A method and system for encrypted file upload and message split-path transmission
Patent Information
- Application Number
- CN202611069213.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-17
- Publication Date
- 2026-09-29
AI Technical Summary
[0005]本申请提供一种文件加密上传与消息分通路传输方法及系统,旨在解决现有技术在面向数据中心的数据上传过程中,大容量数据传输效率较低、关联业务信息上报及时性不足、上传处理链路耦合度较高以及传输过程安全防护能力有限的问题
本申请基于对现有技术问题的进一步分析和研究,认识到在面向数据中心的数据上传过程中,大容量数据传输效率较低、关联业务信息上报及时性不足、上传处理链路耦合度较高以及传输过程安全防护能力有限的问题,通过获取终端设备产生的待上传文件,并在终端侧对待上传文件进行加密处理得到加密文件,使待上传文件在离开终端设备前即由明文状态转化为加密状态,从而降低文件在传输链路、中间节点或缓存环节中被暴露的风险;同时,根据待上传文件和/或加密文件生成包括文件标识信息和/或文件摘要值的摘要消息,使平台能够通过轻量级摘要消息获知与待上传文件相关的关联信息,而不必等待完整文件到达;进一步地,将加密文件通过用于承载文件数据的第一传输通路上传至数据中心,并在不以加密文件上传完成作为发送条件的情况下,将摘要消息通过不同于第一传输通路且用于承载消息数据的第二传输通路发送至平台,使大容量文件上传过程与摘要消息上报过程相互分离,避免大容量文件上传耗时对关联业务信息上报造成阻塞;在此基础上,再基于文件关联信息和分通路传输结果,将平台接收的摘要消息与数据中心接收的加密文件进行关联处理并建立上传关联记录,使分通路传输后的文件数据和消息数据能够被统一对应管理。因此,本申请能够在提高文件传输安全性的同时,提高关联业务信息上报的及时性,降低上传处理链路的耦合度,并改善面向数据中心的数据上传过程中的实时性、稳定性和安全防护能力。
Smart Images

Figure CN122845246A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data transmission technology, and in particular to a method and system for encrypted file upload and message split-path transmission. Background Technology
[0002] With the development of IoT, edge computing, and big data technologies, surveillance cameras, industrial sensors, mobile terminals, and various edge devices continuously generate various types of data during operation, including images, videos, logs, and status information. This data typically needs to be uploaded to cloud platforms or data centers for centralized storage, business analysis, event identification, status monitoring, or subsequent scheduling. Because different types of data differ in data volume, real-time requirements, security levels, and processing methods, transmission efficiency, business response timeliness, and data security during data upload are increasingly becoming crucial factors for data center access systems.
[0003] Existing data upload systems are typically designed around a unified data access interface or a common communication protocol to reduce the complexity of terminal access and platform processing. In practical applications, the upload process of large-capacity data such as images and videos is easily affected by network bandwidth, terminal computing power, link stability, and the platform's concurrent processing capabilities, resulting in long upload times. Simultaneously, descriptive information, status information, or prompts related to business processing may also be affected by the large-capacity data upload process, making it difficult to participate in timely business judgment and scheduling processing on the platform side. Furthermore, in scenarios with a large number of terminal devices, high upload frequency, or complex transmission environments, the risks of data upload failures, duplicate uploads, platform processing delays, and data exposure during transmission will further increase, impacting the stability and security of system operation.
[0004] Therefore, in the process of uploading data to data centers, the low efficiency of large-capacity data transmission, insufficient timeliness of reporting related business information, high coupling of the upload processing link, and limited security protection capabilities during the transmission process have become problems that urgently need to be solved. Summary of the Invention
[0005] This application provides a method and system for encrypted file upload and message split-path transmission, aiming to solve the problems of low efficiency in large-capacity data transmission, insufficient timeliness of reporting related business information, high coupling of upload processing links, and limited security protection capabilities in the data upload process for data centers in the existing technology.
[0006] Firstly, a method for encrypted file upload and message split-path transmission is provided, applied to a data upload system including terminal devices, platforms, and data centers, the method comprising: Obtain the file to be uploaded generated by the terminal device; The file to be uploaded is encrypted on the terminal side to obtain an encrypted file; Generate a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file. The digest message includes file association information for associating the encrypted file. The file association information includes file identification information and / or file digest value. The encrypted file and the digest message are subjected to multi-path transmission processing to obtain a multi-path transmission result. The multi-path transmission processing includes: uploading the encrypted file to the data center through a first transmission path, where the first transmission path is a file upload path used to carry file data; and sending the digest message to the platform through a second transmission path without requiring the completion of the encrypted file upload as a sending condition, where the second transmission path is a message transmission path different from the first transmission path and used to carry message data. Based on the file association information and the multi-channel transmission results, the digest message received by the platform is associated with the encrypted file received by the data center to establish an upload association record corresponding to the file to be uploaded.
[0007] Optionally, in the above solution, obtaining the file to be uploaded generated by the terminal device includes: Obtain the original files collected or generated by the terminal device; Perform an integrity check on the original file to obtain the integrity check result; The original file is formatted to obtain a file format confirmation result; If the integrity verification result indicates that the original file is complete, and the file format confirmation result indicates that the file format of the original file meets the upload requirements, the original file is identified as the file to be uploaded, and file identification information corresponding to the file to be uploaded is generated. The file identification information is used to generate the file association information.
