File sharing method and electronic equipment
By using a temporary encrypted public key and a random file key generated by a key management platform, the problem of key negotiation affecting file sharing efficiency is solved, thus achieving efficient and secure file sharing.
Patent Information
- Application Number
- CN202410408882.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-03
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-04-03
AI Technical Summary
In end-to-end data encryption schemes, the sender and receiver need to negotiate keys. This process, in which the receiver generates a public-private key pair and provides the encryption public key, affects file sharing efficiency and leads to a poor user experience.
The first terminal receives a temporary encryption public key returned by the key management platform, encrypts the file to be shared using a randomly generated file key, and encrypts the file key using the temporary encryption public key to generate a file key envelope, which is then sent to the key management platform and the terminal being shared with.
It enables efficient and secure file sharing even when the recipient has not registered for the secure sharing service, ensuring the security of key transmission.
Smart Images

Figure CN120825701A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of terminal technology, and in particular to a file sharing method and electronic device. Background Art
[0002] In end-to-end data encryption schemes, the sender and receiver typically need to negotiate a key to ensure they share a shared key. For example, in a key agreement scheme based on a public-private key pair, the sender needs to use the receiver's public encryption key to encrypt the file to be shared, and then send the ciphertext of the shared file to the receiver.
[0003] Therefore, the receiver needs to generate a public-private key pair before sending the file and provide the encrypted public key in the public-private key pair to the sender. Otherwise, the sender needs to wait for the receiver to generate a public-private key pair and provide the encrypted public key, which affects file sharing efficiency and leads to a poor user experience. Summary of the Invention
[0004] In order to solve the above technical problems, the present application provides a file sharing method and electronic device. In this method, the first terminal receives a temporary encryption public key returned by a key management platform, and the temporary encryption public key is generated by the key management platform when it determines based on identification information that the sharee has not registered for a secure sharing service. The first terminal uses a randomly generated file key to encrypt the file to be shared to obtain a shared file ciphertext, and uses a temporary encryption public key to encrypt the file key to obtain a file key envelope. The first terminal sends the file key envelope to the key management platform, and sends the shared file ciphertext to the second terminal corresponding to the sharee through a third-party application. This is conducive to achieving efficient and secure file sharing functions when the recipient has not registered for a secure sharing service.
[0005] In a first aspect, an embodiment of the present application provides a file sharing method, which is applied to a first terminal, and the method includes: sending a key acquisition request to a key management platform in response to identification information of a sharee selected by a user, the key acquisition request carrying the identification information of the sharee; receiving a temporary encryption public key returned by the key management platform, the temporary encryption public key being generated by the key management platform when it is determined based on the identification information that the sharee has not registered for a secure sharing service; encrypting the file to be shared using a randomly generated file key to obtain a shared file ciphertext, and encrypting the file key using the temporary encryption public key to obtain a file key envelope; sending the file key envelope to the key management platform, and sending the shared file ciphertext to the second terminal corresponding to the sharee through a third-party application.
[0006] Using a temporary encryption public key to encrypt the file key can effectively ensure the security of key transmission when the recipient has not registered for the secure sharing service, which is conducive to achieving safe and efficient file sharing functions.
[0007] According to the first aspect, the method also includes: in response to the received temporary encryption public key, displaying the authorization time limit parameters matching the file to be shared; in response to the parameter giving operation for the authorization time limit parameters, using the given parameters as access policy parameters for the file to be shared; and generating access policy data corresponding to the access policy parameters, and sending the access policy data to the key management platform.
[0008] According to the first aspect, or any implementation of the first aspect above, the allowed given parameter value of the time validity parameter to be authorized is not greater than the preset validity period matching the temporary encryption public key.
[0009] According to the first aspect, or any implementation of the first aspect above, the method further includes: sending a notification message to the second terminal, wherein the notification message indicates that the first terminal has completed the file sharing operation based on the secure sharing service.
[0010] According to the first aspect, or any implementation of the first aspect above, the key management platform is a cloud service platform composed of a computer cluster.
[0011] According to the first aspect, or any implementation of the first aspect above, the identification information includes an email address or a mobile phone number.
[0012] In the second aspect, an embodiment of the present application provides a file sharing method, which is applied to a key management platform, and the method includes: in response to a key acquisition request received from a first terminal, searching for an encryption public key that matches the identification information of the sharee carried in the key acquisition request; if the encryption public key is not found, generating a temporary key pair that matches the identification information, and sending the temporary encryption public key in the temporary key pair to the first terminal; and in response to a file key envelope received from the first terminal, storing the file key envelope, wherein the file key envelope is obtained by encrypting the file key by the first terminal using the temporary encryption public key.
[0013] According to the second aspect, the method further includes: when the encryption public key is found, sending the encryption public key to the first terminal, so that the first terminal encrypts the file key using the encryption public key to obtain the file key envelope.
[0014] According to the second aspect, or any implementation of the second aspect above, the method further includes: storing the key certificate data in response to receiving key certificate data sent by the second terminal, wherein the key certificate data includes the current login account in the second terminal, the device information of the second terminal and the encryption public key matching the current login account, the current login account constitutes the identification information of the sharee, and the key certificate data indicates that the sharee requests to register for the secure sharing service.
[0015] According to the second aspect, or any implementation of the above second aspect, the method also includes: receiving a key acquisition request sent by the second terminal, the key acquisition request including a timestamp parameter and a file ID of the file to be decrypted; determining whether the key type corresponding to the file to be decrypted is a temporary encryption public key based on the timestamp parameter and the file ID; when the key type is the temporary encryption public key, using the encryption public key in the key certificate data to encrypt the file key envelope and the temporary decryption private key matching the temporary encryption public key to obtain key encapsulation data; and sending the key encapsulation data to the second terminal.
[0016] According to the second aspect, or any implementation of the second aspect above, the method further includes: when the key type is a non-temporary encryption public key, sending the file key envelope to the second terminal.
[0017] According to the second aspect, or any implementation of the second aspect above, the method also includes: in response to a key acquisition request received from other terminals, searching for an encryption public key that matches the identification information based on the identification information of the sharee carried in the key acquisition request; and if the encryption public key is not found, sending the temporary encryption public key to the other terminals, wherein the other terminals include terminals other than the first terminal.
[0018] According to the second aspect, or any implementation of the second aspect above, the method also includes: scanning the validity period of the temporary key pairs stored in the key management platform at a preset frequency; and in response to the existence of a temporary key pair whose validity period exceeds the preset validity period, destroying the corresponding temporary key pair as an invalid key pair.
[0019] According to the second aspect, or any implementation of the second aspect above, the method also includes: receiving a key acquisition request sent by the second terminal, the key acquisition request including a timestamp parameter and a file ID of the file to be decrypted, the key acquisition request being used to request acquisition of a file key envelope matching the file to be decrypted; determining, based on the timestamp parameter and the file ID, whether the key type corresponding to the file to be decrypted is a temporary encryption public key; if the key type is the temporary encryption public key, determining whether the temporary encryption public key is an expired encryption public key; and in response to the temporary encryption public key being an expired encryption public key, refusing to provide the file key envelope to the second terminal.
[0020] In a third aspect, an embodiment of the present application provides an electronic device comprising: one or more processors, a memory, and one or more computer programs, wherein the one or more computer programs are stored on the memory, and when the computer programs are executed by the one or more processors, the electronic device performs the following steps: in response to the identification information of the sharee selected by the user, sending a key acquisition request to a key management platform, the key acquisition request carrying the identification information of the sharee; receiving a temporary encryption public key returned by the key management platform, the temporary encryption public key being generated by the key management platform when it is determined based on the identification information that the sharee has not registered for a secure sharing service; encrypting the file to be shared using a randomly generated file key to obtain a shared file ciphertext, and encrypting the file key using the temporary encryption public key to obtain a file key envelope; sending the file key envelope to the key management platform, and sending the shared file ciphertext to the second terminal corresponding to the sharee through a third-party application.
[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable medium for storing a computer program, wherein the computer program includes instructions for executing the method in the first and second aspects or any possible implementation of the first and second aspects.
[0022] In a fifth aspect, an embodiment of the present application provides a computer program comprising instructions for executing the method of the first and second aspects or any possible implementation of the first and second aspects.
[0023] In a sixth aspect, embodiments of the present application provide a chip comprising a processing circuit and transceiver pins. The transceiver pins and the processing circuit communicate with each other via an internal connection path, and the processing circuit executes the method of the first aspect or any possible implementation of the first aspect to control the receive pin to receive a signal and to control the transmit pin to send a signal. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 A schematic diagram illustrating an existing file sharing process;
[0025] Figure 2 is a schematic structural diagram of an illustrative electronic device;
[0026] Figure 3 is a software structure block diagram of an illustrative electronic device;
[0027] Figure 4 A schematic diagram of a file sharing process provided in an embodiment of the present application;
[0028] Figure 5 A flowchart of a file sharing method provided in an embodiment of the present application;
[0029] Figure 6 A schematic diagram of another file sharing process provided in an embodiment of the present application;
[0030] Figure 7 A schematic diagram of another file sharing process provided in an embodiment of the present application;
[0031] Figure 8 A schematic diagram of another file sharing process provided in an embodiment of the present application;
[0032] Figure 9 A schematic diagram of access policy parameters provided in an embodiment of the present application;
[0033] Figure 10 A schematic diagram of the file access parameter verification process provided in an embodiment of the present application;
[0034] Figure 11 A flowchart of a key management method provided in an embodiment of the present application;
[0035] Figure 12 A schematic diagram of a key management process provided in an embodiment of the present application;
[0036] Figure 13 A schematic diagram of another key management process provided in an embodiment of the present application;
[0037] Figure 14 A schematic diagram of another file sharing process provided in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0039] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0040] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.
[0041] In the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.
[0042] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.
[0043] Before describing the technical solution of the embodiment of the present application, the application scenario of the embodiment of the present application is first described with reference to the accompanying drawings. In daily life and work scenarios, it is often necessary to share files through chat software such as WeChat and QQ. Figure 1 The following is a schematic diagram showing an example of an existing file sharing process. Figure 1 As shown, the sender selects the file to be shared, such as a document, picture, or video, based on the first terminal 101. The sender uses an encryption tool or plug-in to encrypt the selected file to obtain the shared file ciphertext. During the encryption process, a file key is generated, which is used to decrypt the shared file ciphertext. Only the sender and the designated recipient can access the file key. The sender sends the data to be shared 102, including the shared file ciphertext and the file key, to the second terminal 104 corresponding to the recipient via instant messaging software 103 (such as WeChat). After receiving the file ciphertext, the recipient uses the key to decrypt the file ciphertext to obtain the file content.
