[0144] Step 17: The decrypted plaintext data is written into the mapped memory.

[0145] Step 18: Return the memory write request for the plaintext buffer.

[0146] Step 19: Complete the write request to the plaintext buffer and modify the plaintext data.

[0147] Step 20: Return the modified plaintext data to the application. The encryption / decryption module 30 performs encryption on the data stream after the data is written to the file in the plaintext buffer.

[0148] The dual-buffered transparent encryption / decryption system of this invention not only provides advanced data protection but also offers excellent convenience in data usage, providing enterprises and organizations with a more secure and efficient data management method and ensuring the privacy and integrity of sensitive data. This innovative technology elevates data security to a new level, providing enterprises with a reliable data protection solution.

[0149] Figure 11 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 11As shown, the electronic device may include: a processor 1110, a communications interface 1120, a memory 1130, and a communication bus 1140, wherein the processor 1110, the communications interface 1120, and the memory 1130 communicate with each other through the communication bus 1140. The processor 1110 can call logical instructions in the memory 1130 to execute a file access method, which includes: creating a file object corresponding to an access request based on an application's access request, and sending the file object to a file filtering driver module, wherein the access request includes an identifier of the file to be accessed; the file filtering driver module determines the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and a first segment object pointer and a second segment object pointer associated with the file object in the stream context information; an encryption / decryption module determines an encryption / decryption strategy for the file to be accessed in the target cache area based on the application's permission type and the type of the access request; wherein the first segment object pointer points to the plaintext cache area, and the second segment object pointer points to the ciphertext cache area.

[0150] Furthermore, the logical instructions in the aforementioned memory 1130 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0151] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program that can be stored on a machine-readable storage medium. When the computer program is executed by a processor, the computer is able to execute a file access method, the method including: creating a file object corresponding to an access request based on an application's access request, and sending the file object to a file filtering driver module, the access request including an identifier of a file to be accessed; the file filtering driver module determining a target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and a first segment object pointer and a second segment object pointer associated with the file object in the stream context information; an encryption / decryption module determining an encryption / decryption strategy for the file to be accessed in the target cache area based on the application's permission type and the type of the access request; wherein the first segment object pointer points to the plaintext cache area, and the second segment object pointer points to the ciphertext cache area.

[0152] In another aspect, the present invention also provides a machine-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a file access method. The method includes: creating a file object corresponding to an access request based on an application's access request; and sending the file object to a file filtering driver module, wherein the access request includes an identifier of a file to be accessed; the file filtering driver module determines a target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and a first segment object pointer and a second segment object pointer associated with the file object in the stream context information; and an encryption / decryption module determines an encryption / decryption strategy for the file to be accessed in the target cache area based on the application's permission type and the type of the access request; wherein the first segment object pointer points to the plaintext cache area, and the second segment object pointer points to the ciphertext cache area.

[0153] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0154] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0155] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A file access system, characterized in that, include: The sending module creates a file object corresponding to the access request based on the application's access request, and sends the file object to the file filtering driver module. The access request includes the identifier of the file to be accessed. The file filtering driver module determines the target cache area to be accessed by the access request based on the permission type of the application, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information. The encryption / decryption module determines the encryption / decryption strategy for the file to be accessed in the target cache based on the permission type of the application and the type of the access request. The first object pointer points to the plaintext buffer, and the second object pointer points to the ciphertext buffer. The first section object pointer and the second section object pointer are created through the following steps: When the file to be accessed is created, a ciphertext buffer is created on the file filtering driver module and the second section object pointer is stored in the stream context information; When reading the file to be accessed, the cache manager module creates a plaintext cache and stores the pointer to the first section object in the stream context information.

2. The file access system according to claim 1, characterized in that, The step of determining the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information includes: When the application's permission type is authorized process and the identifier of the file to be accessed indicates that plaintext data access is required, the file filtering driver module determines that the access request is to perform cached access to the plaintext cache area based on the object pointer in the first section.

3. The file access system according to claim 1, characterized in that, The step of determining the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information includes: When the application's permission type is unauthorized process and the identifier of the file to be accessed indicates that encrypted data needs to be accessed, the file filtering driver module determines that the access request is to perform cached access to the encrypted cache area based on the object pointer in the second section.

4. The file access system according to claim 1, characterized in that, The step of determining the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the access request type includes: When the application's permission type is authorized process, the access request type is read request, and the target cache is plaintext cache, the encryption / decryption module decrypts the file to be accessed in the plaintext cache. When the application's permission type is authorized process, the access request type is write request, and the target cache is plaintext cache, the encryption / decryption module decrypts the file to be accessed in the plaintext cache and encrypts the data stream after the data is written to the file to be accessed in the plaintext cache.

5. The file access system according to claim 1, characterized in that, The step of determining the encryption / decryption strategy for the file to be accessed in the target cache based on the application's permission type and the access request type includes: When the application's permission type is unauthorized process, the access request type is read request or write request, and the target cache is ciphertext cache, the encryption / decryption module does not process the file to be accessed.

6. A file access method, characterized in that, The method, applied to the file access system according to any one of claims 1 to 5, comprises: Based on the application's access request, a file object corresponding to the access request is created, and the file object is sent to the file filtering driver module. The access request includes the identifier of the file to be accessed. The file filtering driver module determines the target cache area to be accessed by the access request based on the application's permission type, the identifier of the file to be accessed, and the first and second section object pointers associated with the file object in the stream context information. The encryption / decryption module determines the encryption / decryption strategy for the file to be accessed in the target cache based on the permission type of the application and the type of the access request; The first object pointer points to the plaintext buffer, and the second object pointer points to the ciphertext buffer. The first section object pointer and the second section object pointer are created through the following steps: When the file to be accessed is created, a ciphertext buffer is created on the file filtering driver module and the second section object pointer is stored in the stream context information; When reading the file to be accessed, the cache manager module creates a plaintext cache and stores the pointer to the first section object in the stream context information.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the file access method of claim 6.

8. A machine-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the file access method of claim 6.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the file access method of claim 6.

Citation Information

Patent Citations

  • Transparent encryption and decryption control method and device, program, storage medium and electronic equipment

    CN108229190A

  • File access control method and device, equipment and medium

    CN115758420A