[0008] Optionally, in the above scheme, the step of encrypting the file to be uploaded on the terminal side to obtain an encrypted file includes: Obtain encryption configuration information corresponding to the terminal device, wherein the encryption configuration information includes an encryption algorithm identifier and a key identifier; The target encryption algorithm is determined based on the encryption algorithm identifier, and the encryption processing parameters corresponding to the target encryption algorithm are determined based on the key identifier. Based on the target encryption algorithm and the encryption processing parameters, the file to be uploaded is encrypted to obtain the encrypted file; An encryption description is generated based on the encryption algorithm identifier and the key identifier. The encryption description is used to generate the digest message and / or to perform subsequent processing on the encrypted file. The encryption description does not include the plaintext key used to decrypt the encrypted file.
[0009] Optionally, in the above scheme, generating a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file includes: Based on the file to be uploaded, determine the basic description information of the file, which includes at least one of the following: file type information, file size information, collection time information, and terminal identification information; File verification information is determined based on the encrypted file, and the file verification information includes the file digest value; Determine the file upload target information based on the upload target of the file to be uploaded; Determine the encryption identifier information based on the encryption description information; Based on the file basic description information, the file verification information, the file upload target information, and the encryption identification information, the digest message is generated, and the file identification information and / or the file digest value are determined as the file association information.
[0010] Optionally, in the above scheme, uploading the encrypted file to the data center via the first transmission path includes: A file upload request is generated based on the encrypted file, the file association information, and the file upload path configuration, wherein the file upload path configuration is used to indicate at least one of the HTTP protocol, HTTPS protocol, or object storage protocol. A file upload session is established for the data center based on the file upload request, and file upload session information is obtained. Based on the file upload session information, the encrypted file is sent to the data center through the first transmission channel, and file reception feedback information is obtained. The file storage information is determined based on the file reception feedback information, and the file storage information is used to establish or update the upload association record.
[0011] Optionally, in the above scheme, during the process of sending the encrypted file to the data center through the first transmission channel, the method further includes: Based on the received feedback information of the file, determine whether the upload recovery conditions are met, and obtain the upload recovery judgment result; When the upload recovery judgment result indicates that the upload of the encrypted file was interrupted or failed, the range of uploaded files is determined according to the file upload session information. The uploaded content to be recovered is determined based on the range of uploaded files and the encrypted files. The upload content to be restored is sent to the data center through the first transmission channel to obtain upload recovery feedback information. Update the file storage information and the file upload status in the upload association record based on the restored upload feedback information.
[0012] Optionally, in the above scheme, sending the summary message to the platform via the second transmission path includes: The target message transmission protocol for the second transmission path is determined based on the message path configuration. The target message transmission protocol includes a message queue protocol or a lightweight message transmission protocol. Message routing information is determined based on the summary message, and the message routing information includes at least one of message topic information, message queue information, and platform receiving address information; Based on the target message transmission protocol, the message routing information, and the file association information, the digest message is encapsulated to obtain a digest message to be sent. The digest message to be sent is sent to the platform through the second transmission channel to obtain message sending feedback information. The delivery status of the summary message is determined based on the feedback information sent in the message. The delivery status of the summary message is used to trigger the platform to process the summary message.
[0013] Optionally, in the above scheme, after sending the digest message to be sent to the platform through the second transmission path, the method further includes: When the summary message delivery status indicates that the summary message to be sent has been successfully sent, the platform parses the summary message to be sent to obtain the file association information and business description information; A business triggering result is generated based on the business description information, and the business triggering result is used to trigger at least one of task scheduling, index creation, and business notification. A file record to be matched is established based on the file association information. The file record to be matched is used to associate and match the encrypted file received by the data center.
[0014] In the above scheme, optionally, the file association information includes file identification information and file digest value; the step of associating the digest message received by the platform with the encrypted file received by the data center based on the file association information and the multi-channel transmission result, and establishing an upload association record corresponding to the file to be uploaded, includes: Determine the target file association information based on the file records to be matched; Extract the target file identification information and target file digest value from the target file association information; Based on the target file identification information, candidate encrypted files are determined from the data center; The candidate encrypted files are verified to obtain the candidate file digest value; The candidate file digest value is matched with the target file digest value to obtain the file matching result; The upload association record is established or updated based on the file matching results.
[0015] Secondly, a file encryption upload and message split-path transmission system is provided, the system comprising terminal equipment, a platform, and a data center; The terminal device includes a file acquisition module, a terminal encryption module, a digest generation module, a file upload module, and a message sending module; The file acquisition module is used to acquire the file to be uploaded generated by the terminal device; The terminal encryption module is used to perform terminal-side encryption processing on the file to be uploaded to obtain an encrypted file; The digest generation module is used to generate a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file. The digest message includes file association information for associating the encrypted file. The file association information includes file identification information and / or file digest value. The file upload module and the message sending module are used to perform multi-path transmission processing on the encrypted file and the digest message to obtain the multi-path transmission result. The file upload module is used to upload the encrypted file to the data center through a first transmission path, where the first transmission path is a file upload path used to carry file data. The message sending module is used to send the digest message to the platform through a second transmission path without requiring the encrypted file upload to be completed as a sending condition. The second transmission path is a message transmission path that is different from the first transmission path and is used to carry message data. The platform is used to receive the summary message and perform at least one of task scheduling, index creation, and business triggering based on the summary message; The data center is used to receive and store the encrypted files; The platform and / or the data center are also used to associate the digest message received by the platform with the encrypted file received by the data center based on the file association information and the multi-channel transmission result, and establish an upload association record corresponding to the file to be uploaded.