[0044] In existing file sharing, once a file is sent, the sender typically loses control of the file, allowing the recipient to forward it without the sender's knowledge. For sensitive and important files, such as design drafts and financial documents, forwarding them to unauthorized parties could harm the sender's interests.
[0045] This application presents an end-to-end encryption solution for electronic devices. By separating data from keys, only the designated recipient can decrypt the file, preventing it from being opened even if it is forwarded again. Furthermore, this solution allows users to send files using familiar methods like WeChat and QQ, while the keys are transmitted via a separate cloud service, improving data security.
[0046] Electronic devices may include mobile phones, tablet computers, smart watches, laptop computers, smart home devices, vehicle-mounted devices, virtual-reality fusion devices, etc. The embodiments of the present application can be applied to various scenarios where file sharing is required.
[0047] like Figure 2 The figure shows a schematic diagram of the structure of the electronic device 100. Optionally, the electronic device 100 can be called a terminal or a terminal device. The specific product form of the electronic device 100 can be a smart terminal, such as a mobile phone, a tablet computer, a wearable device, an augmented reality / virtual reality device, a laptop computer, a vehicle-mounted device, a personal digital assistant (PDA), and other electronic devices with a file sharing function. Specifically, the functional modules involved in this application can be deployed on the DSP chip of the relevant device, and specifically can be the application program or software therein. A file sharing function can be implemented through software installation or upgrade, as well as through hardware call coordination.
[0048] It should be understood that Figure 2 The illustrated electronic device 100 is merely one example of an electronic device, and the electronic device 100 may have more or fewer components than shown in the figures, may combine two or more components, or may have a different configuration of components. Figure 2 The various components shown in the drawings may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.
[0049] The electronic device 100 may include a processor 110, a memory 200, a mobile communication module 130, a wireless communication module 140, a sensor module 150, a button 160, a motor 161, an indicator 162, a camera 163, and a display screen 164. The sensor module 150 may include a pressure sensor, a gyroscope sensor, an acceleration sensor, a temperature sensor, a motion sensor, an air pressure sensor, a magnetic sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, and the like.
[0050] The processor 110 may include one or more processing units, for example, an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0051] The processor 110 may further include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory.
[0052] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 130, the wireless communication module 140, the modem processor, and the baseband processor.
[0053] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization.
[0054] The mobile communication module 130 can provide solutions for wireless communications including 2G / 3G / 4G / 5G, etc., applied to the electronic device 100. The mobile communication module 130 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc.
[0055] The wireless communication module 140 can provide wireless communication solutions for application on the electronic device 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication technology (NFC), infrared technology (IR), etc.
[0056] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 130 , and antenna 2 is coupled to wireless communication module 140 , so that electronic device 100 can communicate with a network and other devices via wireless communication technology.
[0057] The electronic device 100 implements display functions through a GPU, a display screen 164, an application processor, etc. The processor 110 may include one or more GPUs that execute program instructions to generate or change display information.
[0058] The display screen 164 is used to display images, videos, etc. The display screen 164 includes a display panel. In some embodiments, the electronic device 100 may include one or N display screens 164, where N is a positive integer greater than one.
[0059] The electronic device 100 can implement a shooting function through an ISP, a camera 163, a video codec, a GPU, a display screen 164, and an application processor.
[0060] The ISP processes data fed back by the camera 163. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within the camera 163.
[0061] The camera 163 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 100 may include 1 or N cameras 163, where N is a positive integer greater than 1.
[0062] Among them, the camera 163 can be located in the edge area of the electronic device, can be an under-screen camera, or can be a liftable camera. The camera 163 can include a front camera and can also include a rear camera. The embodiment of the present application does not limit the specific position and form of the camera 163. The electronic device 100 can include cameras with one or more focal lengths. For example, cameras with different focal lengths can include a telephoto camera, a wide-angle camera, an ultra-wide-angle camera, or a panoramic camera.
[0063] The memory 120 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the memory 120, for example, enabling the electronic device 100 to implement the file sharing method in the embodiment of the present application. The memory 120 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area may store data created during the use of the electronic device 100, etc. In addition, the memory 120 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0064] A touch sensor, also known as a "touch panel," can be provided on display screen 164. The touch sensor and display screen 164 form a touch screen, also known as a "touch screen." The touch sensor is used to detect touch operations applied to or near the touch sensor. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 164.
[0065] The pressure sensor is used to sense pressure signals and convert the pressure signals into electrical signals. In some embodiments, the pressure sensor can be provided on the display screen 164. The electronic device 100 can also calculate the touch position based on the detection signal of the pressure sensor.
[0066] The gyroscope sensor may be used to determine the motion posture of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (ie, x, y, and z axes) may be determined by the gyroscope sensor.
[0067] The accelerometer can detect the magnitude of the electronic device 100's acceleration in all directions (generally three axes). When the electronic device 100 is stationary, the accelerometer can detect the magnitude and direction of gravity. The accelerometer can also be used to identify the electronic device's posture, enabling applications such as switching between landscape and portrait modes and pedometers.
[0068] The buttons 160 include a power button (also known as a power button), a volume button, etc. The buttons 160 can be mechanical buttons or touch buttons. The electronic device 100 can receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 100.
[0069] The software system of the electronic device 100 may adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a microservice architecture, or a cloud architecture. In the embodiment of the present invention, the Android system with a layered architecture is used as an example to illustrate the software structure of the electronic device 100.
[0070] like Figure 3 This is an illustrative block diagram of the software structure of electronic device 100. The layered architecture of electronic device 100 divides the software into several layers, each with distinct roles and responsibilities. Layers communicate with each other via software interfaces. In some embodiments, the Android system is divided into five layers: application layer, application framework layer, Android runtime layer, system layer, and kernel layer, from top to bottom.
[0071] The application layer can include a series of application packages, such as Figure 3 As shown, the application package can include applications such as a camera, gallery, instant messaging, and quantum-safe envelopes. Instant messaging applications enable real-time communication over the internet, allowing users to communicate in real time through text messages, voice calls, video calls, and other methods. Common instant messaging applications include WeChat, QQ, and WhatsApp. Quantum-safe envelopes protect the privacy and security of communications using quantum cryptography. They can securely generate and distribute encryption keys using the quantum key distribution protocol, providing secure and reliable end-to-end encryption.
[0072] The application framework layer provides application programming interfaces (APIs) and programming frameworks for applications in the application layer, including various components and services to support developers' Android development. The application framework layer includes some predefined functions. Figure 3 As shown, the application framework layer may include window managers, content providers, notification managers, resource managers, and file sharing applications.
[0073] The window manager is used to manage window programs. The window manager can obtain the display size, determine whether there is a status bar, lock the screen, take screenshots, etc.
[0074] Content providers are used to store and retrieve data and make it accessible to applications. Data can include videos, images, audio, calls made and received, browsing history and bookmarks, phone books, etc.
[0075] The resource manager can provide various resources for applications, such as localized strings, icons, images, layout files, video files, and so on.
[0076] The Notification Manager allows applications to display notifications in the status bar. These messages can be used to convey notifications and disappear automatically after a short pause, without requiring user interaction. For example, notifications are used to notify the completion of downloads, message reminders, etc. Notifications can also appear in the system's top status bar in the form of icons or scrolling text, such as notifications from applications running in the background, or in the form of dialog windows that appear on the screen. Examples include text messages in the status bar, beeping, electronic devices vibrating, indicator lights flashing, etc.
[0077] File-sharing applications can provide key management and encryption / decryption capabilities, such as key generation and distribution, encrypted file transfer, encrypted messaging, multi-factor authentication, and customized permission control. When a user first uses a file-sharing application, the application automatically generates an encryption key pair and a signing key pair that match the user's identification information and uploads the encryption and signing public keys to the key management platform.
[0078] The system layer includes the system library and the Android Runtime. The system library includes multiple functional modules, such as the image rendering library, image synthesis library, function library, media library, and key management module. The key management module provides applications with the necessary key management and encryption and decryption functions, such as generating, storing, and managing encryption keys to protect the security of applications and user data.
[0079] The Android runtime consists of core libraries and a virtual machine (VM). The runtime is responsible for scheduling and management of the Android system. The core libraries consist of two parts: one containing the Java language's callable functions and the other the Android core library. The application layer and the application framework layer run in the VM, which executes the Java files in the application and framework layers as binary files. The VM is responsible for managing object lifecycles, stack management, thread management, security and exception management, and garbage collection.
[0080] It is understandable that Figure 3 The components included in the illustrated system framework layer, system library, and runtime layer do not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or split certain components, or arrange the components differently.
[0081] The kernel layer is the layer between the hardware and the aforementioned software layers. It includes at least the display driver, camera driver, and sensor driver. Hardware can include components such as cameras, displays, microphones, processors, and memory.
[0082] The following combination Figure 4 The file sharing process of the embodiment of the present application is schematically described. Figure 4 The following schematic diagram shows a file sharing process. Figure 4 As shown, the sender selects a file to be shared, such as a document, image, or video, based on a first terminal 201. During the file sharing process, the first terminal 201 randomly generates a file key and uses the file key to encrypt the file to be shared, obtaining a shared file ciphertext 202. The shared file ciphertext 202 is sent to the second terminal 204 corresponding to the sharee via a third-party application (such as WeChat) on the first terminal 201. The first terminal 201 uses the encryption public key obtained from the cloud service platform to encrypt the file key, obtaining a file key envelope 205. The first terminal 201 sends the file key envelope 205 to the cloud service platform 206, thereby achieving the transmission of data streams and key streams based on different paths.
[0083] After receiving the shared file ciphertext 202, the second terminal 204 corresponding to the shared file recipient can obtain the file key envelope 205 from the cloud service platform 206. The second terminal 204 uses the locally stored decryption private key to decrypt the file key envelope 205 and obtain the file key. The second terminal 204 uses the file key to decrypt the shared file ciphertext 202 and obtain the shared file content.
[0084] The first terminal 201 also sends the shared file ciphertext 202 to the other terminal 207 through the third-party application 203 . The other terminal 207 cannot obtain the file key envelope 205 from the cloud service platform 206 . Therefore, the other terminal 207 cannot decrypt the shared file ciphertext 202 .
[0085] Figure 5 The flowchart of a file sharing method is schematically shown. Taking the execution subject as the first terminal as an example, the terminal corresponding to the file sharer (ie the sender) constitutes the first terminal. Figure 5 As shown, the file sharing method includes, for example, operations S110 to S160.
[0086] In operation S110 , the first terminal sends identification information to the key management platform in response to identification information of a sharee selected by the user.