[0016] Compared with the prior art, this application has at least the following beneficial effects: Based on further analysis and research of existing technical problems, this application recognizes the following issues in data upload processes for data centers: low efficiency of large-capacity data transmission, insufficient timeliness of reporting related business information, high coupling of upload processing links, and limited security protection capabilities during transmission. This application addresses these issues by acquiring the file to be uploaded from the terminal device and encrypting it on the terminal side to obtain an encrypted file. This ensures the file is converted from plaintext to encrypted before leaving the terminal device, reducing the risk of file exposure during transmission, intermediate nodes, or caching. Simultaneously, a digest message including file identification information and / or file digest value is generated based on the file to be uploaded and / or the encrypted file, enabling the platform to obtain information related to the file to be uploaded through a lightweight digest message. The encrypted file is uploaded to the data center via a first transmission path carrying the file data, without waiting for the complete file to arrive. Furthermore, without requiring the encrypted file upload to be complete, a digest message is sent to the platform via a second transmission path carrying message data, separate from the first transmission path. This separates the large-capacity file upload process from the digest message reporting process, preventing the time spent on large-capacity file uploads from blocking the reporting of related business information. Based on this, and using the file association information and the results of the separate transmission paths, the digest message received by the platform is associated with the encrypted file received by the data center, and an upload association record is established. This allows for unified management of the file data and message data after the separate transmission paths. Therefore, this application can improve the security of file transmission, enhance the timeliness of related business information reporting, reduce the coupling of the upload processing link, and improve the real-time performance, stability, and security protection capabilities of data uploads to the data center. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating a file encryption upload and message splitting transmission method provided in one embodiment of this application. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0019] In some embodiments, such as Figure 1As shown, this application provides a method for encrypted file upload and message split-path transmission, which can be applied to a data upload system including terminal devices, platforms, and data centers. Terminal devices can be surveillance cameras, industrial sensors, mobile terminals, edge computing devices, or other devices capable of collecting, generating, and uploading files. The platform can be used to receive digest messages and perform task scheduling, index building, service triggering, alarm handling, or status monitoring based on the digest messages. The data center can be used to receive, store, and manage encrypted files, and can collaborate with the platform to complete file matching, file verification, and subsequent business processing.
[0020] In some embodiments, the terminal device acquires a file it generates to be uploaded. The file to be uploaded can be an image file, video file, log file, or other large file that needs to be uploaded to the data center. The file to be uploaded can be acquired by the terminal device in real time, or it can be generated by the terminal device based on locally cached data, service-collected data, or edge processing results. By acquiring the file to be uploaded, the file objects that need to be uploaded to the data center can be determined, providing a data foundation for subsequent encryption processing, digest message generation, and multi-path transmission processing.
[0021] After acquiring the file to be uploaded, the terminal device performs terminal-side encryption, resulting in an encrypted file. Terminal-side encryption means encrypting the file before it leaves the terminal device, rather than encrypting it after it arrives at the data center. Encryption can employ preset symmetric, asymmetric, or hybrid encryption algorithms, or a suitable encryption method can be selected based on the terminal device type, file type, business security level, or encryption configuration issued by the platform. Terminal-side encryption ensures that the file is not exposed in plaintext form during transmission, intermediate nodes, cache nodes, or proxy nodes, thereby improving file transmission security.
[0022] After receiving the encrypted file, the terminal device generates a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file. The digest message is lightweight message data used to describe the basic information of the file to be uploaded or the encrypted file, and to enable the platform to know the file's relevant status without directly receiving the complete file. The digest message includes file association information for associating with the encrypted file, which includes file identification information and / or a file digest value. The file identification information can be a file number, upload task identifier, object storage key value, a unique identifier generated on the terminal side, or a business identifier assigned by the platform. The file digest value can be a hash value, checksum, or other digest value that can characterize the consistency of the file content, calculated based on the file to be uploaded or the encrypted file. By generating digest messages, the key information corresponding to large files can be abstracted into lightweight messages, enabling the platform to process business information promptly.
[0023] After receiving the encrypted file and digest message, the terminal device performs multi-path transmission processing on the encrypted file and digest message to obtain the multi-path transmission result. Multi-path transmission processing includes: uploading the encrypted file to the data center via a first transmission path, and sending the digest message to the platform via a second transmission path, without requiring the encrypted file upload to be completed as a sending condition. The first transmission path is the file upload path used to carry file data, which can adapt to the reliable upload requirements of large-capacity files. The second transmission path is a message transmission path, different from the first transmission path, used to carry message data, which can adapt to the real-time sending requirements of lightweight messages. The sending of the digest message is not conditional on the completion of the encrypted file upload; it can be sent before, during, or after the encrypted file upload, but its sending process does not depend on the file upload completion status. Therefore, even if the encrypted file upload takes a long time, retries occur, or the upload is in the process of resuming interrupted transmission, the platform can still receive the digest message in a timely manner.
[0024] After the platform receives the digest message and the data center receives the encrypted file, it can associate the digest message received by the platform with the encrypted file received by the data center based on file association information and the results of multi-path transmission, establishing an upload association record corresponding to the file to be uploaded. The upload association record can include at least one of the following: file identification information, file digest value, terminal identifier, file type, upload target, encrypted file storage address, digest message delivery status, file upload status, verification status, and business processing status. Through the upload association record, the platform and data center can uniformly manage the digest message and encrypted file of the same file to be uploaded, avoiding the problem of mismatch when the digest message and encrypted file are transmitted separately.
[0025] The method in this embodiment achieves several advantages. First, encrypting the file to be uploaded on the terminal side before uploading reduces the risk of plaintext exposure during transmission. Second, transmitting the encrypted file and digest message through the first and second transmission paths respectively prevents the uploading of large-capacity files from blocking the transmission of digest messages, thus improving the timeliness of the platform's acquisition of business information. Third, establishing upload association records based on file association information enables the platform and data center to effectively associate data transmitted through different paths, thereby addressing issues such as low efficiency of large-capacity data transmission, insufficient timeliness of reporting associated business information, high coupling of the upload processing link, and limited security protection capabilities during transmission.
[0026] In some embodiments, when a terminal device determines a file to be uploaded, it can first obtain the original file collected or generated by the terminal device. The original file can be an image or video captured by a camera, or a business data file generated by an industrial sensor, mobile terminal, or edge device. After obtaining the original file, the terminal device can perform an integrity check on the original file to obtain an integrity check result. Integrity check may include checking whether the file has been completely written, whether the file header and footer are complete, whether the file size meets expectations, whether the file can be read normally, and whether the file checksum is correct. The integrity check result indicates whether the original file is missing, corrupted, or incompletely generated.
[0027] The terminal device can also verify the format of the original file, obtaining a file format verification result. Format verification can include identifying the file extension, header identifier, encoding format, media container format, or business data format. For example, when the original file is an image file, it can verify whether it is JPEG, PNG, or other preset image formats; when the original file is a video file, it can verify whether it is MP4, AVI, or other preset video formats. The file format verification result indicates whether the original file's format meets the upload requirements.
[0028] If the integrity verification result indicates that the original file is complete, and the file format confirmation result indicates that the original file's file format meets the upload requirements, the terminal device will identify the original file as the file to be uploaded and generate corresponding file identification information. The file identification information can be generated by the terminal device based on the terminal identifier, collection time, file sequence number, random number, or service number, or it can be pre-issued by the platform or allocated by the data center. This file identification information is used to generate file association information and for the correspondence between subsequent summary messages, encrypted files, and upload association records.
[0029] By using the method in this embodiment, the integrity and format of the original file are checked before it enters the encryption and upload process. This can prevent incomplete, abnormal, or format-incompatible files from entering the subsequent transmission process, thereby reducing invalid and duplicate uploads. At the same time, by generating file identification information, a unified identification basis can be provided for the association processing between digest messages and encrypted files, improving the accuracy of subsequent file matching and business processing.
[0030] In some embodiments, when a terminal device performs terminal-side encryption on a file to be uploaded, it can first obtain encryption configuration information corresponding to the terminal device. The encryption configuration information can be pre-configured locally on the terminal device or distributed by a platform or data center. The encryption configuration information includes an encryption algorithm identifier and a key identifier. The encryption algorithm identifier indicates the target encryption algorithm to be used, and the key identifier indicates the key source, key version, or key index used for this encryption; however, the key identifier itself is not equivalent to the plaintext key.
[0031] The terminal device determines the target encryption algorithm based on the encryption algorithm identifier and determines the corresponding encryption processing parameters based on the key identifier. The target encryption algorithm can be a symmetric encryption algorithm, an asymmetric encryption algorithm, or a hybrid encryption algorithm. The encryption processing parameters may include an initialization vector, key version, encryption mode, padding method, block size, or other parameters required for encryption. After determining the target encryption algorithm and encryption processing parameters, the terminal device encrypts the file to be uploaded based on the target encryption algorithm and encryption processing parameters to obtain an encrypted file.
[0032] After obtaining the encrypted file, the terminal device can generate encrypted description information based on the encryption algorithm identifier and key identifier. The encrypted description information may include the encryption algorithm identifier, key identifier, encryption version, encryption time, or encryption policy identifier. This description information can be used to generate digest messages or for subsequent management and processing of the encrypted file by the platform or data center. The encrypted description information does not include the plaintext key used to decrypt the encrypted file to avoid sensitive key content being carried in the digest message or uploaded associated records.
[0033] Through the method of this embodiment, the terminal device can locally encrypt the file to be uploaded based on the encryption configuration information, so that the file is protected from the terminal device side. At the same time, by generating encryption description information through encryption algorithm identifier and key identifier, subsequent file management and decryption processing can have a traceable basis, but the plaintext key is not exposed. Thus, while improving the security of file transmission, the manageability of subsequent processing of encrypted files is also taken into account.