[0087] In operation S120 , the first terminal receives an encryption public key that matches the identification information and is returned by the key management platform.
[0088] In operation S130 , the first terminal encrypts the file to be shared using the randomly generated file key to obtain a ciphertext of the shared file.
[0089] In operation S140 , the first terminal encrypts the file key using the encryption public key to obtain a file key envelope.
[0090] In operation S150 , the first terminal generates access policy data corresponding to the access policy parameters in response to the access policy parameters generated for the file to be shared.
[0091] In operation S160 , the first terminal sends a file key envelope and access policy data to the key management platform, and sends the shared file ciphertext to the second terminal corresponding to the sharee via a third-party application.
[0092] The following is an illustrative description of the various operation examples of the file sharing method of this embodiment.
[0093] In operation S110 , the first terminal sends identification information to the key management platform in response to identification information of a sharee selected by the user.
[0094] For example, the first terminal includes a file sharing application that provides key management and encryption / decryption functions. The file sharing application and a key management platform can exchange data to implement the file sharing method of this embodiment. The key management platform, which can be a cloud service platform composed of a computer cluster, plays a key role in encrypted communications and can be responsible for storing, managing, and distributing encryption keys to ensure the security of encrypted communications and protect the confidentiality of user data.
[0095] A user can select a file to share on a first terminal. In response to the user triggering the file sharing option, the first terminal displays an option to share the file through a file sharing application. In response to the user triggering the sharing option, the file sharing application displays the identification information of candidate contacts. Furthermore, in response to the user selecting the identification information of a target contact, the file sharing application selects the target contact as the recipient of the share.
[0096] The target contact includes any contact in the candidate contacts. Candidate contacts can be users who have registered and enabled the file sharing service in the file sharing application. The identification information of the candidate contacts can include mobile phone numbers, email accounts, or other information with unique identification functions, such as ID numbers.
[0097] In response to the user's selected sharee's identification information, the file sharing application sends a key acquisition request to the key management platform, which includes the sharee's identification information. Based on the received key acquisition request, the key management platform returns the encryption public key that matches the identification information to the file sharing application.
[0098] As an optional embodiment, in response to a user triggering a sharing option, the file sharing application may also display policy parameters matching the file to be shared. In response to the user specifying parameters for the policy parameters, the file sharing application uses the specified parameters as access policy parameters generated for the file to be shared. Access policy parameters may include, for example, at least one of the following: file expiration date, trusted access address, trusted access time, and access limit.
[0099] For example, after a user chooses to share a file using a file sharing app, the app displays the access time parameters that match the file to be shared. In response to the user specifying the access time parameters, the app determines the trusted access time for the file to be shared based on the specified time parameters and generates access policy data including the trusted access time.
[0100] Figure 6 Schematic diagram of another file sharing process is shown schematically. Figure 6 In the example, as shown in interface 301, a user selects a file to be shared on a first terminal. In response to the user triggering the file sharing option 3011, as shown in interface 302, the first terminal displays an option to share the file via a file sharing application 3021. File sharing application 3021 can be, for example, a quantum secure envelope.
[0101] In response to a user triggering the "file sharing application 3021," as shown in interface 303, the file sharing application displays candidate contact identification information 3031. In response to a user selecting a target contact identification information 3041, as shown in interface 304, the file sharing application selects the target contact as the shareeee, where the target contact includes any of the candidate contacts.
[0102] In addition, the file sharing application may also display policy parameters 3042 to be authorized that match the file to be shared. Policy parameters 3042 to be authorized may, for example, be parameters for the validity period to be authorized. As shown in interface 305, in response to the user's parameter setting operation for policy parameters 3042 to be authorized, the file sharing application uses the given parameters 3051 as access policy parameters generated for the file to be shared.
[0103] In operation S120 , the first terminal receives an encryption public key that matches the identification information and is returned by the key management platform.
[0104] In operation S130 , the first terminal encrypts the file to be shared using the randomly generated file key to obtain a ciphertext of the shared file.
[0105] For example, after a user chooses to share a file using a file-sharing app, the app uses a randomly generated file key to encrypt the file, converting it from plaintext to ciphertext. The ciphertext retains the original file information, but after encryption, only the recipient with the correct key can decrypt and restore the original file content. This encryption process effectively ensures confidentiality and security during file transmission.
[0106] In operation S140 , the first terminal encrypts the file key using the encryption public key to obtain a file key envelope.
[0107] For example, a file sharing application encrypts the file key using a public key that matches the identity of the person being shared with, resulting in a file key envelope. The file key envelope contains a key copy of the file key and is typically encrypted with the recipient's public key, effectively ensuring that only the recipient can decrypt the file key envelope and obtain the file key. The file key envelope provides a secure way to transmit the file key during file transfer without exposing the key itself. Even if the file key envelope is intercepted during transmission, the interceptor cannot obtain the decryption key for the file ciphertext, effectively ensuring the security and confidentiality of the file transfer process.
[0108] In operation S150 , the first terminal generates access policy data corresponding to the access policy parameters in response to the access policy parameters generated for the file to be shared.
[0109] Exemplarily, the file sharing application specifies the parameters to be authorized when generating access policy data. These parameters may include, for example, validity period parameters, access time parameters, access location parameters, and hardware fingerprint parameters. Hardware fingerprint parameters may be hardware features or attributes used to uniquely identify a specific device, such as the device model or unique device identifier. In response to the user's parameter specification for the parameters to be authorized, the file sharing application assigns values to the internal attribute parameters in the authorization file plaintext template based on the specified parameters, obtains the authorization file plaintext, and uses the authorization file plaintext as the access policy data matching the file to be shared.
[0110] In operation S160 , the first terminal sends a file key envelope and access policy data to the key management platform, and sends the shared file ciphertext to the second terminal corresponding to the sharee via a third-party application.
[0111] For example, a file sharing application packages a file key envelope and access policy data to obtain access control data for the file to be shared. Furthermore, the file sharing application signs the access control data using the private signing key and sends the signed access control data to the key management platform. This signing operation ensures the integrity and authenticity of the access control data, effectively preventing data tampering or forgery during transmission. The key management platform can verify the signature of the access control data and, when necessary, provide the file key envelope to decrypt the file.
[0112] In addition, the file sharing application sends the shared file ciphertext to the second terminal through the social platform or instant messaging software in the first terminal. This makes it easier for users to receive shared files on the social platform or instant messaging software, improving the convenience of file sharing and user experience.
[0113] refer to Figure 6 For illustrative purposes, the file sharing application uses a randomly generated file key to encrypt the file to be shared, as shown in interface 306, resulting in shared file ciphertext 3061. Next, the user can choose to send the generated shared file ciphertext 3061 via an instant messaging application (e.g., WeChat). As shown in interface 307, in response to the user's triggering operation on the instant messaging application, the instant messaging application will display a chat creation interface. After the user selects a target object to share with, the instant messaging application will display that shared file ciphertext 3061 has been sent to the target object, as shown in interface 308.
[0114] Next, the file sharing method of the embodiment of the present application is described by taking the execution subject as a system as an example. The system can be an end-to-end encryption system, including a first terminal, a second terminal and a key management platform.
[0115] Exemplarily, in response to the user's selected identification information of a sharee, the first terminal sends a key acquisition request to the key management platform, which includes the sharee's identification information. Based on the received key acquisition request, the key management platform returns an encrypted public key that matches the identification information to the first terminal.
[0116] The first terminal encrypts the file to be shared using a randomly generated file key to obtain the shared file ciphertext, and then encrypts the file key using the encryption public key to obtain a file key envelope. In response to the access policy parameters generated for the file to be shared, the first terminal generates access policy data corresponding to the access policy parameters. The first terminal sends the file key envelope and access policy data to the key management platform and, via a third-party application, sends the shared file ciphertext to the second terminal.
[0117] For example, the first terminal packages the file key envelope and access policy data to obtain access control data for the file to be shared. Furthermore, the first terminal signs the access control data using a locally stored private signature key and sends the signed access control data to the key management platform. Furthermore, the first terminal can also send the shared file ciphertext to the second terminal via a social platform or instant messaging software.
[0118] In response to the received shared file ciphertext, the second terminal sends a key acquisition request to the key management platform. The key acquisition request carries the identification information of the sharee, that is, the identification information of the logged-in account in the second terminal. The identification information includes, for example, a mobile phone number, an email account, or other information with a unique identification function.
[0119] As an optional method, after the third-party application on the second terminal receives the shared file ciphertext, the second terminal displays an option to view the shared file ciphertext through the file sharing application. In response to the user selecting to view the shared file ciphertext through the file sharing application on the second terminal, the file sharing application sends a key acquisition request to the key management platform, which carries the identification information of the shared party.
[0120] In response to the received key acquisition request, the key management platform uses the signature public key that matches the sharer to verify the access control data. If the signature verification passes, the key management platform parses the access control data to obtain the file key envelope and access policy data.
[0121] Next, the key management platform determines whether all access policy parameters for the shared file ciphertext are satisfied based on the received identification information of the shared party. For example, the key management platform determines whether the user corresponding to the second terminal is the target user for sharing the shared file ciphertext based on the received identification information.
[0122] If the user corresponding to the second terminal is the target user for sharing, the key management platform determines whether all access policy parameters indicated by the access policy data are satisfied based on the received log data that matches the identification information. The received log data may include, for example, at least one of the time the identification information was received, the source address, and the number of times it was received. Based on the received log data that matches the identification information, the key management platform can determine whether the second terminal's request to access the shared file's ciphertext complies with parameters specified by the file sharer, such as the file's validity period, trusted access time, trusted access location, trusted access device, and access limit.
[0123] For example, the key management platform determines, based on the time the identification information was received, whether the time the second terminal requested to access the shared file's ciphertext meets the file's validity period and / or trusted access period. Based on the source of the identification information's address, the key management platform determines whether the address the second terminal requested to access the shared file's ciphertext is a trusted access address. Furthermore, based on the number of times the identification information was received, the key management platform determines whether the number of times the second terminal requested to access the shared file's ciphertext meets the access limit.
[0124] If all access policy parameters for the shared file ciphertext are met, the key management platform returns a file key envelope to the second terminal. The file sharing application on the second terminal decrypts the file key envelope using the locally stored decryption private key, obtaining the plaintext file key. The decryption private key used to decrypt the file key envelope is compatible with the encryption public key provided by the key management platform to the first terminal, which matches the shared user's identification information.
[0125] The file sharing application uses the file key to decrypt the shared file's ciphertext, obtain the shared file content, and display it. After completing the decryption operation on the shared file's ciphertext, the file sharing application clears the file key and the file key envelope to ensure the security of the key data and prevent the key and related information from being illegally used.