[0034] In some embodiments, when a terminal device generates a digest message based on a file to be uploaded and / or an encrypted file, it may first determine the basic file description information based on the file to be uploaded. The basic file description information may include at least one of file type information, file size information, acquisition time information, and terminal identification information. File type information indicates that the file to be uploaded belongs to an image, video, log, or other file type; file size information indicates the data volume of the file to be uploaded or the encrypted file; acquisition time information indicates the time when the file was generated or acquired; and terminal identification information indicates the terminal device that generated the file.
[0035] Terminal devices can also determine file verification information based on encrypted files. File verification information includes a file digest value. The file digest value can be obtained by performing a hash calculation or verification calculation on the encrypted file, or it can be calculated based on the file to be uploaded and then a correspondence established between it and the encrypted file. The file digest value can be used to subsequently determine whether the encrypted file received by the data center corresponds to the digest message, and it can also be used to detect whether the file has been corrupted or inconsistent during transmission.
[0036] The terminal device can also determine the file upload target information based on the upload destination of the file to be uploaded. The file upload target information may include the data center address, object storage bucket identifier, storage directory, business system identifier, or file storage policy. This information indicates where the encrypted file should be uploaded, or it is used by the platform to determine the corresponding business processing path for the file based on the digest message. The terminal device can also determine encryption identification information based on the encryption description information. This encryption identification information may include the encryption algorithm identifier, key identifier, or encryption version information.
[0037] After obtaining the basic file description information, file verification information, file upload target information, and encryption identification information, the terminal device generates a summary message based on the above information and determines the file identification information and / or file summary value as file association information. The summary message can adopt a structured message format, such as JSON format, key-value pair format, or other message formats supported by the message queue. The summary message does not carry the complete file content, but rather carries lightweight information required by the platform for business judgment, scheduling processing, and file association.
[0038] Through the method of this embodiment, the digest message can simultaneously carry basic file description information, file verification information, file upload target information, and encryption identification information, enabling the platform to obtain business information, verification information, and upload target information related to the file without receiving the complete file. At the same time, the file identification information and file digest value can serve as the basis for associating the digest message with the encrypted file, thereby improving the timeliness of the platform's business response and the reliability of file matching and verification.
[0039] In some embodiments, when an encrypted file is uploaded to a data center via a first transmission path, the terminal device can generate a file upload request based on the encrypted file, file association information, and file upload path configuration. The file upload path configuration indicates at least one of the following protocols: HTTP, HTTPS, or object storage. The object storage protocol can be a file upload protocol suitable for object storage services. Through the file upload path configuration, an upload method suitable for large-capacity file transfers can be selected based on the data center's access capabilities, file size, terminal network environment, or business policies.
[0040] The terminal device establishes a file upload session with the data center based on the file upload request, and obtains file upload session information. This information may include a session identifier, upload address, authentication information, fragmentation information, upload start position, upload validity period, or an upload token returned by the data center. This file upload session information is used to maintain the upload process of encrypted files between the terminal device and the data center.
[0041] The terminal device sends the encrypted file to the data center through the first transmission path based on the file upload session information and receives file reception feedback information. This feedback information may include successful reception, reception failure, the range of received files, the file storage address, and the file verification result or error reason. The terminal device or the data center can determine the file storage information based on this feedback. The file storage information may include the encrypted file's storage address in the data center, object identifier, storage time, storage status, and file upload status, and can be used to establish or update upload association records.
[0042] Through the method of this embodiment, the first transmission path can upload encrypted files in a manner suitable for file data transmission, avoiding the forced transmission of large-capacity files in a lightweight message channel; at the same time, through the continuous processing of file upload requests, file upload session information, file reception feedback information, and file storage information, the controllability and reliability of the encrypted file upload process can be improved, and file storage basis can be provided for the establishment of subsequent upload association records.
[0043] In some embodiments, during the process of sending an encrypted file to the data center through the first transmission path, the terminal device can determine whether the upload recovery conditions are met based on the file reception feedback information, and obtain an upload recovery judgment result. Upload recovery conditions may include upload interruption, upload timeout, network connection error, data center return of reception failure, incomplete reception of uploaded content, or file verification failure. The upload recovery judgment result indicates whether a retry or resumption of interrupted transmission is currently required.
[0044] When the upload recovery judgment indicates that the encrypted file upload was interrupted or failed, the terminal device determines the range of uploaded files based on the file upload session information. The range of uploaded files can be the range of file bytes that the data center has confirmed receiving, file fragment numbers, object block sequence numbers, or data segments that have been successfully uploaded. Based on the range of uploaded files, the terminal device determines the content to be recovered for upload, including the encrypted file. The content to be recovered can be the remaining file content that was not successfully uploaded, file fragments that were not confirmed for receipt, or data segments that need to be resent.
[0045] The terminal device sends the content to be uploaded to the data center through the first transmission path and receives feedback information indicating whether the content has been successfully received by the data center. The terminal device or the data center can update the file storage information and the file upload status in the upload association record based on the feedback information. For example, if the upload is successfully restored, the file upload status can be updated to "upload completed"; if the upload fails, the file upload status can be updated to "waiting for retry" or "upload error".