[0126] When viewing shared files through a file sharing app, the app stores the shared file content in memory. Keeping the decrypted shared file content in memory, rather than storing it on disk, effectively improves the security and privacy of user data, conserves storage space, and enhances system security and performance.
[0127] In response to detecting the operation of exiting the file sharing application, the file sharing application clears the shared file content stored in the memory, which can effectively prevent other applications or users from accessing the shared file content after the file sharing application is closed, which is conducive to ensuring the security and confidentiality of user data.
[0128] Figure 7 Schematic diagram of another file sharing process is shown. Figure 7 As shown, in the first terminal, the sender selects the file to be shared through user operation. After selecting the file to be shared, the user can choose to share the file by triggering the share box. After the user triggers the share box, the first terminal displays the option to share it through the file sharing application.
[0129] The file sharing application authenticates the user's identity based on the current login account in the terminal. The current login account may include, for example, a mobile phone number, an email account, or other information with a unique identification function.
[0130] After the sender chooses to share a file using a file sharing application, the file sharing application obtains an encryption public key that matches the recipient's identification information from the key management platform. Furthermore, in response to the sender specifying access policy parameters for the file to be shared, the file sharing application generates access policy data based on the access policy parameters.
[0131] The file sharing application uses a randomly generated file key to encrypt the shared file, generating the shared file ciphertext. The file sharing application then uses the received encryption public key to encrypt the file key, generating a file key envelope. The file sharing application then packages the file key envelope with the access policy data to generate the access control data for the shared file.
[0132] The file sharing application uses the locally stored private signature key to sign the access control data and sends the signed access control data to the key management platform. The file sharing application sends the shared file ciphertext to the second terminal through a third-party application (such as WeChat, QQ, or email) on the first terminal.
[0133] After the third-party application on the second terminal receives the shared file ciphertext, the second terminal displays an option to view the shared file ciphertext through the file sharing application. In response to the recipient selecting to view the shared file ciphertext through the file sharing application on the second terminal, the file sharing application sends a key acquisition request to the key management platform. The key acquisition request carries the recipient's identification information and requests a file key envelope for decrypting the shared file ciphertext.
[0134] In response to the received key acquisition request, the key management platform performs signature verification on the access control data using the signature public key that matches the sender. If the signature verification passes, the key management platform parses the access control data to obtain the file key envelope and access policy data. Next, based on the received identification information of the recipient, the key management platform determines whether all access policy parameters for the shared file ciphertext are satisfied. For example, the key management platform determines whether all access policy parameters indicated by the access policy data are satisfied based on the received log data that matches the identification information.
[0135] If all access policy parameters are met, the key management platform returns a file key envelope to the file sharing application on the second terminal. The file sharing application uses its locally stored decryption private key to decrypt the file key envelope and obtain the file key. The file sharing application then uses the file key to decrypt the shared file ciphertext and obtain the shared file content. The recipient can then open the shared file content by performing a user operation in the file sharing application.
[0136] Figure 8 Schematic diagram of another file sharing process is shown. Figure 8 As shown, in the initialization phase, the first terminal corresponding to the sender generates a signature public and private key pair<EnvSignKey pk,EnSignKey sk> , and the verification public key<EnvSignKey pk> Upload to the key management platform.
[0137] The second terminal corresponding to the recipient generates an encrypted public and private key pair<EnvEncKey pk,EnvEnKey sk> , and the encrypted public key<EnvEncKey pk> Upload to the key management platform.
[0138] The key management platform can be a cloud service platform composed of a computer cluster.
[0139] During the file sharing phase, the first terminal uploads the recipient's identification information to the key management platform. The identification information may include a mobile phone number, email account, or other information with a unique identification function. The key management platform returns the encrypted public key that matches the recipient's identification information to the first terminal.<EnvEncKey pk> .
[0140] The first terminal randomly generates a file key<FileKey sk> , and use the encrypted public key<EnvEncKey pk> Key to file<FileKey sk> Encrypt and get the file key envelope<FileKey c> .
[0141] The first terminal uses the file key<FileKey sk> The shared file is encrypted to obtain a shared file ciphertext, and the first terminal sends the shared file ciphertext to the second terminal via a third-party application.
[0142] The first terminal uses the signature private key<EnvSignKey sk> File Key Envelope<FileKey c> Sign the access policy data to obtain the signed<FileKey c,Poilcy Signature> and the signed<FileKeyc,Poilcy Signature> Upload to the key management platform.
[0143] The second terminal responds to the received shared file ciphertext and requests the file key envelope from the key management platform. The key management platform uses the verification public key<EnvSignKey pk> , for the signed<FileKey c,Poilcy Signature> Perform signature verification. If the verification is successful, the key management platform<FileKey c,Poilcy Signature> Parse and get the file key envelope<FileKey c> and access policy data.
[0144] The key management platform determines whether the access policy parameters indicated by the access policy data are all satisfied. If the access policy parameters are all satisfied, the key management platform returns the file key envelope to the second terminal.<FileKey c> The second terminal uses the decryption private key<EnvEnKey sk> File Key Envelope<FileKey c> Decrypt and get the file key<FileKey sk> , and using the file key<FileKey sk> Decrypt the shared file ciphertext to obtain the shared file content.
[0145] Current end-to-end file encryption solutions can restrict recipients to ensure that only authorized recipients can open files. However, in some cases, restricting recipients alone is insufficient. For example, a work file may require restrictions, not only for employees but also for those within the office and during working hours. If the file is not at the designated location or time, even employees cannot open it. Furthermore, to prevent circumvention of these restrictions by reporting false locations or modifying system time, the requesting party must provide reliable time and location information.
[0146] The embodiment of the present application proposes an end-to-end encryption scheme with access policy control. By generating a shared file header and access policy data, more refined access control is performed on the shared file ciphertext, which can effectively protect the privacy and security of the file sharing process.
[0147] For example, the embodiment of the present application provides a file sharing method. First, the method is described by taking the execution subject as the first terminal as an example.
[0148] The first terminal sends identification information to the key management platform in response to the identification information of the sharee selected by the user. The first terminal receives the encrypted public key matching the identification information returned by the key management platform. The first terminal encrypts the file to be shared using the randomly generated file key to obtain the shared file ciphertext, and encrypts the file key using the encrypted public key to obtain a file key envelope. In response to the access policy parameters generated for the file to be shared, the first terminal generates a shared file header and access policy data corresponding to the access policy parameters. The first terminal sends the file key envelope and access policy data to the key management platform, and sends the shared file header and shared file ciphertext to the second terminal corresponding to the sharee through a third-party application.
[0149] The first terminal includes a file sharing application that can provide key management and encryption and decryption functions. The file sharing application and the key management platform can interact with each other through data to implement the file sharing method of the embodiment of the present application.
[0150] During the file sharing process, the file sharing application displays the policy parameters matching the file to be shared. In response to a user inputting parameters for the policy parameters, the file sharing application uses the parameters as access policy parameters generated for the file to be shared. Access policy parameters include, for example, at least one of the following: file validity period, trusted access address, trusted access time, terminal restriction parameters, and access limit times.
[0151] Based on the generated access policy parameters, the file sharing application determines an access control identifier that matches the file to be shared. The access control identifier indicates the file access parameters that the second terminal must report when accessing the encrypted shared file. These file access parameters may include, for example, at least one of the following: a timestamp parameter, a location identification parameter, and a terminal identification parameter.
[0152] The timestamp parameter indicates the time when the second terminal requested to view the shared file ciphertext. The location identification parameter indicates the geographic location when the second terminal requested to view the shared file ciphertext. The terminal identification parameter indicates the terminal information of the second terminal, such as the MAC address, IMEI number (International Mobile Equipment Identity), serial number, etc.
[0153] The file sharing application generates access policy data based on the access policy parameters provided by the user and packages this access policy data with the file key envelope to obtain the access control data for the file to be shared. The file sharing application signs the access control data using the signature private key and sends the signed access control data to the key management platform.
[0154] The file sharing application constructs a shared file header containing an access control identifier. Alternatively, the file sharing application can add the access control identifier to the metadata of the file to be shared, forming a shared file header containing the access control identifier. The metadata of the file to be shared can be a collection of information describing the file's attributes and characteristics, such as the file name, file size, file type, and creation time.
[0155] The file sharing application merges the shared file header and the shared file ciphertext to generate a shared file package. Furthermore, the file sharing application sends the shared file package to the second terminal via the social platform or instant messaging software on the first terminal. By embedding an access control identifier in the shared file package, refined control over file access can be effectively achieved, enhancing the security and confidentiality of file access. After receiving the shared file package, the second terminal can determine the file access parameters that need to be reported to the key management platform based on the access control identifier in the shared file header.
[0156] Next, the file sharing method of the embodiment of the present application is described by taking the execution subject as a system as an example. The system can be an end-to-end encryption system, including a first terminal, a second terminal and a key management platform.
[0157] Exemplarily, in response to the user's selected identification information of a sharee, the first terminal sends a key acquisition request to the key management platform, which includes the sharee's identification information. Based on the received key acquisition request, the key management platform returns an encrypted public key that matches the identification information to the first terminal.
[0158] The first terminal encrypts the file to be shared using the randomly generated file key to obtain the shared file ciphertext, and encrypts the file key using the encryption public key to obtain a file key envelope.
[0159] In response to the access policy parameters given by the user for the file to be shared, the first terminal generates a shared file header and access policy data corresponding to the access policy parameters. Exemplarily, the file sharing application determines an access control identifier that matches the file to be shared based on the generated access policy parameters. The access control identifier is used to indicate the file access parameters that the second terminal needs to report when accessing the ciphertext of the shared file. The file sharing application adds the access control identifier to the metadata of the file to be shared, forming a shared file header containing the access control identifier. The file access parameters include, for example, at least one of the following parameters: a timestamp parameter, a location identification parameter, and a terminal identification parameter.
[0160] The file sharing application packages the access policy data with the file key envelope to obtain the access control data for the file to be shared. The file sharing application signs the access control data using the locally stored private signature key and sends the signed access control data to the key management platform.
[0161] The file sharing application combines the shared file header and the shared file ciphertext to obtain a shared file package, and sends the shared file package to the second terminal via the social platform or instant messaging software in the first terminal.
[0162] After the third-party application in the second terminal receives the shared file package, in response to the user selecting to view the shared file package through the file sharing application, the file sharing application parses the shared file header to obtain a file access identifier that matches the shared file ciphertext.
[0163] If the file access identifier indicates that file access parameters need to be reported, the file sharing application obtains the file access parameters from the trusted execution environment of the second terminal. For example, if the file access identifier indicates that file access parameters need to be reported, the file sharing application obtains the file access parameters signed by the trusted execution environment from the second terminal. The file access parameters may include at least one of the following parameters: a timestamp parameter, a location identification parameter, and a terminal identification parameter.
[0164] The Trusted Execution Environment (TEE) in a terminal is a secure execution environment, typically composed of hardware and software, used to protect sensitive data and execute critical tasks. The TEE is typically supported by hardware security components (such as a secure processor and secure memory areas), ensuring that sensitive data is protected during task execution and prevented from being illegally modified or accessed by unauthorized parties. File access parameters signed by the TEE are trustworthy and can be considered legitimate after being verified by the TEE, effectively ensuring that the file access parameters have not been tampered with or forged.
[0165] The file sharing application on the second terminal sends a key acquisition request to the key management platform. The key acquisition request carries the file access parameters and the identity of the person being shared. Based on the received file access parameters and identity, the key management platform determines whether all access policy parameters for the shared file ciphertext are met.
[0166] As an optional method, the key management platform responds to the key acquisition request and verifies the signature of the access control data using the signature public key that matches the sharer. If the signature verification is successful, the key management platform parses the access control data to obtain the file key envelope and access policy data.
[0167] The key management platform determines whether all access policy parameters indicated by the access policy data are satisfied based on the received file access parameters and identification information. For example, the key management platform determines whether the user of the second terminal is the target user for sharing the ciphertext of the file based on the received identification information. If the user of the second terminal is the target user, the key management platform determines whether the received file access parameters satisfy the corresponding access policy parameters. If the file access parameters satisfy the corresponding access policy parameters, the key management platform determines whether all other access policy parameters, except for the aforementioned corresponding access policy parameters, are satisfied based on the received log data that matches the identification information.
[0168] The file access parameters may include at least one of the following parameters: a timestamp parameter, a location identification parameter, and a terminal identification parameter. Furthermore, the access policy parameters may include at least one of the following parameters: a file validity period, a trusted access address, a trusted access time, a terminal restriction parameter, and an access limit.
[0169] For example, the key management platform determines, based on the timestamp parameter, whether the time when the second terminal requests to access the shared file ciphertext meets the file validity period and / or trusted access time. Based on the location identification parameter, it determines whether the address at which the second terminal requests to access the shared file ciphertext is a trusted access address. Alternatively, based on the terminal identification parameter, it determines whether the second terminal meets the terminal restriction parameter. In other words, the key management platform verifies whether the second terminal meets the access restriction conditions set by the sender by identifying the terminal characteristics of the second terminal. For example, if the terminal restriction parameter requires access to the shared file content on a specific type of device, the key management platform will verify the device type of the second terminal based on the terminal identification parameter to confirm whether it meets the access restriction conditions.
[0170] In response to the access policy parameters for the shared file ciphertext being met, the key management platform returns a file key envelope to the second terminal. The file sharing application on the second terminal decrypts the file key envelope using the locally stored decryption private key to obtain the file key. It then decrypts the shared file ciphertext using the file key to obtain and display the shared file content.
[0171] After completing the decryption operation on the shared file ciphertext, the file sharing application clears the file key and the file key envelope. In addition, in response to detecting the operation of exiting the file sharing application, the file sharing application clears the shared file content stored in the memory.
[0172] Figure 9 The schematic diagram of access policy parameters is shown schematically. The access policy parameters may, for example, define information such as recipient identity, file validity period, trusted access location, trusted access time, and device restriction parameters.
[0173] like Figure 9 In other words, a mobile phone number, email account, or other unique identifying information can be used as the recipient's identification information. The sender can limit the recipient's identity by filtering the recipient's identification information.
[0174] The file expiration period is the timeframe during which a file remains valid or accessible. During file sharing or data exchange, files often have a limited expiration period. After the expiration date, they may automatically expire or become inaccessible. File expiration periods can be set based on specific needs and security policies to ensure that files are accessible within an appropriate timeframe. File expiration periods can be self-destructing or can be set by the sender for any custom duration.
[0175] A trusted access location refers to a trusted place where a file can be accessed or opened. In order to protect the security of a file or control access rights to a file, a file may only be accessed or opened in specific locations, which are called trusted access locations. For example, certain sensitive files may only be accessible on specific computers within a company's internal network and cannot be opened on external networks or other devices. Determining the trusted access location of a file helps to strengthen the security management and access control of the file. The trusted access location can be indicated by, for example, GPS coordinates set by the sender. The sender can limit the access location of the file by specifying the GPS coordinates, and the file can only be accessed or opened within the specified GPS coordinate range.
[0176] Device restriction parameters can ensure that devices of specific types or under specific conditions can access or open a file. The sender can restrict the devices that can access or open a file by specifying the device type or device authentication status.
[0177] Figure 10 A schematic diagram schematically shows a verification process of file access parameters.
[0178] After receiving the shared file package through the third-party application, the second terminal displays an option to view the shared file package through the file sharing application. In response to the user's triggering operation for the above option, the file sharing application parses the shared file header to obtain a file access identifier that matches the shared file ciphertext.
[0179] The shared file header and shared file ciphertext constitute the shared file package. The file access identifier indicates the file access parameters that the second terminal needs to report when requesting to view the shared file ciphertext. If the file access identifier indicates that the file access parameters need to be reported, the file sharing application obtains the file access parameters signed by the trusted execution environment from the second terminal.
[0180] like Figure 10As shown, the request packaging module in the file sharing application obtains the timestamp parameter signed by the TEE (Trusted Execution Environment) from the TEE's time module and the location parameter signed by the TEE from the TEE's location module.
[0181] The timestamp parameter signed by the TEE is typically obtained from a secure clock or timer within the TEE. The TEE typically contains a secure real-time clock (RTC), whose time is protected from external influence by the operating system or other applications. When a timestamp parameter needs to be generated, the TEE reads its internal secure clock and uses the current time as the timestamp parameter for signing.
[0182] The location parameter signed by the TEE is usually obtained by obtaining the current location information of the device through various sensors and then signing it with the TEE private key. The location parameter signed by the TEE can, for example, indicate the GPS coordinates of the second terminal.
[0183] The request packaging module sends a key envelope request to the key management platform to request a file key envelope for decrypting the shared file ciphertext. The key envelope request carries a timestamp parameter signed by the TEE, a location parameter signed by the TEE, and the file ID corresponding to the shared file ciphertext.
[0184] In response to the received key envelope request, the key management platform retrieves access policy parameters matching the shared file ciphertext from the policy database based on the file ID in the key envelope request. Based on the file access time indicated by the timestamp parameter and the file access location indicated by the location parameter, the key management platform verifies whether all access policy parameters are satisfied. If all access policy parameters are satisfied, the key management platform retrieves a file key envelope from the key envelope repository based on the file ID and returns the file key envelope to the file sharing application on the second terminal, allowing the file decryption module in the file sharing application to use the file key envelope to decrypt the shared file ciphertext.
[0185] In end-to-end data encryption solutions, the client typically generates a public-private key pair for signing and a public-private key pair for encryption. To ensure the security of key data and improve the convenience of key management, the management of public-private key pairs can be delegated to the client application. In practice, the same user account may log in to multiple terminals and register for secure sharing services. When a user changes services on a terminal, such as adding a new terminal or deregistering a secure sharing service, key data must be synchronized across multiple terminals and the cloud service platform to ensure that data can be correctly decrypted on any terminal.
[0186] The present application provides a key management method for an electronic device. The electronic device includes a file sharing application that provides key management and encryption / decryption functionality. When a user first uses the file sharing application, the application automatically generates an encryption key pair and a signature key pair that match the user's identification information and uploads the encryption public key and signature public key to a key management platform.
[0187] Figure 11 A flowchart of a key management method is schematically shown. Figure 11 As shown, the key management method includes, for example, operations S210 to S240.
[0188] In operation S210 , in response to detecting a service change event based on the file sharing application, the file sharing application initiates a key management request, where the key management request includes a current login account in the electronic device.
[0189] In operation S220 , the electronic device receives public key data returned by the key management platform based on the current login account.
[0190] In operation S230 , the electronic device performs consistency verification on the public key data and the local key data to obtain a verification result.
[0191] In operation S240, the electronic device updates the current key pair indicated by the local key data according to the verification result.
[0192] The following exemplifies the operation examples of the key management method of this embodiment.
[0193] The service change event may include at least one of the following events: service registration event, service deregistration event, new device joining event, account switching event, device change event, permission change event, subscription status change event, and security setting change event.
[0194] In response to detecting a service change event based on a file sharing application, the file sharing application initiates a key management request to the key management platform. The key management request includes the current login account of the electronic device. The current login account constitutes the identification information of the user corresponding to the electronic device. The current login account can be a mobile phone number, email account, username, social media account, ID number, or other unique identifying information.
[0195] The file sharing application receives the public key data returned by the key management platform based on the currently logged-in account and performs a consistency check between the encryption public key indicated by the public key data and the public key in the current key pair, obtaining a verification result. If the verification result indicates that the encryption public key is inconsistent with the public key in the current key pair, the file sharing application can update the current key pair based on the received public key data.
[0196] In one exemplary embodiment, upon detecting a service registration event based on a file-sharing application, the file-sharing application initiates a key acquisition request to the key management platform as a key management request. The file-sharing application then receives public key data matching the currently logged-in account from the key management platform and performs a consistency check against the public key data and local key data to obtain a verification result.
[0197] If the public key data indicates that the encryption public key matching the current login account is empty, it indicates that the current login account has not yet registered for the secure sharing service based on the file sharing application. If the file sharing application detects the current key pair stored locally, it means that the current key pair does not match the current login account in the electronic device. This may be caused by a change in the login account in the electronic device. Deleting the current key pair stored locally is beneficial to ensure the consistency and freshness of the key data.
[0198] Additionally, the file sharing app can generate a key pair based on the current login account, obtaining a local key pair. For example, a local key pair includes a public-private key pair for signing and a public-private key pair for encryption. The file sharing app uses the local key pair as the new current key pair and uploads the current login account, the device information of the electronic device, and the public key from the local key pair to the key management platform.
[0199] In another example, in response to detecting a new device joining a file-sharing application, the file-sharing application initiates a key acquisition request to the key management platform as a key management request. The file-sharing application receives the public key data matching the currently logged-in account from the key management platform and performs a consistency check between the public key data and the local key data to obtain a verification result.
[0200] When the public key data indicates an encrypted public key that matches the currently logged-in account, and the local key data indicates that the current key pair is empty, the file sharing application searches for the target key pair corresponding to the encrypted public key through the key synchronization service, and stores the found target key pair as the current key pair.