[0046] By using the method in this embodiment, when an interruption or failure occurs during the upload of encrypted files, the content to be resumed can be determined based on the file upload session information and the range of already uploaded files, avoiding the need to re-upload the complete encrypted file from scratch, thereby reducing the overhead of repeated transmission and improving the stability and efficiency of uploading large-capacity files. At the same time, by updating the file storage information and file upload status, the platform and data center can keep abreast of the upload progress of encrypted files, enhancing the robustness of the system in complex network environments.
[0047] In some embodiments, when a summary message is sent to the platform via a second transmission path, the terminal device can determine the target message transmission protocol for the second transmission path based on the message path configuration. The target message transmission protocol includes a message queuing protocol or a lightweight message transmission protocol. Message queuing protocols or lightweight message transmission protocols are suitable for carrying small data messages such as file description information, status information, business fields, and alarm information, but do not need to carry large files such as complete images or videos.
[0048] The terminal device determines message routing information based on the summary message. Message routing information includes at least one of message topic information, message queue information, and platform receiving address information. The message topic information can be used to identify the service topic to which the summary message belongs; the message queue information can be used to indicate the platform-side queue into which the summary message enters; and the platform receiving address information can be used to indicate the message receiving service. Through the message routing information, the summary message can be sent to the corresponding service processing module within the platform.
[0049] The terminal device encapsulates the summary message according to the target message transmission protocol, message routing information, and file association information to obtain a summary message to be sent. The summary message to be sent may include a message header and a message body. The message header may carry the message subject, message type, routing information, or sending time, while the message body may carry file association information, basic file description information, file upload target information, encryption identification information, and service description information. The terminal device sends the summary message to be sent to the platform through a second transmission path, receives message sending feedback information, and determines the summary message delivery status based on the message sending feedback information. The summary message delivery status is used to trigger the platform to process the summary message.
[0050] Using the method in this embodiment, the summary message is sent to the platform through a second transmission path suitable for message data transmission. It does not need to wait for the encrypted file to be uploaded, nor does it need to be sent by binding the encrypted file with the first transmission path carrying the file data, thereby improving the timeliness of reporting related business information. At the same time, through the target message transmission protocol, message routing information and message encapsulation processing, the summary message can be accurately entered into the corresponding business processing flow on the platform side, reducing the coupling of the data upload link.
[0051] In some embodiments, after the digest message to be sent is sent to the platform via the second transmission path, when the digest message delivery status indicates that the digest message to be sent has been successfully sent, the platform parses and processes the digest message to obtain file association information and business description information. The business description information may include business type, event type, alarm level, collection scenario, upload task type, processing priority, or other information used by the platform for business judgment.
[0052] The platform generates business triggering results based on business description information. These results are used to trigger at least one of the following: task scheduling, index creation, and business notification. For example, when the business description information indicates that the file to be uploaded is an alarm image, the platform can trigger an alarm processing task; when the business description information indicates that the file to be uploaded is a video clip, the platform can create a file index or schedule subsequent recognition tasks; when the business description information indicates that the file to be uploaded belongs to a specific terminal device, the platform can allocate the corresponding summary message to the relevant business system.
[0053] The platform can also create files to be matched based on file association information. These files are used to associate and match encrypted files received by the data center. A file to be matched record may include file identifier information, file digest value, digest message reception time, business description information, platform processing status, and pending matching status. Files to be matched can be created before the encrypted files are uploaded, allowing the platform to complete business preparation or scheduling in advance.
[0054] Using the method in this embodiment, the platform can parse the file association information and business description information after receiving the summary message, and perform task scheduling, index building or business notification accordingly, without waiting for the data center to complete the reception of the encrypted file, thereby reducing business response delay. At the same time, by establishing a record of files to be matched, the platform can provide a record basis for matching the summary message with the subsequently arriving encrypted files in the data center, and improve the collaborative processing capability after the transmission through different channels.
[0055] In some embodiments, file association information includes file identification information and file digest value. When performing association processing, the platform or data center can determine the target file association information based on the file records to be matched. Target file association information refers to the file association information that needs to be matched with encrypted files in the data center. The platform or data center extracts target file identification information and target file digest value from the target file association information. The target file identification information is used to find candidate encrypted files in the data center, and the target file digest value is used to perform consistency verification on the candidate encrypted files.
[0056] The data center can determine candidate encrypted files based on the target file identification information. Candidate encrypted files can be encrypted files already received and stored by the data center, or encrypted files in the uploaded or pending verification state. After determining the candidate encrypted files, verification processing can be performed to obtain the candidate file digest value. The candidate file digest value can be obtained by performing a digest calculation method consistent with that used by the terminal device on the candidate encrypted files.
[0057] The platform or data center matches the candidate file digest value with the target file digest value to obtain the file matching result. The file matching result can include a successful match, a failed match, or pending further confirmation. When the candidate file digest value matches the target file digest value, it can be determined that the digest message received by the platform corresponds to the candidate encrypted file received by the data center; when they do not match, it can be determined that the candidate encrypted file does not match the digest message, or that there is an anomaly in the file during transmission or storage. Based on the file matching result, upload association records can be established or updated. Upload association records can record the file matching status, file verification status, encrypted file storage location, and platform business processing status.
[0058] Using the method in this embodiment, the platform and data center can find candidate encrypted files based on file identification information and perform consistency verification based on file digest values, thereby avoiding incorrect associations caused by relying solely on file names or upload addresses. At the same time, by establishing or updating upload association records based on file matching results, the matching accuracy between digest messages and encrypted files after multi-path transmission can be improved, and the file transmission integrity verification capability can be enhanced.