[0201] If the public key data indicates that the key management platform holds an encryption public key that matches the currently logged-in account, this indicates that the currently logged-in account has already registered for a secure sharing service based on a file sharing application. If the local key data indicates that the current key pair is empty, this indicates that the key management platform may not have yet synchronized the key data that matches the currently logged-in account to the newly added device.
[0202] The Key Synchronization Service is a service used to synchronize key data across multiple devices, ensuring that users use the same key for encryption and decryption across multiple devices, effectively guaranteeing the security and consistency of key data. File sharing apps use the Key Synchronization Service to locate the target key pair corresponding to the encryption public key and store the target key pair as the current key pair. This ensures the consistency of key data between newly added devices and the key management platform, preventing inconsistencies in key management across different devices.
[0203] Alternatively, in response to a user logging into the current account on a new device (i.e., in response to detecting a new device joining event based on the file sharing application), the file sharing application initiates a key acquisition request to the key management platform as a key management request. The file sharing application receives the public key data matching the currently logged-in account returned by the key management platform, and performs a consistency check between the public key data and the local key data to obtain a verification result.
[0204] If the public key data indicates an encrypted public key that matches the currently logged-in account, this indicates that the currently logged-in account has already registered for a secure sharing service based on a file sharing application. If the local key data indicates that the current key pair is not empty and is inconsistent with the encrypted public key indicated by the public key data, this indicates that the newly added device may have previously logged in to another account, and the key management platform may not have temporarily synchronized the key data that matches the currently logged-in account to the newly added device. The file sharing application can use the key synchronization service to find the target key pair corresponding to the encrypted public key and use the target key pair to replace the current key pair for storage.
[0205] If the public key data indicates that the encryption public key matching the currently logged-in account is empty, this indicates that the currently logged-in account has not yet registered for a secure sharing service based on the file sharing application. The file sharing application can generate a key pair based on the currently logged-in account to obtain a local key pair. The file sharing application uses the local key pair as the new current key pair and uploads the currently logged-in account, the device information of the electronic device, and the public key in the local key pair to the key management platform.
[0206] In another exemplary embodiment, in response to detecting a service deregistration event for a file sharing application on an electronic device, the file sharing application sends a key deletion request to the key management platform as a key management request. In response to the received key deletion request, the key management platform deletes the encryption public key that matches the currently logged-in account.
[0207] Therefore, the public key data returned by the key management platform indicates that the encryption public key matching the current login account is empty. In response to the encryption public key matching the current login account being empty, the file sharing application deletes the current key pair stored locally.
[0208] Furthermore, in response to detecting a service deregistration event based on a file sharing application in another electronic device, the file sharing application initiates a key acquisition request to the key management platform as a key management request. The file sharing application receives public key data returned by the key management platform, the public key data indicating that the currently logged-in account is inactive. Furthermore, in response to the currently logged-in account being inactive, the file sharing application deletes the current key pair.
[0209] The file-sharing app on the current device can monitor service deregistration events on other devices in real time through its connection to the key management platform. When a file-sharing app on another device deregisters, the key management platform sends a corresponding deregistration event notification to the current device. Upon receiving this notification, the file-sharing app can respond by initiating a key retrieval request to update the key data on the current device, ensuring that key data remains synchronized and consistent across all devices.
[0210] The following uses the execution entity as an example of a key management platform to schematically illustrate the key management method of an embodiment of the present application.
[0211] After receiving a key management request, the key management platform returns the corresponding public key data to the electronic device based on the current login account of the electronic device carried in the request. The public key data indicates the encryption public key that matches the current login account and is stored in the key management platform. Depending on the actual situation, the encryption public key that matches the current login account may or may not be empty.
[0212] In one example, if the key management request is a key deletion request, the key management platform deletes the encryption public key that matches the currently logged-in account. After deleting the encryption public key, the key management platform still sends public key data to the electronic device. In this case, the public key data indicates that the encryption public key that matches the currently logged-in account is empty. As described above, the key deletion request is triggered by the electronic device when it detects a service logout event based on a file sharing application.
[0213] In addition, in response to a received key deletion request, the key management platform also sets the status of the currently logged-in account to inactive. Subsequently, when other devices corresponding to the currently logged-in account send key management requests to the key management platform, the key management platform still returns public key data to the corresponding devices, indicating that the encryption public key matching the currently logged-in account is empty.
[0214] In another example, the key management platform stores the key certificate data in response to receiving it. The key certificate data includes the encryption public key that matches the current login account, the current login account, and the device information of the electronic device. The key certificate data is generated by the electronic device based on the local key data and the public key data returned by the key management platform.
[0215] The current login account can be a mobile phone number, email address, username, social media account, ID number, or other unique identifying information. For example, the current login account can be represented as a string. Device information includes, for example, the device identifier, device model, and operating system version. The public key is typically represented as a string, but may be appropriately encoded or encrypted when actually stored.
[0216] Exemplarily, the key management platform, in response to the received key certificate data, sets a validity period parameter that matches the encryption public key based on the key type of the encryption public key. Furthermore, the key management platform associates and stores the key certificate data and the validity period parameter using the current login account as the primary key. Key types include temporary key types and permanent key types.
[0217] Figure 12 The schematic diagram of a key management process is shown schematically. The key management process of the embodiment of the present application is implemented by interacting data between the file sharing application in the electronic device and the key management platform. Figure 12 As shown, the file sharing application includes a secure envelope module, an information query module, an account management module, a security component module, and a key management module. The key management platform can be a secure cloud platform composed of a computer cluster.
[0218] The secure envelope module queries the account management module for the account login status of the second terminal. The account management module returns the current login account in the electronic device to the secure envelope module as the query result. The secure envelope module queries the account management module for the account cache information of the current login account. The account management module returns the cache information to the secure envelope module as the query result. The query result includes information such as the authentication token ServiceToken associated with the current login account, the user's unique identifier UserID, and the device's unique identifier DeviceID.
[0219] The secure envelope module applies to the key management platform for a cloud-based secure channel, and the key management platform returns a secure channel for end-cloud authentication.
[0220] The secure envelope module requests the key management module to generate a service key pair for key authentication and obtains the certificate chain from the key management module. The secure envelope module requests the secure component module to generate an ECC public key for communication key negotiation. The secure component module returns the ECC public key and its corresponding alias. The secure envelope module uploads the certificate chain and channel public key information to the key management platform, which returns the cloud public key to the secure envelope module.
[0221] The secure envelope module passes the cloud public key to the secure component module to generate a communication session key, and the secure component module returns the communication session key to the secure component module.
[0222] The security envelope module queries the key management platform whether the current login account has been registered. The key management platform returns the query result to the security envelope module, and the query result indicates that the current login account has not yet registered for the secure sharing service based on the file sharing application.
[0223] The secure envelope module requests the signature key pair and encryption / decryption key pair from the information query module. The information query module requests the security component module to generate a signature key pair, and the security component module returns the key generation result to the information query module. The information query module requests the security component module to generate an encryption / decryption key pair, and the security component module returns the key generation result to the information query module. The information query module queries the security component module for the signature public key and encryption public key, and the security component module returns the corresponding public key data to the information query module.
[0224] The secure envelope module requests the key management module to sign the signature public key and encryption public key using the private key corresponding to the HUKS business certificate. The key management module returns the signature result to the secure envelope module. The secure envelope module requests the security component module to encrypt the key certificate data using the session communication key. The security component module returns the data encryption result to the secure envelope module.
[0225] The secure envelope module uploads the encrypted key certificate data to the key management platform. The key certificate data includes the signed public key, the current login account, and the device information of the second terminal. The key management platform verifies the signature information in the key certificate data. If the verification passes, the key management platform saves the key certificate data in the database and returns the operation results to the secure envelope module.
[0226] In addition, the security component module stores the signature key pair and the encryption and decryption key pair.
[0227] Figure 13 The schematic diagram of another key management process is shown schematically. The key management process of the embodiment of the present application is implemented by interacting data with the key management platform through the file sharing application in the electronic device. Figure 13As shown, the file sharing application includes a secure envelope module, an information query module, an account management module, a security component module, and a key management module. The key management platform can be a secure cloud platform composed of a computer cluster.
[0228] The secure envelope module queries the account management module for the account login status of the second terminal. The account management module returns the current login account in the electronic device to the secure envelope module as the query result. The secure envelope module queries the account management module for the account cache information of the current login account. The account management module returns the cache information to the secure envelope module as the query result. The query result includes information such as the authentication token ServiceToken associated with the current login account, the user's unique identifier UserID, and the device's unique identifier DeviceID.
[0229] The secure envelope module applies to the key management platform for a cloud-based secure channel, and the key management platform returns a secure channel for end-cloud authentication.
[0230] The secure envelope module requests the key management module to generate a service key pair for key authentication and obtains the certificate chain from the key management module. The secure envelope module requests the secure component module to generate an ECC public key for communication key negotiation. The secure component module returns the ECC public key and its corresponding alias. The secure envelope module uploads the certificate chain and channel public key information to the key management platform, which returns the cloud public key to the secure envelope module.
[0231] The secure envelope module passes the cloud public key to the secure component module to generate a communication session key, and the secure component module returns the communication session key to the secure component module.
[0232] The secure envelope module queries the key management platform to determine if the current account has been registered. The key management platform returns a registered result to the secure envelope module, along with the public key information. A registered result indicates that the current account has been registered for the secure sharing service based on the file sharing application.
[0233] The secure envelope module queries the secure component module for the signing key pair and encryption / decryption key pair based on the alias. The secure component module then returns the query results to the secure envelope module. Querying a key pair based on an alias involves searching for the associated key based on an alias or identifier. In the cryptography and security fields, aliases can be used to represent specific keys without directly exposing the key itself. When a key is needed, it can be queried by alias or identifier to perform encryption, decryption, or other security operations.
[0234] If the key pair query fails, the security component module returns an empty result, indicating that there is no corresponding key pair locally. The secure envelope module displays a query result error, which indicates that the electronic device is not included in the trust ring or data synchronization is not complete. In this case, you need to confirm whether the electronic device is included in the trust ring or wait for the cloud to synchronize key data to the electronic device.
[0235] If the key pair query is successful, the security component module returns the public key data. The security envelope module verifies the consistency between the public key returned by the cloud and the local public key, and updates the local key pair based on the verification result.
[0236] In end-to-end data encryption schemes, the sender and receiver typically need to negotiate a key to ensure they share the key. For example, in a key agreement scheme based on a public-private key pair, the sender needs to obtain the receiver's public encryption key from the key management platform, use the public encryption key to encrypt the shared file, and then send the ciphertext of the shared file to the receiver.
[0237] Therefore, the recipient needs to generate a public-private key pair before sending the file and upload the encrypted public key in the public-private key pair to the key management platform. Otherwise, the sender needs to wait for the recipient to generate a public-private key pair and upload the encrypted public key, resulting in a poor user experience.
[0238] This embodiment of the application solves the sender's waiting problem by using the key management platform as a public key hosting platform to generate temporary key pairs for unhosted users. After the recipient uploads their official public key to the key management platform, the key management platform replaces the temporary key, ensuring that the previous file can be decrypted, and simultaneously uses the official public key to encrypt subsequent files, effectively ensuring the security of file transmission.
[0239] The embodiment of the present application provides a file sharing method. First, a schematic description is given by taking the execution subject as a first terminal as an example.
[0240] The first terminal responds to the identification information of the sharee selected by the user by sending a key acquisition request to the key management platform, and the key acquisition request carries the identification information of the sharee. The first terminal receives a temporary encryption public key returned by the key management platform. The temporary encryption public key is generated by the key management platform when it determines based on the identification information that the sharee has not registered for the secure sharing service. The first terminal uses the randomly generated file key to encrypt the file to be shared to obtain the shared file ciphertext, and uses the temporary encryption public key to encrypt the file key to obtain a file key envelope. The first terminal sends the file key envelope to the key management platform, and sends the shared file ciphertext to the second terminal corresponding to the sharee through a third-party application.
[0241] In order to ensure that the file to be shared can be decrypted within the validity period of the temporary encryption public key, it is necessary to set the file validity period of the file to be shared, and the file validity period shall not be longer than the validity period of the temporary encryption public key. Exemplarily, the first terminal displays the time-limit parameters to be authorized that match the file to be shared in response to the received temporary encryption public key. In response to the user's parameter-giving operation for the time-limit parameters to be authorized, the first terminal uses the given parameters as access policy parameters for the file to be shared. The first terminal generates access policy data corresponding to the access policy parameters, and sends the access policy data to the key management platform. Among them, the allowed given parameter value of the time-limit parameters to be authorized shall not be greater than the preset validity period that matches the temporary encryption public key.
[0242] Optionally, after sending the shared file ciphertext to the second terminal, the first terminal sends a notification message to the second terminal, indicating that the first terminal has completed the file sharing operation based on the secure sharing service. Based on the notification message, the second terminal can be informed that it has received the shared file ciphertext and can register for the secure sharing service in the file sharing application to decrypt the shared file ciphertext through the file sharing application.
[0243] Using a temporary encryption public key to encrypt the file key can effectively ensure the security of key transmission when the recipient has not registered for the secure sharing service, which is conducive to achieving safe and efficient file sharing functions.
[0244] Next, a schematic description is given by taking a system as an example, wherein the system may be an end-to-end encryption system including a first terminal, a second terminal, and a key management platform.
[0245] In response to the user's selected identification information of the sharee, the first terminal sends a key acquisition request to the key management platform. The key acquisition request carries the sharee's identification information. In response to the key acquisition request, the key management platform searches for an encryption public key that matches the identification information carried in the key acquisition request.
[0246] If the encryption public key is not found, the key management platform generates a temporary key pair that matches the identification information and sends the temporary encryption public key in the temporary key pair to the first terminal. Exemplarily, the key management platform uses a secure random number generation algorithm to generate a random number as the key seed of the temporary key pair. A temporary key pair is generated based on the key seed using a key generation algorithm. The key generation algorithm includes, for example, elliptic curve cryptography (ECC) or RSA. Then, the public key part is extracted from the generated temporary key pair as a temporary encryption public key. The key management platform sends the temporary encryption public key to the first terminal so that the first terminal can use the temporary encryption public key to encrypt the file key to obtain a file key envelope.
[0247] If the key management platform fails to find an encryption public key that matches the identification information, this indicates that the current login account on the second terminal has not yet registered for the secure sharing service based on the file sharing application, and the key management platform does not store key data that matches the current login account. The current login account can be a mobile phone number, email account, username, social media account, ID number, or other unique identifying information. The current login account constitutes the identification information of the person being shared.
[0248] The first terminal encrypts the shared file using a randomly generated file key to obtain the shared file ciphertext, and then encrypts the file key using a temporary encryption public key to obtain a file key envelope. The first terminal sends the file key envelope to the key management platform and, through a third-party application, sends the shared file ciphertext to the second terminal corresponding to the shared file.
[0249] The key management platform stores the file key envelope in response to the received file key envelope.
[0250] After the third-party application on the second terminal receives the encrypted shared file sent by the first terminal, the second terminal displays an option to access the encrypted shared file through the file sharing application. In response to the user's triggering operation on this option, the file sharing application sends a key acquisition request to the key management platform. The key acquisition request includes a timestamp parameter, the file ID of the file to be decrypted, and the identification information of the shared person.
[0251] The user's choice to access the encrypted shared file through the file sharing application indicates that the user has requested to register for a secure sharing service based on the file sharing application. The file sharing application generates a public-private key pair that matches the current login account on the second terminal. The public-private key pair includes, for example, a signature public-private key pair and an encryption public-private key pair.
[0252] The file sharing app uses the second terminal's current login account, device information, and the encrypted public key that matches the current login account as key certificate data, and uploads the key certificate data to the key management platform. The current login account constitutes the sharee's identification information, and the key certificate data indicates that the sharee is requesting registration for a secure sharing service based on the file sharing app.
[0253] The key management platform stores the received key certificate data in response. Upon receiving the key certificate data from the second terminal, the key management platform marks the temporary key pair as invalid. If a key acquisition request for a file encryption key is received from another terminal, the key management platform will directly return the encrypted public key in the key certificate data to the corresponding terminal, without providing the temporary encrypted public key.
[0254] In response to the key acquisition request received from the second terminal, the key management platform determines whether the key type corresponding to the file to be decrypted is a temporary encryption public key according to the timestamp parameter and the file ID in the key acquisition request.
[0255] If the key type is a temporary encryption public key, the key management platform uses the encryption public key in the key certificate data to encrypt the file key envelope and the temporary decryption private key that matches the temporary encryption public key, obtaining key-encapsulated data and returning the key-encapsulated data to the second terminal. If the key type is a non-temporary encryption public key, the key management platform directly returns the file key envelope to the second terminal.
[0256] In response to the received key-encapsulated data, the file sharing application on the second terminal decrypts the key-encapsulated data using the locally stored decryption private key, obtaining a file key envelope and a temporary decryption private key. The file sharing application decrypts the file key envelope using the temporary decryption private key to obtain the file key. The file sharing application then decrypts the shared file ciphertext using the file key, obtains the shared file content, and displays it.
[0257] After completing the decryption operation on the shared file ciphertext, the file sharing application clears the file key and the temporary decryption private key.
[0258] If the key management platform does not receive the key certificate data sent by the second terminal, it indicates that the current login account in the second terminal has not yet registered for the secure sharing service based on the file sharing application. When other terminals need to send a shared file ciphertext to the second terminal, the other terminals will send a key acquisition request to the key management platform to request the public key used to encrypt the file key.
[0259] In response to a key acquisition request received from another terminal, the key management platform searches for an encryption public key that matches the identification information of the shared party carried in the key acquisition request. If no encryption public key is found, the key management platform sends the generated temporary encryption public key to the other terminal, allowing the other terminal to use the temporary encryption public key to encrypt the file key. The other terminal includes terminals other than the first terminal.
[0260] Because temporary encryption public keys have a short validity period, the key management platform needs to scan the validity period of temporary key pairs at a preset frequency. If a temporary key pair exceeds the preset validity period, the key management platform will destroy the corresponding temporary key pair as an invalid key pair.
[0261] If the second terminal does not send a key acquisition request to the key management platform within the validity period of the temporary encryption public key to obtain the file key envelope for decrypting the shared file ciphertext, the key management platform will no longer provide the temporary encryption public key.
[0262] Exemplarily, the key management platform receives a key acquisition request sent by a second terminal. The key acquisition request includes a timestamp parameter and a file ID of a file to be decrypted. The key acquisition request is used to request a file key envelope that matches the file to be decrypted. Based on the timestamp parameter and the file ID, the key management platform determines whether the key type corresponding to the file to be decrypted is a temporary encryption public key. If the key type is a temporary encryption public key, the key management platform determines whether the temporary encryption public key is an expired encryption public key. Furthermore, in response to the temporary encryption public key being an expired encryption public key, the key management platform refuses to provide the file key envelope to the second terminal.
[0263] Figure 14 The schematic diagram of another file sharing process is schematically shown. The file sharing process of the embodiment of the present application is realized by interacting data with the key management platform through the file sharing application in the second terminal. Figure 14 As shown, the file sharing application includes a secure envelope module, an information query module, an account management module, a security component module, and a key management module. The key management platform can be a secure cloud platform composed of a computer cluster.
[0264] The secure envelope module queries the account management module for the account login status in the second terminal. The account management module returns the current login account in the second terminal to the secure envelope module as the query result. The secure envelope module queries the account management module for the account cache information of the current login account. The account management module returns the cache information to the secure envelope module as the query result. The query result includes information such as the authentication token ServiceToken associated with the current login account, the user's unique identifier UserID, and the device's unique identifier DeviceID.
[0265] The secure envelope module imports the shared file ciphertext and parses the file metadata to obtain the file ID, which is used to uniquely identify the shared file ciphertext.
[0266] The secure envelope module queries the information query module for a signature key pair and encryption / decryption key pair that match the current login account. The information query module queries the security component module for a key pair based on the alias. The security component module returns the query result to the information query module, indicating that a signature key pair and encryption / decryption key pair matching the current login account are locally stored. The information query module returns the query result to the secure envelope module.
[0267] The secure envelope module queries the key management platform whether the cloud stores the temporary key. The key management platform returns the query result to the secure envelope module, and the query result indicates that the cloud stores the temporary key.
[0268] The secure envelope module requests key data from the information query module, which in turn queries the security component module for public key data. The security component module returns the public key data, which includes the signature and encryption public keys that match the current login account. The information query module then passes the public key data to the secure envelope module.
[0269] The secure envelope module requests the key management module to sign the signature public key and the encryption public key, and the key management module requests to return the signed public key data to the secure envelope module.
[0270] The secure envelope module uploads the key certificate data to the key management platform. This key certificate data includes the signed public key, the current login account, and the device information of the second terminal. The key management platform verifies the signature information in the key certificate data. If the verification passes, the key management platform saves the key certificate data in the database and returns the operation results to the secure envelope module.
[0271] The key management platform confirms whether the temporary key pair is invalid at a preset frequency and deletes it if it is invalid.