[0059] In some embodiments, this application also provides a file encryption upload and message split-path transmission system. The system includes a terminal device, a platform, and a data center. The terminal device includes a file acquisition module, a terminal encryption module, a digest generation module, a file upload module, and a message sending module. These modules can communicate with each other through logical interfaces or data interfaces. Each module can be deployed within the same terminal device or in different functional processes of the terminal device.
[0060] The file acquisition module is used to acquire files to be uploaded generated by the terminal device. This module can acquire files from cameras, sensors, business applications, edge computing programs, or local storage units. The terminal encryption module performs terminal-side encryption on the files to be uploaded, resulting in encrypted files. The terminal encryption module can perform encryption operations based on the encryption algorithm identifier, key identifier, and encryption processing parameters, transforming the files into encrypted files before they are uploaded to the data center.
[0061] The digest generation module generates a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file. The digest message includes file association information for associating with the encrypted file, including file identification information and / or a file digest value. The digest generation module can also generate file type information, file size information, collection time information, terminal identification information, file upload target information, and encryption identification information, so that the platform can process the digest message and associate it with the encrypted file received by the data center.
[0062] The file upload module and message sending module are used to process encrypted files and digest messages through separate transmission paths, resulting in separate transmission paths. The file upload module uploads the encrypted file to the data center via a first transmission path. This first transmission path is the file upload path carrying the file data and can be implemented based on HTTP, HTTPS, or object storage protocols. The file upload module also supports retrying on failure, resuming interrupted uploads, and integrity verification to improve the reliability of large-capacity file uploads. The message sending module sends the digest message to the platform via a second transmission path without requiring the encrypted file upload to be completed. The second transmission path is different from the first transmission path and is used to carry message data; it can be implemented based on message queue protocols or lightweight message transmission protocols.
[0063] The platform receives summary messages and performs at least one of the following actions based on them: task scheduling, index creation, and business triggering. The platform can parse the summary messages to obtain file association information and business description information, and trigger corresponding business processes based on the business description information. The data center receives and stores encrypted files and can determine file storage information based on file upload requests, file upload session information, and file reception feedback information. The platform and / or the data center also associate the summary messages received by the platform with the encrypted files received by the data center based on file association information and multi-path transmission results, establishing upload association records corresponding to the files to be uploaded.
[0064] Through the system of this embodiment, the terminal device, platform, and data center form a clearly defined upload processing architecture: the terminal device is responsible for file acquisition, terminal-side encryption, digest generation, and multi-channel transmission; the platform is responsible for digest message reception and service triggering; the data center is responsible for receiving and storing encrypted files; and the platform and / or data center is responsible for the association processing of digest messages and encrypted files. Therefore, while ensuring the security of file source encryption, large-capacity file uploads and lightweight digest message reporting are independent and do not block each other, improving the system's real-time performance, stability, scalability, and security.
[0065] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
Claims
1. A method for encrypted file upload and message split-path transmission, characterized in that, The method, applied to a data upload system including terminal devices, platforms, and data centers, includes: Obtain the file to be uploaded generated by the terminal device; The file to be uploaded is encrypted on the terminal side to obtain an encrypted file; Generate a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file. The digest message includes file association information for associating the encrypted file. The file association information includes file identification information and / or file digest value. The encrypted file and the digest message are subjected to multi-path transmission processing to obtain a multi-path transmission result. The multi-path transmission processing includes: uploading the encrypted file to the data center through a first transmission path, where the first transmission path is a file upload path used to carry file data; and sending the digest message to the platform through a second transmission path without requiring the completion of the encrypted file upload as a sending condition, where the second transmission path is a message transmission path different from the first transmission path and used to carry message data. Based on the file association information and the multi-channel transmission results, the digest message received by the platform is associated with the encrypted file received by the data center to establish an upload association record corresponding to the file to be uploaded.
2. The file encryption upload and message split-path transmission method according to claim 1, characterized in that, The step of obtaining the file to be uploaded generated by the terminal device includes: Obtain the original files collected or generated by the terminal device; Perform an integrity check on the original file to obtain the integrity check result; The original file is formatted to obtain a file format confirmation result; If the integrity verification result indicates that the original file is complete, and the file format confirmation result indicates that the file format of the original file meets the upload requirements, the original file is identified as the file to be uploaded, and file identification information corresponding to the file to be uploaded is generated. The file identification information is used to generate the file association information.
3. The file encryption upload and message split-path transmission method according to claim 1, characterized in that, The step of encrypting the file to be uploaded on the terminal side to obtain an encrypted file includes: Obtain encryption configuration information corresponding to the terminal device, wherein the encryption configuration information includes an encryption algorithm identifier and a key identifier; The target encryption algorithm is determined based on the encryption algorithm identifier, and the encryption processing parameters corresponding to the target encryption algorithm are determined based on the key identifier. Based on the target encryption algorithm and the encryption processing parameters, the file to be uploaded is encrypted to obtain the encrypted file; An encryption description is generated based on the encryption algorithm identifier and the key identifier. The encryption description is used to generate the digest message and / or to perform subsequent processing on the encrypted file. The encryption description does not include the plaintext key used to decrypt the encrypted file.