[0272] The secure envelope module generates a key envelope request based on the file ID and sends it to the information query module. The information query module then sends the key envelope request to the key management module, requesting it to sign the key envelope request using its private signature key. The key management module returns the signature data to the information query module, which then passes the signature data to the secure envelope module.
[0273] The secure envelope module sends the signed key envelope request to the key management platform. The key management platform verifies the signature information in the key envelope request and determines whether the key envelope request is legitimate based on the file ID. If the key envelope request is legitimate, the key management platform uses the encrypted public key to encapsulate the temporary key and key envelope and returns the encapsulated temporary key and key envelope to the secure envelope module. The secure envelope module then performs subsequent file decryption operations based on the received key data.
[0274] It is understandable that, in order to implement the above functions, the electronic device includes hardware and / or software modules that perform the corresponding functions. In combination with the algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in combination with the embodiments, but such implementation should not be considered to be beyond the scope of this application.
[0275] All relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0276] This embodiment also provides an electronic device, comprising: one or more processors, a memory, and one or more computer programs, wherein the one or more computer programs are stored in the memory, and when the computer programs are executed by the one or more processors, the electronic device performs the following steps: in response to the identification information of the sharee selected by the user, sending a key acquisition request to a key management platform, the key acquisition request carrying the identification information of the sharee; receiving a temporary encryption public key returned by the key management platform, the temporary encryption public key being generated by the key management platform when it is determined based on the identification information that the sharee has not registered for a secure sharing service; encrypting the file to be shared using a randomly generated file key to obtain a shared file ciphertext, and encrypting the file key using the temporary encryption public key to obtain a file key envelope; sending the file key envelope to the key management platform, and sending the shared file ciphertext to the second terminal corresponding to the sharee through a third-party application.
[0277] This embodiment further provides a computer storage medium, in which computer instructions are stored. When the computer instructions are executed on an electronic device, the electronic device executes the above-mentioned related method steps to implement the file sharing method in the above-mentioned embodiment.
[0278] This embodiment further provides a computer program product. When the computer program product is run on a computer, the computer is caused to execute the above-mentioned related steps to implement the file sharing method in the above-mentioned embodiment.
[0279] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the file sharing method in the above-mentioned method embodiments.
[0280] Among them, the electronic device, computer storage medium, computer program product or chip provided in this embodiment is used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be repeated here.
[0281] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0282] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0283] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0284] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0285] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.
[0286] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0287] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
[0288] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing a software instruction. The software instruction can be composed of corresponding software modules, and the software module can be stored in a random access memory (Random Access Memory, RAM), a flash memory, a read-only memory (Read Only Memory, ROM), an erasable programmable read-only memory (Erasable Programmable ROM, EPROM), an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), a register, a hard disk, a mobile hard disk, a read-only compact disc (CD-ROM) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0289] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any media that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0290] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A file sharing method, characterized in that: Applied to a first terminal, the method includes: In response to the identification information of the sharee selected by the user, sending a key acquisition request to the key management platform, wherein the key acquisition request carries the identification information of the sharee; receiving a temporary encryption public key returned by the key management platform, where the temporary encryption public key is generated by the key management platform when it is determined based on the identification information that the sharee has not registered for a secure sharing service; Encrypting the file to be shared using the randomly generated file key to obtain a shared file ciphertext, and encrypting the file key using the temporary encryption public key to obtain a file key envelope; The file key envelope is sent to the key management platform, and the shared file ciphertext is sent to the second terminal corresponding to the sharee through a third-party application.
2. The method according to claim 1, characterized in that The method further comprises: In response to the received temporary encryption public key, displaying a time limit parameter to be authorized that matches the file to be shared; In response to a parameter setting operation for the time-limit parameter to be authorized, using the given parameter as an access policy parameter for the file to be shared; and Generate access policy data corresponding to the access policy parameters, and send the access policy data to the key management platform.
3. The method according to claim 2, characterized in that The allowed given parameter value of the time validity parameter to be authorized is not greater than the preset validity period matching the temporary encryption public key.
4. The method according to claim 1, wherein The method further comprises: A notification message is sent to the second terminal, where the notification message indicates that the first terminal has completed the file sharing operation based on the secure sharing service.
5. The method according to claim 1, wherein The key management platform is a cloud service platform composed of a computer cluster.
6. The method according to claim 1, characterized in that The identification information includes an email address or a mobile phone number.
7. A file sharing method, characterized in that: Applied to a key management platform, the method includes: In response to a key acquisition request received from the first terminal, searching for an encryption public key that matches the identification information of the sharee carried in the key acquisition request; If the encryption public key is not found, generating a temporary key pair that matches the identification information, and sending the temporary encryption public key in the temporary key pair to the first terminal; and In response to receiving a file key envelope sent by the first terminal, the file key envelope is stored, wherein the file key envelope is obtained by encrypting the file key by the first terminal using the temporary encryption public key.
8. The method according to claim 7, characterized in that The method further comprises: When the encryption public key is found, the encryption public key is sent to the first terminal so that the first terminal encrypts the file key using the encryption public key to obtain the file key envelope.
9. The method according to claim 7, characterized in that The method further comprises: In response to receiving the key certificate data sent by the second terminal, storing the key certificate data, Among them, the key certificate data includes the current login account in the second terminal, the device information of the second terminal and the encrypted public key matching the current login account. The current login account constitutes the identification information of the sharee, and the key certificate data indicates that the sharee requests to register for the secure sharing service.
10. The method according to claim 9, characterized in that The method further comprises: receiving a key acquisition request sent by the second terminal, the key acquisition request including a timestamp parameter and a file ID of a file to be decrypted; Determine, based on the timestamp parameter and the file ID, whether the key type corresponding to the file to be decrypted is a temporary encryption public key; In a case where the key type is the temporary encryption public key, using the encryption public key in the key certificate data, encrypting the file key envelope and a temporary decryption private key that matches the temporary encryption public key to obtain key encapsulation data; and The key encapsulation data is sent to the second terminal.
11. The method according to claim 10, characterized in that The method further comprises: In a case where the key type is a non-temporary encryption public key, the file key envelope is sent to the second terminal.
12. The method according to claim 7, characterized in that The method further comprises: In response to a key acquisition request received from another terminal, searching for an encryption public key that matches the identification information of the sharee carried in the key acquisition request; and If the encryption public key is not found, the temporary encryption public key is sent to the other terminal. The other terminals include terminals other than the first terminal.
13. The method according to claim 7, characterized in that The method further comprises: Scanning the validity period of the temporary key pairs stored in the key management platform at a preset frequency; and In response to the existence of a temporary key pair whose validity period exceeds a preset validity period, the corresponding temporary key pair is destroyed as an invalid key pair.
14. The method according to claim 13, characterized in that The method further comprises: receiving a key acquisition request sent by the second terminal, the key acquisition request including a timestamp parameter and a file ID of a file to be decrypted, the key acquisition request being used to request acquisition of a file key envelope matching the file to be decrypted; Determine, based on the timestamp parameter and the file ID, whether the key type corresponding to the file to be decrypted is a temporary encryption public key; In a case where the key type is the temporary encryption public key, determining whether the temporary encryption public key is an expired encryption public key; and In response to the temporary encryption public key being an invalid encryption public key, refusing to provide the file key envelope to the second terminal.
15. A file sharing method, characterized in that: Applied to a second terminal, the second terminal including a file sharing application, the method comprising: In response to viewing the shared file ciphertext sent by the first terminal through the file sharing application, the file sharing application sends a key acquisition request to the key management platform, wherein the key acquisition request carries identification information of the sharee; The file sharing application receives the key encapsulation data returned by the key management platform; The file sharing application decrypts the key-encapsulated data using the decryption private key to obtain a file key envelope and a temporary decryption private key; The file sharing application decrypts the file key envelope using the temporary decryption private key to obtain the file key; The file sharing application uses the file key to decrypt the shared file ciphertext, obtains the shared file content and displays it.
16. The method according to claim 15, characterized in that In response to viewing the shared file ciphertext sent by the first terminal through the file sharing application, the file sharing application sending a key acquisition request to the key management platform includes: In response to the third-party application receiving the shared file ciphertext sent by the first terminal, displaying an option to view the shared file ciphertext through the file sharing application; and In response to a triggering operation for the option, the file sharing application sends the key acquisition request to the key management platform.
17. The method according to claim 15, characterized in that The method further comprises: In response to completing the decryption operation on the shared file ciphertext, the file sharing application clears the file key and the temporary decryption private key.
18. An electronic device, characterized in that: include: One or more processors, a memory, and one or more computer programs, wherein the one or more computer programs are stored on the memory, and when the computer programs are executed by the one or more processors, the electronic device performs the following steps: In response to the identification information of the sharee selected by the user, sending a key acquisition request to the key management platform, wherein the key acquisition request carries the identification information of the sharee; receiving a temporary encryption public key returned by the key management platform, where the temporary encryption public key is generated by the key management platform when it is determined based on the identification information that the sharee has not registered for a secure sharing service; Encrypting the file to be shared using the randomly generated file key to obtain a shared file ciphertext, and encrypting the file key using the temporary encryption public key to obtain a file key envelope; The file key envelope is sent to the key management platform, and the shared file ciphertext is sent to the second terminal corresponding to the sharee through a third-party application.
19. An electronic device, characterized in that: include: One or more processors, a memory, a file sharing application, and one or more computer programs, wherein the one or more computer programs are stored in the memory and when the computer programs are executed by the one or more processors, the electronic device performs the following steps: In response to viewing the shared file ciphertext sent by the first terminal through the file sharing application, the file sharing application sends a key acquisition request to the key management platform, wherein the key acquisition request carries identification information of the sharee; The file sharing application receives the key encapsulation data returned by the key management platform; The file sharing application decrypts the key-encapsulated data using the decryption private key to obtain a file key envelope and a temporary decryption private key; The file sharing application decrypts the file key envelope using the temporary decryption private key to obtain the file key; The file sharing application uses the file key to decrypt the shared file ciphertext, obtains the shared file content and displays it.
20. A computer-readable storage medium, characterized in that The invention comprises a computer program, which, when executed on an electronic device, enables the electronic device to execute the file sharing method according to any one of claims 1 to 17.
Citation Information
Patent Citations
Safe sharing method, sharing device and sharing system for files of network disk
CN103595721A
Universal data sharing method for heterogeneous encryption clouds
CN104735070A
File encryption transmission and sharing method in instant messaging
CN109951378A
Undeniable secure data transmission method based on block chain
CN110223064A
Real-time communication distributed key distribution method and system
CN112272095A