4. The file encryption upload and message split-path transmission method according to claim 3, characterized in that, The step of generating a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file includes: Based on the file to be uploaded, determine the basic description information of the file, which includes at least one of the following: file type information, file size information, collection time information, and terminal identification information; File verification information is determined based on the encrypted file, and the file verification information includes the file digest value; Determine the file upload target information based on the upload target of the file to be uploaded; Determine the encryption identifier information based on the encryption description information; Based on the file basic description information, the file verification information, the file upload target information, and the encryption identification information, the digest message is generated, and the file identification information and / or the file digest value are determined as the file association information.
5. The file encryption upload and message split-path transmission method according to claim 1, characterized in that, Uploading the encrypted file to the data center via the first transmission channel includes: A file upload request is generated based on the encrypted file, the file association information, and the file upload path configuration, wherein the file upload path configuration is used to indicate at least one of the HTTP protocol, HTTPS protocol, or object storage protocol. A file upload session is established for the data center based on the file upload request, and file upload session information is obtained. Based on the file upload session information, the encrypted file is sent to the data center through the first transmission channel, and file reception feedback information is obtained. The file storage information is determined based on the file reception feedback information, and the file storage information is used to establish or update the upload association record.
6. The file encryption upload and message split-path transmission method according to claim 5, characterized in that, During the process of sending the encrypted file to the data center through the first transmission channel, the method further includes: Based on the received feedback information of the file, determine whether the upload recovery conditions are met, and obtain the upload recovery judgment result; When the upload recovery judgment result indicates that the upload of the encrypted file was interrupted or failed, the range of uploaded files is determined according to the file upload session information. The uploaded content to be recovered is determined based on the range of uploaded files and the encrypted files. The upload content to be restored is sent to the data center through the first transmission channel to obtain upload recovery feedback information. Update the file storage information and the file upload status in the upload association record based on the restored upload feedback information.
7. The file encryption upload and message split-path transmission method according to claim 1, characterized in that, Sending the summary message to the platform via the second transmission path includes: The target message transmission protocol for the second transmission path is determined based on the message path configuration. The target message transmission protocol includes a message queue protocol or a lightweight message transmission protocol. Message routing information is determined based on the summary message, and the message routing information includes at least one of message topic information, message queue information, and platform receiving address information; Based on the target message transmission protocol, the message routing information, and the file association information, the digest message is encapsulated to obtain a digest message to be sent. The digest message to be sent is sent to the platform through the second transmission channel to obtain message sending feedback information. The delivery status of the summary message is determined based on the feedback information sent in the message. The delivery status of the summary message is used to trigger the platform to process the summary message.
8. The file encryption upload and message split-path transmission method according to claim 7, characterized in that, After sending the digest message to be sent to the platform via the second transmission path, the method further includes: When the summary message delivery status indicates that the summary message to be sent has been successfully sent, the platform parses the summary message to be sent to obtain the file association information and business description information; A business triggering result is generated based on the business description information, and the business triggering result is used to trigger at least one of task scheduling, index creation, and business notification. A file record to be matched is established based on the file association information. The file record to be matched is used to associate and match the encrypted file received by the data center.
9. The file encryption upload and message split-path transmission method according to claim 8, characterized in that, The file association information includes file identification information and a file digest value; the process of associating the digest message received by the platform with the encrypted file received by the data center based on the file association information and the multi-channel transmission result, and establishing an upload association record corresponding to the file to be uploaded, includes: Determine the target file association information based on the file records to be matched; Extract the target file identification information and target file digest value from the target file association information; Based on the target file identification information, candidate encrypted files are determined from the data center; The candidate encrypted files are verified to obtain the candidate file digest value; The candidate file digest value is matched with the target file digest value to obtain the file matching result; The upload association record is established or updated based on the file matching results.
10. A file encryption upload and message split-path transmission system, characterized in that, This includes terminal equipment, platforms, and data centers; The terminal device includes a file acquisition module, a terminal encryption module, a digest generation module, a file upload module, and a message sending module; The file acquisition module is used to acquire the file to be uploaded generated by the terminal device; The terminal encryption module is used to perform terminal-side encryption processing on the file to be uploaded to obtain an encrypted file; The digest generation module is used to generate a digest message corresponding to the encrypted file based on the file to be uploaded and / or the encrypted file. The digest message includes file association information for associating the encrypted file. The file association information includes file identification information and / or file digest value. The file upload module and the message sending module are used to perform multi-path transmission processing on the encrypted file and the digest message to obtain the multi-path transmission result. The file upload module is used to upload the encrypted file to the data center through a first transmission path, where the first transmission path is a file upload path used to carry file data. The message sending module is used to send the digest message to the platform through a second transmission path without requiring the encrypted file upload to be completed as a sending condition. The second transmission path is a message transmission path that is different from the first transmission path and is used to carry message data. The platform is used to receive the summary message and perform at least one of task scheduling, index creation, and business triggering based on the summary message; The data center is used to receive and store the encrypted files; The platform and / or the data center are also used to associate the digest message received by the platform with the encrypted file received by the data center based on the file association information and the multi-channel transmission result, and establish an upload association record corresponding to the file to be uploaded.